ISO 31000 gives your organisation a framework for thinking about risk and then leaves the meeting without making a choice. I helped write the standard it descends from, so I say this as a participant, not a critic from the gallery. The framework describes conditions for deciding. It does not decide.

In 2015 I was in Rio while ISO 31000 was being revised. I had joined the AS/NZS 4360 committee in 1999, chaired it for a decade, and co-authored the 2004 edition that became a predecessor to the international standard. The proposal before us would have put organisational decision making at the centre. It was voted down. I saw the gap remain in the document.

That gap is why a risk manager looking for ISO 31000 decision making can open the standard before a board meeting and still be left without a way to choose. The standard has principles and process diagrams. The meeting has a market exit or a supplier failure to deal with. Those are different things.

ISO 31000 decision making is the use of a risk-governance standard to inform a decision, rather than a method for selecting an option when uncertainty remains.

ISO 31000 decision making starts after the decision is framed

ISO 31000 begins with objectives. That sounds unexceptionable until a group has to establish which objective applies to the call in front of it. A board may be asked to approve a plant closure, yet the paper does not say if the purpose is preserving cash, retaining capability, or meeting a date promised to a customer. The risk work starts moving before the decision has been framed.

I have watched this happen often. The group produces a register because it has been told to use the standard. It identifies possible events and rates them. It has still not stated the decision, who owns it, or what outcome the owners require. The resulting record may satisfy a process requirement; it cannot settle an argument that was never made explicit.

That is where ISO 31000 decision making needs a prior discipline. The field has accumulated more than 40 definitions of its central word, risk. The most familiar ISO wording refers to the effect of uncertainty on objectives. In his critique of that formulation, Terje Aven identified the problem plainly: objectives may themselves need to be developed through the assessment and decision process. A standard cannot assume settled objectives when the room is still deciding what it is trying to achieve.

The useful question is therefore not, "Have we applied ISO?" It is, "What decision are we making?" Once that is clear, uncertainty has a home. The difference between risk and uncertainty matters here because uncertainty belongs to a decision about the future, not to an isolated object that can be catalogued.

Name the decision your committee is making and the assumption it rests on before the standard review replaces both. Start the Walk →

ISO 31000 decision making does not choose between options

Comparison showing what ISO 31000 can govern versus what it does not supply: the choice and its key assumption
Governance structure cannot make the call.
Click to expand

A risk standard can require a process. It cannot tell a committee whether to retain a failing supplier for another six months or spend the money to replace it now. It cannot tell them what must be true for either choice to work. The judgment stays with the Deciders, as it should.

That limitation is not a defect hidden in the small print. ISO 31000 is deliberately generic. Carole Lalonde and Olivier Boiral found that a generic standard can become a rational ritual when it is not embedded in the work that people actually do. Their analysis of ISO 31000 does not say that standards are useless. It says the artefacts can give people a feeling of safety without changing the work that determines the outcome.

I chaired the Australian committee through the period when this confusion was becoming entrenched. The international standard talked about integration with decision making, while its separate process and associated documents made separation quite easy. A department could own the standard, prepare the report and take it to a meeting. The people in the meeting still had to decide, usually without a clear statement of what their preferred option rested on.

A 2018 pilot study of 149 health-and-safety informants reached a similar practical conclusion. Forty-two people contributed results. They saw ISO as a starting point and a supplement to existing practice, while also finding it vague and difficult to implement. One concern was that administration could consume the time needed for the real work. Pillay's account of the study describes a problem I have seen for years: a process can be complete on paper while the decision remains open.

This is why a risk register often becomes a record of anxieties rather than a basis for action. It records what somebody fears. It rarely records the assumption that makes a particular option worth pursuing, or the evidence that would make the group change its mind. The decision must be made visible before it can be properly tested. A decision record exists for that purpose.

The standard is useful when it governs the work

Use ISO 31000 as a common expectation for responsibility and review. It can make a board ask whether uncertainty has been considered, who owns the work, and when the position will be examined again. Those are useful disciplines, particularly where an organisation has many decisions being made in different places.

That value sits at the organisational level. Alison Olechowski and her colleagues surveyed 215 practitioners who completed the final part of their work on ISO principles in engineering and product development. Higher adherence was associated with better project outcomes. Their study of ISO 31000 principles points to better conditions for work, not to a formula that selects an option for a particular committee.

That is an important distinction. A standard can make it harder for a serious issue to be ignored. It can require a decision to be reviewed after new information arrives. It cannot provide the missing judgment when two credible options produce different consequences for the organisation.

The full guide to risk as uncertainty explains why I object to treating risk as a thing that can be managed apart from the choice being made. ISO has a proper place around the work. It becomes harmful when the organisation mistakes the surrounding apparatus for the decision itself.

Put a decision method beside the standard

A live decision needs a method that makes the choice visible and tests its basis. The Universal Decision-Making Method starts with Frame the decision and Develop options. It then requires people to Recognise assumptions. The group decides whether it has reached Sufficient certainty, then must Design monitoring after it commits.

That sequence gives ISO something useful to govern. The group can show the decision it made, the assumption carrying the most weight, and the condition that would cause it to reopen the call. A review date is then not merely a calendar entry. It has a purpose, because the group knows what it is watching for.

Consider the supplier decision. The risk team may have documented exposure to disruption. The Deciders still need to state the option they favour and the assumption that makes it sensible: perhaps that the current supplier can recover production by an agreed date. They can then decide if the evidence is sufficient to retain that supplier, or if the cost of replacing it is justified. Monitoring has a clear job because it tests that assumption.

Used this way, the standard has a proper role. It provides the organisation with discipline around ownership and review. The decision method does the work the standard leaves to the people in the room. That is why I would keep ISO where it improves governance, and use risk-based decision making where a consequential call must be made.

You could tick every ISO clause and still leave the meeting without a choice.

Work through your decision

No sign-up. Just pick your decision and start.


Grant Purdy is the co-author, with Roger Estall, of Deciding (2020), and the architect of the Universal Decision-Making Method.