Risk Management Readiness Check

Sixteen yes/no questions that assess the maturity of your enterprise risk management framework per ISO 31000: governance, identification, treatment, and monitoring. Applicable to any type of organisation.

  • 16 questions
  • ± 7 minutes
  1. 1Details
  2. 2
  3. 3
Before you start

Before you start

Four short fields so we can send you the result and follow up if you wish.

The result summary is sent to this address.

By continuing you agree that these details are used to send your result and to follow up, per our Privacy Policy.

16 questions · ± 7 minutes

Frequently asked questions

Is this questionnaire specific to cyber risk?

No. This questionnaire assesses your general enterprise risk management (ERM) framework per ISO 31000, covering strategic, operational, financial, and compliance risk; cyber risk is one category within it.

Does every organisation need formal ISO 31000 certification?

ISO 31000 is guidance, not a certifiable standard like ISO 27001. Organisations can adopt its principles and framework without certification, though some choose to align with other standards such as COSO ERM.

What is the difference between a risk register and risk appetite?

A risk register is the list of identified risks and their assessments. Risk appetite is the level of risk the organisation is willing to accept in pursuit of its objectives, and serves as the reference for deciding which risks need treatment.

Who should complete this questionnaire?

The Chief Risk Officer, a risk manager, or a business process owner who understands the organisation's current risk management framework.

Discuss your risk management framework with our consultants

We help build an enterprise risk management (ERM) framework per ISO 31000, from policy to a working risk register.