Course overview
Enterprise risk management was supposed to give boards a single view of what could stop the organization achieving its objectives. In many companies it has become a compliance exercise: a register of eighty risks, each rated amber, each owned by a director who inherited it, reviewed quarterly by people who already knew what was on it. The register is complete, the meeting is held, and no decision changes as a result.
This course treats ERM as a decision-support system rather than a reporting obligation. It covers the frameworks that structure it, the identification and assessment methods that populate it, the appetite statements that give it teeth, and the governance that decides who is allowed to accept which exposure. Reference points include ISO 31000, the COSO Enterprise Risk Management framework, and the risk governance expectations that regulators and stock exchanges now apply to listed companies.
Why most risk registers do not work
Three failures recur. Risks are written as topics instead of as events with a cause and a consequence, so nobody can test whether they are getting worse. Risk appetite is stated in language too abstract to reject any actual proposal. And residual ratings are lowered on the strength of mitigations that exist only as plans. The result is a document that describes an organization's intentions rather than its exposure.
The environment has also become less forgiving. Supply chain concentration, cyber dependency, climate exposure and geopolitical disruption interact in ways a siloed register cannot capture. Organizations that connect risk to strategy, capital and decision rights get early warning. Organizations that keep risk in a separate quarterly meeting find out at the same time as everyone else.
Course objectives
By the end of the course, participants will be able to:
- Frame enterprise risk above any single risk type or function.
- Steer framework choice to what the organization can sustain.
- Articulate each exposure as a cause and a consequence.
- Rank exposures by severity where the data supports it.
- Cascade appetite and tolerance from the board to the front line.
- Report exposure so the board can act on the same day.
- Own the residual exposure the group is left carrying.
- Convene a crisis team with the authority to decide quickly.
- Aggregate local registers into a single enterprise picture.
- Consolidate sustainability exposure into the same appetite.
- Debate risk culture using evidence rather than assertion.
- Accept a level of exposure formally and record it in writing.
Course outline
Unit 1: Introduction to enterprise risk management
- Risk, uncertainty and exposure defined under challenge.
- The move from a control activity to a strategic capability.
- The accountability that stops at one person, not a committee.
- Stalled registers and amber ratings that mean nothing.
Unit 2: ERM frameworks and standards
- ISO 31000 and its deliberately non-prescriptive design.
- One framework applied across many operating units.
- Risk governance codes and rules for listed companies.
- Adapting a framework without the bureaucracy it invites.
Unit 3: Risk identification and categorization
- Workshops, interviews and loss data as starting points.
- Turning a vague heading into a cause and a consequence.
- Risk taxonomy shared by every business and function.
- Tracking emerging risk before it reaches the register.
Unit 4: Risk assessment and analysis
- Qualitative scales and what a five-by-five matrix hides.
- Monte Carlo methods where the data supports them.
- Stress testing and the trigger that defines the scenario.
- Inherent, current and residual exposure side by side.
Unit 5: Risk appetite and tolerance
- What appetite means when capacity and limits differ.
- Wording appetite so it can actually block a proposal.
- Risk appetite turned into limits a manager cannot exceed.
- Breach handling and the record of who approved it.
Unit 6: Governance and oversight in ERM
- What a risk committee must see before it can decide.
- Chief risk officer, risk owners and independent assurance.
- Risk policy, mandate and a route past a blocking executive.
- Integrating risk into planning and capital allocation.
Unit 7: Risk mitigation and control strategies
- Treatment choices seen across the whole portfolio.
- Control coverage across the enterprise risk portfolio.
- Exposure retained by the group and exposure passed on.
- Mitigation approved and then quietly never done.
Unit 8: Crisis preparedness and resilience
- Continuity planning for the services the group cannot lose.
- Who takes the decision when the crisis clock starts.
- Messages to staff, regulators and the market in a crisis.
- Post-event review and what it changes in the register.
Unit 9: Digital tools in ERM
- Risk platforms and the work they do not remove.
- Register consolidation across dozens of business units.
- Incident logs and external feeds as risk data sources.
- Board dashboards and the presentation choices that mislead.
Unit 10: ESG and sustainability in ERM
- Climate exposure entering the group register.
- Environmental and social obligations across the group.
- Regulator and investor pressure on ESG exposure.
- Bringing ESG risks into the same register and appetite.
Unit 11: Global best practices in ERM
- Embedding risk into the gates where money is committed.
- Risk culture seen in waivers, escalations and near misses.
- ERM maturity models and independent review of the function.
- Turnaround steps a failing risk function takes first.
Unit 12: Capstone case study
- Building a register and taxonomy for the case organization.
- Assessing top exposures and drafting an appetite statement.
- Designing continuity for the two most severe scenarios.
- Defending the board risk report and the exposure accepted.
How the course is delivered
The course runs as guided analysis of documented material: real risk registers, appetite statements, board risk reports and post-incident reviews that participants examine and rebuild in discussion. Worked examples take assessment and quantification decisions step by step, and the closing unit runs as an extended case discussion. The course is educational and does not certify participants, assess any organization's risk framework, or constitute financial or legal advice. Those who need to build the framework document itself will find Developing Risk Management Frameworks a direct companion.
Who should attend
- Risk managers and chief risk officers building or repairing an ERM framework.
- Internal auditors and compliance professionals who assess risk management quality.
- Finance, strategy and operations leaders who own risks in the first line.
- Board and risk committee members who receive and challenge risk reporting.
About EuroQuest International Training
EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We deliver over 1,000 courses and have trained more than 15,000 participants. Our head office is in Bratislava, Slovakia, with hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Courses are written and reviewed by practitioners from the fields they cover.
Frequently asked questions
Do I need a quantitative background?
No. Quantified methods such as value at risk and Monte Carlo analysis are explained conceptually, with attention to when they are justified and when they create false precision. The course does not require statistical training.
Is the course tied to ISO 31000 or to COSO?
Both are covered and compared, because organizations use them differently and often together. The course does not push one framework as the only correct answer.
Will I be certified as a risk manager?
No. You receive a EuroQuest attendance certificate. The course is educational and does not provide a professional risk certification or assess your organization's framework.
Related courses
- Enterprise-Wide Risk Governance Strategies
- Financial Risk Assessment and Management
- Crisis Management and Risk Leadership
- Digital Risk Management and Business Continuity
Register for this course
Choose a city and date from the schedule above to register, or contact the EuroQuest team about in-house delivery for a risk function and its business risk owners together.
All Course Dates & Locations
18 dates · 14 cities · Oct 2026 – Jul 2027