ISO 31000
Evidence request list. 43 controls, 43 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Framework
Top management and oversight bodies demonstrate leadership and commitment.
- Board charter
- Risk appetite statement
- Tone communications
- Appetite vague
- No board challenge
Integrate risk management based on understanding structures and context.
- Org map
- Integration plan
- Process embedment evidence
- Integration limited to ERM team
Design the framework considering external and internal context, commitment, roles, resources, communication.
- Framework document
- Resource plan
- RACI
- Resources unfunded
Implement the framework through a plan with timing, resources, and metrics.
- Implementation plan
- Milestone tracker
- No metrics for implementation
Periodically measure framework performance against purpose, plans, and indicators.
- Performance review
- Maturity assessment
- No maturity baseline
Adapt and continually improve the framework to address changes.
- Improvement backlog
- Change log
- Backlog stale
ISO 31000: Risk Assessment
Risk identification methods. Control from ISO 31000 framework, domain: ISO 31000: Risk Assessment.
- Risk register
- Risk assessment methodology
- Scenario library
- Heat map
- Scenarios too generic
- Criteria not calibrated
- Interdependencies overlooked
Risk analysis and evaluation. Control from ISO 31000 framework, domain: ISO 31000: Risk Assessment.
- Risk register
- Risk assessment methodology
- Scenario library
- Heat map
- Scenarios too generic
- Criteria not calibrated
- Interdependencies overlooked
Risk criteria and thresholds. Control from ISO 31000 framework, domain: ISO 31000: Risk Assessment.
- Risk register
- Risk assessment methodology
- Scenario library
- Heat map
- Scenarios too generic
- Criteria not calibrated
- Interdependencies overlooked
Risk scenario development. Control from ISO 31000 framework, domain: ISO 31000: Risk Assessment.
- Risk register
- Risk assessment methodology
- Scenario library
- Heat map
- Scenarios too generic
- Criteria not calibrated
- Interdependencies overlooked
Risk interdependency analysis. Control from ISO 31000 framework, domain: ISO 31000: Risk Assessment.
- Risk register
- Risk assessment methodology
- Scenario library
- Heat map
- Scenarios too generic
- Criteria not calibrated
- Interdependencies overlooked
ISO 31000: Risk Framework & Governance
Risk management policy and scope. Control from ISO 31000 framework, domain: ISO 31000: Risk Framework & Governance.
- Risk management policy
- Risk governance charter
- Stakeholder map
- Risk integration plan
- Risk appetite not approved by board
- Stakeholder needs not surfaced
- Risk culture not measured
Risk governance structure. Control from ISO 31000 framework, domain: ISO 31000: Risk Framework & Governance.
- Risk management policy
- Risk governance charter
- Stakeholder map
- Risk integration plan
- Risk appetite not approved by board
- Stakeholder needs not surfaced
- Risk culture not measured
Risk culture and communication. Control from ISO 31000 framework, domain: ISO 31000: Risk Framework & Governance.
- Risk management policy
- Risk governance charter
- Stakeholder map
- Risk integration plan
- Risk appetite not approved by board
- Stakeholder needs not surfaced
- Risk culture not measured
Stakeholder requirements for risk. Control from ISO 31000 framework, domain: ISO 31000: Risk Framework & Governance.
- Risk management policy
- Risk governance charter
- Stakeholder map
- Risk integration plan
- Risk appetite not approved by board
- Stakeholder needs not surfaced
- Risk culture not measured
Risk management integration. Control from ISO 31000 framework, domain: ISO 31000: Risk Framework & Governance.
- Risk management policy
- Risk governance charter
- Stakeholder map
- Risk integration plan
- Risk appetite not approved by board
- Stakeholder needs not surfaced
- Risk culture not measured
ISO 31000: Risk Monitoring & Review
Risk monitoring procedures. Control from ISO 31000 framework, domain: ISO 31000: Risk Monitoring & Review.
- Risk monitoring report
- Risk register update log
- Management review minutes
- Trend dashboard
- Register stale beyond 90 days
- Trends not communicated
- Management review skipped
Risk reporting and communication. Control from ISO 31000 framework, domain: ISO 31000: Risk Monitoring & Review.
- Risk monitoring report
- Risk register update log
- Management review minutes
- Trend dashboard
- Register stale beyond 90 days
- Trends not communicated
- Management review skipped
Risk register maintenance. Control from ISO 31000 framework, domain: ISO 31000: Risk Monitoring & Review.
- Risk monitoring report
- Risk register update log
- Management review minutes
- Trend dashboard
- Register stale beyond 90 days
- Trends not communicated
- Management review skipped
Continuous improvement of risk processes. Control from ISO 31000 framework, domain: ISO 31000: Risk Monitoring & Review.
