An Overview of ISO 31000: 2018 Risk Management and Role of Chartered Accountants
“In the last decade, there has been a major surge in the interest towards Risk Management. This is due to the change in management’s attitude towards Risk Management. Risk Management which earlier limited itself to the middle and lower-level management has now risen to the strategic level management with an emphasis on the Tone at the Top. This momentum has initiated the need for the change in the Standards and Frameworks related to Risk Management. Most of the standard-setting organisations have updated their standards with the changing needs. Read on to know more…”
Introduction & Background: The Evolution of ISO 31000
ISO 31000: 2018 Risk Management is a prominent standard that was updated in February 2018, following the update of the COSO Enterprise Risk Management – Integrated Framework in September 2017. This article provides a comprehensive understanding of ISO 31000: 2018 Risk Management and the expanding role of Chartered Accountants in its implementation.
The International Organisation for Standardisation (ISO) is an international standard-setting body composed of representatives from various national standards organisations. This organisation promotes worldwide proprietary, industrial, and commercial standards. The Technical Management Board of ISO is responsible for more than 250 technical committees, which develop ISO standards taking into consideration global industry requirements.
In November 2009, ISO released the generic standard on Risk Management titled ISO 31000:2009 Risk Management – Principles and Guidelines. The objective of this standard was to replace the multitude of differing regional, industry-specific, and subject-specific standards with a single, universally applicable framework. It was designed for use by any public, private, or community enterprise, association, group, or individual, across any type or nature of risk and at any stage of an organisation’s life cycle.
Drawbacks of ISO 31000:2009 and Key Improvements in ISO 31000:2018
Over a period of operational experience, ISO identified several critical drawbacks in the erstwhile 2009 standard:
Drawbacks Identified in ISO 31000:2009:
- A very minimal integration with corporate control systems, including strategic planning and management control;
- The non-integrated approach of Risk Management with other functional disciplines of the organisation;
- Absence of structured risk taxonomies; and
- Failure to offer practical implementation tools for Risk Managers on the ground.
Owing to these limitations and the rapidly transforming global business environment, ISO issued ISO 31000:2018 Risk Management with five key improvement areas:
Key Improvements in ISO 31000:2018:
- Leadership and Governance: The importance and leadership of top management are prominently highlighted. Managing risk is recognized as an inseparable part of governance and leadership, fundamental to how the organisation is managed at all levels.
- Holistic Integration: Comprehensive integration of risk management with all organisational functions, starting directly with board governance.
- Refinement of Core Principles: Thorough review and modernization of the foundational principles of risk management.
- Iterative Nature: Greater emphasis on the iterative nature of risk management – documenting new experiences, knowledge, and analysis leading to revisions of process elements, actions, and controls at each stage.
- Open Systems Model: Streamlining of content with a focused emphasis on sustaining an open systems model to fit multiple needs and operational contexts.
Tripartite Architecture of ISO 31000:2018
ISO 31000:2018 divides risk management into three interconnected pillars:
The 8 Foundational Principles of Risk Management
As defined in the standard, the Principles are the bedrock foundation for managing risk. They serve as guiding factors that enable an organisation to achieve its objectives.
Core Principle: Value Creation and Protection
“Value creation and protection” sits at the very center of the standard. All other principles are bounded together with this core principle. Risk management not only creates value for internal stakeholders (management and shareholders seeking stake appreciation) but also protects and creates value for external stakeholders, including customers purchasing products and services.
Effective risk management requires all eight supporting principles to operate harmoniously:
a. Integrated
Risk management cannot work in silos; it is not solely the responsibility of the risk team. In contrast to traditional siloed approaches, ISO 31000 mandates that risk management is an integral part of all organisational activities, across all functions and all management levels.
b. Structured and Comprehensive
Risk management must be a structured, methodical approach rather than an ad-hoc, reactive exercise. It must be comprehensive enough to cover all organizational activities, producing consistent, comparable, and desirable risk management outcomes.
c. Customised
The framework rejects any ‘one size fits all’ approach. It must be tailored to the nature, scale, complexity, and strategic objectives of the entity, properly aligning with both internal and external operational operating contexts.
d. Inclusive
Appropriate and timely involvement of stakeholders ensures that diverse views, expertise, and perceptions are collated. Inclusivity fosters organizational risk awareness and results in well-informed risk management decisions.
