Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a44f65548987bdc9

Jump to content

Talk:ISO 31000

Page contents not supported in other languages.
Add topic
From Wikipedia, the free encyclopedia

External associated with the ISO 31000 risk managmeent standard

[edit]

Over the past 10 years, the Wikipedia page for the keyword "ISO 31000" included three key external links:

1. A direct link to the official ISO 31000 standard on the ISO website.

2. A landmark article titled "ISO 31000, the Gold Standard", co-authored by myself and Chris Lajtha (former Corporate Risk Manager at Schlumberger), published in Strategic Risk magazine. This was one of the first in-depth publications on ISO 31000:2008 and contributed significantly to the global risk management dialogue.

3. A link to the first dedicated discussion forum on ISO 31000, hosted on LinkedIn. This group rapidly became the largest and most active platform for risk professionals, now gathering over 98,000 members. It remains a leading space for interpretation, debate, and knowledge exchange on the standard.

Recently, a Wikipedia moderator removed these three external links and invited me to present my case for their relevance.

As a former member of the ISO/TC262 risk management committee, I was also surprised by the disorganized structure of the current article, which lacks alignment with the format typically used for other ISO management system standards. I have since reviewed and restructured the content accordingly.

That said, my primary concern is the removal of these three historically significant and informative links. I welcome your thoughts: do you agree with this decision?

