An industrial organization may maintain a risk register containing dozens of entries while its production lines continue to experience unexpected breakdowns, unplanned downtime, quality problems, delayed raw materials, and recurring operational errors that are never addressed systematically.
The problem is not necessarily the absence of “risk management.” It may be that risk management has remained at the reporting level and has not reached the place where risks actually arise: the operational process.
ISO 31000 provides an international framework that helps organizations identify, analyze, evaluate, treat, monitor, and communicate risks. It also encourages the integration of risk management into governance, strategy, planning, decision-making, and daily operations.
For a factory, genuine implementation does not mean creating another file titled “ISO 31000.” It means establishing a method that makes risk consideration a natural part of decisions relating to production, maintenance, quality, procurement, inventory, operational change, and investment.
What Is ISO 31000?
ISO 31000:2018 is an international standard that provides principles, a framework, and a process for managing risk.
It can be applied to:
- Organizations of different sizes.
- Different industries and sectors.
- Different types of risk.
- Decisions, projects, processes, and activities.
The framework helps an organization manage an interconnected cycle that includes:
- Understanding the context.
- Identifying risks.
- Analyzing risks.
- Evaluating risks.
- Treating risks.
- Monitoring and reviewing risks.
- Communicating and consulting with relevant stakeholders.
One point must be clarified from the beginning:
ISO 31000 is not a certification standard.
ISO expressly explains that ISO 31000 provides guidelines rather than requirements. It is therefore not intended for organizational certification.
Organizations can use it as an international reference for evaluating and improving their risk-management practices, governance arrangements, and audit programmes.
The accurate description is therefore:
“Implementing an ISO 31000-based risk-management framework.”
Not:
“Obtaining ISO 31000 certification.”
What Is Operational Risk in a Factory?
Operational risk arises from uncertainty that may affect the achievement of a process or factory objective.
It should not be reduced to occupational accidents or safety issues alone.
Within a production line, operational risk may appear as:
- Failure of critical machinery.
- Product-quality deviation.
- Disruption of a principal supplier.
- Shortage of raw materials.
- Failure of a control system.
- Human error.
- Unstable power supply.
- Loss of a supporting utility.
- Uncontrolled process change.
- Delayed maintenance.
- Loss of operational data.
- An environmental or safety event that interrupts production.
This is one of the strengths of ISO 31000. It offers a general approach that can be integrated into different organizational activities and decisions rather than being limited to one category of risk.
The First Mistake: Creating a Risk Register Away From the Production Line
If the management team meets once a year to prepare a document titled “Operational Risks,” but production and maintenance managers and supervisors do not use it afterward, risk management has not been integrated into operations.
The risk register should become a decision-making tool.
When a factory considers:
- Increasing line speed.
- Introducing a new material.
- Changing a supplier.
- Postponing maintenance.
- Modifying a control programme.
- Adding another shift.
- Changing staffing levels.
- Reconfiguring a production area.
The effect of that decision on risk should form part of the process.
ISO emphasizes that risk management is more effective when it is integrated into governance, strategy, planning, policies, values, culture, and decision-making rather than operated as a separate activity.
Begin With Process Objectives, Not a List of Hazards
Before asking:
What are the risks?
First determine:
What are we trying to achieve?
A production line may aim to produce a defined daily quantity:
- At a specified quality level.
- Within an acceptable level of waste.
- Within defined downtime and cost limits.
- While meeting safety and environmental requirements.
- Within the required delivery schedule.
The risk question then becomes more precise:
Which events or circumstances could prevent us from achieving these objectives or affect their achievement?
This makes risk assessment directly relevant to performance instead of treating it as an exercise separate from the factory’s objectives.
This approach aligns with IAC’s methodology of connecting risk management with strategy, performance, and resource allocation rather than managing it through an isolated register.
Map the Process Before Assessing Its Risks
In an industrial environment, it is difficult to manage the risks of a process without understanding its flow.
Begin with:
- Receipt of raw materials.
