Nederlandse norm. NEN-ISO (en) Risk management - Principles and guidelines (ISO 31000:2009,IDT) ICS december 2009

Vergelijkbare documenten
Vervangt NEN-EN :2000 Ontw. Nederlandse norm. NEN-EN (en)

Voorbeeld. Preview INTERNATIONAL STANDARD ISO Glass containers Standard tolerances for bottles

Nederlandse voornorm NAD-NVN-ENV (nl)

Voorbeeld. Preview. NEN-IEC /A2 (en; fr) Wijzigingsblad. Nederlandse

Vervangt NEN 913:1963; NEN 913:1998 Ontw. Nederlandse norm. NEN 913 (nl) Melk en vloeibare melkproducten - Bepaling van de titreerbare zuurtegraad

Vervangt NEN-EN :1997; NEN-EN :1999 Ontw. Nederlandse norm. NEN-EN (en)

INTERNATIONAL STANDARD. Machine bridge reamers. Alésoirs de chaudronnerie, à machine

Voorbeeld. norm NEN-EN Preview. Ontwerp

Vervangt CR :1996; NEN-EN :2003 Ontw. Nederlandse norm. NEN-EN (en)

Voorbeeld. norm NEN-ISO Preview. Olie van Eucalyptus citriodora Hook (ISO 3044:1997) Nederlandse. Nederlands Normalisatie-instituut

Nederlandse norm. NEN-ISO 9462/A1 (en) Alpine ski-bindings - Requirements and test methods (ISO 9462:2006/Amd 1:2009,IDT) ICS

Nederlandse norm. NEN-ISO /A1 (en)

Nederlandse norm. NEN-EN (en)

Voorbeeld. norm NEN-ISO Preview

Voorbeeld. norm NEN-EN Preview. 2e Ontwerp

Voorbeeld. Preview ISO INTERNATIONAL STANDARD

Nederlandse norm. NEN-ISO 16039/A1 (en)

Vervangt NEN-EN 50182:1994 Ontw. Nederlandse norm. NEN-EN (en)

Nederlandse norm. NEN-EN (en) Lichtmasten - Deel 3-2: Ontwerp en verificatie - Verificatie door beproeving

Voorbeeld. Preview. NEN-ISO (en)

Nederlandse norm. NEN-ISO /A1 (en)

(en; fr) Matten van isolerend materiaal voor elektrotechnische doeleinden (IEC 61111:1992,MOD,IEC 61111:1992/C1:2000,MOD)

Voorbeeld. Preview. Dit document is een voorbeeld van NEN / This document is a preview by NEN

Nederlandse norm. NEN 3576 (nl) Beglazing van kozijnen, ramen en deuren Functionele eisen

Voorbeeld. Preview ISO 5208 INTERNATIONAL STANDARD. Industrial valves - Pressure testing of valves

Voorbeeld. Preview. NEN-ISO (en)

Voorbeeld. norm NEN-EN Preview. 2e Ontwerp

Nederlandse norm. NEN-ISO 16602/A1 (en)

oktober 2004 ICS Vervangt NEN-ISO 4730:1997/C1:1997; NEN-ISO 4730:1997

Nederlandse norm. NEN 6578 (nl) Water - Potentiometrische bepaling van het totale gehalte aan totaal fluoride

Voorbeeld. Preview ISO INTERNATIONAL STANDARD

Nederlandse norm. NEN-EN-ISO 4287 (en)

Voorbeeld. Preview. NEN-ISO/IEC /A1 (en) Wijzigingsblad

Voorbeeld. Preview. NEN-ISO 4149 (en)

Nederlandse norm. NEN 5087/A1 (nl) Inbraakveiligheid van woningen - Bereikbaarheid van dak- en gevelelementen: deuren, ramen en kozijnen

Nederlandse norm. NEN-ISO 7573 (en) Technical product documentation - Parts lists (ISO 7573:2008,IDT) Vervangt NEN-ISO 7573:1994

Soil - Investigation, sampling and analysis of asbestos in soil augustus 2006 ICS

NTA 2581 (nl) Opstellen van meetrapporten volgens NEN Nederlandse technische afspraak ICS ;

Voorbeeld. Preview. Dit document is een voorbeeld van NEN / This document is a preview by NEN

Nederlandse norm NEN Dit document mag slechts op een stand-alone PC worden geïnstalleerd. Gebruik op een netwerk is alleen.

