SS-ISO 31000:2018 — Risk management, principles and guidelines
The principles, framework and process for managing risk in an organisation: context, risk identification, analysis, evaluation, treatment, communication and monitoring.
Register
- Designation
- SS-ISO 31000:2018
- Edition
- 2018
- Publisher
- Svenska institutet för standarder (SIS)
- Group
- Risk, compliance and continuity
- Area
- Company law, tax and finance
- Read date
- 2026-09-09
Standards are not statute. They are purchased documents from SIS that parties agree to, or that regulations refer to. We carry the designation, edition and scope, never the text.
Official text
Buy the standard from SISSS-ISO 31000:2018
Used together with
- ABL · SFS 2005:551
Risk, compliance and continuity
- Guidelines for auditing management systems
SS-EN ISO 19011:2018Svenska institutet för standarder (SIS)
Guidance on how internal and external audits of management systems are planned, performed, reported and followed up, and what competence the auditor needs. Used to make internal control auditable.
- Business continuity management systems, requirements
SS-EN ISO 22301:2019Svenska institutet för standarder (SIS)
The requirements for continuity management: impact analysis, recovery times, continuity plans, exercises and review. Financial undertakings and public sector suppliers meet the same requirements again in supervisory rules on operations and outsourcing.
- Anti-bribery management systems, requirements
SS-ISO 37001:2016Svenska institutet för standarder (SIS)
The requirements for work against bribery and corruption: risk assessment, control of gifts and hospitality, due diligence on business partners, a reporting channel and investigation.
- Compliance management systems, requirements
SS-ISO 37301:2021Svenska institutet för standarder (SIS)
The requirements for a compliance management system: identification of obligations, accountability, routines, training, reporting and follow-up of deviations. Used to make compliance documentable in supervision and procurement.
- Information security incident management, principles
SS-EN ISO/IEC 27035-1:2023Svenska institutet för standarder (SIS)
The principles of incident management: preparation, detection, assessment, response and lessons learned. Used alongside the duty to report personal data breaches and incidents in essential services.
Swedish law
Next step
Three ways to put the register to work in your own practice.
Start with your task
Litigation
Find support in a judgment
Search guiding decisions, see what became final and follow changes in the law.
In-house, deals
Map the rules in a transaction
Move from theme to act and on to the article that carries the duty.
Compliance
Assess the risk in a process
Risk scoring per legal area, with the sources behind every score.