What is ISO 31000?
ISO 31000:2018 is the international standard providing principles, framework, and process for managing risk. Published by the International Organization for Standardization, the 2018 edition replaced the 2009 version and simplified the framework substantially.
The standard has three pillars: eight principles that define what good risk management looks like (integrated, structured, customised, inclusive, dynamic, best available information, human and cultural factors, continual improvement); a framework for embedding risk management into governance, leadership, and accountability; and a process for actually identifying, analysing, evaluating, treating, monitoring, and communicating risks.
The vocabulary is defined in ISO Guide 73:2009 — terms like “risk source”, “risk owner”, “residual risk”, and “risk appetite” carry specific meanings that are consistent across all ISO risk-related standards.
AS ISO 31000:2018 — the Australian Standard
In Australia the standard is published by Standards Australia as AS ISO 31000:2018, released on 30 October 2018. It is an identical adoption of ISO 31000:2018 — same principles, same framework, same process. If a tender, policy or position description asks for “AS ISO 31000”, PECB ISO 31000 training covers it.
One detail catches people out. The previous edition was AS/NZS ISO 31000:2009, a joint Australian/New Zealand standard. For the 2018 revision, Standards Australia and Standards New Zealand agreed to publish it as an Australian Standard rather than a joint one, so the “/NZS” was dropped. Documents still citing “AS/NZS ISO 31000” as the current standard are referring to a superseded edition.
How the Australian standard evolved
| Designation | Years | Status |
|---|---|---|
| AS/NZS 4360 | 1995, 1999, 2004 | Superseded |
| AS/NZS ISO 31000 | 2009 | Superseded |
| AS ISO 31000 | 2018 | Current |
Australia has unusual standing here. AS/NZS 4360:1995 was one of the first national risk management standards published anywhere, and it directly shaped ISO 31000 when the international standard was drafted. The Australian approach to risk was exported, then re-adopted under an ISO number — which is why practitioners who learned AS/NZS 4360 find ISO 31000 familiar rather than foreign.
Important: ISO 31000 is guidance, not a certifiable standard
Unlike ISO 27001 or ISO 42001, ISO 31000 does not have a Stage 1/Stage 2 audit and no certificate is issued to organisations. Any vendor offering “ISO 31000 certification” for your company is selling something that does not formally exist. What does exist: individual practitioner certifications through PECB (Foundation, Risk Manager, Lead Risk Manager) — those credentials apply to a person, not a company.
The reason is design intent. ISO 31000 is deliberately principle-based so it can be applied to any organisation, regardless of sector, size, or risk maturity. Removing the prescriptive “shall” requirements that auditors rely on was a conscious choice; the trade-off is that the standard cannot be audited the way ISO 27001 can.
For organisations wanting a certifiable risk standard, ISO/IEC 27005 (information security risk management) is closer to auditable territory and is the methodology most commonly used inside ISO 27001 certifications.
Who benefits from ISO 31000 in Australia?
Even though organisational certification doesn't exist, the framework and the practitioner credentials are highly valued. The people who most commonly take ISO 31000 courses in Australia:
- Risk and compliance professionals at ASX-listed companies, government departments, and financial institutions — where PECB Lead Risk Manager is a recognised senior credential on tender responses and procurement panels.
- APRA-regulated entities — banks, insurers, super funds — using ISO 31000 as the methodology underpinning CPS 230 (operational risk) and CPS 234 (information security risk) compliance.
- ISO 27001 implementers who want a deeper grounding in risk methodology than the ISO 27001 Lead Implementer course provides on its own.
- Internal audit teams at Big-Four advisory firms and second-line risk functions where ISO 31000 is the assumed common vocabulary across engagements.
Industries that use ISO 31000 in Australia
Four sectors drive most Australian ISO 31000 training demand: APRA-regulated financial services, ASX-listed companies under corporate-governance recommendations, government and public sector under Comcover and PSPF, and mining / energy / critical-infrastructure operators under the SOCI Act. The standard is voluntary across all four, but the credentials are consistently expected.
