ISO 31000 coverage that turns principles into practice
Principles, framework and process implemented as one operating cycle, with every assessment, treatment decision and review recorded automatically.
Compliance at a glance
What ISO 31000 sets out
Three-step assessment built in
Identification, analysis and evaluation run as distinct steps rather than a single scoring exercise, capturing sources, events and consequences before likelihood and impact are applied.
Treatment that closes and is measured
Treatment options carry owners, dates and cost. Residual positions are reassessed after implementation rather than assumed.
Recording and reporting by default
Every assessment, rating change and treatment decision is recorded with its author and date automatically. The audit trail exists without anyone maintaining it.
Shared credit across risk frameworks
An assessment that satisfies ISO 31000 also satisfies PSRMF and COSO ERM expectations. Dimeri records it once and reflects it in each scorecard.
ISO 31000 compliance, covered by default
ISO 31000 is adopted more often than it is used. Dimeri closes the gap by implementing its three parts directly. The principles shape the approach, the framework embeds it, and the process runs cycle after cycle.
Aligned to the standard
The platform follows the structure of ISO 31000 directly, from scope, context and criteria through identification, analysis and evaluation to treatment, monitoring and reporting, so the register maps onto the standard without translation.
Three-step assessment
Identification, analysis and evaluation run as three distinct steps rather than a single scoring exercise, capturing sources, events and consequences before likelihood and impact are applied.
Leadership integration
Risk policy, mandate and accountabilities held with review dates, and risk information embedded in the same registers as strategy and operations, the integration the 2018 revision calls for.
Treatment tracking
Treatment options recorded with their rationale, turned into actions with owners and dates, and residual positions reassessed after implementation rather than assumed.
Recording and reporting by default
Every assessment, rating change and treatment decision recorded with its author and date automatically. Recording and reporting handled as a by-product, not a separate effort.
The process Dimeri implements
Dimeri follows the clause structure of the standard directly, so a register built in the platform maps onto ISO 31000 without translation.
Principles
Risk management that is integrated, structured and comprehensive, customised, inclusive, dynamic, informed, human aware and continually improving.
- Register structure customised to your context
- Inclusive input from line functions rather than central drafting
- Dynamic capture of emerging risk between cycles
- Improvement actions tracked on the process itself
Framework and leadership
Leadership and commitment expressed through a mandate, policy, allocated resources and defined accountabilities, then designed, implemented, evaluated and improved.
- Risk policy and mandate held with review dates
- Accountabilities assigned to named individuals
- Framework evaluation recorded against its own criteria
- Improvement actions with owners and due dates
Scope, context and criteria
Defining the scope of each risk activity, understanding external and internal context, and setting the criteria that determine what is significant.
- Scope statement held against each assessment
- External and internal context factors recorded
- Configurable likelihood and consequence criteria
- Appetite and tolerance thresholds applied per category
Risk assessment
Identification, analysis and evaluation, treated as three distinct steps rather than a single scoring exercise.
- Identification capturing sources, events and consequences
- Analysis of likelihood, consequence and control effectiveness
- Evaluation against criteria to decide what needs treatment
- Inherent and residual positions held separately
Risk treatment
Selecting and implementing treatment options, then assessing the residual risk and deciding whether it is tolerable.
- Treatment option recorded with its rationale
- Treatment plans with owners, dates and cost
- Residual assessment after implementation
- Secondary risks introduced by treatment captured
Monitoring, review, recording and reporting
Planned monitoring and review of the process and outcomes, with recording and reporting that reaches decision makers.
- Review schedules per risk and per control
- Key risk indicators with thresholds and trends
- Complete audit trail of who changed what and when
- Reporting tailored to board, committee and management
Getting ISO 31000 coverage in place
4 steps from where you are today to a ISO 31000 position your auditor can rely on.
Book a demoThe risk policy, mandate and accountabilities are loaded, and the criteria that determine significance are configured to your context rather than to a default scale.
How Dimeri covers ISO 31000
Recording and reporting as a by-product
ISO 31000 expects records that support reporting and preserve the basis of decisions. In Dimeri every assessment, rating change and treatment decision is recorded with its author and date automatically, so the record exists without anyone maintaining it.
Integrated with decisions, not parallel to them
Project risks, compliance obligations, audit findings and business continuity all sit in the same register with the same criteria. Risk stops being a separate exercise that runs alongside the organisation's decisions.
Customised without being bespoke
Criteria, scales, categories and appetite are configured to your context, which is what the standard's principles ask for, while the underlying structure stays consistent enough to report across the organisation.
ISO 31000 questions
Can we get certified against ISO 31000?
No. ISO 31000 provides guidelines rather than requirements, and it is not a certifiable management system standard in the way ISO 9001 or ISO 27001 are. Organisations demonstrate alignment through the quality of their framework and process, and through independent assessment such as internal audit, rather than through a certificate.
What changed in the 2018 edition?
The 2018 revision simplified the standard considerably and moved leadership and commitment to the centre of the framework, with a stronger emphasis on integrating risk management into governance and decision making. The process steps were also clarified, including making recording and reporting an explicit part of the process rather than an afterthought.
Should we use ISO 31000 or COSO ERM?
They answer slightly different questions. ISO 31000 is a concise, sector neutral guideline that works well as the operating method for a risk function. COSO ERM 2017 is more detailed and more explicitly tied to strategy and performance, which suits organisations whose board wants risk framed in those terms. Many organisations run both, and Dimeri maps controls once across the two.
Does Dimeri support our own risk scoring scales?
Yes. Likelihood and consequence criteria, the number of levels, the labels, appetite and tolerance thresholds and category specific scales are all configurable. The standard explicitly asks for the framework to be customised to the organisation, so a fixed scale would work against it.
Is this a substitute for the standard itself?
No. This page describes how Dimeri implements the ISO 31000 process. The standard is a copyrighted document published by ISO and should be obtained from ISO or a national standards body if you intend to work to it.
Ready to Transform Your GRC?
Join governance, risk, and compliance teams using AI to work smarter.