What is ISO 31000?
ISO 31000:2018 is the international standard providing principles, framework, and process for managing risk. Published by the International Organization for Standardization, the 2018 edition replaced the 2009 version and simplified the framework substantially.
The standard has three pillars: eight principles that define what good risk management looks like (integrated, structured, customised, inclusive, dynamic, best available information, human and cultural factors, continual improvement); a framework for embedding risk management into governance, leadership, and accountability; and a process for actually identifying, analysing, evaluating, treating, monitoring, and communicating risks.
The current risk-management vocabulary reference is ISO 31073:2022 — terms like “risk source”, “risk owner”, “residual risk”, and “risk appetite” carry specific meanings that are consistent across all ISO risk-related standards.
AS ISO 31000:2018 — the Australian Standard
In Australia the standard is published by Standards Australia as AS ISO 31000:2018, released on 30 October 2018. It is an identical adoption of ISO 31000:2018 — same principles, same framework, same process. If a tender, policy or position description asks for “AS ISO 31000”, PECB ISO 31000 training covers it.
One detail catches people out. The previous edition was AS/NZS ISO 31000:2009, a joint Australian/New Zealand standard. For the 2018 revision, Standards Australia and Standards New Zealand agreed to publish it as an Australian Standard rather than a joint one, so the “/NZS” was dropped. Documents still citing “AS/NZS ISO 31000” as the current standard are referring to a superseded edition.
How the Australian standard evolved
| Designation | Years | Status |
|---|---|---|
| AS/NZS 4360 | 1995, 1999, 2004 | Superseded |
| AS/NZS ISO 31000 | 2009 | Superseded |
| AS ISO 31000 | 2018 | Current |
Australia has unusual standing here. AS/NZS 4360:1995 was one of the first national risk management standards published anywhere, and it directly shaped ISO 31000 when the international standard was drafted. The Australian approach to risk was exported, then re-adopted under an ISO number — which is why practitioners who learned AS/NZS 4360 find ISO 31000 familiar rather than foreign.
Important: ISO 31000 is guidance, not a certifiable standard
Unlike ISO 27001 or ISO 42001, ISO 31000 does not have a Stage 1/Stage 2 audit and no certificate is issued to organisations. Any vendor offering “ISO 31000 certification” for your company is selling something that does not formally exist. What does exist: individual practitioner certifications through PECB (Foundation, Risk Manager, Lead Risk Manager) — those credentials apply to a person, not a company.
The reason is design intent. ISO 31000 is deliberately principle-based so it can be applied to any organisation, regardless of sector, size, or risk maturity. Removing the prescriptive “shall” requirements that auditors rely on was a conscious choice; the trade-off is that the standard cannot be audited the way ISO 27001 can.
ISO/IEC 27005 provides information-security-specific risk guidance. An organisation can use it, ISO 31000 or another suitable method inside an ISO 27001 ISMS; the certification audit evaluates the organisation's documented method against ISO 27001 requirements.
Who benefits from ISO 31000 in Australia?
Even though organisational certification doesn't exist, the framework and individual training may be useful to people responsible for structured risk work. Relevant roles include:
- Risk and compliance professionals who maintain risk criteria, registers, treatment plans and reporting across an organisation.
- APRA-regulated entities — banks, insurers and super funds — whose teams must understand the organisation's chosen method for meeting CPS 220, CPS 230 and CPS 234 obligations. Those standards do not mandate an ISO 31000 method or a PECB credential.
- ISO 27001 implementers who want a deeper grounding in risk methodology than the ISO 27001 Lead Implementer course provides on its own.
- Internal audit and second-line risk teams that evaluate whether risk criteria, assessments, treatments and reporting are applied consistently.
Industries that use ISO 31000 in Australia
ISO 31000 can be considered by organisations in financial services, listed-company governance, the public sector and critical infrastructure. The applicable laws and frameworks remain the authority. None of the regimes below universally requires a PECB ISO 31000 credential.
