Skip to main content
PECB Partner ID: 232290PECB · 27005Risk ManagerPage updated

PECB ISO/IEC 27005 Risk Manager Course & Exam Australia

Information security risk management based on ISO/IEC 27005 — plus OCTAVE, MEHARI, EBIOS, NIST, CRAMM, and Harmonized TRA. Published Self-Study or eLearning enrolment starts from $849 + GST and includes the official exam access stated on this page. Instructor-led delivery for organisations can be scoped on request; no public cohort is implied unless confirmed dates, mode, venue and trainer are shown.

Available Australia-wide, in New Zealand and across Asia Pacific — and, because self-study and eLearning are delivered online through the myPECB platform, from anywhere in the world. Instructor-led organisational delivery can be scoped on request; no public cohort or classroom venue is implied unless confirmed details are shown. Base prices are published in AUD, and every course page supports available local currencies including NZD. An Australian billing address adds 10% GST; a non-Australian billing address has no Australian GST.

The PECB ISO/IEC 27005 Risk Manager Self-Study course costs A$849 excluding GST (A$933.90 including 10% GST for an Australian billing address) through Aegentra Academy, an official PECB authorised training partner in Australia. That price includes the official PECB examination voucher, the full course materials, 12 months of myPECB access, and one free exam resit within 12 months. Typical total learning effort is 21–30 hours. The eLearning format is A$949 excluding GST (A$1,043.90 including Australian GST), with 21–30 hours of typical total learning effort. For non-Australian billing addresses, Australian GST is not charged and any applicable local taxes are determined at checkout.

Instructor-led delivery is enquiry-only. Aegentra Academy is not currently publishing scheduled live online or classroom cohorts. Contact us to arrange a class for your organisation; Self-Study and eLearning are available without waiting for a cohort.

Official course provider
PECB
Standard family recorded
ISO/IEC 27005
Typical total learning effort
21–30 hours
Self-Study · eLearning · access period, not effort
12 months access
Initial attempt and one free retake
2 exam attempts included
/ Purchase order

ISO/IEC 27005 Risk Manager course price and enrolment options

Australian totals above include 10% GST. For non-Australian billing addresses, Australian GST is not charged; any applicable local taxes are determined at checkout.

Live online class

Online classes are arranged through the Aegentra Academy team for individual learners and groups.

Contact us for online class

Questions before enrolling?

Ask about prerequisites, delivery, employer invoicing, or which course fits your goal.

We normally reply within one Australian business day.

Learn · Implement

What your course includes—and what you can use next

Official PECB training is included. The practical ISO/IEC 27005 resources are free to use after the course, with no email required.

Learn

Included with course

Official PECB training + exam

  • Official PECB ISO/IEC 27005 Risk Manager training
  • Official PECB examination voucher
  • Initial exam attempt plus one free resit
  • 12 months myPECB access
  • Official course materials
  • PECB credential application pathway

This is what the A$849 + GST Self-Study price covers, or A$949 + GST with PECB eLearning.

Choose your course

Implement

Free · No email required

Free ISO 27005 practitioner resources

Go beyond passing the exam. Practical resources built around the work itself — the documents you will actually have to produce.

Explore free ISO 27005 resources

How much does ISO 27005 training cost in Australia?

The ISO 27005 Risk Manager course is $849 + GST self-paced, or $949 + GST with guided eLearning. There is no separate ISO 27005 exam cost — the official PECB examination voucher is included, along with one free retake within 12 months and 12 months of myPECB access. Aegentra Academy is an official PECB authorised training partner, and prices are quoted in Australian dollars ex-GST.

CourseCourse focusExamSelf-StudyeLearning
Risk ManagerRun information security risk assessments — assets, threats, vulnerabilities, likelihood, consequence, treatment60 questions, 2 hours, open book$849 + GST$949 + GST
Lead Risk ManagerLead the risk management programme — criteria, methodologies, communication, monitoring and board reporting80 questions, 3 hours, open book$989 + GST

ISO 27005 vs ISO 27001 — what is the difference?

This is the question most people arrive with, and the answer is simpler than the internet makes it. ISO/IEC 27001 is the certifiable management system. ISO/IEC 27005 is the risk methodology you run inside it. They are not alternatives and you do not choose between them.

