Training module

Risk Management

Build the capability to surface, structure and act on risk while action is still possible

Cross-disciplineManagement System AuditorManagement System Manager
Abstract layered data visualisation representing risk signals, uncertainty, prioritisation and decision-ready risk information.

Risk management that holds up in decisions

Develop the practical judgement behind effective risk work: structuring ambiguity, calibrating granularity, challenging false precision, escalating proportionately, and translating uncertainty into treatment, monitoring or explicit acceptance decisions.

Overview

What this module is about

In many organisations, the most important risks are not invisible. They are already present in audit findings, operational workarounds, customer pressure, supplier dependencies, unresolved actions, and management review discussions. The problem is that they are often fragmented, tolerated, poorly structured, or escalated too late.

This module develops the practical judgement needed to make risk management useful in real management-system work. Participants learn how to turn messy inputs into clear risk structures, calibrate granularity, challenge weak scoring, distinguish treatment from acceptance, and prepare risk information that supports proportionate action, monitoring, escalation and governance decisions.

The module uses a realistic organisational case to let participants practise these judgements in context, without reducing risk management to templates, scoring exercises or compliance paperwork.

Audience

Who it is for

Management system implementers and coordinators

Executives and department heads accountable for management system performance

Those responsible for processes, policies, assets, risks and controls

Auditors seeking insight into management-side practice, not audit technique

Consultants working on management system design, governance or improvement

Decision supportIs this module for you?

It is a good fit if you…

need risk information to support real priorities, decisions and follow-through.

see risks, findings, incidents or unresolved actions that are visible but not acted on decisively.

want to improve how risk is structured, escalated, treated, monitored or accepted.

need a risk approach that works across management systems without becoming bureaucracy.

want to practise judgement, proportionality and governance thinking in a realistic case context.

It may not be the best fit if you…

want a short overview of risk terminology or ISO clause requirements only.

are mainly looking for software configuration or a risk-register tool tutorial.

need advanced quantitative risk modelling as the main focus.

expect a checklist method that removes the need for contextual judgement.

are not in a position to influence, evaluate or challenge how risk decisions are made.

Agenda

What is taught

7 parts
01Risk as Governance Work

The purpose of risk management in management systems

Why visible risks are often tolerated, fragmented or escalated too late

Connections between risk, uncertainty, obligations, objectives and decisions

02Risk Inputs and Structuring

Use context, stakeholders, obligations, objectives, incidents and findings as risk inputs

Distinguish risks from issues, causes, controls, impacts and actions

Write risk statements that support ownership and decisions

03Process Reality, Ownership and Escalation

Compare the documented risk process with how risk is actually handled

Diagnose weak ownership, passive tolerance and unclear authority

Decide when risk needs escalation rather than local administration

04Granularity, Aggregation and Prioritisation

Calibrate the right level of risk detail for teams, functions and executives

Group related signals without hiding important differences

Build a risk picture that supports prioritisation rather than noise

05Criteria, Comparability and Uncertainty

Define impact, likelihood and confidence consistently

Challenge false precision and inconsistent scoring

Use simple quantitative thinking to understand ranges, sensitivity and tail exposure

06Treatment, Controls and Acceptance

Compare treatment options against cost, effort, obligations and risk reduction

Distinguish treatment, monitoring, transfer and explicit acceptance

Make residual risk decisions visible, owned and reviewable

07Reporting, Monitoring and Improvement

Prepare risk information for governance conversations

Define reassessment triggers, escalation points and management-review inputs

Identify targeted improvements to the risk process itself

Outcomes

Learning outcomes

01

Structure risk information from context, objectives, obligations, incidents, findings and operational signals

02

Analyse and prioritise risks using criteria, evidence confidence, uncertainty and proportionality

03

Translate risk analysis into treatment, monitoring, escalation or explicit acceptance decisions

Recognise when visible risks are fragmented, tolerated or escalated too late

Calibrate risk granularity for team, management and executive decision levels

Challenge vague risk statements, false precision and inconsistent scoring

Link risk treatment to controls, ownership, verification and residual exposure

Evaluate whether a documented risk process is working in practice and producing useful governance evidence

The practical reflexes this module trains

This module is built around practical reflexes rather than around a list of topics. A practical reflex is what a practitioner asks and does without being prompted, under pressure: whether an owner can actually act, whether an exposure is being accepted or merely tolerated, whether the criteria in use can carry the decisions they are asked to carry, and then the move that follows from the answer. Topics can be listed after a course; reflexes show up in the next register review, the next escalation and the next acceptance signature. Each reflex below is developed in the written module, practised on the case organisation's own material, and assessed in graded exercises that must be passed before the certificate is issued.

Real ownership and escalation

Test whether a named owner actually holds the authority and the resources to act, keep risk, control and treatment ownership apart, and recognise when an exposure needs escalating as a decision request rather than another status update.

Residual exposure and explicit acceptance

See where exposure is being carried rather than treated, accept that an organisation may run exposure deliberately to pursue its objectives, and insist that such acceptance is named, dated, reasoned and signed instead of arriving by inertia.

