Integrated
Make risk thinking part of ordinary decisions, not a separate annual exercise.
Aegentra Academy / Standards guide
New Zealand’s current adoption is NZS ISO 31000:2025, published on 17 October 2025. It is identical to ISO 31000:2018 and supersedes AS/NZS ISO 31000:2009.
Check the Standards New Zealand record
By Aegentra Academy · Source facts checked .
Educational cross-references—not legal advice or a compliance determination.
The standards record
A national publication date does not necessarily mean the underlying international guidance has changed. Standards New Zealand identifies the 2025 adoption as identical to the 2018 ISO text. Australia’s current adoption is AS ISO 31000:2018.
| Reference | What to understand |
|---|---|
| AS/NZS 4360:1995, 1999 and 2004 | Earlier joint risk-management standards in the NZ catalogue history. |
| AS/NZS ISO 31000:2009 | The earlier joint adoption, now superseded in New Zealand. |
| ISO 31000:2018 / AS ISO 31000:2018 | The current published international text and Australian adoption. |
| NZS ISO 31000:2025 | New Zealand’s identical adoption, published 17 October 2025. |
Source: Standards New Zealand — current record and version history.
As checked on 11 October 2026, ISO’s replacement project is at Committee Draft stage 30.60, with a recorded committee event on 1 March 2026. That is not a new published edition; no final publication date is shown on the project page checked. ISO 31000:2018 remains the published edition.
Requirements and references
No universal requirement to buy ISO 31000 training follows from the standard itself. Guidance, an agency policy, a contractual requirement and an individual qualification are different things. Assess the instruments that actually apply to your organisation.
PSR GOV 2 calls for a risk-management approach “in accordance with the New Zealand standard ISO 31000:2018”. This security-governance reference is not a requirement for every organisation or individual to take a PECB course. Check the framework’s applicability to your organisation.
Source: Protective Security Requirements — GOV 2.
Some sources retain an older designation. Record the reference accurately and seek clarification where its interpretation matters rather than silently updating a binding document.
Public-sector capability
The government’s Enterprise Risk Maturity framework sets out 12 attributes across four elements. It can help structure an improvement discussion; it is not a PECB endorsement or a certificate that a course satisfies government requirements.
| Element | Attributes | Learning connection |
|---|---|---|
| Leadership & Direction | Governance, policy and accountabilities; culture, innovation and risk appetite; continuous improvement | Framework direction and review |
| People & Development | Roles and responsibilities; resourcing, skills and training | Ownership and capability |
| Processes & Tools | Risk assessment and mitigation; assurance; monitoring and reporting | Assessment records and follow-up |
| Business Performance | Strategic risk; partnerships; resilience; change and transformation | Connecting risk to objectives |
This mapping is Aegentra’s educational interpretation, not an official course-to-government compliance mapping.
Source: Enterprise Risk Maturity framework, page updated 22 August 2024.
Local government
The Auditor-General’s 2021 observations on local-government risk management are historical context, not a current score for every council. The report distinguishes management responsibilities, elected-member accountability and the assurance role of audit and risk committees.
For a practical review, ask who sets the criteria, who can accept a risk, how actions are followed up and what information the committee receives. A committee can challenge and provide assurance without taking over management’s responsibility.
Read the 2021 report overview · Governance and committee responsibilities
Regulatory cross-references
RBNZ’s Tranche 2 consultation included a Risk Management exposure draft. The consultation closed on 22 May 2026. Its proposals include a risk appetite statement, review arrangements, an independent risk function and a chief risk officer function, with group-specific modifications.
Relevant clauses in the exposure draft include 13 (risk appetite), 22 (review), 30–31 (risk function and CRO) and 35 (board responsibilities). Clause 5 modifies requirements for some groups. Do not assume every institution needs the same standalone role. The text of this particular draft does not reference ISO 31000.
The RBNZ timetable, updated 14 September 2026 targets most standards commencing on 1 December 2028, with exceptions for Crisis Preparedness and Continuity of Access to Deposits. It is not accurate to describe the whole Act and every standard as coming into full effect on that one date.