ISO 27001 Clause 6.1.2 requires you to define and apply an information security risk assessment process — but it deliberately does not say which one. ISO/IEC 27005:2022 is the guidance that fills that gap: how to identify assets, threats and vulnerabilities, how to analyse likelihood and consequence, how to evaluate against criteria you set in advance, and how to choose between modifying, retaining, avoiding or sharing a risk.

ISO 27005 is not certifiable for an organisation. There is no Stage 1 / Stage 2 audit and no certificate saying a company is “ISO 27005 certified” — it is guidance, not an auditable management system. Individuals are certified, through PECB. Where it does get audited is inside an ISO 27001 assessment: your risk method is evidence for Clause 6.1.2, and an auditor will test whether you actually followed it.

The third standard people ask about is ISO 31000, which is generic enterprise risk management. Most Australian organisations use ISO 31000 as the umbrella framework, ISO 27005 for information security risk specifically, and hold ISO 27001 as the certificate. See the ISO 27005 certification guide for Australia for the full comparison.

What is on the ISO 27005 Risk Manager exam?

60 multiple-choice questions across 4 competency domains, open book, 2 hours, 70% to pass. PECB publishes the per-domain weighting in its certification scheme, which is worth knowing before you study:

  • Fundamental principles and concepts of information security risk management — 13 questions (21.7%)
  • Implementation of an information security risk management program — 7 questions (11.7%)
  • Risk management framework and processes based on ISO/IEC 2700531 questions (51.7%)
  • Other information security risk assessment methods — 9 questions (15%)

More than half the paper sits in one domain. If you are short on study time, the framework and process is where it should go.

A caution on sources: PECB’s older candidate handbooks for this standard still describe ISO/IEC 27005:2008 and a 12-question essay exam. That is two editions out of date. The figures above come from the current ISO/IEC 27005:2022 certification scheme. If a provider quotes you an essay exam for ISO 27005, they are republishing the old handbook.

What does the Risk Manager credential qualify you for?

Passing awards PECB Certified ISO/IEC 27005:2022 Risk Manager, or Senior Risk Manager depending on the experience you can attest to. Risk Manager requires two years of professional experience with one year in risk management, plus 200 hours of risk management activity. Note the edition year is part of the credential name — it is 27005:2022, not a generic “ISO 27005” certificate.

Certification runs three years and is maintained through 60 CPD hours per cycle plus the annual maintenance fee. If you will lead the programme rather than run assessments within it, the Lead Risk Manager course covers six domains rather than four and carries the Lead ladder.

Where ISO 27005 fits Australian security obligations

APRA CPS 234 requires regulated entities to classify information assets by criticality and sensitivity and to size controls to the threat — which is an information security risk assessment by another name. The ASD Essential Eight maturity model assumes you know which systems matter most, and that judgement comes from a risk assessment rather than from the model itself.

Neither names ISO 27005. Both assume what it produces: a documented, repeatable method for deciding which information security risks matter and what to do about them. That is why Australian GRC and information security auditor roles ask for risk credentials alongside ISO 27001.

Free ISO 27005 risk assessment templates

The two documents this method actually produces, published in full and free — no email required.

/ What you get

What's included in the ISO/IEC 27005 Risk Manager course fee

The official PECB course and exam package starts at A$849 + GST — with no separate exam fee after enrolment. Optional Aegentra Labs exam preparation is clearly priced separately.

Course materials
  • PECB ISO/IEC 27005 Risk Manager slide deck (digital)
  • Over 350 pages of training material with practical examples
  • 12 months access via myPECB
  • Practical exercises, quizzes, and case studies
Exam package
  • Official PECB ISO/IEC 27005 Risk Manager exam voucher
  • Two-hour exam covering four competency domains
  • Two exam attempts (initial + one free resit within 12 months)
  • Attestation of course completion worth 21 CPD credits
Practitioner extras
  • Risk-register and risk-treatment-plan templates aligned to ISO/IEC 27005
  • Worked comparison of OCTAVE, MEHARI, EBIOS, NIST, CRAMM, and Harmonized TRA
  • Mapping notes from ISO/IEC 27005 risk output to the ISO 27001 Statement of Applicability
  • Australian-context worked examples from live readiness programmes
/ Exam requirements & credential

ISO/IEC 27005 Risk Manager exam format, duration and pass mark

The exam voucher is included in your enrolment, and so is one free resit if you don’t pass first time. Both the exam and the credential are issued directly by PECB.

