Skip to main content

How to become an ISO 31000 Risk Manager in Australia

By Harry Sidhu — ISO 27001 Lead Implementer · Director and Principal Consultant, Aegentra · Published 1 August 2026

Foundation, Risk Manager and Lead Risk Manager are three separate course levels; none is a formal prerequisite for another. This guide explains the two tiers assigned to the 60-question Risk Manager exam by PECB’s 2026 handbook, the conflicting public course table, the separate 80-question Lead Risk Manager exam, and the current formats, prices and typical effort.

To pursue a PECB ISO 31000 Risk Manager credential, complete the official training and pass the two-hour exam — 60 multiple-choice questions across three competency domains, open book, 70% to pass — then apply for the eligible tier. PECB validates the application and experience requirements; Risk Manager requires two years of professional experience with one year in risk management plus 200 hours of risk-management project activity. Aegentra Academy offers Self-Study for A$579 excluding GST with 25–35 hours of typical effort, and eLearning for A$599 excluding GST with 20–30 hours, approximately 3–4 training days. Both include the exam voucher and one free resit within 12 months.

What the ISO 31000 Risk Manager course covers

ISO 31000:2018 — published in Australia by Standards Australia as AS ISO 31000:2018 — gives principles, a framework and a process for managing risk. The course develops knowledge of that framework and process. It does not assign organisational authority or qualify a learner for a particular job. For the standard itself and what it means in Australia, see our ISO 31000 certification guide.

Two clarifications: organisations are not ISO 31000 certified because the standard is guidance, and Risk Manager and Lead Risk Manager use different exams. PECB’s 2026 Risk Manager Candidate Handbook assigns the 60-question exam to the first two tiers, while PECB’s current Risk Manager course table also displays Lead tiers. Aegentra discloses that conflict rather than promising a Lead-tier outcome from the Risk Manager exam.

The step-by-step pathway

  1. Consider optional Foundation preparation. ISO 31000 Foundation covers the eight principles, framework, process and ISO Guide 73 vocabulary at an introductory level. It is optional preparation, not a formal prerequisite for Risk Manager.
  2. Take the official Risk Manager course. The official PECB ISO 31000 Risk Manager course teaches you to establish a risk management framework and run the process end to end — scope, context and risk criteria, identification, analysis, evaluation, treatment, monitoring and reporting. PECB supplies over 300 pages of course material alongside it.
  3. Sit and pass the PECB exam. Two hours, 60 multiple-choice questions across three competency domains, open book, 70% to pass. Being open book you may bring a hard copy of ISO 31000, the course materials and your own notes, so retrieval speed matters more than memorisation. Pass it and you can apply for Provisional Risk Manager with no experience required.
  4. Log your experience and project hours. PECB counts two things separately — years of professional experience with a minimum specifically in risk management, and hours of hands-on risk management project activity. Keep a running log with dates, the organisation, the deliverable and the hours. Reconstructing it two years later is painful.
  5. Sign the Code of Ethics and apply for your tier. Every tier requires signing the PECB Code of Ethics and submitting an application with references. PECB verifies the claim and issues a digital credential that can be verified independently.
  6. Compare the separate Lead Risk Manager course. Risk Manager has a two-hour, 60-question exam across three competency domains. Lead Risk Manager has a three-hour, 80-question exam across five competency domains. PECB official sources conflict on whether the Risk Manager exam can reach Lead tiers, so use the published scope and obtain written confirmation from PECB if a specific credential outcome matters.

Aegentra Academy is an official PECB authorised training partner and delivers the ISO 31000 Risk Manager course as Self-Study and eLearning, with instructor-led organisational delivery scoped on request. Foundation-level grounding is available through the ISO 31000 Foundation course.

Credential tiers and the experience each one needs

PECB publishes four ISO 31000 credential tiers, separated by professional experience and hands-on risk management hours. Official-source note: the 2026 Risk Manager Candidate Handbook assigns the 60-question exam to Provisional Risk Manager and Risk Manager, while PECB’s current Risk Manager course table also displays Lead tiers. Aegentra does not promise a Lead-tier outcome from that exam; choose Lead Risk Manager or obtain written confirmation from PECB if that outcome matters.

Credential tierTotal experienceIn risk managementProject hours
Provisional Risk ManagerNoneNoneNone
Risk Manager2 years1 year200 hours
Lead Risk Manager5 years2 years300 hours
Senior Lead Risk Manager10 years7 years1,000 hours

These are PECB scheme requirements, not requirements of the ISO standard itself — confirm the current criteria on the official PECB ISO 31000 Risk Manager page. Every tier also requires signing the PECB Code of Ethics.

What counts as risk management project hours

Two things are counted separately. Professional experience is your years of work, with a minimum specifically in risk management — one year for Risk Manager, two for Lead Risk Manager, seven for Senior Lead Risk Manager. Project activity hours are hands-on hours doing the risk work itself. This is the part people underestimate and then cannot evidence later. If you already do any of the activities below in a GRC, audit, compliance or operations role, you are banking hours right now and should be logging them with dates and outputs.

  • Building and maintaining the risk register — Identifying risks across strategy, operations, compliance, people, technology and supply chain, scoring them inherent and residual, and keeping the register current rather than treating it as an annual-only record.
  • Defining risk criteria and appetite — The Clause 6.3.4 work: setting the thresholds that decide what is acceptable before assessment rather than after, so the result follows stated criteria rather than a case-by-case argument.
  • Calibrating likelihood and consequence scales — Turning adjectives into frequency bands and thresholds to improve consistency when different assessors apply the same scale.
  • Running risk assessment workshops — Facilitating identification and analysis sessions with business owners — as much about drawing out what people actually worry about as about the method.
  • Designing and tracking treatment plans — Selecting treatment options against the criteria, assigning named owners, and following through to the point where residual risk is formally accepted by someone with authority to accept it.
  • Risk reporting and key risk indicators — Building reporting that shows trend and appetite context rather than a static heat map, and defining KRIs with thresholds that trigger action before the risk materialises.
  • Integrating risk with other management systems — Connecting enterprise risk to the ISO 27001 ISMS, business continuity under ISO 22301, and AI governance under ISO 42001 — one register and one appetite, not four that contradict each other.

