Risk Professionals

Risk Professionals Provide consulting and training in Risk Management including ISO trainings.

Introducing our Virtual Chief Governance Officer service.Most organisations do not have a governance problem in any sing...
07/09/2026

Introducing our Virtual Chief Governance Officer service.

Most organisations do not have a governance problem in any single domain. They have a governance coordination problem across them. Cyber sits with the security team. AI sits with the technology team. Business resilience sits with operations. Each function reports upward through a different chain, uses a different risk taxonomy, and reaches the board through a different pack.

Boards end up seeing three parallel views of risk with no single line of sight across them.

Our vCGO service exists to fill that gap. A Virtual Chief Governance Officer provides senior governance leadership across cyber security, artificial intelligence, and business resilience, holding the frameworks together at the top rather than running each one in isolation.

The engagement covers the design and maturity of your governance frameworks, the policy set that sits underneath them, board-level reporting and KPIs that give directors a coherent view, and integrated risk oversight across all three domains. Where you already have a vCISO, vBRM, or internal function running in one of these areas, the vCGO coordinates above them rather than duplicating what they do.

The service suits organisations that are growing past the point where governance can sit informally across a few executives, boards that are receiving fragmented risk reporting and want a single lens, and regulated entities where governance obligations now span cyber, AI, and operational resilience simultaneously.

Learn more at riskprofs.com/virtual-chief-governance-officer or get in touch at [email protected].

Introducing our Virtual Business Resilience Manager service.Disruption is no longer a rare event that organisations plan...
06/09/2026

Introducing our Virtual Business Resilience Manager service.
Disruption is no longer a rare event that organisations plan for once and file away. Cyber incidents, supplier failures, extreme weather, and regulatory shocks are now a normal part of the operating environment. What separates the organisations that recover from the ones that struggle is whether their resilience capability was built before it was needed.
Our vBRM service provides senior business continuity leadership on a fractional basis, giving your organisation access to the expertise required to build, run, and continually improve a business resilience programme without a full-time executive hire.

The engagement typically covers business impact analysis, business continuity policy and plan development, disaster recovery planning and testing, crisis management framework design, and the exercise and testing programme that keeps everything current. It is aligned to ISO 22301 for organisations pursuing certification, and shaped to the maturity and regulatory environment of each client.

The service suits organisations pursuing ISO 22301 certification, businesses with critical operations that need continuity assurance, regulated entities with resilience obligations under frameworks such as APRA CPS 230, and organisations that are either recovering from a disruption or preparing for one.

Learn more at riskprofs.com/virtual-business-resilience-manager or get in touch at [email protected].

Introducing our Virtual Business Resilience Manager service.Disruption is no longer a rare event that organisations plan...
06/09/2026

Introducing our Virtual Business Resilience Manager service.

Disruption is no longer a rare event that organisations plan for once and file away. Cyber incidents, supplier failures, extreme weather, and regulatory shocks are now a normal part of the operating environment. What separates the organisations that recover from the ones that struggle is whether their resilience capability was built before it was needed.

Our vBRM service provides senior business continuity leadership on a fractional basis, giving your organisation access to the expertise required to build, run, and continually improve a business resilience programme without a full-time executive hire.
The engagement typically covers business impact analysis, business continuity policy and plan development, disaster recovery planning and testing, crisis management framework design, and the exercise and testing programme that keeps everything current. It is aligned to ISO 22301 for organisations pursuing certification, and shaped to the maturity and regulatory environment of each client.

The service suits organisations pursuing ISO 22301 certification, businesses with critical operations that need continuity assurance, regulated entities with resilience obligations under frameworks such as APRA CPS 230, and organisations that are either recovering from a disruption or preparing for one.
Learn more at riskprofs.com/virtual-business-resilience-manager or get in touch at [email protected].

Our vCISO service is available for engagements starting this quarter.A Virtual Chief Information Security Officer gives ...
03/09/2026

Our vCISO service is available for engagements starting this quarter.

A Virtual Chief Information Security Officer gives your organisation the strategic security leadership of a CISO without the cost of a full-time executive hire. We take ownership of information security strategy, sit across governance and risk oversight, lead incident response when it happens, and report to your board on the things they need to hear.

Common reasons organisations engage us on a vCISO basis:

You are pursuing ISO 27001 certification and need someone to own the ISMS end to end.

