AegentraNew Zealand

Govern / New Zealand

ISO 31000 risk management review

Aegentra reviews risk-management arrangements against ISO 31000 guidance for New Zealand organisations. We examine how objectives, criteria, ownership and reporting support decisions, then identify practical improvements.

On this page

Start with the boundary

Define the work that is needed.

For leadership, risk and governance teams whose registers and reports are not providing the clarity needed for decisions.

  • Framework, policy, roles and decision authority
  • Risk criteria and assessment practices
  • Treatment ownership, escalation and reporting
  • Review triggers and continual improvement

Keep the responsibilities distinct

ISO 31000 is guidance, not an organisational certification standard. This is a review and improvement service, not an ISO 31000 certificate or a legal compliance opinion.

What the engagement can produce

Useful outputs, agreed in advance.

  • An agreed review scope and evidence request
  • Observations against the selected ISO 31000 guidance
  • Prioritised improvements with ownership considerations
  • A discussion of practical next steps

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How we work

From evidence to a practical next step.

Agree

Confirm the objective, authority, systems, criteria, access and exclusions. Establish how information will be shared and handled.

Examine

Gather the records and context required by the scope. Distinguish what evidence supports from what is still uncertain.

Act or report

Carry out the agreed consulting, audit, assessment or implementation task. Obtain approval before operational changes.

Verify and hand over

Document outcomes, limitations, owners and follow-up. Retesting or ongoing work is included only when expressly scoped.

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

An illustrative starting point

What a useful first decision looks like.

Fictional example to explain the service, not a New Zealand client case study or a promised outcome.

Business units give the same scenario different risk ratings. Rather than forcing a shared colour, review whether the objectives, criteria and decision authorities are actually aligned.

Questions for the first discussion

  • Which decisions should the risk process improve?
  • Who uses the current risk reports?
  • Where do ownership, criteria or escalation break down?

Before you begin

Your questions, answered.

Does this review produce an ISO 31000 certificate?

No. ISO 31000 provides risk-management guidance and is not used for organisational certification. The useful outputs are an evidence-based view of the agreed scope and prioritised actions, not a certificate.

What can be included in iso 31000 risk management review?

The agreed scope can include framework, policy, roles and decision authority; risk criteria and assessment practices; treatment ownership, escalation and reporting; review triggers and continual improvement. We confirm the exact deliverables and exclusions before work begins, rather than treating every organisation as the same project.

How much does this service cost?

Service pricing is provided by scoped quote, not the Academy’s per-learner course prices. The proposal identifies deliverables, assumptions, exclusions, responsibilities and commercial terms. No fixed price or completion date is promised before the scope is understood.

How do you deliver the work in New Zealand?

We deliver online and arrange visits by appointment where agreed. Scope, assigned competence, timing, access requirements and any travel are confirmed before an engagement.

What should we provide before a proposal?

Bring answers to these starting questions: Which decisions should the risk process improve? Who uses the current risk reports? Where do ownership, criteria or escalation break down? A short initial discussion should establish the boundary and next evidence needed. Do not email secrets or detailed personal records before secure handling has been agreed.

Reference points

Check the underlying guidance.

Page prepared and source references checked . References explain the relevant standard or technology; they are not endorsements of Aegentra.

Discuss your requirement

Start with your business.

Start with the requirement, the systems involved and the outcome you need. Please do not send passwords, sensitive records or unrestricted tenant access in an initial enquiry.