Skip to content
LokalMatch

Risk Consultants

Risk Consultants near you

A risk consultant helps an organisation work out what could stop it achieving its objectives, how bad that would be, and what is worth doing about it. The output is a framework rather than a document: a register of risks with named owners, an agreed way of rating them, decisions about which ones are being treated and which are being accepted deliberately, and a rhythm for revisiting all of it. Done properly it is unglamorous and quietly useful. Done badly it produces a colour-coded chart that nobody looks at again.

Tell us what you need and we’ll help you find risk consultants who serve your area.

Free for homeowners · No obligation to hire

On this page

The reference point for most of this work is ISO 31000, the international standard on risk management. It is worth knowing at the outset that ISO 31000 provides guidelines rather than requirements, and is not intended for certification purposes, which is deliberate: it leaves managers free to implement it in a way that suits their organisation. Business continuity is the neighbouring discipline and has its own standard, ISO 22301, which does set out requirements for a management system. Sector rules sit on top for some organisations, most notably the guidelines the Office of the Superintendent of Financial Institutions issues for federally regulated financial institutions. This guide is general information, not legal or financial advice.

What risk consultants are brought in to do

  • Enterprise risk frameworks: establishing how risks are identified, rated, owned and escalated across an organisation.
  • Risk assessments for a specific decision, project, site or supplier, rather than for the business as a whole.
  • Business continuity and disaster recovery planning, including business impact analysis and recovery priorities.
  • Operational and third-party risk work, covering the vendors and service providers a business depends on.
  • Controls design and testing, so that the mitigation recorded against a risk is actually in place and working.
  • Board and committee support: reporting risk in a form non-specialists can challenge and act on.

How a structured risk assessment is actually run

The sequence used by most practitioners follows the ISO 31000 pattern, and Public Safety Canada's risk management guide for critical infrastructure sectors, which states that it is adapted from that standard, sets it out in a form that is easy to follow. It starts with communication and consultation, because a risk assessment done to people rather than with them collects polite answers instead of real ones.

Establishing the context comes next: what the organisation actually does, which services and products matter most, and what it depends on to deliver them. Risk identification then builds a register of the threats and hazards that could affect those services, taking an all-hazards view that includes natural hazards, deliberate threats and accidental or technical failures. Risk analysis assesses likelihood and consequence, drawing on expert judgement and structured techniques rather than intuition alone.

Risk evaluation is where judgement becomes policy: risks are prioritised, typically into those that are intolerable, those worth weighing the cost of treatment against the benefit, and those that can reasonably be accepted. Treatment and monitoring follow, with mitigation strategies, implementation plans and exercises that test whether the treatment works. The loop closes through continuous improvement, capturing lessons after incidents. If a consultant's method skips the context stage and starts at a risk workshop, expect a generic register.

ISO 31000, ISO 22301 and sector rules: which applies to you

ISO 31000 is guidance. It gives principles and a framework for managing risk, and because it is not intended for certification there is no such thing as being certified to it. A consultant offering to certify your organisation against ISO 31000 has misunderstood the standard, or is hoping you have. What you can do is align your practice with it and have that alignment reviewed.

ISO 22301 is different in kind. It sets out requirements for a business continuity management system covering planning, implementation, operation, monitoring, review and improvement, and its requirements are generic and intended to apply to organisations of any type or size. Because it is written as requirements, it can be certified by an accredited certification body. ISO 22313 provides guidance on applying ISO 22301 for organisations that want the discipline without the certificate.

Sector obligations are the third layer, and they apply to far fewer organisations than the marketing around them suggests. OSFI's guidelines are directed at federally regulated financial institutions such as banks, foreign bank branches, insurers and trust and loan companies. If your business is not federally regulated, those guidelines are not rules you must follow, although they are often worth reading as a well-developed statement of practice. Other sectors carry their own regulators and their own expectations, so establish which regime genuinely binds you before buying a programme built for someone else's.

What OSFI expects of federally regulated financial institutions

Guideline E-21, Operational Risk Management and Resilience, was published in August 2024. It sets expectations for identifying, assessing, managing and monitoring operational risk, and for operational resilience: the ability to prepare for and recover from severe disruptive events, whether they arise from internal control failures, third-party disruption, infrastructure or technology failures, cyber incidents, pandemics or natural disasters. Its resilience expectations extend to business continuity risk management, crisis management, change management and data risk management. Adherence to the operational risk management expectations was immediate on publication, with the remaining expectations phased in and full implementation expected by 1 September 2026.

Guideline B-10, Third-Party Risk Management, covers the arrangements an institution has with outside parties and applies to all federally regulated financial institutions. It requires a third-party risk management framework, risk assessments proportionate to how critical an arrangement is, both before entering into it and periodically afterwards, written agreements setting out rights and responsibilities, monitoring and incident management, contingency and exit plans for critical arrangements, and attention to technology and cyber risk. The principle underneath it is that an institution keeps accountability for activities it has outsourced.

For everyone else, the useful part of these guidelines is structural rather than legal: the idea that resilience is defined around critical operations, that dependence on a supplier is a risk you still own, and that plans which have never been exercised are assumptions.

Business continuity: planning for the day something actually fails

Continuity planning starts by asking which activities the organisation cannot be without, and for how long. That business impact analysis drives everything else, because it decides what gets recovered first when resources are short. Without it, continuity plans tend to protect whatever the person writing them understood best.

The plan itself should be specific enough to be usable by someone having a bad day: who decides that the plan is active, who must be contacted, what the fallback arrangements are for premises, systems, data and key suppliers, and what the organisation will tell customers and staff. Crisis management and communication belong in it, because most reputational damage in a disruption comes from the silence rather than the fault.

