4.1 Communication and Stakeholder Consultation

Key Takeaways

  • ISO 31000 positions communication and consultation as an iterative, continuous process that underpins every step of the risk management framework and process.
  • Stakeholder consultation differs fundamentally from one-way reporting; it requires establishing an ongoing dialogue to gather diverse perceptions, context, and specialized domain expertise.
  • Effective stakeholder mapping evaluates interest and power/influence to tailor engagement strategies (e.g., Manage Closely vs. Keep Informed).
  • Managing risk perception requires addressing psychological biases, transparently sharing uncertainty parameters, and establishing feedback loops to align organizational objectives with stakeholder expectations.
Last updated: July 2026

4.1 Communication and Stakeholder Consultation

In the ISO 31000:2018 Risk Management Guidelines, communication and consultation are not treated as isolated, peripheral activities or one-off administrative checks. Instead, they constitute an continuous, iterative hub surrounding every single phase of the risk management process—from defining scope, context, and criteria, through risk assessment and treatment, to ongoing monitoring, review, recording, and reporting.

Effective communication and consultation ensure that the risk management process is inclusive, customized, and informed by the best available information—directly reflecting several of ISO 31000's core risk management principles.


Defining Communication versus Consultation

For certification candidates and risk practitioners, distinguishing between communication and consultation is fundamental:

  • Communication: The process of promoting awareness, understanding, and alignment regarding risk, risk management processes, and risk decisions. Communication involves distributing relevant information to internal and external stakeholders through structured channels. While necessary, communication alone is predominantly a one-way transmission of information (e.g., issuing a corporate risk policy, releasing an annual risk disclosure, or broadcasting compliance instructions).
  • Consultation: A two-way dialogue and interactive process between an organization and its stakeholders. Consultation seeks to obtain feedback, gather diverse perspectives, understand varying values and risk perceptions, and incorporate specialized domain expertise prior to making a decision or determining a course of action. Consultation involves active listening, joint problem-solving, and transparent exchange.
AttributeCommunicationConsultation
Direction of FlowPrimarily One-Way (Sender to Receiver)Interactive Two-Way (Bi-directional Dialogue)
Core ObjectiveBuild awareness, inform, instruct, and reportGather input, evaluate perceptions, build alignment
Primary MechanismReports, policies, town halls, press releasesWorkshops, interviews, surveys, focus groups
TimingOngoing distribution and post-decision reportingPre-decision engagement and iterative feedback loops
ISO 31000 ValueEnsures transparency and clarity of expectationsEnriches risk context and improves decision quality

Internal versus External Stakeholder Landscapes

ISO 31000 emphasizes that risk exists in relation to organizational objectives, and objectives are held or impacted by diverse stakeholders. Stakeholders are any individuals, groups, or entities that can affect, be affected by, or perceive themselves to be affected by a decision or activity.

1. Internal Stakeholders

Internal stakeholders operate within the organizational boundary and possess direct influence over or exposure to daily operations:

  • Board of Directors & Audit/Risk Committees: Focus on strategic alignment, governance oversight, risk appetite boundaries, and legal accountability.
  • Executive Leadership (CEO, CRO, CFO): Focus on enterprise risk profile, resource allocation, strategic objective achievement, and business continuity.
  • Operational Managers & Department Heads: Focus on process-level risks, control design, resource constraints, and operational efficiency.
  • Frontline Employees: Possess granular, day-to-day insights into operational vulnerabilities, safety hazards, control workarounds, and cultural norms.
  • Internal Audit & Compliance Functions: Focus on independent assurance, control operating effectiveness, and regulatory compliance.

2. External Stakeholders

External stakeholders exist outside the organization's governance hierarchy but exert critical pressure or hold legitimate interests:

  • Regulators and Supervisory Bodies: Enforce statutory requirements, compliance standards, and industry guidelines.
  • Shareholders, Investors, and Lenders: Demand financial return, capital preservation, transparent risk reporting, and sound governance.
  • Customers and Clients: Expect product/service reliability, data privacy, safety, and ethical conduct.
  • Suppliers, Contractors, and Supply Chain Partners: Focus on commercial terms, operational continuity, counterparty risk, and contractual obligations.
  • Local Communities, NGOs, and Media: Focus on environmental sustainability, social responsibility, public safety, and corporate reputation.

Stakeholder Mapping and Analysis Frameworks

To optimize resources and ensure appropriate engagement, risk managers employ stakeholder mapping techniques during context establishment. The most widely utilized framework is Mendelow's Power versus Interest Grid, which categorizes stakeholders into four distinct quadrants based on their level of influence (Power) and level of concern (Interest).

