Risk management

The purpose of risk management is the creation and protection of value. Organizations of all types and sizes face external and internal factors and influences that make it uncertain whether they will achieve their objectives. The Risks are to be managed.

 

Managing risk is part of governance and leadership, and is fundamental to how the organization is managed at all levels. It contributes to the improvement of management systems.

 

One of the existing standards for managing risk - beside the COSO Enterprize Risk Management - globally wellknown and widely used is:

ISO 31000 - Risk management - Guidelines

Managing risk is based in ISO 31000 on

  • Principles
  • Framework
  • Process

ISO 31000 is for use by people who create and protect value in organizations by managing risks, making decisions, setting and achieving objectives and improving performance. 


iso family - risk based approach

ISO 31000 provides a common approach to the management of all types of risks to which enterprises are exposed throughout the life of the enterprise and is used to further develop and/or improve an integrated management system.