Training alone does not demonstrate compliance. Check the latest final requirements, applicability and implementation evidence with an appropriately qualified adviser.
Principles, framework and process
Make risk thinking part of ordinary decisions, not a separate annual exercise.
Use a consistent approach so decisions can be understood and compared.
Fit the approach to your objectives, operating context and resources.
Bring relevant perspectives into the decision at the right time.
Revisit risks as conditions, assumptions and objectives change.
Use useful evidence and make its uncertainty and limitations explicit.
Consider how behaviour and organisational culture affect decisions.
Learn from outcomes and strengthen how risk is managed.
Original Aegentra explanations of the principle names, not a reproduction of the ISO standard.
Source: ISO 31000:2018.
The principles describe characteristics of effective risk management. The framework supports integration into how an organisation is directed and managed. The process brings context, assessment, treatment, communication, monitoring and records into particular decisions. This is an original summary, not the paid standard text.
An illustrative decision
Original fictional example—not a client case study, official PECB question or compliance determination. Nothing is scored, stored or sent.
A New Zealand service provider plans to move a customer-facing system to a new supplier. A faster migration may reduce cost, but interruption during the change could affect service commitments. Before choosing a treatment, the team needs to agree what it is protecting and how a decision will be made.
Write the objective, stakeholders and boundary. Ask what information would change the decision and whose judgement is needed.
Record assumptions, evidence gaps and consequences. A neat colour in a risk register is not evidence that uncertainty has been resolved.
Compare options, name an accountable person and define what successful treatment would look like. Record the reasoning.
Choose a date or event that requires a fresh decision—for example a failed migration test, a changed service commitment or a supplier incident.
Ask whether the decision criteria are agreed, whether the evidence is sufficient and whether anyone has accepted responsibility for follow-up. Escalation should be tied to authority and objectives, not simply the largest number in a spreadsheet.
What the award means
ISO 31000 is guidance rather than a requirements standard for organisational ISO certification. PECB offers individual learning and credentials. Course completion, examination success and professional credential eligibility are separate steps; none certifies the learner’s organisation.
Free original resource
Use this worksheet to record applicability questions, evidence, ownership and review dates. It contains the same five source cross-references in CSV and PDF. It does not reproduce the standard, determine compliance or claim to cover every NZ obligation.
Cross-references, not compliance determinations. Original Aegentra learning aid, 11 October 2026. Leave conclusions open until applicability has been assessed.
| Source | Applicability question |
|---|---|
| NZS ISO 31000:2025 | Which objectives and decisions need a structured risk approach? |
| PSR GOV 2 | Is the organisation subject to PSR, and what security risks are in scope? |
| Enterprise Risk Maturity | Which maturity attributes are relevant to the organisation? |
| Council governance | Who owns risk decisions and who provides assurance? |
| Deposit-taker risk management | Is the organisation a deposit taker and which proposed group rules apply? |
Put learning into practice
| Course | Learning focus | English exam | NZD per learner |
|---|---|---|---|
| ISO 31000 Foundation | Understand the essentials | 1 hour · 40 questions · closed book | NZ$470.00 Self-Study |
| ISO 31000 Risk Manager | Apply the risk process | 2 hours · 60 questions · open book | NZ$745.00 Self-Study NZ$743.54 eLearning |
| ISO 31000 Lead Risk Manager | Lead the framework | 3 hours · 80 questions · open book | NZ$1,050.00 Self-Study |
Prices in NZD. No GST is added for New Zealand billing addresses. Australian billing addresses attract 10% GST. Foundation and Risk Manager are not compulsory certificates before the next course; check each course’s expected starting knowledge.
Compare all three ISO 31000 learning pathways · Discuss your learning requirements
Sources and editorial approach
This guide brings together the linked standards catalogues, issuer records and government publications. The worked example and cross-reference worksheet are Aegentra’s illustrative learning material, not official government or PECB guidance.
No named external reviewer or government endorsement is claimed. Check current primary sources before relying on a changing draft or publication status.