Training module
Risk Management
Build the capability to surface, structure and act on risk while action is still possible
Risk management that holds up in decisions
Develop the practical judgement behind effective risk work: structuring ambiguity, calibrating granularity, challenging false precision, escalating proportionately, and translating uncertainty into treatment, monitoring or explicit acceptance decisions.
Overview
What this module is about
In many organisations, the most important risks are not invisible. They are already present in audit findings, operational workarounds, customer pressure, supplier dependencies, unresolved actions, and management review discussions. The problem is that they are often fragmented, tolerated, poorly structured, or escalated too late.
This module develops the practical judgement needed to make risk management useful in real management-system work. Participants learn how to turn messy inputs into clear risk structures, calibrate granularity, challenge weak scoring, distinguish treatment from acceptance, and prepare risk information that supports proportionate action, monitoring, escalation and governance decisions.
The module uses a realistic organisational case to let participants practise these judgements in context, without reducing risk management to templates, scoring exercises or compliance paperwork.
Audience
Who it is for
Management system implementers and coordinators
Executives and department heads accountable for management system performance
Those responsible for processes, policies, assets, risks and controls
Auditors seeking insight into management-side practice, not audit technique
Consultants working on management system design, governance or improvement
Decision supportIs this module for you?
It is a good fit if you…
need risk information to support real priorities, decisions and follow-through.
see risks, findings, incidents or unresolved actions that are visible but not acted on decisively.
want to improve how risk is structured, escalated, treated, monitored or accepted.
need a risk approach that works across management systems without becoming bureaucracy.
want to practise judgement, proportionality and governance thinking in a realistic case context.
It may not be the best fit if you…
want a short overview of risk terminology or ISO clause requirements only.
are mainly looking for software configuration or a risk-register tool tutorial.
need advanced quantitative risk modelling as the main focus.
expect a checklist method that removes the need for contextual judgement.
are not in a position to influence, evaluate or challenge how risk decisions are made.
Agenda
What is taught
7 parts01Risk as Governance Work
The purpose of risk management in management systems
Why visible risks are often tolerated, fragmented or escalated too late
Connections between risk, uncertainty, obligations, objectives and decisions
02Risk Inputs and Structuring
Use context, stakeholders, obligations, objectives, incidents and findings as risk inputs
Distinguish risks from issues, causes, controls, impacts and actions
Write risk statements that support ownership and decisions
03Process Reality, Ownership and Escalation
Compare the documented risk process with how risk is actually handled
Diagnose weak ownership, passive tolerance and unclear authority
Decide when risk needs escalation rather than local administration
04Granularity, Aggregation and Prioritisation
Calibrate the right level of risk detail for teams, functions and executives
Group related signals without hiding important differences
Build a risk picture that supports prioritisation rather than noise
05Criteria, Comparability and Uncertainty
Define impact, likelihood and confidence consistently
Challenge false precision and inconsistent scoring
Use simple quantitative thinking to understand ranges, sensitivity and tail exposure
06Treatment, Controls and Acceptance
Compare treatment options against cost, effort, obligations and risk reduction
Distinguish treatment, monitoring, transfer and explicit acceptance
Make residual risk decisions visible, owned and reviewable
07Reporting, Monitoring and Improvement
Prepare risk information for governance conversations
Define reassessment triggers, escalation points and management-review inputs
Identify targeted improvements to the risk process itself
Outcomes
Learning outcomes
01
Structure risk information from context, objectives, obligations, incidents, findings and operational signals
02
Analyse and prioritise risks using criteria, evidence confidence, uncertainty and proportionality
03
Translate risk analysis into treatment, monitoring, escalation or explicit acceptance decisions
Recognise when visible risks are fragmented, tolerated or escalated too late
Calibrate risk granularity for team, management and executive decision levels
Challenge vague risk statements, false precision and inconsistent scoring
Link risk treatment to controls, ownership, verification and residual exposure
Evaluate whether a documented risk process is working in practice and producing useful governance evidence
The practical reflexes this module trains
This module is built around practical reflexes rather than around a list of topics. A practical reflex is what a practitioner asks and does without being prompted, under pressure: whether an owner can actually act, whether an exposure is being accepted or merely tolerated, whether the criteria in use can carry the decisions they are asked to carry, and then the move that follows from the answer. Topics can be listed after a course; reflexes show up in the next register review, the next escalation and the next acceptance signature. Each reflex below is developed in the written module, practised on the case organisation's own material, and assessed in graded exercises that must be passed before the certificate is issued.
Real ownership and escalation
Test whether a named owner actually holds the authority and the resources to act, keep risk, control and treatment ownership apart, and recognise when an exposure needs escalating as a decision request rather than another status update.
Residual exposure and explicit acceptance
See where exposure is being carried rather than treated, accept that an organisation may run exposure deliberately to pursue its objectives, and insist that such acceptance is named, dated, reasoned and signed instead of arriving by inertia.
Risk criteria and acceptance authority
Design impact, likelihood and acceptance criteria proportionate to the organisation's size and decision needs, with named acceptance authority, escalation thresholds and a review cadence, and recognise the defects that make a framework unusable: scales that cannot be compared across units, criteria without decision consequence, and rules copied from elsewhere that nobody applies consistently.
