پژوهش‌نامه حقوق اسلامی

پژوهش‌نامه حقوق اسلامی

مروری بر مفهوم، اصول و فرایند ناظر بر مدیریت «ریسک حقوقی» مبتنی بر استاندارد بین‌المللی ISO 31022 با تطبیق در نظام حقوقی ایران

نوع مقاله : مقاله مروری

نویسندگان
1 دانش‌آموخته کارشناسی ارشد حقوق خصوصی، دانشکده معارف اسلامی و حقوق، دانشگاه امام صادق علیه‌السلام، تهران، ایران.
2 استادیار، گروه حقوق خصوصی، دانشکده معارف اسلامی و حقوق، دانشگاه امام صادق علیه‌السلام، تهران، ایران.
چکیده
ریسک‌های‌حقوقی به‌عنوان اثر عدم‌قطعیت‌های حقوقی بر اهداف سازمان، در زمره مهم‌ترین ریسک‌هایی قرار دارند که می‌توانند مشروعیت فعالیت سازمان را مخدوش کرده، هزینه‌های حقوقی بر آن تحمیل یا حتی در مواردی فرصت‌هایی را جهت خلق ارزش برای سازمان ایجاد نمایند. این مقاله با هدف مفهوم‌شناسی «ریسک حقوقی» و تبیین اصول و فرایند ناظر بر مدیریت آن، بر مبنای استاندارد ایزو ۳۱۰۲۲، و بررسی جایگاه مدیریت ریسک حقوقی در سیستم حقوقی ایران نگارش یافته است. استاندارد مذکور، با ارائه چارچوبی جامع برای مدیریت ریسک‌های حقوقی، اصولی شامل یکپارچه‌سازی، رویکرد ساختاریافته و جامع، انطباق‌پذیری، شمول‌گرایی، پویایی، دسترسی به اطلاعات، عوامل انسانی و فرهنگی، بهبود مستمر و انصاف را به‌همراه فرایندی نظام‌مند، متشکل از شناسایی، تحلیل، ارزیابی و مقابله با ریسک ترسیم می‌کند که ثبات و پایداری سازمان را در فعالیت‌های حقوقی تضمین می‌کند؛ این نوشتار ضمن تبیین این مفاهیم، با روش توصیفی تحلیلی به جایگاه مدیریت ریسک حقوقی در سیستم حقوقی ایران می‌پردازد. یافته‌ها نشان می‌دهد که این مفهوم در سیستم حقوقی ایران یک رویکرد واکنشی است که در حال دگرگون شدن است، در سطح نظری نیز با خلط میان مدیریت حقوقی ریسک و مدیریت ریسک حقوقی مواجه بوده، و در سطح قانونی نیز، با خلأ الزامات تنظیم‌گرایانه روبرو است. با این همه، مبانی مسئولیت مدنی، به‌ویژه مفهوم تقصیر و رفتار متعارف، بستر حقوقی بالقوه‌ای را برای پذیرش ضرورت پیاده سازی نظام مدیریت ریسک حقوقی در سازمان فراهم می‌کند.
واژگان کلیدی
موضوعات

عنوان مقاله English

A Review of the Concept, Principles, and Process Governing 'Legal Risk' Management Based on the International Standard ISO 31022, with Adaptation to the Iranian Legal System

نویسندگان English

Mohammad Mahdi Fattahian 1
Taher Habibzadeh 2
1 LLM in Private Law, Faculty of Islamic Studies and Law, Imam Sadiq University, Tehran, Iran.
2 Assistant Professor, Department of Private Law, Faculty of Islamic Studies and Law, Imam Sadiq University, Tehran, Iran.
چکیده English