Risk criteria and acceptance authority

Design impact, likelihood and acceptance criteria proportionate to the organisation's size and decision needs, with named acceptance authority, escalation thresholds and a review cadence, and recognise the defects that make a framework unusable: scales that cannot be compared across units, criteria without decision consequence, and rules copied from elsewhere that nobody applies consistently.

Materials

The content and the assessment

Written module

The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.

Exercises

Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.

On completion

The assessed exercises must be passed before the certificate is issued.

Templates

You keep the artefacts

Included

Reusable artefacts you take into your own organisation, not exercise handouts, and all of them included in the module price.

Decision protocol one-pager setThe three named intervention protocols as one-page working documents, shipped as one set: Decide / Sign / Own (who decides, approves and owns the outcome); Three scenarios, never one (approval as a choice between explicit risk postures); Make the silence sign (tolerated exposure made named, dated, reasoned and reviewable).
Escalation and acceptance-authority design templateDesign template for escalation routes and risk acceptance authority: thresholds with named authorities, routes that end in a decision, non-overlapping authority spans, and criteria that carry decision consequence.
Executive risk picture templateExecutive reporting template: top risks with stated aggregation basis, escalation questions framed as decision requests, the explicit residual list, and the monitoring set.
Risk criteria and rating scale design templateCriteria design template: harmonised rating scales with observable anchors, acceptance criteria with decision consequences, and a reassessment-trigger and review-cadence column per criterion.
Risk register architecture templateRegister architecture template: parent/sub-risk structure with per-level owner assignment, a stated propagation rule, and a bounded executive top-risk view that cannot mask above-appetite children.
Three-scenario treatment framing templateTreatment framing template: minimum-vital, recommended and ambitious treatment scenarios, each costed and each with an explicit residual-exposure statement, turning approval into a choice between risk postures.
Monte Carlo workbook for uncertainty and tail exposureExcel Monte Carlo workbook: scenario assumptions in, expected annual loss, P90 and threshold-exceedance bands out - the uncertainty and tail-exposure analysis of the course as a reusable tool.

From

CHF 1,450

approx. €1,530 · invoiced in CHFapprox. £1,270 · invoiced in CHFapprox. US$1,800 · invoiced in CHF

No VAT is charged.

Includes 7 working artefacts you keep and reuse.

Book a course run

Payment by card or invoice · seat confirmed immediately

Bought from us before? Sign in to see your price and any track credit you hold.

Module facts

Module ID
HAM-AG-C-07
Domains
Controls · Decisions · Governance · Risk
Delivery
Live virtual
Download fact sheet (PDF, 2.8 MB) →

Case organisation

You work inside a company that already has the problem

Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.

Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.

Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes

Not a case study
Nothing is summarised for you; the evidence is where it would really be

It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after

It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions

Why it matters

Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.

How we teach →

Delivery & dates

How this module reaches you

Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.

Live virtualFree orientation on 25 August

25 August – 29 September 2026

English · 5 sessions, Tuesdays 14:00 Zurich time · plus a free 45-minute orientation

CHF 1,450

Book this run

FAQ

Good to know

Do I need a risk management background to take part?

No formal prerequisites apply, because the module is designed to work as a standalone entry point into practical risk governance for management systems; general familiarity with organisational processes, roles, responsibilities and operational decision-making is helpful, but nothing beyond that is assumed.

Is the module tied to a particular standard?

No. It is standard-agnostic and works across the management-system standards you already operate under, including ISO 9001, ISO 14001, ISO/IEC 27001, ISO 22301 and ISO/IEC 42001 as well as regulatory contexts such as NIS2 and DORA, because what it trains is the judgement behind risk work rather than the clause requirements of any one standard; the vocabulary it works in is ISO 31000's, ISO's cross-discipline guidance on managing risk and the one standard here that nobody certifies against.

Is the module useful for auditors as well as for managers?

Yes, and it is a mandatory step in both the auditor and the manager track, because judging whether risk information is structured, owned and accepted well enough to support a decision is the same work whether you are building that information or examining it.

Follow-up modules

Where this module leads next

Modules that build on this one. Each is self-contained; a professional track sequences them for you.

None of the dates work?

We will tell you when the next run is scheduled, or run this module in-house with your own case material.

Not sure it is the right module?

Describe your context in a short message and we will tell you honestly.

Free · no obligation

25 August, 14:00 Zurich · 45 minutes. Meet the trainer, see the case organisation and the session plan, and ask whatever you need before deciding. We send the joining link by email.
About Risk Management · HAM-AG-C-07

No account and no payment details needed. Sending is not switched on yet, so write to us in the meantime: contact us.

No obligation

Tell us what would work and we will come back with dates, or with an in-house proposal if you would rather run this for a group on your own management system.
About Risk Management · HAM-AG-C-07

No account needed. We reply personally, usually within a working day. Sending is not switched on yet, so write to us in the meantime: contact us.

Decision support

Describe your role and your context in a short message and we will tell you honestly whether this module is the right one, or point you at a better fit.
About Risk Management · HAM-AG-C-07

No account needed. We reply personally, usually within a working day. What happens to your message is set out in the privacy policy.