ISO 31000:2018 Training

ISO 31000 Lead Risk Manager Course in Pakistan

40 CPD hours, examination fee included. Learn to design, lead and report a risk management framework built on ISO 31000:2018, using the assessment techniques of IEC 31010. Delivered live online, on site in the classroom, or at your own pace.

Course at a glance
Duration
40 CPD hours
Standard
ISO 31000:2018
Delivery
Live online, on site classroom
or self paced
Assessment
Formal exam, fee included
Fee
PKR 70,000 to 90,000Approximately USD 250 to 320
Certificate
Internationally recognised
and verifiable
New batches run throughout the year. Ask us for the next available date.
The course

Risk is the effect of uncertainty on objectives. Everything else follows from that.

ISO 31000:2018 was published on 14 February 2018 and reconfirmed in 2023, and it is the international reference for how an organisation manages risk. It has three parts: eight principles that say what good risk management is for, a framework that puts risk inside governance and decision making rather than beside it, and a process that runs from context and criteria through identification, analysis, evaluation and treatment to monitoring, reporting and review.

This course trains you to lead that work. Across 40 CPD hours you go through the principles, build and evaluate a framework, run the process on a real case, and learn to choose an assessment technique from IEC 31010 rather than reaching for a five by five matrix out of habit. The course closes with a formal examination.

A risk register that only contains the things that have already gone wrong is a history of the organisation, not a view of its future.

The part most delegates find genuinely new is integration. Risk management fails far more often through organisational design than through technique: the register sits with a risk function, the decisions sit with the business, and the two meet once a quarter. A full module is spent on how risk reaches a budget conversation, a project gate and a board paper in a form somebody can act on.

Why now

Why a risk credential is worth more here than a risk policy.

Including the thing most providers get wrong about this standard, which is worth understanding before you pay anybody for training on it.

No organisation can be certified to ISO 31000

ISO is explicit that the standard cannot be used for certification purposes, although it does give guidance for internal and external audit programmes. Several providers in this market still advertise an ISO 31000 lead auditor certification. What genuinely exists is a competence credential held by a person, which is what this course leads to, and knowing the difference will save you from buying the wrong thing.

Governance makes the committee optional, not the duty

Under the SECP Listed Companies Code of Corporate Governance Regulations 2019, the Audit Committee is mandatory and must ascertain that internal control systems, financial and operational, are adequate and effective, and review the company's statement on internal controls before the board endorses it. The Risk Management Committee at Regulation 30 is recommendatory. Boards therefore carry the obligation without being required to build the function, and somebody inside the company has to be competent enough to close that gap.

The uncertainty is not theoretical

The 2022 floods alone produced an estimated Rs 1.986 trillion in economic losses, and after the 2025 season the year's growth target was revised down from 4.2 percent to a range of 3.25 to 4.25 percent. Add currency movement, energy cost and export demand, and the difference between boards that had priced these into an appetite statement and boards that had not shows up in the decisions they made.

The one qualification that sits above the others

ISO 9001, ISO 27001, ISO 22301, ISO 45001 and ISO 42001 all now run on risk based thinking, and each of them assumes a competence the auditor training does not itself teach. A risk credential is the foundation under every other standard you work with, which is why it travels further than any single management system qualification.

Practice

The risk management process, and where it usually breaks.

Every step below is in the standard. The right hand column is what actually happens to it inside most organisations, and learning to see it is the difference between running a register and managing risk.

Step in ISO 31000The failure it usually collapses into
Leadership and commitmentA risk appetite that has never been written down, let alone agreed by the board, so nobody can say which risks the organisation is willing to carry
Integration into governanceA parallel process running beside strategy and budgeting rather than inside them, reviewed after the decision has already been taken
Scope, context and criteriaCriteria set once in a workshop and never revisited, with the result that almost everything scores medium
Risk identificationThis year's register built from last year's register, capturing the events that have already happened rather than the ones that have not
Risk analysisA five by five matrix used as arithmetic, multiplying two estimates together and treating the product as data
Risk evaluationNo stated appetite, so there is no rule for which risks are accepted, by whom, and on what authority
Risk treatmentTreatments assigned to people who hold neither the budget nor the authority to change anything
Monitoring and reviewReviewed on a calendar rather than when something material actually changes
Recording and reportingA register presented to the board as a list, with no aggregation, no trend and nothing a director can decide on
Communication and consultationRisk owned by the risk function instead of by the people who make the decisions that create it

IEC 31010 sets out more than thirty risk assessment techniques. Part of what this course teaches is how to choose among them, because the matrix is appropriate for a narrow set of problems and is used for almost all of them.

Course content

40 CPD hours across five modules.

Instruction, workshops and a running case study, with the formal examination at the end of the final module.

Module one
Language, principles and purposeRisk defined as the effect of uncertainty on objectives, the vocabulary of ISO 31073, the eight principles of ISO 31000 and what each one rules out, and why the definition of risk changes the shape of everything built on it.
Module two
The frameworkLeadership and commitment, integration into governance and decision making, designing, implementing, evaluating and improving the framework, defining risk appetite and setting criteria that can survive a real decision.
Module three
The processScope, context and criteria, identification, analysis, evaluation and treatment, worked end to end on a case, with the IEC 31010 techniques and how to select one that fits the question rather than the habit.
Module four
Making it stickMonitoring and review, recording and reporting, communication and consultation, and getting risk into strategy, budgeting, project gates and board papers in a form somebody can act on.
Module five
Leading the programme and examinationRunning a risk programme across a business, maturity assessment and improvement, reporting to a board committee, then the formal written examination.
Who should attend

For the people who have to answer when a board asks what could go wrong.

