Skip to main content
Category: GRC Frameworks

ISO 31073

Also known as: ISO 31073:2022, Risk management — Vocabulary
Simply put

ISO 31073 is an international standard, published by the International Organization for Standardization (ISO), that defines a common vocabulary of generic terms used in the management of risks faced by organizations. Its purpose is to help people share a consistent understanding of risk management concepts and terms. It provides definitions rather than requirements or implementation guidance.

Formal definition

ISO 31073:2022, titled "Risk management, Vocabulary," is a standard issued by the International Organization for Standardization that establishes generic terminology and definitions to support a common understanding of concepts and terms relating to the management of risk. It organizes terms including those related to the risk management process. Certain entries carry notes indicating, for example, that legal or regulatory requirements can limit, prohibit, or mandate specific risk treatment options such as risk sharing. ISO 31073:2022 is understood to succeed the earlier ISO Guide 73:2009, which similarly provided definitions of generic risk management terms; practitioners should confirm the current status and edition, as terminology sources may be updated. The standard is a vocabulary reference and does not itself specify a risk management framework or process, which are addressed in other documents.

Why it matters

Consistent terminology is a foundational condition for effective risk management. When practitioners, executives, auditors, and regulators use terms such as risk, risk treatment, or risk sharing to mean different things, risk registers, board reporting, and control assessments can become inconsistent or misleading. ISO 31073 addresses this by providing a common vocabulary of generic risk management terms, helping organizations develop a shared understanding of concepts across functions and, where adopted, across organizational boundaries.

Who it's relevant to

Risk managers and risk professionals
Those responsible for building and maintaining risk registers, risk reporting, and risk management documentation can use ISO 31073 to anchor terminology, promoting consistency in how concepts are described across the organization and over time.
Governance and compliance professionals
Governance and compliance specialists may reference the standard's definitions to align internal policies and communications with widely recognized terms, while noting that ISO 31073 is a vocabulary source and does not address the substantive legal or regulatory obligations that apply in a given jurisdiction.
Internal auditors and assurance providers
Assurance functions can draw on shared definitions to reduce ambiguity when evaluating how management describes and treats risk. The standard supports clearer communication but does not substitute for the frameworks, controls, or requirements that assurance activities assess.
Standards and framework users
Organizations applying other risk management standards or frameworks may use ISO 31073 as a companion vocabulary reference to interpret terms consistently, confirming the current edition before relying on specific definitions.

Inside ISO 31073

Risk management vocabulary standard
ISO 31073 is an International Organization for Standardization (ISO) document that provides a standardized vocabulary for risk management. It collects and defines the terms used across the ISO risk management landscape so that practitioners share a common language.
Defined terms and definitions
The standard sets out terms and their agreed definitions, typically covering concepts such as risk, risk source, event, consequence, likelihood, risk assessment, risk treatment, and related terminology. Its purpose is terminological consistency rather than prescribing a process.
Relationship to ISO 31000
ISO 31073 supports ISO 31000, the ISO standard providing principles and guidelines for risk management. Where ISO 31000 describes the framework and process, ISO 31073 focuses on defining the vocabulary those documents use. It succeeded the earlier ISO Guide 73 in the role of vocabulary reference.
Non-prescriptive, guidance nature
As a vocabulary standard, it does not impose a management system, controls, or certifiable requirements. It is a reference resource intended to promote consistent understanding and communication across organizations, sectors, and jurisdictions.

Common questions

Answers to the questions practitioners most commonly ask about ISO 31073.

