Skip to content
Innovation Excellence Consulting & Training
Quality & Management Systems

Enterprise Risk Management (ISO 31000)

Build a living risk register that gets reviewed and used in decisions — not a table filled in once a year.

Practitioner3 days18 training hours6-20 participants

All training programmes are accredited by the Sharjah Private Education Authority.

Programme objectives

  • Build a risk framework aligned to ISO 31000
  • Identify and analyse risks qualitatively and quantitatively
  • Define risk appetite and tolerance levels
  • Select risk responses and track their effectiveness

Detailed agenda

1
Day 1

The framework

  • ISO 31000 principles and framework
  • Risk management roles and responsibilities
  • The internal and external context
  • Risk appetite and tolerance
2
Day 2

Identification and analysis

  • Identification methods: brainstorming, checklists, scenario analysis
  • The likelihood-and-impact matrix
  • Inherent versus residual risk
  • A risk identification workshop
3
Day 3

Response and monitoring

  • Responses: avoid, reduce, transfer, accept
  • Controls and their effectiveness
  • Key risk indicators
  • Building the register and its review cycle

Competencies developed

  • Risk identification
  • Quantitative analysis
  • Governance
  • Monitoring and reporting

What participants take away

  • A risk register template
  • A likelihood-and-impact matrix
  • A guide to setting risk appetite
  • A company-issued certificate of attendance

Prerequisites

None.

How it is assessed

A completed risk register for one department, with an assessment and response for each key risk.

Message us on WhatsApp