Skip to main content
ISO 31000

ISO 31000 Lead Risk Manager

ISO 31000 Lead Risk Manager. Review available formats, prerequisites, current inclusions and certification terms before booking.

PECBLead Risk Manager5 daysLiveSelf-pacedIn-house
  • Practitioner-led, taught by a working CISO
Christophe Mazzola

Taught by

Christophe Mazzola

Practicing CISO · Founder of Cyber Academy

See full profile →

Right fit if you are.

  • Managers or consultants involved in implementing or overseeing a risk management programme
  • Project managers and expert advisors seeking to lead the deployment of a risk management framework and process
  • Professionals with direct responsibility for risk management processes in their organisation
  • Individuals looking to build or advance a career in risk management

NOT for. When to skip it.

We'd rather you keep your money than buy the wrong path.

  • Individuals with no background in risk management concepts who would benefit from starting with the ISO 31000 Foundation course first
  • Those seeking a risk auditing or certification auditing curriculum rather than an implementation and management focus
  • Professionals looking for domain-specific risk frameworks unrelated to the ISO 31000 guidelines

What you'll be able to do

  • 1Explain the fundamental concepts, principles, and terminology of risk management as defined by ISO 31000
  • 2Establish and improve a risk management framework within an organisation based on ISO 31000 guidelines
  • 3Initiate and plan the deployment of a risk management process aligned with ISO 31000
  • 4Apply best practices to identify, analyse, evaluate, treat, and monitor risks across an organisation
  • 5Integrate risk recording, reporting, communication, and consultation activities into ongoing risk management operations
  • 6Support management decision-making by producing meaningful risk information in a structured and repeatable way

Day by day

Day 1Introduction to ISO 31000 and risk management
  • ISO 31000 structure and risk management principles

    Participants examine the architecture of ISO 31000, its guiding principles, and how these principles inform effective risk management decision-making across an organisation.

  • Key concepts and risk management terminology

    This module establishes a shared vocabulary by reviewing the core terms and definitions used throughout ISO 31000 and related risk management literature.

By end of day

  • Articulate the purpose and structure of ISO 31000 to organisational stakeholders
  • Apply consistent risk management terminology when communicating with teams and leadership
Day 2Establishing the risk management framework and initiating the risk management process
  • Designing and implementing the risk management framework

    Participants learn how to design a risk management framework tailored to their organisation's context, obtain leadership commitment, and begin its implementation in line with ISO 31000.

  • Integrating risk management into organisational processes

    This module explores how to embed risk management thinking into strategic planning, governance structures, and day-to-day operations.

By end of day

  • Design a risk management framework that reflects the organisation's context and objectives
  • Identify integration points between the risk management framework and existing organisational processes
Day 3Risk analysis, evaluation, and treatment according to ISO 31000
  • Risk identification and analysis techniques

    Participants practise identifying risks and applying qualitative and semi-quantitative analysis techniques to assess likelihood and consequence in line with ISO 31000 guidance.

  • Risk evaluation and treatment planning

    This module covers how to compare risk analysis results against defined criteria and select appropriate treatment options, including avoidance, reduction, sharing, and acceptance.

By end of day

  • Conduct a structured risk assessment using ISO 31000-aligned techniques
  • Develop a risk treatment plan that addresses prioritised risks in a practical and proportionate way
Day 4Recording, reporting, monitoring, review, communication, and consultation according to ISO 31000
  • Risk recording and reporting

    Participants examine how to document risk information accurately and produce reports that give decision-makers a clear picture of the organisation's risk profile.

  • Monitoring, review, and continual improvement

    This module addresses how to establish monitoring activities, conduct periodic reviews, and use findings to continuously improve the effectiveness of the risk management process.

  • Communication and consultation with stakeholders

    Participants explore how to develop and execute a communication and consultation plan that keeps internal and external stakeholders appropriately informed throughout the risk management process.