APRA-regulated entities (CPS 230 + CPS 220)
Banks, mutuals, insurers, and superannuation funds operating under APRA CPS 230 (operational risk management) and CPS 220 (risk management framework) need a documented risk-management methodology. ISO 31000 is the most commonly cited international standard used to satisfy the methodological expectation. Lead Risk Manager-credentialled practitioners staff the second-line risk functions designing and operating those frameworks.
ASX-listed companies and corporate governance
The ASX Corporate Governance Principles and Recommendations (4th edition) — Principle 7 in particular — expects listed entities to maintain a sound risk management framework and to disclose it. ISO 31000 is the international standard most often cited as the underlying framework. Chief Risk Officers, Heads of Risk, and audit-committee chairs of ASX-listed entities expect their senior risk staff to hold ISO 31000-aligned credentials.
Government, public sector, and Comcover
The Commonwealth Risk Management Policy(administered by Comcover) sets out risk-management expectations for Commonwealth entities. ISO 31000 is the international standard the policy aligns with. State equivalents (e.g. Victorian Government Risk Management Framework) follow similar lines. Public-sector risk functions, internal audit teams, and the audit-and-risk committees of agencies routinely require ISO 31000-aligned credentials for senior risk staff.
Mining, energy, and SOCI-captured critical infrastructure
Operators captured by the Security of Critical Infrastructure (SOCI) Act — energy, water, ports, communications, financial-market infrastructure, data-storage and processing — must maintain Risk Management Programs covering hazards across cyber, personnel, supply-chain, and physical domains. ISO 31000 is the methodology most commonly used to underpin the RMP. Mining and resources sector risk programmes (driven by operational safety, environmental, and ESG obligations) similarly lean on ISO 31000 as the cross-domain risk methodology.
Where ISO 31000 sits in Australian risk regulation
ISO 31000 is voluntary guidance, but it appears under the surface of many of Australia's risk-management requirements. The table summarises how the standard relates to the Australian regulations Aegentra is most often asked about.
| Australian regulation / framework | What it requires | How ISO 31000 helps |
|---|---|---|
| APRA CPS 230 | Operational risk management for APRA-regulated entities — risk identification, controls, business continuity, third-party arrangements. | Provides the risk-management methodology the operational-risk framework expects. Lead Risk Manager is the credential for the practitioner running the framework. |
| APRA CPS 220 | Risk management framework for APRA-regulated entities — board accountability, risk appetite, risk culture, independent assurance. | ISO 31000 is the international standard most commonly used to satisfy the methodological expectations of CPS 220. The principles and process are imported wholesale into many CPS 220 frameworks. |
| ASX Corporate Governance Principles (4th ed.) | Principle 7 expects listed entities to maintain a sound risk management framework and disclose it. | ISO 31000 is the international standard most often cited in ASX entity risk-framework disclosures. |
| Commonwealth Risk Management Policy | Risk-management expectations for Commonwealth entities, administered by Comcover. | Explicitly aligned with ISO 31000. The Policy references the standard as the international baseline for Commonwealth risk practice. |
| SOCI Act — Risk Management Program rules | Captured critical-infrastructure entities must document an integrated RMP covering cyber, personnel, supply-chain, and physical hazards. | ISO 31000 is the most commonly used methodology for the integrated, cross-hazard risk programme the RMP Rules expect. |
| ASIC RG 271 (and broader risk obligations) | Australian Financial Services Licensees face conduct-risk and operational-risk obligations under ASIC regulatory guides. | ISO 31000 supports the underlying risk-management framework, particularly when combined with operational risk requirements from APRA CPS 230. |
| ISO 27001 (information security) | Requires a documented risk-assessment methodology; does not mandate which. | ISO 31000 (and its companion ISO/IEC 27005) is the most common methodology imported into ISO 27001 risk registers and Statements of Applicability. |
| ISO 42001 (AI management) | Requires AI-specific risk identification and treatment across bias, accuracy, robustness, transparency, and safety dimensions. | ISO 31000 provides the underlying risk-management framework; ISO/IEC 23894 (AI-specific risk guidance) layers on top. |
ISO 31000 sits under almost every Australian risk regime — rarely as a literal requirement, but consistently as the methodology that satisfies the framework expectations of regulators, boards, and audit committees.
How much does ISO 31000 training cost in Australia?
