The risk management framework in ISO 31000 provides a flexible approach to create the right program for your organization. The document doesn’t provide advice or wisdom, so you have to supply that yourself.
The details of the risk management program or specific framework in your organization includes policies, procedures, analysis, and reporting, yet it also has to work within the context of your organization.
Based on the work of Greg Hutchins in ISO 31000: Enterprise Risk Management here are four considerations to supplement your wisdom as you design and implement your program. [Read more…]