Introduce compliance risk management according to ISO 31000: From a mission statement to an audit-proof risk matrix
ISO 31000:2018 is the international guide for risk management and has been referenced in ISO 37301:2021 (compliance management) since the key framework was updated. This guide takes you step by step through the introduction in a compliance context.
ISO 31000:2018 is the international guide for risk management. Unlike ISO 9001 or ISO 27001, ISO 31000 is not a certifiable standard, but rather a framework. It is the reference architecture for ISO 37301:2021 (compliance management systems), ISO/IEC 27005 (information security risk management) and numerous industry-specific standards. Anyone who sets up compliance risk management today cannot ignore ISO 31000.
The operational impact only develops through the integration with national obligations. Section 130 OWiG (breach of duty of supervision) requires management to take the supervisory measures necessary to prevent breaches of duty. Section 91 (2) AktG requires the board of directors to have a monitoring system for the early identification of risks that threaten the continued existence of the company. This guide shows how you can introduce ISO 31000:2018 as compliance risk management in an audit-proof manner and anchor it in the appointment certificate, reporting line and audit templates.
Key Takeaways
- ISO 31000:2018 provides the framework, ISO 37301:2021 the compliance-specific specification, Section 130 OWiG the national obligation.
- Risk management is a management task, not a staff task. Responsibility can be delegated, but not given up.
- A risk matrix without documented methodology, versioning and reporting lines does not stand up to scrutiny.
What ISO 31000:2018 does and what it doesn't do
ISO 31000:2018 was published in February 2018 as a successor to the 2009 version. It is a guideline (Guidance Standard), not a requirement standard. It is not certifiable. It provides eight principles, a framework and a process, which together structure risk management.
The eight principles (Section 4) are: integrated, structured and comprehensive, adapted, inclusive, dynamic, best available information, human and cultural factors, continuous improvement. They replace the eleven principles of the previous version and are the heart of the standard.
The framework (Section 5) follows a Plan-Do-Check-Act cycle with leadership and engagement at its core. The process (Section 6) describes scope, risk assessment (identification, analysis, evaluation), risk treatment, monitoring and communication.
ISO 31000 is not a step-by-step guide. It is a frame of reference that must be specified in specific sectors. ISO 37301 for compliance, ISO/IEC 27005 for IT security, ISO 22301 for business continuity use ISO 31000 as the architecture.
CIVAC models ISO 31000 as a workspace structure in which the Compliance Officer and the risk owner work together. Audit templates, risk registers and reporting lines are all in one system.
Anyone who wants to introduce ISO 31000 as a certifiable standard is misunderstanding it. Anyone who uses it as an architectural reference builds the basis for ISO 37301, ISO 27001 and industry-specific requirements.
Interlocking with ISO 37301 and § 130 OWiG
ISO 37301:2021 replaces ISO 19600 and is the certifiable standard for compliance management systems. Section 4.6 requires a compliance risk analysis, Section 6 requires risk-based planning, Section 9 requires an assessment of effectiveness. ISO 31000 provides the methodological basis.
§ 130 OWiG sanctions the violation of the supervisory obligation in companies with fines of up to 10 million euros for legal entities (§ 30 OWiG). The duty of supervision includes the selection, instruction and supervision of employees. Documented compliance risk management is the central relief in fine proceedings.
§ 91 Para. 2 AktG requires the board of directors to implement appropriate risk management for the early identification of risks that threaten the continued existence. The Federal Court of Justice has made it clear in several judgments that this also applies analogously to GmbH managing directors via Section 43 GmbHG.
FCPA (USA), UK Bribery Act 2010 (UK) and the Sapin II Act (France) additionally require risk-based compliance management for internationally active companies. ISO 31000 plus ISO 37301 meet the methodological expectations of these regimes.
CIVAC manages compliance risk management as a workspace with a documented reporting line between the compliance officer, management and supervisory body. The appointment certificate, signed, filed, verifiable.
Others run compliance like a filing cabinet. We run it like software. Anyone who only sets up risk management for ISO audits will miss out on the OWiG relief. The auditor calls, the evidence is ready.
Step 1: Define the scope and framework conditions
The first step according to ISO 31000 Section 5.4 is to determine the scope. Which units, processes, regions and risk types fall under compliance risk management. The answer depends on the company structure, regulatory environment and existing subsystems.
Typical scope definitions distinguish between mandatory risks (data protection, IT security, money laundering prevention, taxes, occupational safety, supply chain, environment) and market-related risks (reputation, contractual risks). Compliance risk management focuses on mandatory risks plus reputational risks from compliance violations.
The framework conditions include the internal context (strategy, values, structures, resources) and the external context (regulation, competition, stakeholders). Both are recorded in context statement documentation, updated annually and reported to management.
