How much does the ISO 31000 Risk Manager course cost in Australia?
$594 + GST as self-paced study, or $649 + GST for the guided eLearning version with video lectures from PECB master trainers — reduced from $849 and $928 respectively. Both include the official PECB examination voucher, two attempts (the initial sit plus one free resit within 12 months), and 12 months of myPECB access. There is no separate exam fee.
Typical effort is 25–35 hours of self-paced study, usually spread over three to five weeks alongside a full-time job, and the course carries 21 CPD credits. PECB also supplies over 300 pages of course material.
Compare carefully when you shop this course. Several Australian providers quote a course fee and bill the PECB examination separately, so the advertised figure is not the figure you pay. Ask two questions of any provider: is the exam voucher included, and is a resit included.
What is on the ISO 31000 Risk Manager exam?
60 multiple-choice questions across 3 competency domains, open book, 70% to pass. The domains are fundamental principles and concepts of risk management, establishment of a risk management framework, and implementation of a risk management process. Questions carry three options with one correct answer, mixing stand-alone items with scenario-based ones where several questions hang off a single short case.
It is not an essay exam. That claim circulates widely and is worth correcting, because it changes how people prepare: candidates who expect to write long-form answers practise the wrong skill entirely. The handbook is unambiguous that this is a multiple-choice paper.
Being open book, you may bring a hard copy of ISO 31000, the course materials, and any personal notes you took during training. That makes speed of retrieval the real constraint rather than memorisation — candidates who fail usually knew the content but could not find it quickly enough. Build an index into your notes before you sit.
These figures come from PECB’s published candidate handbook for the ISO 31000 Risk Manager examination. Note what is absent: the handbook states no exam duration. Providers quoting two or three hours for this paper are citing something other than the handbook, which is worth knowing when you are comparing course pages.
What does the Risk Manager credential actually qualify you for?
This exam leads to two credentials, and it is worth being precise because the distinction is often blurred in course marketing:
- PECB Certified ISO 31000 Provisional Risk Manager — awarded on passing, with no professional experience required.
- PECB Certified ISO 31000 Risk Manager — requires two years of professional experience, one year of it in risk management, plus 200 hours of risk management project activity. Both require signing the PECB Code of Ethics.
This exam does not lead to Lead Risk Manager or Senior Lead Risk Manager. Those sit on a separate scheme and require the Lead Risk Manager exam, which covers five competency domains rather than three. If your target is a head-of-risk or CRO-track role, buy that one instead of buying this and discovering the ceiling later.
How do you build a risk matrix that actually works?
Most risk matrices fail for one reason: likelihood and consequence are left as adjectives. When “Possible” and “Major” mean whatever the person scoring them wants, two people assess the same risk and land three bands apart, and the heat map that reaches the board is noise presented as analysis.
A working 5×5 matrix calibrates every level. Likelihood becomes a frequency band — “about once in three years” rather than “possible”. Consequence becomes a threshold per consequence type, so a financial consequence has a dollar range, a safety consequence has an injury classification, and a regulatory consequence has a defined enforcement outcome. That is what makes scoring repeatable between assessors, and repeatability is the whole point of Clause 6.4.3.
The second thing most registers get wrong is stopping at the score. A register that records only numbers cannot tell a board whether anything needs to change. What makes it decision-useful is two more columns: how effective the current controls actually are, and whether the residual score sits inside appetite. We publish both worked out in full below.
Where ISO 31000 fits APRA CPS 220 and CPS 230
No Australian law mandates ISO 31000, but several regimes require exactly what it produces. APRA CPS 220 requires regulated institutions to maintain a risk management framework and a board-approved risk appetite statement — Clause 5 gives you the framework structure and Clause 6.3.4 gives you appetite expressed as thresholds rather than intent. CPS 230 requires identification of critical operations with tolerance levels for disruption, and management of service provider risk, which is Clause 6.4 applied beyond your own boundary.
This is why Australian employers ask for ISO 31000-aligned credentials rather than for the standard itself: the standard supplies the vocabulary and method that the prudential framework assumes you already have. If you work in an APRA-regulated entity, that mapping is the practical reason this credential is on the position description.
Organisational risk certification is a separate question from certifying yourself — the ISO 31000 certification guide for Australia covers what applies at the organisation level, and our governance and risk consulting covers doing the work rather than learning it.
Free risk management documents to work through with the course
Risk Manager teaches the process. These are the artefacts you would produce running it for real — published in full, free, no email required.
- Calibrated 5×5 risk matrix (CSV) or PDF — five likelihood levels with frequency bands and five consequence types (financial, safety, regulatory, reputation, service delivery), each with real thresholds.
- Enterprise risk register (CSV) or PDF — twelve worked risks with inherent and residual scoring, control effectiveness, appetite tests and named owners.
- Risk criteria and appetite statement (CSV) or PDF — nine categories with escalation thresholds and key risk indicators.
- AS ISO 31000 mapped to Australian obligations (CSV) or PDF — twenty obligations across APRA, the SOCI Act, the PSPF and more, each mapped to the clause that satisfies it and the evidence to retain.