How much does the ISO 31000 Lead Risk Manager course cost in Australia?
$979 + GST, including the official PECB examination voucher, two attempts (the initial sit plus one free resit within 12 months) and 12 months of myPECB access. Typical effort is 35–45 hours of self-paced study over five to seven weeks, and the course carries 31 CPD credits — the highest of the three ISO 31000 levels.
What is on the ISO 31000 Lead Risk Manager exam?
80 multiple-choice questions across 5 competency domains, open book, 70% to pass. The five domains are:
- Fundamental principles and concepts of risk management
- Establishment of the risk management framework
- Initiation of the risk management process and risk assessment
- Risk treatment, risk recording and reporting
- Risk monitoring, review, communication and consultation
That is twenty more questions and two more domains than Risk Manager, and the extra ground is where the seniority sits: domains 4 and 5 cover the reporting, monitoring and consultation duties that a head of risk owns and a business-unit risk manager generally does not.
Open book means a hard copy of ISO 31000, the course materials and your own notes are permitted. As with every PECB ISO 31000 exam, questions carry three options with one correct answer and mix stand-alone with scenario-based items.
These figures come from PECB’s published candidate handbook for the ISO 31000 Lead Risk Manager examination. As at the Risk Manager level, the handbook publishes no exam duration, so none is asserted here. Question count, domain split, materials policy and pass mark are all stated — duration simply is not.
Risk Manager or Lead Risk Manager — which should you take?
The deciding question is not how much risk experience you have. It is whose risk you are accountable for.
Take Risk Manager if you run risk inside a function, business unit or project — you are identifying, assessing and treating risk within a framework somebody else designed. Three competency domains, 60 questions, $594 + GST reduced from $849.
Take Lead Risk Manager if you are accountable for the framework itself — designing it, setting appetite, chairing the risk committee, reporting to a board and answering for whether the whole thing works. Five domains, 80 questions, $979 + GST.
There is also a credential ceiling to weigh. The Risk Manager exam awards Provisional Risk Manager or Risk Manager and stops there. Only the Lead Risk Manager exam carries the full ladder — Provisional Risk Manager, Risk Manager, Lead Risk Manager (five years of professional experience, two in risk management, 300 hours) and Senior Lead Risk Manager (ten years, seven in risk management, 1,000 hours). If a CRO or head-of-risk track is the destination, this is the exam that reaches it. The $130 difference between the two courses is small against sitting the wrong one.
What does a Lead Risk Manager do that a Risk Manager does not?
Four things, and they map directly onto the two extra exam domains.
Sets risk appetite rather than applying it. Clause 6.3.4 asks for risk criteria defined before assessment. Most organisations skip it, which leaves “acceptable” to be argued case by case after the fact. Turning appetite into escalation thresholds a manager can actually apply is lead-level work.
Builds reporting a board can act on. The most common failure in Australian risk reporting is a heat map with no trend and no appetite context — it shows where risks sit but not whether that is acceptable or which way it is moving. Replacing it with appetite-versus-actual trending and named key risk indicators with thresholds is what makes oversight real.
Owns risk culture and consultation. Domain 5 covers communication and consultation as a duty rather than a courtesy. A framework nobody outside the risk team understands does not change behaviour.
Integrates rather than parallels. Enterprise risk has to connect to the ISO 27001 ISMS, to business continuity under ISO 22301, and to the AI governance work under ISO 42001 — one register and one appetite, not four that contradict each other.
ISO 31000 for Australian government and critical infrastructure
Public sector and critical infrastructure risk roles are where this credential earns its keep, because the obligations are explicit and the assessor is a regulator.
The PSPF requires non-corporate Commonwealth entities to manage security risk using a risk management approach, with the Accountable Authority attesting annually to security maturity — an attestation is only as defensible as the method behind it. The Commonwealth Risk Management Policy under the PGPA Act requires appropriate systems of risk oversight and internal control, and Comcover benchmarks risk maturity annually across insured entities, which rewards a framework producing comparable year-on-year evidence.
The SOCI Act requires responsible entities across the designated critical infrastructure sectors to maintain a written Risk Management Program covering all hazards — cyber, personnel, supply chain and physical — with annual reporting to the board and the regulator. An all-hazards program is exactly what Clause 5.4 describes, and it is the reason ISO 31000 rather than a cyber-only framework is the right umbrella.
Certifying yourself and certifying an organisation are different questions: the ISO 31000 certification guide for Australia covers the organisational side, and Aegentra’s governance and risk practice does the work itself.
Free enterprise risk documents to work through with the course
Lead Risk Manager is about the framework, not just the process. These are the four artefacts that framework produces — published in full, free, no email required.
- Risk criteria and appetite statement (CSV) or PDF — the Clause 6.3.4 artefact, worked across nine categories with appetite position, escalation thresholds to executive and board, and a named KRI per category. Start here: this is the lead-level document.
- AS ISO 31000 mapped to Australian obligations (CSV) or PDF — twenty obligations across APRA CPS 220, CPS 230 and CPS 234, the SOCI Act, the PSPF, the Commonwealth Risk Management Policy, Comcover, ASX Principle 7, WHS and the Privacy Act, each with the clause that satisfies it and the evidence to retain.
- Enterprise risk register (CSV) or PDF — twelve risks with control effectiveness and an explicit within-appetite test, which is what turns a register into a board paper.
- Calibrated 5×5 risk matrix (CSV) or PDF — the scales underneath the register, with frequency bands and per-consequence-type thresholds.