Format
Open-book, multiple-choice — stand-alone and scenario-based questions
Duration
2 hours
Questions
60 multiple-choice questions across 4 competency domains — fundamental principles and concepts of information security risk management (13 questions), implementation of an information security risk management program (7), the risk management framework and processes based on ISO/IEC 27005 (31, the largest domain at 52% of the paper), and other information security risk assessment methods (9)
Pass mark
70%
Language
English (other PECB languages available on request)
Credential experience requirements

Passing the exam makes you eligible to apply for the PECB Certified ISO/IEC 27005:2022 Risk Manager credential, or Senior Risk Manager depending on attested experience. Risk Manager requires two years of professional experience with one year in risk management, plus 200 hours of risk management activity. All tiers require signing the PECB Code of Ethics. Certification is valid three years and is maintained through 60 CPD hours per three-year cycle plus the annual maintenance fee.

An exam pass is the first step. You must submit PECB's certification application and required declarations and references. PECB decides whether the requirements for the requested credential tier are met.

/ Before you enrol

Clear answers about price, tax, exams, and certification.

These answers use this course's current catalogue record and PECB's published exam, certification, and maintenance policies.

What is included in the ISO/IEC 27005 Risk Manager course fee?

The published price is A$849 for Self-Study or A$949 for eLearning, before tax. It includes the official PECB course materials, 12 months of access, the first exam attempt, one free retake, and the certification application fee. PECB’s partner-course policy also includes the first year of the Annual Maintenance Fee where maintenance applies; Foundation and Provisional credentials are maintenance-exempt. There is no separate first-exam or certification-application charge after enrolment.

What will PECB charge to maintain the ISO/IEC 27005 Risk Manager credential?

PECB’s current maintenance policy lists no maintenance fee for Foundation, Provisional, or Transition credentials. For all other PECB certifications, the published fee is $390 per three-year certification cycle, together with the applicable CPD requirements and continued adherence to the PECB Code of Ethics. PECB sets this fee and may change it, so check the linked policy before renewal.

Can I pay in NZD or another currency, and when is Australian GST added?

Yes. Every Academy course supports AUD and multiple local currencies, including NZD, USD, SGD, GBP, EUR, INR, AED, MYR, PHP, IDR, and VND when a live quote is available. Currency and tax are separate: an Australian billing address adds 10% GST, while a non-Australian billing address has no Australian GST. For example, an Australian working in New Zealand may pay in NZD and use an Australian billing address, but 10% GST will still be added because the billing address is Australian.

What is the difference between Self-Study and eLearning for ISO/IEC 27005 Risk Manager?

Self-Study costs A$849 before tax and uses the official PECB slide-based materials. eLearning costs A$949 before tax — A$100 more — and adds recorded trainer-led lessons and interactive learning activities. Both routes lead to the same PECB exam and credential, and both include the same exam package. Choose eLearning if explanations and video guidance help you learn; choose Self-Study if you are comfortable working through standards-based material independently.

Can I sit the ISO/IEC 27005 Risk Manager exam remotely from New Zealand or another time zone?

Yes. PECB publishes remote online exam sessions that candidates can take from home or another suitable location through the PECB Exams application. The published course record lists these exam facts: duration — 2 hours; format — Open-book, multiple-choice — stand-alone and scenario-based questions; assessment — 60 multiple-choice questions across 4 competency domains — fundamental principles and concepts of information security risk management (13 questions), implementation of an information security risk management program (7), the risk management framework and processes based on ISO/IEC 27005 (31, the largest domain at 52% of the paper), and other information security risk assessment methods (9); pass mark — 70%; language — English (other PECB languages available on request). New Zealand candidates should choose a published session that suits their local time, meet PECB’s identity and technical requirements, and complete the system check before exam day. PECB’s general exam policy does not publish a New Zealand restriction.

Which credential tier will I receive after the ISO/IEC 27005 Risk Manager exam, and who assesses it?