APRA-regulated entities (CPS 230 + CPS 220)
Banks, mutuals, insurers, and superannuation funds operating under APRA CPS 230 (operational risk management) and CPS 220 (risk management framework) need a documented risk-management methodology. ISO 31000 can provide a general method, but compliance must be assessed against the prudential standards and the entity's actual obligations; the standards do not prescribe a PECB credential.
ASX-listed companies and corporate governance
The ASX Corporate Governance Principles and Recommendations (4th edition) — Principle 7 in particular — expects listed entities to maintain a sound risk management framework and to disclose it. ISO 31000 can inform that framework, but Principle 7 does not prescribe ISO 31000 training or a personnel credential.
Government, public sector, and Comcover
The Commonwealth Risk Management Policy(administered by Comcover) sets out risk-management expectations for Commonwealth entities. ISO 31000 is the international standard the policy aligns with. State equivalents (e.g. Victorian Government Risk Management Framework) have their own requirements. Alignment to a risk framework does not establish government recognition of, or a universal requirement for, a PECB credential.
Mining, energy, and SOCI-captured critical infrastructure
Operators captured by the Security of Critical Infrastructure (SOCI) Act — energy, water, ports, communications, financial-market infrastructure, data-storage and processing — must maintain Risk Management Programs covering hazards across cyber, personnel, supply-chain, and physical domains. ISO 31000 is one framework that can help structure cross-domain risk work, but the SOCI Act and applicable Rules remain the compliance authority and do not prescribe a PECB credential.
Where ISO 31000 sits in Australian risk regulation
ISO 31000 is voluntary guidance, but it appears under the surface of many of Australia's risk-management requirements. The table summarises how the standard relates to the Australian regulations Aegentra is most often asked about.
| Australian regulation / framework | What it requires | How ISO 31000 helps |
|---|---|---|
| APRA CPS 230 | Operational risk management for APRA-regulated entities — risk identification, controls, business continuity, third-party arrangements. | ISO 31000 can provide a general risk-management method, but it does not replace the specific requirements of CPS 230 or mandate a personnel credential. |
| APRA CPS 220 | Risk management framework for APRA-regulated entities — board accountability, risk appetite, risk culture, independent assurance. | ISO 31000 can inform risk principles and process. The entity still has to demonstrate compliance with CPS 220 against its own framework and evidence. |
| ASX Corporate Governance Principles (4th ed.) | Principle 7 expects listed entities to maintain a sound risk management framework and disclose it. | ISO 31000 can inform the framework, but Principle 7 does not prescribe it or require a PECB credential. |
| Commonwealth Risk Management Policy | Risk-management expectations for Commonwealth entities, administered by Comcover. | Use the current Commonwealth policy as the authority. Alignment with ISO 31000 does not make a PECB credential a government requirement. |
| SOCI Act — Risk Management Program rules | Captured critical-infrastructure entities must document an integrated RMP covering cyber, personnel, supply-chain, and physical hazards. | ISO 31000 can help structure an integrated, cross-hazard method, but the Act and RMP Rules determine compliance. |
| ASIC RG 271 (internal dispute resolution) | ASIC RG 271 sets internal dispute resolution requirements for covered financial firms; separate instruments govern broader risk obligations. | ISO 31000 supports the underlying risk-management framework, particularly when combined with operational risk requirements from APRA CPS 230. |
| ISO 27001 (information security) | Requires a documented risk-assessment methodology; does not mandate which. | ISO 31000 (and its companion ISO/IEC 27005) is the kind of general method an organisation may adapt for its ISO 27001 risk assessment. ISO 27001 does not prescribe it. |
| ISO 42001 (AI management) | Requires AI-specific risk identification and treatment across bias, accuracy, robustness, transparency, and safety dimensions. | ISO 31000 provides the underlying risk-management framework; ISO/IEC 23894 (AI-specific risk guidance) layers on top. |
The relationship between ISO 31000 and each regime depends on the organisation's chosen method and evidence. None of these regimes, by itself, establishes a requirement for or recognition of a PECB ISO 31000 credential.
