
Identify, assess, and control threats to an organization's capital, earnings, and digital assets, including data, personal data, and intellectual property, through risk management.
Identify limitations of risk management, including a false sense of stability, past-focused value-at-risk measures, illusion of control, and immature policies that obscure the big picture of cumulative risk.
Explore the main risk management approaches: avoidance, reduction, sharing, and retention. Learn how deflect threats, adjust plans, distribute consequences, or accept risk to protect projects.
Explore essential risk management terms such as authentication, authorization, committee charter, compliance risk profile, control assessments, and key indicators including KPIs within enterprise risk management.
Identify key risk indicators that signal future and emerging risks and assess them alongside likelihood, mitigation actions, and risk appetite to manage operational, strategic, and reputation risks.
Identify risk, analyze risk, evaluate and prioritize risk, implement risk treatment, and monitor risk within the five-step risk management process.
Identify and analyze risks in the operating environment, evaluate their severity, and rank them to prioritize intervention, then treat and monitor them with a centralized risk management solution.
Coordinate executive level risk owners to manage the full scope of organizational risks. Cooperate within the enterprise risk management team to identify and manage cross-functional risks.
Learn how an enterprise risk management team is composed, from the board and its risk committee to the chief risk officer, aligning irm with strategy and resilience.
Operational risk management aligns the chief legal officer's liability oversight with the CFO's revenue and insurance risk focus, while addressing privacy, compliance, and cyber risk through CIO and CISO leadership.
Examine how C-suite roles align risk management with strategy and ESG priorities, focusing on workforce risks and cybersecurity. See staff, CISO collaboration, and independent contractor laws shape risk management.
Compare traditional risk management as a formal function in large companies with enterprise risk management that spans governance, risk and compliance, and cyber security.
Traditional risk management operates in silos, overlooking interconnected risks and their upstream and downstream effects. Enterprise risk management adopts a proactive, holistic approach spanning cyber, compliance, financial, and reputational risk.
Learn how an integrated IRM framework guides enterprise risk management through governance, culture, risk appetite, and objectives, with COSO, ISO 31000, and BS 31100 guiding identification, assessment, reporting, and response.
Implement an IRM framework by tailoring processes per ISO 31,000, establishing context, identifying risks, and analyzing likelihood and impact to drive awareness, reporting, and stakeholder communication.
Evaluate risk and respond; if within appetite and tolerance, take no action. Otherwise, apply controls, transfer or avoid risk, then monitor KPIs and KRIs for continuous improvement.
Compare ISO 31000 and COSO IRM frameworks to identify, assess, and control risks for meeting business objectives and supporting enterprise risk management.
Explore the enterprise risk management framework, its 2017 update, and how governance, culture, strategy and objectives, risk appetite, and ISO 31,000 principles guide risk performance.
Explore ISO 31000 risk management principles and the six customizable components that embed risk management into decision making. Compare ISO 31000 with COSO and ISO 31010, risk appetite and communication.
Explore the three core decisions in operations management: production planning, production control, and improving production methods, and how operations aligns with marketing and finance to meet demand.
Explore process management in operations by transforming inputs into outputs, using a transformation model with a feedback loop to balance capacity with demand and manage process variation.
Learn how operations management centers on planning and decision making to optimize resources, scheduling, and process design, balancing strategic and tactical decisions for long-term success.
Identify hazards and risks that could threaten an organization's ability to conduct business, including manufacturing and other operations, using RCAF and RAAF frameworks to prioritize and share IT infrastructure risks.
Identify hazards, determine affected assets, and evaluate risks to implement controls that minimize property damage, business interruption, financial loss, and penalties; regularly record findings and update assessments.
Compare qualitative and quantitative risk assessments, recognizing that many risks are inherently qualitative; climate change illustrates quantification limits, while finance risks rely on objective metrics.
Develop a risk profile with quantitative threat analysis and a complete information technology and data asset inventory. Identify, prioritize, and document threats to justify remediation and measure return on investment.
Identify and document risks that could hinder objectives, communicate concerns, assess threats such as malware, ransomware, accidents, and natural disasters, and implement robust risk management plans to minimize impact.
Identify and analyze potential issues through risk analysis to avoid or mitigate risks, guiding decision making across the project management cycle and reducing exposure, litigation, and regulatory impact.
Perform risk analysis by identifying and analyzing potential issues that could impact key business initiatives, to avoid or mitigate risks and inform decision making across the project management cycle.
Learn how risk ratings use probability multiplied by loss to quantify the expected loss for processes, production activities, and investments exposed to disruptive events.
Explore bow tie analysis, qualitative risk analysis, metrics, risk register, and swift analysis to identify causes, consequences, and mitigation strategies, prioritize risks, and build a risk management plan.
Use the risk impact probability charts to prioritize risks by evaluating their probability of occurrence and potential impact. Read outcomes on two axes to decide which risks require attention.
Identify and rate project risks using the risk impact probability chart, assigning 1–10 scores for likelihood and impact, then develop response plans by chart position.
Align your project team through risk review meetings to identify, categorize by likelihood, and prioritize risks from least to most detrimental, enabling proactive mitigation.
Lead a risk review meeting with a structured process and toolkit to identify risks, coach stakeholders, plan actions, and build a long-term risk management plan.
Learn to conduct a thorough risk audit by planning, setting scope and boundaries, and gathering information through interviews and observations; develop checklists and interview questions.
Conduct an auditing exercise by briefing personnel, performing site visits with checklists, interviewing staff, verifying policies, reviewing injury logs, and producing a risks register with mitigation strategies.
Identify, assess, and mitigate risks across the end to end supply chain through strategic risk management steps.
Explore standard and internal supply chain risks, including demand, supply, environmental, business, manufacturing, planning and control, and mitigation and contingency risks, and see how analytics and IoT support risk assessment.
Explore forms of supply chain management risks, including financial risks such as exchange rate changes and supplier bankruptcy, as well as legal, sociopolitical, and human behavioral risks impacting projects.
The Operational Risk Management Certification Course is a comprehensive online training designed to equip professionals with the skills and tools to proactively manage operational risks in today's complex and fast-changing business environments. Whether you're working in finance, manufacturing, healthcare, energy, or the public sector, this course provides a practical framework for identifying, assessing, monitoring, and mitigating risks that can disrupt operations, damage reputation, or lead to financial loss.
This course explores the foundations of operational risk, including its sources—such as human error, process failures, systems breakdowns, and external events—and how these risks differ from financial, strategic, or compliance risks. You'll learn to use proven risk assessment tools such as risk registers, root cause analysis, risk heat maps, and scenario analysis. Real-world examples and case studies are included to help you understand how leading organizations implement effective operational risk controls and integrate them into their business processes.
In addition to risk identification and assessment, the course covers risk response strategies, key risk indicators (KRIs), internal controls, and how to establish a risk-aware culture within an organization. You’ll also gain insight into risk governance, roles and responsibilities, regulatory expectations (such as Basel III and ISO 31000), and the use of technology in risk monitoring and reporting. The course emphasizes a proactive and systematic approach to risk that supports strategic goals and operational resilience.
By the end of this course, you'll have the confidence and capability to contribute to or lead operational risk management initiatives within your organization. Whether you're building a risk management system from scratch or enhancing an existing program, you'll be equipped with actionable tools, templates, and frameworks to reduce uncertainty and strengthen decision-making. This course is ideal for risk officers, compliance professionals, operations manag