Table of Contents
ToggleKey takeaways
- Two standards, two jobs. ISO 31000 supplies the risk methodology. ISO 37301 is a management system standard (MSS) that sets auditable requirements and can be certified against.
- Compliance risk is not a separate species. Assess it with the same matrix, rating definitions and vocabulary you use for strategic, operational and safety risk.
- The integration is designed in, not bolted on. ISO 37301 clauses map cleanly onto the ISO 31000 process, from obligations and risk assessment through to monitoring, review and improvement.
- One register, one control library, one reporting line. Two registers running two methodologies with no reconciliation is the arrangement to avoid.
- Six steps, not six years. Obligations inventory, shared methodology, obligation to risk to control mapping, register consolidation, unified monitoring, then independent review and a certification decision.
- Australian context decides the urgency. PGPA duties, Local Government Acts, aged care and NDIS standards and education regulators make the case strongest, and data sovereignty is now a procurement requirement.
Most organisations run risk management and compliance as two separate systems. The risk team maintains an enterprise risk register. The compliance team maintains its own register of obligations and breaches, often in a different tool, with different terminology and a different reporting line. Twice a year, someone tries to reconcile the two for a board paper, and the numbers never quite line up.
This is not a tooling problem. It is an operating model problem, and it is exactly the problem that ISO 31000 and ISO 37301 were designed to solve together. ISO 31000 provides the methodology for managing any kind of risk. ISO 37301 applies that methodology to one specific category of risk: the risk of failing to meet your compliance obligations. Used properly, the two standards describe one system, not two.
This guide explains how the standards fit together and, more importantly, how to run them as a single integrated system: one methodology, one register, one reporting line. It is written for risk and compliance practitioners in Australian organisations, particularly those in regulated sectors where governance, risk and compliance obligations are heaviest.
ISO 31000 and ISO 37301 in brief
Before integrating the standards, it helps to be precise about what each one is, and is not.
ISO 31000:2018, the risk management foundation
ISO 31000:2018 is the international standard for risk management. It is built on three components: a set of principles that define what good risk management looks like, a framework that embeds risk management into governance and decision-making, and a process for identifying, analysing, evaluating and treating risk.
Two things about ISO 31000 are widely misunderstood.
First, it is guidance, not a certifiable standard. You cannot be “ISO 31000 certified”, and any provider suggesting otherwise should be treated with caution. The standard exists to be adopted and adapted, not audited against.
Second, ISO 31000 does not ask you to build a standalone risk system. The 2018 revision is explicit that risk management should be integrated into the structures, processes and decision-making the organisation already has. In Australia, the standard is adopted domestically as AS ISO 31000, and it underpins most public sector risk frameworks, which is why it is the natural methodological backbone for risk management software used by councils, agencies and regulated providers.
ISO 37301:2021, the compliance management system standard (MSS)
ISO 37301:2021 is the international standard for compliance management systems. It replaced ISO 19600:2014 in April 2021 and was amended in 2024. Where its predecessor only offered recommendations, ISO 37301 is a management system standard (MSS): it sets auditable requirements, and organisations can be independently certified against it.
The standard is organised around a simple chain. An organisation identifies its compliance obligations, which include laws, regulations, permits, contracts, industry codes and its own policies. It then assesses the risk of failing to meet each obligation, designs controls proportionate to that risk, and monitors, reviews and improves the system continuously. Leadership commitment and compliance culture run through the entire standard, because a compliance management system that exists only on paper fails the moment it is tested.
The practical significance of certifiability is easy to miss. Certification puts compliance on the same auditable footing as quality (ISO 9001) or information security (ISO 27001). For boards and regulators, it turns “we take compliance seriously” from a claim into evidence. At Skefto our compliance management software aligns with ISO 37301. The guidance in this article reflects our experience in using the standard to improve compliance systems for our customers.
