RiskReady 31000 documentation
Risk Navigator — end-to-end user guide
Everything you need to run a readiness assessment and gap analysis based on ISO 31000:2018 — from setting up a client company to exporting the 90-day roadmap.
1. What Risk Navigator does
Risk Navigator is the assessment engine inside RiskReady 31000. It guides an organisation through a structured self-assessment of risk management maturity against ISO 31000:2018, then converts the answers into scores, heatmaps, benchmarks, a gap report and a 90-day action plan.
- Choose the risk context so questions are paired with the right supporting standard.
- Answer by multiple choice or by talking to the AI interviewer.
- Score the 8 guiding principles, the framework and leadership expectations, and the risk management process.
- Capture current versus desired risk appetite across eight categories.
- Run a multirater perception gap between Board, Operations and IT.
- Export the gap report to Word or PDF and email it to stakeholders.
2. Roles and access
Access is role-based and a user may hold more than one role.
| Role | What they can do |
|---|---|
| Admin | Full platform control: create, edit and delete users, assign and change roles, manage companies and consultant assignments, monitor activity, open any assessment. |
| Consultant | Sets up client companies, runs assessments on their behalf, invites rater groups, reviews variance heatmaps, looks up completed client assessments and exports reports. |
| Company | Signed in against one assigned company only. Completes assessments and multirater questionnaires and views that company's results. |
| Rater groups (Board / Operations / IT) | Used for the multirater perception gap. Each group answers independently; answers are not shared until variance is calculated. |
Company rater groups
Within a company, staff are tagged as Board, Operations or IT. This tagging drives the multirater perception gap and is set when staff are captured on the company record.
3. Getting started
3.1 Sign in
- Open the application and choose Sign in.
- Sign in with your email and password, or use Google.
- New accounts are created by an Admin or Consultant — there is no open self sign-up.
- After sign-in you land on your Dashboard, showing your email, roles and available actions.
3.2 Dashboard orientation
- Start an assessment — launches the mandatory company selection card.
- Multirater gap — opens the perception gap workspace.
- Admin console — visible to Admins only.
- Completed client assessments — Consultants filter by client, search by title and open any submitted assessment.
- Your access — badges showing the roles assigned to you.
- Organisations — the companies you manage, with staff and contact details.
4. Setting up a company
Every assessment belongs to a company. Consultants create and maintain company records; Admins can create them and reassign consultants at any time.
- From the Dashboard choose Start an assessment, then Create a new company.
- Capture company name, contact number, website and email. Fields are validated inline and problems are highlighted.
- Add staff: name, email and role from the dropdown (CEO, CFO, Risk Manager, HR Manager, IT Manager, Operations and others).
- Tag each staff member with a rater group (Board, Operations or IT) if they will take part in the multirater exercise.
- Save. The company is assigned to you automatically, and a company may have multiple consultants assigned.
Company-role users can only sign in against the company assigned to them. Assign the company when you create the user, otherwise their workspace will be empty.
5. Running an assessment
5.1 Step 1 — Which company is this assessment for?
Wherever you start an assessment, this card appears first. Select an existing company or create a new one. Nothing starts until a company is chosen, which keeps every result, report and heatmap attached to the correct client.
5.2 Step 2 — Choose the risk context
Risk Navigator pairs ISO 31000 questions with the relevant supporting standard and adds context-specific probes.
| Context | Paired standard(s) | Typical focus |
|---|---|---|
| General Enterprise Risk Management | ISO 31000:2018 core | Whole-of-business risk programmes |
| Information Security | ISO/IEC 27001 / 27005 | ISMS risk assessment and treatment |
| Cyber Security | ISO/IEC 27001, NIST CSF | Threat-led cyber risk governance |
| Business Continuity / Resilience | ISO 22301 | BIA, RTO/RPO, disruption scenarios |
| Operational Risk | ISO 31000, Basel-style practice | Process, people and systems failure |
| Project / Portfolio Risk | ISO 21500 / PMBOK | Schedule, cost, scope, benefits |
| Health & Safety | ISO 45001 | Hazard identification, worker consultation |
| Environmental | ISO 14001 | Aspects, impacts, compliance obligations |
| Quality Management | ISO 9001 | Risk-based thinking in processes |
| Financial Risk | ISO 31000, IFRS practice | Credit, market, liquidity, capital |
| Supply Chain / Third Party | ISO 28000 / 27036 | Vendor concentration and dependency |
| ESG / Sustainability | ISO 26000, GRI | Climate, social and governance exposure |
| Data Privacy | ISO/IEC 27701, GDPR/POPIA | Lawful basis, DPIAs, subject rights |
| AI Governance | ISO/IEC 42001 | Model risk, bias, human oversight |
| Fraud & Financial Crime | ISO 37001, PCI DSS v4.0.1 | Bribery, fraud, card payment risk |
| Custom | Describe your own | Any context not listed above |
5.3 Step 3 — Answer the question modules
| Module | ISO 31000 clause | Coverage |
|---|---|---|
| Module A — Principles | Clause 4 | The 8 guiding principles: integrated, structured & comprehensive, customised, inclusive, dynamic, best available information, human & cultural factors, continual improvement. |
| Module B — Framework & Leadership | Clause 5 | Leadership and commitment, integration, design, implementation, evaluation and improvement of the framework. |
| Module C — Process | Clause 6 | Communication & consultation, scope/context/criteria, identification, analysis, evaluation, treatment, monitoring & review, recording & reporting. |
| Module D — Risk Appetite | Supporting | Current versus desired appetite across eight categories, producing the appetite gap heatmap. |
Answering by multiple choice
Each question offers a maturity level from 1 to 5. Choose the statement that best matches current practice and note the evidence you relied on.