How much does ISO 31000 training cost in Australia?
Because there is no organisational certification, these are individual training prices. Each listed package includes the applicable official PECB exam. Current AUD pricing through Aegentra Academy (official PECB authorised training partner):
| Level | Delivery | AUD price excluding GST | Typical effort | Exam and resit |
|---|---|---|---|---|
| ISO 31000 Foundation | Self-Study | A$379 | 8–12 hours | 1-hour exam; voucher and one free resit included |
| ISO 31000 Risk Manager | Self-Study | A$579 | 25–35 hours | 2-hour exam; voucher and one free resit included |
| ISO 31000 Risk Manager | eLearning | A$599 | 20–30 hours · approximately 3–4 training days | 2-hour exam; voucher and one free resit included |
| ISO 31000 Lead Risk Manager | Self-Study | A$979 | 35–45 hours | 3-hour exam; voucher and one free resit included |
Prices above exclude applicable tax. For an Australian billing address, 10% GST is added. There is no separate examination fee at any level — the official PECB exam voucher and one free resit within 12 months are included. Foundation is closed book; Risk Manager and Lead Risk Manager are open book. The exam is separate from the typical learning-effort range.
The 8 risk principles and the process
The 2018 edition codifies eight principles for what good risk management looks like:
- Integrated — risk management is part of all organisational activities, not a separate function.
- Structured and comprehensive — a consistent approach produces consistent, comparable results.
- Customised — the framework and process are tailored to the organisation's objectives and external/internal context.
- Inclusive — appropriate involvement of stakeholders enables their knowledge and views to be considered.
- Dynamic — risk management anticipates and responds to changes in context.
- Best available information — explicit about the quality of the information used.
- Human and cultural factors — recognises that human behaviour and culture influence every aspect of risk management.
- Continual improvement — risk management is continually improved through learning and experience.
The risk management process is the operational sequence:
- Communication and consultation (continuous, throughout).
- Establishing the scope, context, and criteria.
- Risk identification.
- Risk analysis.
- Risk evaluation.
- Risk treatment.
- Monitoring and review (continuous, throughout).
- Recording and reporting.
Choosing a PECB ISO 31000 course
The course pathway is Foundation → Risk Manager → Lead Risk Manager. Each course includes its applicable official exam and one free resit within 12 months:
- ISO 31000 Foundation — for managers and project owners who need to understand the framework without operating it day-to-day. Self-Study is A$379 excluding GST with 8–12 hours of typical learning effort.
- ISO 31000 Risk Manager — for people running risk in a function (information security risk, operational risk, project risk) and ready to apply the full process. Self-Study is A$579 excluding GST with 25–35 hours of typical effort; eLearning is A$599 excluding GST with 20–30 hours, approximately 3–4 training days.
- ISO 31000 Lead Risk Manager — for chief risk officers, heads of risk, and consultants leading enterprise-wide risk programs. Covers board reporting, risk appetite, KRIs, and risk culture in depth. Self-Study is A$979 excluding GST with 35–45 hours of typical learning effort.
PECB publishes accreditation information by credential. Personnel certifications fall under applicable ISO/IEC 17024 scopes, while specified certificate programs appear in ANAB’s ANSI/ASTM E2659-24 scope. Verify the applicable PECB scope before relying on a particular accreditation. Aegentra Academy is on the PECB partner directory — online delivery, with private instructor-led delivery for an organisation or group scoped separately and confirmed in writing.
ISO 31000 vs ISO 27005 vs COSO ERM
Three frameworks Australian risk professionals routinely encounter:
ISO 31000:2018 — generic, principle-based, applicable to any organisation. Not certifiable for organisations. The shared vocabulary across all ISO risk standards.