e. Dynamic
Risks can emerge, evolve, or diminish as an organisation’s context changes. Risk management anticipates, detects, acknowledges, and responds to new events and environmental shifts in a proactive and timely manner.
f. Best Available Information
Inputs are based on historical data, current operations, and future projections. The best available information must explicitly consider limitations, uncertainties, and cost-benefit trade-offs regarding data accuracy and timeliness.
g. Human and Cultural Factors
Human behavior and organizational culture significantly influence all aspects of risk management. Because humans manage risk, the discipline must be actively championed by the ‘Tone at the Top’ and permeate every level of management.
h. Continual Improvement
Risk management is never a one-time exercise; it is continuous throughout an enterprise’s life cycle. Ongoing learning and experience drive systematic, incremental improvements in the overall risk architecture over time.
The ISO 31000:2018 Risk Management Framework
The framework assists organisations in integrating risk management into significant activities and business functions. Developing the framework encompasses leadership commitment, integration, design, implementation, evaluation, and continual improvement:
1. Leadership and Commitment
The critical success factor for any implementation is the commitment of leadership. Top management and oversight bodies must demonstrate leadership by integrating risk management across all functions, creating a positive tone at the top, formulating risk policies, allocating adequate resources (personnel, tools, training), and assigning clear authority and responsibility to oversight bodies.
2. Integration
Risk management must be deeply woven into the organizational fabric. Practice cannot be restricted to an isolated oversight team; every individual across all levels and operational functions shares responsibility for managing risk within their domain, tailored to the structure and culture of the enterprise.
3. Design of the Framework
Designing the framework requires five foundational activities:
- Understanding the organisation and its context: Evaluating external factors (social, cultural, political, legal, regulatory, financial, technological, economic, environmental, international to local) and internal factors (vision, mission, values, culture, strategies, policies, standards, contractual commitments).
- Articulating risk management commitment: Board and senior management establishing explicit risk policies and cascading the tone at the top through clear communication.
- Assigning roles, authorities, responsibilities & accountabilities: Entrusting defined risk duties to specific personnel across all levels of the organisation.
- Allocating resources: Deploying adequate human capital, specialized skills, methodologies, enterprise risk tools, and professional development programs.
- Establishing communication and consultation: Building robust two-way channels for collecting, synthesizing, and disseminating timely risk data to shape strategic decisions.
4. Implementation, 5. Evaluation & 6. Improvement
- Implementation: Executed according to a structured roadmap specifying timelines and resource allocations, securing full stakeholder awareness and continuous monitoring.
- Evaluation: Periodic measurement of framework effectiveness, efficiency, and alignment against established organizational goals.
- Continual Improvement: Ongoing adaptation of the framework to address internal and external shifts, enhancing suitability, adequacy, and maturity over time.
The Risk Management Process
The ISO 31000:2018 process involves a set of systematic activities. While presented sequentially in diagrams, in actual practice the process is deeply iterative:
1. Communication and Consultation
Carried out across all stages with internal and external stakeholders to foster shared understanding, bring different technical expertise together, and provide robust risk oversight for decision-makers.
2. Scope, Context, and Criteria
- Scope: Defining the boundaries and applicability of risk activities (strategic, operational, programme, or project level).
- Context: Establishing the external and internal operating environment specific to the activity.
- Defining Risk Criteria: Documenting the amount and type of risk an enterprise may or may not take (risk appetite/tolerance), considering positive and negative consequences, periodically updated.
3. Risk Assessment (The Tripartite Engine)
Risk assessment encompasses three interrelated subprocesses:
- Risk Identification: Identifying new, emerging, and changing risks that could jeopardize strategic objectives. Considers tangible/intangible sources, causes, events, threats, opportunities, vulnerabilities, and capabilities.
- Risk Analysis: Comprehending the severity, nature, characteristics, consequences, probabilities, scenarios, and control effectiveness using qualitative, quantitative, or hybrid techniques.
- Risk Evaluation: Comparing analysis outcomes against established risk criteria to prioritize actions and support treatment decisions, followed by management validation.
4. Risk Treatment (Selection & Implementation)
Addressing evaluated risks through cost-benefit analysis (weighing socio-economic benefits against implementation costs). The standard enumerates six treatment options:
Post-selection, formal Risk Treatment Plans are prepared specifying implementation sequencing, assigned responsibilities, deadlines, and integration into business plans.
