Risk Framework · Enterprise Risk Management

ISO 31000 gives risk management its structure. XGRC® gives it a system.

ISO 31000 is a guideline for managing risk, not a certifiable management system — there is no audit to pass. XGRC® helps organisations adopt and embed the ISO 31000 risk management process, from establishing context through risk assessment, treatment, and ongoing monitoring and review.

Book a demo
The problem

Without a structured process, risk management becomes a compliance exercise.

When context, criteria, and treatment are not applied consistently, risk registers drift out of date and stop reflecting the organisation's actual exposure — which is exactly what the ISO 31000 process is designed to prevent.

Risk management run as an annual exercise rather than a continuous process

No consistent criteria for likelihood, impact, or risk appetite across business units

Risk treatment actions assigned but never checked for effectiveness

Risk reporting disconnected from real decision-making forums

The XGRC® approach

The ISO 31000 risk management process, in one system.

01

Establish the internal and external context and risk criteria

02

Identify risks across strategic, operational, financial and compliance categories

03

Analyse likelihood and consequence using a consistent scoring model

04

Evaluate risks against risk appetite and prioritise treatment

05

Define and assign risk treatment plans with clear ownership

06

Monitor, review and report on risk performance continuously

How it works

Built for risk owners, visible to the board.

  • Central risk register aligned to the ISO 31000 process
  • Configurable risk criteria and appetite thresholds
  • Risk treatment plans with owner and effectiveness tracking
  • Key risk indicator monitoring and escalation
  • Real-time dashboards and board-ready reporting

One connected view of risk

XGRC® structures risk identification, analysis, evaluation and treatment around the ISO 31000 process, and links every risk to its controls, actions and audit findings. The board gets real-time visibility of risk exposure without waiting for the next review cycle.

From manual to XGRC®

The same risk process, without the friction.

Manual approach
  • Risk management as an annual, point-in-time exercise
  • Inconsistent criteria across business units
  • Treatment actions never checked for effectiveness
  • Reporting disconnected from decision-making
XGRC® approach
  • Continuous risk identification and review
  • Consistent context, criteria and appetite thresholds
  • Treatment tracked through to verified effectiveness
  • Risk reporting embedded in governance forums
Free resource

ISO 31000 Risk Management Checklist

  • Principles and mandate
  • Framework design
  • Establishing the context
  • Risk assessment — identification, analysis and evaluation
  • Risk treatment
  • Monitoring, review, recording and reporting
PDF · ISO 31000:2018 aligned · v1.0
Standards and frameworks

Align risk management to the frameworks that matter.

  • ISO 31000
  • Risk Management
  • Risk Assessment
  • Risk Treatment
  • COSO ERM
  • King V
Scope of application

One platform across every stage of the risk management process.

  • Establishing context and risk criteria
  • Risk assessment (identification, analysis, evaluation)
  • Risk treatment and action tracking
  • Monitoring, review and reporting
Frequently asked

Common questions.

What is ISO 31000 risk management software?

ISO 31000 is a guideline for managing risk, not a certifiable standard, so there is no audit to pass. XGRC® software helps organisations adopt and embed the ISO 31000 process, from establishing context through risk assessment, treatment and ongoing review.

Does XGRC® apply consistent risk criteria across business units?

Yes. Risk criteria and appetite thresholds are configurable once and applied consistently, so likelihood and impact are scored the same way regardless of which business unit raises the risk.

Is risk treatment checked for effectiveness, not just assigned?

Yes. Risk treatment plans are tracked with owner and effectiveness monitoring, so a treatment is verified to have actually reduced the risk rather than assumed complete once assigned.

How does this connect to COSO ERM and King V?

The ISO 31000 process underpins COSO ERM and King V risk governance requirements, so the same risk register and reporting feed all three without maintaining separate risk frameworks.

See ISO 31000 as a structured, embedded risk process.

Book a demo to see how XGRC® turns the ISO 31000 risk management process — context, assessment, treatment and review — into one connected workflow.

Book a demo