RiskReady 31000 documentation
Everything you need to run a readiness assessment and gap analysis based on ISO 31000:2018 — from setting up a client company to exporting the 90-day roadmap.
Risk Navigator is the assessment engine inside RiskReady 31000. It guides an organisation through a structured self-assessment of risk management maturity against ISO 31000:2018, then converts the answers into scores, heatmaps, benchmarks, a gap report and a 90-day action plan.
Access is role-based and a user may hold more than one role.
| Role | What they can do |
|---|---|
| Admin | Full platform control: create, edit and delete users, assign and change roles, manage companies and consultant assignments, monitor activity, open any assessment. |
| Consultant | Sets up client companies, runs assessments on their behalf, invites rater groups, reviews variance heatmaps, looks up completed client assessments and exports reports. |
| Company | Signed in against one assigned company only. Completes assessments and multirater questionnaires and views that company's results. |
| Rater groups (Board / Operations / IT) | Used for the multirater perception gap. Each group answers independently; answers are not shared until variance is calculated. |
Within a company, staff are tagged as Board, Operations or IT. This tagging drives the multirater perception gap and is set when staff are captured on the company record.
Every assessment belongs to a company. Consultants create and maintain company records; Admins can create them and reassign consultants at any time.
Company-role users can only sign in against the company assigned to them. Assign the company when you create the user, otherwise their workspace will be empty.
Wherever you start an assessment, this card appears first. Select an existing company or create a new one. Nothing starts until a company is chosen, which keeps every result, report and heatmap attached to the correct client.
Risk Navigator pairs ISO 31000 questions with the relevant supporting standard and adds context-specific probes.
| Context | Paired standard(s) | Typical focus |
|---|---|---|
| General Enterprise Risk Management | ISO 31000:2018 core | Whole-of-business risk programmes |
| Information Security | ISO/IEC 27001 / 27005 | ISMS risk assessment and treatment |
| Cyber Security | ISO/IEC 27001, NIST CSF | Threat-led cyber risk governance |
| Business Continuity / Resilience | ISO 22301 | BIA, RTO/RPO, disruption scenarios |
| Operational Risk | ISO 31000, Basel-style practice | Process, people and systems failure |
| Project / Portfolio Risk | ISO 21500 / PMBOK | Schedule, cost, scope, benefits |
| Health & Safety | ISO 45001 | Hazard identification, worker consultation |
| Environmental | ISO 14001 | Aspects, impacts, compliance obligations |
| Quality Management | ISO 9001 | Risk-based thinking in processes |
| Financial Risk | ISO 31000, IFRS practice | Credit, market, liquidity, capital |
| Supply Chain / Third Party | ISO 28000 / 27036 | Vendor concentration and dependency |
| ESG / Sustainability | ISO 26000, GRI | Climate, social and governance exposure |
| Data Privacy | ISO/IEC 27701, GDPR/POPIA | Lawful basis, DPIAs, subject rights |
| AI Governance | ISO/IEC 42001 | Model risk, bias, human oversight |
| Fraud & Financial Crime | ISO 37001, PCI DSS v4.0.1 | Bribery, fraud, card payment risk |
| Custom | Describe your own | Any context not listed above |
| Module | ISO 31000 clause | Coverage |
|---|---|---|
| Module A — Principles | Clause 4 | The 8 guiding principles: integrated, structured & comprehensive, customised, inclusive, dynamic, best available information, human & cultural factors, continual improvement. |
| Module B — Framework & Leadership | Clause 5 | Leadership and commitment, integration, design, implementation, evaluation and improvement of the framework. |
| Module C — Process | Clause 6 | Communication & consultation, scope/context/criteria, identification, analysis, evaluation, treatment, monitoring & review, recording & reporting. |
| Module D — Risk Appetite | Supporting | Current versus desired appetite across eight categories, producing the appetite gap heatmap. |
Each question offers a maturity level from 1 to 5. Choose the statement that best matches current practice and note the evidence you relied on.
| Score | Maturity level | Meaning |
|---|---|---|
| 1 | Initial / Ad hoc | No defined approach; reactive and person-dependent. |
| 2 | Developing | Some documentation, inconsistently applied. |
| 3 | Defined | Documented, approved and generally followed. |
| 4 | Managed | Measured, monitored and reported with evidence. |
| 5 | Optimising | Continually improved and embedded in decisions. |
For each of the eight categories — strategy & growth, financial, operational, compliance & regulatory, reputational, technology & cyber, people & culture, and safety & environment — set the appetite you take today and the appetite you believe you should take on a 1–5 scale. The distance between the two becomes the appetite gap heatmap.
Check the summary, then submit. Submitted responses become available to the Consultant lookup and to the multirater variance engine.
The perception gap shows where Board, Operations and IT see the same organisation differently — often the fastest route to a real governance conversation.
From the Dashboard, use Completed client assessments to filter by client organisation, search by title and open any assessment with at least one submitted response, including its results and variance heatmap.
The activity tab records sign-ins, assessment activity and administrative changes so you can see who did what and when.
| Symptom | What to do |
|---|---|
| “Which company is this assessment for?” keeps appearing | Every entry point is gated. Select an existing company or create one — an assessment cannot start without it. |
| Company user sees no data after signing in | The user has not been assigned to a company. An Admin or Consultant must assign them on the company record. |
| Cannot save a company assignment | Assignees must hold the Consultant or Admin role, or already manage that company. |
| Variance heatmap is empty | At least two rater groups must have submitted responses for the same assessment. |
| Voice interview will not record | Allow microphone access in the browser, then reload the page. |
| Report will not download | Disable pop-up blocking for the site and retry the Word or PDF export. |
For help with Risk Navigator, contact Commtac Consult Ltd at tim@commtac.co or pete@commtac.co.
This guide describes functionality aligned to ISO 31000:2018 clauses 4, 5 and 6. ISO 31000 is a guidance standard and is not certifiable; references to other standards are for contextual detail only.
← Back to RiskReady 31000