The two standards at a glance
| ISO 31000:2018 | ISO 37301:2021 | |
|---|---|---|
| Purpose | Guidelines for managing risk of any kind | Requirements for a compliance management system |
| Certifiable | No, guidance only | Yes, certification is available against its requirements |
| Scope | All risk categories: strategic, operational, safety, financial, compliance | Compliance obligations and compliance risk |
| Structure | Principles, framework, process | Harmonized Structure (clauses 4 to 10) |
| Typical owner | Risk function | Compliance function |
| Predecessor | ISO 31000:2009 | ISO 19600:2014 |
| Role in an integrated system | Provides the risk methodology | Applies that methodology to obligations, adds requirements |
ISO 31000 and ISO 37301 compared.
Where the standards meet
Integration between the two standards is not a workaround. It is designed in, at two levels.
The first level is structural. ISO 37301 follows the Harmonized Structure (formerly the High-Level Structure, or Annex SL), the common skeleton shared by modern ISO management system standards: context of the organisation, leadership, planning, support, operation, performance evaluation and improvement. If your organisation already operates a management system for quality, safety or information security, a compliance management system slots into the same document control, audit cycle and management review machinery. You do not rebuild the scaffolding.
The second level is methodological, and this is the one that matters most for practitioners. ISO 37301 requires a compliance risk assessment: you must identify your obligations, assess what happens if you fail to meet them, and prioritise controls accordingly. The standard does not invent a new way of assessing risk for this purpose. It leans on the methodology ISO 31000 already provides. In other words, ISO 31000 supplies the how, and ISO 37301 supplies a specific and non-negotiable what.
The mapping between the two is remarkably clean:
| ISO 37301 requirement | ISO 31000 counterpart | What it means in practice |
|---|---|---|
| Compliance obligations (clause 4.5) | Scope, context and criteria (6.3) | Your obligations inventory defines the context and criteria for compliance risk |
| Compliance risk assessment (clause 4.6) | Risk assessment (6.4) | Identify, analyse and evaluate non-compliance risks using the same method as every other risk |
| Leadership and compliance policy (clause 5) | Leadership and commitment (5.2), integration (5.3) | One governance mandate covers both disciplines |
| Planning and compliance objectives (clause 6) | Framework design (5.4) | Risk and compliance objectives are set in the same planning cycle |
| Operation and controls (clause 8) | Risk analysis (6.4.3) | Compliance controls and their effectiveness should be assessed when analysing risks |
| Performance evaluation (clause 9) | Monitoring and review (6.6) | One monitoring cadence, one management review |
| Improvement and nonconformity (clause 10) | Continual improvement principle | Breaches and audit findings feed back into the register |
How ISO 37301 requirements map to the ISO 31000 risk management process.
The table is worth internalising because it dissolves the most common turf argument in GRC: whether risk or compliance “owns” compliance risk. The standards answer it. The risk function owns the methodology, because consistency of method across all risk categories is the entire point of ISO 31000. The compliance function owns the obligations and the consequence mapping, because knowing what the law requires and what a breach triggers is specialist knowledge. This division sits comfortably within the three lines model, and neither function owns the whole; the system does.

One caution: a shared structure makes integration possible, not automatic. Plenty of organisations hold ISO certifications across multiple standards and still run their registers, controls and reports in silos.
Structure enables integration. Only the operating model delivers it.
Compliance management
Obligations, compliance risks and controls held as linked records, assessed with one methodology. The mapping above stops being a diagram and starts being evidence you can show an auditor.
Explore our compliance software→The integrated operating model
An integrated system has four working parts.
One methodology and one vocabulary
The organisation adopts a single risk methodology, based on ISO 31000, with one likelihood and consequence matrix, one set of rating definitions anchored to the organisation’s risk appetite, and one risk assessment process. Compliance risks are assessed with exactly the same method as strategic, operational and safety risks. The moment compliance invents its own 4×4 matrix while risk uses a 5×5, board reporting becomes an exercise in translation.
One register, category-tagged
Our recommended default is a single enterprise risk register in which compliance risk is a category, not a separate universe. Each compliance risk links back to the specific obligations that generate it, held in an obligations register that the compliance function maintains. The obligations register answers “what must we comply with”; the risk register answers “where could we fail, how badly, and what are we doing about it”.