Nederlandse norm. NEN-ISO /A1 (en)

Nederlandse praktijkrichtlijn. NPR-CLC/TR (en) Leidraad voor de toepassing van de Europese norm EN (NEN-EN 50160)

Road vehicles - Compressed natural gas (CNG) fuel system components - Part 14: Excess flow valve (ISO :2002,IDT) mei 2002 ICS

Nederlandse norm. NEN-ISO (en)

Motorcycle tyres and rims (metric series) - Part 3: Range of approved rim contours (ISO :1999/Amd 1:2002,IDT) maart 2002 ICS 43.

Passenger car tyres and rims - Part 2: Rims (ISO :2001,IDT) oktober 2001 ICS

Voorbeeld. Preview. NEN-ISO 6576 (en) Laurel (Laurus nobilis L.) - Whole and ground leaves - Specification (ISO 6576:2004,IDT)

Vervangt NEN-EN :2001. Nederlandse norm. NEN-EN (en)

Nederlandse norm. NEN-EN (en)

Voorbeeld. norm NEN 2559/A2 Onderhoud van draagbare blustoestellen. Preview. Wijzigingsblad

Voorbeeld. Preview. NEN-ISO 3140 (en) Oil of sweet orange (Citrus sinensis (L.) Osbeck), obtained by mechanical treatment (ISO 3140:2005,IDT)

Nederlandse norm. NEN 5754 (nl) Bodem - Berekening van het gehalte aan organische stof volgens de gloeiverliesmethode

Voorbeeld. norm. Preview. NEN-ISO/IEC 18004/C1 (en) Correctieblad

Voorbeeld. Preview. NEN-ISO (en)

Nederlandse praktijkrichtlijn NPR (nl) Evenementen - Hijs- en heftechniek - Veiligheidsfactoren voor hijs- en hefmiddelen

Voorbeeld. Preview. norm Gas cylinders - Seamless steel CO2 cylinders for fixed fire-fighting installations on ships (ISO 3500:2005,IDT)

Voorbeeld. Preview. Steel and steel products Inspection documents. Aciers et produits sidérurgiques Documents de contrôle. Second edition

Nederlandse norm. NEN-ISO 3065 (en)

Voorbeeld. Preview. NEN-ISO 8296 (en) Plastics - Film and sheeting - Determination of wetting tension (ISO 8296:2003,IDT)

Voorbeeld. Preview. NEN-ISO (en) Non-destructive testing of welds - Visual testing of fusion-welded joints (ISO 17637:2003,IDT)

Truck and bus tyres and rims (metric series) - Part 2: Rims (ISO :2001,IDT) januari 2002 ICS

Voorbeeld. Preview. norm. NEN-ISO/IEC /C2 (en) Correctieblad

Nederlandse norm NEN-IEC /A2. (en; fr)

Nederlandse norm. NEN /A1 (nl)

Nederlandse norm. NEN-ISO /A1 (en)

Voorbeeld. norm Etherische oliën - Ruwe of gerectificeerde Eucalyptus globulusolie (Eucalyptus globulus Labill.) (ISO 770:2002,IDT) Preview

Voorbeeld. Preview ISO 614 INTERNATIONAL STANDARD

Voorbeeld. Preview. NEN-EN-ISO (en) Dit document is een voorbeeld van NEN / This document is a preview by NEN. Nederlandse

Voorbeeld. Preview. NEN-ISO (en)

Voorbeeld. Preview. NEN-ISO (en) Nederlandse. Dit document is een voorbeeld van NEN / This document is a preview by NEN

Voorbeeld. Preview IS INTERNATIONAL STANDARD. Space data and information transfer systems - ASCII encoded English

Carbon fibre - Determination of density (ISO 10119:2002,IDT) augustus 2002 ICS

Nederlandse norm NEN-ISO (en)

Voorbeeld. norm. Preview. NEN-ISO/IEC15418(en)

Voorbeeld. Preview. Implants for surgery Metallic skeletal pins and wires. Part 1: General requirements

Voorbeeld. Preview NEN. NEN-IS0 6883(en)

Nederlandse norm NEN-ISO (en) Rubber, vulcanized - Determination of creep in compression or shear (ISO 8013:2012,IDT)

Voorbeeld. norm Wegvoertuigen - M14 x 1,25 bougies met een vlakke zitting en een 16 mm zeskant en hun behuizing in de cilinderkop (ISO 8470:2001,IDT)

HKZ-certificatieschema > zzp ers in zorg en welzijn

Vervangt NEN-EN :1998 Ontw.; NEN-EN 50061:1991,deels; NEN-EN 50061:1991/A1:1995,deels; NEN-EN 50061:1991/A1:1995/C1:1995,deels

