"To be successful, risk management should function within a risk management framework which provides the foundations and organisational arrangements that will embed it throughout the organisation at all levels. [Such a 'framework'] should ensure that risk information derived from these processes is adequately reported and used as a basis for decision making and accountability at all relevant organisational levels."
- ISO 31000 (2009)
