EDIH, EEN, Interreg: the platform for European programmes.Find out more

ISO 31000 Maturity · Enterprise Risk Management

Your risk management benchmarked against ISO 31000, turned into a costed action plan.

10 themes, 159 questions, a 5-level scale. And the action that moves each level to the next.

The framework’s 10 themes, already written from L1 to L5. One company, one business unit, or 300 at once.

ISO 31000 Maturity · Enterprise Risk Management

Risk management principles and policyN1 → N5
Leadership and management commitmentN1 → N5
Integration with governance and strategyN1 → N5
Design of the organisational frameworkN1 → N5

10 themes, 159 questions, 5-level scale.

Nordhavn Industries

53 / 100

Risk management principles and policy6484
Leadership and management commitment5379
Integration with governance and strategy6182
Design of the organisational framework3773
IAIndustrialised: your interview notes are enough, the AI fills in the audit.

They measure their maturity with Datamensio

  • CNES
  • Docaposte
  • ANITI
  • Pôle SCS
  • Cetim
  • Cap'Tronic

An example

This could be your situation.

Take one company as an example: three sites, three spreadsheets, no shared answer.

01

Nobody can consolidate.

Nordhavn Industries, 2,400 people in Hamburg, Lyon and Porto. A client asks where the group stands. Each site answers in its own spreadsheet, with its own scales.

02

Three weeks, a single base.

One ISO 31000:2018 assessment launched across all three sites at once, from the managers’ interview notes. The framework was already written, its 10 themes and levels L1 to L5 too.

03

Two costs avoided before being committed.

A score of 53 out of 100, with the gap concentrated on three themes. The AI companion spotted that two actions duplicated those of another audit. The committee report took one sentence to request.

What it saved them

  • 3sites measured on the same base, instead of three questionnaires to reconcile
  • 2duplicate actions caught before the spend
  • 1committee report, with no manual rework

These figures are an example. They could be yours.

The standard imposes processes. Datamensio says where you stand.

01

The framework is already written

Themes, questions and levels L1 to L5, all written. You do not start from an empty spreadsheet.

02

The score lands the same day

Online, by self-assessment link or in interview. Theme by theme, comparable over time.

03

The gap becomes a costed plan

Every step up carries its action. The AI prioritises on expected effect, not on the order of the standard.

04

Progress can be demonstrated

Campaign after campaign, against your target and against your own past. That is what your board asks for.

The maturity scale

One level, the next, and the action that links the two.

This mechanism (a level, the level above, and the action that links the two) is what turns a finding into a trajectory.

Is risk appetite defined and used in the organisation’s decisions?

  1. N1

    No formalised risk appetite. Decisions are made on judgement, with no shared reference point.

  2. N2

    An appetite statement appears in the risk management policy, but it stays general and is not linked to usable thresholds.

  3. N3

    Appetite is broken down into thresholds by risk category, communicated to risk owners and cited in investment decisions.

  4. N4

    Threshold breaches trigger a tracked escalation to the appropriate management level, with the decision recorded.

  5. N5

    Appetite is reviewed periodically in light of incidents, context changes and strategy, with a documented history of revisions.

Action to move from L2 to L3

Translate the appetite statement into numerical thresholds by risk category, have them validated at the next quarterly risk committee, then build them into the risk record template and the investment decision file.

« With Datamensio, we meet our objectives far more efficiently. The ERDF inspection services and our supervising ministry particularly appreciated an approach that gives them reliable data. »
Chambre de commerce et d'industrie

Director, CCI 94CCI Île-de-France

« We believe this is the most suitable solution to scale our transformation project and measure impact according to our needs. »
Interreg Danube Region

Maja SucekChief Operating Officer, Interreg Danube

Take your first measurementon ISO 31000.

What this framework covers

ISO 31000 is the reference standard for risk management. It is organised around three sets: principles (risk is managed in an integrated, structured way, tailored to context, inclusive and dynamic), an organisational framework (leadership and commitment, integration, design, implementation, evaluation, improvement) and a process (establishing the context, a three-stage assessment covering identification, analysis and evaluation, followed by treatment, recording, communication and review). The 2018 version tightened the text and placed top management leadership at the centre of the framework. ISO 31000 provides guidelines, it does not set certifiable requirements.

This is exactly what makes it hard to steer. Almost every organisation claims to draw on it, yet few can say what level of control they actually have. Does the risk map genuinely feed into investment decisions, or does it live alongside the strategic plan without touching it? Who decides on risk appetite, and is that decision written down anywhere? Do risks reported by subsidiaries and business units roll up on a comparable scale, or does each apply its own scoring? Without answers, the risk committee is discussing a list, not a trajectory.

