1.4 The Risk Management Standards Landscape and PECB Exam Structure
Key Takeaways
- AS/NZS 4360 (first published 1995, revised 1999 and 2004) is the Australian/New Zealand standard that laid the structural foundation for ISO 31000.
- ISO 31073:2022 replaced ISO Guide 73:2009 as the risk management vocabulary standard; IEC 31010:2019 supplies risk assessment techniques.
- The PECB ISO 31000 Risk Manager exam contains 60 multiple-choice questions, each with three answer options, over 2 hours, with a 70% pass mark.
- The exam is open book: candidates may use a hard copy of ISO 31000, PECB training materials, and personal course notes.
- Exam weighting is Domain 1 (12 questions, 20%), Domain 2 (14 questions, 23.33%), and Domain 3 (34 questions, 56.66%).
1.4 The Risk Management Standards Landscape and PECB Exam Structure
Domain 1 of the PECB exam opens with a competency that candidates routinely underestimate: the ability to recognize relevant standards and regulatory frameworks regarding risk management. Questions in this area do not ask you to apply ISO 31000 — they ask you to place ISO 31000 correctly among the other documents, laws, and contracts that oblige an organization to manage risk. This section supplies that map, then sets out the published structure of the exam itself.
Where ISO 31000 Came From: The AS/NZS 4360 Lineage
ISO 31000 was not written from a blank page. Its architecture was inherited from AS/NZS 4360, the joint Australian/New Zealand risk management standard first published in 1995 and revised in 1999 and 2004. AS/NZS 4360 introduced the now-familiar sequence of establishing the context, identifying risks, analyzing risks, evaluating risks, and treating risks, wrapped by continuous communication/consultation and monitoring/review. When ISO formed working group ISO/TMB WG on risk management, AS/NZS 4360:2004 was adopted as the base document.
| Milestone | Year | Significance |
|---|---|---|
| AS/NZS 4360 | 1995 (rev. 1999, 2004) | Australian/New Zealand standard that laid the structural foundation for ISO 31000 |
| ISO 31000:2009 | 2009 | First international edition: 11 principles, PDCA-style framework |
| ISO 31000:2018 | 2018 | Second edition: 8 principles, leadership-centred 6-component framework |
Exam Tip: A published PECB sample question asks which standard laid the foundation for ISO 31000's structure, with ISO 31030 and IWA 31 as distractors. The answer is AS/NZS 4360. ISO 31030 is travel risk management; IWA 31 is guidance on using ISO 31000 inside management systems.
The Current ISO 31000 Family
ISO 31000 is the anchor of a small family of related deliverables. Knowing which document does what is directly testable.
| Document | Title / Role | Certifiable? |
|---|---|---|
| ISO 31000:2018 | Risk management — Guidelines (principles, framework, process) | No — guidance only |
| ISO 31073:2022 | Risk management — Vocabulary; replaced ISO Guide 73:2009 | No |
| IEC 31010:2019 | Risk management — Risk assessment techniques | No |
| IWA 31:2020 | Guidelines on using ISO 31000 in management systems | No |
| ISO 31022:2020 | Guidelines for the management of legal risk | No |
| ISO 31030:2021 | Travel risk management — Guidance for organizations | No |
| ISO 31050:2023 | Guidance for managing emerging risks to enhance resilience | No |
None of these is a management system standard, so none of them is certifiable for an organization. Certification exists only for individuals, through schemes such as the PECB ISO 31000 credentials. By contrast, ISO 9001, ISO 14001, ISO 22301, ISO 27001, and ISO 45001 are certifiable management system standards — and each of them requires risk-based thinking that ISO 31000 can supply.
Sources of Risk Obligation: Laws, Regulations, Contracts, and Internal Policy
ISO 31000 is voluntary, but the obligations it helps discharge usually are not. A risk manager must be able to identify what compels the organization to manage a given risk, because that determines whether an identified risk is negotiable.
- Laws and statutes — Sarbanes-Oxley Act (internal control over financial reporting), the EU General Data Protection Regulation (GDPR), the EU NIS2 Directive (cybersecurity risk-management measures), occupational health and safety acts, and anti-bribery legislation.
- Sector regulation — Basel III/IV capital and operational risk rules for banks, Solvency II for EU insurers, and prudential regimes that mandate documented risk appetite statements and board risk committees.
- Industry standards and schemes — ISO/IEC 27001, ISO 22301, PCI DSS, and sector codes that carry contractual or licensing force.
- Contracts — service level agreements, indemnity and limitation-of-liability clauses, insurance policy conditions, and supplier flow-down obligations. A contract can create a risk obligation that no statute imposes.
- Market practices — investor expectations, rating-agency methodologies, ESG disclosure norms, and stock-exchange listing rules. These are not legally binding but carry commercial consequence.
- Internal policies — the organization's own code of conduct, delegation of authority, risk appetite statement, and risk management policy. These are self-imposed but are audited and enforced internally.
A structured compliance obligations register — listing each obligation, its source, its owner, and the controls that satisfy it — is the practical output of this competency, and it feeds directly into establishing the internal context in Clause 5.4.1.
The PECB ISO 31000 Risk Manager Exam Structure
PECB publishes the exam structure in the ISO 31000 Risk Manager Candidate Handbook. Study effort should track the official weights, not intuition.
| Competency domain | Questions | Weight |
|---|---|---|
| Domain 1 — Fundamental principles and concepts of risk management | 12 | 20% |
| Domain 2 — Establishment of a risk management framework | 14 | 23.33% |
| Domain 3 — Implementation of a risk management process | 34 | 56.66% |
| Total | 60 | 100% |
Key published mechanics:
- 60 multiple-choice questions, each with three options — one keyed response and two distractors. There is no four-option format on the real exam, so eliminate-two reasoning matters more than on typical certification tests.
- Duration: 2 hours. Candidates sitting in a non-native language may request 20 additional minutes for Manager-level exams.
- Passing score: 70%.
- Open book. Permitted materials are a hard copy of the ISO 31000 standard, PECB training course materials, and personal notes taken during the course.
- Question styles: stand-alone questions plus scenario-based sets, where one scenario is followed by five linked questions.
- Cognitive mix: roughly 26 questions (43.33%) measure comprehension, application, and analysis; roughly 34 questions (56.66%) measure evaluation.
- Results: instant for online multiple-choice delivery; two to four weeks for paper-based multiple-choice.
Passing the exam alone yields the ISO 31000 Provisional Risk Manager credential. The full ISO 31000 Risk Manager credential additionally requires two years of professional experience (one of them in risk management), 200 hours of risk management project activity, two professional references, and signature of the PECB Code of Ethics. Certifications are valid for three years and are maintained through CPD and the annual maintenance fee.
Exam Tip: Because Domain 3 alone is 56.66% of the paper, the risk management process — scope/context/criteria, assessment, treatment, recording and reporting, monitoring and review, and communication and consultation — deserves more than half your revision time. Domains 1 and 2 together are only 26 of 60 questions.
Which standard provided the structural foundation on which ISO 31000 was originally built?
A candidate is allocating revision time across the three PECB ISO 31000 Risk Manager competency domains. Which allocation best reflects the published exam weighting?
Which statement accurately describes the permitted materials and format of the PECB ISO 31000 Risk Manager exam?