Risk Consultants
Risk Consultants near you
A risk consultant helps an organisation work out what could stop it achieving its objectives, how bad that would be, and what is worth doing about it. The output is a framework rather than a document: a register of risks with named owners, an agreed way of rating them, decisions about which ones are being treated and which are being accepted deliberately, and a rhythm for revisiting all of it. Done properly it is unglamorous and quietly useful. Done badly it produces a colour-coded chart that nobody looks at again.
Tell us what you need and we’ll help you find risk consultants who serve your area.
Free for homeowners · No obligation to hire
On this page
The reference point for most of this work is ISO 31000, the international standard on risk management. It is worth knowing at the outset that ISO 31000 provides guidelines rather than requirements, and is not intended for certification purposes, which is deliberate: it leaves managers free to implement it in a way that suits their organisation. Business continuity is the neighbouring discipline and has its own standard, ISO 22301, which does set out requirements for a management system. Sector rules sit on top for some organisations, most notably the guidelines the Office of the Superintendent of Financial Institutions issues for federally regulated financial institutions. This guide is general information, not legal or financial advice.
What risk consultants are brought in to do
- Enterprise risk frameworks: establishing how risks are identified, rated, owned and escalated across an organisation.
- Risk assessments for a specific decision, project, site or supplier, rather than for the business as a whole.
- Business continuity and disaster recovery planning, including business impact analysis and recovery priorities.
- Operational and third-party risk work, covering the vendors and service providers a business depends on.
- Controls design and testing, so that the mitigation recorded against a risk is actually in place and working.
- Board and committee support: reporting risk in a form non-specialists can challenge and act on.
How a structured risk assessment is actually run
The sequence used by most practitioners follows the ISO 31000 pattern, and Public Safety Canada's risk management guide for critical infrastructure sectors, which states that it is adapted from that standard, sets it out in a form that is easy to follow. It starts with communication and consultation, because a risk assessment done to people rather than with them collects polite answers instead of real ones.
Establishing the context comes next: what the organisation actually does, which services and products matter most, and what it depends on to deliver them. Risk identification then builds a register of the threats and hazards that could affect those services, taking an all-hazards view that includes natural hazards, deliberate threats and accidental or technical failures. Risk analysis assesses likelihood and consequence, drawing on expert judgement and structured techniques rather than intuition alone.
Risk evaluation is where judgement becomes policy: risks are prioritised, typically into those that are intolerable, those worth weighing the cost of treatment against the benefit, and those that can reasonably be accepted. Treatment and monitoring follow, with mitigation strategies, implementation plans and exercises that test whether the treatment works. The loop closes through continuous improvement, capturing lessons after incidents. If a consultant's method skips the context stage and starts at a risk workshop, expect a generic register.
ISO 31000, ISO 22301 and sector rules: which applies to you
ISO 31000 is guidance. It gives principles and a framework for managing risk, and because it is not intended for certification there is no such thing as being certified to it. A consultant offering to certify your organisation against ISO 31000 has misunderstood the standard, or is hoping you have. What you can do is align your practice with it and have that alignment reviewed.
ISO 22301 is different in kind. It sets out requirements for a business continuity management system covering planning, implementation, operation, monitoring, review and improvement, and its requirements are generic and intended to apply to organisations of any type or size. Because it is written as requirements, it can be certified by an accredited certification body. ISO 22313 provides guidance on applying ISO 22301 for organisations that want the discipline without the certificate.
Sector obligations are the third layer, and they apply to far fewer organisations than the marketing around them suggests. OSFI's guidelines are directed at federally regulated financial institutions such as banks, foreign bank branches, insurers and trust and loan companies. If your business is not federally regulated, those guidelines are not rules you must follow, although they are often worth reading as a well-developed statement of practice. Other sectors carry their own regulators and their own expectations, so establish which regime genuinely binds you before buying a programme built for someone else's.
What OSFI expects of federally regulated financial institutions
Guideline E-21, Operational Risk Management and Resilience, was published in August 2024. It sets expectations for identifying, assessing, managing and monitoring operational risk, and for operational resilience: the ability to prepare for and recover from severe disruptive events, whether they arise from internal control failures, third-party disruption, infrastructure or technology failures, cyber incidents, pandemics or natural disasters. Its resilience expectations extend to business continuity risk management, crisis management, change management and data risk management. Adherence to the operational risk management expectations was immediate on publication, with the remaining expectations phased in and full implementation expected by 1 September 2026.
Guideline B-10, Third-Party Risk Management, covers the arrangements an institution has with outside parties and applies to all federally regulated financial institutions. It requires a third-party risk management framework, risk assessments proportionate to how critical an arrangement is, both before entering into it and periodically afterwards, written agreements setting out rights and responsibilities, monitoring and incident management, contingency and exit plans for critical arrangements, and attention to technology and cyber risk. The principle underneath it is that an institution keeps accountability for activities it has outsourced.
For everyone else, the useful part of these guidelines is structural rather than legal: the idea that resilience is defined around critical operations, that dependence on a supplier is a risk you still own, and that plans which have never been exercised are assumptions.
Business continuity: planning for the day something actually fails
Continuity planning starts by asking which activities the organisation cannot be without, and for how long. That business impact analysis drives everything else, because it decides what gets recovered first when resources are short. Without it, continuity plans tend to protect whatever the person writing them understood best.
The plan itself should be specific enough to be usable by someone having a bad day: who decides that the plan is active, who must be contacted, what the fallback arrangements are for premises, systems, data and key suppliers, and what the organisation will tell customers and staff. Crisis management and communication belong in it, because most reputational damage in a disruption comes from the silence rather than the fault.
Then it has to be exercised. Testing is what converts a document into a capability, and it reliably finds the dependencies nobody wrote down: the system only one person can restore, the supplier with no alternative, the contact list that was accurate two reorganisations ago. Exercises also give the people who would have to act a rehearsal before the real thing. A consultant who delivers a continuity plan but never proposes testing it has delivered half the engagement.
Why risk programmes fail to survive their first year
- A register with no named owner for each risk, so nothing is anyone's job.
- Ratings applied inconsistently, making the resulting priority order essentially arbitrary.
- Controls recorded as mitigation without anyone checking that they exist and function.
- A framework copied from a regulated sector that does not apply to the business at all.
- Continuity plans that have never been exercised, so untested assumptions are discovered during the incident.
- Risk reporting written for specialists, leaving the board unable to challenge anything in it.
- Treating the consultant's final report as the deliverable, rather than the routine that keeps it current.
How risk engagements are scoped, and how LokalMatch requests reach consultants
Engagements are usually scoped by breadth and depth: how much of the organisation is in scope, how many sites, systems and third parties are involved, whether the work is a one-off assessment or the design of a framework somebody has to run afterwards, and whether continuity plans are to be written and exercised as well as drafted. Work driven by a regulator or a major customer's requirements tends to be tighter in scope because the requirements are written down. A proposal that does not distinguish between assessing risk once and building a capability that outlives the engagement is worth questioning.
On LokalMatch you describe the organisation, what triggered the enquiry, whether any regulator or customer requirement is driving it and whether you need an assessment or an ongoing framework, and risk consultants serving your area contact you directly. LokalMatch does not assess risk, does not certify management systems and does not vet, rank or recommend the consultants who reply; consultants pay for the requests they receive, so approaching several costs you nothing. Ask each of them who will operate the framework once they have gone, and how they propose to test whatever they produce.
Risk Consultants: frequently asked questions
Can my company be certified to ISO 31000?
No. ISO 31000 provides guidelines rather than requirements and is not intended for certification purposes. That is a deliberate design choice, giving organisations flexibility in how they apply it. You can align your risk management with the standard and have that alignment independently reviewed, but there is no certificate to hold.
What is the difference between ISO 31000 and ISO 22301?
ISO 31000 is broad guidance on managing risk of any kind. ISO 22301 sets out requirements for a business continuity management system, specifically about continuing and recovering operations through disruption. Because ISO 22301 is written as requirements, an accredited certification body can certify a management system against it.
Do OSFI's guidelines apply to my business?
Only if you are a federally regulated financial institution, such as a bank, a foreign bank branch, an insurer or a trust and loan company. Most businesses are not. OSFI's guidelines are still useful reading as a detailed statement of practice on operational resilience and third-party risk, but they are not obligations for organisations outside its remit.
Where should a business with no risk framework start?
With context rather than a risk workshop: what the organisation does, which services matter most and what it depends on to deliver them. From there identify threats against those services, analyse likelihood and consequence, and prioritise. Public Safety Canada's risk management guide, adapted from ISO 31000, sets out that sequence in an accessible form.
Is a risk assessment the same as a business continuity plan?
No. A risk assessment identifies and prioritises what could go wrong. A continuity plan says how the organisation keeps its critical activities running and recovers when something does. They connect through the business impact analysis, which establishes what cannot be without and for how long, but buying one does not give you the other.
How often should risks and continuity plans be reviewed?
Frequently enough that they reflect the organisation as it is now, and always after a significant change or an actual incident. Standards and regulator guidance consistently expect periodic reassessment, monitoring and exercising rather than a single exercise. Agree the review rhythm and who owns it before the consultant's engagement ends.
Sources
- ISO 31000:2018 Risk management — Guidelines
- ISO 22301:2019 Security and resilience — Business continuity management systems — Requirements
- OSFI: Backgrounder on Guideline E-21, Operational Risk and Resilience
- OSFI: Third-Party Risk Management Guideline (B-10)
- Public Safety Canada: Risk Management Guide for Critical Infrastructure Sectors
Written by the LokalMatch editorial team. Last reviewed September 14, 2026. How we write and check our guides
Find risk consultants by city
Alberta
Show 17 citiesHide cities
- Risk Consultants in Calgary
- Risk Consultants in Edmonton
- Risk Consultants in Airdrie
- Risk Consultants in Cochrane
- Risk Consultants in Fort McMurray
- Risk Consultants in Fort Saskatchewan
- Risk Consultants in Grande Prairie
- Risk Consultants in Leduc
- Risk Consultants in Lethbridge
- Risk Consultants in Medicine Hat
- Risk Consultants in Okotoks
- Risk Consultants in Parkland County
- Risk Consultants in Red Deer
- Risk Consultants in Rocky View County
- Risk Consultants in Spruce Grove
- Risk Consultants in St. Albert
- Risk Consultants in Strathcona County
British Columbia
Show 31 citiesHide cities
- Risk Consultants in Abbotsford
- Risk Consultants in Burnaby
- Risk Consultants in Kelowna
- Risk Consultants in Surrey
- Risk Consultants in Vancouver
- Risk Consultants in Victoria
- Risk Consultants in Campbell River
- Risk Consultants in Chilliwack
- Risk Consultants in Coquitlam
- Risk Consultants in Courtenay
- Risk Consultants in Delta
- Risk Consultants in District of North Vancouver
- Risk Consultants in Kamloops
- Risk Consultants in Langford
- Risk Consultants in Langley
- Risk Consultants in Maple Ridge
- Risk Consultants in Mission
- Risk Consultants in Nanaimo
- Risk Consultants in New Westminster
- Risk Consultants in North Cowichan
- Risk Consultants in North Vancouver
- Risk Consultants in Penticton
- Risk Consultants in Port Coquitlam
- Risk Consultants in Port Moody
- Risk Consultants in Prince George
- Risk Consultants in Richmond
- Risk Consultants in Saanich
- Risk Consultants in Township of Langley
- Risk Consultants in Vernon
- Risk Consultants in West Kelowna
- Risk Consultants in West Vancouver
Manitoba
Show 2 citiesHide cities
