Based on ISO 31000, does risk management apply to all levels of an organization or project?
JPL: Actually, according to ISO 31000, risk management applies to governance processes, strategy, planning, management, and reporting, as well as policies, values and the company’s culture as a whole. However, we have observed that with the financial crisis, risk management did not need the standard to make inroads into the corporate boards of Europe. However, ISO 31000 recommends the variation of all uncertainties at all functions, at all levels. Top managers at the highest level consider risks as serious consequences for strategy, and each operating level concentrates on their own risks that could affect strategy in order to optimize both its development and its execution. Certifiable standards are opened such as ISO 27000 for information security, ISO 28000 for the supply chain security or ISO 9000 for quality, etc. ISO 31000 brings them together: after laying the foundation, you build the roof. Did you experience any difficulties during the preparation of this standard? JPL: Divers