Risk criteria (Section 6.3.4) determine the threshold values above which a risk is considered material and which treatment is required. They must correspond to the risk appetite of the management, which is recorded in writing.
CIVAC offers preconfigured scope templates for SMEs and corporations that reflect the typical compliance risk types. Audit templates include context statements, risk appetite statements and risk criteria.
If you draw the scope too narrowly, you risk leaving gaps. If you pull it too far, you overload the process. The two working day SLA at CIVAC includes a scope workshop session with the external compliance officer.
Step 2: Build risk identification and risk register
ISO 31000 Section 6.4.2 requires systematic risk identification. Methods include workshops with process owners, document analysis, interviews, brainstorming techniques, scenario analysis and external sources (industry reports, regulatory notices, association information).
The risk register is the central documentation. At least the following are recorded for each risk: risk ID, risk name, risk owner, risk cause, possible impact, affected compliance fields, date of recording, reference to legal basis.
Compliance-specific risks should be structured according to mandatory fields. Data protection (GDPR, BDSG), IT security (NIS-2, BSIG, IT-SiG 2.0), occupational safety (ArbSchG), environment (BImSchG, KrWG), money laundering (AMLA), supply chain (LkSG), corruption (StGB, OECD Convention), whistleblower protection (HinSchG).
The 25 representative roles that CIVAC covers live correspond to these mandatory fields. Each role comes with a standard risk set that can be loaded into the workspace as a starting point.
The risk register is completely reviewed at least annually and updated ad-hoc in the event of significant changes. The clock starts on awareness.
CIVAC maintains the risk register with an audit trail. Every change is versioned with a time stamp, author and justification. Audit-proof, documented, OWiG-proof.
Step 3: Risk analysis and assessment with documented methodology
The risk analysis (Section 6.4.3) determines the probability of occurrence and impact. The risk assessment (Section 6.4.4) compares the result with the risk criteria and decides on treatment. Methods range from qualitative (low/medium/high) to quantitative (amount of money times probability).
Semi-quantitative methodology is typical for compliance risks. Impact is categorised on a 5-level scale (amount of fines, regulatory consequences, reputational consequences). Probability also in 5 levels (very unlikely to very likely, with time window).
The risk matrix combines both axes to form risk classes. Four classes are typical: low (acceptance with monitoring), medium (measures when the opportunity arises), high (measures with a deadline), critical (immediate measures and management involvement).
The methodology must be recorded in writing before use. Changes are versioned and justified. BaFin and other regulators expect that the methodology will not be adjusted ad hoc or retroactively to move problematic risks into acceptable classes.
CIVAC offers a configurable risk matrix with industry-specific templates. The methodology is documented and versioned in the workspace. The compliance officer's appointment document refers to the applicable methodology version.
Anyone who does not document the methodology will lose the OWiG relief in the fine procedure. The examiner asks: how did this risk come to this assessment on this date. The answer must be reproducible.
Step 4: Risk treatment and action tracking
ISO 31000 Section 6.5 lists four treatment options: risk avoidance (stop activity), risk reduction (reduce probability or impact), risk sharing (insurance, contractual clauses), risk acceptance (conscious acceptance of low risk).
Compliance risks are usually treated through risk reduction. Preventative measures include policies, training, process controls, IT controls, audits, reporting lines. The effectiveness of the measures is checked periodically in the monitoring (Section 6.6).
The list of measures contains for each measure: measure ID, description, person responsible, deadline, planned effort, effectiveness criterion, status tracking. It is linked to the risk register so that the chain of evidence between risk and measure remains traceable.
Escalation rules define when a risk or an unimplemented measure moves to the next reporting line. Typical rules: High risk without action escalated to management after 30 days, critical risk immediately.
CIVAC links risk register, action list and reporting line in one workspace. Resubmissions are generated automatically and escalations are logged with a time stamp. The auditor calls, the evidence is ready.
Licence the workspace for your internal representatives, or have our representatives order it. Both models share the same data structure and provide OWiG relief in one system.
Step 5: Monitoring, reporting and continuous improvement
ISO 31000 Section 6.6 requires ongoing monitoring and review. The risk matrix is updated at least annually, and quarterly in dynamic industries. Effectiveness tests are carried out in a risk-oriented manner: high risks more often, low risks less often.
The reporting system is multi-level. Operational risk owners report to the compliance officer, who reports to the management, and the management to the supervisory body (supervisory board, advisory board). Frequencies typical: monthly operational, quarterly to management, semi-annually to the supervisory body.
Report formats are not required in ISO 31000, but should include risk map, top risks, action status, incidents, KPIs and new regulatory requirements. A compliance dashboard in the workspace brings the data into a consistent format.