Passing the exam makes you eligible to apply for the PECB Certified ISO/IEC 27005:2022 Risk Manager credential, or Senior Risk Manager depending on attested experience. Risk Manager requires two years of professional experience with one year in risk management, plus 200 hours of risk management activity. All tiers require signing the PECB Code of Ethics. Certification is valid three years and is maintained through 60 CPD hours per three-year cycle plus the annual maintenance fee. Passing the exam does not by itself award a credential or guarantee the highest experience-based tier. PECB requires an online certification application and reference contact details, and its Certification Department decides whether the education, professional experience, and risk-management activity requirements are met.

What evidence does PECB accept for the experience or project hours for ISO/IEC 27005 Risk Manager?

PECB’s public certification-process page does not publish a closed list of documents that automatically proves project hours. It requires the online application and contact details for references who may be contacted to validate your experience. Keep a dated activity log showing the organisation or client, your role, the risk-management activity, dates, responsibilities, and hours; retain employer or client confirmations, statements of work, timesheets, or similar records in case PECB asks for support. The PECB Certification Department assesses the application and makes the final decision.

/ Training prerequisites

What you should know before starting ISO/IEC 27005 Risk Manager

  • A fundamental understanding of ISO/IEC 27005 and comprehensive knowledge of risk assessment and information security.
  • Prior ISO 27001 exposure is helpful — the course teaches risk assessment in the context of an ISMS.
/ Who this course is for

Who should take the ISO/IEC 27005 Risk Manager course

  • Managers or consultants responsible for information security in an organisation
  • Individuals responsible for managing information security risks
  • Members of information security teams, IT professionals, and privacy officers
  • Individuals maintaining conformity with the information security requirements of ISO/IEC 27001
  • Project managers, consultants, and expert advisers seeking to master information security risk management
/ What you'll learn

By the end of this course you’ll be able to:

  • Explain the risk management concepts and principles outlined by ISO/IEC 27005 and ISO 31000.
  • Establish, maintain, and improve an information security risk management framework based on the guidelines of ISO/IEC 27005.
  • Apply information security risk management processes based on the guidelines of ISO/IEC 27005.
  • Plan and establish risk communication and consultation activities.
  • Select an appropriate assessment method — OCTAVE, MEHARI, EBIOS, NIST, CRAMM, or Harmonized TRA — for the organisation in front of you.
/ Curriculum

What does the ISO 27005 Risk Manager course cover?

3 modules, fully on-demand. Click any module to see the topics inside.

01Day 1 — Introduction to ISO/IEC 27005 and risk management
  • Training course objectives and structure
  • Standards and regulatory frameworks
  • Fundamental concepts and principles of information security risk management
  • Information security risk management program
  • Context establishment
02Day 2 — Risk assessment, treatment, and communication based on ISO/IEC 27005
  • Risk identification
  • Risk analysis
  • Risk evaluation
  • Risk treatment
  • Information security risk communication and consultation
03Day 3 — Risk recording and reporting, monitoring and review, and assessment methods
  • Information security risk recording and reporting
  • Information security risk monitoring and review
  • OCTAVE and MEHARI methodologies
  • EBIOS method and NIST framework
  • CRAMM and TRA methods
  • Closing of the training course
/ Career signal

What is the ISO 27005 Risk Manager credential worth?

The credential for the risk half of ISO 27001

Most ISO 27001 programmes fail their Stage 2 audit on risk, not on controls — the risk assessment is undocumented, the methodology is undefined, or the Statement of Applicability cannot be traced back to any assessed risk. ISO/IEC 27005 Risk Manager is the credential that says you can run that half of the management system properly: define the method, establish context, and produce a risk assessment an auditor can follow.

Where it shows up in Australian job descriptions

Information Security Risk Analyst, Security Risk Manager, GRC Analyst, ISMS Manager, and Cyber Risk Consultant roles all treat information security risk management as a named competency. It is a frequent requirement where an organisation is standing up or maintaining an ISO 27001 certified ISMS.

Method fluency, not just one framework

The course covers OCTAVE, MEHARI, EBIOS, NIST, CRAMM, and Harmonized TRA alongside ISO/IEC 27005. That matters in consulting and in-house work alike, because you frequently inherit an existing method rather than choosing one — being able to work inside a client’s established approach, and explain its trade-offs, is what separates a practitioner from a checklist follower.

How it sits beside ISO 31000

ISO 31000 is the enterprise risk framework; ISO/IEC 27005 is the information security specific companion. Practitioners who hold both can move between the enterprise risk register and the ISMS risk register without re-learning vocabulary, which is exactly the position integrated GRC roles are recruiting for.

