"The structure, the practice exams, the instructor — all top tier. Passed first try."
Course Outline
What the programme covers, module by module.
Module 1: Introduction to ISO 31000
- Purpose of ISO 31000
- Risk management fundamentals
- Scope and application
- Key terminology
- Organisational relevance
- Implementation perspective
Module 2: Understanding Risk and Uncertainty
- Definition of risk
- Sources of uncertainty
- Opportunities and threats
- Causes and consequences
- Risk exposure
- Organisational risk environment
Module 3: ISO 31000 Risk Management Principles
- Integrated approach
- Structured and comprehensive approach
- Customised approach
- Inclusive risk management
- Dynamic risk management
- Continual improvement
Module 4: Risk Management Framework
- Framework purpose
- Leadership and commitment
- Integration
- Framework design
- Implementation
- Evaluation and improvement
Module 5: Planning the Implementation
- Implementation objectives
- Current-state assessment
- Implementation scope
- Key activities
- Responsibilities
- Implementation roadmap
Module 6: Organisational Context
- Internal context
- External context
- Business environment
- Strategic objectives
- Organisational capabilities
- Context analysis
Module 7: Interested Parties and Stakeholders
- Stakeholder identification
- Stakeholder expectations
- Internal stakeholders
- External stakeholders
- Consultation requirements
- Stakeholder engagement
Module 8: Leadership and Commitment
- Leadership responsibilities
- Management commitment
- Strategic alignment
- Resource allocation
- Accountability
- Leadership involvement
Module 9: Risk Governance
- Governance structures
- Oversight responsibilities
- Decision authority
- Risk ownership
- Accountability
- Escalation arrangements
Module 10: Developing Risk Management Policy
- Policy purpose
- Organisational commitments
- Roles and responsibilities
- Policy communication
- Policy implementation
- Policy review
Module 11: Defining Risk Appetite and Tolerance
- Risk appetite concepts
- Risk tolerance
- Risk capacity
- Decision boundaries
- Escalation thresholds
- Organisational alignment
Module 12: Establishing Risk Criteria
- Risk criteria
- Likelihood criteria
- Consequence criteria
- Risk levels
- Acceptability criteria
- Evaluation thresholds
Module 13: Designing the Risk Management Process
- Process structure
- Scope and context
- Risk assessment
- Risk treatment
- Monitoring
- Communication and consultation
Module 14: Risk Identification
- Risk sources
- Events
- Causes
- Consequences
- Emerging risks
- Identification techniques
Module 15: Risk Analysis
- Likelihood assessment
- Consequence assessment
- Existing controls
- Risk levels
- Qualitative analysis
- Quantitative concepts
Module 16: Risk Evaluation
- Comparing risks with criteria
- Risk prioritisation
- Risk significance
- Risk acceptance
- Escalation
- Decision-making
Module 17: Risk Treatment
- Treatment objectives
- Avoiding risk
- Reducing risk
- Sharing risk
- Accepting risk
- Treatment planning
Module 18: Designing Risk Controls
- Preventive controls
- Detective controls
- Corrective controls
- Control ownership
- Control design
- Control documentation
Module 19: Evaluating Control Effectiveness
- Control implementation
- Control testing
- Control effectiveness
- Control weaknesses
- Residual risk
- Improvement actions
Module 20: Developing Risk Registers
- Risk descriptions
- Risk categories
- Risk ratings
- Risk ownership
- Existing controls
- Treatment actions
Module 21: Risk Treatment Plans
- Treatment actions
- Responsibilities
- Resources
- Target dates
- Performance measures
- Progress tracking
Module 22: Communication and Consultation
- Communication planning
- Internal communication
- External communication
- Stakeholder consultation
- Risk information
- Feedback mechanisms
Module 23: Integrating Risk Management
- Strategic planning
- Business processes
- Project management
- Operational management
- Decision-making
- Performance management
Module 24: Building Risk Culture
- Risk awareness
- Leadership behaviours
- Employee involvement
- Accountability
- Risk-based thinking
- Organisational learning
Module 25: Risk Monitoring and Review
- Monitoring activities
- Risk reviews
- Control monitoring
- Emerging risks
- Changes in exposure
- Review frequency
Module 26: Risk Indicators and Reporting
- Key risk indicators
- Risk dashboards
- Risk trends
- Management reporting
- Escalation reporting
- Decision support
Module 27: Evaluating Framework Effectiveness
- Performance indicators
- Framework evaluation
- Process effectiveness
- Stakeholder feedback
- Implementation gaps
- Improvement opportunities
Module 28: Managing Change and Emerging Risks
- Organisational change
- Environmental change
- Emerging risks
- Changing assumptions
- Risk reassessment
- Adaptive risk management
Module 29: Continual Improvement
- Lessons learned
- Improvement priorities
- Framework enhancement
- Process improvement
- Risk maturity
- Continuous development
Module 30: Sustaining Risk Management Implementation
- Implementation review
- Governance oversight
- Maintaining accountability
- Ongoing monitoring
- Organisational integration
- Long-term effectiveness
Who it's for & what's included
Pick a delivery method to see exactly who it suits and everything you receive.
Classroom
Best for learners who want face-to-face tuition and to network with peers in person.
Everything you get
- ✓ Live instructor on-site
- ✓ Printed workbook & materials
- ✓ Group exercises & case studies
Online Instructor-Led
Best for learners who want a live instructor and a fixed schedule, without the travel.
Everything you get
- ✓ Live instructor via video call
- ✓ Digital workbook & resources
- ✓ Session recordings
Self-Paced
Best for self-motivated learners who need maximum flexibility around work and life.
Everything you get
- ✓ On-demand video lessons
- ✓ Interactive quizzes
- ✓ 24/7 access on any device
Course Overview
This course develops practical capabilities for leading the implementation of risk management based on ISO 31000 principles and guidance. Participants will explore organisational context, governance, risk criteria, risk assessment, treatment, controls, communication, monitoring, reporting, integration, risk culture, implementation planning, performance evaluation, and continual improvement.