Skip to main content

/ ISO 31000 · Risk management guidelines

ISO 31000 risk management review, from governance to evidence.

We assess how your organisation governs risk, sets criteria, identifies and analyses uncertainty, selects treatments, monitors change and reports decisions against ISO 31000 principles and guidance.

ISO 31000 provides guidance rather than certifiable management-system requirements. This engagement is a risk management review, not a certification audit or certificate.

Scope a risk management review

Delivered across Australia — all states and territories — with remote delivery and onsite attendance by arrangement. New Zealand and wider Asia Pacific engagements may be available by arrangement.

Two risk leaders reviewing organisational risk evidence beside a connected risk map

/ Engagement scope

What we examine and deliver.

Leadership, accountability and integration with decision-making

Risk framework design, roles, appetite, criteria and escalation

Risk identification, analysis, evaluation and treatment practice

Consultation, communication, monitoring, review and continual improvement

A traceable findings report with priorities and recommended actions

Qualified delivery matched to your scope

Our team combines implementation, audit, security-governance and technical expertise. Across their professional careers, team members have delivered 2,000+ hours of ISO, ISM and GRC audit work across 70+ organisations.

Team qualifications and credentials

Qualifications, professional credentials and formal training held across Aegentra’s delivery team.

Management systems and audit

  • ISO/IEC 27001 Lead Implementer
  • PECB ISO/IEC 27001 Lead Auditor
  • ISO/IEC 42001 Lead Auditor
  • CISA — Certified Information Systems Auditor
  • ISM Auditor

Cybersecurity and cloud

  • CISSP — Certified Information Systems Security Professional
  • CISM — Certified Information Security Manager
  • Certificate of Cloud Security Knowledge (CCSK)
  • OSCP+ — OffSec Certified Professional Plus

Service delivery and specialist training

  • ITIL Expert
  • PRINCE2
  • Mastering Generative AI for Cybersecurity Certificate
  • Essential Eight Assessment Course certificate — TAFEcyber

Further training and audit qualifications across the team include ISO/IEC 42001 Lead Implementer training, ASD ISM General and Technical audit codes, ISO/IEC 27017 and ISO/IEC 27018 audit codes, and ISO 9001 and ISO 19011 audit qualifications.

Personnel security clearance

NV1 Security Clearance

NV1 security clearance is held within the team. It is a personnel clearance, not a company accreditation or government endorsement. Any clearance requirement and the assigned consultant’s current status are confirmed for the engagement.

Credentials are held across the team and matched to assigned roles. Your proposal identifies the consultants, their responsibilities and the relevant qualification evidence before work begins.

View our delivery-team capability

/ Frequently asked questions

Important boundaries.

Can an organisation be certified to ISO 31000?

No. ISO 31000 is a guidance standard, not a certifiable management-system standard. Aegentra reviews your framework and practice against its principles and guidance but does not issue an ISO certificate.

Is this the same as a risk assessment?

No. A risk assessment examines defined risks. This review examines the organisation-wide governance, framework and process used to manage risk, including how assessments inform decisions and treatments.