Business Continuity Risk Assessment and Governance Fundamentals Training Course

5 days Business Continuity Certificate on completion
Course codeSD-BC-012
Duration5 days
LevelIntermediate
CategoryBusiness Continuity
DeliveryClassroom or live online
LanguageEnglish
CertificateCertificate of completion

Course overview

Business continuity programmes often fail at the point where risk information must be converted into defensible priorities, recovery requirements and management decisions. Teams may hold a business impact analysis (BIA), risk register and emergency plans, yet lack a consistent way to identify disruption scenarios, set recovery time objectives, assess supplier dependencies or present residual risk to senior leadership. This course addresses the governance gap between operational risk assessment and an auditable, actionable business continuity management system (BCMS).

Participants learn to structure a continuity risk assessment using ISO 31000 principles and ISO 22301 requirements; define risk criteria; identify internal, external, digital, site, people and third-party disruption scenarios; and evaluate likelihood, consequence and control effectiveness. They practise linking risk assessment findings to BIA outputs, maximum acceptable outage, recovery time objectives (RTOs), recovery point objectives (RPOs), treatment plans, continuity strategies, ownership and escalation thresholds. The course also covers governance roles, BCMS policy, reporting dashboards, assurance activity and management review.

Instructor-led briefings are combined with worked examples, spreadsheet-based scoring, scenario workshops and peer review of continuity decisions. Across the week, participants build a continuity risk assessment pack for a realistic operating unit, including a risk appetite statement, scoring matrix, scenario register, treatment plan, governance RACI and executive reporting format. This practical pack can be adapted as a starting point for use in their own organisation.

The course is suited to practitioners who already contribute to resilience, risk, safety, security, IT service continuity or operational assurance and now need a disciplined method for governing business continuity risk.

Course objectives

By the end of this course, participants will be able to:

  • Define business continuity risk criteria, appetite statements and escalation thresholds aligned to ISO 22301 governance requirements
  • Construct a disruption scenario register covering people, premises, technology, suppliers, utilities and regulatory dependencies
  • Apply likelihood, consequence and control-effectiveness scoring to produce a prioritised continuity risk register
  • Link business impact analysis outputs to maximum acceptable outage, recovery time objectives and recovery point objectives
  • Evaluate existing preventive, response and recovery controls using residual-risk and control-gap analysis
  • Develop proportionate risk treatment plans with named owners, milestones, resource requirements and acceptance decisions
  • Create a BCMS governance RACI, management-review agenda and risk reporting dashboard for senior decision-makers
  • Present a documented continuity risk assessment pack that supports strategy selection, assurance and audit evidence

Benefits of attending

For you

  • Gain a defensible method for converting disruption scenarios into prioritised continuity actions
  • Produce risk scoring and treatment documentation that can withstand management and audit scrutiny
  • Build confidence challenging unrealistic recovery assumptions, unowned dependencies and weak controls
  • Strengthen credibility when briefing executives on residual risk, risk acceptance and continuity investment
  • Prepare practical evidence for progression into business continuity, resilience, operational risk or assurance roles

For your organisation

  • Creates a consistent basis for assessing disruption risks across sites, functions and critical services
  • Improves alignment between risk registers, BIA results, recovery objectives and continuity strategies
  • Makes risk ownership, treatment deadlines and acceptance decisions visible to accountable leaders
  • Reduces overlooked exposure from third parties, utilities, single points of failure and shared services
  • Provides structured governance evidence for ISO 22301 programmes, internal audit and management review

Target competencies

Continuity risk scoringBIA integrationControl gap analysisRisk treatment planningBCMS governance designExecutive risk reporting

Who should attend

  • Business Continuity Managers — who need a repeatable method for prioritising disruption risks and governing the BCMS
  • Operational Risk Managers — who must connect enterprise risk registers with recovery requirements and resilience actions
  • HSE Managers — who assess operational disruption, duty-of-care exposures and emergency preparedness arrangements
  • Resilience and Crisis Management Officers — who need to translate scenarios into accountable prevention and recovery measures
  • IT Service Continuity Managers — who must align technology recovery objectives with business impact and risk decisions
  • Internal Auditors and Compliance Officers — who review continuity controls, management oversight and ISO 22301 evidence

Requirements and prerequisites

Participants should understand their organisation’s core products or services, key operational dependencies and current continuity or emergency arrangements. Familiarity with basic risk-register fields—risk event, likelihood, consequence, control, owner and action—is assumed, as is confidence reading simple spreadsheets. Prior exposure to a business impact analysis, incident management plan, ISO 22301 or ISO 31000 is helpful but not essential; these concepts are introduced and applied during the course. No certification, specialist continuity software, statistical modelling experience or prior audit experience is required. Complete beginners should expect a structured intermediate-level pace and should review their organisation’s risk or continuity documents beforehand.

Training methodology

The course uses instructor-led explanation of ISO 22301, ISO 31000 and ISO 22317 concepts, followed by guided application to a running disruption case. Participants work individually and in small groups to define risk criteria, score scenarios in Microsoft Excel, challenge control assumptions, map dependencies and choose treatment responses. Facilitated case discussions focus on decisions that continuity managers must defend: recovery priorities, risk acceptance, investment justification and escalation. Each day ends with a practical output, culminating in an individual application plan for adapting the assessment pack to a live organisational area.

