ISO 31000 Risk Management Training

A two-day programme built around ISO 31000, the international standard most organisations already reference when someone asks how risk management is supposed to work. The gap this closes is personal rather than organisational: plenty of people can describe risk management in the abstract, and far fewer can open a blank template and produce a defensible risk register for their own function by the end of the week. This course produces the second kind of person.

Day one covers the ISO 31000 principles, framework and process in enough depth to use them, not just recognise them on a slide. Day two is a workshop: participants build a risk register against a case organisation, then against their own, and leave with a completed template plus a realistic roadmap for pursuing a personal risk management certification such as PECB's Certified ISO 31000 Risk Manager exam, if they choose to sit it. It pairs naturally with the Enterprise Risk Management course, which goes deeper on organisation-wide implementation, and with Corruption Risk Management, which applies the same register-building discipline to a single risk category.

HRD Corp Training Provider Malaysia HRD Corp SBL-Khas Claimable

Programme Agenda

01

Day 1, 9:00 AM - 9:15 AM

Welcome and Programme Overview

Introduction to the session, objectives, and housekeeping.

02

Day 1, 9:15 AM - 10:15 AM

What ISO 31000 Actually Is

The difference between a management system standard and a guidance standard, and why ISO 31000 is the second kind: there is nothing to certify an organisation against, which is precisely why the standard is so widely adopted. Where ISO 31000 sits relative to COSO ERM and sector-specific frameworks like BNM's RMiT. What changed between the 2009 and 2018 editions.

03

Day 1, 10:15 AM - 10:30 AM

Break

04

Day 1, 10:30 AM - 11:30 AM

The Eight Principles

Integrated, structured, customised, inclusive, dynamic, best available information, human and cultural factors, and continual improvement. Working through each principle against real organisational failures where ignoring it was the actual root cause, not the risk that was eventually blamed.

05

Day 1, 11:30 AM - 12:30 PM

The Framework: Leadership and Integration

Leadership and commitment as the framework's foundation, and what that looks like when it is genuine versus decorative. Integrating risk management into governance, strategy, planning and operations rather than running it as a parallel compliance exercise. Designing a framework proportionate to the organisation's size, not copying a template built for a bank.

06

Day 1, 12:30 PM - 1:30 PM

Lunch

07

Day 1, 1:30 PM - 3:15 PM

The Framework: Implementation, Evaluation and Improvement

Rolling out a framework in practice: resourcing, communication, and the sequencing that determines whether it survives contact with a busy operation. Evaluating whether the framework is actually working, using evidence rather than the existence of a policy document. Improving the framework on a cycle instead of leaving it untouched until the next audit finding.

08

Day 1, 3:15 PM - 3:30 PM

Break

09

Day 1, 3:30 PM - 4:45 PM

Risk Assessment: Identification and Analysis

Structured techniques for identifying risk rather than relying on whoever shouts loudest in the workshop: checklists, bow-tie analysis, and structured interviews. Analysing likelihood and consequence without false precision, and the specific ways a heat map misleads the people using it. Distinguishing inherent risk from residual risk, and why conflating the two is the most common error in a first risk register.

10

Day 1, 4:45 PM - 5:00 PM

Day 1 Close

Recap and what to review before day two.

11

Day 2, 9:00 AM - 9:15 AM

Day 1 Review

Recap of day one and the questions it left open.

12

Day 2, 9:15 AM - 10:15 AM

Risk Evaluation and Treatment

Comparing analysed risk against the organisation's risk criteria to decide what needs treatment now, what is monitored, and what is accepted deliberately rather than by default. The treatment options: avoid, take, remove the source, change likelihood, change consequence, share, or retain. Building a treatment plan with an owner, a deadline and a way to tell later whether it worked.