Because there is no organisational certification, the only direct costs are individual training and the official PECB exam. AUD pricing through Aegentra Academy (official PECB authorised training partner):
| Level | Price | Exam voucher | Free resit | Who it is for |
|---|---|---|---|---|
| ISO 31000 Foundation | $379 + GST | Included | Included | General managers and non-specialists |
| ISO 31000 Risk Manager | $594 + GST | Included | Included | Practitioners running risk in a business unit |
| ISO 31000 Lead Risk Manager | $979 + GST | Included | Included | CROs, heads of risk, consultants leading enterprise programs |
There is no separate examination fee at any level — the official PECB exam voucher and one free resit within 12 months are included in the price shown. Exams are open-book and remotely proctored, so you can sit them from anywhere in Australia. Tax invoices with GST and ABN are issued automatically at checkout.
The 8 risk principles and the process
The 2018 edition codifies eight principles for what good risk management looks like:
- Integrated — risk management is part of all organisational activities, not a separate function.
- Structured and comprehensive — a consistent approach produces consistent, comparable results.
- Customised — the framework and process are tailored to the organisation's objectives and external/internal context.
- Inclusive — appropriate involvement of stakeholders enables their knowledge and views to be considered.
- Dynamic — risk management anticipates and responds to changes in context.
- Best available information — explicit about the quality of the information used.
- Human and cultural factors — recognises that human behaviour and culture influence every aspect of risk management.
- Continual improvement — risk management is continually improved through learning and experience.
The risk management process is the operational sequence:
- Communication and consultation (continuous, throughout).
- Establishing the scope, context, and criteria.
- Risk identification.
- Risk analysis.
- Risk evaluation.
- Risk treatment.
- Monitoring and review (continuous, throughout).
- Recording and reporting.
Choosing a PECB ISO 31000 course
Three pathways through PECB, each with the official exam included and a free resit within 12 months:
- ISO 31000 Foundation — best for managers and project owners who need to understand the framework without operating it day-to-day. $399 + GST.
- ISO 31000 Risk Manager — for people running risk in a function (information security risk, operational risk, project risk) and ready to apply the full process. $594 + GST, reduced from $849.
- ISO 31000 Lead Risk Manager — for chief risk officers, heads of risk, and consultants leading enterprise-wide risk programs. Covers board reporting, risk appetite, KRIs, and risk culture in depth. $979 + GST.
PECB credentials are accredited by ANAB under ANSI/ASTM E2659-24 and recognised internationally. Aegentra Academy is on the PECB partner directory — online delivery, with instructor-led classroom in Melbourne and Sydney on request.
ISO 31000 vs ISO 27005 vs COSO ERM
Three frameworks Australian risk professionals routinely encounter:
ISO 31000:2018 — generic, principle-based, applicable to any organisation. Not certifiable for organisations. The shared vocabulary across all ISO risk standards.
ISO/IEC 27005:2022 — information security risk management specifically. More prescriptive than ISO 31000 and used as the risk methodology inside ISO 27001 certifications. Not separately certifiable for organisations either, but is audited as part of the ISO 27001 Stage 2 audit.
COSO ERM (2017) — published by the Committee of Sponsoring Organizations in the US. Strong in financial services and listed companies; provides a five-component, 20- principle framework. ISO 31000 and COSO ERM are largely compatible at the principles level but differ in the level of detail and the assumed organisational structure.
Most Australian organisations use ISO 31000 as the umbrella framework, ISO/IEC 27005 inside the ISO 27001 ISMS, and reference COSO ERM where US-aligned governance is required (typically dual-listed or US-acquired entities).
Who needs ISO 31000 certification in Australia?
Nobody, in the sense of a legal requirement — and everybody, in the sense that the regimes below all assume the method it supplies. The people who actually buy ISO 31000 training in Australia fall into four groups.
Risk and compliance staff in APRA-regulated entities. CPS 220 requires a board-approved risk management framework and appetite statement; CPS 230 adds critical operations, disruption tolerances and service-provider risk. Neither names ISO 31000, but both assume a documented, repeatable method — which is why the credential appears on the position description rather than the standard.
Critical infrastructure operators under the SOCI Act. Responsible entities across the designated sectors must maintain a written all-hazards Risk Management Program covering cyber, personnel, supply chain and physical risk, reported annually to the board and the regulator. An all-hazards program is precisely what the ISO 31000 framework describes.
