Risk Management Readiness Check
Sixteen yes/no questions that assess the maturity of your enterprise risk management framework per ISO 31000: governance, identification, treatment, and monitoring. Applicable to any type of organisation.
- 16 questions
- ± 7 minutes
Frequently asked questions
Is this questionnaire specific to cyber risk?
No. This questionnaire assesses your general enterprise risk management (ERM) framework per ISO 31000, covering strategic, operational, financial, and compliance risk; cyber risk is one category within it.
Does every organisation need formal ISO 31000 certification?
ISO 31000 is guidance, not a certifiable standard like ISO 27001. Organisations can adopt its principles and framework without certification, though some choose to align with other standards such as COSO ERM.
What is the difference between a risk register and risk appetite?
A risk register is the list of identified risks and their assessments. Risk appetite is the level of risk the organisation is willing to accept in pursuit of its objectives, and serves as the reference for deciding which risks need treatment.
Who should complete this questionnaire?
The Chief Risk Officer, a risk manager, or a business process owner who understands the organisation's current risk management framework.
Discuss your risk management framework with our consultants
We help build an enterprise risk management (ERM) framework per ISO 31000, from policy to a working risk register.