Quality & Management Systems
Enterprise Risk Management (ISO 31000)
Build a living risk register that gets reviewed and used in decisions — not a table filled in once a year.
Practitioner3 days18 training hours6-20 participants
All training programmes are accredited by the Sharjah Private Education Authority.
Programme objectives
- Build a risk framework aligned to ISO 31000
- Identify and analyse risks qualitatively and quantitatively
- Define risk appetite and tolerance levels
- Select risk responses and track their effectiveness
Detailed agenda
1
Day 1
The framework
- ISO 31000 principles and framework
- Risk management roles and responsibilities
- The internal and external context
- Risk appetite and tolerance
2
Day 2
Identification and analysis
- Identification methods: brainstorming, checklists, scenario analysis
- The likelihood-and-impact matrix
- Inherent versus residual risk
- A risk identification workshop
3
Day 3
Response and monitoring
- Responses: avoid, reduce, transfer, accept
- Controls and their effectiveness
- Key risk indicators
- Building the register and its review cycle
Competencies developed
- Risk identification
- Quantitative analysis
- Governance
- Monitoring and reporting
What participants take away
- A risk register template
- A likelihood-and-impact matrix
- A guide to setting risk appetite
- A company-issued certificate of attendance
Prerequisites
None.
How it is assessed
A completed risk register for one department, with an assessment and response for each key risk.
Related programmes
Advanced
ISO 9001 Internal Auditor
Qualify internal auditors who run effective audits and write reports that stand up to challenge.
3 days999 AEDFoundationISO 27001 Information Security Foundations
Understand the information security management system and its controls, and build a realistic implementation plan.
2 days399 AEDAdvancedBusiness Continuity (ISO 22301)
Business impact analysis and continuity plans that are actually exercised, not merely filed.
3 days999 AED