- Incoming inspection.
- Storage.
- Preparation.
- Production and transformation.
- Packaging.
- Final inspection.
- Finished-goods storage.
- Dispatch and shipping.
Then add the supporting processes, such as:
- Maintenance.
- Power and utilities.
- Laboratories.
- Information technology.
- Automation and control systems.
- Procurement.
- Human resources.
Identify the principal dependencies and control points between stages.
Ask:
- If the third stage stops, what happens to the fourth?
- If a particular device fails, is an alternative available?
- If a supplier is delayed, how many days can inventory support operations?
- If a supporting utility fails, which production lines will stop?
- If laboratory results are delayed, can production continue?
- If a data or control system becomes unavailable, what happens to process control?
These relationships reveal risks that do not appear in generic checklists.
Identify Risks With Process Owners
The risk manager or quality officer should not be the only person responsible for identifying risks.
Different people hold different parts of the operational picture:
- The machine operator knows that a particular sensor fails repeatedly.
- The maintenance technician knows that a critical spare part requires weeks to arrive.
- Procurement knows that a particular material is available from only one supplier.
- Quality personnel know which types of nonconformity recur most frequently.
- Warehouse personnel know where storage and handling problems arise.
- Production personnel understand the principal bottlenecks.
Risk identification should therefore be participatory and based on actual operational knowledge.
ISO 31000 places communication and consultation within the risk-management process and emphasizes the importance of involving relevant stakeholders in understanding risk and making decisions.
Participation also improves the likelihood that the resulting controls will be practical and implemented.
Classify Risks in a Way That Supports Decisions
The objective is not to create dozens of categories.
Use a classification method that helps management understand the nature of exposure.
Depending on its needs, a factory may distinguish between risks relating to:
- Production.
- Quality.
- Maintenance and reliability.
- Supply chains.
- Inventory.
- Human resources and competence.
- Technology and automation.
- Occupational health and safety.
- The environment.
- Utilities and supporting services.
- Compliance.
These categories should not become isolated silos.
For example:
Failure of a main air compressor may begin as a maintenance issue, but it can also cause:
- Production stoppage.
- Delayed customer orders.
- Additional cost.
- Product-quality problems.
- Safety concerns under particular operating conditions.
The risk should therefore be evaluated according to its effect on organizational objectives, not merely according to the department that owns it.
Analyze Causes Before Rating Consequences
Weakness in a risk register is often visible when the risk is written as:
“Production stoppage.”
This describes an outcome, not a sufficiently analyzed risk scenario.
A more useful structure is:
Cause → Event → Impact
For example:
Weak preventive-maintenance programme → Failure of critical machinery → Production-line stoppage and delayed customer orders
Or:
Dependence on a single supplier → Interruption in raw-material supply → Production stoppage or purchase of a higher-cost substitute
Or:
Changing process settings without approval → Deviation from operating parameters → Increased nonconforming products and waste
This structure makes it possible to design risk treatments that target the cause of the risk, rather than merely responding to the consequences after they occur.
Evaluate Likelihood and Impact Using Clear Criteria
A risk matrix is a tool, not the objective.
If ratings such as “high,” “medium,” and “low” depend entirely on the opinion of whoever is present at the meeting, the results will vary from one meeting to another.
Define clear criteria.
For example:
- What does high likelihood mean?
- What financial effect is considered high?
- When is production downtime considered significant?
- What is the impact of a delayed customer order?
- How should product-quality consequences be rated?
- How should safety or environmental consequences be assessed?
- How should legal and reputational implications be considered?
Use operational data whenever possible.
Instead of merely stating that machinery failure is “likely,” review:
- Number of previous failures.
- Mean time between failures.
- Mean time to repair.
- Downtime hours.
- Asset age and condition.
- Availability of spare parts.
- Maintenance history.
- Vendor-support capability.
The more closely the risk assessment is linked to reliable data, the more defensible, consistent, and reviewable the resulting decision becomes.