Materials
The content and the assessment
Written module
The full content in writing, complete in itself. Videos are recorded for parts of it as an alternative way through, and the written module always carries everything.
Exercises
Graded work on the case organisation's own registers: structured answers checked against the encoded case, written answers scored against a rubric traced to it, with a trainer holding the final word on every assessed item.
On completion
The assessed exercises must be passed before the certificate is issued.
Templates
You keep the artefacts
IncludedReusable artefacts you take into your own organisation, not exercise handouts, and all of them included in the module price.
From
CHF 1,450
No VAT is charged.
Includes 7 working artefacts you keep and reuse.
Book a course runPayment by card or invoice · seat confirmed immediately
Bought from us before? Sign in to see your price and any track credit you hold.
Module facts
- Module ID
- HAM-AG-C-07
- Discipline
- Cross-discipline
- Domains
- Controls · Decisions · Governance · Risk
- Part of tracks
- Management System Auditor · Management System Manager
- Delivery
- Live virtual
Case organisation
You work inside a company that already has the problem
Exercises run on one case organisation, carried across modules rather than restarted, so what you build here is what the next module finds.
Northstar Integrated Services AG is a group headquartered in Zurich, providing digital operations platforms and managed services to regulated organisations across Europe. It has not always been that. It began in 2008 as a field-operations firm of about twenty-five people, and what first forced documented decisions and named accountability on it was not growth but a single regulated customer. It now runs an acquired business in Poland and the Czech Republic through a subsidiary that kept its own legal identity, which is where the interesting failures live: group instruments rolled out operationally and never put in force by the governing bodies of the subsidiary itself.
Linked registers
Organisation and people, risks, objectives, policies and documents, findings and reviews, third parties, processes
Not a case study
Nothing is summarised for you; the evidence is where it would really be
It has a history
The organisation has a timeline, and modules enter it at different points, so a structure can be studied before it broke as well as after
It crosses borders
A Swiss parent, an acquired operating business in Poland and the Czech Republic under its own legal entity, and customers in several jurisdictions
Why it matters
Judgement is not trained on tidy examples, and it is not trained on a fresh one each week. Northstar is deliberately untidy, and modules enter it at different points of its history, so you see a governance structure being built, outgrown and rebuilt rather than a finished one. What you decide in one module is what the next one finds.
Delivery & dates
How this module reaches you
Delivered live online, combining conceptual framing, discussion, case work and direct interaction with the trainer. In-house and contextualised delivery is available on request.
CHF 1,450
Sessions · ZURICH
- Miss a session?
- The written module carries the full content, so nothing is lost. The sessions themselves are not recorded.
Trainer for this run
Dominik LangerManagement systems practitioner
Implements and audits management systems, and has carried executive accountability for the decisions they produce. He led an ISO/IEC 27001 information security management system and an ISO 14001 environmental management system from design through to certification, sat on the board that carried the integrated system, and audits to ISO/IEC 27001 and ISO/IEC 42001. What he teaches is the part that outlasts the standard: how a method survives contact with a decision somebody has to sign.
Risk, governance and decision-making at strategic depth, controls at applied: the four capabilities this module develops are the four he has had to hold together in one job. He built the risk assessment and control framework of an ISO/IEC 27001 system he then took through certification, and sat on the board that had to live with what it produced. He holds CRISC and CISM, audits to ISO/IEC 27001 and 42001, and has taken cloud risk work through to supervisory outsourcing approval, which is the point at which a risk assessment stops being an internal document and has to survive somebody else's reading of it.
He wrote this module, teaches its live sessions, and has the final word on its exercises.
The orientation on 25 August is free and carries no obligation: meet the trainer, see the case organisation and decide afterwards.
FAQ
Good to know
Do I need a risk management background to take part?
No formal prerequisites apply, because the module is designed to work as a standalone entry point into practical risk governance for management systems; general familiarity with organisational processes, roles, responsibilities and operational decision-making is helpful, but nothing beyond that is assumed.
Is the module tied to a particular standard?
No. It is standard-agnostic and works across the management-system standards you already operate under, including ISO 9001, ISO 14001, ISO/IEC 27001, ISO 22301 and ISO/IEC 42001 as well as regulatory contexts such as NIS2 and DORA, because what it trains is the judgement behind risk work rather than the clause requirements of any one standard; the vocabulary it works in is ISO 31000's, ISO's cross-discipline guidance on managing risk and the one standard here that nobody certifies against.
Is the module useful for auditors as well as for managers?
Yes, and it is a mandatory step in both the auditor and the manager track, because judging whether risk information is structured, owned and accepted well enough to support a decision is the same work whether you are building that information or examining it.
Follow-up modules
Where this module leads next
Modules that build on this one. Each is self-contained; a professional track sequences them for you.
None of the dates work?
We will tell you when the next run is scheduled, or run this module in-house with your own case material.
Not sure it is the right module?
Describe your context in a short message and we will tell you honestly.