Overview
ISO 31022:2020 - Risk management - Guidelines for the management of legal risk - is an ISO guidance standard that complements ISO 31000 by giving practical recommendations for identifying, assessing, treating and monitoring legal risk. It is non-sector specific and can be customized to any organization and context. The standard helps organizations align legal risk activities with broader risk management and compliance processes to protect value, meet stakeholder expectations and support informed decision-making.
Key topics and requirements
ISO 31022 provides structured guidance rather than prescriptive obligations. Major topics covered include:
- Principles for managing legal risk consistent with ISO 31000.
- Establishing context and criteria (external and internal legal context; defining legal risk criteria).
- Legal risk assessment - systematic steps for identification, analysis and evaluation of legal risk.
- Legal risk treatment - selecting treatment options, evaluating current practices and implementing risk treatment plans.
- Communication, consultation and reporting - internal/external communication, learning, monitoring and review, recording and reporting.
- Implementation - policy development, roles and functions, integration with other management systems, resource allocation and awareness.
- Informative annexes with practical tools: Legal Risk Identification Matrix (LRIM), example legal risk register, matrices for estimating likelihood and consequences, and key contract clauses to review.
Keywords naturally associated with the standard: ISO 31022, legal risk management, ISO 31000 alignment, compliance, legal risk register, LRIM, contract review, risk treatment plan, monitoring and reporting.
Practical applications
ISO 31022 is designed to be applied practically across organizational functions to:
- Build a consistent, auditable approach to legal risk identification and assessment.
- Improve contract management by identifying contractual clauses and obligations that carry legal exposure.
- Integrate legal risk into enterprise risk management and compliance programs.
- Design treatment plans (controls, insurance, contract amendments, dispute prevention) and monitor their effectiveness.
- Support due diligence for transactions, new operations, market entry and regulatory change management.
Who uses this standard
Typical users include:
- In-house legal teams and external counsel
- Compliance officers and risk managers
- Senior management and boards overseeing governance and legal exposures
- Contract managers, procurement and business unit leaders
- SMEs and multinational organizations seeking a consistent legal risk framework
Related standards
- ISO 31000 - Risk management - Guidelines (primary framework to which ISO 31022 is aligned)
ISO 31022:2020 is a practical, adaptable guideline to strengthen legal risk oversight, improve compliance integration and support better-informed business decisions.