Fundamentals · ISO 31000 as guidance
Most risk registers stop at the factory gate.
Companies track market, financial, people and IT risk – but dependence on a single supplier rarely appears, although it halts operations faster than anything else.
Risk management describes how an organisation handles uncertainty: identify, assess, treat, monitor and report. ISO 31000 provides an internationally recognised framework – guidance without certification, deliberately broad.
In practice two separate worlds emerge. Enterprise risk management works with a matrix and an annual cycle; supplier management works with certificates and evaluations. They are rarely connected, although each is incomplete without the other: a supplier failure is an enterprise risk, and it can only be spotted where the supplier data lives.
What a risk register misses
- Single sources without a qualified alternative – usually parked as “a purchasing matter”.
- Hidden concentration: several suppliers, one shared upstream source.
- Providers with system access who appear on no procurement list.
- Regulatory risk arriving through customer contracts rather than statutes.
The cycle
- Identify
- Collect risks systematically, not only those someone happens to think of.
- Assess
- Likelihood and impact – with described levels, not by instinct.
- Treat
- Avoid, reduce, transfer or consciously carry – the last option belongs on record.
- Monitor
- Risks change; an annual look is not enough for fast-moving ones.
- Report
- Present to management in a form that permits decisions.
Where SCRM fits in
Supplier risk with data
Criticality, incidents and deadlines as the basis rather than an estimate.
Dependencies visible
Hidden concentration becomes apparent before it becomes an outage.
Actions with deadlines
Treatment as a task with an owner, not a line in a matrix.
Board view
One page for the meeting: what is open, what is due, what has changed.
Frequently asked
Does an SME need formal risk management?
Not an elaborate one. But a list of the risks that could seriously disrupt operations, with a measure and an owner – that is manageable and required by most standards anyway.
Is ISO 31000 certifiable?
No, it is guidance. What gets certified are management systems such as ISO 9001 or ISO 27001, which themselves require risk-based thinking.
How often should risks be reassessed?
At the speed of the risk. A sanctions exposure can change in days, a site risk in years. One uniform annual cycle is wrong for both.