
Explore how internal audits support enterprise risk management, moving from traditional insurance-based risk control to integrated goals-driven identification. Focus on decision making under uncertainty and spotting opportunities across the organization.
Define enterprise risk management as risk management applied across an organization, focusing on events that threaten goals and objectives, aligning long-term goals with specific, measurable, accurate, realistic, time-based objectives.
Explore the differences between risk management and enterprise risk management, comparing risk-averse mitigation focus with ERM's organization-wide resilience, governance, interrelated risks, and risk appetite.
Apply the top-down risk model to map inherent risks from entity to transaction level, eliminate large risks through governance and oversight, then address residual risks at the process level.
Board oversight sets the tone for enterprise risk management, defines risk appetite and governance structure, while management implements systems and processes, and internal audit provides independent assurance.
erm documentation clarifies how policies, risk appetite statements, and risk registers define risk levels, objectives, and controls, while guidelines, procedures, and internal audit verify accountability across branches.
Learn the COSO enterprise risk management model, its integration with strategy and performance, and how portfolio view concepts help answer precise CRM questions.
Explore the COSO helix and its components—governance and culture, strategy and objective setting, performance, review and revision, and information, communication and reporting—and how to form a portfolio view of risks.
Analyze risk using defined likelihood, time period, and impact, then evaluate velocity, persistence, and preparedness to support business continuity strategies.
Analyze volatility to see how risk varies over time, and examine interdependence where risks amplify each other. Learn how correlation differs from causation and why dependent risks may occur together.
Explore the risk management maturity model as a benchmarking tool that measures how fully an organization implements risk management measures across levels, with examples from the CMMi Institute.
Describe how a startup evolves from informal, ad hoc risk handling to a mature, optimized risk culture. Build policies, controls, contingency plans, and KPIs/KRIs, aligning with board and management.
Increase risk management maturity strengthens risk culture and integrates risk practices into decision making and rewards. Elevate governance with skilled personnel and board training for better risk prioritization and monitoring.
Explore how risk information ownership evolves across the risk management maturity model from internal audit at inception to cross-functional collaboration with a common risk language, policy, and risk appetite.
Leverage risk management maturity models to guide internal audits, assess organizational stages from initial to defined, and evaluate governance and reporting processes.
Examine the coso erm fan and how internal audits define roles in enterprise risk management, including must undertake, should undertake with safeguards, and should not undertake.
Learn how to respond to risk with terminate, reduce or mitigate, transfer or share, and accept strategies, plus exploiting opportunities to increase upside within risk tolerances.
Examine risk measurement methods such as risk exposure, expected loss, and sensitivity analysis with scenarios, plus stress testing to probe capital adequacy, while monitoring key risk indicators.
Explore the three lines of defense model in banking, identifying first line risk owners, second line oversight, and third line internal audit, with examples of compliance, risk management, and assurance.
Learn risk assurance mapping, a visual framework aligning risks with the first, second, and third lines of defense, showing risk owners, controls, and audit coverage.
Define risk management governance and apply governance structures and frameworks to oversee and implement risk management, guided by the board to help the organization meet its goals.
Present a governance structure with a board, risk and audit committees, a chief risk officer reporting to the CEO, and an enterprise risk management committee overseeing risk across the organization.
Internal audit supports governance as third line of defense, providing insight to the board, evaluating board and risk committee processes, benchmarking against best practices, and improving reporting, escalation, and assurance.
The lecture outlines the three fiduciary duties of board members—care, loyalty, and obedience—emphasizing diligent, good-faith decision-making, avoidance of insider trading, and legal compliance.
Explore COSO's ERM cube and how internal environment, objective setting, event identification, risk assessment, risk response, control activities, information and communication, and monitoring enable integrated risk management.
Define risk appetite and explain how much risk an organization is willing to accept; clarify risk types and amounts, and connect them to mission, planning, and risk communication.
Explore a bank's risk appetite statement, detailing sustainability criteria and exclusions such as tobacco, marijuana, and online gambling, with measurable terms for interest rate, credit, liquidity, currency, and basis risks.
Sobel and Reding's capability criteria define an organization's risk capacity through readiness and preparedness, agility, resilience, controllability, monitor ability, maturity, and confidence to take on and manage risk.
Explore how to measure risk using risk appetite, risk level or severity, risk capacity, and risk tolerance, including graphical representations of boundaries of acceptable risk.
Explore how risk appetite, risk tolerance, and risk capacity relate to volatility and value at risk in portfolio decisions.