This is a recommendation, not a law of nature. There are legitimate exceptions. Organisations under prudential-style regulation, or those with very large obligation inventories and a mature standalone compliance function, sometimes run a dedicated compliance risk register that rolls up into the enterprise view. That model can work, provided the methodology, rating scales and reporting lines remain shared. What does not work is two registers with two methodologies and no reconciliation, which is the arrangement most organisations drift into by accident.
One control library
Controls are recorded once and mapped to every risk and every obligation they serve. A staff training program might treat a safety risk, satisfy an obligation under WHS legislation, and support a compliance objective at the same time. In a siloed model that control is documented three times and tested three times. In an integrated model it is documented once, tested once, and the evidence satisfies every framework that relies on it. This is where integration stops being an elegant idea and starts saving real audit hours.
One monitoring and reporting line
Performance evaluation under ISO 37301 and monitoring and review under ISO 31000 collapse into a single cadence: one schedule of control testing and internal audit, one management review, one board or audit and risk committee report that presents compliance risk alongside every other risk category in the same language. This is the arrangement that supports enterprise risk management in the true sense: the board sees the whole risk landscape at once, not two partial views that never reconcile.

Risk management
One register, one control library, one reporting line. See what the integrated operating model looks like when a single platform carries it, built for Australian regulated sectors.
Learn about our risk software→A six-step integration roadmap

Integration is achievable in a structured program of a few months, not a multi-year transformation. The sequence matters more than the speed.
Build the obligations inventory
The compliance function catalogues every obligation: legislation, regulations, licences, funding agreements, contracts, industry codes and internal policies. Each obligation records its source, its owner, and what a breach would trigger. This inventory becomes the context and criteria for everything that follows. Most organisations discover during this step that their real obligation count is two to three times what anyone had written down.
Adopt one methodology and one vocabulary
Agree a single risk matrix, single rating definitions and single terminology across risk and compliance. This step is more political than technical. Run it as a joint workshop with both functions and get executive sign-off on the result, because the methodology decision fails if it is imposed by one function on the other.
Map obligations to risks and controls
For each material obligation, identify the ways the organisation could fail to meet it, assess those failure scenarios with the shared methodology, and map the controls that treat them. Prioritise ruthlessly: a regional council with obligations spanning its Local Government Act, procurement rules, planning law and WHS legislation cannot deep-dive everything at once, and does not need to. Start with the obligations where breach consequences are severe or regulator attention is active.
Consolidate registers
Migrate compliance risks into the enterprise register as a tagged category, linked back to the obligations register. Retire the spreadsheet copies. A typical aged care provider might arrive at this step with one register for clinical risk, one for compliance against the Aged Care Quality Standards, and one enterprise register that mentions neither; consolidation is the moment the organisation sees its true exposure in one place for the first time.
Unify monitoring, review and reporting
Build one calendar of control testing, internal audit and management review that serves both standards. Redesign the board pack so compliance risk appears inside the enterprise risk report, in the same format, rather than as a separate compliance attachment nobody connects to the risk pages.
Review the framework and decide certification scope
With the integrated system running, commission an independent review of the framework against both standards, then decide whether ISO 37301 certification is worthwhile. For a university facing TEQSA requirements, research compliance and WHS duties, certification may be a strategic signal to regulators and council.
For a smaller provider, conformance without certification may be enough. Be aware that certifying only a slice of the organisation is rarely practical, because compliance obligations cut across the whole entity; scope decisions should be made with that reality in view. An independent framework review at this stage catches design gaps far more cheaply than a failed certification audit does.
Considerations for Australian regulated sectors
The integration case is strongest in sectors where compliance obligations are dense, public and actively enforced. Australia has several.