Do Not Assess Inherent Risk Alone—Evaluate Existing Controls
A risk may be inherently high, while effective controls substantially reduce its likelihood or impact.
Ask:
- What controls currently exist?
- Are they operating?
- How do we know they are operating?
- Who monitors them?
- When was their effectiveness last tested?
- Have they failed previously?
- Are they dependent on one person or one system?
Controls may include:
- Engineering safeguards.
- Preventive maintenance.
- Predictive monitoring.
- Safety stock.
- An approved alternative supplier.
- Inspection and testing.
- Operating procedures.
- Training and competence.
- Warning and alarm systems.
- Monitoring systems.
- Business-continuity arrangements.
The purpose is not merely to record the control. It is to demonstrate its effectiveness.
A control that exists only in a procedure should not be rated as though it is fully operational.
Understand Residual Risk
After considering current controls, a certain level of exposure remains.
This is the residual risk that management needs to understand.
If the residual risk exceeds the accepted level, the organization needs additional treatment.
If it remains within approved limits, management may decide to continue operating while monitoring it.
This is where concepts such as Risk Appetite, risk-tolerance limits, and acceptance criteria become relevant.
IAC’s consulting catalogue identifies risk appetite, acceptance thresholds, and escalation mechanisms as elements within an enterprise risk-management framework.
The important question is not simply:
“What was the initial risk rating?”
It is:
“What level of risk remains after existing controls, and is management willing and authorized to accept it?”
Do Not Allow Risk Acceptance to Become an Undocumented Decision
Sometimes the proposed treatment costs more than the potential impact, is not immediately feasible, or must be implemented over time.
The organization may decide to accept the risk temporarily.
However, acceptance should be:
- Explicit.
- Justified.
- Approved within defined authority.
- Documented.
- Time-bound where appropriate.
- Accompanied by monitoring when necessary.
The problem is not that some risks are accepted. Management cannot eliminate every form of uncertainty.
The problem arises when a known high risk remains without clarity regarding:
Who accepted it, under what authority, and for what reason?
A documented acceptance process also ensures that risks exceeding the authority of a line manager are escalated appropriately.
Convert High Risks Into Treatment Plans
A risk register that ends with the risk rating is operationally incomplete.
When a risk exceeds the approved acceptance threshold, the organization should establish a treatment plan that identifies:
- The required action.
- The risk owner.
- The action owner.
- Required resources.
- Target completion date.
- Progress status.
- The performance or risk indicator.
- How the reduction in risk will be verified.
- The expected residual risk after treatment.
IAC’s ISO 31000 consulting framework includes the development of risk registers and Treatment Plans, connecting them to decisions and follow-up.
The organization should move from:
“We have a high machinery-failure risk.”
To:
“These are the actions that will reduce the likelihood or impact of failure, this is the responsible owner, this is the implementation deadline, and this is how we will measure effectiveness.”
A Practical Production-Line Example
Assume that a factory depends on one critical filling machine.
Operational Objective
Maintain the required production rate without extended downtime.
Source of Risk
Dependence on one machine containing critical components with long procurement lead times.
Potential Event
Failure of a critical component.
Potential Impact
- Packaging stops.
- Finished-product dispatch is disrupted.
- Customer orders are delayed.
- Additional cost is incurred.
- Service levels may be affected.
The organization should then review existing controls.
Ask:
- Is preventive maintenance performed?
- Have critical spare parts been identified?
- Are those parts held in inventory?
- Is a technical-support agreement in place with the supplier?
- Is an alternative machine available?
- Can production be transferred to another line or location?
- Has the recovery time been tested?
The residual risk is then estimated.
If it remains above the acceptance threshold, treatment may include:
- Increasing the inventory of critical spare parts.
- Improving predictive-maintenance capability.
- Establishing a supplier-response agreement.
- Developing an alternative production route.
- Investing in standby or replacement capacity.
- Cross-training additional maintenance personnel.