Nederlandse norm. NEN 6702/A1 (nl) Technische grondslagen voor bouwconstructies - TGB Belastingen en vervormingen

Voorbeeld. norm. Preview. N Nederlands. NEN-ISO (en)

Voorbeeld. Preview ISO INTERNATIONAL STANDARD

Fire safety of larger fire compartments - Risk approach juni 2016 ICS

Vervangt NEN-EN :1994; NEN-EN :1994/Ontw. A1:1997. Nederlandse norm. NEN-EN (en)

Voorbeeld. norm. Preview. NEN-ISO (en)

Transcriptie:

Dit document mag slechts op een stand-alone PC worden geinstalleerd. Gebruik op een netwerk is alleen. toestaan als een aanvullende licentieovereenkomst voor netwerkgebruik met NEN is afgesloten. This document may only be used on a stand-alone PC. Use in a network is only permitted when a supplementary license agreement for us in a network with NEN has been concluded. Nederlandse norm NEN-ISO 31000 (en) Risk management - Principles and guidelines (ISO 31000:2009,IDT) ICS 03.100.01 december 2009

NEN-ISO 31000 Als Nederlandse norm is aanvaard: - ISO 31000:2009,IDT Normcommissie 400179 "Risicomanagement" Apart from exceptions provided by the law, nothing from this publication may be duplicated and/or published by means of photocopy, microfilm, storage in computer files or otherwise, which also applies to full or partial processing, without the written consent of the Netherlands Standardization Institute. The Netherlands Standardization Institute shall, with the exclusion of any other beneficiary, collect payments owed by third parties for duplication and/or act in and out of law, where this authority is not transferred or falls by right to the Reproduction Rights Foundation. Auteursrecht voorbehouden. Behoudens uitzondering door de wet gesteld mag zonder schriftelijke toestemming van het Nederlands Normalisatie-instituut niets uit deze uitgave worden verveelvoudigd en/of openbaar gemaakt door middel van fotokopie, microfilm, opslag in computerbestanden of anderszins, hetgeen ook van toepassing is op gehele of gedeeltelijke bewerking. Het Nederlands Normalisatie-instituut is met uitsluiting van ieder ander gerechtigd de door derden verschuldigde vergoedingen voor verveelvoudiging te innen en/of daartoe in en buiten rechte op te treden, voor zover deze bevoegdheid niet is overgedragen c.q. rechtens toekomt aan de Stichting Reprorecht. Although the utmost care has been taken with this publication, errors and omissions cannot be entirely excluded. The Netherlands Standardization Institute and/or the members of the committees therefore accept no liability, not even for direct or indirect damage, occurring due to or in relation with the application of publications issued by the Netherlands Standardization Institute. Hoewel bij deze uitgave de uiterste zorg is nagestreefd, kunnen fouten en onvolledigheden niet geheel worden uitgesloten. Het Nederlands Normalisatie-instituut en/of de leden van de commissies aanvaarden derhalve geen enkele aansprakelijkheid, ook niet voor directe of indirecte schade, ontstaan door of verband houdend met toepassing van door het Nederlands Normalisatie-instituut gepubliceerde uitgaven. 2009 Nederlands Normalisatie-instituut Postbus 5059, 2600 GB Delft Telefoon (015) 2 690 390, Fax (015) 2 690 190

NEN-ISO 31000:2009 INTERNATIONAL STANDARD ISO 31000 First edition 2009-11-15 Risk management Principles and guidelines Management du risque Principes et lignes directrices Reference number ISO 31000:2009(E) ISO 2009

ISO 31000:2009(E) NEN-ISO 31000:2009 PDF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobe's licensing policy, this file may be printed or viewed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading this file, parties accept therein the responsibility of not infringing Adobe's licensing policy. The ISO Central Secretariat accepts no liability in this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the General Info relative to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that the file is suitable for use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below. COPYRIGHT PROTECTED DOCUMENT ISO 2009 All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or utilized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either ISO at the address below or ISO's member body in the country of the requester. ISO copyright office Case postale 56 CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax + 41 22 749 09 47 E-mail copyright@iso.org Web www.iso.org Published in Switzerland ii ISO 2009 All rights reserved