Commonwealth entities
operate under the PGPA Act, which places a positive duty on accountable authorities to establish appropriate systems of risk oversight, management and internal control. The Commonwealth Risk Management Policy that supports it is aligned to ISO 31000, which means an integrated system built on the model in this article is not just compatible with Commonwealth requirements, it is the natural implementation of them. The compliance load these entities carry is covered in more depth in our guide to the PGPA Act and its strategic challenges.
Local government
faces a compounding obligation set: the relevant state Local Government Act, procurement and tendering rules, planning and environmental law, WHS duties and, in several states, mandated audit and risk committees. Councils typically run lean risk teams, which makes duplicated risk and compliance effort more painful for them than for anyone else. The sector context is covered in our article on Local Government Act challenges.
Aged care and disability providers
answer to the Aged Care Quality and Safety Commission and the NDIS Commission respectively, and both regimes explicitly require risk management as part of provider governance. The strengthened Aged Care Quality Standards make organisational governance, including risk and incident management systems, a directly assessable standard. For these providers, an integrated system is not an efficiency play; it is close to a regulatory expectation.
Education providers,
from schools to TAFEs and universities, sit under sector regulators, child safety obligations, WHS law and, for universities, research integrity and foreign interference requirements. The obligation mix is broad rather than deep, which is precisely the profile where a single obligations-to-risks-to-controls chain prevents things falling between functional cracks.
Across all four sectors there is one further consideration: data sovereignty. Risk and compliance registers contain some of the most sensitive governance information an organisation holds, and Australian public sector and care sector buyers increasingly require that it stays onshore in certified infrastructure.
Operationalising the integrated system
Everything in this article can be done in spreadsheets, and step one of any integration program usually is. But the model has moving parts that spreadsheets handle badly: obligations linked to risks, risks linked to controls, controls linked to test evidence, and all of it feeding a live reporting layer. Once the volume passes a few hundred obligations and risks, the links are the system, and spreadsheets cannot maintain links at that scale.
If you are evaluating software to carry the integrated model, the criteria follow directly from the operating model above:
- A single register architecture with category tagging rather than separate risk and compliance modules that do not talk to each other
- Obligations, risks and controls held as linked records, not parallel lists
- A full audit trail on every change, because your register is evidence in any regulatory review
- Monitoring and review workflows with ownership and due dates
- Board-ready reporting that presents compliance risk inside the enterprise view
Skefto was built for exactly this model, for exactly these sectors. Risk, compliance, obligations, controls and reporting operate on one platform, data is hosted in government-certified Australian data centres, and the platform aligns with ISO 37301 while the organisation behind it is certified against ISO 27001, so the system reflects the standards from the inside. If you want to see the integrated model running rather than read about it, book a demo.
Frequently asked questions
No. ISO 31000 is a guidance standard. Organisations adopt it and align to it, but there is no accredited certification against it. ISO 37301, by contrast, is a management system standard (MSS) that organisations can be certified against.
You need one methodology and one obligations discipline, and the standards supply one each. Formally adopting ISO 31000 and implementing ISO 37301 is the cleanest way to get both, but the value comes from the integrated operating model, not from citing two standard numbers in your policy.
ISO 37301 replaced ISO 19600 in 2021. The decisive change is that ISO 19600 offered only guidance, while ISO 37301 sets auditable requirements and supports third-party certification. Organisations still referencing ISO 19600 in their compliance frameworks are working from a withdrawn standard.
Our recommended default is no: hold compliance risk as a category within the enterprise risk register, linked to a separate obligations register. A dedicated compliance risk register can be justified in heavily regulated environments with mature standalone compliance functions, provided methodology and reporting remain shared. Two registers with two methodologies is the arrangement to avoid.
Yes. All three follow the Harmonized Structure, so document control, internal audit and management review can run as one machinery across quality, information security and compliance. ISO 37301 then manages the obligations dimension that the other standards touch only within their own scope.
Technically a certification scope can be limited, but in practice partial scoping is difficult because compliance obligations cut across the whole entity. Artificially fencing off business units tends to create boundaries the auditor will challenge and the regulator will ignore. Most organisations are better served certifying the whole entity or deferring certification until they can.