Risk management has now become connected to a real operational and investment decision.
Connect Maintenance to Risk Management
In many factories, maintenance operates through a fixed schedule while risk management functions separately.
The two should be connected.
Equipment whose failure would cause significant loss should not be treated in the same way as noncritical equipment.
A criticality analysis can help determine:
- Maintenance priority.
- Spare-parts levels.
- Inspection frequency.
- Predictive-monitoring requirements.
- Contingency arrangements.
- Replacement and capital-investment decisions.
Maintenance then moves from:
“We maintain every asset according to a similar schedule.”
To:
“We allocate resources according to the effect of asset failure on the factory’s objectives.”
This approach helps direct limited maintenance resources towards the assets that matter most to continuity, quality, safety, and delivery.
Connect Quality Data to Risk Management
Quality data can also inform the operational risk register.
If a particular type of nonconformity recurs, it should not be treated solely as a quality report that must be closed.
It may be an early indication of a continuing operational risk.
Analyze:
- Which process causes the problem?
- Is the cause related to raw material?
- Is it connected to machine settings?
- Does operator competence contribute?
- Is the process design inadequate?
- Is a measuring instrument involved?
- Did a supplier change?
- Is the problem linked to environmental or utility conditions?
The more effectively an organization uses quality data to identify emerging risks, the more proactive its risk-management process becomes.
Quality indicators such as rejection, rework, scrap, deviation, and complaint trends can serve as valuable risk information.
Connect Supply-Chain Management to Risk
A production line may operate effectively but still stop because one essential material does not arrive.
Operational risk management should therefore extend beyond the factory boundary.
Identify highly critical materials and suppliers.
Ask:
- Is there only one supplier?
- What is the normal and maximum lead time?
- Are qualified alternatives available?
- What is the minimum required inventory level?
- What is the likelihood of transport disruption?
- Does the supplier itself depend on one source?
- Are substitute materials technically approved?
- How quickly could an alternative be activated?
The results should inform:
- Inventory policy.
- Procurement strategy.
- Supplier qualification.
- Contractual arrangements.
- Contingency planning.
Effective risk management may justify maintaining a higher stock level for a critical material while allowing the organization to reduce stock for a material that is readily available and easily substituted.
Use Early-Warning Indicators
One of the most valuable improvements in risk management is moving from measuring what has already happened to monitoring signs of what may happen.
Instead of tracking actual downtime hours alone, the organization may monitor:
- An increase in minor equipment failures.
- Delayed preventive maintenance.
- Declining stocks of critical spare parts.
- Increased rejection of materials from a particular supplier.
- Higher employee turnover in a critical role.
- Increasing levels of product rework.
- Rising alarm frequency.
- An increase in temporary repairs.
These indicators may alert management before the risk becomes an actual loss.
This is where Key Risk Indicators (KRIs) can be used alongside Key Performance Indicators (KPIs).
A KPI asks:
How are we performing?
A KRI helps management ask:
Is our exposure to a risk that could affect performance increasing?
For the indicators to be useful, the organization should define:
- The indicator.
- The data source.
- The owner.
- The threshold.
- The monitoring frequency.
- The required response when the threshold is exceeded.
Make Risk Management Part of Change Management
Change is one of the most significant sources of operational risk.
Examples include changing:
- Machinery.
- A control programme.
- Raw material.
- A supplier.
- An operating method.
- Production-line speed.
- Packaging design.
- Staffing levels.
- Work shifts.
- Factory layout.
A change should not be approved solely because the responsible department believes it will be beneficial.
Before implementation, ask:
- What new risks will arise?
- Which existing risks will change?
- Are current controls sufficient?
- Do workers need training?
- Will quality be affected?
- Will occupational health and safety be affected?
- Will environmental performance be affected?
- Will maintenance requirements change?
- Will supply arrangements change?
After implementation, verify whether the original assumptions were correct.
This is one of the points at which risk management moves from a “report” to a decision gateway.