By end of day

  • Produce risk reports that support informed management decisions
  • Design a monitoring and review schedule that sustains risk management effectiveness over time
Day 5Risk management programme consolidation and certification exam preparation
  • Managing a risk management programme

    Participants consolidate their understanding of how to oversee an end-to-end risk management programme, covering governance, resource allocation, and performance evaluation.

  • Exam competency domain review

    A structured review session revisits all five exam competency domains to help participants identify knowledge gaps before sitting the assessment.

By end of day

  • Outline a governance structure for sustaining an organisational risk management programme
  • Map personal knowledge gaps to the five exam competency domains before sitting the assessment

Upcoming public sessions

Open-enrolment cohorts. Pick a date and book your seat. Want a private cohort for your team instead? Request an in-house quote.

No confirmed live cohort right now. You can still:

Everything inside this certification

The detail behind the headline. Read at your own pace. Each section answers a buyer question we get on discovery calls.

  • Domain 1: Fundamental principles and concepts of risk management
  • Domain 2: Establishing the risk management framework
  • Domain 3: Initiating the risk management process and assessing risks
  • Domain 4: Risk treatment
  • Domain 5: Risk recording and reporting
  • Domain 6: Risk monitoring and review
  • Domain 7: Risk communication and consultation

Certification Rules and Policies

The requirements for the “PECB Certified ISO 31000 Lead Risk Manager” certifications are:

To be considered a valid risk management experience, the risk management activities should follow best risk management practices and include the following:

  • Certification and examination fees are included in the price of the training course
  • Participants will be provided with the training course material containing over 450 pages of explanatory information, examples, best practices, exercises, and quizzes.
  • An attestation of course completion worth 31 CPD (Continuing Professional Development) credits will be issued to the participants who have attended the training course.
  • In case candidates fail the exam, they can retake it within 12 months following the initial attempt for free.

Educational approach

  • The training course is based on theory and best practices used in risk management.
  • Lecture sessions are illustrated with practical examples and scenarios.
  • Participants are encouraged to communicate and engage in discussions and exercises.
  • The exercises are similar in structure with the certification exam questions.

Buyers always ask

Is the certification exam included with this course?+

Exam inclusion depends on the delivery format and commercial option selected. Check the booking summary or ask Cyber Academy for written confirmation before registering.

Completing the training, passing the applicable exam, and meeting the PECB credential requirements are separate steps.

Which competency domains does the PECB ISO 31000 Lead Risk Manager exam cover?+

According to PECB, the exam covers five domains: fundamental principles and concepts of risk management, establishment of the risk management framework, initiation of the risk management process and risk assessment, risk treatment and risk recording and reporting, and risk monitoring, review, communication, and consultation.

For details on exam format, languages, and scheduling, consult PECB's official List of Exams and Exam Rules and Policies.

Should I complete the ISO 31000 Foundation course before attending this Lead Risk Manager programme?+

PECB states that a fundamental understanding of the risk management framework, process, and principles is expected before attending the Lead Risk Manager course. The ISO 31000 Foundation course is one way to build that understanding, although equivalent knowledge gained through professional experience would also be relevant.

Participants without this background may find the pace of Days 2 through 4 challenging, as those days move quickly into framework design, process execution, and advanced management topics.

How does this course address both the risk management framework and the risk management process?+

ISO 31000 makes a deliberate distinction between the framework, which deals with governance, leadership, and integration, and the process, which covers the iterative steps of identifying, analysing, evaluating, treating, and monitoring risks. The course addresses both dimensions across separate days so participants understand how each supports the other.

Day 2 focuses primarily on establishing the framework, while Days 3 and 4 concentrate on executing and sustaining the process in practice.

Who is this course not suitable for?+

This course is not designed for individuals who have no prior exposure to risk management concepts. Those without a foundational background are likely to find the implementation and programme management content difficult to absorb and apply.

It is also not an auditing course. Professionals whose primary goal is to audit risk management systems rather than implement or manage them should consider whether an audit-focused programme better meets their needs.

Ready to get certified?

Taught by a practicing CISO. Prices and exam terms shown up front.