Skip to content

Evidence request lists

ISO 31000

Evidence request list. 43 controls, 43 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.

Framework

ISO31000-5.2
Leadership and commitment

Top management and oversight bodies demonstrate leadership and commitment.

Artefacts an auditor will ask for
  • Board charter
  • Risk appetite statement
  • Tone communications
Where this commonly fails
  • Appetite vague
  • No board challenge
ISO31000-5.3
Integration into the organisation

Integrate risk management based on understanding structures and context.

Artefacts an auditor will ask for
  • Org map
  • Integration plan
  • Process embedment evidence
Where this commonly fails
  • Integration limited to ERM team
ISO31000-5.4
Design of framework

Design the framework considering external and internal context, commitment, roles, resources, communication.

Artefacts an auditor will ask for
  • Framework document
  • Resource plan
  • RACI
Where this commonly fails
  • Resources unfunded
ISO31000-5.5
Implementation

Implement the framework through a plan with timing, resources, and metrics.

Artefacts an auditor will ask for
  • Implementation plan
  • Milestone tracker
Where this commonly fails
  • No metrics for implementation
ISO31000-5.6
Evaluation

Periodically measure framework performance against purpose, plans, and indicators.

Artefacts an auditor will ask for
  • Performance review
  • Maturity assessment
Where this commonly fails
  • No maturity baseline
ISO31000-5.7
Improvement

Adapt and continually improve the framework to address changes.

Artefacts an auditor will ask for
  • Improvement backlog
  • Change log
Where this commonly fails
  • Backlog stale

ISO 31000: Risk Assessment

ISO31000-06
Risk identification methods

Risk identification methods. Control from ISO 31000 framework, domain: ISO 31000: Risk Assessment.

Artefacts an auditor will ask for
  • Risk register
  • Risk assessment methodology
  • Scenario library
  • Heat map
Where this commonly fails
  • Scenarios too generic
  • Criteria not calibrated
  • Interdependencies overlooked
ISO31000-07
Risk analysis and evaluation

Risk analysis and evaluation. Control from ISO 31000 framework, domain: ISO 31000: Risk Assessment.

Artefacts an auditor will ask for
  • Risk register
  • Risk assessment methodology
  • Scenario library
  • Heat map
Where this commonly fails
  • Scenarios too generic
  • Criteria not calibrated
  • Interdependencies overlooked
ISO31000-08
Risk criteria and thresholds

Risk criteria and thresholds. Control from ISO 31000 framework, domain: ISO 31000: Risk Assessment.

Artefacts an auditor will ask for
  • Risk register
  • Risk assessment methodology
  • Scenario library
  • Heat map
Where this commonly fails
  • Scenarios too generic
  • Criteria not calibrated
  • Interdependencies overlooked
ISO31000-09
Risk scenario development

Risk scenario development. Control from ISO 31000 framework, domain: ISO 31000: Risk Assessment.

Artefacts an auditor will ask for
  • Risk register
  • Risk assessment methodology
  • Scenario library
  • Heat map
Where this commonly fails
  • Scenarios too generic
  • Criteria not calibrated
  • Interdependencies overlooked
ISO31000-10
Risk interdependency analysis

Risk interdependency analysis. Control from ISO 31000 framework, domain: ISO 31000: Risk Assessment.

Artefacts an auditor will ask for
  • Risk register
  • Risk assessment methodology
  • Scenario library
  • Heat map
Where this commonly fails
  • Scenarios too generic
  • Criteria not calibrated
  • Interdependencies overlooked

ISO 31000: Risk Framework & Governance

ISO31000-01
Risk management policy and scope

Risk management policy and scope. Control from ISO 31000 framework, domain: ISO 31000: Risk Framework & Governance.

Artefacts an auditor will ask for
  • Risk management policy
  • Risk governance charter
  • Stakeholder map
  • Risk integration plan
Where this commonly fails
  • Risk appetite not approved by board
  • Stakeholder needs not surfaced
  • Risk culture not measured
ISO31000-02
Risk governance structure

Risk governance structure. Control from ISO 31000 framework, domain: ISO 31000: Risk Framework & Governance.

Artefacts an auditor will ask for
  • Risk management policy
  • Risk governance charter
  • Stakeholder map
  • Risk integration plan
Where this commonly fails
  • Risk appetite not approved by board
  • Stakeholder needs not surfaced
  • Risk culture not measured
ISO31000-03
Risk culture and communication

Risk culture and communication. Control from ISO 31000 framework, domain: ISO 31000: Risk Framework & Governance.

