ISO 31000: Risk Management Principles and Guidelines Training Course

Work through ISO 31000 in depth, from its principles and framework to the risk process, monitoring, communication, governance integration and sustainability.

19 dates in 17 cities · Oct 2026 – Jul 2027

Paris

Fees: 9900
From:
To:

Budapest

Fees: 9900
From:
To:

Singapore

Fees: 9900
From:
To:

Vienna

Fees: 9900
From:
To:

Manama

Fees: 8900
From:
To:

Istanbul

Fees: 8900
From:
To:

Zurich

Fees: 11900
From:
To:

Amman

Fees: 8900
From:
To:

Budapest

Fees: 9900
From:
To:
See all 19 dates & locations
17 cities · filter by city or month

Course overview

ISO 31000 is the most widely referenced risk management standard and the most widely misunderstood. It is not a certifiable standard, it prescribes almost nothing, and it will not tell you what your risk matrix should look like. What it provides is a coherent set of principles, a framework for embedding risk management in an organization, and a process that runs from establishing context through to monitoring and review.

This course works through the standard across twelve units, taking each element seriously and translating it into practice. It covers the principles, the framework, the full risk process, monitoring, communication and consultation, governance integration, sustainability and global practice, closing with an integrated case.

Why a non-prescriptive standard is harder to apply

Because the work is left to you. ISO 31000 says risk management should be integrated, structured, customized, inclusive, dynamic and based on the best available information. Every one of those words implies decisions the standard does not make for you: how integrated, into which processes, customized to what, inclusive of whom.

Organizations that implement it well treat the standard as a design brief rather than a checklist. They spend their effort on the framework: mandate, ownership, integration into decisions, and the review cycle. Organizations that implement it badly buy a template, adopt the vocabulary, and produce a register that satisfies the words and changes nothing.

Course objectives

By the end of the course, participants will be able to:

  • Define what the standard covers and what it does not.
  • Apply the ISO 31000 principles to a live decision.
  • Embed the framework in leadership, planning and operations.
  • Establish a risk process that runs from context to reporting.
  • Identify exposures and analyze them with a fitting method.
  • Evaluate an exposure against the criteria set in advance.
  • Treat risks using the options the standard sets out.
  • Review the framework itself when conditions change.
  • Communicate uncertainty to the board and to the business.
  • Set risk work beside compliance obligations and audit assurance.
  • Record climate and sustainability exposure in one register.
  • Tailor a framework to an organization that already has one.

Course outline

Unit 1: Introduction to ISO 31000

  • ISO 31000 as guidance rather than a certifiable standard.
  • The link to ISO 31010 techniques and ISO 22301 continuity.
  • Comparison with COSO ERM and its different emphasis.
  • One vocabulary so two teams mean the same thing.

Unit 2: ISO 31000 risk management principles

  • Integration and structure with risk inside the decision.
  • Customization and inclusiveness in proportionate design.
  • Dynamic response as conditions change rather than annually.
  • Best available information, human and cultural factors.

Unit 3: Risk management framework

  • What leadership must provide for the framework to work.
  • Integration of risk into strategy, planning and operations.
  • Design of roles and authorities that fit the organization.
  • Implementation, evaluation and continual improvement.

Unit 4: Risk management process overview

  • Establishing scope, context and criteria in concrete terms.
  • The sequence of identification, analysis and evaluation.
  • Treatment, monitoring and review through the whole cycle.
  • Communication and consultation as a continuous activity.

Unit 5: Risk identification and analysis

  • Identification methods from checklists to horizon scanning.
  • Risk written so its cause and its effect stay separate.
  • Bow-tie, fault tree and scenario analysis from ISO 31010.
  • Qualitative and quantitative analysis matched to the data.

Unit 6: Risk evaluation and treatment

  • Risk criteria and the point at which exposure needs action.
  • Every response the standard permits, and when each fits.
  • Treatment plans with owners, dates and measures of effect.
  • Residual exposure and the person who signs for it.

Unit 7: Monitoring and review

  • Watching the framework as well as the risks inside it.
  • Evidence that a treatment changed the exposure.
  • Review triggers from strategic and regulatory change.
  • Recording and reporting what is kept and who reads it.