Explore risk evaluation measures across the risk universe, balancing appetites for operational, market, and reputational risks to align actual risk profile with a target risk profile, guided by executive insights.
Identify the risk universe as all risks that may affect organizational objectives, including security, strategic, regulatory, systemic, and operational risks, then align with the audit universe to plan.
Map likelihood and impact to define risk levels, using yellow for risk appetite, green for the target profile, and a risk tolerance, with cash thresholds illustrating acceptable and critical levels.
Explore the main functions of controls—directive, preventive, detective, and corrective—and see how audits, backups, and audit trails prevent, detect, and respond to risk in an organization.
Learn to use lead indicators for emerging risks, along with preventive, detective, directive, and corrective controls, to map a risk from trigger events to consequences and improve response.
Clarify objectives and context within the COSO framework to identify potential risk events, assess their likelihood and impact, and explore how risk responses reduce inherent risk to determine residual risk.
Explore how residual risk emerges from inherent risk after internal controls and control risk are considered, and how internal audit assesses residual risk after controls and reconciliation in the environment.
Explore how audit risk arises from inherent, control, and detection risks, and learn how external and internal audits assess the likelihood of undetected material misstatements.
Analyze inherent and residual risks plotted by likelihood and impact, and how controls move risk from red to orange by reducing likelihood while impact remains.
Explore major risk management frameworks—COSO, ISO 31000, COBIT, NIST RMF, GATE for IT risks, and the Australian standard—and how they support governance and IT risk management for government contracts.
Explore the roles in the coso erm framework, from the board's risk appetite and tone at the top to management, risk officer, internal audit, and external partners.
ISO 31000 principles embed risk management into decision making and operations, enabling structured, accountable risk reporting. The framework is organization-wide, customizable, and designed for continual improvement through monitoring and learning.
compare coso erm components with iso 31000 components to reveal their alignment in internal environment and objective setting, and show how risk evaluation and risk analysis fall under risk assessment.
Explore the COSO internal control cube and its five components (control environment, risk assessment, control activities, information and communication, and monitoring) and their link to operations, reporting, and compliance.
Explore COSO's 17 principles of internal control across the control environment, risk assessment, control activities, information and communication, and monitoring.
Discover how risk culture shapes risk management through collective attitudes and behaviors, from tone at the top to open communication and accountability, defining acceptable risks.
The ABC model of risk culture links attitude, behavior, and culture, showing how risk attitude drives behavior and controls shape culture across diverse subsidiaries.
Identify indicators of a healthy risk culture, including ethical commitment, risk awareness, code of conduct, clear roles, incident reporting, and a common risk management framework that rewards risk-aware performance.
Assess risk culture by examining the tone at the top, governance and risk leadership, then link to competency and resources that enable risk-aware decision making and reporting.
Explore the McKinsey seven s model, detailing structure, systems, style, staff, skills, strategy, and shared values, and examine how hard and soft elements shape risk culture.
Identify emerging risks as issues not yet understood or revealed, illustrated by World Economic Forum's 2021 risks report, contrasting 2018 examples like infectious disease and cyber security risks.
Internal auditors must assess emerging risks with due professional care and ethical duty, ensuring coverage of significant risks affecting objectives, balancing uncertainty with risk to pursue opportunities.
Identify internal, connected, and external stakeholders—staff, directors, managers, shareholders, clients, suppliers, government, and the public—and explain how their interests and power drive stakeholder engagement and risk management.
Explore risk identification techniques and other risk management concepts, including risk assessments, measures for evaluating risks, risk and control self assessments, monitoring, and maturity models.
Identify risks through workshops and face-to-face interviews with operational staff, using a bottom-up approach and control self-assessments to inform risk management.
Facilitate a control and risk self-assessment session where operational team members brainstorm risks from inputs to outputs, guiding internal auditors to surface bottom-up insights and strengthen risk responses.
Analyze processes to identify vulnerabilities and single points of failure, like bottlenecks and slack, and build redundancy to avoid overreliance on a single system such as payment platforms.
Explore scenario planning in risk management using decision trees and sensitivity analysis to assess capital adequacy under Basel II across recession and interest-rate scenarios.
Brainstorming invites all ideas in a judgment-free, facilitator-led session to identify risks and enrich the risk inventory with overlooked vulnerabilities.
Use anonymous questionnaires distributed widely to capture bottom-up risk insights. Platforms can run short weekly or biweekly surveys (4–5 questions) to gauge staff views across large organizations.
