RiskReady 31000 documentation

Risk Navigator — end-to-end user guide

Everything you need to run a readiness assessment and gap analysis based on ISO 31000:2018 — from setting up a client company to exporting the 90-day roadmap.

1. What Risk Navigator does

Risk Navigator is the assessment engine inside RiskReady 31000. It guides an organisation through a structured self-assessment of risk management maturity against ISO 31000:2018, then converts the answers into scores, heatmaps, benchmarks, a gap report and a 90-day action plan.

2. Roles and access

Access is role-based and a user may hold more than one role.

RoleWhat they can do
AdminFull platform control: create, edit and delete users, assign and change roles, manage companies and consultant assignments, monitor activity, open any assessment.
ConsultantSets up client companies, runs assessments on their behalf, invites rater groups, reviews variance heatmaps, looks up completed client assessments and exports reports.
CompanySigned in against one assigned company only. Completes assessments and multirater questionnaires and views that company's results.
Rater groups (Board / Operations / IT)Used for the multirater perception gap. Each group answers independently; answers are not shared until variance is calculated.

Company rater groups

Within a company, staff are tagged as Board, Operations or IT. This tagging drives the multirater perception gap and is set when staff are captured on the company record.

3. Getting started

3.1 Sign in

  1. Open the application and choose Sign in.
  2. Sign in with your email and password, or use Google.
  3. New accounts are created by an Admin or Consultant — there is no open self sign-up.
  4. After sign-in you land on your Dashboard, showing your email, roles and available actions.

3.2 Dashboard orientation

4. Setting up a company

Every assessment belongs to a company. Consultants create and maintain company records; Admins can create them and reassign consultants at any time.

  1. From the Dashboard choose Start an assessment, then Create a new company.
  2. Capture company name, contact number, website and email. Fields are validated inline and problems are highlighted.
  3. Add staff: name, email and role from the dropdown (CEO, CFO, Risk Manager, HR Manager, IT Manager, Operations and others).
  4. Tag each staff member with a rater group (Board, Operations or IT) if they will take part in the multirater exercise.
  5. Save. The company is assigned to you automatically, and a company may have multiple consultants assigned.

Company-role users can only sign in against the company assigned to them. Assign the company when you create the user, otherwise their workspace will be empty.

5. Running an assessment

5.1 Step 1 — Which company is this assessment for?

Wherever you start an assessment, this card appears first. Select an existing company or create a new one. Nothing starts until a company is chosen, which keeps every result, report and heatmap attached to the correct client.

5.2 Step 2 — Choose the risk context

Risk Navigator pairs ISO 31000 questions with the relevant supporting standard and adds context-specific probes.

ContextPaired standard(s)Typical focus
General Enterprise Risk ManagementISO 31000:2018 coreWhole-of-business risk programmes
Information SecurityISO/IEC 27001 / 27005ISMS risk assessment and treatment
Cyber SecurityISO/IEC 27001, NIST CSFThreat-led cyber risk governance
Business Continuity / ResilienceISO 22301BIA, RTO/RPO, disruption scenarios
Operational RiskISO 31000, Basel-style practiceProcess, people and systems failure
Project / Portfolio RiskISO 21500 / PMBOKSchedule, cost, scope, benefits
Health & SafetyISO 45001Hazard identification, worker consultation
EnvironmentalISO 14001Aspects, impacts, compliance obligations
Quality ManagementISO 9001Risk-based thinking in processes
Financial RiskISO 31000, IFRS practiceCredit, market, liquidity, capital
Supply Chain / Third PartyISO 28000 / 27036Vendor concentration and dependency
ESG / SustainabilityISO 26000, GRIClimate, social and governance exposure
Data PrivacyISO/IEC 27701, GDPR/POPIALawful basis, DPIAs, subject rights
AI GovernanceISO/IEC 42001Model risk, bias, human oversight
Fraud & Financial CrimeISO 37001, PCI DSS v4.0.1Bribery, fraud, card payment risk
CustomDescribe your ownAny context not listed above

5.3 Step 3 — Answer the question modules

ModuleISO 31000 clauseCoverage
Module A — PrinciplesClause 4The 8 guiding principles: integrated, structured & comprehensive, customised, inclusive, dynamic, best available information, human & cultural factors, continual improvement.
Module B — Framework & LeadershipClause 5Leadership and commitment, integration, design, implementation, evaluation and improvement of the framework.
Module C — ProcessClause 6Communication & consultation, scope/context/criteria, identification, analysis, evaluation, treatment, monitoring & review, recording & reporting.
Module D — Risk AppetiteSupportingCurrent versus desired appetite across eight categories, producing the appetite gap heatmap.