New Brunswick
Show 4 citiesHide cities
Newfoundland and Labrador
Show 2 citiesHide cities
Northwest Territories
Show 1 citiesHide cities
Nova Scotia
Show 4 citiesHide cities
Nunavut
Show 1 citiesHide cities
Ontario
Show 71 citiesHide cities
- Risk Consultants in Barrie
- Risk Consultants in Brampton
- Risk Consultants in Greater Sudbury
- Risk Consultants in Guelph
- Risk Consultants in Hamilton
- Risk Consultants in Kingston
- Risk Consultants in Kitchener
- Risk Consultants in London
- Risk Consultants in Markham
- Risk Consultants in Mississauga
- Risk Consultants in Oshawa
- Risk Consultants in Ottawa
- Risk Consultants in St. Catharines
- Risk Consultants in Toronto
- Risk Consultants in Vaughan
- Risk Consultants in Waterloo
- Risk Consultants in Windsor
- Risk Consultants in Ajax
- Risk Consultants in Aurora
- Risk Consultants in Belleville
- Risk Consultants in Blue Mountains
- Risk Consultants in Bradford
- Risk Consultants in Brantford
- Risk Consultants in Burlington
- Risk Consultants in Caledon
- Risk Consultants in Cambridge
- Risk Consultants in Centre Wellington
- Risk Consultants in Chatham
- Risk Consultants in Clarence-Rockland
- Risk Consultants in Clarington
- Risk Consultants in Collingwood
- Risk Consultants in Cornwall
- Risk Consultants in County of Brant
- Risk Consultants in East Gwillimbury
- Risk Consultants in Fort Erie
- Risk Consultants in Georgetown
- Risk Consultants in Georgina
- Risk Consultants in Grimsby
- Risk Consultants in Haldimand County
- Risk Consultants in Innisfil
- Risk Consultants in Kawartha Lakes
- Risk Consultants in King
- Risk Consultants in Lakeshore
- Risk Consultants in LaSalle
- Risk Consultants in Leamington
- Risk Consultants in Lincoln
- Risk Consultants in Milton
- Risk Consultants in New Tecumseth
- Risk Consultants in Newmarket
- Risk Consultants in Niagara Falls
- Risk Consultants in Norfolk County
- Risk Consultants in North Bay
- Risk Consultants in Oakville
- Risk Consultants in Orangeville
- Risk Consultants in Orillia
- Risk Consultants in Peterborough
- Risk Consultants in Pickering
- Risk Consultants in Prince Edward County
- Risk Consultants in Quinte West
- Risk Consultants in Richmond Hill
- Risk Consultants in Sarnia
- Risk Consultants in Sault Ste. Marie
- Risk Consultants in St. Thomas
- Risk Consultants in Stratford
- Risk Consultants in Thunder Bay
- Risk Consultants in Timmins
- Risk Consultants in Welland
- Risk Consultants in Whitby
- Risk Consultants in Whitchurch-Stouffville
- Risk Consultants in Woodstock
- Risk Consultants in Woolwich
Prince Edward Island
Show 1 citiesHide cities
Quebec
Show 74 citiesHide cities
- Risk Consultants in Gatineau
- Risk Consultants in Laval
- Risk Consultants in Longueuil
- Risk Consultants in Montreal
- Risk Consultants in Quebec City
- Risk Consultants in Sherbrooke
- Risk Consultants in Trois-Rivières
- Risk Consultants in Alma
- Risk Consultants in Baie-Comeau
- Risk Consultants in Beaconsfield
- Risk Consultants in Beloeil
- Risk Consultants in Blainville
- Risk Consultants in Boisbriand
- Risk Consultants in Boucherville
- Risk Consultants in Brossard
- Risk Consultants in Candiac
- Risk Consultants in Chambly
- Risk Consultants in Châteauguay
- Risk Consultants in Côte-Saint-Luc
- Risk Consultants in Cowansville
- Risk Consultants in Deux-Montagnes
- Risk Consultants in Dollard-des-Ormeaux
- Risk Consultants in Dorval
- Risk Consultants in Drummondville
- Risk Consultants in Gaspé
- Risk Consultants in Granby
- Risk Consultants in Joliette
- Risk Consultants in Kirkland
- Risk Consultants in L'Ancienne-Lorette
- Risk Consultants in L'Assomption
- Risk Consultants in La Prairie
- Risk Consultants in Lévis
- Risk Consultants in Magog
- Risk Consultants in Mascouche
- Risk Consultants in Mirabel
- Risk Consultants in Mont-Saint-Hilaire