/ Where this lands in Australia

ISO 27005 risk manager training in Australia — who hires it

Organisations pursuing or holding ISO 27001 certification

Any organisation with a certified ISMS must perform and maintain information security risk assessments. ISO/IEC 27005 is the guidance those assessments are most commonly built on, which makes this the natural credential for the person who owns the risk register.

Australian government and PSPF-aligned entities

Commonwealth and state entities operating under the Protective Security Policy Framework run risk-based decisions on information handling and system authorisation. A documented, repeatable information security risk method is a standing requirement rather than a one-off deliverable.

APRA-regulated financial services

CPS 234 obliges APRA-regulated entities to maintain information security capability commensurate with the size and extent of threats. That is a risk judgement, and it has to be evidenced — which is precisely what an ISO/IEC 27005 assessment produces.

Critical infrastructure under the SOCI Act

Responsible entities for critical infrastructure assets must maintain a Risk Management Program covering cyber and information hazards. ISO/IEC 27005 supplies a defensible method for the information security portion of that programme.

/ Study plan

How hard is the ISO 27005 Risk Manager exam?

The exam is open-book, but the questions reward fluency, not lookup. Plan your study around these checkpoints.

  1. 01Work the risk process end to end at least twice — context establishment, identification, analysis, evaluation, treatment, communication, recording, monitoring. The process is the spine of nearly every scenario question.
  2. 02Be precise about the difference between risk identification, analysis, and evaluation. Scenario questions frequently hinge on which stage a described activity belongs to.
  3. 03Build a small information security risk register for an imagined Australian organisation, then write the treatment plan for its top three risks. Doing it once is worth more than re-reading the deck.
  4. 04Learn what distinguishes OCTAVE, MEHARI, EBIOS, NIST, CRAMM, and Harmonized TRA from each other — Domain 4 tests exactly this, and they are easy to blur.
  5. 05Practise tracing a risk through to an ISO 27001 Statement of Applicability decision. The course deliberately teaches ISO/IEC 27005 alongside ISO/IEC 27001.
  6. 06The exam is two hours — shorter than the Lead-level exams. Time-box a practice run accordingly rather than assuming a three-hour window.

Free learning resources

Put the course concepts into practice.

Use Aegentra’s existing templates, checklists, registers and mappings alongside your course. No account or email is required.

Browse free ISO 27005 resources
/ Related reading

Related ISO 27005 resources

Free companion reading for anyone studying information security risk management — the risk method behind every ISO 27001 risk assessment:

Compare the family

See where this course fits

The ISO 27005 family page compares current levels, prices, delivery, audiences and exam facts before you choose a pathway.

Compare ISO 27005 pathways

Source and review status

How these course facts are governed

Price, delivery and course content are generated from Aegentra’s authoritative catalogue record. The official PECB course page and exam policy are linked directly below. Source-link checks and substantive human review are tracked separately so one is never presented as the other.

Official PECB sources

Editorial accountability

Harry Sidhu owns publication of this record. A separate course-specific substantive reviewer has not yet been recorded.

Substantive review status

Official source links are checked separately. A course-specific substantive review date will be published when completed.

/ Accreditation

How can I verify the ISO/IEC 27005 Risk Manager credential pathway?

Official PECB training through an authorised partner. PECB is accredited by IAS and UKAS as a personnel certification body under ISO/IEC 17024 and by ANAB as a certificate issuer under ANSI/ASTM E2659-24. Accreditation is program- and scope-specific—verify the applicable credential before enrolment.

Official PECB training and credential pathway. Check PECB’s current accreditation information and the applicable program scope before enrolment.

This official PECB course is sold and supported by Aegentra Academy. PECB supplies the course material, examination and professional credential scheme. Aegentra's wider practice also runs governance, risk and compliance engagements and Microsoft 365 hardening for Australian organisations. Named eLearning trainers are credited separately on this page when the course record supplies them.

Published courses run online and self-paced through the myPECB platform, so professionals across Melbourne, Sydney, Brisbane, Perth, Adelaide, Canberra and New Zealand enrol online. Instructor-led delivery for organisations can be scoped on request. No public cohort or classroom venue is implied unless confirmed dates, mode, venue and trainer are shown on the course page. Multi-seat team pricing is available for five or more seats — email Academy@aegentra.com.au for an enterprise quote. Tax invoices with GST and ABN are issued automatically at checkout.