 ‌Context & Objective: Legal risks, defined as the effects of legal uncertainties on organizational objectives, are among the most critical threats and opportunities facing modern entities. They manifest across contractual, compliance, regulatory, intellectual property, and third-party liability domains, possessing the potential to compromise organizational legitimacy, impose severe financial burdens, or concurrently create avenues for value generation. Despite the extensive history of general risk management in corporate governance, the specialized management of legal risks remains a nascent concept within the Iranian legal system, frequently overshadowed by traditional interpretations of corporate law. The primary objective of this study is to conceptualize legal risk and systematically explicate the principles and operational processes governing its management, utilizing the international standard ISO 31022 as a foundational framework. Furthermore, the research strictly examines the current status and placement of legal risk management within the Iranian legal framework. To achieve this, the study addresses four core questions regarding the exact definition and categorization of legal risk, its structural status in Iran, its fundamental operative principles, and the required procedural steps for mitigation.
 ‌Method & Approach: The research is conducted utilizing a descriptive-analytical methodology combined with a doctrinal legal approach. This framework allows for a comprehensive conceptualization of legal risk by examining its underlying nature and distinct categories. The methodology is applied to pursue three principal structural aims. First, it undertakes a theoretical exposition of legal risk, categorizing its primary operational types. Second, the doctrinal approach is utilized to evaluate the position of legal risk management within the Iranian legal system, drawing direct comparisons with established analogous mechanisms found in traditional Islamic jurisprudence and civil law. Third, the descriptive analysis is employed to delineate the nine core principles and the four-stage procedural framework of legal risk management—comprising identification, analysis, evaluation, and treatment—strictly based on the guidelines delineated in the international standard ISO 31022. Through this structured approach, the study evaluates domestic practices against international benchmarks to provide a systematic understanding of the subject matter.
 ‌Findings: The findings reveal that the current state of legal risk management within the Iranian legal system is predominantly characterized by a fragmented and reactive approach. At the conceptual level, there exists a pervasive conflation between the "legal management of risk"—utilizing legal instruments to mitigate general operational hazards—and the distinct discipline of "management of legal risk." Examples of the former are prevalent in traditional Iranian civil law, such as ḍamān (liability or guarantee) or the prohibition of ġarar (contractual uncertainty or excessive risk), which apply the law strictly as a tool rather than addressing inherent legal uncertainties. At the organizational level, legal departments predominantly assume a reactive stance, engaging only after disputes arise. Furthermore, at the normative level, a pronounced regulatory vacuum exists, lacking specific legislative mandates for comprehensive legal risk management systems. Despite this deficiency, the foundational principles of Iranian civil liability, particularly the concepts of taqṣīr (fault) and the duty to uphold reasonable conduct, establish a robust potential legal basis. Neglecting to establish an effective framework can therefore be construed as a failure to exercise reasonable care, potentially invoking civil liability. Concurrently, the implementation of ISO 31022 offers a viable corrective framework, providing nine structural principles and a structured four-stage mechanism to systematically manage legal exposures.
 ‌Conclusion: The paper concludes that legal risk management must transition from a reactive departmental function into an integrated pillar of corporate governance. Organizations are advised to implement personalized frameworks modeled on ISO 31022, restructure legal departments to ensure direct reporting to boards of directors, integrate technologies for continuous monitoring, and foster a pervasive culture of legal awareness. On a national scale, lawmakers must recognize legal risk management as an essential component of modern governance and enact legislation that incentivizes its adoption. Furthermore, the legislature should actively facilitate alternative dispute resolution mechanisms by providing explicit statutory recognition for online dispute resolution within commercial frameworks. Finally, regulatory bodies must evolve from issuing strictly prescriptive and retroactive sanctions toward adopting risk-based regulatory paradigms. By encouraging self-regulation and proactive compliance, the legal system can fundamentally reduce the societal costs of litigation, enhance corporate compliance mechanisms, and foster a highly secure environment for sustainable economic development.