Connect the Risk Register to Operational Meetings
A separate meeting titled “Risk Committee” is not always necessary.
Risk review can be integrated into existing operational meetings.
When the factory manager reviews weekly production performance, the agenda can include principal risks:
- Which risks have increased?
- Which treatment actions are overdue?
- Has a new risk emerged?
- Has a control failed?
- Has a KRI exceeded its threshold?
- Does an issue require escalation?
- Have assumptions changed?
Risk management then becomes part of daily performance management rather than an additional bureaucratic layer.
Periodic senior-management review can still be used for cross-functional, strategic, high-impact, or escalating risks.
What Should an Operational Risk Register Contain?
A useful register should support decisions rather than become an unnecessarily complex form.
At a minimum, it may include:
- Risk-scenario description.
- Affected process or objective.
- Causes.
- Potential events.
- Consequences.
- Existing controls.
- Assessment of control effectiveness.
- Risk level.
- Risk owner.
- Treatment decision.
- Required actions.
- Action owner.
- Target date.
- Implementation status.
- Residual risk after treatment.
Where useful, it may also include:
- Key Risk Indicators.
- Escalation status.
- Date of last review.
- Date of next review.
- Related incidents or nonconformities.
- Link to a continuity or contingency plan.
Adding dozens of fields that no one uses does not make the system more mature.
The best register is the one that management and process owners actually use.
When Should a Risk Be Escalated to Senior Management?
Not every operational risk needs to reach the general manager.
Establish clear escalation rules.
A risk that a production-line manager can address within their authority should remain at that level.
A risk may require higher-level decision-making when it:
- Exceeds the approved risk appetite.
- Requires significant investment.
- Affects several departments.
- Threatens production continuity.
- Could affect key customers.
- May create major legal, safety, environmental, financial, or reputational consequences.
- Cannot be treated within the current owner’s authority.
- Remains high despite existing controls.
Escalation should be connected to the size and authority of the decision required, not to the person who wrote the risk report.
How Can You Determine Whether the Risk-Management System Is Working?
Do not measure success by the number of risks in the register.
Ask:
- Have decisions become clearer?
- Have operational surprises decreased?
- Are the causes of repeated downtime being addressed?
- Do high risks have owners and treatment plans?
- Are overdue actions visible?
- Do risk ratings change when circumstances change?
- Do managers use risk information when allocating resources?
- Are early-warning indicators in place?
- Does the organization learn after problems occur?
- Are ineffective controls identified and improved?
ISO 31000 emphasizes integrating risk management into the organization and continually monitoring, reviewing, and improving it.
The objective is not to create a static register.
ISO 31000 and Its Relationship With Other ISO Standards
ISO 31000 does not replace specialized management systems.
When a risk relates to occupational health and safety, ISO 45001 may provide more specialized requirements.
When it concerns environmental management, ISO 14001 becomes relevant.
Within quality management, ISO 9001 provides a framework for addressing risks and opportunities affecting the quality management system.
For business continuity, ISO 22301 provides requirements for a business continuity management system. ISO describes it as a framework that helps organizations strengthen resilience and respond systematically to disruption.
ISO 31000 can operate as an overarching organizational framework that helps management consider different categories of risk through one governance and decision-making logic.
This is consistent with IAC’s positioning of risk management as part of governance and performance rather than as a service isolated from institutional management.
Can an Organization Obtain ISO 31000 Certification?
No.
This distinction is particularly important in marketing materials and technical proposals.
ISO confirms that ISO 31000 provides guidelines, not requirements. It is therefore not intended for certification.
Organizations can use it to:
- Develop a risk-management framework.
- Benchmark existing practices against an international reference.
- Improve governance.
- Strengthen decision-making.
- Develop risk-management and audit programmes.
However, it does not result in an organizational “ISO 31000 certificate.”
A training provider may offer an educational or professional development programme relating to ISO 31000. That is different from certification of an organization’s management system.
What Is the Current Edition of ISO 31000?
