---
title: "ISO 31000, Definition | MedTech Terms"
description: "Generic enterprise risk management standard; complements ISO 14971's product risk focus. Plain-English Quality &amp; Risk definition for MedTech teams, with example"
lang: en
json-ld: |
  {
    "@context": "https://schema.org",
    "@graph": [
      {
        "@type": "DefinedTerm",
        "@id": "https://medtechterms.com/terms/iso-31000#term",
        "name": "ISO 31000",
        "description": "ISO 31000 provides high-level principles and a framework for risk management across an organization - strategy, projects, supply chain, IT - rather than the patient-safety focus of ISO 14971.",
        "url": "https://medtechterms.com/terms/iso-31000",
        "termCode": "iso-31000",
        "inDefinedTermSet": {
          "@type": "DefinedTermSet",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com/terms"
        }
      },
      {
        "@type": "Article",
        "@id": "https://medtechterms.com/terms/iso-31000#article",
        "headline": "ISO 31000",
        "description": "Generic enterprise risk management standard; complements ISO 14971's product risk focus.",
        "url": "https://medtechterms.com/terms/iso-31000",
        "mainEntityOfPage": {
          "@type": "WebPage",
          "@id": "https://medtechterms.com/terms/iso-31000"
        },
        "about": {
          "@id": "https://medtechterms.com/terms/iso-31000#term"
        },
        "articleSection": "Quality & Risk",
        "inLanguage": "en",
        "keywords": "ISO 31000, Quality & Risk, medical device, MedTech",
        "author": {
          "@type": "Person",
          "name": "Christian Espinosa",
          "jobTitle": "Founder, Blue Goat Cyber",
          "url": "https://bluegoatcyber.com"
        },
        "publisher": {
          "@type": "Organization",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "isPartOf": {
          "@type": "WebSite",
          "name": "MedTech Terms",
          "url": "https://medtechterms.com"
        },
        "datePublished": "2026-05-05",
        "dateModified": "2026-05-05",
        "citation": [
          {
            "@type": "CreativeWork",
            "name": "ISO 31000",
            "url": "https://www.iso.org/iso-31000-risk-management.html",
            "publisher": {
              "@type": "Organization",
              "name": "ISO"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "AAMI - Quality Systems Resources",
            "url": "https://www.aami.org/standards",
            "publisher": {
              "@type": "Organization",
              "name": "AAMI"
            }
          },
          {
            "@type": "CreativeWork",
            "name": "MDIC Case for Quality",
            "url": "https://mdic.org/program/case-for-quality/",
            "publisher": {
              "@type": "Organization",
              "name": "MDIC"
            }
          }
        ],
        "mentions": [
          {
            "@type": "DefinedTerm",
            "@id": "https://medtechterms.com/terms/iso-14971#term",
            "name": "ISO 14971",
            "url": "https://medtechterms.com/terms/iso-14971"
          }
        ]
      },
      {
        "@type": "BreadcrumbList",
        "itemListElement": [
          {
            "@type": "ListItem",
            "position": 1,
            "name": "Home",
            "item": "https://medtechterms.com/"
          },
          {
            "@type": "ListItem",
            "position": 2,
            "name": "Terms",
            "item": "https://medtechterms.com/terms"
          },
          {
            "@type": "ListItem",
            "position": 3,
            "name": "Quality & Risk",
            "item": "https://medtechterms.com/terms?cat=Quality%20%26%20Risk"
          },
          {
            "@type": "ListItem",
            "position": 4,
            "name": "ISO 31000",
            "item": "https://medtechterms.com/terms/iso-31000"
          }
        ]
      },
      {
        "@type": "FAQPage",
        "@id": "https://medtechterms.com/terms/iso-31000#faq",
        "mainEntity": [
          {
            "@type": "Question",
            "name": "How does ISO 31000 relate to ISO 14971?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "ISO 31000 provides a high-level framework for enterprise risk management, applicable across all organizational activities. ISO 14971 is a specific standard for risk management of medical devices, focusing on patient safety. ISO 31000 can provide the overarching structure into which ISO 14971's more detailed requirements for medical devices can fit."
            }
          },
          {
            "@type": "Question",
            "name": "Is ISO 31000 certifiable?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "No, ISO 31000 is a guideline, not a management system standard like ISO 9001 or ISO 13485. Therefore, organizations cannot be certified to ISO 31000. It is intended to provide principles and generic guidelines for managing risk."
            }
          },
          {
            "@type": "Question",
            "name": "What are the core components of the ISO 31000 framework?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "The ISO 31000 framework involves principles, a framework, and a process. The principles provide guidance on effective risk management, the framework helps integrate risk management into the organization's overall governance, and the process outlines the systematic application of management policies, procedures, and practices to the activities of communicating, consulting, establishing the context, and identifying, analyzing, evaluating, treating, monitoring, and reviewing risk."
            }
          },
          {
            "@type": "Question",
            "name": "Can ISO 31000 help with cybersecurity risk management in MedTech?",
            "acceptedAnswer": {
              "@type": "Answer",
              "text": "Yes, ISO 31000's general framework is well-suited for managing cybersecurity risks at an enterprise level. It provides a structured approach for identifying, analyzing, evaluating, treating, and monitoring risks related to information security and data integrity, which can then be integrated with specific cybersecurity standards and regulations, like those from the FDA regarding medical device cybersecurity premarket submissions."
            }
          }
        ]
      }
    ]
  }
---