Benchmark risk management against ISO 31,000 and the Coso framework to identify gaps and drive improvements, while auditors use benchmarks as criteria for assurance and legal compliance.
Plot actual incidents with a risk event map to assess impact and likelihood, define criteria, and establish a zero baseline to rank the most impactful and likely events.
Define likelihood levels and impact thresholds with a common policy language, link high likelihood and impact to board and management discussions, and use financial impact as the main measure.
Explore how data analytics supports internal audit by comparing paper-based and big data approaches, including AI-driven automation, data gathering, analysis, and extracting insights for decision making.
Data analytics enables continuous monitoring, real-time reporting, and internal audit insights to detect failures, predict future risks, and identify external changes for timely assurance.
Discover how internal audit and risk management add value by identifying and evaluating risks and predicting future risks, using four data analytics types: descriptive, diagnostic, predictive, prescriptive.
Describe or summarize data to understand what is going on and what has happened, aggregating sources and consolidating into a single source for descriptive analytics.
Explore diagnostic analytics by interpreting past data to uncover why events happened, identify root causes, drill down with data mining, and reveal correlations and trends.
Forecast future outcomes with predictive data analytics by extrapolating trends, adjusting with future changes, and using statistical models and machine learning to reveal correlations and guide pricing.
Prescriptive analytics builds on predictive analytics to recommend decision options and show their implications for future opportunities and risks, using variables like weather or sentiment data.
Explore ratio estimation, a data-analysis method that extrapolates insights from a representative sample to a population. Understand how sample representativeness affects accuracy, illustrated by an internal-auditor example with approval sheets.
Explore variance analysis to identify causes of differences between data sets and relate variance to the mean and standard deviation for insights into auction prices and store arrival times.
Explore proportional analysis and trend analysis to interpret data ratios and evolving patterns. Learn how embedded audit modules and software like IDEA or SPSS automate testing and reveal correlations.
Benford's law shows that leading digits in real life data follow a predictable frequency pattern. Use it to detect fraud in accounting and sales data by flagging unusual digit distributions.
Learn how regression analysis reveals relationships between independent variables and a dependent variable, using single or multiple regression to explain factors like age on arrivals and transactions.
Apply statistical process control to analyze data with a bell curve, set upper and lower control limits, and identify outliers. Learn when to remove nonrepresentative data to reveal true trends.
Explore budget versus actual variance analysis and planned versus actual comparisons, then map decisions with decision trees, and apply data mining and continuous monitoring to detect suspicious patterns in transactions.
Explore neural networks and data mining, using probabilistic outcomes from multi-step algorithms to mimic human problem solving, and apply fuzzy logic, discriminant analysis, and factor analysis to uncover complex patterns.
Discover root cause analysis by exploring methods to uncover reasons for incidents and issues. Learn fishbone diagrams, the five whys, logic trees, failure mode effects analysis, and fault tree analysis.
Use the fishbone (Ishikawa) diagram to identify causes and sub-causes and reveal why reporting delays occur in risk management.
Explore the five whys method for root cause analysis, drilling down by repeatedly asking why to determine the underlying cause of issues in risk management.
Explore logic trees as a hierarchical method to decompose a high environmental impact issue into subcomponents, identify root causes, and target high-impact actions to reduce carbon footprint, emissions, and pollution.
Apply fault tree analysis, a structured five-step process that maps faults, compares expected outcomes with potential alternatives, and identifies risk responses to hazards like fuel leaks and blocked exits.
Study failure modes and effects analysis as a systematic, proactive method to identify root causes, assess impacts, and prioritize risks with cross-functional teams and probability ratings.
Explore the system development life cycle (SDLC) as a framework for planning, analyzing requirements, designing or selecting systems, programming, testing—including user acceptance testing—and deploying with ongoing improvement.
Internal audit ensures deployment feasibility and embeds security controls from the start, aligns with policy and ISO 27001, and compares final objectives to initial criteria for acceptance.
Explore the systems development life cycle by outlining four methods—waterfall, spiral, rapid development, and Agile—and provide a roadmap to implementing the system.
Follow the waterfall method's SDLC steps—planning, analysis, design, programming, and testing—with sign-offs to prevent overlapping and reduce resource waste, though it can be inflexible and lead to longer deadlines.
The spiral method emphasizes an iterative, flexible approach to the systems development life cycle, focusing on continuous learning, risk assessment, testing, and applying past lessons to repeat software projects.
Explore rapid development in the SDLC, where planning, analysis, and design overlap with alpha and beta testing of multiple prototypes to shorten delivery time.
