ISO Guide 73
ISO Guide 73 is a document published by the International Organization for Standardization (ISO) that sets out standard definitions of common terms used in risk management. Its purpose is to help people and organizations understand risk-related language in a consistent way. By providing a shared vocabulary, it supports clearer communication across different risk management standards and practices.
ISO Guide 73, first issued as ISO/IEC Guide 73:2002 and updated as ISO Guide 73:2009 (Risk management, Vocabulary), provides definitions of generic terms related to risk management to encourage a mutual and consistent understanding of, and a coherent approach to, the description of risk-related activities in standards. It is intended as a terminological reference for use in standards development and complements the risk management framework and principles set out in ISO 31000, which draws its defined terms from Guide 73. The vocabulary content of ISO Guide 73:2009 has subsequently been carried forward and superseded by ISO 31073:2022 (Risk management, Vocabulary); the Guide establishes terminology only and does not prescribe risk management processes, controls, or implementation requirements.
Why it matters
Risk management as a discipline spans many standards, sectors, and jurisdictions, and the same everyday words, "risk," "likelihood," "consequence," "risk treatment", can carry subtly different meanings in different contexts. ISO Guide 73 matters because it establishes a shared vocabulary intended to reduce that ambiguity, encouraging a mutual and consistent understanding of risk-related terms across standards. For organizations that operate under multiple frameworks or communicate with regulators, auditors, and business partners, this common terminology helps avoid the miscommunication that can arise when parties use the same word to mean different things.
The Guide is closely tied to the wider ISO risk management architecture. ISO 31000 draws its defined terms from Guide 73, so the two are designed to work together: Guide 73 supplies the vocabulary while ISO 31000 sets out the principles and framework for managing risk. Because it standardizes definitions rather than practices, Guide 73 underpins consistency in how risk concepts are expressed in other standards, supporting clearer cross-referencing and reducing the risk that terminology is redefined inconsistently from one document to another.
It is important to understand what Guide 73 does not do. It establishes terminology only and does not prescribe risk management processes, controls, or implementation requirements. Users seeking guidance on how to identify, assess, or treat risk should look to ISO 31000 or sector-specific standards; Guide 73 is a reference for the meaning of terms, not a manual for practice. Users should also note its status: the vocabulary content of ISO Guide 73:2009 has been carried forward and superseded by ISO 31073:2022 (Risk management, Vocabulary), so those citing current terminology should confirm which document applies.
Who it's relevant to
Inside ISO Guide 73
Common questions
Answers to the questions practitioners most commonly ask about ISO Guide 73.
