ISO 31000

Companies in the Czech Republic are increasingly looking at how to work with risks systematically. The ISO 31000 standard gives a clear answer. It is not a certification standard, but an internationally recognised framework of principles for managing risk in an organisation.

What ISO 31000 is and what it is for

ISO 31000 is an international standard describing the principles and process for managing risk in an organisation. Unlike ISO 9001 or ISO 14001, it is not a certifiable standard. A company cannot be certified against it, because no such certificate exists.

The standard works as a guide. It describes what risk identification, risk assessment and risk management should look like. The aim is to recognise risks before they turn into a loss or damage.

Many people want to know how to manage risk according to ISO 31000 in practice. The standard answers in three areas: the principles of risk management, the framework for managing risks and the process itself. A company adapts these layers to its sector and size.

Summary: ISO 31000 is a general framework for risk management, not a certification standard. On its own, it does not lead to a certificate.

The difference between ISO 31000 and certifiable standards

ISO 31000 provides general principles. Standards such as ISO 45001 or ISO 14001 build on similar principles, but they are designed as certifiable systems with specific requirements and documentation.

  • ISO 31000 – a general framework for risk management, without certification
  • ISO 45001 – a certifiable occupational health and safety management system, workplace risk assessment
  • ISO 14001 – a certifiable environmental management system

Recommendation: if a company is considering certification, ISO 31000 is a good starting point for understanding the principles. Certification itself, however, is handled by other standards.

The risk management process under the international standard

At the heart of ISO 31000 is a process consisting of several steps. The procedure is universal and works in a manufacturing company just as well as in an office or on a construction site.

The process starts with establishing the context, when the company clarifies its objectives and responsibilities. This is followed by risk identification – mapping everything that could threaten operations, employees’ health or property. After identification comes assessing the likelihood and severity of the consequences. The final phase is treating the risks – through technical solutions, training or organisational procedures.

Summary: the process has four phases – context, identification, assessment and treatment of risks. Risks cannot be managed effectively without systematic identification.

Risk management

Why risk analysis is the basis of safety in a company

A theoretical framework such as ISO 31000 does not help a company on its own. The real benefit comes when the principles of risk management are reflected in a concrete workplace risk analysis.

A risk analysis in a company means a detailed mapping of the operation. A specialist finds out where there is a risk of injury, fire or another adverse event. The output is an overview of risks divided into two groups.

  1. Removable risks – solved quickly, often with protective equipment or changes to the workplace
  2. Non-removable risks – addressed through internal rules and work procedures

Many people ask how to carry out a workplace risk analysis under current legislation. Czech law requires the employer to identify and assess risks and take measures to limit them. A risk analysis is therefore an obligation, not an optional activity.

Recommendation: a company should first have a thorough workplace risk analysis prepared. On that basis, tailor-made health and safety and fire protection documentation and other measures can be prepared.

Who benefits from working with the ISO 31000 principles

Managing risk according to ISO 31000 makes sense for every organisation, regardless of sector. A manufacturing company will use it to manage the risks of operating machinery, an office-based company to protect data, and a construction company to plan safety on site.

Companies often ask whether managing risk according to ISO 31000 is suitable for small companies too. The answer is yes – the standard scales to the size of the organisation.

Recommendation: whatever the size of the company, it is best to start simply – map the main risks of the operation and gradually expand the system.

How Rescue Group can help

At Rescue Group we do not offer ISO 31000 as a certification service, because certification does not exist for this standard. We do, however, offer a thorough risk analysis in companies, based on the same principles the standard describes.

Our risk analysis is the starting point for all further safety work. We find out how the operation works, identify the risks and divide them into removable and non-removable ones. Based on the output, we prepare tailor-made health and safety documentation, fire protection documentation and other measures.

If your company is working towards certification to ISO 14001 or ISO 19011, we will also help you prepare for the certification audit.

Training

Q&A: frequently asked questions about ISO 31000

Can you get ISO 31000 certification?

No. ISO 31000 contains general principles for risk management, but it is not certifiable.

What is the difference between ISO 31000 and ISO 45001?

ISO 31000 describes a general risk management process that can be used in any area of business. ISO 45001 is a specific certifiable occupational safety management system that supplements risk assessment with specific documentation requirements.

Does a company have to have a risk analysis by law?

Yes. Czech legislation obliges employers to identify and assess risks in the workplace and take measures to limit them.

How often should a risk analysis be updated?

A risk analysis should be reviewed after every significant change in operations. If no such change occurs, a review at least once a year is recommended.

Will Rescue Group help with ISO 31000 certification?

We offer a professional risk analysis and, if needed, help prepare for certification audits according to ISO 14001 or ISO 19011.

Risk analysis

ISO 31000 gives companies a solid theoretical framework for managing risk, but on its own it provides neither a certificate nor a ready-made solution. Real value arises only when the principles of the standard are reflected in a concrete risk analysis of a specific workplace.

We will carry out a thorough risk analysis in your company and, if needed, support you in preparing for ISO 14001 or ISO 19011 certification audits. Get in touch and we will discuss what a risk analysis could look like for you.

Want to analyse the risks in your company?

Contact us

Health and Safety for Companies

Health and safety for companies includes risk assessment, training and documentation. Find out which obligations an employer must meet and what happens if they are neglected.

OHS

Fire Extinguisher Inspections

Find out how often fire extinguishers are checked, what the periodic test includes, and what obligations and penalties companies face.

Fire protectionInspections

Fire Safety Measures

What fire safety measures must a company have in place? An overview of legal obligations, documentation, training, inspections and possible fines, all in one place.

Fire protection

Workplace Lighting Measurement

Workplace lighting measurement: when is it mandatory, how does it work and what is assessed? An overview of legal requirements and recommendations for health and safety.

OHSInspections

We will help you keep safety under control

Tell us what you are dealing with. We will propose a solution tailored to your company – with no obligation.