Skip to main content

How to become an ISO 31000 Risk Manager in Australia

By the Aegentra Security Team — NV1-cleared risk and assurance practitioners · Published 1 August 2026

Risk management is one of the few Australian professions where the regulator effectively writes the job description. This guide covers the credential behind it — the PECB Risk Manager pathway for ISO 31000: the tiers, the experience and project hours each one needs, the exam, the cost, and the roles it opens.

To become a PECB Certified ISO 31000 Risk Manager you complete the official ISO 31000 Risk Manager training, pass the PECB exam — 60 multiple-choice questions across three competency domains, open book, 70% to pass — then meet the experience tier you are claiming: two years of professional experience with one year in risk management, plus 200 hours of risk management project activity. The entry tier, Provisional Risk Manager, needs only the exam. Aegentra Academy is an official PECB authorised training partner and runs the course for $849 + GST, with the exam voucher and a free 12-month resit included.

What an ISO 31000 Risk Manager actually is

ISO 31000:2018 — published in Australia by Standards Australia as AS ISO 31000:2018 — is the international standard giving principles, a framework and a process for managing risk. A Risk Manager is the person who runs that process in practice: the risk register, the criteria that define what is acceptable, the assessment workshops, the treatment plans, and the reporting that lets leadership act. For the standard itself and what it means in Australia, see our ISO 31000 certification guide; this page is about the individual credential and the career behind it.

Two clarifications, because they are where most of the confusion sits. First, no organisation is ever “ISO 31000 certified” — the standard is guidance, there is no organisational audit, and only individuals hold the credential. Second, Risk Manager and Lead Risk Manager are different exams on different schemes, so the one you sit determines the credential ceiling you can reach.

The step-by-step pathway

  1. Get the vocabulary grounding. If you have never worked inside a formal risk framework, start with ISO 31000 Foundation — it covers the eight principles, the framework, the process and the ISO Guide 73 vocabulary the Risk Manager course assumes you already have. If you already run risk assessments day to day, skip it.
  2. Take the official Risk Manager course. The official PECB ISO 31000 Risk Manager course teaches you to establish a risk management framework and run the process end to end — scope, context and risk criteria, identification, analysis, evaluation, treatment, monitoring and reporting. PECB supplies over 300 pages of course material alongside it.
  3. Sit and pass the PECB exam. 60 multiple-choice questions across three competency domains, open book, 70% to pass. It is not an essay exam, despite what several course pages claim. Being open book you may bring a hard copy of ISO 31000, the course materials and your own notes, so retrieval speed matters more than memorisation. Pass it and you hold Provisional Risk Manager with no experience required.
  4. Log your experience and project hours. PECB counts two things separately — years of professional experience with a minimum specifically in risk management, and hours of hands-on risk management project activity. Keep a running log with dates, the organisation, the deliverable and the hours. Reconstructing it two years later is painful.
  5. Sign the Code of Ethics and apply for your tier. Every tier requires signing the PECB Code of Ethics and submitting an application with references. PECB verifies the claim and issues a digital credential a procurement team or hiring manager can verify independently.
  6. Decide whether to go on to Lead Risk Manager. If you move from running risk inside a business unit to owning the framework itself — setting appetite, chairing the risk committee, reporting to a board — the Lead Risk Manager exam covers five domains rather than three and carries the full credential ladder. It is the only route to those two tiers.

Aegentra Academy is an official PECB authorised training partner and delivers the ISO 31000 Risk Manager course online and self-paced, with instructor-led delivery available on request. Foundation-level grounding is available through the ISO 31000 Foundation course.

Credential tiers and the experience each one needs

“Risk Manager” is not a single pass/fail credential — it is the second rung of a four-rung ladder. What separates the rungs is the professional experience and the hours of hands-on risk management work you can evidence. Note carefully which exam reaches which rung: the Risk Manager exam awards the first two only, and the top two require the Lead Risk Manager exam.

Credential tierTotal experienceIn risk managementProject hours
Provisional Risk ManagerNoneNoneNone
Risk Manager2 years1 year200 hours
Lead Risk Manager5 years2 years300 hours
Senior Lead Risk Manager10 years7 years1,000 hours

These are PECB scheme requirements, not requirements of the ISO standard itself — confirm the current criteria on the official PECB ISO 31000 Risk Manager page. Every tier also requires signing the PECB Code of Ethics.