- Risk Consultants in Mount Royal
- Risk Consultants in Pointe-Claire
- Risk Consultants in Repentigny
- Risk Consultants in Rimouski
- Risk Consultants in Rivière-du-Loup
- Risk Consultants in Rouyn-Noranda
- Risk Consultants in Saguenay
- Risk Consultants in Saint-Augustin-de-Desmaures
- Risk Consultants in Saint-Basile-le-Grand
- Risk Consultants in Saint-Bruno-de-Montarville
- Risk Consultants in Saint-Charles-Borromée
- Risk Consultants in Saint-Colomban
- Risk Consultants in Saint-Constant
- Risk Consultants in Saint-Eustache
- Risk Consultants in Saint-Georges
- Risk Consultants in Saint-Hyacinthe
- Risk Consultants in Saint-Jean-sur-Richelieu
- Risk Consultants in Saint-Jérôme
- Risk Consultants in Saint-Lambert
- Risk Consultants in Saint-Lazare
- Risk Consultants in Saint-Lin–Laurentides
- Risk Consultants in Sainte-Anne-des-Plaines
- Risk Consultants in Sainte-Catherine
- Risk Consultants in Sainte-Julie
- Risk Consultants in Sainte-Marthe-sur-le-Lac
- Risk Consultants in Sainte-Sophie
- Risk Consultants in Sainte-Thérèse
- Risk Consultants in Salaberry-de-Valleyfield
- Risk Consultants in Sept-Îles
- Risk Consultants in Shawinigan
- Risk Consultants in Sorel-Tracy
- Risk Consultants in Terrebonne
- Risk Consultants in Thetford Mines
- Risk Consultants in Val-d'Or
- Risk Consultants in Varennes
- Risk Consultants in Vaudreuil-Dorion
- Risk Consultants in Victoriaville
- Risk Consultants in Westmount
Saskatchewan
Show 4 citiesHide cities
Yukon
Show 1 citiesHide cities
What affects the fees risk consultants charge
Fees depend on the work involved and how the professional bills. We only publish fee ranges when they’re backed by real LokalMatch data or reliable sources. Until then, here’s what usually changes the fee:
- Scope and complexity of the work
- How the firm bills: hourly, per project or on a monthly retainer
- Experience of the team
- Timeline and how urgent the work is
- Ongoing support after the work is delivered
How to compare risk consultants before you hire
- Ask for examples of similar work for clients like you.
- Read reviews and ask for references you can contact.
- Make sure the scope, deliverables and timeline are written down before work starts.
- Ask who will do the work: an in-house team, freelancers or subcontractors.
- Compare two or three proposals before you decide.
Questions to ask risk consultants before you hire
- Have you done work like this before, and can I see examples?
- Who will work on this, and who is my main contact?
- How do you charge: hourly, per project or monthly?
- What is included, and what costs extra?
- How long is the contract, and how can either side end it?
- How will you report on progress?
- Who owns the work, files and accounts you set up for me?
Licences and registration
This kind of work is often limited to licensed or registered professionals, and the rules depend on where you are. Ask which body they’re registered with, and check their status on that body’s public register before you hire.
Guides about risk management
- ✦
Environmental Consultants guide
An environmental consultant investigates whether a property or an operation carries contamination or regulatory exposure, and records the answer in a form a lender, a buyer, a municipality or a ministry will accept.
Read guide - ✦
Sustainability Consultants guide
A sustainability consultant helps an organisation measure its environmental performance, report it in a recognised format, and say something about it in public without breaking the law.
Read guide - ✦
ISO Consultants guide
An ISO consultant helps an organisation build a management system that meets the requirements of a published standard, and prepares it for the audit that leads to certification.
Read guide
Related professional services
Ready to contact risk consultants?
Tell us what you need in a few sentences.