Cyber risk, feeding enterprise risk — not replacing it.
ISO 31000 is the risk standard for everything. It sets out principles, a framework and a process for managing risk of any kind across an entire organization — financial, operational, strategic, reputational — and it does so without prescribing a method, a scoring scale or a template. It is guidance, not a certifiable standard. What it gives a board is a common language for risk that does not belong to any one department.
Cyber risk tends to arrive at that table speaking a different language. It is scored on a scale nobody else uses, owned by a function nobody else reports to, and presented in a format the audit committee has to translate. The result is that the largest operational risk most organizations carry is the one least legible to the people who are supposed to own it.
Who it applies to
Any organization that wants a single risk framework rather than several — which in practice means the board, the audit and risk committee, and the enterprise risk function that reports to them. It is sector-neutral by design. Cyber and AI risk do not get their own standard here; they get a seat in the same register as everything else.
Cyber risk as an input, not an island
TruSecure is not an enterprise risk management platform and does not pretend to be. What it does is structure cyber and AI risk so it can be fed upward into a 31000-aligned enterprise framework without translation: the same likelihood and consequence language, the same ownership model, the same review discipline, and a treatment that is tied to a control someone can inspect. An ISO 27005 register is, structurally, a 31000 register scoped to information security — so a cyber risk that is well-formed for 27005 arrives at the enterprise register already in the right shape. The board sees one register. The security team still owns its part of it.
What it asks, in operating terms
Read as an operating requirement rather than a principles document, 31000 reduces to a handful of standing asks of any risk that wants to sit in the enterprise register.
| What 31000 asks | Where it is answered |
|---|---|
| Risk integrated into governance, not bolted on | Governance workspace · owners, review dates, board pack |
| One risk language across the organization | Risk register · criteria configurable to the enterprise scale |
| Cyber and AI risk legible to non-specialists | Board reporting · every figure drills to its source |
| Treatment that is owned and evidenced | Control library · treatment tied to an inspectable control |
| Continual review as context changes | Review triggers · event-driven, not calendar-driven |
What you'd actually look at
In the dashboard, every figure opens on click to the risk, the control and the person behind it. This excerpt is what the enterprise feed is made of:
- Risks exported to ERM
- 11 · top tier only, by agreed criteria
- Scale
- mapped to the enterprise 5x5 · no translation step
- Owners
- named · each risk has one
- Treatment evidenced
- 11/11 · control linked
- Last board pack
- generated · drills to source
Where teams usually start
With a demo walked through by TruSecure — your cyber and AI risks shown on the scale your enterprise register already uses, a single risk opened to its treatment and its control, the board pack a non-specialist can read and drill into. A Resilience Sprint then produces the first baseline; the subscription keeps it current. Packaging is scoped in the conversation, not a price list.
TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.
The short answer
ISO 31000 provides general risk management principles applicable across an entire enterprise. TruSecure structures its cyber and AI risk register to feed into a 31000-aligned enterprise risk framework; it is not itself a full enterprise risk management platform.