ISO 31073
ISO 31073 is an international standard, published by the International Organization for Standardization (ISO), that defines a common vocabulary of generic terms used in the management of risks faced by organizations. Its purpose is to help people share a consistent understanding of risk management concepts and terms. It provides definitions rather than requirements or implementation guidance.
ISO 31073:2022, titled "Risk management, Vocabulary," is a standard issued by the International Organization for Standardization that establishes generic terminology and definitions to support a common understanding of concepts and terms relating to the management of risk. It organizes terms including those related to the risk management process. Certain entries carry notes indicating, for example, that legal or regulatory requirements can limit, prohibit, or mandate specific risk treatment options such as risk sharing. ISO 31073:2022 is understood to succeed the earlier ISO Guide 73:2009, which similarly provided definitions of generic risk management terms; practitioners should confirm the current status and edition, as terminology sources may be updated. The standard is a vocabulary reference and does not itself specify a risk management framework or process, which are addressed in other documents.
Why it matters
Consistent terminology is a foundational condition for effective risk management. When practitioners, executives, auditors, and regulators use terms such as risk, risk treatment, or risk sharing to mean different things, risk registers, board reporting, and control assessments can become inconsistent or misleading. ISO 31073 addresses this by providing a common vocabulary of generic risk management terms, helping organizations develop a shared understanding of concepts across functions and, where adopted, across organizational boundaries.
Who it's relevant to
Inside ISO 31073
Common questions
Answers to the questions practitioners most commonly ask about ISO 31073.