You have grown past the point where security can sit in someone's side-of-desk portfolio, but a full CISO hire is 12 months away.
You handle sensitive data or operate in a regulated sector, and your board is starting to ask harder questions than your current team can answer.
You have had an incident, a near miss, or an audit finding that made clear the gap in senior security oversight.

Engagements are scoped to what your organisation actually needs, from a few days a month for governance oversight through to deeper involvement during a certification programme or post-incident recovery.
Learn more at riskprofs.com/virtual-chief-information-security-officer or get in touch at [email protected].

The PECB ISO 22301 Lead Implementer training course.Five days of structured content covering the establishment, implemen...
02/09/2026

The PECB ISO 22301 Lead Implementer training course.

Five days of structured content covering the establishment, implementation, operation, and continual improvement of a Business Continuity Management System aligned to ISO 22301.

The course draws on the full family of resilience standards. ISO 22301 for the BCMS requirements themselves. ISO 22313 for practical guidance on applying them. ISO/TS 22317 for the business impact analysis methodology that sits underneath any credible BCMS.

Included in the course fee: 31 CPD credits, over 450 pages of course material, and the PECB certification exam with two attempts.
From US$599. Self-paced delivery.

Enroll at riskprofs.com/pecb-trainings.

Three terms every risk framework uses. Three terms most people muddle up in practice.Risk appetite, risk tolerance, and ...
01/09/2026

Three terms every risk framework uses. Three terms most people muddle up in practice.

Risk appetite, risk tolerance, and risk capacity all appear on the same page in most ERM policies. Executives use them interchangeably. Board papers switch between them without noticing. And every so often, someone gets asked to explain the difference in a meeting and struggles.

Here is what each one actually means.

Appetite is what the board is willing to take on. It is a choice, expressed as a target posture. Some organizations state it in words: we accept moderate operational risk in exchange for growth. Others express it numerically: we set an operating risk exposure of X.

Tolerance is the room around that target. The acceptable range before management has to escalate or intervene. If appetite is a 5% error rate, tolerance might allow up to 8% in a given month before someone is required to act.

Capacity is what would break you. The maximum exposure your balance sheet, operating model, or regulatory position could absorb before real damage is done. Capacity is a fact of the organization, not a choice.

The three sit inside one another. Capacity is the outer boundary. Appetite is set inside capacity, chosen deliberately. Tolerance is set around appetite, defining the operational range.

Confuse them and things go sideways slowly. Set appetite equal to capacity and you have an organization willing to bet everything it could theoretically survive. Set tolerance too wide and you drift toward the boundary without noticing. Neither shows up in a monthly report. Both eventually show up in a board pack.

If you have a risk framework document that quietly uses these interchangeably, it is worth fixing before your next audit.

Risk Professionals is a PECB Authorized Platinum Partner. We support risk framework development, ISO 31000 alignment, and board risk governance for clients across the globe.

Certification is the beginning of the work, not the end of it.The audit proves you had a management system on the day th...
31/08/2026

Certification is the beginning of the work, not the end of it.

The audit proves you had a management system on the day the auditor visited. Sustained conformance proves you still do six months later, twelve months later, and at every surveillance visit that follows.

This is where many programmes quietly lose momentum. The certificate arrives. The consultants leave. The project team disbands. The Statement of Applicability stops being updated. The risk register goes untouched between audits. Internal audits become a compliance exercise rather than a source of genuine assurance. Management reviews start noting things rather than deciding them.

Then the surveillance audit arrives, and the gaps that have accumulated over twelve months are visible in a single week.

A management system that only performs during an audit is not a management system. It is a rehearsed demonstration. Auditors have seen enough of both to tell the difference within the first hour.

The organizations that sustain their certifications well share a few common practices. They treat internal audit as a source of intelligence, not just an assurance activity. They review the Statement of Applicability whenever the risk landscape or the control environment materially changes, not only when an external audit is approaching. They maintain a management review cadence that produces decisions rather than acknowledgements. And they resource the management system as an operating function, not a project that ended at Stage 2.

Risk Professionals is a PECB Authorized Platinum Partner delivering ISO management system implementation, internal audit, and post-certification support to clients globally.

Australia’s AI Regulation: What’s Changing?At the National Cabinet meeting on 26 August 2026, Australia’s First Minister...
31/08/2026

Australia’s AI Regulation: What’s Changing?