One confusion comes up repeatedly: ISO 31000 is neither ISO 31010 nor a management system. ISO 31010 is the catalogue of assessment techniques, ISO 31000 is the framework that says how to use them. And unlike ISO 9001 or ISO 27001, no body certifies ISO 31000. Another point of context: the growing number of sector obligations, DORA for finance, NIS 2 for cybersecurity, duty of vigilance and CSRD for non-financial risks, is pushing organisations to unify what were previously separate arrangements. ISO 31000 provides exactly the common language needed, provided it is applied beyond the vocabulary.

A maturity assessment asks a different question from a compliance audit. An audit asks whether a requirement is met, yes or no. The assessment places each practice on a progressive scale, from informal gesture to a framework revised on the basis of lessons learned, and names the action that moves it up a level. For a guidelines standard like ISO 31000, this is the only reading that produces a trajectory the committee can actually work with.

In Datamensio, the framework is ready to use and you retain full control. AI adjusts the themes, questions and level wording to your sector and size, or builds a variant from your risk management policy and existing risk maps. The models used are selectable, including European offerings.

Reference standard: ISO 31000:2018

The themes assessed

  • Risk management principles and policy

    Existence of an approved policy, alignment with the standard’s principles, scope covered, definition of risk appetite and tolerance, updates.

  • Leadership and management commitment

    Backing from executive management, mandate given to the risk function, resources allocated, decisions taken at the right level, role of the board and risk committee.

  • Integration with governance and strategy

    Alignment with the strategic plan, risk factored into investment decisions and projects, embedding in the budget cycle and performance reviews.

  • Design of the organisational framework

    Understanding of internal and external context, roles and responsibilities assigned, lines of defence, coordination with internal audit, compliance and security.

  • Risk identification

    Sources and methods of identification, coverage of strategic, operational, financial, non-financial and emerging risks, review frequency, business input.

  • Analysis and evaluation

    Common scoring scale, assessment of likelihood and impact, distinction between gross and net risk, prioritisation, threshold breach criteria.

  • Risk treatment

    Choice of treatment options, risk owners assigned, dated action plans, tracking through to closure, formal acceptance of residual risks.

  • Communication and consultation

    Reporting to the risk committee and board, reporting format and frequency, dialogue with internal and external stakeholders, awareness raising across the business.

  • Monitoring and review of the framework

    Tracking indicators, alert thresholds, triggers for reassessment, incorporation of incidents and audit findings.

  • Continual improvement

    Formalised lessons learned, revision of method and scales, comparison of assessments over time and across entities, maturity of the framework itself.

A short version of the framework, with 34 questions, is available for the online self-assessment. The full version covers 10 themes and 159 questions.

Frequently asked questions

Is ISO 31000 certifiable?

No. The standard provides guidelines, not requirements auditable by a certification body. The assessment measures your maturity level and prepares the ground for management system audits that examine the risk-based approach, such as ISO 9001, ISO 22301 or ISO 27001.

What is the difference between a maturity assessment and a compliance audit?

An audit concludes with a gap or compliance finding against a given requirement. The assessment places each practice on a progressive scale and names the action that moves it up a level. For a guidelines standard, this second reading is the only one that produces a workable roadmap.

How long does the assessment take?

The short version can be completed in a single working session. The full version, run collaboratively with several contributors, typically spans one to two weeks, with most of the time spent gathering input from the relevant departments.

Can the framework be adapted to our organisation?

Yes. You can edit the questions, the wording of the levels, add your own themes or start from a blank base. AI can also generate a variant from your risk management policy and existing risk maps. The framework is yours.

How can several subsidiaries or business units be compared?

The same framework is rolled out to each entity, making scores comparable by theme. The benchmark positions each entity against the others and against its own past assessments. A cross-entity roadmap consolidates action plans without duplicating them.

How does this assessment fit with DORA, NIS 2 or ISO 22301?

These texts require risk management arrangements built on the same principles. A solid ISO 31000 assessment forms the common baseline, with sector frameworks then covering their own specific requirements. Action plans converge into a single roadmap.

Do respondents need technical expertise?

The questions cover governance and management practices, not quantitative methods. A risk manager, internal auditor or internal controller can answer them. Collaborative mode allows specific questions to be assigned to the right person.

Where is the data hosted?

In France, with OVH, backed up at Scaleway. No transfer outside the European Union. The AI models used are selectable, including European offerings.

Take your first measurementon ISO 31000.