Overview
ISO/TS 31050:2023 - Risk management - Guidelines for managing an emerging risk to enhance resilience - is a Technical Specification (first edition, 2023) that complements ISO 31000. It provides guidance for identifying, assessing and managing emerging risks - new or evolving threats and opportunities characterized by limited data and high uncertainty - with the aim of improving organizational resilience. The document is applicable to any organization, at any stage and can be customized to different contexts.
Key topics and technical requirements
The specification focuses on practical, knowledge-driven risk management under uncertainty. Key topics include:
- Nature and characterization of emerging risks
- Newness, limited verifiable data, measurement and time dimensions, volatility and development pathways.
- Principles (how to apply ISO 31000 to emerging risks)
- Integrated, structured and comprehensive, customized, inclusive, dynamic, best-available information, human and cultural factors, continual improvement.
- Risk management process
- Apply ISO 31000 steps specifically for emerging risks: communication and consultation; defining scope, context and risk criteria; risk assessment (identification, analysis, evaluation); risk treatment; monitoring and review; recording and reporting.
- Enhancing resilience
- Capability development, resilience indicators and alignment of treatments to improve absorption, adaptation and recovery.
- Risk intelligence and knowledge cycle
- Gathering data, converting data to information and knowledge, creating intelligence to support strategic, tactical and operational decisions.
- Supporting materials (informative annexes)
- Examples of context changes, templates for emerging risk descriptions and resilience indicators, systemic risks, and a knowledge/risk intelligence cycle.
Practical applications and users
ISO/TS 31050:2023 is designed for organizations that need to anticipate and manage risks that are:
- Novel, rapidly evolving or poorly understood
- Likely to have significant consequences for objectives or operations
Primary users include:
- Risk managers and enterprise risk management (ERM) teams
- Organizational resilience and business continuity professionals
- Senior leaders and boards for strategic decision‑making
- Security, compliance and operational teams integrating emerging-risk monitoring
- Consultants and auditors advising on risk frameworks
Benefits include earlier detection of signals, improved preparedness, better stakeholder communication and more resilient decision-making.
Related standards
- ISO 31000 - Risk management - Guidelines (core framework)
- ISO 22316 - Organizational resilience - Principles and attributes
- ISO 22300 - Security and resilience - Vocabulary
- IEC 31010 - Risk management - Risk assessment techniques
Keywords: ISO/TS 31050:2023, emerging risks, risk management, ISO 31000, organizational resilience, risk intelligence, resilience indicators.