All Practice Exams

100+ Free PECB ISO 31000 Foundation Practice Questions

Prepare for the PECB Certificate Holder in ISO 31000 Foundation exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: PECB ISO 31000 Foundation Exam

40 Questions

Exam Format

PECB ISO 31000 Foundation Candidate Handbook

60 Minutes

Exam Time Limit

PECB Foundation Exam Specifications

70%

Passing Score

PECB ISO 31000 Foundation Candidate Handbook

37.5% / 62.5%

Domain Weights (Concepts / Framework & Process)

PECB ISO 31000 Foundation Exam Blueprint

8 Principles

ISO 31000:2018 Risk Management Principles

ISO 31000:2018 Clause 4

Closed Book

Exam Delivery Mode

PECB Exam Rules

PECB ISO 31000 Foundation is PECB's entry-level credential for risk management based on ISO 31000:2018. The exam consists of 40 multiple-choice questions in 60 minutes with a 70% passing score. Domain 1 (about 37.5%) covers fundamental principles and concepts; Domain 2 (about 62.5%) covers the risk management framework and process.

Sample PECB ISO 31000 Foundation Practice Questions

Try these sample questions to test your PECB ISO 31000 Foundation exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1According to ISO 31000, what is the primary purpose of risk management?
A.The creation and protection of value
B.The elimination of all organizational uncertainty
C.The creation of risk-based organizational processes only
D.The certification of management systems against mandatory requirements
Explanation: ISO 31000 states that the purpose of risk management is the creation and protection of value. Effective risk management improves performance, encourages innovation, and supports the achievement of objectives.
2How does ISO 31000:2018 define risk?
A.Only negative events that cause financial loss
B.The effect of uncertainty on objectives
C.The total number of audit nonconformities in a year
D.Any hazard that has already materialized into an incident
Explanation: ISO 31000 defines risk as the effect of uncertainty on objectives. Risk is usually expressed in terms of risk sources, potential events, their consequences, and their likelihood. Effects can be positive, negative, or both.
3Which statement best describes the nature of ISO 31000?
A.It replaces all sector-specific risk standards with a single audit checklist
B.It is limited to financial risk disclosure for publicly listed companies
C.It specifies mandatory requirements for a certifiable organizational risk management system
D.It provides guidelines on managing risk that any organization can customize
Explanation: ISO 31000:2018 provides guidelines—not auditable requirements—on managing risk. Organizations of any type and size can customize the guidance to their context.
4Which document provides a vocabulary for risk management terminology commonly used with ISO 31000?
A.ISO/IEC 27001
B.ISO 9001
C.ISO Guide 73
D.ISO 14001
Explanation: ISO Guide 73 provides risk management vocabulary and is commonly used alongside ISO 31000 for consistent terminology.
5Which standard provides guidance on selecting and applying risk assessment techniques that support ISO 31000?
A.ISO 19011
B.IEC 31010
C.ISO 22301
D.ISO 45001
Explanation: IEC 31010 provides guidance on risk assessment techniques and is designed to support the risk assessment component of ISO 31000.
6In ISO 31000 terminology, what is a risk source?
A.The residual risk remaining after all controls have failed
B.A mandatory legal requirement that cannot be treated
C.An element which alone or in combination has the potential to give rise to risk
D.The final documented risk treatment plan approved by the board
Explanation: A risk source is an element which alone or in combination has the potential to give rise to risk. Identifying risk sources is part of understanding how risk may arise.
7According to ISO 31000, an 'event' is best described as:
A.A permanently accepted residual risk
B.Occurrence or change of a particular set of circumstances
C.Only a catastrophic failure that closes the business
D.A documented policy signed by top management
Explanation: An event is an occurrence or change of a particular set of circumstances. An event can have several causes and can lead to a range of consequences.
8What does 'likelihood' mean in the ISO 31000 risk context?
A.The chance of something happening, whether defined, measured, or determined objectively or subjectively
B.The budget available for risk treatment
C.The severity of impact if an event occurs
D.Only a statistical probability calculated from ten years of historical data
Explanation: Likelihood is the chance of something happening, whether defined, measured, or determined objectively or subjectively, qualitatively or quantitatively, and described using general terms or mathematically.
9Which of the following is a main benefit organizations can gain from effective risk management based on ISO 31000?
A.Improved identification of opportunities and threats, supporting better decisions and performance
B.Replacement of strategic planning with a single risk register
C.Automatic exemption from all legal and regulatory obligations
D.Guaranteed elimination of every operational disruption
Explanation: Effective risk management helps organizations improve the identification of opportunities and threats, increase the likelihood of achieving objectives, improve governance and stakeholder confidence, and support better decisions and performance.
10ISO 31000 can be applied at which organizational levels?
A.Only at the enterprise strategic level
B.Only for projects funded by external investors
C.Strategic, operational, programme, project, or other activities
D.Only within the internal audit function
Explanation: The risk management process can be applied at strategic, operational, programme, project, or other activity levels. ISO 31000 is scalable across the organization.