Unit 8: Communication and consultation

  • Who holds the knowledge about a risk and who is asked.
  • Stakeholder consultation and the perceptions behind a risk.
  • Reporting to the board, to management and to the business.
  • Transparency about uncertainty and what is not known.

Unit 9: Governance and compliance integration

  • Where risk sits on the board's own agenda.
  • Board decisions turned into written risk criteria.
  • Alignment with compliance obligations held elsewhere.
  • What internal audit tests when it reviews risk work.

Unit 10: ISO 31000 and ESG integration

  • Climate and environmental exposure in the same framework.
  • Social exposure across the workforce and the community.
  • Sustainability disclosure and overstated public claims.
  • Twenty-year risks inside a three-year planning cycle.

Unit 11: Global best practices in ISO risk management

  • Proportionate implementation in a small organization.
  • Sector adaptations in financial services and healthcare.
  • Evidence that an implementation has changed decisions.
  • Failed implementations and the corrections that follow.

Unit 12: Capstone case study

  • Setting the context and criteria for the case company.
  • Identifying and analyzing the main exposures in the case.
  • Designing treatment plans and the monitoring behind them.
  • Adapting the standard to one company and what was left out.

How the course is delivered

Sessions work through the standard's text alongside real artifacts: risk policies, registers, treatment plans and framework reviews that participants critique and rebuild in discussion. Worked examples take context-setting, analysis and treatment decisions step by step. The course is educational and does not certify participants or organizations; ISO 31000 is guidance and is not a certifiable standard in any case. Participants who want the enterprise view beyond the standard should look at Enterprise Risk Management Strategies.

Who should attend

  • Risk managers implementing or improving a risk framework.
  • Compliance, quality and governance professionals using ISO frameworks.
  • Internal auditors assessing risk management against the standard.
  • Managers and executives who own risks within the framework.

About EuroQuest International Training

EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We run over 1,000 courses and have trained more than 15,000 participants. Our head office is in Bratislava, Slovakia, with hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Courses are written and reviewed by practitioners from the fields they cover.

Frequently asked questions

Can my organization be certified against ISO 31000?

No. ISO 31000 is guidance and was deliberately written as non-certifiable. Any body offering certification against it is offering something the standard does not support. EuroQuest does not certify participants or organizations.

Do I need the standard document to attend?

It is useful to have access to it, but not required. The course explains each element and works through its application, and participants who own the standard often find its brevity is exactly the problem the course solves.

Does the course include a live lab?

No. There is no software environment. The sessions use the standard, real risk artifacts and worked examples analyzed in discussion.

Related courses

Register for this course

Select a city and date from the schedule above to register, or contact EuroQuest about in-house delivery for a risk function implementing the standard.

All Course Dates & Locations

19 dates · 17 cities · Oct 2026 – Jul 2027

September - 2026
October - 2026
November - 2026
December - 2026
January - 2027
February - 2027
March - 2027
April - 2027
May - 2027
June - 2027
July - 2027
August - 2027
Amman
Barcelona
Brussels
Budapest
Cairo
Dubai
Geneva
Istanbul
Jakarta
Kuala Lumpur
London
Madrid
Manama
Paris
Singapore
Vienna
Zurich
Showing 19 of 19 dates

Paris

Fees: 9900
From:
To:

Budapest

Fees: 9900
From:
To:

Singapore

Fees: 9900
From:
To:

Vienna

Fees: 9900
From:
To:

Manama

Fees: 8900
From:
To:

Istanbul

Fees: 8900
From:
To:

Zurich

Fees: 11900
From:
To:

Amman

Fees: 8900
From:
To:

Budapest

Fees: 9900
From:
To:

Brussels

Fees: 9900
From:
To:

Dubai

Fees: 8900
From:
To:

Barcelona

Fees: 9900
From:
To:

Cairo

Fees: 8900
From:
To:

Geneva

Fees: 11900
From:
To:

Madrid

Fees: 9900
From:
To:

London

Fees: 9900
From:
To:

Jakarta

Fees: 9900
From:
To:

Kuala Lumpur

Fees: 8900
From:
To:

Istanbul

Fees: 8900
From:
To: