AegentraNew Zealand

Aegentra Academy / Standards guide

ISO 31000 in New Zealand: NZS ISO 31000:2025 explained

New Zealand’s current adoption is NZS ISO 31000:2025, published on 17 October 2025. It is identical to ISO 31000:2018 and supersedes AS/NZS ISO 31000:2009.

Check the Standards New Zealand record

By Aegentra Academy · Source facts checked .
Educational cross-references—not legal advice or a compliance determination.

On this page

The standards record

Separate the edition from the adoption.

A national publication date does not necessarily mean the underlying international guidance has changed. Standards New Zealand identifies the 2025 adoption as identical to the 2018 ISO text. Australia’s current adoption is AS ISO 31000:2018.

A short standards timeline
ReferenceWhat to understand
AS/NZS 4360:1995, 1999 and 2004Earlier joint risk-management standards in the NZ catalogue history.
AS/NZS ISO 31000:2009The earlier joint adoption, now superseded in New Zealand.
ISO 31000:2018 / AS ISO 31000:2018The current published international text and Australian adoption.
NZS ISO 31000:2025New Zealand’s identical adoption, published 17 October 2025.

Source: Standards New Zealand — current record and version history.

As checked on 11 October 2026, ISO’s replacement project is at Committee Draft stage 30.60, with a recorded committee event on 1 March 2026. That is not a new published edition; no final publication date is shown on the project page checked. ISO 31000:2018 remains the published edition.

Requirements and references

Does the standard make training mandatory?

No universal requirement to buy ISO 31000 training follows from the standard itself. Guidance, an agency policy, a contractual requirement and an individual qualification are different things. Assess the instruments that actually apply to your organisation.

PSR GOV 2 calls for a risk-management approach “in accordance with the New Zealand standard ISO 31000:2018”. This security-governance reference is not a requirement for every organisation or individual to take a PECB course. Check the framework’s applicability to your organisation.

Source: Protective Security Requirements — GOV 2.

Some sources retain an older designation. Record the reference accurately and seek clarification where its interpretation matters rather than silently updating a binding document.

Public-sector capability

Look beyond the risk register.

The government’s Enterprise Risk Maturity framework sets out 12 attributes across four elements. It can help structure an improvement discussion; it is not a PECB endorsement or a certificate that a course satisfies government requirements.

Aegentra illustrative learning cross-reference
ElementAttributesLearning connection
Leadership & DirectionGovernance, policy and accountabilities; culture, innovation and risk appetite; continuous improvementFramework direction and review
People & DevelopmentRoles and responsibilities; resourcing, skills and trainingOwnership and capability
Processes & ToolsRisk assessment and mitigation; assurance; monitoring and reportingAssessment records and follow-up
Business PerformanceStrategic risk; partnerships; resilience; change and transformationConnecting risk to objectives

This mapping is Aegentra’s educational interpretation, not an official course-to-government compliance mapping.

Source: Enterprise Risk Maturity framework, page updated 22 August 2024.

Local government

Be clear about who decides and who assures.

The Auditor-General’s 2021 observations on local-government risk management are historical context, not a current score for every council. The report distinguishes management responsibilities, elected-member accountability and the assurance role of audit and risk committees.

For a practical review, ask who sets the criteria, who can accept a risk, how actions are followed up and what information the committee receives. A committee can challenge and provide assurance without taking over management’s responsibility.

Read the 2021 report overview · Governance and committee responsibilities

Regulatory cross-references

A draft is not a compliance determination.

RBNZ’s Tranche 2 consultation included a Risk Management exposure draft. The consultation closed on 22 May 2026. Its proposals include a risk appetite statement, review arrangements, an independent risk function and a chief risk officer function, with group-specific modifications.

Relevant clauses in the exposure draft include 13 (risk appetite), 22 (review), 30–31 (risk function and CRO) and 35 (board responsibilities). Clause 5 modifies requirements for some groups. Do not assume every institution needs the same standalone role. The text of this particular draft does not reference ISO 31000.

The RBNZ timetable, updated 14 September 2026 targets most standards commencing on 1 December 2028, with exceptions for Crisis Preparedness and Continuity of Access to Deposits. It is not accurate to describe the whole Act and every standard as coming into full effect on that one date.

Training alone does not demonstrate compliance. Check the latest final requirements, applicability and implementation evidence with an appropriately qualified adviser.