Artefacts an auditor will ask for
  • Risk management policy
  • Risk governance charter
  • Stakeholder map
  • Risk integration plan
Where this commonly fails
  • Risk appetite not approved by board
  • Stakeholder needs not surfaced
  • Risk culture not measured
ISO31000-04
Stakeholder requirements for risk

Stakeholder requirements for risk. Control from ISO 31000 framework, domain: ISO 31000: Risk Framework & Governance.

Artefacts an auditor will ask for
  • Risk management policy
  • Risk governance charter
  • Stakeholder map
  • Risk integration plan
Where this commonly fails
  • Risk appetite not approved by board
  • Stakeholder needs not surfaced
  • Risk culture not measured
ISO31000-05
Risk management integration

Risk management integration. Control from ISO 31000 framework, domain: ISO 31000: Risk Framework & Governance.

Artefacts an auditor will ask for
  • Risk management policy
  • Risk governance charter
  • Stakeholder map
  • Risk integration plan
Where this commonly fails
  • Risk appetite not approved by board
  • Stakeholder needs not surfaced
  • Risk culture not measured

ISO 31000: Risk Monitoring & Review

ISO31000-16
Risk monitoring procedures

Risk monitoring procedures. Control from ISO 31000 framework, domain: ISO 31000: Risk Monitoring & Review.

Artefacts an auditor will ask for
  • Risk monitoring report
  • Risk register update log
  • Management review minutes
  • Trend dashboard
Where this commonly fails
  • Register stale beyond 90 days
  • Trends not communicated
  • Management review skipped
ISO31000-17
Risk reporting and communication

Risk reporting and communication. Control from ISO 31000 framework, domain: ISO 31000: Risk Monitoring & Review.

Artefacts an auditor will ask for
  • Risk monitoring report
  • Risk register update log
  • Management review minutes
  • Trend dashboard
Where this commonly fails
  • Register stale beyond 90 days
  • Trends not communicated
  • Management review skipped
ISO31000-18
Risk register maintenance

Risk register maintenance. Control from ISO 31000 framework, domain: ISO 31000: Risk Monitoring & Review.

Artefacts an auditor will ask for
  • Risk monitoring report
  • Risk register update log
  • Management review minutes
  • Trend dashboard
Where this commonly fails
  • Register stale beyond 90 days
  • Trends not communicated
  • Management review skipped
ISO31000-19
Continuous improvement of risk processes

Continuous improvement of risk processes. Control from ISO 31000 framework, domain: ISO 31000: Risk Monitoring & Review.

Artefacts an auditor will ask for
  • Risk monitoring report
  • Risk register update log
  • Management review minutes
  • Trend dashboard
Where this commonly fails
  • Register stale beyond 90 days
  • Trends not communicated
  • Management review skipped
ISO31000-20
Management review of risk program

Management review of risk program. Control from ISO 31000 framework, domain: ISO 31000: Risk Monitoring & Review.

Artefacts an auditor will ask for
  • Risk monitoring report
  • Risk register update log
  • Management review minutes
  • Trend dashboard
Where this commonly fails
  • Register stale beyond 90 days
  • Trends not communicated
  • Management review skipped

ISO 31000: Risk Treatment

ISO31000-11
Risk treatment options and selection

Risk treatment options and selection. Control from ISO 31000 framework, domain: ISO 31000: Risk Treatment.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Residual risk acceptance memo
  • Insurance schedule
  • Control mapping
Where this commonly fails
  • Residual risk approval missing
  • Treatment owners unassigned
  • Insurance gaps unmapped
ISO31000-12
Risk treatment plan development

Risk treatment plan development. Control from ISO 31000 framework, domain: ISO 31000: Risk Treatment.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Residual risk acceptance memo
  • Insurance schedule
  • Control mapping
Where this commonly fails
  • Residual risk approval missing
  • Treatment owners unassigned
  • Insurance gaps unmapped
ISO31000-13
Residual risk acceptance

Residual risk acceptance. Control from ISO 31000 framework, domain: ISO 31000: Risk Treatment.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Residual risk acceptance memo
  • Insurance schedule
  • Control mapping
Where this commonly fails
  • Residual risk approval missing
  • Treatment owners unassigned
  • Insurance gaps unmapped
ISO31000-14
Risk transfer and insurance

Risk transfer and insurance. Control from ISO 31000 framework, domain: ISO 31000: Risk Treatment.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Residual risk acceptance memo
  • Insurance schedule
  • Control mapping
Where this commonly fails
  • Residual risk approval missing
  • Treatment owners unassigned
  • Insurance gaps unmapped
ISO31000-15
Control implementation and monitoring

Control implementation and monitoring. Control from ISO 31000 framework, domain: ISO 31000: Risk Treatment.

