Skip to main content
ISO 31000

ISO 31000 Foundation

ISO 31000 Foundation. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBFoundation2 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Individuals who want to learn the foundational concepts and principles of risk management based on ISO 31000
  • Professionals responsible for creating or protecting organisational value
  • Personnel tasked with managing risks and opportunities within their area of responsibility
  • Individuals considering a career path in risk management

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Experienced risk managers seeking advanced implementation or programme management content, who would be better served by the ISO 31000 Lead Risk Manager course
  • Professionals looking for industry-specific risk frameworks such as financial or operational risk standards
  • Those expecting detailed technical risk modelling or quantitative risk analysis methodologies

What you'll be able to do

  • 1Summarise the main concepts, terms, and principles of risk management as presented in ISO 31000
  • 2Explain the ISO 31000 guidelines for establishing and maintaining a risk management framework
  • 3Describe how the risk management process is applied in accordance with ISO 31000, including risk assessment, treatment, recording, reporting, monitoring, and communication
  • 4Distinguish between the risk management framework and the risk management process as defined by ISO 31000

Day by day

Day 1Introduction to risk management, ISO 31000 components, and initiation of the risk management process
  • Core risk management concepts and ISO 31000 principles

    Participants explore the terminology, principles, and overall structure of ISO 31000, establishing a shared understanding of what risk management involves and why it matters to organisations.

  • The ISO 31000 risk management framework

    This module examines the components of the risk management framework, including leadership commitment, integration, design, implementation, evaluation, and improvement.

  • Initiating the risk management process

    Participants are introduced to the steps that begin the risk management process, including establishing context and defining the scope within which risks will be identified and assessed.

By end of day

  • Explain the purpose and structure of ISO 31000 to colleagues or stakeholders
  • Identify the key components of a risk management framework
Day 2Risk assessment, treatment, recording, reporting, monitoring, review, and communication according to ISO 31000
  • Risk identification, analysis, and evaluation

    Participants learn how to systematically identify risks, analyse their likelihood and consequences, and evaluate them against agreed criteria to prioritise a response.

  • Risk treatment options and selection

    This module covers the range of risk treatment options available under ISO 31000 and how to select and plan appropriate responses to assessed risks.

  • Recording, reporting, monitoring, and review

    Participants examine how risk information should be documented and reported, and how ongoing monitoring and periodic review keep the risk management process effective.

  • Communication and consultation

    This module addresses how to engage internal and external stakeholders throughout the risk management process to support informed decision-making.

By end of day

  • Apply the ISO 31000 risk assessment steps to a practical scenario
  • Select suitable risk treatment options and describe how to record and report outcomes

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

The exam fully meets the requirements of the PECB Examination and Certificate Programme. It covers the following competency domains:

  • Domain 1: Fundamental principles and concepts of risk management
  • Domain 2: Risk management framework and risk management process

First, a candidate needs to complete the PECB ISO 31000 Foundation training course. Then, they need to take the exam and after successfully passing the exam, candidates will be able to apply for the “PECB Certificate Holder in ISO 31000 Foundation” certificate. This is an entry-level credential.

There are no prerequisites on professional or management system project experience required. Thus, following the training course, passing the exam and applying for the certificate are the only certificate program requisites that certificate holders shall meet before obtaining the certificate.

The certificate requirements are:

  • Certificate and examination fees are included in the price of the training course.
  • Training material containing over 200 pages of information and practical examples will be distributed.
  • An attestation of course completion worth 14 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free.

Why should you attend?

The ISO 31000 Foundation training course presents the basic principles and approaches of managing risks and opportunities based on the guidelines of ISO 31000. This training course focuses on the main components of ISO 31000: basic terms and definitions, principles of risk management, risk management framework, and risk management process. In addition, each step of the risk management process is analyzed and elaborated individually.

Upon completion of the training course, you can sit for the exam and apply to obtain the “PECB Certificate Holder in ISO 31000 Foundation” designation. The certificate demonstrates that you understand the fundamental concepts of risk and methodologies for risk management based on the guidelines of ISO 31000.

Educational approach

The training course is participant centered and contains:

  • Lecture sessions are illustrated with graphics, examples, and discussions
  • Interactions between participants by means of questions and suggestions
  • Quizzes with similar structure to the exam

Prerequisites

There are no prerequisites to participate in this training course.

What is the PECB ISO 31000 Foundation course?

The PECB ISO 31000 Foundation course is an introductory training program designed to provide participants with a solid understanding of the fundamental concepts and principles of risk management based on the ISO 31000 standard. This course covers essential topics such as the structure and requirements of the standard, including the risk management framework and process. By acquiring a comprehensive understanding of these aspects, participants will gain the required competencies to participate effectively in risk management projects.

Who should attend the ISO 31000 Foundation course?

This course is intended for individuals involved in risk management, individuals seeking to gain knowledge about the ISO 31000 guidelines for risk management principles, framework, and process, individuals responsible for the creation and protection of value in an organization, personnel tasked with managing the risks and opportunities in their area of responsibility, and individuals interested in pursuing a career as a risk manager.

What will I learn in the ISO 31000 Foundation course?

Participants will gain a comprehensive understanding of the fundamental concepts and principles of risk management as articulated in ISO 31000. The course covers the ISO 31000 guidelines for establishing the risk management framework and describes the application of the risk management process in accordance with ISO 31000 guidelines.

How long is the ISO 31000 Foundation course?

The ISO 31000 Foundation course is a two-day training program. The first day introduces participants to the fundamental concepts of risk management, ISO 31000 components, and initiation of the risk management process, while the second day focuses on risk assessment, risk treatment, recording and reporting, monitoring and review, and communication and consultation according to ISO 31000.

Is there a certification exam included in the course?

Yes, the course includes the "PECB Certified ISO 31000 Foundation" exam, which fully meets all the requirements of the PECB Examination and Certification Program (ECP). The exam covers fundamental principles and concepts of risk management and the risk management framework and process. Upon passing the exam, participants can apply for the "PECB Certificate Holder in ISO 31000 Foundation" credential, demonstrating their knowledge and competence in this area.

Buyers always ask

Are there any prerequisites for attending the ISO 31000 Foundation course?+

According to PECB, there are no prerequisites for participating in this training course. It is designed to be accessible to anyone interested in learning the foundational concepts of risk management based on ISO 31000, regardless of their prior experience.

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

What competency domains does the PECB ISO 31000 Foundation exam cover?+

According to PECB, the exam covers two domains: fundamental principles and concepts of risk management, and the risk management framework and risk management process. For details on exam format, languages, and scheduling, refer to PECB's official List of Exams and Exam Rules and Policies.

How does the ISO 31000 Foundation course differ from the ISO 31000 Lead Risk Manager course?+

The Foundation course provides an introductory overview of ISO 31000 concepts, principles, framework, and process components over two days. It is suited to individuals building general awareness of risk management.

The Lead Risk Manager course is a five-day programme aimed at professionals who need to establish, implement, and manage a full risk management programme within an organisation. It assumes prior familiarity with the risk management framework and process that the Foundation course provides.

What CPD value does attending this course provide?+

According to PECB, participants who attend the ISO 31000 Foundation training course receive an attestation of course completion worth 14 Continuing Professional Development credits. These credits recognise the structured learning hours completed during the two-day programme.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.