Is ISO 31073 a certifiable management system standard like ISO 37301?
No. ISO 31073 is a vocabulary standard that provides terminology relating to risk management; it is not a requirements standard against which an organization can be certified. Certifiable management system standards contain auditable requirements (often signalled by clauses using terms such as 'shall'), whereas a vocabulary standard supplies defined terms to promote consistent usage across related documents. Organizations seeking certification would look to a standard structured around requirements rather than to a terminology reference.
Does ISO 31073 replace ISO 31000 or set out how to implement risk management?
No. ISO 31073 addresses vocabulary rather than process, principles, or framework. It does not prescribe how to identify, assess, or treat risk, and it does not supersede guidance-oriented documents. Its role is to define terms so that different parties use them consistently; questions of implementation, framework design, or process fall outside its scope.
How can an organization make practical use of ISO 31073 in its risk documentation?
Organizations commonly use a terminology standard as a reference point when drafting risk policies, procedures, registers, and reporting templates, so that terms such as risk, likelihood, and risk treatment are applied consistently. Referencing an agreed vocabulary can reduce ambiguity when multiple teams, functions, or external parties exchange risk information. The standard itself does not dictate document structure or content; it supplies definitions that an organization may choose to adopt.
Who within an organization typically references ISO 31073?
Those responsible for developing or maintaining risk management frameworks, policies, and training materials may reference it to align terminology, including risk managers, second line risk functions, and internal audit when assessing consistency of usage. Because it is a vocabulary reference rather than a set of requirements, its use is generally a matter of internal choice rather than an obligation, and the extent of adoption varies by organization.
Can adopting a common vocabulary from ISO 31073 improve communication with auditors and regulators?
Consistent terminology can support clearer communication with assurance providers and, where relevant, regulators, because shared definitions reduce the risk of misinterpreting terms such as inherent risk, residual risk, or risk appetite. However, using an agreed vocabulary does not by itself demonstrate the effectiveness of a risk management framework or satisfy any specific regulatory obligation, which depend on jurisdiction, sector, and applicable requirements. Terminology alignment is a supporting practice, not evidence of control effectiveness.
How does ISO 31073 relate to other risk management documents an organization may already use?
A vocabulary standard is intended to complement, not compete with, principles- or process-oriented risk management documents by supplying the defined terms those documents rely on. Organizations that maintain their own glossaries may map internal terms to the standard's definitions to preserve consistency. Where internal or sector-specific usage differs, it is advisable to note the intended meaning explicitly, since terminology can vary across frameworks, jurisdictions, and industries.

Common misconceptions

ISO 31073 is a certifiable management system standard that organizations can be audited against.
ISO 31073 is a vocabulary standard providing definitions of terms. It does not specify requirements and is not, by itself, a basis for certification. Certifiable requirements would come from other types of standards, not a terminology document.
ISO 31073 replaces ISO 31000 as the standard describing how to manage risk.
The two serve different roles. ISO 31000 provides principles and guidelines for the risk management process and framework, while ISO 31073 provides the shared vocabulary. They are complementary; the vocabulary standard supports rather than supersedes the guidance standard.
The definitions in ISO 31073 are legal definitions that override how regulators or laws define risk terms.
ISO 31073 offers standardized terminology for voluntary use in risk management practice. It does not carry legal force, and specific statutory or regulatory definitions in a given jurisdiction or sector may differ and would take precedence in their own context.

Best practices

Use ISO 31073 as a shared reference to align terminology across risk registers, policies, and reporting so that terms such as risk, likelihood, and consequence are understood consistently by stakeholders.
Read ISO 31073 alongside ISO 31000 rather than in isolation, treating the vocabulary standard as support for the process and framework guidance.
When adopting the standard's definitions internally, document any organization-specific adaptations and note where regulatory or contractual definitions differ from the ISO terminology.
Confirm the current edition and exact wording of definitions directly from the official ISO publication before relying on them, rather than reproducing terms from secondary summaries.
Avoid presenting adherence to ISO 31073 vocabulary as evidence of a mature or certified risk management program; pair terminology consistency with substantive framework, process, and control work.
Where terms span governance, risk, and compliance functions, clarify in internal documentation which pillar a given definition is being applied to, since consistent vocabulary does not by itself resolve pillar-specific responsibilities.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps