Programmes · Enterprise Risk Management and Risk-Based Internal Auditing
About this programme
Every organisation faces strategic, operational, financial and compliance risks capable of quietly derailing its objectives. Internal audit is at its most valuable when it is pointed squarely at those risks — and at its least valuable when it works through a plan inherited from last year.
This one-day intensive teaches you to make that connection deliberately. You will learn to identify and categorise the risks that genuinely threaten organisational objectives, apply both qualitative and quantitative assessment techniques, and weigh likelihood against impact well enough to prioritise what management should address first.
From there the programme moves to the practical artefacts: building and maintaining a risk register people actually use, assigning genuine risk ownership, documenting mitigating controls, and tracking residual risk continuously rather than at year-end. The later sessions turn that register into an audit plan — prioritising focus areas by real risk exposure and aligning the plan with what the register says.
The day closes with a group case exercise in which participants assess a set of organisational risks, build a sample risk register and draft a risk-based internal audit plan, so you leave having done the work rather than only having heard it described.
Taught from first principles, the programme suits newcomers and experienced professionals alike — including those looking to formalise an approach they have been running on instinct. No prior risk-management or audit certification is required.
What you will learn
- Explain core enterprise risk management concepts
- Identify and categorise the risks that may affect organisational objectives
- Apply practical risk-assessment techniques
- Develop and maintain an effective risk register
- Assign risk ownership and document mitigating controls
- Assess and track residual risk
- Prioritise internal audit areas based on risk exposure
- Align a risk-based internal audit plan with the organisation’s risk register
Who should attend
- Internal and external auditors seeking to strengthen their risk-based audit planning skills
- Risk officers and risk management professionals
- Finance managers and controllers with responsibility for organisational risk
- Compliance officers responsible for enterprise risk frameworks
Also suitable for
- ICAG, ACCA, and CIA students seeking practical audit and risk-management skills
- Business owners and executives seeking stronger organisational risk oversight
- Consultants advising on internal controls, governance, or risk management
Programme curriculum
Session 1
Risk Concepts and Types of Risk
- Core risk-management terminology and concepts
- Strategic, operational, financial, and compliance risks
- How different risks affect organisational objectives
Session 2
Risk Assessment Techniques
- Identifying, analysing, and evaluating risks
- Qualitative and quantitative assessment methods
- Likelihood and impact analysis
- Prioritising risks for management attention
Session 3
Developing a Risk Register
- Building and maintaining a risk register
- Documenting identified risks
- Assigning risk ownership
- Recording mitigating controls
- Monitoring residual risk over time
Session 4
Risk-Based Internal Audit Planning
- Applying a risk-based approach to internal audit planning
- Prioritising audit focus areas according to risk exposure
- Aligning the audit plan with the organisation’s risk register
Session 5
Practical Group Exercise
- Assess organisational risks
- Develop a sample risk register
- Draft a risk-based internal audit plan
Participants work through a practical case study covering all three deliverables above.
Course format
- Course code
- ERM1
- Delivery
- Live, instructor-led session via Zoom
- Duration
- One-day intensive training
- Certification
- Verifiable Certificate of Completion
- Learner portal
- Personal portal for the meeting link, resources, and course materials
- Facilitator
- Mr. Isaac Adjin Bonney, CA, CPFA, CFIP
Prerequisites
- No prior risk-management or audit certification is required.
- A general understanding of business operations will be helpful. The course is taught from first principles and is suitable for newcomers as well as experienced professionals seeking to formalise their approach.
What your registration includes
- A live, instructor-led one-day intensive session
- Guided teaching across five structured sessions
- A practical group case exercise
- Course resources and materials
- Access to a personal learner portal
- A verifiable Certificate of Completion
- A credential anyone can confirm through our public certificate verification page.
Training a team?
Companies registering four or more participants receive a 15% discount, plus a Corporate Portal to track attendance, download certificates, and manage employees from one account.
Frequently asked questions
Is prior risk-management experience required?
No. The programme begins with foundational concepts and is suitable for both newcomers and experienced professionals.
How will the programme be delivered?
The training will be delivered live and interactively through Zoom.
Will I receive course materials?
Yes. Each participant will receive access to a personal learner portal containing the meeting link, session resources, and course materials.
Will I receive a certificate?
Yes. Participants who complete the programme will receive a verifiable Certificate of Completion.