13

Day 2, 10:15 AM - 10:30 AM

Break

14

Day 2, 10:30 AM - 11:30 AM

Monitoring, Review and Reporting

Why a risk register that is never revisited is worse than no register, because it creates false confidence. Building a monitoring rhythm that fits the organisation's actual meeting cadence instead of an ideal one nobody keeps. Recording and reporting risk information so a board or client audience can use it, not just a risk team.

15

Day 2, 11:30 AM - 12:30 PM

Building the Risk Register

Participants build a complete risk register against a supplied case organisation, working through identification, analysis, evaluation and treatment as one continuous exercise rather than four separate ones.

16

Day 2, 12:30 PM - 1:30 PM

Lunch

17

Day 2, 1:30 PM - 3:15 PM

Applying It to Your Own Organisation

The same register rebuilt against the participant's own function or organisation, with group critique on where the case-study version was easier than the real one and what that implies about rollout.

18

Day 2, 3:15 PM - 3:30 PM

Break

19

Day 2, 3:30 PM - 4:45 PM

Certification Roadmap and Close

For participants who want a personal credential to show for this: what PECB's Certified ISO 31000 Risk Manager exam covers, how it differs from this workshop, and a realistic study plan for anyone who wants to sit it. What this course does and does not certify, stated plainly.

20

Day 2, 4:45 PM - 5:00 PM

Wrap-Up and Q&A

Key takeaways, next steps, and close.

Key Outcomes

  • Explain ISO 31000's eight principles and why the standard has nothing to certify an organisation against
  • Distinguish inherent from residual risk and avoid the most common first-register error
  • Identify and analyse risk using structured techniques instead of whoever is loudest in the room
  • Evaluate risk against stated criteria and choose a defensible treatment option
  • Build a complete risk register end to end: identification, analysis, evaluation and treatment
  • Design a monitoring and reporting rhythm that survives contact with a real meeting calendar
  • Leave with a personal roadmap for pursuing an external risk management certification exam

Training Mode   Physical / Online / Hybrid / e-learning

HRD Corp   SBL-Khas Claimable

Level   Intermediate. Suitable for risk officers, internal auditors, compliance managers, department heads building their first risk register, and anyone pursuing a personal risk management credential. No prior formal risk training required, though familiarity with the participant's own organisation is assumed for the workshop day.

Duration   2 Days (16 Hours)  |  9:00 AM to 5:00 PM daily

Venue   In-house at the client's premises, or delivered via the client's preferred platform (Microsoft Teams, Zoom, or equivalent)

Assessment   A completed risk register built against a case organisation, and a second completed register built against the participant's own organisation or function

Certificate   Certificate of Completion issued to all participants upon full attendance

EnquiriesContact us to register or discuss scheduling

Frequently Asked Questions

Yes. ISO 31000 Risk Management Training is HRD Corp SBL-Khas claimable. Employers registered with HRD Corp (PSMB) can claim the training fee against their levy, as Orbix Tech Sdn Bhd is an HRD Corp certified training provider. Submit the SBL-Khas application before the session date.

ISO 31000 Risk Management Training runs for 2 days (16 hours) | 9:00 AM to 5:00 PM daily. It is delivered as an in-house closed group session, so the schedule can be adjusted to fit your team's working hours.

Yes. Delivery options are physical, online, hybrid, e-learning. In-house sessions run at your premises anywhere in Malaysia, online sessions run live over video conference, and hybrid combines both for teams split across sites.

Certificate of Completion issued to all participants upon full attendance. Each certificate carries a certificate number that can be checked at orbixtech.my/certificate-verify.

Level: Intermediate. Suitable for risk officers, internal auditors, compliance managers, department heads building their first risk register, and anyone pursuing a personal risk management credential. No prior formal risk training required, though familiarity with the participant's own organisation is assu. The session is built around worked examples and group exercises rather than theory, so participants apply the material to their own organisation during the session.

Half-day and full-day sessions are quoted per session for a closed group, from RM 800 and RM 1,750 respectively. Advanced 2-day programmes are quoted per participant, from RM 4,000. All figures are before any HRD Corp levy claim.