By the Aegentra Security Team — NV1-cleared risk and assurance practitioners · Published 1 August 2026
Risk management is one of the few Australian professions where the regulator effectively writes the job description. This guide covers the credential behind it — the PECB Risk Manager pathway for ISO 31000: the tiers, the experience and project hours each one needs, the exam, the cost, and the roles it opens.
To become a PECB Certified ISO 31000 Risk Manager you complete the official ISO 31000 Risk Manager training, pass the PECB exam — 60 multiple-choice questions across three competency domains, open book, 70% to pass — then meet the experience tier you are claiming: two years of professional experience with one year in risk management, plus 200 hours of risk management project activity. The entry tier, Provisional Risk Manager, needs only the exam. Aegentra Academy is an official PECB authorised training partner and runs the course for $849 + GST, with the exam voucher and a free 12-month resit included.
ISO 31000:2018 — published in Australia by Standards Australia as AS ISO 31000:2018 — is the international standard giving principles, a framework and a process for managing risk. A Risk Manager is the person who runs that process in practice: the risk register, the criteria that define what is acceptable, the assessment workshops, the treatment plans, and the reporting that lets leadership act. For the standard itself and what it means in Australia, see our ISO 31000 certification guide; this page is about the individual credential and the career behind it.
Two clarifications, because they are where most of the confusion sits. First, no organisation is ever “ISO 31000 certified” — the standard is guidance, there is no organisational audit, and only individuals hold the credential. Second, Risk Manager and Lead Risk Manager are different exams on different schemes, so the one you sit determines the credential ceiling you can reach.
Aegentra Academy is an official PECB authorised training partner and delivers the ISO 31000 Risk Manager course online and self-paced, with instructor-led delivery available on request. Foundation-level grounding is available through the ISO 31000 Foundation course.
“Risk Manager” is not a single pass/fail credential — it is the second rung of a four-rung ladder. What separates the rungs is the professional experience and the hours of hands-on risk management work you can evidence. Note carefully which exam reaches which rung: the Risk Manager exam awards the first two only, and the top two require the Lead Risk Manager exam.
| Credential tier | Total experience | In risk management | Project hours |
|---|---|---|---|
| Provisional Risk Manager | None | None | None |
| Risk Manager | 2 years | 1 year | 200 hours |
| Lead Risk Manager | 5 years | 2 years | 300 hours |
| Senior Lead Risk Manager | 10 years | 7 years | 1,000 hours |
These are PECB scheme requirements, not requirements of the ISO standard itself — confirm the current criteria on the official PECB ISO 31000 Risk Manager page. Every tier also requires signing the PECB Code of Ethics.
Two things are counted separately. Professional experience is your years of work, with a minimum specifically in risk management — one year for Risk Manager, two for Lead Risk Manager, seven for Senior Lead Risk Manager. Project activity hours are hands-on hours doing the risk work itself. This is the part people underestimate and then cannot evidence later. If you already do any of the activities below in a GRC, audit, compliance or operations role, you are banking hours right now and should be logging them with dates and outputs.
No Australian law mandates ISO 31000. Demand arrives through a different door: several regimes require precisely what the standard produces — a documented, repeatable, board-visible risk method. Four pressures account for most of it.
Indicative Australian ranges, drawn from public risk, governance and assurance salary guides — a market guide, not a quote:
| Role | Indicative range (AUD) |
|---|---|
| Risk & Compliance Analyst | $95,000 – $130,000 |
| Risk Manager | $130,000 – $170,000 |
| Senior Risk Manager | $150,000 – $195,000 |
| Head of Risk | $180,000 – $240,000 |
| Chief Risk Officer | $220,000 – $320,000 |
The deciding question is not how much risk experience you have. It is whose risk you are accountable for. Take Risk Manager if you run risk inside a function, business unit or project, working within a framework somebody else designed. Take Lead Risk Manager if you are accountable for the framework itself — setting appetite, chairing the risk committee, and answering to a board for whether the whole thing works.
| ISO 31000 Risk Manager | ISO 31000 Lead Risk Manager | |
|---|---|---|
| Course price | $849 + GST ($928 with eLearning) | $979 + GST |
| Exam | 60 multiple-choice questions, open book | 80 multiple-choice questions, open book |
| Competency domains | 3 | 5 |
| Credentials awarded | Provisional Risk Manager, Risk Manager | The full ladder, up to Senior Lead Risk Manager |
| Who it is for | Running risk in a function or business unit | Owning the framework — heads of risk, CROs, consultants |
The gap between the two courses is $130. The gap between the credentials they can award is considerably larger, because only the Lead exam reaches Lead Risk Manager and Senior Lead Risk Manager. If a head-of-risk track is the destination, that difference matters more than the price. If your organisation needs a risk framework built rather than a person trained, that is our governance and risk practice.
No. ISO 31000 is guidance, not a certifiable management system standard. There is no Stage 1 / Stage 2 audit and no certification body issues an organisational ISO 31000 certificate. Any vendor offering one is selling something that does not formally exist. Only individuals are certified, through PECB.
No, and this is the most misunderstood part of the pathway. The ISO 31000 Risk Manager exam awards Provisional Risk Manager (no experience) or Risk Manager (two years of professional experience, one in risk management, plus 200 hours of project activity). Lead Risk Manager and Senior Lead Risk Manager require the separate Lead Risk Manager exam, which covers five competency domains rather than three.
60 multiple-choice questions across three competency domains, open book, 70% to pass. Each question has three options with one correct answer, mixing stand-alone with scenario-based items. On duration: PECB does not publish one in its candidate handbook for any ISO 31000 exam, so any specific number of hours quoted elsewhere is unsourced. Because it is open book, retrieval speed is the real constraint.
Aegentra Academy runs the official PECB ISO 31000 Risk Manager course for $849 + GST as self-study and $928 + GST for guided eLearning. Both include the official PECB exam voucher and one free resit within 12 months, so there is no separate exam fee. Several Australian providers quote a course fee and bill the examination separately.
Yes. Standards Australia publishes it as AS ISO 31000:2018, an identical adoption — same eight principles, same framework, same process. Note the previous edition was the joint AS/NZS ISO 31000:2009; for the 2018 revision the "/NZS" was dropped, so a document citing AS/NZS ISO 31000 as current refers to a superseded edition.
No, and the relationship usually runs the other way. ISO 27001 requires a documented risk assessment methodology but does not mandate which one, and ISO 31000 — or its information-security-specific companion ISO/IEC 27005 — is the most common choice.
Ready to start? Aegentra Academy is an official PECB authorised training partner and runs the ISO 31000 Risk Manager course for $849 + GST, exam voucher and free 12-month resit included, with instructor-led delivery available on request. More field notes are on the Aegentra Insights hub.