Training module
Auditing Risk & Opportunity Management
Assess whether risk and opportunity management credibly informs organisational decisions and priorities
Does your audit go beyond checking the risk register to judging the quality of risk-based decisions?
In many organisations, risk-based thinking is documented but rarely influences decisions. This module develops the capability to test whether risks and opportunities credibly inform priorities, trade-offs, and operational choices.
Overview
What this module is about
ISO management system standards require organisations to consider risks and opportunities when planning and operating their systems. In practice, many organisations maintain risk registers and periodic updates while links to decisions, priorities, and resource allocation remain weak.
This module develops the capability to audit whether risk and opportunity management meaningfully influences organisational decisions. Participants first review the core concepts of risk and opportunity management across management system standards and then learn how auditors test completeness, traceability, and credibility of risk-based decisions using operational evidence.
Audience
Who it is for
Management system implementers and coordinators
Executives and department heads accountable for management system performance
Those responsible for processes, policies, assets, risks and controls
Auditors seeking insight into management-side practice, not audit technique
Consultants working on management system design, governance or improvement
Decision supportIs this module for you?
It is a good fit if you…
audit whether risks and opportunities influence organisational decisions.
need to test credibility beyond documented risk registers.
want to trace risk-based reasoning from context to operational evidence.
aim to judge decision quality rather than register completeness.
audit risk-based thinking across different ISO management system standards.
It may not be the best fit if you…
want to learn risk assessment methods or modelling techniques.
focus on implementing risk management processes.
expect clause-by-clause compliance checklists.
already audit risk-based decision-making at a very advanced level.
Agenda
What is taught
7 parts01Foundations of risk and opportunity management in management systems
How ISO management system standards frame risks and opportunities and how these concepts influence planning, prioritisation, and decision-making
02What effective auditing of risk and opportunity management looks like
How auditors judge whether risk and opportunity management is credible, decision-relevant, and used in organisational priorities
03Testing completeness of risk and opportunity identification
How to evaluate whether risk identification covers relevant activities, assets, processes, sites, and change scenarios
04Building and testing the audit evidence trail
How to follow risks and opportunities from context inputs through actions and operational evidence without re-teaching risk methods
05Detecting consistency gaps and false assurance patterns
How to identify disconnects between risks, actions, decisions, and operational reality that undermine assurance
06Judging the credibility of risk-based decisions
How auditors assess whether risks and opportunities influence prioritisation, trade-offs, and resourcing decisions
07Case-based audit simulation
Applying the learned concepts, methods, and approaches in a realistic case setting
Outcomes
Learning outcomes
01
Assess whether risk and opportunity identification is complete and appropriate for the organisational context and audit scope
02
Trace risks and opportunities from context inputs to actions, decisions, and operational evidence
03
Judge whether risk and opportunity management credibly informs organisational priorities and decisions
Identify common failure patterns such as “paper risk management”, convenience-driven scoping, and unmanaged risk acceptance
Detect inconsistencies between risk registers, actions, decisions, and operational evidence
Select meaningful sampling targets when auditing risk and opportunity management
Formulate clear audit conclusions on the credibility and decision relevance of risks and opportunities
Materials
The content and the assessment
Written module
The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.
Exercises
Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.
On completion
The assessed exercises must be passed before the certificate is issued.
Scheduling
No public run of Auditing Risk & Opportunity Management is scheduled at the moment. Tell us you are interested and we will let you know when the next one opens, or discuss running it in-house.
Module facts
- Module ID
- HAM-AG-A-03
- Discipline
- Cross-discipline
- Part of tracks
- Management System Auditor
Case organisation
You work inside a company that already has the problem
Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.
Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.
Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes
Not a case study
Nothing is summarised for you; the evidence is where it would really be
It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after
It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions
Why it matters
Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.
Delivery & dates
How this module reaches you
Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.
No public run is scheduled at the moment. Most modules run on request as well as on the public calendar, so tell us the timing you need.
Want this module scheduled?
We will tell you when the next run is scheduled, or run this module in-house with your own case material.
Not sure it is the right module?
Describe your context in a short message and we will tell you honestly.