| Score | Maturity level | Meaning |
|---|---|---|
| 1 | Initial / Ad hoc | No defined approach; reactive and person-dependent. |
| 2 | Developing | Some documentation, inconsistently applied. |
| 3 | Defined | Documented, approved and generally followed. |
| 4 | Managed | Measured, monitored and reported with evidence. |
| 5 | Optimising | Continually improved and embedded in decisions. |
Answering by AI interview
- Switch to the interview view to answer conversationally by text or voice.
- Voice answers are transcribed automatically; the agent replies in speech and in text.
- The agent asks follow-up probes drawn from your chosen context and paired standard.
- Leave the interview at any point — answered questions are retained and the rest can be completed by multiple choice.
5.4 Step 4 — Risk appetite
For each of the eight categories — strategy & growth, financial, operational, compliance & regulatory, reputational, technology & cyber, people & culture, and safety & environment — set the appetite you take today and the appetite you believe you should take on a 1–5 scale. The distance between the two becomes the appetite gap heatmap.
5.5 Step 5 — Review and submit
Check the summary, then submit. Submitted responses become available to the Consultant lookup and to the multirater variance engine.
6. Multirater perception gap
The perception gap shows where Board, Operations and IT see the same organisation differently — often the fastest route to a real governance conversation.
- Open Multirater gap from the Dashboard and select the company (mandatory).
- Select or create the assessment the groups will complete.
- Invite the registered users in each rater group — only registered users can be invited.
- Each group completes the questionnaire independently; no group sees another group's answers.
- Once two or more groups have submitted, open the variance heatmap.
Reading the variance heatmap
- Each cell shows the spread between the highest and lowest group score for that question or clause.
- Low variance means aligned perception; high variance flags a blind spot or assurance gap.
- Select a cell to see each group's score side by side.
- Treat any clause with a two-point-or-greater spread as a priority discussion item.
7. Results, reports and benchmarking
On-screen results
- Overall readiness score and per-module scores.
- Radar chart across principles, framework and process.
- Appetite heatmap of current versus desired appetite.
- Industry benchmark comparison for your sector.
- Gap analysis table listing each shortfall against the relevant ISO 31000 clause.
- Prioritised 90-day roadmap of recommended actions.
Exporting
- Open the results view for the completed assessment.
- Choose Word for the formatted report or PDF for a print-ready version.
- On publish or download, a Word copy is emailed to the Commtac review addresses.
Consultant lookup of completed assessments
From the Dashboard, use Completed client assessments to filter by client organisation, search by title and open any assessment with at least one submitted response, including its results and variance heatmap.
8. Administration
User management
- Add, edit and delete users.
- Assign and change roles (Admin, Consultant, Company).
- Re-issue access for a user.
- An Admin cannot remove their own Admin role, which prevents lock-out.
Companies
- Create and edit company records, including contact details and staff.
- Assign one or many consultants to a company; assignees appear as badges on the record.
- Assignees must hold the Consultant or Admin role, or already manage that company.
Activity monitoring
The activity tab records sign-ins, assessment activity and administrative changes so you can see who did what and when.
9. Recommended end-to-end workflow
- Admin creates the Consultant account and assigns the Consultant role.
- Consultant creates the client company with contact details and staff, tagging Board, Operations and IT members.
- Consultant starts an assessment, selects the company and chooses the risk context.
- Client completes Modules A, B and C by multiple choice or AI interview.
- Client completes the risk appetite step.
- Consultant invites the Board, Operations and IT groups to answer independently.
- Consultant reviews scores, appetite heatmap, benchmarks and the variance heatmap.
- Consultant exports the Word gap report and 90-day roadmap and presents it to the client.
- Re-run the assessment after the roadmap period to evidence improvement.
10. Good-practice tips
- Agree the context before you start — changing it mid-assessment changes the probes.
- Score on evidence, not intent; note the document or system behind each score.
- Run the multirater exercise before the debrief so the gaps drive the agenda.
- Keep the roadmap to a small number of achievable actions per quarter.
- Reassess at least annually, and after any major change or incident.
11. Troubleshooting
| Symptom | What to do |
|---|---|
| “Which company is this assessment for?” keeps appearing | Every entry point is gated. Select an existing company or create one — an assessment cannot start without it. |
| Company user sees no data after signing in | The user has not been assigned to a company. An Admin or Consultant must assign them on the company record. |
| Cannot save a company assignment | Assignees must hold the Consultant or Admin role, or already manage that company. |
| Variance heatmap is empty | At least two rater groups must have submitted responses for the same assessment. |
| Voice interview will not record | Allow microphone access in the browser, then reload the page. |
| Report will not download | Disable pop-up blocking for the site and retry the Word or PDF export. |
12. Support
For help with Risk Navigator, contact Commtac Consult Ltd at tim@commtac.co or pete@commtac.co.
This guide describes functionality aligned to ISO 31000:2018 clauses 4, 5 and 6. ISO 31000 is a guidance standard and is not certifiable; references to other standards are for contextual detail only.