All terms
Quality & RiskQuality System
ISO 31000
Generic enterprise risk management standard; complements ISO 14971's product risk focus.
Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026
Definition
ISO 31000 provides high-level principles and a framework for risk management across an organization - strategy, projects, supply chain, IT - rather than the patient-safety focus of ISO 14971. What the regulation says
While not a regulatory standard itself, ISO 31000 provides a globally recognized framework for risk management that can be adopted by organizations to meet broader regulatory expectations for documented risk processes, as seen in areas like the FDA Quality System Regulation (21 CFR Part 820) which calls for a quality system that ensures medical devices are safe and effective. It offers a structured approach for integrating risk management into an organization’s overall governance, strategy, and operations, complementing sector-specific standards like ISO 14971 for medical device risk management by providing a larger enterprise risk context. Regulators generally expect organizations to have robust risk management processes, and adherence to ISO 31000 can demonstrate a comprehensive commitment to managing risks beyond just product safety.
What this means in practice
Useful for quality leaders building enterprise-level risk programs that cover product, business continuity, and cyber risk in one structure.Examples
- A MedTech company uses ISO 31000 principles to develop an enterprise-wide risk management strategy that covers product development, supply chain disruptions, and IT security incidents.
- A quality leader applies the ISO 31000 risk assessment process to evaluate potential business continuity risks associated with a single-source supplier for a critical component.
- A medical device manufacturer integrates the principles of ISO 31000 into its corporate governance structure, ensuring that risk management considerations are part of strategic decision-making.
Common pitfalls
- •Confusing ISO 31000 with a prescriptive regulatory requirement; it is a guideline, not an auditable standard for compliance.
- •Attempting to replace ISO 14971 with ISO 31000 for medical device product risk management; the standards are complementary, not interchangeable.
- •Implementing ISO 31000 without tailoring its principles to the specific context and risks of a MedTech organization.
- •Failing to integrate ISO 31000 principles into existing quality management systems, leading to duplicated or disjointed efforts.
- •Overlooking the importance of culture and leadership commitment in successful ISO 31000 implementation, focusing solely on processes.
Frequently asked questions
ISO 31000 provides a high-level framework for enterprise risk management, applicable across all organizational activities. ISO 14971 is a specific standard for risk management of medical devices, focusing on patient safety. ISO 31000 can provide the overarching structure into which ISO 14971's more detailed requirements for medical devices can fit.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsMore in Quality & Risk
· Same categoryQuality & Risk
Biocompatibility
Ability of a material to perform with an appropriate host response in a specific application.
Quality & Risk
CAPA Effectiveness Check
Verification step confirming a corrective or preventive action actually fixed the problem.
Quality & Risk
Change Control
Formal QMS process for evaluating, approving, and implementing changes that could affect product quality or compliance.
Quality & Risk
Complaint Handling
Process for receiving, evaluating, and responding to device complaints.
Primary references
3 sourcesLink health: 3 verified· last checked 2026-06-20
ISO·1AAMI·1MDIC·1
- 1
ISO 31000VerifiedISOiso.org
- 2
AAMI - Quality Systems ResourcesVerifiedAAMIaami.org
- 3
MDIC Case for QualityVerifiedMDICmdic.org
Inline markers like [1] jump to the matching reference above.