[

MedTech Terms

The authoritative reference



](/)

Browse

Learn

[Latest](/latest)

About

1.  [Home](/)
2.  /
3.  [Terms](/terms)
4.  /
5.  [Quality & Risk](/terms?cat=Quality%20%26%20Risk)
6.  /
7.  ISO 31000

[All terms](/terms)

Quality & Risk [Quality System](/ecosystems/quality-system)

# ISO 31000

Generic enterprise risk management standard; complements ISO 14971's product risk focus.

Reviewed by [Christian Espinosa, Founder, Blue Goat Cyber](/authors/christian-espinosa) Last reviewed May 5, 2026 

## Definition

ISO 31000 provides high-level principles and a framework for risk management across an organization - strategy, projects, supply chain, IT - rather than the patient-safety focus of  [ISO 14971](/terms/iso-14971). 

What the regulation says

While not a regulatory standard itself, ISO 31000 provides a globally recognized framework for risk management that can be adopted by organizations to meet broader regulatory expectations for documented risk processes, as seen in areas like the FDA  [Quality System Regulation](/terms/qsr) (21 CFR Part 820) which calls for a quality system that ensures medical devices are  [safe](/terms/safe-note) and effective. It offers a structured approach for integrating risk management into an organization’s overall governance, strategy, and operations, complementing sector-specific standards like  [ISO 14971](/terms/iso-14971) for medical device risk management by providing a larger enterprise risk context. Regulators generally expect organizations to have robust risk management processes, and adherence to ISO 31000 can demonstrate a comprehensive commitment to managing risks beyond just product safety. 

## What this means in practice

Useful for quality leaders building enterprise-level risk programs that cover product, business continuity, and cyber risk in one structure. 

## Examples

-   A MedTech company uses ISO 31000 principles to develop an enterprise-wide risk management strategy that covers product development, supply chain disruptions, and IT security incidents.
-   A quality leader applies the ISO 31000 risk assessment process to evaluate potential business continuity risks associated with a single-source supplier for a critical component.
-   A medical device manufacturer integrates the principles of ISO 31000 into its corporate governance structure, ensuring that risk management considerations are part of strategic decision-making.

Common pitfalls

-   • Confusing ISO 31000 with a prescriptive regulatory requirement; it is a guideline, not an auditable standard for compliance. 
-   • Attempting to replace ISO 14971 with ISO 31000 for medical device product risk management; the standards are complementary, not interchangeable. 
-   • Implementing ISO 31000 without tailoring its principles to the specific context and risks of a MedTech organization. 
-   • Failing to integrate ISO 31000 principles into existing quality management systems, leading to duplicated or disjointed efforts. 
-   • Overlooking the importance of culture and leadership commitment in successful ISO 31000 implementation, focusing solely on processes. 

## Frequently asked questions

How does ISO 31000 relate to ISO 14971? 

ISO 31000 provides a high-level framework for enterprise risk management, applicable across all organizational activities.  [ISO 14971](/terms/iso-14971) is a specific standard for risk management of medical devices, focusing on patient safety. ISO 31000 can provide the overarching structure into which ISO 14971's more detailed requirements for medical devices can fit. 

Is ISO 31000 certifiable? 

What are the core components of the ISO 31000 framework? 

Can ISO 31000 help with cybersecurity risk management in MedTech? 