NEN-ISO 31000:2009 ISO 31000:2009(E) Contents Foreword...iv Introduction...v 1 Scope...1 2 Terms and definitions...1 3 Principles...7 4 Framework...8 4.1 General...8 4.2 Mandate and commitment...9 4.3 Design of framework for managing risk...10 4.3.1 Understanding of the organization and its context...10 4.3.2 Establishing risk management policy...10 4.3.3 Accountability...11 4.3.4 Integration into organizational processes...11 4.3.5 Resources...11 4.3.6 Establishing internal communication and reporting mechanisms...12 4.3.7 Establishing external communication and reporting mechanisms...12 4.4 Implementing risk management...12 4.4.1 Implementing the framework for managing risk...12 4.4.2 Implementing the risk management process...13 4.5 Monitoring and review of the framework...13 4.6 Continual improvement of the framework...13 5 Process...13 5.1 General...13 5.2 Communication and consultation...14 5.3 Establishing the context...15 5.3.1 General...15 5.3.2 Establishing the external context...15 5.3.3 Establishing the internal context...15 5.3.4 Establishing the context of the risk management process...16 5.3.5 Defining risk criteria...17 5.4 Risk assessment...17 5.4.1 General...17 5.4.2 Risk identification...17 5.4.3 Risk analysis...18 5.4.4 Risk evaluation...18 5.5 Risk treatment...18 5.5.1 General...18 5.5.2 Selection of risk treatment options...19 5.5.3 Preparing and implementing risk treatment plans...20 5.6 Monitoring and review...20 5.7 Recording the risk management process...21 Annex A (informative) Attributes of enhanced risk management...22 Bibliography...24 Page ISO 2009 All rights reserved iii

ISO 31000:2009(E) NEN-ISO 31000:2009 Foreword ISO (the International Organization for Standardization) is a worldwide federation of national standards bodies (ISO member bodies). The work of preparing International Standards is normally carried out through ISO technical committees. Each member body interested in a subject for which a technical committee has been established has the right to be represented on that committee. International organizations, governmental and non-governmental, in liaison with ISO, also take part in the work. ISO collaborates closely with the International Electrotechnical Commission (IEC) on all matters of electrotechnical standardization. International Standards are drafted in accordance with the rules given in the ISO/IEC Directives, Part 2. The main task of technical committees is to prepare International Standards. Draft International Standards adopted by the technical committees are circulated to the member bodies for voting. Publication as an International Standard requires approval by at least 75 % of the member bodies casting a vote. Attention is drawn to the possibility that some of the elements of this document may be the subject of patent rights. ISO shall not be held responsible for identifying any or all such patent rights. ISO 31000 was prepared by the ISO Technical Management Board Working Group on risk management. iv ISO 2009 All rights reserved

NEN-ISO 31000:2009 ISO 31000:2009(E) Introduction Organizations of all types and sizes face internal and external factors and influences that make it uncertain whether and when they will achieve their objectives. The effect this uncertainty has on an organization's objectives is risk. All activities of an organization involve risk. Organizations manage risk by identifying it, analysing it and then evaluating whether the risk should be modified by risk treatment in order to satisfy their risk criteria. Throughout this process, they communicate and consult with stakeholders and monitor and review the risk and the controls that are modifying the risk in order to ensure that no further risk treatment is required. This International Standard describes this systematic and logical process in detail. While all organizations manage risk to some degree, this International Standard establishes a number of principles that need to be satisfied to make risk management effective. This International Standard recommends that organizations develop, implement and continuously improve a framework whose purpose is to integrate the process for managing risk into the organization's overall governance, strategy and planning, management, reporting processes, policies, values and culture. Risk management can be applied to an entire organization, at its many areas and levels, at any time, as well as to specific functions, projects and activities. Although the practice of risk management has been developed over time and within many sectors in order to meet diverse needs, the adoption of consistent processes within a comprehensive framework can help to ensure that risk is managed effectively, efficiently and coherently across an organization. The generic approach described in this International Standard provides the principles and guidelines for managing any form of risk in a systematic, transparent and credible manner and within any scope and context. Each specific sector or application of risk management brings with it individual needs, audiences, perceptions and criteria. Therefore, a key feature of this International Standard is the inclusion of establishing the context as an activity at the start of this generic risk management process. Establishing the context will capture the objectives of the organization, the environment in which it pursues those objectives, its stakeholders and the diversity of risk criteria all of which will help reveal and assess the nature and complexity of its risks. The relationship between the principles for managing risk, the framework in which it occurs and the risk management process described in this International Standard are shown in Figure 1. When implemented and maintained in accordance with this International Standard, the management of risk enables an organization to, for example: increase the likelihood of achieving objectives; encourage proactive management; be aware of the need to identify and treat risk throughout the organization; improve the identification of opportunities and threats; comply with relevant legal and regulatory requirements and international norms; improve mandatory and voluntary reporting; improve governance; improve stakeholder confidence and trust; ISO 2009 All rights reserved v