Artefacts an auditor will ask for
  • Risk treatment plan
  • Residual risk acceptance memo
  • Insurance schedule
  • Control mapping
Where this commonly fails
  • Residual risk approval missing
  • Treatment owners unassigned
  • Insurance gaps unmapped

Principles

ISO31000-4.1
Risk management principles overview

Apply the eight ISO 31000 principles to guide value creating risk management.

Artefacts an auditor will ask for
  • Risk policy
  • Principles mapping
  • Governance charter
Where this commonly fails
  • Principles cited but not operationalised
ISO31000-4.2
Integrated principle

Integrate risk management into all organisational activities and decisions.

Artefacts an auditor will ask for
  • Process maps showing risk gates
  • Decision templates
Where this commonly fails
  • Siloed risk function
ISO31000-4.3
Structured and comprehensive principle

Use a structured approach to risk to produce consistent comparable outcomes.

Artefacts an auditor will ask for
  • Risk methodology
  • Taxonomy
  • Standardised templates
Where this commonly fails
  • Divisional methodologies diverge
ISO31000-4.4
Customised principle

Customise the framework and process to the organisation context and objectives.

Artefacts an auditor will ask for
  • Tailoring rationale
  • Context document
Where this commonly fails
  • Off the shelf framework unadjusted
ISO31000-4.5
Inclusive principle

Involve stakeholders to ensure their knowledge, views, and perceptions are considered.

Artefacts an auditor will ask for
  • Stakeholder engagement plan
  • Workshop minutes
Where this commonly fails
  • Frontline not consulted
ISO31000-4.6
Dynamic principle

Anticipate, detect, acknowledge, and respond to changes affecting risk.

Artefacts an auditor will ask for
  • Horizon scanning reports
  • Change triggers
Where this commonly fails
  • Annual update cycle only
ISO31000-4.7
Best available information principle

Base risk management on best available information acknowledging limitations.

Artefacts an auditor will ask for
  • Data sources register
  • Assumption log
  • Limitations note
Where this commonly fails
  • Assumptions undocumented
ISO31000-4.8
Human and cultural factors principle

Recognise human and cultural factors influence all aspects of risk management.

Artefacts an auditor will ask for
  • Risk culture survey
  • Behavioural assessment
Where this commonly fails
  • No risk culture metrics
ISO31000-4.9
Continual improvement principle

Continually improve risk management through learning and experience.

Artefacts an auditor will ask for
  • Lessons learned register
  • Improvement plan
Where this commonly fails
  • Lessons not actioned

Process

ISO31000-6.2
Communication and consultation

Ongoing communication and consultation with stakeholders throughout the process.

Artefacts an auditor will ask for
  • Comms plan
  • Workshop logs
  • Stakeholder feedback
Where this commonly fails
  • One off communication
ISO31000-6.3
Scope, context and criteria

Establish scope, external and internal context, and risk criteria for the activity.

Artefacts an auditor will ask for
  • Scope statement
  • Context analysis
  • Criteria definition
Where this commonly fails
  • Criteria undefined
  • Likelihood scales arbitrary
ISO31000-6.4.1
Risk identification

Find, recognise, and describe risks that might help or hinder objectives.

Artefacts an auditor will ask for
  • Risk register
  • Identification workshops
  • Bow tie diagrams
Where this commonly fails
  • Opportunities omitted
  • Emerging risks missed
ISO31000-6.4.2
Risk analysis

Comprehend nature of risk and characteristics including likelihood, consequence, controls.

Artefacts an auditor will ask for
  • Analysis worksheets
  • Scenario analysis
  • Control effectiveness ratings
Where this commonly fails
  • Inherent vs residual not distinguished
ISO31000-6.4.3
Risk evaluation

Compare analysis results with criteria to determine where additional action is required.

Artefacts an auditor will ask for
  • Heat maps
  • Tolerance comparison
  • Decision log
Where this commonly fails
  • No tolerance comparison
ISO31000-6.5
Risk treatment

Select and implement options to address risks and assess residual risk.

Artefacts an auditor will ask for
  • Treatment plans
  • Control owners
  • Residual risk approval
Where this commonly fails
  • Treatment owner missing
  • No residual sign off
ISO31000-6.6
Monitoring and review

Monitor and review the process and the risks to assure quality and effectiveness.

Artefacts an auditor will ask for
  • KRIs
  • Review minutes
  • Trend reports
Where this commonly fails
  • KRIs lagging only
ISO31000-6.7
Recording and reporting

Record and report risk management activities and outcomes to stakeholders.

Artefacts an auditor will ask for
  • Risk reports
  • Board pack
  • Audit trail
Where this commonly fails
  • Reports do not drive decisions
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the ISO 31000 framework page.