NS-ISO 31000:2018 — Risk management, guidelines
The principles and process for enterprise risk management: identification, analysis, evaluation, treatment, monitoring and reporting. It is guidance and cannot be certified, but it is used as a reference in internal control and board reporting.
Register
- Designation
- NS-ISO 31000:2018
- Edition
- 2018
- Publisher
- Standard Norge
- Group
- Risk, compliance and continuity
- Area
- Finance and anti-money laundering
- Read date
- 2026-09-09
Standards are not statute. They are purchased documents from Standard Norge that parties agree to, or that regulations refer to. We carry the designation, edition and scope, never the text.
Official text
- Buy the standard from Standard NorgeNS-ISO 31000:2018
- Publisher: Standard Norge
Used together with
- Financial Institutions Act
LOV-2015-04-10-17In force: 2016-01-01Finanstilsynet
The Act regulates authorisation, ownership control, organisation, capital requirements, conduct of business and crisis management for banks, credit institutions, finance companies, insurers and pension undertakings.
Risk, compliance and continuity
- Compliance management systems, requirements with guidance
NS-ISO 37301:2021Standard Norge
The requirements for a compliance management system: mapping compliance obligations, roles and independence, training, a reporting channel, monitoring and reporting. It is the closest standard to what supervisory bodies mean by documented compliance.
- Anti-bribery management systems, requirements with guidance
NS-ISO 37001:2016Standard Norge
Measures against bribery: risk assessment, due diligence on business associates, gifts and hospitality, third-party controls and investigation. It is used alongside the customer due diligence duties of the Anti-Money Laundering Act in internationally exposed businesses.
- Requirements for risk assessments
NS 5814:2021Standard Norge
The Norwegian method for planning, conducting and documenting a risk assessment: purpose, scope, acceptance criteria, analysis and verifiable documentation. It is widely used in HSE work, emergency preparedness and public procurement.
- Business continuity management systems, requirements
NS-EN ISO 22301:2019Standard Norge
The requirements for continuity management: impact analysis, recovery times, continuity plans, exercises and review. Financial undertakings and public sector suppliers meet the same requirements again in supervisory rules on operational continuity and outsourcing.
Norwegian law
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.