5. Monitoring and Review
Because risk treatments may produce unintended consequences or degrade over time, ongoing monitoring assures and improves process quality, providing feedback across planning, data gathering, and analysis stages.
6. Recording and Reporting
Documenting and communicating outcomes across all levels of management to enhance dialogue with oversight bodies. Reporting mechanisms are customized per user tier, taking into consideration frequency, timeliness, and administrative cost.
Indian Statutory Mandates: SEBI Clause 49 & Companies Act, 2013
Unlike other developed nations, India had no comprehensive legislation promoting risk management until the advent of the Companies Act, 2013. The pioneering attempt was spearheaded by SEBI through Clause 49 of the Listing Agreement, formulated on the recommendations of the Kumar Mangalam Birla Committee and the Narayana Murthy Committee, taking effect from 31st December 2005.
Key Risk Management Provisions under SEBI Clause 49:
- Independent Directors’ Duty: Responsibility of Independent Directors to periodically review risk and compliance reports arranged by the company along with remediation steps.
- Disclosure of Procedures: Mandatory disclosure of risk management procedures, specifically highlighting fraud risks including third-party transactions and contingent liabilities.
- Audit Committee Oversight: Reports concerning legal compliance and risk management are subject to mandatory review by the Audit Committee.
- Board Information Systems: Management must establish procedures to inform corporate directors regarding risk assessment and minimization initiatives within a predefined framework.
- Compliance Officer Certification: Management must submit a quarterly report certified by the Compliance Officer to the Board articulating business risks and mitigation measures for board attestation.
The Companies Act, 2013: Statutory Game-Changers
Risk management received legislative teeth under the Companies Act, 2013 through two pivotal statutory provisions:
“There shall be attached to (Financial) statements laid before a company in general meeting, a report by its Board of Directors, which shall include — (n) a statement indicating development and implementation of a risk management policy for the company including identification therein of elements of risk, if any, which in the opinion of the Board may threaten the existence of the company.”
“Every Audit Committee shall act in accordance with the terms of reference specified in writing by the Board which shall, inter alia, include, — (vii) evaluation of internal financial controls and risk management systems.”
Significantly, the Companies Act makes the development and implementation of risk policies mandatory, but is silent on the specific standard or framework to use, leaving the selection to the discretion of management.
Professional Horizon for Chartered Accountants & ICAI Vision
Chartered Accountants are trusted advisors providing consulting and leadership services. Historically focused on Auditing, Taxation, and Accounting, CAs have expanded rapidly into strategic advisory services – preeminently in Enterprise Risk Management. As outward-looking risk experts, CAs possess the acumen to transform risk into strategic advantage.
Key Engagement Avenues for Chartered Accountants:
- Outsourced Risk Management Services: Delivering complete, end-to-end risk management activities for entities that do not maintain large dedicated internal departments.
- In-house Risk Team Leadership: Guiding management in architecting and tailoring suitable frameworks (such as ISO 31000:2018 or COSO) to organizational scale and culture.
- Process Execution & Facilitation: Supporting all operational stages: communicating, defining context/criteria, conducting risk assessments (identification, analysis, evaluation), implementing treatments, and structuring board-level reporting.
- Internal Financial Controls (IFC) & Audit Committee Support: Assisting Audit Committees in performing rigorous evaluations of internal financial controls and risk systems mandated by Section 177.
Our visionary institute, ICAI, had already envisaged these changing market demands by incorporating Risk Management as a dedicated subject in the Chartered Accountancy curriculum, equipping members with world-class theoretical and practical competencies.
Conclusion
Business success fundamentally demands intelligent risk-taking and seizing emerging opportunities. Modern risk management must move beyond mere hazard mitigation to embrace effective opportunity management that drives sustained value creation and value preservation over time.
By aligning with ISO 31000:2018 and meeting the statutory mandates of the Companies Act, organisations can construct resilient risk architectures. For Chartered Accountants, this paradigm shift unlocks an unprecedented professional horizon to deliver forward-looking, high-value advisory services to corporate India.
Risk management is not a constraint on enterprise; it is the cornerstone of sustainable governance and strategic leadership, empowering organizations to protect assets, seize opportunities, and maximize value creation.