Skip to product information
1 of 1

Information Security, Risk & Business ContinuityAGS-08-003

ISO 31000-2018 · IEC 31010 -Risk Management System

ISO 31000-2018 · IEC 31010 -Risk Management System

A risk register earns its place only when the method behind each score can be explained.

Regular price $490USD
Regular price USD Sale price $490USD
Taxes included.
Secure checkout American Express Apple Pay Diners ClubDiscoverGoogle Pay JCBMastercard Visa

Written by practising auditors with 20+ years in the field.

Preview free samples

View full details
29 ready-to-use documents 29 Word · plus the AGS license

By document type

Total 29
CategoryFiles
Manuals2
Procedures & SOPs10
Forms & Records9
Checklists & Audit Tools4
Training & Awareness2
Guides & Work Instructions2

Key documents

ReferenceDocumentFormat
AGS-QM-01Risk Management Quality Manual Word
AGS-PR-03Risk Assessment Procedure Word
AGS-PR-04Risk Treatment Procedure Word
AGS-FR-01Risk Register Word
AGS-FR-05Risk Treatment Plan Word
AGS-CL-01Risk Assessment Checklist Word

Overview

ISO 31000:2018 and IEC 31010 are the core international guidance on managing risk. ISO 31000 sets out principles, a framework and a process for any organisation, any sector and any type of risk, whether its consequences are negative or positive. It is guidance rather than a certifiable requirements standard, written for boards, executives and anyone deciding under uncertainty, and it holds that risk management should be integrated, structured, customised, inclusive and dynamic, based on the best available information, and should create and protect value.

The framework covers leadership and commitment, integration, design, implementation, evaluation and improvement; the process runs from communication and consultation and the establishment of scope, context and criteria, through risk assessment and treatment, to monitoring, review, recording and reporting. IEC 31010 expands the assessment step, cataloguing techniques and setting out where each applies and where it falls short: brainstorming, structured interviews, checklists, failure modes and effects analysis, hazard and operability studies, fault and event tree analysis, bow-tie analysis and Monte Carlo simulation among others. Vocabulary follows ISO Guide 73, so the register lines up with the risk-based thinking already embedded in ISO 22301, ISO 27001 and ISO 37301.

What this system covers

  • Scope, context and criteria — what is assessed, and the thresholds by which risk is judged
  • Identification and analysis — choosing an IEC 31010 technique that suits the decision in hand
  • Evaluation and scoring — consistent likelihood and consequence criteria across departments
  • Risk treatment — selecting, justifying and tracking controls, with residual risk recorded
  • Communication and consultation — involving stakeholders throughout, not at sign-off
  • Monitoring, review and reporting — keeping the register current and risk in front of management
  • Framework maturity — leadership commitment, integration into decisions, review of the framework

Who it's for

Risk managers, internal auditors and the executives who own the register, most often where every department scores risk its own way and the results cannot be compared. Purchase follows a board request for one consistent view of risk, or an auditor asking how a rating was arrived at. Because both documents are guidance, the outcome is not a certificate but a defensible framework, a live register and treatment plans whose reasoning survives challenge.

Everything you get

Every toolkit gives you a full set of working documents for your standard, ready to edit and use.

Editable Word and Excel

Native Microsoft files. Add your logo and adapt every document to how you work.

Instant download

Your full toolkit arrives as a ZIP the moment payment clears.

Unlimited users

One purchase covers everyone in your organisation. No per-seat fees.

Written by auditors

Built by people who run real audits, so the content matches what assessors check.

Yours to keep

One payment, perpetual licence for your organisation. No subscriptions, no renewals.

Refund guarantee

Full refund if your files are faulty, incomplete or not as described and we can't put it right

Frequently asked questions

What exactly do I receive?

A downloadable ZIP containing the full set of ready-to-use documents for this toolkit — manuals, procedures, forms, records, checklists, guidance and training material, all in editable Word and Excel format. The exact document count is shown at the top of this page.

Are the documents really editable?

Yes. Every file is native Microsoft Word or Excel — no locked PDFs. Add your logo, change wording, and tailor the content to your organisation. The toolkit is yours to keep and reuse.

Does this certify my organisation?

No. These are documentation toolkits aligned to the relevant standard to help you prepare. Certification itself is issued by an accredited certification body after their audit. Our toolkits give you a strong, audit-ready starting point.

How is it delivered?

Instantly and digitally. There's no physical shipment — you download the files right after payment and receive a backup link by email.

Do I get updates?

Yes. If we revise this toolkit, you're entitled to the updated version at no extra cost — just contact us with your order details.

What is your refund policy?

These are digital products, so once a toolkit has been downloaded we cannot take it back. If you have not downloaded yet, contact us and we will cancel the order and refund you in full. We also refund in full if the files are damaged, incomplete, or not what the product page described.

Cannot find your standard?

Tell us which scheme you work to. We will point you to the right toolkit.

Request a toolkit