Commonwealth and state government risk teams. The PSPF requires entities to manage security risk using a risk management approach, with the Accountable Authority attesting annually to security maturity. The Commonwealth Risk Management Policy under the PGPA Act requires systems of risk oversight, and Comcover benchmarks risk maturity annually — which rewards a framework producing comparable year-on-year evidence. PSPF-facing roles are among the most common reasons Canberra-based practitioners take this course.
ISO 27001 practitioners who need the risk half. ISO 27001 requires a documented risk assessment methodology but does not mandate which one. ISO 31000 — or ISO/IEC 27005 for the information-security-specific version — is the usual choice, so practitioners in Melbourne, Sydney, Brisbane and Perth frequently hold both. See the ISO 27001 certification guide for the other side of that pairing.
How long does ISO 31000 certification take?
Because only individuals are certified, the timeline is study time plus one exam — not a readiness project and a two-stage audit. There is no organisational timeline, because there is no organisational certificate.
Foundation is 8–12 hours of self-paced study, which most people finish inside two weeks of evenings. The exam is 40 multiple-choice questions across two competency domains, and it is the only ISO 31000 level sat closed book.
Risk Manager is 25–35 hours, usually three to five weeks alongside a full-time job. The exam is 60 multiple-choice questions across three domains, open book.
Lead Risk Manager is 35–45 hours, typically five to seven weeks. The exam is 80 multiple-choice questions across five domains, open book.
A note on exam duration: PECB does not publish one in its candidate handbook for any ISO 31000 level. Figures quoted elsewhere — one, two or three hours — are not sourced from PECB documentation. The credential tiers, and the professional experience and project hours each requires, are set out in how to become an ISO 31000 Risk Manager in Australia.
Free ISO 31000 risk management templates
The four working documents an ISO 31000 framework actually produces, published in full and free — no email required. They are worked examples for an Australian organisation, not blank forms.
- Calibrated 5×5 risk matrix (PDF) or CSV — likelihood as frequency bands and five consequence types with real thresholds. Most matrices fail because “Possible” and “Major” mean whatever the scorer wants.
- Risk criteria and appetite statement (PDF) or CSV — the Clause 6.3.4 artefact, nine categories with escalation thresholds to executive and board plus a named KRI each.
- Enterprise risk register (PDF) or CSV — twelve worked risks with inherent and residual scoring, control effectiveness, and an explicit within-appetite test.
- AS ISO 31000 mapped to Australian obligations (PDF) or CSV — twenty obligations across APRA CPS 220, CPS 230 and CPS 234, the SOCI Act, the PSPF, the Commonwealth Risk Management Policy, Comcover, ASX Principle 7, WHS and the Privacy Act, each with the clause that satisfies it and the evidence to retain.
If you would rather the framework was built than studied, that is our governance and risk practice.
FAQs
No. ISO 31000 is guidance, not a certifiable management system standard. There is no Stage 1/Stage 2 audit and no certificate that says "this company is ISO 31000 certified". Any vendor selling you organisational ISO 31000 certification is selling something that does not formally exist. Individuals can be certified under ISO 31000 through PECB (Foundation, Risk Manager, Lead Risk Manager) — those credentials apply to the practitioner, not the company.
ISO designed ISO 31000 to be applicable to any organisation regardless of size, sector, or risk maturity. To stay that universal, the standard avoids prescriptive "shall" requirements. Without prescriptive requirements, there is nothing concrete for an auditor to issue a non-conformity against. The companion standard ISO/IEC 27005 (information security risk management) is closer to auditable territory and is used inside ISO 27001 certifications.
Two reasons. First, the framework is genuinely useful — it gives boards, audit committees, and executive teams a shared vocabulary and a defensible enterprise risk management approach. Second, the PECB Risk Manager and Lead Risk Manager credentials are recognised by employers, tender panels, and Big-Four consultancies. Many ASX-listed companies and government departments require risk officers to hold ISO 31000-aligned credentials.