واژگان کلیدی English

Legal Risk
Risk Management
Legal Risk Management
ISO 31022 Standard
  1. احسنی‌فروز، محمد (1404). حقوق انتقال فناوری (شرح و تفسیر ساختار، مواد، شروط و تعهدات قرارداد). چاپ 4، تهران: دادگستر.
  2. افشار، حسن (1394). مسئولیت مدنی جبران خسارت معنوی در حقوق ایران. تهران: مجد.
  3. السان، مصطفی (1402). حقوق تجارت الکترونیکی. تهران: سمت.
  4. الماسی، نجادعلی (1395). حقوق بین‌الملل خصوصی. تهران: میزان.
  5. پاکدامن، رضا (1401). مدیریت ریسک‌های قرارداد. تهران: شرکت چاپ و نشر بازرگانی.
  6. پدرام، محمدمتین (1390). روش‌های حقوقی مدیریت ریسک در قراردادهای نفتی (پایان‌نامه کارشناسی ارشد). دانشکده حقوق و علوم سیاسی دانشگاه تهران.
  7. پورمیکاییل، کسری (1395). مدیریت حقوقی خطرهای (ریسک) سرمایه‌گذاری خارجی در پرتوی تحولات اخیر حقوق بین‌الملل (پایان‌نامه کارشناسی ارشد). دانشکده حقوق و علوم سیاسی دانشگاه تهران.
  8. جعفری لنگرودی، محمدجعفر (1392). وسیط در ترمینولوژی حقوق. تهران: گنج دانش.
  9. حجتی، یلدا (1402). نقش هوش مصنوعی در پیش‌بینی و مدیریت ریسک‌های قراردادی و چالش‌های اخلاقی و حقوقی ناظر بر آن (پایان‌نامه کارشناسی ارشد). دانشکده حقوق و علوم سیاسی دانشگاه تهران.
  10. خواجه‌داد، سحر (1404). نقش مدیریت ریسک یکپارچه در ایجاد تاب‌آوری سازمانی در محیط‌های پویای کسب‌وکار. پنجمین همایش بین‌المللی علوم سیاسی، مدیریت، اقتصاد و حسابداری، همدان.
  11. دانش‌پژوه، مصطفی (1392)، مقدمه علم حقوق با رویکرد به حقوق ایران و اسلام. قم: پژوهشگاه حوزه و دانشگاه.
  12. رشیدی، سوران، میری لواسانی، سیدمحمدرضا و منتظر، مهدی (1403 الف). مدیریت ریسک‌های حقوقی و تطبیق در صنعت بانکداری ایران (رویکرد ماتریس ریسک). فصلنامه مطالعات فقه اقتصادی، دوره 6، شماره 2، صص. 81-100.
  13. رشیدی، سوران، میری لواسانی، سیدمحمدرضا و منتظر، مهدی (1403 ب). الگویی برای مدیریت ریسک‌های حقوقی در صنعت بانکداری ایران. دانشنامه حقوق اقتصادی، 31 (25)، صص. 233-257.
  14. زارع، محمدحسن و دهقانی، حسین (1396). چیستی سازمان از منظر استاد آیت‌الله قوامی. فصلنامه مدیریت در اسلام. 33 (34)، صص. 53-66.
  15. عبدی‌پور فرد، ابراهیم و چاچ، سعید (1401). سازوکارهای حقوقی کاهش ریسک در تجارت بین‌الملل. تهران: مجد.
  16. غلام‌نیا، رضا (1398). مقدمه‌ای بر مدیریت ریسک. تهران: آثار سبحان.
  17. فرهی، نیکو و شافع، میرشهبیز (1402). مدیریت حقوقی ریسک‌های داخلی در پروژه‌های صنعتی با رویکرد مقایسه میان قراردادهای مختلف پیمان‌کاری. مجله تحقیقات حقوقی، 26 (103)، صص. 287-312.
  18. قاسمی، امیرعلی (1402). مدیریت حقوقی ریسک‌های مالکیت فکری در شرکت‌های نوآفرین استارتاپ (پایان‌نامه کارشناسی ارشد). دانشکده حقوق و علوم سیاسی دانشگاه تهران.
  19. کاتوزیان، امیرناصر (1396). مقدمه علم حقوق و مطالعه در نظام حقوقی ایران. تهران: گنج دانش.
  20. کاتوزیان، امیرناصر (1398). دوره مقدماتی حقوق مدنی وقایع حقوقی مسئولیت مدنی. تهران: گنج دانش.
  21. کاتوزیان، امیرناصر (1399). دوره مقدماتی حقوق مدنی درس‌هایی از عقود معین (جلد اول). تهران: گنج دانش.
  22. مطیعی، انسیه و البرزی ورکی، مسعود (1398). اصل انصاف؛ ماهیت، انواع و کارکردهای آن. مجله حقوق خصوصی، 17 (2)، صص. 521-541. 
  23. معین، محمد (1382). فرهنگ معین. چاپ 1، تهران: زرین.
  24. ملکوتی، رسول (1400). مسئولیت مدنی در فضای سایبر. تهران: مجد.
  25. هاشمی، مهدی (1398). ریسک ارزی در تجارت بین‌الملل و مدیریت حقوقی آن (پایان‌نامه کارشناسی ارشد). دانشکده حقوق دانشگاه شهید بهشتی.
  26. Akinsola, O. Kayode, Onu, Kingsley, Owoeye, Yinka, & John, Beauden. (2025). How Corporate Directors Manage Legal Compliance and Risk Management: The Legal Responsibilities of Corporate Boards.
  27. Almada, Marco. (2024). Law & Compliance in AI Security & Data Protection. Postdoc, University of Luxembourg.
  28. Burnett, Rachel. (2005). Legal risk management for the IT industry. Computer Law & Security Review, 21(1), 61-67. https://doi.org/10.1016/j.clsr.2004.11.011
  29. Construction Research Congress 2005: Broadening Perspectives. https://doi.org/10.1061/40754(183)52
