General / Cross-sector 16 items
Enterprise Risk Assessment (ISO 31000)
A structured risk assessment following the ISO 31000 process of identification, analysis, evaluation, and treatment.
ISO 31000
Free PDF · enter your email to download.
Scope, Context & Criteria
- Is the scope and objective of the risk assessment defined? *
- Are internal and external context factors identified? *
- Are risk criteria (likelihood/consequence scales and tolerance) defined? *
Risk Identification
- Have risks and their sources been systematically identified? *
- Are relevant stakeholders engaged in identifying risks? *
- Are risks recorded in a risk register? *
Risk Analysis
- Is each risk analyzed for likelihood and consequence? *
- Are existing controls and their effectiveness considered? *
- Is the analysis method (qualitative/quantitative) documented? *
Risk Evaluation
- Are analyzed risks compared against risk criteria to prioritize? *
- Are decisions on which risks need treatment documented? *
- Overall residual risk rating: *
Treatment & Monitoring
- Are treatment options selected and owners assigned for each priority risk? *
- Is a treatment plan with actions and timelines documented? *
- Are risks monitored and the register reviewed on a defined cadence? *
- Assessor sign-off: *
Download the full Enterprise Risk Assessment (ISO 31000) checklist
Get it as a clean, printable PDF — free.
