What you'll learn:
- The risk management framework of ISO 31000
- Principles of risk management
- Selection of the risk assessment techniques
- Risk techniques of IEC 31010
- Risk treatment options
ISO 31000 is the international standard for risk management — the framework and principles used worldwide for enterprise risk management (ERM) in organizations of every type and size. Its companion standard, IEC 31010, provides the toolbox: dozens of risk assessment techniques for identifying, analysing and evaluating risk. This course teaches both.
After completing the lessons you will understand the principles of risk management, the ISO 31000 framework and process, how to select and apply risk assessment techniques, and the options available for risk treatment.
Course structure
Risk management and the ISO 31000 framework — general concepts, the structure of the standard, and how the framework integrates risk management into the organization
The principles of risk management — the eight principles that make risk management effective
Leadership and commitment — the support and involvement of top management in the risk management process
The risk assessment process — risk identification, risk analysis and risk evaluation, and how to select the appropriate technique for each situation
The risk techniques of IEC 31010
The core of the course: the risk assessment techniques of IEC 31010, each explained in an easy-to-understand way with simple examples, including:
Brainstorming, structured and semi-structured interviews, and the Delphi technique
HAZOP (hazard and operability study) and HACCP (hazard analysis and critical control points)
Business impact analysis (BIA) and root cause analysis (RCA)
FMEA and FMECA — failure modes, effects (and criticality) analysis
Fault tree analysis, event tree analysis, and cause–consequence analysis
Cause-and-effect analysis and bow tie analysis
Reliability-centred maintenance and Markov analysis
Monte Carlo simulation
The consequence/probability matrix (risk matrix)
Cost–benefit analysis and multi-criteria decision analysis
and others
Risk treatment and beyond
The final part of the course covers the risk treatment options, the concepts of residual risk and secondary risk, and the monitoring and continual improvement of the risk management process. A quiz at the end lets you test your understanding.
Who this course is for
Risk managers and risk analysts building a structured, standards-based foundation
Professionals implementing enterprise risk management (ERM) programs
Quality, safety, security and compliance professionals — risk assessment is the engine of every ISO management system (ISO 9001, ISO 14001, ISO 45001, ISO/IEC 27001)
Project managers, engineers and business analysts who need practical risk assessment techniques
Auditors and consultants evaluating risk management processes
Learn how to develop and apply a risk management process following the framework of ISO 31000 — with the full IEC 31010 toolbox at your disposal.