ISO/IEC 27005:2022 — information security risk management specifically. More prescriptive than ISO 31000 and used as the risk methodology inside ISO 27001 certifications. Not separately certifiable for organisations either, but is audited as part of the ISO 27001 Stage 2 audit.
COSO ERM (2017) — published by the Committee of Sponsoring Organizations in the US. Strong in financial services and listed companies; provides a five-component, 20- principle framework. ISO 31000 and COSO ERM are largely compatible at the principles level but differ in the level of detail and the assumed organisational structure.
An organisation may use ISO 31000 as an umbrella risk method, ISO/IEC 27005 for information-security risk inside an ISO 27001 ISMS, or COSO ERM where that framework has been selected. The right choice depends on the organisation's obligations and approved governance model.
Who needs ISO 31000 certification in Australia?
Nobody is legally required to hold a PECB ISO 31000 credential. The training may be relevant where a role involves designing, operating or reviewing a structured risk-management method. Examples include the four groups below.
Risk and compliance staff in APRA-regulated entities. CPS 220 requires a board-approved risk management framework and appetite statement; CPS 230 adds critical operations, disruption tolerances and service-provider risk. Neither names ISO 31000, but both require documented risk work. The organisation's chosen method and role requirements determine whether ISO 31000 training is relevant.
Critical infrastructure operators under the SOCI Act. Responsible entities across the designated sectors must maintain a written all-hazards Risk Management Program covering cyber, personnel, supply chain and physical risk, reported annually to the board and the regulator. ISO 31000 may help structure the general risk method, but the Act and Rules determine compliance and do not prescribe a PECB credential.
Commonwealth and state government risk teams. The PSPF requires entities to manage security risk using a risk management approach, with the Accountable Authority attesting annually to security maturity. The Commonwealth Risk Management Policy under the PGPA Act requires systems of risk oversight, and Comcover benchmarks risk maturity annually — which rewards a framework producing comparable year-on-year evidence. These government frameworks do not, by themselves, recognise or require a PECB ISO 31000 credential.
ISO 27001 practitioners who need the risk half. ISO 27001 requires a documented risk assessment methodology but does not mandate which one. ISO 31000 — or ISO/IEC 27005 for the information-security-specific version — can inform that method. See the ISO 27001 certification guide for the other side of that pairing.
How long does ISO 31000 certification take?
Because only individuals are certified, the timeline is study time plus one exam — not a readiness project and a two-stage audit. There is no organisational timeline, because there is no organisational certificate.
Foundation has 8–12 hours of estimated self-paced learning effort. Individual completion time varies. The exam is 40 multiple-choice questions across two competency domains, and it is the only ISO 31000 level sat closed book. PECB’s current official brochure publishes a one-hour exam duration.
Risk Manager Self-Study has 25–35 hours of typical total learning effort. Risk Manager eLearning has 20–30 hours, approximately 3–4 training days. These are estimated workloads, not video runtime or completion guarantees. Both formats lead to the same 60-question, three-domain, open-book, two-hour exam.
Lead Risk Manager Self-Study has 35–45 hours of typical total learning effort. The exam is 80 multiple-choice questions across five domains, open book, with a three-hour duration.
Question counts come from PECB’s current candidate handbooks; exam durations come from PECB’s current official course brochures. These remain separate from the typical learning-effort ranges above. On the credential pathway, PECB’s 2026 Risk Manager Candidate Handbook assigns the 60-question exam to Provisional Risk Manager and Risk Manager, while PECB’s current public Risk Manager course table also displays Lead tiers. Because those official sources conflict, Aegentra does not promise a Lead-tier outcome from the Risk Manager exam. The evidence and recommended next step are set out in how to become an ISO 31000 Risk Manager in Australia.
Free ISO 31000 risk management templates
The four working documents an ISO 31000 framework actually produces, published in full and free — no email required. They are worked examples for an Australian organisation, not blank forms.