At the National Cabinet meeting on 26 August 2026, Australia’s First Ministers formally endorsed the “AI laws in Australia’s Interests” framework.

The initial focus is large data centres, with nationally consistent standards for:

• Energy use
• Water use
• Land use
• Conditions on AI training

Commonwealth legislation is targeted for early 2027.

Importantly, this framework focuses on the infrastructure layer of AI not application-level AI risk regulation like the EU AI Act.

For organisations operating AI in Australia, it’s time to start preparing for upcoming compliance requirements.

Risk Professionals supports organisations with AI governance, ISO/IEC 42001 implementation, and EU AI Act readiness globally.

At the National Cabinet meeting held in Sydney on 26 August 2026, First Ministers confirmed Australia's national artific...
30/08/2026

At the National Cabinet meeting held in Sydney on 26 August 2026, First Ministers confirmed Australia's national artificial intelligence regulatory framework, titled AI laws in Australia's Interests.

The framework had been announced by the Prime Minister on 15 July 2026 and has now been formally endorsed by every state and territory leader. Commonwealth legislation is targeted for early 2027.

What the framework covers.

The initial focus is large data centres. First Ministers agreed that the material energy, water, and land-use impacts of these facilities need to be managed through nationally consistent standards. The framework will set minimum requirements across these three areas and will include conditions on delivering AI training.

Commonwealth legislation is designed to complement, not duplicate, existing state and territory planning and approval processes. The Commonwealth will work with state and territory governments to develop the consistent mandatory standards.

The stated purpose is threefold. To capture the generational opportunity artificial intelligence represents for Australia. To share the benefits across the economy. To keep Australians safe.

What it means for organizations tracking Australian AI regulation.

This is an infrastructure-level framework. It regulates the physical layer of Australia's AI ecosystem, being the facilities that host and train large-scale AI systems, and the resources those facilities consume. It is a distinct regulatory model from the European Union's AI Act, which focuses on classifying and regulating AI use cases by risk category.

Application-level regulation of AI systems in Australia, comparable in scope to the EU AI Act, remains a separate policy conversation. The current framework does not address it directly.

For organisations building, hosting, or deploying AI in Australia, three implications are worth noting.

First, large data centre operators should begin preparing for new energy, water, and land-use compliance obligations. The mandatory standards are still to be developed, but the direction is now clear.

Second, providers of AI training will face new conditions attached to that delivery. The detail will emerge in the legislative drafting.

Third, application-level AI governance obligations, whether under a future Australian framework or through extraterritorial application of the EU AI Act, remain a live consideration for organisations operating AI systems.

Risk Professionals is a PECB Authorised Platinum Partner delivering AI governance, ISO 42001 implementation, and EU AI Act readiness support to clients globally.

ISO 9001:2026 will be published on 16 September 2026, replacing ISO 9001:2015 as the current edition of the world's most...
27/08/2026

ISO 9001:2026 will be published on 16 September 2026, replacing ISO 9001:2015 as the current edition of the world's most widely adopted management system standard.

The sixth edition of ISO 9001 is an evolutionary refresh. The clause structure, the process approach, the Plan-Do-Check-Act cycle, and risk-based thinking all remain. What has changed is targeted.

Five key updates:
Quality culture and ethical behaviour are now embedded within Clause 5.1, Leadership and commitment. Organizations will be expected to demonstrate how leadership actively promotes both.

Climate change is formally integrated across the standard, building on the 2024 amendment that first introduced climate considerations into ISO management system standards.

Risk and opportunity management under Clause 6.1 has been restructured for clarity, reflecting how the discipline has evolved since 2015.

A guidance Annex A has been added. This is a first for ISO 9001. It is non-binding but provides practical explanation of the requirements, which certified organizations and auditors alike are expected to find useful.

Awareness and training under Clause 7.3 has been expanded to reflect the new emphases on quality culture, ethical behaviour, and climate.

A three-year transition period begins on the publication date and ends in September 2029. Existing ISO 9001:2015 certifications remain valid throughout that period, so certified organizations have time to plan their transition around a surveillance or recertification audit.

Risk Professionals is a PECB Authorized Platinum Partner delivering ISO management system implementation and transition support to clients globally.

Address

Level 3, 478 George Street
Sydney, NSW
2570

Alerts

Be the first to know and let us send you an email when Risk Professionals posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Risk Professionals:

Shortcuts

Share