As of 17 August 2026, ISO 31000:2018 — Risk Management — Guidelines remains the current published edition.
ISO currently lists its status as “To be revised.”
This means that a revision process is planned, but a replacement edition has not yet become a published international standard.
Current projects should therefore use ISO 31000:2018 while monitoring the official revision process.
A future draft should not be presented as the effective edition before it is formally published.
What Is IAC’s Role in Operational Risk Management?
IAC’s official consulting catalogue includes an ISO 31000 Risk Management Framework Consulting pathway designed to help leadership teams use risk management as a strategic decision-support tool and connect risk with performance, strategy, and resources.
The documented scope of this service includes:
- Designing an enterprise risk-management framework.
- Identifying and analyzing strategic, operational, compliance, and reputational risks.
- Developing risk registers and matrices.
- Developing risk-treatment plans.
- Defining risk appetite and acceptance thresholds.
- Establishing escalation mechanisms.
- Connecting risk management with strategic planning and performance indicators.
The engagement follows IAC’s methodology:
Objective Diagnosis → Tailored Design → Phased Implementation → Internal Capability Building → Impact Measurement
The objective is not to deliver a Risk Register and end the project.
It is to build an internal capability that enables the factory’s departments to identify, understand, treat, and review risks as part of daily operations.
Frequently Asked Questions
Is ISO 31000 Intended Only for Factories?
No.
The standard is general and can be applied to different organizations, sectors, activities, and decisions.
Its implementation should nevertheless be adapted to the organization’s context, objectives, and risks.
Does ISO 31000 Address Negative Risks Only?
ISO considers risk in the context of uncertainty and its effect on objectives.
Risk management can help organizations understand threats and opportunities and improve decision-making and resource allocation.
Is a 5×5 Risk Matrix Sufficient?
No.
A matrix is only a tool for estimating or presenting risk.
A complete risk-management process includes:
- Defining the context.
- Identifying risk.
- Analyzing risk.
- Evaluating risk.
- Treating risk.
- Communicating and consulting.
- Monitoring and reviewing.
- Integrating results into decisions.
Who Should Own Risks Within a Factory?
Each risk should have an owner with the authority and capability to manage it or escalate it.
Risk management is not the responsibility of the risk officer alone. It should be embedded in operational processes and decision-making.
What Is the Difference Between a KPI and a KRI?
A KPI measures the performance of a process or objective.
A KRI indicates the organization’s level of exposure to a risk or the direction in which that exposure is moving.
They can be used together so that management understands both current performance and the risks that may affect future performance.
When Should the Risk Register Be Updated?
It should not be reviewed only once a year.
The register should be reviewed when significant changes occur in:
- Processes.
- Machinery.
- Suppliers.
- Materials.
- Resources.
- Technology.
- The regulatory environment.
- Organizational objectives.
- Operating conditions.
It should also be updated when incidents, failures, near misses, audit findings, quality problems, or other events reveal new information, in addition to the organization’s planned review cycle.
Conclusion
Operational risk management does not succeed because the risk register becomes larger.
It succeeds when the factory makes better decisions.
Practical application of ISO 31000 across production lines begins with operational objectives, followed by understanding the process flow, identifying risks with the people who perform the work, analyzing causes and consequences, evaluating controls and residual risk, and converting unacceptable risks into treatment plans, indicators, follow-up mechanisms, and clearly assigned responsibilities.
The practical pathway is:
Objective → Process → Risk → Cause and Impact → Controls → Evaluation → Treatment Decision → Owner → Indicator → Review and Improvement
At that point, the Risk Register no longer remains a file used only during management meetings.
It becomes part of decisions relating to:
- Maintenance.
- Production.
- Quality.
- Procurement.
- Inventory.
- Capital investment.
- Operational change.
To request an initial diagnostic session for operational risk management within your industrial facility, contact IAC to assess the current state and develop a framework connecting risks with processes, responsibilities, performance indicators, and management decisions.