- Calibrated 5×5 risk matrix (PDF) or CSV — likelihood as frequency bands and five consequence types with real thresholds. Most matrices fail because “Possible” and “Major” mean whatever the scorer wants.
- Risk criteria and appetite statement (PDF) or CSV — the Clause 6.3.4 artefact, nine categories with escalation thresholds to executive and board plus a named KRI each.
- Enterprise risk register (PDF) or CSV — twelve worked risks with inherent and residual scoring, control effectiveness, and an explicit within-appetite test.
- AS ISO 31000 mapped to Australian obligations (PDF) or CSV — twenty obligations across APRA CPS 220, CPS 230 and CPS 234, the SOCI Act, the PSPF, the Commonwealth Risk Management Policy, Comcover, ASX Principle 7, WHS and the Privacy Act, each with a potentially relevant ISO 31000 clause and suggested evidence to consider.
If you would rather the framework was built than studied, that is our governance and risk practice.
Course-material access, examination and retake deadlines, and any certificate-application deadline are separate. Confirm the material-access start date in your booking confirmation and check the deadlines recorded in myPECB before scheduling your examination. PECB’s partner-course policy sets a 12-month examination and included-retake cycle from purchase for Self-Study and eLearning, or from course completion for instructor-led training. A failed attempt does not restart that cycle. The first retake requires at least 15 days after the unsuccessful examination; booking rules and the recorded myPECB deadline also apply.
FAQs
Can my organisation be "ISO 31000 certified"?
No. ISO 31000 is guidance, not a certifiable management system standard. There is no Stage 1/Stage 2 certification audit and no accredited organisational ISO 31000 certificate. PECB offers individual Foundation, Risk Manager and Lead Risk Manager pathways; those credentials apply to the practitioner, not the company.
Why is ISO 31000 not certifiable like ISO 27001?
ISO designed ISO 31000 to be applicable to any organisation regardless of size, sector, or risk maturity. To stay that universal, the standard avoids prescriptive "shall" requirements. Without prescriptive requirements, there is nothing concrete for an auditor to issue a non-conformity against. The companion standard ISO/IEC 27005 (information security risk management) is closer to auditable territory and is used inside ISO 27001 certifications.
So what is the point of pursuing ISO 31000?
The framework gives boards, audit committees and operational teams a shared vocabulary and a structured enterprise risk management approach. Individual training can help a practitioner learn to apply that framework. No law, regulator, employer, tender panel or professional body universally requires or recognises a PECB ISO 31000 credential; verify the requirements of the specific role or procurement process.
Does ISO 31000 satisfy APRA CPS 230 or CPS 234?
No. APRA CPS 230 and CPS 234 impose their own obligations on APRA-regulated entities. ISO 31000 can help structure a general risk-management method, but it does not establish compliance and neither prudential standard mandates ISO 31000 training or a PECB credential.
How is ISO 31000 used inside ISO 27001 readiness?
ISO 27001 requires a documented risk assessment methodology but does not mandate which one. An organisation may adapt ISO 31000, or the information-security-specific ISO/IEC 27005, when designing its risk criteria, assessment and treatment process.
What is the difference between Foundation, Risk Manager, and Lead Risk Manager?
Foundation is an overview — for general managers, project owners, and non-specialists who need to understand the framework. Risk Manager is the practitioner course — for people running risk programs in their function or business unit. Lead Risk Manager is the senior pathway — for chief risk officers, heads of risk, and consultants leading enterprise risk programs across a whole organisation.
How long does the Lead Risk Manager course take?
Typical total learning effort for the current Self-Study course is 35–45 hours. This is an estimated workload, not video runtime, exam duration or a completion guarantee. Individual completion time varies, and the exam is scheduled separately.
How do I verify accreditation for a PECB credential?