Then it has to be exercised. Testing is what converts a document into a capability, and it reliably finds the dependencies nobody wrote down: the system only one person can restore, the supplier with no alternative, the contact list that was accurate two reorganisations ago. Exercises also give the people who would have to act a rehearsal before the real thing. A consultant who delivers a continuity plan but never proposes testing it has delivered half the engagement.

Why risk programmes fail to survive their first year

  • A register with no named owner for each risk, so nothing is anyone's job.
  • Ratings applied inconsistently, making the resulting priority order essentially arbitrary.
  • Controls recorded as mitigation without anyone checking that they exist and function.
  • A framework copied from a regulated sector that does not apply to the business at all.
  • Continuity plans that have never been exercised, so untested assumptions are discovered during the incident.
  • Risk reporting written for specialists, leaving the board unable to challenge anything in it.
  • Treating the consultant's final report as the deliverable, rather than the routine that keeps it current.

How risk engagements are scoped, and how LokalMatch requests reach consultants

Engagements are usually scoped by breadth and depth: how much of the organisation is in scope, how many sites, systems and third parties are involved, whether the work is a one-off assessment or the design of a framework somebody has to run afterwards, and whether continuity plans are to be written and exercised as well as drafted. Work driven by a regulator or a major customer's requirements tends to be tighter in scope because the requirements are written down. A proposal that does not distinguish between assessing risk once and building a capability that outlives the engagement is worth questioning.

On LokalMatch you describe the organisation, what triggered the enquiry, whether any regulator or customer requirement is driving it and whether you need an assessment or an ongoing framework, and risk consultants serving your area contact you directly. LokalMatch does not assess risk, does not certify management systems and does not vet, rank or recommend the consultants who reply; consultants pay for the requests they receive, so approaching several costs you nothing. Ask each of them who will operate the framework once they have gone, and how they propose to test whatever they produce.

Risk Consultants: frequently asked questions

Can my company be certified to ISO 31000?

No. ISO 31000 provides guidelines rather than requirements and is not intended for certification purposes. That is a deliberate design choice, giving organisations flexibility in how they apply it. You can align your risk management with the standard and have that alignment independently reviewed, but there is no certificate to hold.

What is the difference between ISO 31000 and ISO 22301?

ISO 31000 is broad guidance on managing risk of any kind. ISO 22301 sets out requirements for a business continuity management system, specifically about continuing and recovering operations through disruption. Because ISO 22301 is written as requirements, an accredited certification body can certify a management system against it.

Do OSFI's guidelines apply to my business?

Only if you are a federally regulated financial institution, such as a bank, a foreign bank branch, an insurer or a trust and loan company. Most businesses are not. OSFI's guidelines are still useful reading as a detailed statement of practice on operational resilience and third-party risk, but they are not obligations for organisations outside its remit.

Where should a business with no risk framework start?

With context rather than a risk workshop: what the organisation does, which services matter most and what it depends on to deliver them. From there identify threats against those services, analyse likelihood and consequence, and prioritise. Public Safety Canada's risk management guide, adapted from ISO 31000, sets out that sequence in an accessible form.

Is a risk assessment the same as a business continuity plan?

No. A risk assessment identifies and prioritises what could go wrong. A continuity plan says how the organisation keeps its critical activities running and recovers when something does. They connect through the business impact analysis, which establishes what cannot be without and for how long, but buying one does not give you the other.

How often should risks and continuity plans be reviewed?

Frequently enough that they reflect the organisation as it is now, and always after a significant change or an actual incident. Standards and regulator guidance consistently expect periodic reassessment, monitoring and exercising rather than a single exercise. Agree the review rhythm and who owns it before the consultant's engagement ends.

Sources

  1. ISO 31000:2018 Risk management — Guidelines
  2. ISO 22301:2019 Security and resilience — Business continuity management systems — Requirements
  3. OSFI: Backgrounder on Guideline E-21, Operational Risk and Resilience
  4. OSFI: Third-Party Risk Management Guideline (B-10)
  5. Public Safety Canada: Risk Management Guide for Critical Infrastructure Sectors

Written by the LokalMatch editorial team. Last reviewed September 14, 2026. How we write and check our guides

Find risk consultants by city

Nunavut

Show 1 cities

Ontario

Show 71 cities

Quebec

Show 74 cities

Yukon

Show 1 cities

What affects the fees risk consultants charge

Fees depend on the work involved and how the professional bills. We only publish fee ranges when they’re backed by real LokalMatch data or reliable sources. Until then, here’s what usually changes the fee:

  • Scope and complexity of the work
  • How the firm bills: hourly, per project or on a monthly retainer
  • Experience of the team
  • Timeline and how urgent the work is
  • Ongoing support after the work is delivered

How to compare risk consultants before you hire

  • Ask for examples of similar work for clients like you.
  • Read reviews and ask for references you can contact.
  • Make sure the scope, deliverables and timeline are written down before work starts.
  • Ask who will do the work: an in-house team, freelancers or subcontractors.
  • Compare two or three proposals before you decide.

Questions to ask risk consultants before you hire

  • Have you done work like this before, and can I see examples?
  • Who will work on this, and who is my main contact?
  • How do you charge: hourly, per project or monthly?
  • What is included, and what costs extra?
  • How long is the contract, and how can either side end it?
  • How will you report on progress?
  • Who owns the work, files and accounts you set up for me?

Licences and registration

This kind of work is often limited to licensed or registered professionals, and the rules depend on where you are. Ask which body they’re registered with, and check their status on that body’s public register before you hire.

Ready to contact risk consultants?

Tell us what you need in a few sentences.