Course overview
Risk governance is the part of risk management that determines who is allowed to take what, who has to be told, and who answers when it goes wrong. It is distinct from risk assessment technique. An organization can assess risk beautifully and still govern it badly, because the person with the revenue target can proceed regardless of what the assessment said, and no one with authority is required to sign off on the exposure.
This course examines governance structures across the enterprise: the board mandate, committee architecture, the role and independence of the risk function, the integration of risk into strategy and capital decisions, oversight and assurance, and the accountability culture that decides whether any of it binds. It draws on ISO 31000, COSO ERM, the Three Lines Model, and corporate governance codes as applied to risk oversight.
Why governance is the binding constraint
After most large corporate failures, the risk had been identified. It appears in a register, sometimes in a board paper. What was missing was a mechanism that forced a decision: an appetite limit that made the exposure impermissible, an escalation route that could not be blocked, or an accountable executive who had to personally accept the risk in writing.
Regulators have noticed. Governance codes and supervisory expectations increasingly ask about decision rights, the independence of the risk function, the board's information quality, and whether the risk officer can reach the board without the chief executive's permission. Those are governance questions, not assessment questions.
Course objectives
By the end of the course, participants will be able to:
- Allocate decision rights across the board, executives and owners.
- Appoint a risk function able to say no and make it stick.
- Authorize an exposure only at the threshold set for it.
- Gate a major investment against a limit drawn from appetite.
- Constrain incentives so they do not reward breaching a limit.
- Inform a board with a paper it can act on.
- Convene oversight arrangements without duplication or gaps.
- Overrule an executive who breaches an approved limit.
- Decide who carries accountability through a restructure.
Course outline
Unit 1: Foundations of enterprise risk governance
- Risk governance as oversight, not process and technique.
- Corporate governance codes and supervisory expectations.
- Decision rights, thresholds and who may accept exposure.
- A limit that nobody enforced and the loss that followed.
Unit 2: Governance structures and accountability
- Committee mandates and the information a board may demand.
- The chief risk officer's reporting line and independence.
- Risk ownership and what an accountable owner must evidence.
- Delegated authority and the record of a formal acceptance.
Unit 3: Integrating risk governance with strategy
- Risk appetite cascaded into capital allocation and limits.
- Strategic options weighed against the exposure they create.
- Questions asked before a major transaction, not after.
- Rewarding the year in which a limit was respected.
Unit 4: Oversight, monitoring, and assurance
- The scrutiny a board keeps and the work it delegates.
- Board papers that change a decision and those that do not.
- Evidence a committee needs before it accepts a report.
- Scrutiny of the function that scrutinizes everyone else.
Unit 5: Building a culture of risk responsibility
- Accountability for a decision taken under pressure.
- Decisions taken outside a mandate and how they surface.
- Handling the executive who overrides a limit.
- Handing a live exposure to a successor with its history.
How the course is delivered
Sessions are discussion-led around documented material: governance charters, board risk reports, delegated authority matrices and published post-failure inquiry findings that participants analyze and debate. Worked examples take a governance structure apart and rebuild it around decision rights. The course is educational: it does not certify participants, does not assess any organization's governance, and is not legal advice. Participants who want the compliance dimension in more depth should look at Governance, Risk, and Compliance (GRC) Frameworks.
Who should attend
- Board members, risk committee members and company secretaries.
- Chief risk officers and senior risk managers responsible for governance arrangements.
- Executives who own risks and hold delegated authority to accept them.
- Internal auditors and compliance leaders who assess governance quality.
About EuroQuest International Training
EuroQuest International Training was founded in 2015 by a team with more than 25 years of experience in professional development. We deliver over 1,000 courses and have trained more than 15,000 participants, from our head office in Bratislava, Slovakia, and hubs in Dubai, London, Barcelona, Istanbul, Vienna, Paris and Geneva. Courses are written and reviewed by practitioners from the fields they cover.
Frequently asked questions
How is this different from an enterprise risk management course?
ERM covers the process: identify, assess, treat, monitor. This course covers the authority structure around that process: who decides, who oversees, who is accountable, and what happens when a limit is breached.
Is it relevant outside listed companies?
Yes. Family businesses, public bodies and private companies all face the question of who may accept an exposure on the organization's behalf. The formality differs; the decision rights problem does not.
Does the course provide legal guidance on directors' duties?
It describes governance expectations in general terms and uses codes as reference material. It is educational and is not legal advice; directors' duties in your jurisdiction should be confirmed with qualified counsel.
Related courses
- Enterprise Risk Management Strategies
- Developing Risk Management Frameworks
- Auditing Risk and Compliance Practices
- Ethical Leadership and Risk Governance
Register for this course
Select a city and date from the schedule above to register, or contact EuroQuest about in-house delivery for a board, risk committee or executive team.
All Course Dates & Locations
29 dates · 14 cities · Sep 2026 – Jul 2027