simpl.
General / Cross-sector 16 items

Enterprise Risk Assessment (ISO 31000)

A structured risk assessment following the ISO 31000 process of identification, analysis, evaluation, and treatment.

ISO 31000

Free PDF · enter your email to download.

Scope, Context & Criteria

  • Is the scope and objective of the risk assessment defined? *
  • Are internal and external context factors identified? *
  • Are risk criteria (likelihood/consequence scales and tolerance) defined? *

Risk Identification

  • Have risks and their sources been systematically identified? *
  • Are relevant stakeholders engaged in identifying risks? *
  • Are risks recorded in a risk register? *

Risk Analysis

  • Is each risk analyzed for likelihood and consequence? *
  • Are existing controls and their effectiveness considered? *
  • Is the analysis method (qualitative/quantitative) documented? *

Risk Evaluation

  • Are analyzed risks compared against risk criteria to prioritize? *
  • Are decisions on which risks need treatment documented? *
  • Overall residual risk rating: *

Treatment & Monitoring

  • Are treatment options selected and owners assigned for each priority risk? *
  • Is a treatment plan with actions and timelines documented? *
  • Are risks monitored and the register reviewed on a defined cadence? *
  • Assessor sign-off: *

Download the full Enterprise Risk Assessment (ISO 31000) checklist

Get it as a clean, printable PDF — free.