C L A R E N T   3 6 0

Loading

ISO 31000:2018 Self-Assessment

Evaluate your organization's risk maturity against international guidelines, identify structural gaps, and establish a robust framework.

Introducing ISO 31000:2018

Globally recognized best practice, ISO 31000:2018, provides universally applicable guidelines, principles, and a framework for managing risk of any type in any organization. It helps you continually review and refine your processes, building operational resilience today, while ensuring readiness for tomorrow's uncertainties.

The Benefits of Alignment

Aligning with ISO 31000:2018 demonstrates your organization’s commitment to proactive risk management.

By gaining structured assurance that your risk management program meets the guidelines of ISO 31000, you can inspire confidence in your stakeholders, safeguard your assets, mitigate potential disruptions, and build an organizational culture of informed, effective decision-making.

ISO 31000 Risk Management GRC

Why Organizations Adopt ISO 31000

Establish a structured, internationally recognized framework to secure critical assets, mitigate systemic risks, and foster stakeholder trust.

Value Creation & Protection

The core purpose of risk management is the creation and protection of organizational value. It improves performance, encourages innovation, and supports the achievement of objectives.

Integrated Decision-Making

Risk management is not a stand-alone activity; it is an integral part of all organizational activities, including governance, leadership, planning, strategy, and operations.

Structured & Comprehensive

A structured and comprehensive approach to risk management contributes to consistent, comparable, and reliable results across the entire organization.

Continual Improvement

Risk management is continually improved through learning, experience, and structured feedback loops, keeping the framework responsive to dynamic risks.

Are you ready to evaluate your risk maturity?

Managing risk effectively is vital for organizational resilience and success. Unlock your risk maturity score, benchmark against ISO 31000:2018 guidelines, and receive tailored expert advisory recommendations.

How the Self-Assessment Works

By filling in the checklist below, you can gauge what stage of maturity your risk management framework is currently at in relation to the main requirements and principles of the standard, and what actions you can take next.

Check each box once you have validated the corresponding principles and framework elements. Each completed item counts as one point towards your final score.

Clause 4 - Principles of Risk management
0 / 8 Completed
1. Creating & Protecting Value

Does the organization’s risk management framework and approach create and protect value by contributing to the achievement of its objectives and improvement of performance?

2. Integrated into All Activities

Is risk management integrated into all organizational activities, processes, and decision-making structures rather than operating as a standalone function?

3. Structured & Comprehensive Approach

Is risk management structured, comprehensive, and applied consistently across the organization to produce comparable and reliable results?

4. Adapted & Proportionate Context

Is the risk management approach adapted and proportionate to the organization’s external and internal context, as well as its risk profile and objectives?

5. Based on Best Available Information

Does the organization ensure that the best available information – including historical data, expert judgment, stakeholder feedback, and observations – is used as an input to risk management?

6. Human and Cultural Factors

Does the risk management approach account for human and cultural factors, including the behaviors, perceptions, and intentions of internal and external stakeholders, which can facilitate or hinder achievement of objectives?

7. Transparent & Inclusive Stakeholders

Is risk management transparent and inclusive, with relevant stakeholders appropriately involved in defining the framework, identifying risks, and evaluating risk treatment options?

8. Continual Framework Improvement

Is the risk management framework and process continually monitored, evaluated, and improved to reflect changing internal and external conditions and lessons learned?

Clause 5 - Framework
0 / 11 Completed

The framework provides the foundations and organizational arrangements for designing, implementing, monitoring, reviewing, and continually improving risk management processes throughout the organization.

9. Leadership Commitment & Policies (5.2)

Has leadership and top management demonstrated commitment to integrating risk management into all organizational activities, including setting the risk management policy and objectives?

10. Authority, Resources & Designating Owner (5.2)

Has the organization ensured that appropriate authority, resources, and accountability are assigned for managing risk, including designating a risk owner at relevant levels?

11. Integration into Governance & Operations (5.3)

Is risk management integrated into the organization’s governance structure, strategic planning, operational processes, and project management activities?

12. Understanding Internal & External Context (5.4)

Has the organization understood and documented its internal and external context, including its legal, regulatory, financial, operational, and strategic environment?

13. Articulated Risk Management Policy (5.4)

Has the organization articulated a documented risk management policy that states its objectives, commitment, and approach to managing risk?

14. Defined Roles & Reporting Structures (5.4)

Has the organization defined roles, responsibilities, accountabilities, and reporting structures for risk management across all functions and levels?

