ISO 31000:2018
What is ISO 31000:2018?
ISO 31000:2018 Risk Management Guidelines (guidance, not certifiable).. It comprises 28 controls organised across 3 domains, published by ISO/IEC, and applies in International.
How ISO 31000:2018 maps to other frameworks
All 28 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 3 domains ISO 31000:2018 groups its controls into
Frameworks that share controls with ISO 31000:2018
Each of these has at least one control mapped to a control in ISO 31000:2018. The number is how many ISO 31000:2018 controls are shared, counted from the mapping graph.
ISO 19011:2018
27 shared controlsISO/IEC 23894:2023
10 shared controlsISO 27005
7 shared controlsISO/IEC 38500:2024
4 shared controlsBelgium CyberFundamentals
4 shared controlsBSI IT-Grundschutz
4 shared controlsISO/IEC 17025:2017 - General Requirements for Testing and Calibration
4 shared controlsISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
3 shared controlsWhere ISO 31000:2018 overlaps with the standards you already hold
Analysis of ISO 31000:2018
Where to get trained on ISO 31000:2018
4 courses in the catalogue cover ISO 31000:2018 directly. Each is self-paced, includes the downloadable toolkit and the implementation playbook, and carries a certificate of completion.
Training more than one person? Ten seats of any course is $1,490 on a single licence, against $199 a seat bought one at a time.
What ISO 31000:2018 means in your sector
What ISO 31000:2018 means for your job
Questions people ask about ISO 31000:2018
What is ISO 31000:2018?
How many controls does ISO 31000:2018 have?
Where does ISO 31000:2018 apply?
What frameworks does ISO 31000:2018 map to?
How do I get started with ISO 31000:2018 compliance?
Query ISO 31000:2018 programmatically
ISO 31000:2018, its 28 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
ISO 31000:2018 API reference and MCP config →What ISO 31000:2018 requires, control by control
Each page carries the requirement text for one ISO 31000:2018 control and what an assessor expects to see as evidence.
- 4-B Fair Presentation
- 4-D Confidentiality
- 4-E Independence
- 4-F Evidence-Based Approach
- 4-G Risk-Based Approach
- 4-H Continual improvement
- 5-4-2 Articulating risk management commitment
- 5-4-3 Assigning organizational roles, authorities, responsibilities and accountabilities
- 5-4-4 Allocating resources
- 5-4-5 Establishing communication and consultation
How ready are you for ISO 31000:2018?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.