Explore the agile method's continuous iteration with overlapping development and testing in sprints. It centers on collaboration and customer focus, prioritizing individuals and interactions, working software, and adapting to change.
Learn six steps to assessing risk management within internal audits, including establishing scopes and objectives, gathering information, conducting a preliminary risk assessment, allocating resources, performing the audit, and reporting findings.
Assess the context of the organization for risk management by identifying stakeholder expectations, collecting strategic documents, and aligning with regulatory requirements and organizational goals.
Identify and map risks through a risk inventory and preliminary assessment, using workflows and flowcharts to reveal controls, redundancies, and single points of failure in processes.
Establish the scope and objectives for risk management by applying evaluation criteria from risk policies, procedures, external laws, and best practices.
Internal audits must understand organizational risks, provide assurance over risks, and move from auditing risk management to actively supporting risk processes, without becoming risk owners.
Internal auditors provide assurance on risk management processes, identify overlooked risks, review the risk register, and evaluate key risk indicators and risk reporting within enterprise risk management.
Explore legitimate internal audit roles with safeguards that facilitate identification and evaluation of risk, while coordinating across departments and coaching management without owning the risks.
Internal audit should not set risk appetite or impose risk management; report assurance gaps and provide recommendations, while the board and audit committee determine risk appetite.
Examine how internal auditors determine whether to rely on risk assurance from three sources: board-reported internal audits, management functions such as quality control, self assessments, and compliance, and external-stakeholder audits.
Internal audit assesses risk management effectiveness and decides whether to rely on internal or external assurance, guiding communication to management and the board and prioritizing audit work.
Sharing plans, resources, data, and findings within risk management assurance increases responsiveness to breaches, coordinates resources across the organization, and reduces duplication of tests and effort.
Apply continuous monitoring and self-reported issues as assurance over risk management, using integrated information systems for real-time detection of control failures and macro assurance across providers.
Explore models for assurance on risk management, including the process elements model, the key principles model, and the maturity model, a roadmap of approaches.
Communicate risk management policies and context to ensure a structured, ongoing process for identifying, analyzing, prioritizing, and treating risks. Monitor risk responses and controls to continuously improve the process.
Apply the key principles approach to assurance over risk management, focusing on value, integration into decision making, and handling uncertainty with disciplined, transparent practices.
Identify the four main qualities of persuasive internal audit information—sufficient, proper, reliable, and relevant and useful—and understand how competency shapes evidence for audit conclusions.
Understand the hierarchy of audit evidence, from primary or direct evidence like signed contracts to secondary, corroborative, analytical, and testimonial evidence, with practical examples.
Explore the process map for communicating risk acceptance, from audit findings to management responses and planned controls; show how board acceptance relates to risk tolerance and appetite.
Learn to craft audit communications that are accurate, objective, clear, and concise, with lean, timely reports and a one-page executive summary that drives action and value.
We are glad to bring you a course on Risk Management.
This course will help you manage risks so that your business can succeed.
Learn essential business knowledge for anyone who want to manage operations successfully.
This course will give you all that you need to know to get a firm understanding of operational risk management.
It is intended for either:
1. Risk Managers and those who want to learn more about risk management.
2. Managers and those who are responsible for operations in their organization.
3. Auditors and others assessing how risks are managed.
It is taught by Adrian Resag, an experienced Head of Risk Management, who has also been teaching for nearly 2 decades.
You will learn:
The basics (and intermediate knowledge) of operational risk management.
How to put in place Enterprise Risk Management (ERM) in your organization.
Risk Management tools and techniques.
What you need to know to perform proper audits of risk management.
The course covers:
Introduction to Risk Management
Understand the role of Risk Management in the management of an organization’s risks.
The Governance of Risk Management
Learn how to apply governance structures and frameworks over the management of risks in an organization.
Know how to assess the governance framework in place.
Risk Management Tools and Techniques
Lean about the main risk management frameworks, such as ISO 31000 and COSO ERM.
Learn risk identification and risk evaluation techniques, such as control self-assessment or fault tree analysis.
Learn about using data analytics for risk management.
Learn statistical techniques for risk management.
Learn how to assess risks in the Systems Development Life Cycle (SDLC).
Assurance over Risk Management Learn how to perform risk assessments
Know different measures for evaluating risks, how risk and control self-assessments are performed.
Know how the monitoring of risks and the risk management system should be performed.
Know how to use risk management maturity models in your organization.