Principles, framework and process

Make the guidance useful.

Integrated

Make risk thinking part of ordinary decisions, not a separate annual exercise.

Structured and comprehensive

Use a consistent approach so decisions can be understood and compared.

Customised

Fit the approach to your objectives, operating context and resources.

Inclusive

Bring relevant perspectives into the decision at the right time.

Dynamic

Revisit risks as conditions, assumptions and objectives change.

Best available information

Use useful evidence and make its uncertainty and limitations explicit.

Human and cultural factors

Consider how behaviour and organisational culture affect decisions.

Continual improvement

Learn from outcomes and strengthen how risk is managed.

Original Aegentra explanations of the principle names, not a reproduction of the ISO standard.

Source: ISO 31000:2018.

The principles describe characteristics of effective risk management. The framework supports integration into how an organisation is directed and managed. The process brings context, assessment, treatment, communication, monitoring and records into particular decisions. This is an original summary, not the paid standard text.

An illustrative decision

From a supplier change to a review trigger.

Original fictional example—not a client case study, official PECB question or compliance determination. Nothing is scored, stored or sent.

A service provider is changing a critical supplier.

A New Zealand service provider plans to move a customer-facing system to a new supplier. A faster migration may reduce cost, but interruption during the change could affect service commitments. Before choosing a treatment, the team needs to agree what it is protecting and how a decision will be made.

Start with the decision

Write the objective, stakeholders and boundary. Ask what information would change the decision and whose judgement is needed.

Make uncertainty visible

Record assumptions, evidence gaps and consequences. A neat colour in a risk register is not evidence that uncertainty has been resolved.

Give the action an owner

Compare options, name an accountable person and define what successful treatment would look like. Record the reasoning.

Set a review trigger

Choose a date or event that requires a fresh decision—for example a failed migration test, a changed service commitment or a supplier incident.

What would you challenge before approving the plan?

Ask whether the decision criteria are agreed, whether the evidence is sufficient and whether anyone has accepted responsibility for follow-up. Escalation should be tied to authority and objectives, not simply the largest number in a spreadsheet.

What the award means

Individuals and organisations are different.

ISO 31000 is guidance rather than a requirements standard for organisational ISO certification. PECB offers individual learning and credentials. Course completion, examination success and professional credential eligibility are separate steps; none certifies the learner’s organisation.

Source: ISO’s explanation of risk-management guidance.

Free original resource

Build your own cross-reference.

Use this worksheet to record applicability questions, evidence, ownership and review dates. It contains the same five source cross-references in CSV and PDF. It does not reproduce the standard, determine compliance or claim to cover every NZ obligation.

Cross-references, not compliance determinations. Original Aegentra learning aid, 11 October 2026. Leave conclusions open until applicability has been assessed.

What the worksheet helps you ask
SourceApplicability question
NZS ISO 31000:2025Which objectives and decisions need a structured risk approach?
PSR GOV 2Is the organisation subject to PSR, and what security risks are in scope?
Enterprise Risk MaturityWhich maturity attributes are relevant to the organisation?
Council governanceWho owns risk decisions and who provides assurance?
Deposit-taker risk managementIs the organisation a deposit taker and which proposed group rules apply?

Put learning into practice

Choose a course for your starting point.

Choose the depth that fits your responsibilities
CourseLearning focusEnglish examNZD per learner
ISO 31000 FoundationUnderstand the essentials1 hour · 40 questions · closed bookNZ$470.00 Self-Study
ISO 31000 Risk ManagerApply the risk process2 hours · 60 questions · open bookNZ$745.00 Self-Study
NZ$743.54 eLearning
ISO 31000 Lead Risk ManagerLead the framework3 hours · 80 questions · open bookNZ$1,050.00 Self-Study

Prices in NZD. No GST is added for New Zealand billing addresses. Australian billing addresses attract 10% GST. Foundation and Risk Manager are not compulsory certificates before the next course; check each course’s expected starting knowledge.

Compare all three ISO 31000 learning pathways · Discuss your learning requirements

Sources and editorial approach

Check the primary record.

This guide brings together the linked standards catalogues, issuer records and government publications. The worked example and cross-reference worksheet are Aegentra’s illustrative learning material, not official government or PECB guidance.

No named external reviewer or government endorsement is claimed. Check current primary sources before relying on a changing draft or publication status.