Answering by multiple choice

Each question offers a maturity level from 1 to 5. Choose the statement that best matches current practice and note the evidence you relied on.

ScoreMaturity levelMeaning
1Initial / Ad hocNo defined approach; reactive and person-dependent.
2DevelopingSome documentation, inconsistently applied.
3DefinedDocumented, approved and generally followed.
4ManagedMeasured, monitored and reported with evidence.
5OptimisingContinually improved and embedded in decisions.

Answering by AI interview

5.4 Step 4 — Risk appetite

For each of the eight categories — strategy & growth, financial, operational, compliance & regulatory, reputational, technology & cyber, people & culture, and safety & environment — set the appetite you take today and the appetite you believe you should take on a 1–5 scale. The distance between the two becomes the appetite gap heatmap.

5.5 Step 5 — Review and submit

Check the summary, then submit. Submitted responses become available to the Consultant lookup and to the multirater variance engine.

6. Multirater perception gap

The perception gap shows where Board, Operations and IT see the same organisation differently — often the fastest route to a real governance conversation.

  1. Open Multirater gap from the Dashboard and select the company (mandatory).
  2. Select or create the assessment the groups will complete.
  3. Invite the registered users in each rater group — only registered users can be invited.
  4. Each group completes the questionnaire independently; no group sees another group's answers.
  5. Once two or more groups have submitted, open the variance heatmap.

Reading the variance heatmap

7. Results, reports and benchmarking

On-screen results

Exporting

  1. Open the results view for the completed assessment.
  2. Choose Word for the formatted report or PDF for a print-ready version.
  3. On publish or download, a Word copy is emailed to the Commtac review addresses.

Consultant lookup of completed assessments

From the Dashboard, use Completed client assessments to filter by client organisation, search by title and open any assessment with at least one submitted response, including its results and variance heatmap.

8. Administration

User management

Companies

Activity monitoring

The activity tab records sign-ins, assessment activity and administrative changes so you can see who did what and when.

9. Recommended end-to-end workflow

  1. Admin creates the Consultant account and assigns the Consultant role.
  2. Consultant creates the client company with contact details and staff, tagging Board, Operations and IT members.
  3. Consultant starts an assessment, selects the company and chooses the risk context.
  4. Client completes Modules A, B and C by multiple choice or AI interview.
  5. Client completes the risk appetite step.
  6. Consultant invites the Board, Operations and IT groups to answer independently.
  7. Consultant reviews scores, appetite heatmap, benchmarks and the variance heatmap.
  8. Consultant exports the Word gap report and 90-day roadmap and presents it to the client.
  9. Re-run the assessment after the roadmap period to evidence improvement.

10. Good-practice tips

11. Troubleshooting

SymptomWhat to do
“Which company is this assessment for?” keeps appearingEvery entry point is gated. Select an existing company or create one — an assessment cannot start without it.
Company user sees no data after signing inThe user has not been assigned to a company. An Admin or Consultant must assign them on the company record.
Cannot save a company assignmentAssignees must hold the Consultant or Admin role, or already manage that company.
Variance heatmap is emptyAt least two rater groups must have submitted responses for the same assessment.
Voice interview will not recordAllow microphone access in the browser, then reload the page.
Report will not downloadDisable pop-up blocking for the site and retry the Word or PDF export.

12. Support

For help with Risk Navigator, contact Commtac Consult Ltd at tim@commtac.co or pete@commtac.co.

This guide describes functionality aligned to ISO 31000:2018 clauses 4, 5 and 6. ISO 31000 is a guidance standard and is not certifiable; references to other standards are for contextual detail only.