/ Frequently asked

ISO/IEC 27005 Risk Manager — frequently asked.

Do you run live or in-person classes for this course?

The published option is self-paced study. Instructor-led delivery for organisations can be scoped on request, subject to trainer availability, learner numbers and an agreed date. Aegentra does not publish a live or classroom cohort unless its dates, delivery mode, venue (where applicable) and trainer are confirmed. Email Academy@aegentra.com.au with your requirements.

What does the PECB ISO/IEC 27005 Risk Manager course cover?

Three days of material: an introduction to ISO/IEC 27005 and risk management concepts including context establishment; risk assessment, treatment, and communication; then risk recording, reporting, monitoring and review, plus the other assessment methods — OCTAVE, MEHARI, EBIOS, NIST, CRAMM, and Harmonized TRA. Delivered self-paced, it is typically 21–30 hours of study.

What is the difference between ISO/IEC 27005 and ISO 31000?

ISO 31000 is the general risk management standard — principles, framework, and process for any kind of risk across an enterprise. ISO/IEC 27005 is the information security specific guidance, designed to be used with an ISO/IEC 27001 ISMS. The Risk Manager course explains the concepts and principles of both, but the process it trains you to run is the information security one.

Do I need ISO 27001 experience first?

It helps considerably. PECB expects a fundamental understanding of ISO/IEC 27005 plus knowledge of risk assessment and information security. The course teaches risk assessment by combining ISO/IEC 27005 with ISO/IEC 27001, so prior exposure to an ISMS makes the material land faster. It is not a formal prerequisite.

How is the exam structured?

Two hours, open-book, covering four competency domains: fundamental principles and concepts of information security risk management; implementation of an information security risk management program; the risk management framework and processes based on ISO/IEC 27005; and other information security risk assessment methods. Pass mark is 70%.

Which credential do I actually receive?

It depends on attested experience. Provisional Risk Manager requires no professional experience. Risk Manager requires two years total with one year in information security management, plus 200 hours of information security risk management activities. Senior Risk Manager requires ten years total with seven in information security management, plus 1,000 hours. All three require signing the PECB Code of Ethics.

What is the difference between the slide-only and eLearning options?

Self-Study at $849 + GST gives you the official PECB slide deck and course material to work through at your own pace. The eLearning option at $949 + GST adds recorded video lectures and scenario-based quizzes on top of the same material. Both include the exam voucher and the free resit, and both lead to the identical PECB credential.

What CPD credits do I earn?

Participants receive an attestation of course completion worth 21 CPD credits. These count toward the continuing professional development requirements of ISACA, IIA Australia, and other professional bodies on submission.

Does this course cover risk assessment methods other than ISO/IEC 27005?

Yes — Day 3 surveys OCTAVE, MEHARI, EBIOS, the NIST framework, CRAMM, and Harmonized TRA, and Domain 4 of the exam covers them. The point is to be able to work within whichever method an organisation already uses rather than only the one you were trained on.

Can my employer pay or reimburse?

Yes. Either complete checkout yourself and forward the Stripe tax invoice for reimbursement, or write to Academy@aegentra.com.au and we will issue an invoice direct to your organisation with payment terms. For group enrolments, request a written quote confirming the current price, payment terms and inclusions before purchase.

How long does the ISO/IEC 27005 Risk Manager course take?

Self-Study — Typical total learning effort: 21–30 hours. Course-day equivalent: approximately 3 training days. eLearning — Typical total learning effort: 21–30 hours. Course-day equivalent: approximately 3 training days. These are typical total-learning-effort estimates. They are separate from the 12-month access period, exam duration, any live-class calendar span, and professional-experience requirements.

When can I start the course?

After payment, the Academy team confirms your enrolment with PECB and you receive login details by email — usually within one business day.

How long do I have access to the course?

You have 12 months of access from enrolment. That window covers the course material, the official PECB exam, and one free resit if you need it.

What if I fail the exam?

One PECB-issued resit is included in your enrolment at no extra cost. Aegentra does not publish a pass-rate claim without an audited cohort dataset.

Questions about invoicing, GST, group bookings, refunds or instructor-led delivery? Read the Academy FAQ.

$849AUD · EXCL. TAX