Commtac readiness assessments

RiskReady 31000Based on ISO 31000:2018 — Risk Management Guidelines

A readiness assessment and gap analysis for your risk management framework. Score the 8 guiding principles, the framework and governance expectations, and the risk management process — then get a prioritised action plan.

21 clause-mapped questions 15 risk contexts Appetite heatmap 90-day roadmap

What we assess

Three modules mapped directly to the clauses of ISO 31000:2018, plus a risk appetite assessment covering current versus desired appetite per category.

Module A · ISO 31000 Clause 4

Principles

The 8 guiding principles that make risk management create and protect value.

Module B · ISO 31000 Clause 5

Framework

Leadership, governance and the framework that carries risk management.

Module C · ISO 31000 Clause 6

Process

How risk is actually communicated, assessed, treated, monitored and reported.

Module D · Risk appetite

Risk Appetite Assessment

Rate your current versus desired appetite across eight categories.

How it works

Context-aware questioning

Pick your risk domain and ISO 31000 is paired with the right companion standard — ISO 27001, 45001, 22301, 9001, 14001, 27701, 42001 and more.

Maturity scoring per clause

Every principle, framework element and process step is rated 1–5 and rolled into weighted module and overall percentages.

Radar, heatmaps, benchmarks

See gaps on a radar, red-to-green heatmaps per element, and your score against banking, insurance, manufacturing, government, healthcare or technology averages.

Gap report and action plan

Current state vs ISO 31000 requirement vs recommended action, with owners, due dates and a 90-day roadmap for your top five gaps.

Multirater ready

Board, operations and IT answer independently so perception variance surfaces as its own heatmap.

Questionnaire or AI conversation

Answer the multi-choice questionnaire, or work through the same assessment conversationally with the AI assessor.

What practitioners say

Illustrative feedback from risk, assurance and governance teams using clause-mapped readiness assessments. Replace with your own client quotes before publishing.

"Mapping every answer back to a clause settled the debate in our risk committee — we stopped arguing about opinions and started working the gap list."

Group Risk Manager

Financial services, 2 400 staff

"The board and operations answered separately and the variance heatmap showed exactly where leadership thought we were further along than we were."

Head of Governance

Public sector entity

"Pairing ISO 31000 with ISO 27001 for our cyber context meant the recommendations were usable the same week, not after a rewrite."

Information Security Lead

Technology services