Enterprise Risk Management Training
A two-day programme on running risk management as a working system rather than an annual spreadsheet refresh. It covers the ISO 31000:2018 principles, framework and process alongside the COSO ERM approach, and applies both to the practical problems that stop risk management being useful: registers nobody updates, heat maps that hide more than they reveal, appetite statements too vague to refuse anything, and risk reports the board receives without ever challenging.
The programme is built around participants' own risk landscape. By the end of Day 2 each group has drafted a risk appetite statement, populated a register with assessed and treated risks, defined key risk indicators with thresholds, and produced a board-level risk report from it. Suitable for organisations building an ERM function from scratch and for those with a framework on paper that has stopped earning its keep.
HRD Corp SBL-Khas Claimable
Programme Agenda
Day 1, 9:00 AM - 9:15 AM
Welcome and Programme Overview
Introduction to the session, objectives, and housekeeping.
Day 1, 9:15 AM - 10:15 AM
What ERM Is, and Why Most Implementations Stall
Enterprise risk management against siloed risk management, and what enterprise-wide actually requires. The common failure patterns: risk management run as a compliance exercise, a register maintained by one person, assessment scales nobody agrees on, and risk reporting that arrives too late to affect a decision. What good looks like.
Day 1, 10:15 AM - 10:30 AM
Break
Day 1, 10:30 AM - 11:45 AM
Frameworks: ISO 31000:2018 and COSO ERM
The ISO 31000 structure of principles, framework and process, and how the 2018 revision shifted emphasis towards integration and leadership. The COSO ERM components and their focus on strategy and performance. Where the two agree, where they differ in emphasis, and how to choose or combine them without importing two vocabularies.
Day 1, 11:45 AM - 12:45 PM
Risk Governance and the Three Lines Model
Board and audit or risk committee responsibilities, the risk function's mandate, and the three lines model: management ownership, risk and compliance oversight, and internal audit assurance. Why the second line loses authority when it also owns controls, and how to keep the lines distinct in a small organisation where people wear several hats.
Day 1, 12:45 PM - 1:45 PM
Lunch
Day 1, 1:45 PM - 3:00 PM
Risk Appetite and Tolerance
The difference between appetite, tolerance and capacity, and why an appetite statement that cannot refuse a proposal is decoration. Writing appetite statements that are specific by risk category, setting quantitative tolerances where the data supports it and qualitative ones where it does not, and cascading appetite into decision limits people actually use.
Day 1, 3:00 PM - 3:15 PM
Break
Day 1, 3:15 PM - 4:15 PM
Risk Identification
Techniques beyond the workshop brainstorm: process mapping, scenario analysis, loss event data, near miss review, external horizon scanning and structured interviews. Writing a risk statement that names cause, event and consequence rather than a one-word topic. Emerging risk: cyber, third party and supply chain, climate and transition risk, regulatory change and AI adoption.
Day 1, 4:15 PM - 5:00 PM
Risk Assessment
Likelihood and consequence scales and the discipline of defining each band before scoring anything. Inherent against residual risk, control effectiveness assessment, and where heat maps mislead: compressed scales, averaged scores and the tail risk that lands in the same box as the routine one. An introduction to quantification where it is warranted. Day 1 wrap-up.
Day 2, 9:00 AM - 9:15 AM
Recap and Day 2 Objectives
Review of Day 1 and the plan for the application day.
Day 2, 9:15 AM - 10:30 AM
Risk Treatment and Controls
The treatment options and how to choose between them, designing controls proportionate to residual risk, preventive against detective controls, and testing whether a control that exists on paper actually operates. Cost of control against cost of risk, and documenting an accepted risk so the acceptance is a decision rather than an oversight.
Day 2, 10:30 AM - 10:45 AM
Break
Day 2, 10:45 AM - 12:00 PM
Workshop: Risk Register and Appetite Statement
Groups draft an appetite statement for two risk categories, then build a register: risk statements, owners, assessment, controls, treatment actions with dates, and residual position. Facilitated challenge of the output.
Day 2, 12:00 PM - 12:45 PM
Key Risk Indicators and Early Warning
Selecting indicators that lead rather than lag, setting thresholds and escalation triggers, and avoiding the indicator set that only measures what is easy to count. Linking KRIs to appetite so a breach forces a conversation.
Day 2, 12:45 PM - 1:45 PM
Lunch
Day 2, 1:45 PM - 3:00 PM
Aggregation, Reporting and the Board Conversation
Rolling operational risk up to enterprise level without losing meaning, connecting risks that share a cause, and reporting formats that support a decision. What the board and audit committee should be asking, and the Statement on Risk Management and Internal Control expected of Bursa-listed issuers. Workshop: groups produce a board risk report from their register.
Day 2, 3:00 PM - 3:15 PM
Break
Day 2, 3:15 PM - 4:15 PM
Embedding ERM and Risk Culture
Integrating risk into strategy, budgeting, project approval and procurement so the register stops being a separate artefact. Risk culture and how to read it, incentives that quietly work against the framework, assurance mapping, and maturity assessment. How ERM connects to business continuity, compliance and internal audit.
Day 2, 4:15 PM - 5:00 PM
Implementation Roadmap and Wrap-Up
Groups present a twelve-month ERM improvement plan for their organisation. Key takeaways, next steps, and close.
Key Outcomes
- Apply the ISO 31000:2018 framework and process, and place COSO ERM alongside it
- Write a risk appetite statement specific enough to refuse a proposal
- Build a risk register with proper risk statements, owners, controls and treatment actions
- Assess control effectiveness and distinguish inherent from residual risk
- Select key risk indicators that give warning rather than confirmation
- Report risk to the board in a form that prompts challenge and decision
- Diagnose why an existing ERM framework has stopped being used, and plan the fix
Training Mode Physical / Online / Hybrid / e-learning
HRD Corp SBL-Khas Claimable
Level Intermediate, suitable for risk managers and risk coordinators, internal audit, compliance, finance, operations managers, and senior management accountable for risk oversight
Duration 2 Days (16 Hours) | 9:00 AM to 5:00 PM daily
Venue In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)
Assessment Knowledge assessment covering both days, three facilitated workshops, and a group implementation roadmap presentation
Certificate Certificate of Completion issued to all participants upon full attendance