  30. Guo, Qingmei. (2023). Research on the Evaluation Method of Enterprise Legal Risk. International Journal of Professional Business Review, 8(4). https://doi.org/10.26668/businessreview/2023.v8i4.2005
  31. Hirth Jr., Robert B., Chambers, Richard F., Danaher, Mitchell A., Landes, Charles E., Prawitt, Douglas F., & Richtermeyer, Sandra. (2017). Enterprise Risk Management: Integrating with Strategy and Performance. Committee of Sponsoring Organizations of the Treadway Commission.
  32. Hopkin, Paul. (2017). Fundamentals of Risk Management: Understanding, Evaluating and Implementing Effective Risk Management (4th ed.). London: Kogan Page.
  33. Ismail, Ihab A., & Kamat, Vineet R. (2012). Legal Risk Analysis, Modeling and Programming for E-Commerce in Construction.
  34. ISO 31000. (2018). Risk Management - Guidelines (2nd ed.). Switzerland.
  35. ISO 31022. (2020). Risk Management - Guidelines for the Management of Legal Risk (1st ed.). Switzerland.
  36. Lannyati, Niniek, Sarwono, Ayuningtyas Pratita, Taufiq, Sami'an, & Soeharto, Achmad. (2024). Legal and Financial Risk Management in Large-Scale Construction Projects. Sch Int J Law Crime Justice, 7(8), 316-322. https://doi.org/10.36348/sijlcj.2024.v07i08.005
  37. Li, Xiaoying. (2025). Enhancing Legal Risk Management Through Advanced Multi-Feature Recognition Techniques. International Journal of Knowledge Management, 21. https://doi.org/10.4018/IJKM.390780
  38. Mahler, Tobias. (2010). Tool-supported Legal Risk Management: A Roadmap. European Journal of Legal Studies, 2(3), 146-167. https://hdl.handle.net/1814/15122
  39. McCormick, Roger. (2010). Legal Risk in The Financial Markets (2nd ed.). New York: Oxford University Press.
  40. Moorhead, Richard Lewis, & Vaughan, Steven. (2015). Legal Risk: Definition, Management and Ethics. Available at SSRN: https://ssrn.com/abstract=2594228
  41. Netshifhefhe, Khodani, Netshifhefhe, Magalane Vivian, Mupa, Munashe Naphtali, Kudakwashe, Artwell, & Murapa, Kudakwashe. (2024). Integrating Internal Auditing and Legal Compliance: A Strategic Approach to Risk Management. Iconic Research And Engineering Journals, 8(4), 446-465.
  42. OECD. (2023). G20/OECD Principles of Corporate Governance 2023. Paris: OECD Publishing. https://doi.org/10.1787/ed750b30-en
  43. Project Management Institute. (2021). PMBOK GUIDE: A Guide to the Project Management Body of Knowledge (7th ed.). Project Management Institute.
  44. Rejas-Muslera, Ricardo, Cuadrado-Gallego, Juan, & Rodriguez, Daniel. (2007). Defining a Legal Risk Management Strategy: Process, Legal Risk and Lifecycle. Conference: Software Process Improvement, 14th European Conference, EuroSPI 2007, Potsdam, Germany, September 26-28, 2007, Proceedings, 118-123.
  45. Shoa, Ziqian. (2025). Legal Risk Management in Intellectual Property-Supported Financing: The Role of Court Decisions in the Construction of Secured Transaction Rules. Academic Journal of Management and Social Sciences, 12(2), 51-55. https://doi.org/10.54097/vtyv6b18
  46. Stradella, Rafaella. (2025). Legal Risk Management: Strategies for Identifying and Mitigating Legal Risks in International Business Operation. Brazilian Journal of Development, 11(5), e79916. https://doi.org/10.34117/bjdv11n5-071
  47. Weinstein, Stuart. (2025). An evaluation of the utility of ISO 31022:2020 [risk management - guidelines for the management of legal risk] for use by micro-entities. International Review of Law, Computers & Technology. https://doi.org/10.1080/13600869.2025.2506167
  48. Whalley, M., & Guzelian, C. (2017). The Legal Risk Management Handbook: An International Guide to Protect Your Business from Legal Loss. London: Kogan Page.

  • دریافت 02 خرداد 1405
  • پذیرش 11 تیر 1405