MedTech Terms
    The authoritative reference
    All terms
    Quality & RiskQuality System

    ISO 31000

    Generic enterprise risk management standard; complements ISO 14971's product risk focus.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026

    Definition

    ISO 31000 provides high-level principles and a framework for risk management across an organization - strategy, projects, supply chain, IT - rather than the patient-safety focus of ISO 14971.
    What the regulation says
    While not a regulatory standard itself, ISO 31000 provides a globally recognized framework for risk management that can be adopted by organizations to meet broader regulatory expectations for documented risk processes, as seen in areas like the FDA Quality System Regulation (21 CFR Part 820) which calls for a quality system that ensures medical devices are safe and effective. It offers a structured approach for integrating risk management into an organization’s overall governance, strategy, and operations, complementing sector-specific standards like ISO 14971 for medical device risk management by providing a larger enterprise risk context. Regulators generally expect organizations to have robust risk management processes, and adherence to ISO 31000 can demonstrate a comprehensive commitment to managing risks beyond just product safety.

    What this means in practice

    Useful for quality leaders building enterprise-level risk programs that cover product, business continuity, and cyber risk in one structure.

    Examples

    • A MedTech company uses ISO 31000 principles to develop an enterprise-wide risk management strategy that covers product development, supply chain disruptions, and IT security incidents.
    • A quality leader applies the ISO 31000 risk assessment process to evaluate potential business continuity risks associated with a single-source supplier for a critical component.
    • A medical device manufacturer integrates the principles of ISO 31000 into its corporate governance structure, ensuring that risk management considerations are part of strategic decision-making.
    Common pitfalls
    • Confusing ISO 31000 with a prescriptive regulatory requirement; it is a guideline, not an auditable standard for compliance.
    • Attempting to replace ISO 14971 with ISO 31000 for medical device product risk management; the standards are complementary, not interchangeable.
    • Implementing ISO 31000 without tailoring its principles to the specific context and risks of a MedTech organization.
    • Failing to integrate ISO 31000 principles into existing quality management systems, leading to duplicated or disjointed efforts.
    • Overlooking the importance of culture and leadership commitment in successful ISO 31000 implementation, focusing solely on processes.

    Frequently asked questions

    ISO 31000 provides a high-level framework for enterprise risk management, applicable across all organizational activities. ISO 14971 is a specific standard for risk management of medical devices, focusing on patient safety. ISO 31000 can provide the overarching structure into which ISO 14971's more detailed requirements for medical devices can fit.
    Grouped by theme

    Primary references

    3 sources
    Link health: 3 verified· last checked 2026-06-20
    ISO·1AAMI·1MDIC·1
    1. 1
      ISO 31000
      Verified
      ISOiso.org
    2. 2
      AAMI - Quality Systems Resources
      Verified
      AAMIaami.org
    3. 3
      MDIC Case for Quality
      Verified
      MDICmdic.org

    Inline markers like [1] jump to the matching reference above.