Skip to main content
Category: GRC Frameworks

ISO Guide 73

Also known as: ISO Guide 73:2009, ISO/IEC Guide 73:2002, Risk management — Vocabulary
Simply put

ISO Guide 73 is a document published by the International Organization for Standardization (ISO) that sets out standard definitions of common terms used in risk management. Its purpose is to help people and organizations understand risk-related language in a consistent way. By providing a shared vocabulary, it supports clearer communication across different risk management standards and practices.

Formal definition

ISO Guide 73, first issued as ISO/IEC Guide 73:2002 and updated as ISO Guide 73:2009 (Risk management, Vocabulary), provides definitions of generic terms related to risk management to encourage a mutual and consistent understanding of, and a coherent approach to, the description of risk-related activities in standards. It is intended as a terminological reference for use in standards development and complements the risk management framework and principles set out in ISO 31000, which draws its defined terms from Guide 73. The vocabulary content of ISO Guide 73:2009 has subsequently been carried forward and superseded by ISO 31073:2022 (Risk management, Vocabulary); the Guide establishes terminology only and does not prescribe risk management processes, controls, or implementation requirements.

Why it matters

Risk management as a discipline spans many standards, sectors, and jurisdictions, and the same everyday words, "risk," "likelihood," "consequence," "risk treatment", can carry subtly different meanings in different contexts. ISO Guide 73 matters because it establishes a shared vocabulary intended to reduce that ambiguity, encouraging a mutual and consistent understanding of risk-related terms across standards. For organizations that operate under multiple frameworks or communicate with regulators, auditors, and business partners, this common terminology helps avoid the miscommunication that can arise when parties use the same word to mean different things.

The Guide is closely tied to the wider ISO risk management architecture. ISO 31000 draws its defined terms from Guide 73, so the two are designed to work together: Guide 73 supplies the vocabulary while ISO 31000 sets out the principles and framework for managing risk. Because it standardizes definitions rather than practices, Guide 73 underpins consistency in how risk concepts are expressed in other standards, supporting clearer cross-referencing and reducing the risk that terminology is redefined inconsistently from one document to another.

It is important to understand what Guide 73 does not do. It establishes terminology only and does not prescribe risk management processes, controls, or implementation requirements. Users seeking guidance on how to identify, assess, or treat risk should look to ISO 31000 or sector-specific standards; Guide 73 is a reference for the meaning of terms, not a manual for practice. Users should also note its status: the vocabulary content of ISO Guide 73:2009 has been carried forward and superseded by ISO 31073:2022 (Risk management, Vocabulary), so those citing current terminology should confirm which document applies.

Who it's relevant to

Standards developers and technical committees
Guide 73 was designed as a reference for use in developing standards, giving drafters a common set of risk management definitions to draw on. Using it helps ensure that terminology is applied consistently across related standards rather than being redefined document by document.
Risk managers and risk practitioners
Practitioners applying ISO 31000 or building enterprise or operational risk programs benefit from Guide 73 because ISO 31000 draws its defined terms from it. A shared vocabulary supports clearer internal communication and more precise risk documentation, though practitioners should look to ISO 31000 or sector standards for process guidance.
Compliance and governance professionals
Those responsible for policies, frameworks, and reporting can use the Guide's definitions, such as its definition of a risk management policy, to align internal language with recognized terminology. This can reduce ambiguity when communicating risk concepts to boards, regulators, and auditors.
Internal and external auditors
Assurance professionals reviewing an organization's risk management arrangements can reference standardized terminology to assess whether risk concepts are being used consistently. Note that Guide 73 defines terms only and does not set control or process requirements against which to audit.

Inside ISO Guide 73

Standardized risk vocabulary
ISO Guide 73 provides a common set of terms and definitions relating to the management of risk, intended to promote consistent understanding and usage across organizations, disciplines, and jurisdictions.
Definition of risk
The Guide expresses risk in terms of the effect of uncertainty on objectives, a formulation aligned with the approach taken in ISO 31000. This framing treats risk as encompassing both positive and negative deviations from objectives rather than negative outcomes alone.
Core risk management concepts
It defines foundational terms used throughout risk management practice, which may include concepts such as risk source, event, consequence, likelihood, and level of risk, providing reference definitions rather than implementation guidance.
Risk process terminology
The Guide covers vocabulary associated with the risk management process, addressing terms relating to risk assessment and its components, as well as risk treatment, so that practitioners describe these activities consistently.
Alignment with ISO 31000
ISO Guide 73, published by the International Organization for Standardization, is designed to be used alongside ISO 31000, the ISO standard on risk management, providing the shared terminology that supports that standard and related documents.