Risk

Risk and compliance officers

In banks, insurers, microfinance institutions and listed companies, where the register already exists and the question is whether it changes any decision.

Assurance

Internal auditors

Moving from testing controls to assessing whether the risk framework those controls are supposed to serve is fit for purpose.

Governance

Company secretaries and committee secretaries

Supporting audit and risk committees under the SECP corporate governance regulations, and preparing the papers those committees rely on.

Operations

Project, plant and supply chain leads

In construction, energy, manufacturing and logistics, where risk decisions are made in project gates and procurement rather than in a committee room.

Systems

Management system managers

Running ISO 9001, ISO 27001, ISO 22301, ISO 45001 or ISO 42001 and wanting the risk competence those standards assume you already have.

Not sure

Unsure whether your background fits?

Send us your role and your experience and we will tell you honestly whether this course is the right one for you before you book anything.

Ask us first
Examination and certificate

What you sit, and what you walk away with.

Examination
Fee included

The examination fee is part of the course fee. There is no separate charge to sit the paper at the end of the course, and no hidden certification cost afterwards.

CPD hours
40 CPD hours

Forty CPD hours of instructed time, matching the hours expected of a lead level qualification internationally. Full attendance across all five modules is required to sit the examination.

Your certificate
Verifiable

Successful delegates receive an internationally recognised certificate issued under an accredited personnel certification scheme. Any employer or certification body can verify it independently, and Axora will confirm any certificate we have issued on request.

Delivery and fee

Three ways to take the same course.

The syllabus, the CPD hours and the examination are identical in all three. Choose the format that fits how you work.

Format one

Live online

Instructor led through the full 40 CPD hours in a virtual classroom, with the same workshops and case work as the in person course. Suitable anywhere in Pakistan and across the Gulf.

Format two

On site classroom

The full 40 CPD hours in the room with the trainer and the rest of the group. The format most delegates prefer for the case work, and the one employers most often book for a team.

Format three

Self paced

The same 40 CPD hours of material worked through on your own schedule, with tutor support and the same formal examination at the end. Almost no other provider in Pakistan offers this route.

PKR 70,000 to 90,000 Approximately USD 250 to 320

The examination fee is included. Where your fee sits inside the band depends on the delivery format you choose, with the self paced route at the lower end and the on site classroom at the upper end. Tell us the format and the number of delegates and we will confirm the exact figure in writing before you commit to anything.

Questions

Frequently asked questions

How much does the ISO 31000 lead risk manager course cost in Pakistan?

The fee is between PKR 70,000 and PKR 90,000, roughly USD 250 to 320, and the examination fee is included in that figure. Where you sit in the band depends on whether you take the self paced, live online or on site classroom format, and on how many delegates you are booking. We confirm the exact figure in writing before you commit.

How long is the course?

40 CPD hours in total, delivered across five modules. The final module closes with the formal examination. How those hours are scheduled depends on the format you choose, which is why we quote the course in hours rather than in days.

Can an organisation be certified to ISO 31000?

No. ISO states plainly that ISO 31000 cannot be used for certification purposes, although it does provide guidance for internal and external audit programmes. What can be certified is a person's competence, which is what this course leads to. If a provider offers to certify your company against ISO 31000, that offer does not match the standard.

Is this a lead auditor course?

No, and that is deliberate. Because no organisation can be certified to ISO 31000, there is no third party audit to lead against it. This is a risk manager credential: it qualifies you to design, run and improve a risk management framework and to assess one against the standard. If you want a lead auditor qualification, look at our ISO 22301 or ISO 42001 courses instead, or ask us and we will point you at the right one.

Is the examination fee included?

Yes. The examination fee is included in the course fee. There is no separate charge to sit the paper and no additional certification cost afterwards.

When is the next batch?

We run batches throughout the year rather than publishing a fixed annual calendar, so the fastest way to get a date is to ask. Send your preferred format and month through the training registration form or the contact page and we will come back with the next available dates.

How does this relate to the risk based thinking in ISO 9001 and ISO 27001?

Every modern management system standard requires risk to be considered, and none of them teaches you how. ISO 9001 asks for risks and opportunities to be addressed, ISO/IEC 27001 requires an information security risk assessment and treatment process, ISO 22301 builds its whole analysis on risk, and ISO/IEC 42001 adds AI specific risk and impact assessment. ISO 31000 is the common method underneath all of them, which is why this credential strengthens every other one you hold.

Can I take the course online or at my own pace?

Both. The live online format is instructor led through the full 40 CPD hours. The self paced format gives you the same material to work through on your own schedule with tutor support, and the same formal examination at the end. Very few providers in Pakistan offer a self paced route at this level.

Is the certificate internationally recognised, and can it be verified?

Yes. Successful delegates receive an internationally recognised certificate issued under an accredited personnel certification scheme, and it can be verified independently by an employer or a certification body. Axora also confirms any certificate we have issued through our certification verification page.

Do I need prior experience in risk management?

Delegates who already work with a risk register, an audit committee or a management system will move fastest, but the course starts from the definitions and builds up. If you are coming from finance, operations or IT without a formal risk role, tell us about your work before you book and we will give you an honest answer about whether to start here.

Do you deliver this course for a whole team?

Yes. In house delivery for a group is available in the classroom or live online. Tell us the number of delegates and your preferred window through the contact page and we will put together a schedule and a fee.

Register

Become the person your board asks before the decision, not after it.

Tell us which format suits you and when you want to sit it. We will confirm the next available batch, the exact fee and what to prepare, in writing, before you commit to anything.