ISO 31000:2018 provides guidelines for managing risk across an organization. It can be adapted to different activities and sectors. It is not an information security management system certification standard. ISO 31000:2018

Apply the risk management process

Establish the scope, context and criteria for the decision. Identify the relevant risks, analyse their characteristics and evaluate them against those criteria. Select and implement suitable treatment, then monitor and review the results.

Communication, consultation, recording and reporting support the process. Revisit the assessment when objectives, assumptions or circumstances change.

An editorial overview of ISO 31000: scope, context and criteria; risk identification, analysis and evaluation; and treatment, supported by communication, review, recording and reporting.
Editorial overview of the ISO 31000:2018 risk management process. Open full-size diagram.

Relate it to continual improvement

Plan–Do–Check–Act is a useful way to discuss planning, implementation, review and improvement. It should not replace ISO 31000's own process terminology or be presented as its four mandatory stages.

For requirements covering an information security management system, refer to ISO/IEC 27001. The standards have related uses but different scopes. ISO/IEC 27001

Use the edition applicable to your organization's work, and check clause references against that edition. Clause numbers from an older edition should not be relabelled as ISO 31000:2018.