What counts as risk management project hours

Two things are counted separately. Professional experience is your years of work, with a minimum specifically in risk management — one year for Risk Manager, two for Lead Risk Manager, seven for Senior Lead Risk Manager. Project activity hours are hands-on hours doing the risk work itself. This is the part people underestimate and then cannot evidence later. If you already do any of the activities below in a GRC, audit, compliance or operations role, you are banking hours right now and should be logging them with dates and outputs.

Why Australian regulators drive demand for this role

No Australian law mandates ISO 31000. Demand arrives through a different door: several regimes require precisely what the standard produces — a documented, repeatable, board-visible risk method. Four pressures account for most of it.

Jobs and indicative salaries in Australia

Indicative Australian ranges, drawn from public risk, governance and assurance salary guides — a market guide, not a quote:

RoleIndicative range (AUD)
Risk & Compliance Analyst$95,000 – $130,000
Risk Manager$130,000 – $170,000
Senior Risk Manager$150,000 – $195,000
Head of Risk$180,000 – $240,000
Chief Risk Officer$220,000 – $320,000

Risk Manager vs Lead Risk Manager

The deciding question is not how much risk experience you have. It is whose risk you are accountable for. Take Risk Manager if you run risk inside a function, business unit or project, working within a framework somebody else designed. Take Lead Risk Manager if you are accountable for the framework itself — setting appetite, chairing the risk committee, and answering to a board for whether the whole thing works.

ISO 31000 Risk ManagerISO 31000 Lead Risk Manager
Course price$849 + GST ($928 with eLearning)$979 + GST
Exam60 multiple-choice questions, open book80 multiple-choice questions, open book
Competency domains35
Credentials awardedProvisional Risk Manager, Risk ManagerThe full ladder, up to Senior Lead Risk Manager
Who it is forRunning risk in a function or business unitOwning the framework — heads of risk, CROs, consultants

The gap between the two courses is $130. The gap between the credentials they can award is considerably larger, because only the Lead exam reaches Lead Risk Manager and Senior Lead Risk Manager. If a head-of-risk track is the destination, that difference matters more than the price. If your organisation needs a risk framework built rather than a person trained, that is our governance and risk practice.

Frequently asked questions

Can my organisation be ISO 31000 certified?

No. ISO 31000 is guidance, not a certifiable management system standard. There is no Stage 1 / Stage 2 audit and no certification body issues an organisational ISO 31000 certificate. Any vendor offering one is selling something that does not formally exist. Only individuals are certified, through PECB.

Does the Risk Manager exam lead to Lead Risk Manager?

No, and this is the most misunderstood part of the pathway. The ISO 31000 Risk Manager exam awards Provisional Risk Manager (no experience) or Risk Manager (two years of professional experience, one in risk management, plus 200 hours of project activity). Lead Risk Manager and Senior Lead Risk Manager require the separate Lead Risk Manager exam, which covers five competency domains rather than three.

How hard is the exam, and how long is it?

60 multiple-choice questions across three competency domains, open book, 70% to pass. Each question has three options with one correct answer, mixing stand-alone with scenario-based items. On duration: PECB does not publish one in its candidate handbook for any ISO 31000 exam, so any specific number of hours quoted elsewhere is unsourced. Because it is open book, retrieval speed is the real constraint.

How much does the course cost in Australia?

Aegentra Academy runs the official PECB ISO 31000 Risk Manager course for $849 + GST as self-study and $928 + GST for guided eLearning. Both include the official PECB exam voucher and one free resit within 12 months, so there is no separate exam fee. Several Australian providers quote a course fee and bill the examination separately.

Is ISO 31000 the same as AS ISO 31000?

Yes. Standards Australia publishes it as AS ISO 31000:2018, an identical adoption — same eight principles, same framework, same process. Note the previous edition was the joint AS/NZS ISO 31000:2009; for the 2018 revision the "/NZS" was dropped, so a document citing AS/NZS ISO 31000 as current refers to a superseded edition.

Do I need ISO 27001 before ISO 31000?

No, and the relationship usually runs the other way. ISO 27001 requires a documented risk assessment methodology but does not mandate which one, and ISO 31000 — or its information-security-specific companion ISO/IEC 27005 — is the most common choice.

Ready to start? Aegentra Academy is an official PECB authorised training partner and runs the ISO 31000 Risk Manager course for $849 + GST, exam voucher and free 12-month resit included, with instructor-led delivery available on request. More field notes are on the Aegentra Insights hub.