Accreditation varies by credential. PECB publishes personnel-certification accreditation under applicable ISO/IEC 17024 scopes and ANAB certificate-program accreditation under ANSI/ASTM E2659-24 for specified programs. Verify the applicable published PECB scope for the credential you are considering.
How much does ISO 31000 certification cost in Australia?
Because ISO 31000 cannot be certified at the organisation level, these are individual training prices. Aegentra Academy currently lists Foundation Self-Study at A$379 excluding GST with 8–12 hours of typical effort; Risk Manager Self-Study at A$579 excluding GST with 25–35 hours; Risk Manager eLearning at A$599 excluding GST with 20–30 hours, approximately 3–4 training days; and Lead Risk Manager Self-Study at A$979 excluding GST with 35–45 hours. Each includes the official PECB examination voucher, one free resit within 12 months and 12 months of myPECB access.
How many questions are on the ISO 31000 exams?
ISO 31000 Foundation: Multiple-choice. Duration: 1 hour. 40 multiple-choice questions across 2 competency domains — fundamental principles and concepts of risk management, and the risk management framework and process. Each question has three options with one correct response.. Passing requirements: 70%. Check the current PECB examination record and assigned examination before booking. ISO 31000 Risk Manager: Open-book, multiple-choice — stand-alone and scenario-based questions. Duration: 120 minutes. 60 multiple-choice questions across 3 competency domains — 12 questions on fundamental principles and concepts of risk management (20%), 14 on establishment of a risk management framework (23.33%), and 34 on implementation of a risk management process (56.67%).. Passing requirements: 70%. Check the current PECB examination record and assigned examination before booking. ISO 31000 Lead Risk Manager: Open-book, multiple-choice — stand-alone and scenario-based questions. Duration: 3 hours. 80 multiple-choice questions across 5 competency domains — fundamental principles and concepts of risk management, establishment of the risk management framework, initiation of the risk management process and risk assessment, risk treatment and risk recording and reporting, and risk monitoring, review, communication and consultation.. Passing requirements: 70%. Check the current PECB examination record and assigned examination before booking.
Is the ISO 31000 Risk Manager exam an essay exam?
No. PECB’s 2026 Risk Manager Candidate Handbook specifies 60 multiple-choice questions across three competency domains, open book. The official course brochure publishes a two-hour exam duration.
Does the Risk Manager exam lead to the Lead Risk Manager credential?
PECB’s 2026 Risk Manager Candidate Handbook assigns the 60-question exam to Provisional Risk Manager and Risk Manager only. However, PECB’s current public Risk Manager course table also displays Lead and Senior Lead tiers, which conflicts with that handbook and PECB’s separate Lead Risk Manager scheme. Aegentra does not promise a Lead-tier credential from the Risk Manager exam. If Lead or Senior Lead is your intended outcome, choose Lead Risk Manager or confirm eligibility with PECB in writing before enrolment.
What is the difference between AS ISO 31000 and AS/NZS ISO 31000?
AS ISO 31000:2018 is the current Australian Standard, published by Standards Australia as an identical adoption of ISO 31000:2018. The previous edition was AS/NZS ISO 31000:2009, a joint Australian and New Zealand standard; for the 2018 revision it was published as an Australian Standard rather than a joint one, so the "/NZS" was dropped. A policy or tender still citing AS/NZS ISO 31000 as current is referring to a superseded edition. Australia has unusual standing here — AS/NZS 4360:1995 was among the first national risk management standards published anywhere and directly shaped ISO 31000 when the international standard was drafted.
Which ISO 31000 course should I take?
Foundation if you contribute to risk decisions without being a specialist — general managers, project owners, board members, internal auditors. Risk Manager if you run risk inside a function, business unit or project, working within a framework somebody else designed. Lead Risk Manager if you are accountable for the framework itself: setting appetite, chairing the risk committee, and answering to a board for whether it works. The deciding question is not how much experience you have, it is whose risk you are accountable for.