Commtac readiness assessments
RiskReady 31000Based on ISO 31000:2018 — Risk Management Guidelines
A readiness assessment and gap analysis for your risk management framework. Score the 8 guiding principles, the framework and governance expectations, and the risk management process — then get a prioritised action plan.
What we assess
Three modules mapped directly to the clauses of ISO 31000:2018, plus a risk appetite assessment covering current versus desired appetite per category.
Module A · ISO 31000 Clause 4
Principles
The 8 guiding principles that make risk management create and protect value.
Module B · ISO 31000 Clause 5
Framework
Leadership, governance and the framework that carries risk management.
Module C · ISO 31000 Clause 6
Process
How risk is actually communicated, assessed, treated, monitored and reported.
Module D · Risk appetite
Risk Appetite Assessment
Rate your current versus desired appetite across eight categories.
How it works
Context-aware questioning
Pick your risk domain and ISO 31000 is paired with the right companion standard — ISO 27001, 45001, 22301, 9001, 14001, 27701, 42001 and more.
Maturity scoring per clause
Every principle, framework element and process step is rated 1–5 and rolled into weighted module and overall percentages.
Radar, heatmaps, benchmarks
See gaps on a radar, red-to-green heatmaps per element, and your score against banking, insurance, manufacturing, government, healthcare or technology averages.
Gap report and action plan
Current state vs ISO 31000 requirement vs recommended action, with owners, due dates and a 90-day roadmap for your top five gaps.
Multirater ready
Board, operations and IT answer independently so perception variance surfaces as its own heatmap.
Questionnaire or AI conversation
Answer the multi-choice questionnaire, or work through the same assessment conversationally with the AI assessor.
What practitioners say
Illustrative feedback from risk, assurance and governance teams using clause-mapped readiness assessments. Replace with your own client quotes before publishing.
"Mapping every answer back to a clause settled the debate in our risk committee — we stopped arguing about opinions and started working the gap list."
Group Risk Manager
Financial services, 2 400 staff
"The board and operations answered separately and the variance heatmap showed exactly where leadership thought we were further along than we were."
Head of Governance
Public sector entity
"Pairing ISO 31000 with ISO 27001 for our cyber context meant the recommendations were usable the same week, not after a rewrite."
Information Security Lead
Technology services