Program Overview
ISO 31000 is guidance, not certifiable — but auditors who understand it can evaluate whether risk thinking is genuinely integrated into governance, strategy and operational decisions across every Annex-SL management system.
Syllabus
Day 1 Schedule
Principles, Framework, Process
The three-part anatomy of ISO 31000 and how auditors test each layer.
Risk Integration into Strategy & Decision-Making
How to audit whether risk informs real choices: capital, M&A, strategic projects, product approvals.
Risk Reporting, Culture & Capability
Workshop: interview executives and middle managers to triangulate whether the risk culture matches the reported maturity.
Crosswalk to COSO ERM, Annex SL §6.1 & Sector Models
Translate ISO 31000 conclusions into language that satisfies COSO, Annex SL clause 6.1, and financial/regulator frameworks.
Final Knowledge Assessment
Multiple-choice assessment covering every clause area introduced in Plug-In: ISO 31000 Enterprise Risk Management Lead Auditor. Pass mark 70%.
This terminal assessment unlocks after you enrol. The exam grades clause-level recall; the simulation requires a passing score before drafting the closing NCR.
Closeout: Live Audit & NCR Drafting
Live War Room simulation tied to Plug-In: ISO 31000 Enterprise Risk Management Lead Auditor. Conduct an AI-driven interview, evidence-gather, then draft a defensible NCR.
This terminal assessment unlocks after you enrol. The exam grades clause-level recall; the simulation requires a passing score before drafting the closing NCR.
Learning Outcomes
- Apply ISO 31000 principles, framework and process to audit work
- Assess board and executive accountability for risk culture
- Evaluate risk integration into strategy, planning, and capital allocation
- Sample risk reporting up and down the organisation
- Reconcile ISO 31000 with COSO ERM, Annex SL §6.1 and sector frameworks