High Power |  Keep Satisfied (B)    |  Manage Closely (A)
           |  (e.g., Regulators)    |  (e.g., Executive Board)
-----------+------------------------+------------------------
Low Power  |  Monitor (D)           |  Keep Informed (C)
           |  (e.g., General Public)|  (e.g., Frontline Staff)
           +------------------------+------------------------
                        Low Interest            High Interest

Engagement Strategies by Quadrant

  1. High Power / High Interest (Key Players - Quadrant A):
    • Strategy: Manage closely through intensive, direct consultation.
    • Actions: Conduct frequent one-on-one briefings, involve them in risk criteria design, and include them on steering committees.
  2. High Power / Low Interest (Context Setters - Quadrant B):
    • Strategy: Keep satisfied by addressing their specific constraints without overwhelming them with operational detail.
    • Actions: Provide regular compliance updates, executive summaries, and targeted risk disclosures to prevent them from becoming hostile or obstructive.
  3. Low Power / High Interest (Subjects - Quadrant C):
    • Strategy: Keep informed and actively consult on operational matters affecting them.
    • Actions: Utilize workshops, surveys, and advisory groups to harness their domain knowledge and secure buy-in for risk treatments.
  4. Low Power / Low Interest (Crowd - Quadrant D):
    • Strategy: Monitor with minimal resource expenditure.
    • Actions: Provide general public communications and monitor for shifts in their power or interest levels over time.

Managing Risk Perception and Cognitive Biases

Risk perception refers to how individuals subjectively process, interpret, and evaluate the severity and likelihood of risks. ISO 31000 recognizes that human and cultural factors significantly influence risk management. Differences in perception between internal experts and external stakeholders can lead to conflict, misaligned priorities, or flawed decision-making.

Key Psychological Drivers of Risk Perception

  • Voluntariness: Risks undertaken voluntarily (e.g., investing in R&D) are perceived as less threatening than risks imposed involuntarily (e.g., environmental pollution from a nearby plant).
  • Controllability: Risks over which individuals feel personal control are perceived as lower risk than risks controlled by third parties or automated systems.
  • Dread Factor: Risks associated with catastrophic, unfamiliar, or delayed consequences (e.g., nuclear failure, cyber attack) evoke higher dread than familiar, everyday risks (e.g., routine maintenance delays).

Cognitive Biases Impacting Consultation

  • Availability Heuristic: Stakeholders judge a risk's likelihood based on how easily recent or dramatic examples come to mind, leading to overestimating rare dramatic events and underestimating common routine risks.
  • Confirmation Bias: Stakeholders seek out information that validates their pre-existing beliefs while ignoring contrary empirical data.
  • Optimism Bias (Wishful Thinking): Operational teams underestimate the likelihood of project failure or cost overruns due to overconfidence in their capabilities.
  • Groupthink: Team members suppress dissenting views to maintain consensus during risk identification workshops.

Strategies for Perception Management

To manage risk perception effectively, risk managers must:

  1. Establish Objective Baselines: Present clear, empirical data and transparent uncertainty parameters rather than subjective assertions.
  2. Build Psychological Safety: Encourage open disclosure of vulnerabilities without fear of retribution or blame.
  3. Address Emotional Concerns: Acknowledge stakeholder fears, values, and cultural expectations directly during consultation.
  4. Iterative Feedback Loops: Demonstrate how stakeholder input directly shaped risk evaluation and treatment decisions.

Real-World Implementation Example: Medical Device Launch

A global healthcare enterprise is preparing to launch an AI-driven surgical robotics platform (ISO 31000 Risk Management Application):

  • Internal Consultation: The risk manager conducts cross-functional SWIFT (Structured What-If) workshops involving software engineers, clinical researchers, legal counsel, and regulatory specialists. Engineers identify algorithmic drift risks, while legal counsel highlights liability exposures.
  • External Consultation: The team engages in pre-submission dialogue with medical device regulators (FDA/EMA), surveys orthopedic surgeons (end-users), and holds focus groups with hospital risk managers to understand operational constraints.
  • Perception Alignment: Public perception regarding autonomous surgical tools is addressed through transparent safety trial reporting, human-in-the-loop safeguards, and comprehensive surgeon training programs.
Loading diagram...
ISO 31000 Communication and Consultation Interaction Model
Test Your Knowledge

According to ISO 31000:2018, what is the fundamental difference between communication and consultation during the risk management process?

A
B
C
D
Test Your Knowledge

A risk manager uses a Power vs. Interest matrix to analyze stakeholders for a major corporate restructuring. How should stakeholders identified as having 'High Power / High Interest' be managed under ISO 31000 stakeholder engagement guidelines?

A
B
C
D
Test Your Knowledge

During a risk assessment workshop, operational managers dismiss a high-impact supply chain risk because no major disruption has occurred in the past ten years. Which cognitive bias is directly distorting the team's risk perception?

A
B
C
D