Thank you for your input and work on the article. To address your points;
  • 1 - Per guidelines here, this is precisely the sort of link that should be in this section, and why I did not remove it.
  • 2 - This link is already cited as a reliable source in the article, and is exactly what the article needs in a secondary source. But can more be said of its significance to the standard? Otherwise, there is no reason for repeating it as an external link, and simply listing it there tells the reader nothing about its importance above any other article available on the internet on the subject.
  • 3 - Per guidelines here, this fails on points 6 and 10. Also not clear what this forum can provide about the subject that cannot be included in the article, so also point 1.
It should be remembered that Wikipedia is not a web directory. It is an encyclopaedia. The fact these two links have been there for over ten years is not a reason for keeping them when issues have been identified about their presence. (Indeed, I can see that concern about the external links was first raised over three years ago. Although the editor doing so could have been more specific.)
Lastly, I am not a moderator, I'm just a Wikipedia editor the same as you, trying to follow guidelines and improve articles. Unfortunately, as co-author of the article you wish to link (and the editor who originally added it to this article) you have a conflict of interest. You are, no doubt, an authority on the subject and your input is very much welcomed. But Wikipedia is wary of people editing articles to include content about themselves or their work. But if you can summarise something about the "ISO 31000, the Gold Standard" article here, as the policy suggests, illustrating its significance to the standard itself, I'd be happy to work it into the article for you. --Escape Orbit (Talk) 14:53, 18 May 2025 (UTC)Reply
Thank you for your detailled reply and suggestions.
Here is a
🟨 Overview
The article discusses ISO 31000:2009, then about to be published, offering practical guidance for its adoption. It emphasizes the standard's role as a non-prescriptive, non-certifiable guideline designed to improve how organizations manage risk without the bureaucratic weight seen in frameworks like COSO ERMI.
✅ Positive Aspects of ISO 31000
Universality: Applicable to any organization or activity.
Consolidation: Intended to replace or align with various fragmented national standards.
Not prescriptive: No legal mandate or certification requirement.
Clear architecture: Built on three pillars:
Principles (why to manage risk),
Framework (how to embed it),
Process (how to execute it).
Educational & communicational value: Useful for training and stakeholder discussions.
Iterative process: Encourages continuous improvement.
⚠️ Cautions and Critical Observations
1. Standard vs. Guideline
Must be communicated clearly: ISO 31000 is a guideline, not a standard for certification of organisation.
2. Comparison with COSO II
ISO 31000 is more practical and user-friendly than the complex COSO ERM cube.
Avoid creating compliance-heavy systems like those seen with ISO 9000.
3. Avoid Creating a Parallel System
Risk management should be integrated into the existing management systems of the organisation, not run separately.
4. Use as a Benchmark, Not a Rulebook
It can help compare and enhance existing practices.
Should not be used to justify burdensome risk reporting.
5. Misuse by Certification Bodies
Be wary of organizations pushing for certification of organisations where none is intended.
6. Language and Definitions
Some ISO 31000 definitions are academically driven and may not be operationally useful.
Examples:
“Risk”: Defined as “effect of uncertainty on objectives.” Better understood as a deviation from expected outcomes.
“Risk management”: Defined broadly as “coordinated activities to direct and control an organization with regard to risk”—potentially misleading.
“Residual risk”: Recognized as a time-bound snapshot, not a static value.
💡 Practical Takeaways
Tailor ISO 31000 to your context. Don’t apply it blindly.
Use ISO 31000 to engage business units, not overwhelm them.
Be cautious of terminology traps (e.g., “risk owner,” “risk plan”)—translate to your organization’s language.
Exploit existing systems and data before turning to expensive GRC platforms.
Be alert to consultants and vendors using ISO 31000 as a sales hook.
🧭 Final Insight
The authors encourage critical thinking when adopting ISO 31000. The standard is a valuable, flexible tool—if understood as a guiding reference rather than a prescriptive rulebook or compliance instrument.
----------------------------
I am not sure that the summary should be integrated in the page, but rather, we should put a quotation from the article. Dali1010 (talk) 00:17, 25 May 2025 (UTC)Reply
For example, in the section "Criticism", we could add :
ISO 31000 has received various criticisms from academics and practitioners. As early as 2009, Alex Dali and Christopher Lajtha (link to article) were giving the following warnings:
  • Tailor ISO 31000 to your context. Don’t apply it blindly.
  • Use ISO 31000 to engage business units, not overwhelm them.
  • Be cautious of terminology traps (e.g., “risk treatment,” “risk plan”) — better is to translate terms to your organization’s language.
  • Exploit existing systems and data before turning to expensive risk software platforms.
  • Be alert to consultants and vendors using ISO 31000 as a sales hook.
The text can continue... It has been described as lacking solid conceptual foundations and containing potentially misleading language. Scholars have questioned the standard's practical utility and clarity, especially in complex organizational settings. Others point to a lack of integration with modern decision theory and formal risk analysis methodologies. The terminology used in the standard has been criticized for being ambiguous and inconsistently interpreted, or for its lack of solidness and misleading language..Some researchers argue that the drive for standardization may hinder innovation and adaptability in risk management practice. Additionally, a gap has been identified between the theoretical principles of ISO 31000 and how they are operationalized within organizations. Dali1010 (talk) 00:25, 25 May 2025 (UTC)Reply
The section "Criticism" could end as followed :
-------------------------------------------
There are more on going discussions about the content of the ISO 31000 standard in different LinkedIn groups, such as ISO 31000 Risk Management Standard (https://www.linkedin.com/groups/1834592/)
-------------------------------------------
This is not a link to any organisation for simply a largest discussion forum on the subject. Dali1010 (talk) 00:37, 25 May 2025 (UTC)Reply
--------------------
Another option is to include quotes from the article itself, such as
"It would be a mistake to use ISO 31000 as a tool for the creation of burdensome reporting on risk."
Meaning : This statement reflects the authors’ warning against misapplying ISO 31000 as a compliance-driven reporting mechanism. Instead, the guideline should be used to enhance decision-making and performance, not to inflate documentation requirements—a key message for organizations seeking value from their risk management efforts.
or
"Although ISO 31000 does not impose any compulsory compliance, it would be a mistake to overlook its usefulness as a generic reference."
This quote strikes at the core message: ISO 31000 is not a mandatory standard, but its value lies in its thoughtful application—not in blind adherence. It’s a reminder to risk professionals to critically engage with the standard, using it to improve existing practices rather than to create new bureaucratic burdens. Dali1010 (talk) 00:39, 25 May 2025 (UTC)Reply
---------------------------------
Another issue which I have faced is the inclusion of the worldmap which the G31000 Risk Institute has published in 2022 showing the number of countries adopting ISO 31000 as national risk management standard
Link : https://drive.google.com/file/d/1ap_fDQp1Wc6XrtBnBvFSgfaVN75xTeF4/view?usp=sharing Dali1010 (talk) 00:49, 25 May 2025 (UTC)Reply
The idea is to make something like this, citing the source of the G31000 Risk Institute
Thanks for your help in improving this page. Dali1010 (talk) 00:54, 25 May 2025 (UTC)Reply