15. Resource Identification & Provisioning (5.4)

Have the resources – including people, systems, processes, and technology – necessary to support effective risk management been identified and allocated?

16. Communication & Stakeholder Consultation (5.4)

Are communication and consultation channels established to ensure relevant stakeholders receive timely and appropriate risk information?

17. Framework Implementation Plan (5.5)

Has the organization developed and implemented an appropriate plan for implementing the risk management framework, including timelines, responsibilities, and integration milestones?

18. Framework Performance Evaluation (5.7)

Does the organization periodically measure the performance of the risk management framework against defined objectives, indicators, and benchmarks?

19. Framework Continual Improvement (5.7)

Is the risk management framework subject to continual improvement, with lessons learned systematically incorporated to enhance organizational resilience?

Clause 6 - Process
0 / 11 Completed

The risk management process is the systematic application of policies, procedures, and practices to communicate, consult, establish context, identify, analyze, evaluate, treat, monitor, and review risk.

20. Ongoing Stakeholder Communication (6.2)

Does the organization maintain ongoing communication and consultation with internal and external stakeholders throughout all stages of the risk management process?

21. Communication & Consultation Plan (6.2)

Is a communication and consultation plan established that specifies the audience, frequency, content, and channels for sharing risk-related information?

22. Defining Scope of Activities (6.3)

Has the organization defined the scope of each risk management activity, including objectives, environment, responsibilities, and exclusions?

23. Context Assessment (Internal & External) (6.3)

Has the organization assessed both its external context (regulatory, competitive, technological, societal factors) and internal context (governance, culture, resources, capabilities) that may influence risk management?

24. Establishing Risk Appetite & Criteria (6.3)

Have risk criteria been established that specify the level of risk the organization is willing to accept, including risk appetite and tolerance thresholds?

25. Risk Identification Methods (6.4)

Has the organization identified risks using appropriate methods, including both threats and opportunities, across all relevant areas of its operations?

26. Risk Analysis & Likelihood Assessment (6.4)

Does the organization analyze identified risks to understand their likelihood, potential impact, and the effectiveness of existing controls?

27. Selecting Treatment Options (6.5)

Has the organization selected and implemented appropriate risk treatment options – including avoiding, taking, removing, changing the likelihood or consequence, sharing, or retaining risks?

28. Risk Treatment Plans & Residual Risks (6.5)

Are risk treatment plans developed that specify actions, responsible parties, resources, timelines, and reporting requirements, and are residual risks explicitly reviewed and accepted?

29. Monitoring, Review & Key Risk Indicators (6.6)

Are risk management activities, outcomes, reporting to relevant stakeholders and the effectiveness of risk controls subject to regular monitoring and review at defined intervals, with key risk indicators tracked to provide early warning of changes with the support of Risk register?

30. Recording, Reporting & Compliance (6.7)

Are risk management activities, outcomes, and decisions documented in a consistent and controlled manner to support accountability and decision-making tailored to the needs of different stakeholders to demonstrate compliance and support continual improvement?

0 / 30 Points Foundational
Foundational
0 - 10 Points

Initial Stage

Developing
11 - 20 Points

Defined Program

Optimized
21 - 30 Points

Audit Ready

Action Recommended: Build Internal Capability & Risk Policy

Your organization is at an early stage of risk management maturity. Risk practices may be ad hoc, informal, or siloed.

We recommend exploring foundational risk management training and qualifications for key personnel to build internal capability. Developing an enterprise risk management policy and assigning dedicated risk roles would be valuable first steps.

Action Recommended: Schedule Structured Gap Assessment

Your organization has established some risk management practices, but significant gaps remain.

A structured Gap Assessment would help identify where your current framework falls short of ISO 31000:2018 requirements. Our specialists can benchmark your practices and provide a prioritized roadmap to strengthen your risk framework and move toward full alignment with the standard.

Congratulations: High Risk Management Alignment!

Your organization demonstrates strong risk management maturity and is well aligned with the principles and requirements of ISO 31000:2018.

At this level, focus should shift to continual improvement, embedding risk culture, and leveraging risk intelligence to drive strategic decision-making. Our team can support you with advanced risk optimization, assurance reviews, and benchmarking against peers.

Ready to take the next step in your GRC journey?

Based on your Foundational status, contact our experts to build internal risk capability and establish your policy baseline.

ISO 31000:2018 Official Standard

Access the official ISO publication directory to review standard guidelines, principles, and the risk management framework.

Visit ISO Directory

Reset Assessment?

This will clear all 30 self-assessment checklist selections and reset your maturity score. This action cannot be undone.