Indirectly. APRA CPS 230 (operational risk management) and CPS 234 (information security) impose specific obligations on APRA-regulated entities. ISO 31000 provides a sound risk management framework that supports both, but compliance with each prudential standard is what APRA audits. Most APRA-regulated entities use ISO 31000 as the risk management methodology that underpins their CPS 230/234 implementations.
ISO 27001 requires a documented risk assessment methodology — the standard does not mandate which one. ISO 31000 (or its companion ISO/IEC 27005, which is more specific to information security) is the most common choice. The risk principles, framework, and process from ISO 31000 are imported wholesale into the ISO 27001 risk register, the Statement of Applicability, and the management review cycle.
Foundation is an overview — for general managers, project owners, and non-specialists who need to understand the framework. Risk Manager is the practitioner course — for people running risk programs in their function or business unit. Lead Risk Manager is the senior pathway — for chief risk officers, heads of risk, and consultants leading enterprise risk programs across a whole organisation.
PECB courses are self-paced through myPECB; the official guidance is roughly 40 hours of study for Lead Risk Manager, plus the exam. Most learners spread this over 4–8 weeks alongside their day job. The exam is taken remotely on a schedule that suits you, with one free resit included.
Yes. PECB is accredited by ANAB under ANSI/ASTM E2659-24 (the standard for certificate programs), plus UKAS, IAS, and COFRAC. PECB credentials are accepted on resumes, tender responses, and procurement panels worldwide — including in Australia, the UK, EU, US, and across APAC.
Because ISO 31000 cannot be certified at the organisation level, the only cost is individual training and examination. Through Aegentra Academy: ISO 31000 Foundation is $379 + GST, Risk Manager is $594 + GST reduced from $849 ($649 + GST for guided eLearning, reduced from $928), and Lead Risk Manager is $979 + GST. Every price includes the official PECB examination voucher, one free resit within 12 months, and 12 months of myPECB access — there is no separate exam fee. Several Australian providers quote a course fee and bill the examination separately, so confirm before comparing prices. Tax invoices with GST and ABN are issued at checkout.
Foundation is 40 multiple-choice questions across two competency domains and is the only ISO 31000 level sat closed book. Risk Manager is 60 questions across three domains, open book. Lead Risk Manager is 80 questions across five domains, open book. All three are multiple-choice with three options per question and one correct answer, mixing stand-alone with scenario-based items, and all three require 70% to pass. These figures come from PECB’s published candidate handbooks. PECB does not publish an exam duration for any ISO 31000 level, so any specific number of hours quoted elsewhere is unsourced.
No. It is multiple-choice — 60 questions across three competency domains, open book. The claim that it is essay-type circulates widely and is worth correcting, because it changes how people prepare: candidates expecting to write long-form answers practise entirely the wrong skill. PECB’s candidate handbook is unambiguous on this point.
No. The ISO 31000 Risk Manager exam awards two credentials only — Provisional Risk Manager, which needs no experience, and Risk Manager, which needs two years of professional experience with one in risk management plus 200 hours of project activity. Lead Risk Manager (five years, two in risk management, 300 hours) and Senior Lead Risk Manager (ten years, seven in risk management, 1,000 hours) sit on a separate scheme and require the Lead Risk Manager exam, which covers five competency domains rather than three. If a head-of-risk or CRO track is your destination, take Lead Risk Manager rather than discovering the ceiling later.
AS ISO 31000:2018 is the current Australian Standard, published by Standards Australia as an identical adoption of ISO 31000:2018. The previous edition was AS/NZS ISO 31000:2009, a joint Australian and New Zealand standard; for the 2018 revision it was published as an Australian Standard rather than a joint one, so the "/NZS" was dropped. A policy or tender still citing AS/NZS ISO 31000 as current is referring to a superseded edition. Australia has unusual standing here — AS/NZS 4360:1995 was among the first national risk management standards published anywhere and directly shaped ISO 31000 when the international standard was drafted.
Foundation if you contribute to risk decisions without being a specialist — general managers, project owners, board members, internal auditors. Risk Manager if you run risk inside a function, business unit or project, working within a framework somebody else designed. Lead Risk Manager if you are accountable for the framework itself: setting appetite, chairing the risk committee, and answering to a board for whether it works. The deciding question is not how much experience you have, it is whose risk you are accountable for.