How ISO 31000 relates to Australian obligations

No Australian law requires ISO 31000 or a PECB credential by name. Prudential standards, critical-infrastructure obligations and governance frameworks can still make a documented risk method relevant. The four contexts below explain the relationship without claiming recognition or job eligibility.

  • APRA CPS 220 and CPS 230 — APRA-regulated institutions must maintain a risk management framework and board-approved risk appetite under CPS 220, and address critical operations, disruption tolerances and service-provider risk under CPS 230. Neither prudential standard names ISO 31000 or requires a PECB credential.
  • The SOCI Act risk management program — Responsible entities in designated critical-infrastructure sectors must maintain a written Risk Management Program addressing applicable hazards. ISO 31000 can help structure a general risk method, but the Act and Rules determine compliance and do not prescribe a PECB credential.
  • The PSPF and Commonwealth risk policy — Commonwealth entities have their own security-risk and risk-oversight obligations. ISO 31000 may be used as a supporting method, but those government frameworks do not establish government recognition of or a universal requirement for a PECB credential.
  • ASX Principle 7 — The ASX Corporate Governance Principles ask listed entities to establish a sound risk management framework and periodically review its effectiveness. Principle 7 does not prescribe ISO 31000 training or a personnel credential.

Each obligation must be assessed against its own legal or regulatory source. Training may build relevant capability, but it does not establish compliance, government recognition, tender eligibility or employment.

Risk Manager vs Lead Risk Manager

Compare the courses by their published workload, exam and competency-domain scope. Do not infer job title, authority or organisational accountability from the course name alone.

ISO 31000 Risk ManagerISO 31000 Lead Risk Manager
Course priceA$579 Self-Study; A$599 eLearning — excluding GSTA$979 Self-Study — excluding GST
Typical learning effort25–35 hours Self-Study; 20–30 hours eLearning (approximately 3–4 training days)35–45 hours Self-Study
Exam2 hours; 60 multiple-choice questions, open book3 hours; 80 multiple-choice questions, open book
Competency domains35
Credential pathway2026 handbook: Provisional and Risk Manager; current PECB course table conflictsFull ladder, up to Senior Lead Risk Manager
Published scope60-question exam across 3 competency domains80-question exam across 5 competency domains

PECB’s 2026 Risk Manager Candidate Handbook assigns the 60-question exam to the first two tiers, while its current Risk Manager course table also displays Lead tiers. Aegentra does not promise a Lead-tier outcome from that exam. Choose Lead Risk Manager or confirm eligibility with PECB in writing if that outcome matters. If your organisation needs a risk framework built rather than a person trained, that is our governance and risk practice.

Frequently asked questions

Can my organisation be ISO 31000 certified?

No. ISO 31000 is guidance, not a certifiable management system standard. There is no Stage 1 / Stage 2 certification audit and no accredited organisational ISO 31000 certificate. PECB’s scheme applies to individual practitioners.

Does the Risk Manager exam lead to Lead Risk Manager?

PECB’s 2026 Risk Manager Candidate Handbook assigns the 60-question exam to Provisional Risk Manager and Risk Manager only. However, PECB’s current public Risk Manager course table also displays Lead and Senior Lead tiers, which conflicts with that handbook and the separate Lead Risk Manager scheme. Aegentra does not promise a Lead-tier credential from the Risk Manager exam. Choose Lead Risk Manager or confirm eligibility with PECB in writing if Lead or Senior Lead is your intended outcome.

How long does the ISO 31000 Risk Manager course take?

Typical total learning effort is 25–35 hours for Self-Study and 20–30 hours for eLearning, approximately 3–4 training days. These are estimated workloads, not video runtime, exam duration or completion guarantees.

How hard is the exam, and how long is it?

PECB’s 2026 Candidate Handbook specifies 60 multiple-choice questions across three competency domains, open book, with a 70% pass mark. PECB’s current official Risk Manager brochure publishes a two-hour duration. Because it is open book, retrieval speed still matters.

How much does the course cost in Australia?

Aegentra Academy lists Self-Study at A$579 excluding GST with 25–35 hours of typical effort, and eLearning at A$599 excluding GST with 20–30 hours, approximately 3–4 training days. Both include the official PECB exam voucher and one free resit within 12 months, so there is no separate exam fee. For an Australian billing address, 10% GST is added at checkout.

Is ISO 31000 the same as AS ISO 31000?

Yes. Standards Australia publishes it as AS ISO 31000:2018, an identical adoption — same eight principles, same framework, same process. Note the previous edition was the joint AS/NZS ISO 31000:2009; for the 2018 revision the "/NZS" was dropped, so a document citing AS/NZS ISO 31000 as current refers to a superseded edition.

Do I need ISO 27001 before ISO 31000?

No. ISO 27001 requires a documented risk assessment methodology but does not mandate which one. ISO 31000, or its information-security-specific companion ISO/IEC 27005, can inform that method.

Ready to start? Aegentra Academy is an official PECB authorised training partner and lists ISO 31000 Risk Manager Self-Study at A$579 excluding GST with 25–35 hours of typical effort, and eLearning at A$599 excluding GST with 20–30 hours, approximately 3–4 training days. Both include the exam voucher and one free resit within 12 months. More field notes are on the Aegentra Insights hub.