ISO 31000:2009(E) NEN-ISO 31000:2009 establish a reliable basis for decision making and planning; improve controls; effectively allocate and use resources for risk treatment; improve operational effectiveness and efficiency; enhance health and safety performance, as well as environmental protection; improve loss prevention and incident management; minimize losses; improve organizational learning; and improve organizational resilience. This International Standard is intended to meet the needs of a wide range of stakeholders, including: a) those responsible for developing risk management policy within their organization; b) those accountable for ensuring that risk is effectively managed within the organization as a whole or within a specific area, project or activity; c) those who need to evaluate an organization's effectiveness in managing risk; and d) developers of standards, guides, procedures and codes of practice that, in whole or in part, set out how risk is to be managed within the specific context of these documents. The current management practices and processes of many organizations include components of risk management, and many organizations have already adopted a formal risk management process for particular types of risk or circumstances. In such cases, an organization can decide to carry out a critical review of its existing practices and processes in the light of this International Standard. In this International Standard, the expressions risk management and managing risk are both used. In general terms, risk management refers to the architecture (principles, framework and process) for managing risks effectively, while managing risk refers to applying that architecture to particular risks. vi ISO 2009 All rights reserved

NEN-ISO 31000:2009 ISO 31000:2009(E) a) Creates value b) Integral part of organizational processes c) Part of decision making d) Explicitly addresses uncertainty e) Systematic, structured and timely f) Based on the best available information g) Tailored h) Takes human and cultural factors into account i) Transparent and inclusive j) Dynamic, iterative and responsive to change k) Facilitates continual improvement and enhancement of the organization Continual improvement of the framework (4.6) Mandate and commitment (4.2) Design of framework for managing risk (4.3) Monitoring and review of the framework (4.5) Implementing risk management (4.4) Establishing the context (5.3) Risk assessment (5.4) Risk identification (5.4.2) Risk analysis (5.4.3) Communication and consultation (5.2) Monitoring and review (5.6) Risk evaluation (5.4.4) Risk treatment (5.5) Principles Framework (Clause 3) (Clause 4) Process (Clause 5) Figure 1 Relationships between the risk management principles, framework and process ISO 2009 All rights reserved vii

Bestelformulier Stuur naar: NEN Standards Products & Services t.a.v. afdeling Klantenservice Antwoordnummer 10214 2600 WB Delft NEN Standards Products & Services Postbus 5059 2600 GB Delft Vlinderweg 6 2623 AX Delft Ja, ik bestel ex. NEN-ISO 31000:2009 en Risicomanagement - Principes en richtlijnen 106.87 T (015) 2 690 390 F (015) 2 690 271 www.nen.nl/normshop Wilt u deze norm in PDF-formaat? Deze bestelt u eenvoudig via www.nen.nl/normshop Gratis e-mailnieuwsbrieven Wilt u op de hoogte blijven van de laatste ontwikkelingen op het gebied van normen, normalisatie en regelgeving? Neem dan een gratis abonnement op een van onze e-mailnieuwsbrieven. www.nen.nl/nieuwsbrieven Gegevens Bedrijf / Instelling T.a.v. O M O V E-mail Klantnummer NEN Uw ordernummer BTW nummer Postbus / Adres Postcode Plaats Telefoon Fax Factuuradres (indien dit afwijkt van bovenstaand adres) Postbus / Adres Postcode Plaats Datum Handtekening Retourneren Fax: 015 2 690 271 E-mail: klantenservice@nen.nl Post: NEN Standards Products & Services, t.a.v. afdeling Klantenservice Antwoordnummer 10214, 2600 WB Delft (geen postzegel nodig). Voorwaarden De prijzen zijn geldig tot 31 december 2018, tenzij anders aangegeven. Alle prijzen zijn excl. btw, verzend- en handelingskosten en onder voorbehoud bij o.m. ISO- en IEC-normen. Bestelt u via de normshop een pdf, dan betaalt u geen handeling en verzendkosten. Meer informatie: telefoon 015 2 690 391, dagelijks van 8.30 tot 17.00 uur. Wijzigingen en typefouten in teksten en prijsinformatie voorbehouden. U kunt onze algemene voorwaarden terugvinden op: www.nen.nl/leveringsvoorwaarden. LEREN, WERKEN EN GROEIEN MET NEN preview - 2018