Common questions

Answers to the questions practitioners most commonly ask about ISO Guide 73.

Is ISO Guide 73 a standard that organizations can be certified against?
No. ISO Guide 73 is a vocabulary document that defines terms related to risk management; it does not set requirements, controls, or a management system against which an organization can be audited or certified. Certification relates to requirements-based standards, not to terminology guides. ISO Guide 73 is intended to promote consistent understanding and use of risk management terms across standards and practitioners.
Does ISO Guide 73 replace or override the definitions used in ISO 31000?
It does not override them; the two are intended to work together. ISO Guide 73 provides a common vocabulary that supports risk management standards, and ISO 31000 addresses principles and guidelines for managing risk. Where a specific standard restates or adapts a definition for its own context, that standard's usage governs within its scope. Practitioners should confirm which definition applies in the document they are working from.
How should we use ISO Guide 73 when drafting an internal risk management policy?
It is commonly used as a reference source to align the terminology in your policy with widely recognized definitions, which can reduce ambiguity across risk registers, reports, and committee discussions. Because it defines vocabulary rather than prescribing processes, you would still design the actual policy content, roles, and procedures separately, drawing on requirements or guidance standards appropriate to your jurisdiction, sector, and organization.
Can adopting ISO Guide 73 terminology help align teams that use different risk frameworks?
It can help by providing a shared baseline vocabulary, which may reduce misunderstandings when teams reference concepts such as risk, likelihood, or consequence differently. However, some frameworks define certain terms in their own way, so alignment is not automatic. Teams typically map their existing definitions against the guide and document any deliberate departures rather than assuming full equivalence.
Where does ISO Guide 73 fit relative to definitions in sector-specific or regulatory guidance?
ISO Guide 73 offers general-purpose risk management vocabulary, while sector-specific or regulatory guidance may use terms with narrower or legally defined meanings. Where a regulator or industry standard specifies its own definition, that definition normally takes precedence for compliance purposes within its scope. It is advisable to treat the guide as a general reference and to check for overriding definitions in the applicable regulatory or contractual context.
Should we cite ISO Guide 73 as authority for risk management processes or controls?
Citing it for process or control requirements would be a misuse, because the guide addresses terminology rather than how to establish, operate, or assure risk management activities. It is appropriate to cite it to support the meaning of a term, but process design, control requirements, and assurance expectations should reference requirements-based or guidance standards suited to your context. This entry does not cover implementation specifics, tooling, or legal advice.

Common misconceptions

ISO Guide 73 tells organizations how to manage risk.
The Guide is a vocabulary document that defines terms; it does not prescribe a risk management process, methods, or controls. Guidance on how to manage risk is addressed by ISO 31000 and other documents, not by the vocabulary itself.
Under ISO Guide 73, risk always means something negative.
Consistent with the ISO 31000 framing, risk is defined as the effect of uncertainty on objectives, and such an effect may be positive, negative, or both. Treating risk purely as a threat narrows the intended meaning.
Adopting the Guide's definitions is a compliance obligation.
ISO Guide 73 is a terminology reference, not a law or regulation. Whether an organization uses its definitions depends on internal choices and any standards it elects to follow; applicability and required practices vary by jurisdiction, sector, and organizational context.

Best practices

Use ISO Guide 73 as the shared terminology reference when adopting or aligning with ISO 31000, so that risk terms carry consistent meaning across policies, registers, and reports.
Adopt the 'effect of uncertainty on objectives' definition of risk deliberately, and confirm that stakeholders understand it can encompass positive as well as negative effects.
Reconcile any internally used risk terms with the Guide's definitions, and document explicitly where your organization's usage differs to avoid ambiguity.
Treat the Guide as vocabulary only, and pair it with ISO 31000 or other appropriate documents when you need process, method, or implementation guidance.
Verify how the terminology maps to other frameworks your organization uses, since definitions of similar terms can differ across sources, and note those differences rather than assuming equivalence.
Confirm the applicable edition and its exact wording directly from the published standard before relying on specific definitions in formal documentation.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.