About the PECB ISO 31000 Foundation Exam

Entry-level certificate validating foundational knowledge of risk management based on ISO 31000:2018 guidelines, including fundamental risk concepts and terminology, the eight risk management principles, the risk management framework (leadership, integration, design, implementation, evaluation, improvement), and the risk management process (communication and consultation; scope, context, and criteria; risk assessment; risk treatment; monitoring and review; recording and reporting).

Questions

40 scored questions

Time Limit

60 minutes

Passing Score

70%

Exam Fee

Included with training course (PECB)

PECB ISO 31000 Foundation Exam Content Outline

~37.5%

Fundamental Principles and Concepts of Risk Management

ISO standards development, ISO 31000 scope and applicability, related risk management standards, benefits of effective risk management, ISO 31000 terminology and concepts, and elements for successful risk management

~62.5%

Risk Management Framework and Risk Management Process

ISO 31000 principles; framework leadership, integration, design, implementation, evaluation, and improvement; process communication and consultation, scope/context/criteria, risk assessment (identify/analyze/evaluate), risk treatment, monitoring and review, and recording and reporting

How to Pass the PECB ISO 31000 Foundation Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 40 questions
  • Time limit: 60 minutes
  • Exam fee: Included with training course

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

PECB ISO 31000 Foundation Study Tips from Top Performers

1Memorize that the purpose of risk management is the creation and protection of value
2Learn the eight ISO 31000:2018 principles: integrated, structured and comprehensive, customized, inclusive, dynamic, best available information, human and cultural factors, and continual improvement
3Distinguish principles (what good risk management looks like), framework (how it is embedded in governance), and process (how risk work is performed day to day)
4Master risk assessment as three linked steps: identification, analysis, and evaluation
5Know risk treatment options: avoid, take/increase for opportunity, remove the source, change likelihood, change consequences, share, or retain by informed decision
6Remember communication and consultation, and monitoring and review, run throughout the process—not only at the end

Frequently Asked Questions

What is the PECB ISO 31000 Foundation exam format?

The PECB ISO 31000 Foundation exam consists of 40 multiple-choice questions to be completed in 60 minutes. The exam is closed-book, proctored online via the PECB Exams platform (or paper-based via a partner), and requires a passing score of 70%.

What topics are covered on the PECB ISO 31000 Foundation exam?

The exam covers two competency domains: Domain 1 (about 37.5%, 15 questions) focuses on fundamental principles and concepts of risk management. Domain 2 (about 62.5%, 25 questions) focuses on the risk management framework and the risk management process as described in ISO 31000.

What is ISO 31000?

ISO 31000:2018 is an international guidelines standard for risk management. It provides principles, a framework, and a process for managing risk that any organization can customize, regardless of size, industry, or sector. It is not a certifiable management system requirements standard for organizations.

Are there prerequisites for taking the PECB ISO 31000 Foundation exam?

There are no formal education or work experience prerequisites. For the certificate program, candidates must complete the PECB ISO 31000 Foundation training course, pass the exam, and sign the PECB Code of Ethics.

What is the retake policy for PECB Foundation exams?

Candidates who complete training with a PECB partner and fail the first attempt are eligible for one free retake within 12 months of course completion. A waiting period applies between attempts. There is no limit on the total number of retakes.

How does ISO 31000 define risk?

ISO 31000 defines risk as the effect of uncertainty on objectives. Risk is usually expressed in terms of risk sources, potential events, their consequences, and their likelihood. Effects can be positive, negative, or both.