- Risk monitoring report
- Risk register update log
- Management review minutes
- Trend dashboard
- Register stale beyond 90 days
- Trends not communicated
- Management review skipped
Management review of risk program. Control from ISO 31000 framework, domain: ISO 31000: Risk Monitoring & Review.
- Risk monitoring report
- Risk register update log
- Management review minutes
- Trend dashboard
- Register stale beyond 90 days
- Trends not communicated
- Management review skipped
ISO 31000: Risk Treatment
Risk treatment options and selection. Control from ISO 31000 framework, domain: ISO 31000: Risk Treatment.
- Risk treatment plan
- Residual risk acceptance memo
- Insurance schedule
- Control mapping
- Residual risk approval missing
- Treatment owners unassigned
- Insurance gaps unmapped
Risk treatment plan development. Control from ISO 31000 framework, domain: ISO 31000: Risk Treatment.
- Risk treatment plan
- Residual risk acceptance memo
- Insurance schedule
- Control mapping
- Residual risk approval missing
- Treatment owners unassigned
- Insurance gaps unmapped
Residual risk acceptance. Control from ISO 31000 framework, domain: ISO 31000: Risk Treatment.
- Risk treatment plan
- Residual risk acceptance memo
- Insurance schedule
- Control mapping
- Residual risk approval missing
- Treatment owners unassigned
- Insurance gaps unmapped
Risk transfer and insurance. Control from ISO 31000 framework, domain: ISO 31000: Risk Treatment.
- Risk treatment plan
- Residual risk acceptance memo
- Insurance schedule
- Control mapping
- Residual risk approval missing
- Treatment owners unassigned
- Insurance gaps unmapped
Control implementation and monitoring. Control from ISO 31000 framework, domain: ISO 31000: Risk Treatment.
- Risk treatment plan
- Residual risk acceptance memo
- Insurance schedule
- Control mapping
- Residual risk approval missing
- Treatment owners unassigned
- Insurance gaps unmapped
Principles
Apply the eight ISO 31000 principles to guide value creating risk management.
- Risk policy
- Principles mapping
- Governance charter
- Principles cited but not operationalised
Integrate risk management into all organisational activities and decisions.
- Process maps showing risk gates
- Decision templates
- Siloed risk function
Use a structured approach to risk to produce consistent comparable outcomes.
- Risk methodology
- Taxonomy
- Standardised templates
- Divisional methodologies diverge
Customise the framework and process to the organisation context and objectives.
- Tailoring rationale
- Context document
- Off the shelf framework unadjusted
Involve stakeholders to ensure their knowledge, views, and perceptions are considered.
- Stakeholder engagement plan
- Workshop minutes
- Frontline not consulted
Anticipate, detect, acknowledge, and respond to changes affecting risk.
- Horizon scanning reports
- Change triggers
- Annual update cycle only
Base risk management on best available information acknowledging limitations.
- Data sources register
- Assumption log
- Limitations note
- Assumptions undocumented
Recognise human and cultural factors influence all aspects of risk management.
- Risk culture survey
- Behavioural assessment
- No risk culture metrics
Continually improve risk management through learning and experience.
- Lessons learned register
- Improvement plan
- Lessons not actioned
Process
Ongoing communication and consultation with stakeholders throughout the process.
- Comms plan
- Workshop logs
- Stakeholder feedback
- One off communication
Establish scope, external and internal context, and risk criteria for the activity.
- Scope statement
- Context analysis
- Criteria definition
- Criteria undefined
- Likelihood scales arbitrary
Find, recognise, and describe risks that might help or hinder objectives.
- Risk register
- Identification workshops
- Bow tie diagrams
- Opportunities omitted
- Emerging risks missed
Comprehend nature of risk and characteristics including likelihood, consequence, controls.
- Analysis worksheets
- Scenario analysis
- Control effectiveness ratings
- Inherent vs residual not distinguished
Compare analysis results with criteria to determine where additional action is required.
- Heat maps
- Tolerance comparison
- Decision log
- No tolerance comparison
Select and implement options to address risks and assess residual risk.
- Treatment plans
- Control owners
- Residual risk approval
- Treatment owner missing
- No residual sign off
Monitor and review the process and the risks to assure quality and effectiveness.
- KRIs
- Review minutes
- Trend reports
- KRIs lagging only
Record and report risk management activities and outcomes to stakeholders.
- Risk reports
- Board pack
- Audit trail
- Reports do not drive decisions
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 31000 framework page.