ISO 31000 · Manager

ISO 31000 Risk Manager

Gain the knowledge to apply risk management best practice, develop an effective framework based on ISO 31000, and support smarter decision-making across your organisation.

  • Self-Paced
  • Trainer-Led
Risk manager presenting a risk matrix to colleagues in a meeting room

Risk management as a decision-making tool

ISO 31000 is not a certification standard for organisations; it is guidance. That makes it unusually practical: the value is in the thinking, not in a certificate on the wall.

The standard's central idea is that risk management should support decisions rather than sit alongside them as a compliance exercise. Most organisations have a risk register. Far fewer can say the register actually changes what they do.

What you will be able to do

This course is built around the process: establishing context and criteria, identifying and analysing risk, evaluating it against your appetite, and choosing treatments that are proportionate.

It also covers the framework question that trips up most implementations: who owns risk, how it is escalated, and how it connects to strategy and planning.

Where it fits alongside other standards

ISO 31000 underpins the risk thinking in ISO/IEC 27001, ISO 22301 and ISO 37001. If you are working across several management systems, this course gives you the common vocabulary that sits beneath all of them.

What you will learn

  • Explain the principles and framework of risk management under ISO 31000
  • Design and implement a risk management framework suited to an organisation
  • Apply the ISO 31000 risk management process end to end
  • Select appropriate risk assessment techniques for a given context
  • Integrate risk management into governance and decision-making
  • Monitor, review and continually improve risk management performance

Course content

  1. 1. Risk management principles

    The eight ISO 31000 principles and what they mean in practice.

  2. 2. Designing the framework

    Leadership, integration, resources and organisational context.

  3. 3. The risk management process

    Scope, criteria, identification, analysis, evaluation and treatment.

  4. 4. Assessment techniques

    Choosing and applying qualitative and quantitative methods.

  5. 5. Monitoring and improvement

    Reporting, review cycles and embedding risk in decision-making.

Exam and certification

Open-book written exam delivered online through PECB Exams.

Your fee includes your first exam attempt and one free retake within 12 months. After passing, you can apply for the relevant PECB credential.

Related courses

Questions before you enrol?

Talk to us about prerequisites, exam timing or arranging this course for a group.