Continuous improvement (Section 5.7) means that risk management itself is regularly evaluated. Internal audits, management reviews, external benchmarking and incident analyses provide the inputs. Changes are documented and communicated.
CIVAC provides preconfigured report formats for compliance officer quarterly reports, management semi-annual reports and supervisory body annual reports. The database is the risk register and the list of measures, not a separate presentation.
If you compile the reporting from PowerPoint, you lose consistency and reproducibility. The system is the source of truth, the report is the view of it.
Typical mistakes during implementation and how to avoid them
Mistake 1: Risk management as a staff task without connection to management. The OWiG relief requires active fulfilment of the supervisory obligation, not delegation. Management must approve the risk appetite and know the top risks.
Mistake 2: Risk matrix without documented methodology. Anyone who does not put the evaluation criteria in writing before applying them runs the risk that examiners will classify the evaluation as arbitrary. The appointment certificate, signed, filed, verifiable.
Error 3: Risk and measure decoupled. If the risk register is in Excel and the measures are in a ticket system without a link, the proof of the effectiveness test cannot be reproduced. CIVAC connects both in the workspace.
Mistake 4: Risk management only for certification. Anyone who only sets up ISO 37301 for the certificate and sees ISO 31000 as a pure tool will miss out on the OWiG relief and the corporate control effect.
Mistake 5: Versioning and audit trail are missing. In a fine procedure or an authority audit, the status of a risk must be reproducible on a specific date. Excel files with a date in the file name are not enough.
CIVAC provides Compliance Officer role as Officer-as-a-Service with reporting line and audit trail in one system. Others run compliance like a filing cabinet. We run it like software.
CIVAC: ISO 31000 as a compliance platform and officer-as-a-service
CIVAC is a compliance platform and officer-as-a-service for compliance, data protection, IT security and 22 other officer roles. Risk register, list of measures, reporting line, audit trail and reporting templates are in one workspace.
Licence the workspace for your internal representatives, or have our representatives order it. Both models share the same data structure: 93 controls according to ISO/IEC 27001:2022, 490 ready-to-use audit templates, appointment certificate, reporting line, EU data residency.
Specifically for ISO 31000: preconfigured scope templates, context statement templates, risk appetite statement, configurable risk matrix with versioning, action tracking with escalation rules, reporting formats for compliance officers, management and supervisory bodies.
The integration with ISO 37301:2021 for compliance management and ISO/IEC 27001:2022 for information security is shown in the workspace. A risk from the compliance register can be linked to ISO 27001 controls and LkSG preventative measures.
The CIVAC SLA is 2 working days for ordering and onboarding, instead of the classic 2 to 6 weeks. The compliance officer receives the appointment certificate, reporting line and audit templates on the first working day. Audit-proof, documented, OWiG-proof.
Turn reading into a mandate. Write to info@civac.de or use the contact form on civac.de. The start is a gap analysis: We map your existing risk management practice against ISO 31000:2018, ISO 37301:2021 and Section 130 OWiG and provide a list of measures with effort and deadline.
FAQ
Is ISO 31000:2018 certifiable?
No, ISO 31000:2018 is a Guidance Standard and cannot be certified. It provides principles, framework and process for risk management. ISO 37301:2021 (compliance management), ISO/IEC 27001:2022 (information security) and other management system standards that reference ISO 31000 as an architecture can be certified.
How does ISO 31000 relate to Section 130 OWiG?
Section 130 OWiG requires management to take supervisory measures to prevent breaches of duty. Documented risk management in accordance with ISO 31000:2018 is the central relief in fine proceedings. It shows that the necessary supervisory measures have been taken and continuously tracked.
Which risks must be included in the compliance risk register?
All mandatory risks from regulated compliance fields: data protection, IT security, occupational safety, environment, money laundering, supply chain, corruption, whistleblower protection, taxes. Optionally also market-related risks from compliance violations (reputation, contractual risks). The scope is recorded in the context statement documentation and updated annually.
How frequently does the risk matrix need to be updated?
At least annually in full, in dynamic industries quarterly. Ad hoc update in case of significant changes: new law, internal incident, supervisory letter, organisational change. The update frequency is determined within the framework and is part of the methodology documentation.
How much time does the introduction of ISO 31000 take in a compliance context?
A gap analysis takes 2 to 3 weeks. Setting up a complete, audit-proof compliance risk management typically takes 3 to 6 months, depending on the size of the company, industry complexity and existing subsystems. CIVAC offers a standard implementation path with defined milestones.
Can I outsource the compliance officer role?
Yes, Officer-as-a-Service is permitted as long as the appointment certificate, reporting line and resources are documented. CIVAC offers the compliance officer with a defined reporting line to management, audit templates and EU data residency. Responsibility for risk appetite and approval of measures remains with the management.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.