## Related terms

Grouped by theme 

### Editor's picks

· Hand-selected related concepts 

[

Standards

ISO 14971

International standard for the application of risk management to medical devices.





](/terms/iso-14971)

### More in Quality & Risk

· Same category 

[

Quality & Risk

Biocompatibility

Ability of a material to perform with an appropriate host response in a specific application.





](/terms/biocompatibility)[

Quality & Risk

CAPA Effectiveness Check

Verification step confirming a corrective or preventive action actually fixed the problem.





](/terms/capa-effectiveness)[

Quality & Risk

Change Control

Formal QMS process for evaluating, approving, and implementing changes that could affect product quality or compliance.





](/terms/change-control)[

Quality & Risk

Complaint Handling

Process for receiving, evaluating, and responding to device complaints.





](/terms/complaint-handling)

Cited by

Where this term appears across MedTech Terms.

Ecosystems (1)

-   [Quality System](/ecosystems/quality-system)

## Primary references

3 sources 

Link health:  3 verified · last checked 2026-06-20 

ISO· 1 AAMI· 1 MDIC· 1 

1.  [1 
    
    ISO 31000
    
    Verified 
    
    ISO · iso.org 
    
    
    
    ](https://www.iso.org/iso-31000-risk-management.html)
2.  [2 
    
    AAMI - Quality Systems Resources
    
    Verified 
    
    AAMI · aami.org 
    
    
    
    ](https://www.aami.org/standards)
3.  [3 
    
    MDIC Case for Quality
    
    Verified 
    
    MDIC · mdic.org 
    
    
    
    ](https://mdic.org/program/case-for-quality/)

Inline markers like \[1\]  jump to the matching reference above.

Sponsor note

### Tying cybersecurity into your QMS?

We help align cybersecurity activities with ISO 13485 design controls and ISO 14971 risk management.

[Book a 30-minute discovery session](https://go.bluegoatcyber.com/meetings/blue-goat-cyber/discovery-session)

-   No obligation
-   Expert-led from minute one
-   NDA available on request

MedTech Terms is a community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com). Definitions are independent of any vendor.

On this term

Category

Quality & Risk

Sources

3

Updated

5/5/2026

[Compare with another term](/compare?a=iso-31000)

Learn in 60 seconds

Card Lesson Quiz

Generic enterprise risk management standard; complements ISO 14971's product risk focus.

-   · Useful for quality leaders building enterprise-level risk programs that cover product, business continuity, and cyber risk in one structure. 

Remember this

Watch out: Confusing ISO 31000 with a prescriptive regulatory requirement; it is a guideline, not an auditable standard for compliance.

Related terms

-   [ISO 14971 ](/terms/iso-14971)

You may also need

Auto-suggested from Quality & Risk and shared keywords.

-   [Risk Acceptability Matrix ](/terms/risk-acceptability-matrix)
-   [AAMI TIR57 ](/terms/aami-tir57)
-   [AAMI TIR97(TIR97) ](/terms/aami-tir97)
-   [Threat Modeling ](/terms/threat-modeling)
-   [Risk Management File(RMF) ](/terms/risk-management-file)
-   [Post-Production Information (Risk) ](/terms/post-production-info)

[All Quality & Risk terms](/terms?cat=Quality%20%26%20Risk)

From the Blue Goat network

Related resources and services on this topic.

-   [
    
    MedTech Truths 
    
    Common misconceptions about medical device development - debunked.
    
    ](https://mdcmisconceptions.com)

MedTech Terms 

An authoritative, plain-language reference for the regulatory, quality, cybersecurity, and software terms that shape modern medical devices.

Browse

-   [All terms](/terms)
-   [A–Z index](/a-z)
-   [Categories](/categories)
-   [Ecosystems](/ecosystems)
-   [Learning paths](/paths)
-   [Compare terms](/compare)
-   [Quiz](/quiz)

Resources

-   [FDA Medical Devices](https://www.fda.gov/medical-devices)
-   [EU MDR](https://eur-lex.europa.eu/eli/reg/2017/745/oj)
-   [IMDRF](https://www.imdrf.org/)
-   [Methodology](/methodology)
-   [Changelog](/changelog)
-   [Editor: Christian Espinosa](/authors/christian-espinosa)
-   [About this site](/about)

© 2026 MedTech Terms. Reference content for educational purposes - not regulatory advice. A community resource sponsored by [Blue Goat Cyber](https://bluegoatcyber.com)