Skip to main content
ISO 31000

ISO 31000 Risk Manager

ISO 31000 Risk Manager. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBRisk Manager3 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers responsible for implementing or overseeing risk management programmes
  • Consultants advising organisations on risk management strategy and practice
  • Individuals whose role involves creating or protecting organisational value
  • Professionals seeking structured knowledge of the ISO 31000 framework and process
  • Those pursuing or advancing a career in enterprise or operational risk management

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Complete beginners with no prior exposure to risk concepts may find the pace challenging without preparatory study
  • Professionals seeking deep technical auditing skills rather than risk management implementation knowledge
  • Those looking for sector-specific risk frameworks such as financial or clinical risk standards

What you'll be able to do

  • 1Explain the core concepts and principles that underpin ISO 31000 risk management
  • 2Establish a risk management framework aligned with ISO 31000 guidance
  • 3Identify gaps in an existing framework and apply improvement measures
  • 4Initiate a structured risk management process within an organisational context
  • 5Conduct a risk assessment by applying ISO 31000 methodology
  • 6Select and apply appropriate risk treatment options based on assessment results
  • 7Record, report, and communicate risk information to relevant stakeholders
  • 8Monitor and review risk management activities to support continual improvement

Day by day

Day 1Introduction to ISO 31000 and establishing the risk management framework
  • Overview of ISO 31000 and risk management principles

    Participants examine the purpose, scope, and guiding principles of ISO 31000 and how they shape organisational risk thinking.

  • Designing and establishing the risk management framework

    This module covers the components required to build a framework that integrates risk management into organisational governance and decision-making.

  • Leadership commitment and organisational context

    Participants explore how leadership mandate and an understanding of internal and external context form the foundation for an effective framework.

By end of day

  • Articulate why ISO 31000 principles matter to organisational resilience
  • Identify the structural elements needed to establish a risk management framework
  • Link organisational context to framework design decisions
Day 2Initiating the risk management process and conducting risk assessment
  • Initiating the risk management process

    Participants learn how to define scope, criteria, and communication plans before beginning the formal risk management process.

  • Risk identification techniques

    This module introduces methods for systematically identifying risks that could affect the achievement of organisational objectives.

  • Risk analysis and risk evaluation

    Participants apply analysis approaches to determine risk likelihood and consequence, then evaluate results against established criteria to prioritise action.

By end of day

  • Define clear scope and criteria to guide a risk assessment exercise
  • Apply identification and analysis techniques to surface and characterise organisational risks
  • Evaluate risk levels to inform prioritisation and decision-making
Day 3Risk treatment, recording and reporting, monitoring, review, and communication
  • Selecting and implementing risk treatment options

    Participants examine the range of treatment options available under ISO 31000 and how to select measures proportionate to evaluated risk levels.

  • Recording and reporting risk information

    This module addresses documentation requirements and how to structure risk reports that support accountability and informed decision-making.

  • Monitoring, review, and continual improvement

    Participants learn how to establish monitoring mechanisms and review cycles that keep the risk management process relevant and effective over time.

  • Communication and consultation throughout the risk management process

    This module covers how to design and execute communication and consultation activities that engage stakeholders at each stage of the process.

By end of day

  • Select risk treatment options that are appropriate to identified risk levels
  • Produce clear risk records and reports suited to different stakeholder audiences
  • Design monitoring and communication plans that sustain the risk management process

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of risk management
  • Domain 2: Establishing the risk management framework
  • Domain 3: Application of the risk management process

Certification Rules and Policies

The requirements for the “PECB Certified ISO 31000 Risk Manager” certifications are:

To be considered valid risk management experience, the activities should follow best risk management practices and include the following:

  • Certificate and examination fees are included in the price of the training course.
  • Training material containing over 350 pages of information and practical examples will be distributed.
  • An attestation of course completion worth 21 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case of exam failure, you can retake the exam within 12 months for free.

The requirements for the "PECB Certified ISO 31000 Risk Manager" certifications are:

Educational approach

  • The training course is based on theory and best practices used in risk management.
  • Lecture sessions are illustrated with practical examples.
  • The participants are encouraged to communicate and engage in discussions and exercises.
  • The exercises are similar in structure with the certification exam questions.

Buyers always ask

What is the difference between completing this training and obtaining an ISO 31000 Risk Manager certification?+

Completing the three-day training course means you have attended all scheduled sessions and engaged with the curriculum. It does not automatically confer a professional certification.

To obtain a PECB certification credential, you must separately pass the relevant PECB examination and satisfy all certification requirements, including any professional-experience criteria set out in PECB Certification Rules and Policies.

Does this course cover a specific industry sector or is it general in scope?+

The course follows the ISO 31000 standard, which is designed to be applicable across any organisation, sector, or industry. Principles, framework guidance, and process steps are discussed in terms that participants can adapt to their own organisational context.

How much prior risk management knowledge should I have before attending?+

PECB indicates that a fundamental understanding of ISO 31000 and comprehensive knowledge of risk management concepts are expected. Participants who arrive without this background may find certain modules move quickly and could benefit from preparatory reading of the ISO 31000 standard beforehand.

What practical skills will I be able to apply immediately after the training?+

By the end of the three days, participants are equipped to establish or improve a risk management framework, conduct structured risk assessments, select treatment options, and design monitoring and communication activities, all grounded in ISO 31000 guidance.

These skills are directly applicable to organisational risk programmes regardless of size or sector.

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.