Course outline

Day 1: Continuity risk foundations and governance context

  • Business continuity risk versus operational, enterprise and emergency management risk
  • ISO 22301:2019 clauses for leadership, planning, performance evaluation and improvement
  • ISO 31000:2018 principles, framework and risk management process
  • BCMS scope statements, interested parties and continuity governance boundaries
  • Risk appetite, tolerance, capacity and acceptance authority
  • Risk criteria for safety, service, financial, legal, environmental and reputational consequences
  • Three-lines roles, accountability and escalation within continuity governance

Workshop: Participants draft risk criteria, a risk appetite statement and an approval hierarchy for the course case organisation.

Day 2: Scenario identification and business impact integration

  • Structured scenario identification using PESTLE, dependency mapping and horizon scanning
  • Disruption categories covering workforce, facilities, IT, cyber, suppliers, utilities and transport
  • Business impact analysis inputs: critical activities, impact categories and maximum acceptable outage
  • Recovery time objectives, recovery point objectives and minimum business continuity objectives
  • Process, asset, data, people and third-party dependency mapping
  • Single points of failure and concentration-risk identification
  • ISO 22317:2021 guidance for business impact analysis and continuity priorities

Workshop: Teams create a disruption scenario register and dependency map for a critical service, linking each scenario to BIA impacts.

Day 3: Assessment, controls and residual risk

  • Inherent-risk, residual-risk and target-risk definitions
  • Likelihood scales, consequence scales and qualitative risk matrices
  • Control design, operating effectiveness and control-assurance evidence
  • Preventive, detective, response and recovery control categories
  • Risk aggregation, interdependency and cascading-failure considerations
  • Microsoft Excel risk register formulas, conditional formatting and heat-map views
  • Risk validation workshops and challenge questions for subject-matter experts

Workshop: Participants score prioritised scenarios in a spreadsheet risk register, assess control effectiveness and identify residual-risk gaps.

Day 4: Treatment strategies and BCMS decision-making

  • Risk treatment options: avoid, reduce, transfer, accept and prepare
  • Continuity strategy selection for alternate sites, remote work, manual workarounds and redundancy
  • Supplier continuity due diligence, contractual recovery requirements and exit planning
  • Treatment-plan design with owners, milestones, budget assumptions and completion evidence
  • Cost, benefit and feasibility tests for resilience investment decisions
  • Formal risk acceptance, exception registers and review dates
  • Linking treatment actions to incident, crisis, recovery and exercise plans

Workshop: Each group develops a prioritised treatment plan and presents a recommendation for accepting, reducing or transferring selected risks.

Day 5: Assurance, reporting and implementation planning

  • BCMS policy content and documented-information controls
  • Continuity risk RACI and committee terms of reference
  • Key risk indicators, key performance indicators and management dashboard design
  • Management review inputs, decisions, actions and retained evidence
  • Internal audit testing of risk assessment quality and treatment completion
  • Exercise, incident and audit findings as inputs to continual improvement
  • Ninety-day implementation roadmap for deploying the assessment method

Workshop: Participants assemble and peer-review their continuity risk assessment pack, then complete a 90-day implementation roadmap for their workplace.

Tools & standards covered

ISO 22301:2019, ISO 31000:2018, ISO 22317:2021, Microsoft Excel

A typical training day

08:30 – 10:30First session
10:30 – 10:45Refreshment break
10:45 – 12:30Second session
12:30 – 13:30Lunch and networking
13:30 – 15:00Third session
15:00 – 15:15Refreshment break
15:15 – 16:30Workshop and daily review

Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.

What the fee includes

  • Instruction by a practitioner facilitator
  • Full course workbook and materials
  • Exercise files, templates and case studies
  • Certificate of completion
  • Refreshments and lunch (classroom deliveries)
  • Post-course application plan
  • Facilitator follow-up on request
  • Group rates from five participants

How you can take this course

Classroom

Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.

Live online

The same facilitator and materials, delivered live for distributed teams and individuals.

In-house

Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.

Certification

Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.

Frequently asked questions

No certification is required. You should understand basic business operations and common risk-register terms, but the course explains how ISO 22301, ISO 31000 and ISO 22317 are applied to continuity risk decisions.

Yes, a laptop is recommended for the spreadsheet-based risk scoring and dashboard exercises. Microsoft Excel is used for practical templates; participants can bring their own non-confidential continuity documents if permitted by their employer.

It is designed for continuity, resilience, operational risk, HSE, crisis management, IT service continuity and assurance professionals. It is particularly useful for staff who must improve an existing programme rather than write a basic emergency response plan.

A BIA course concentrates on critical activities, disruption impacts and recovery requirements. This course uses BIA outputs as one input to assess scenarios, evaluate controls, select treatments and establish the governance needed to manage residual risk.

You can use the scenario register, scoring criteria, control assessment and treatment-plan structure to assess a business unit, critical service or supplier dependency. The final implementation roadmap identifies the stakeholders, evidence and approval steps needed to embed the process.

You leave with a completed continuity risk assessment pack based on the course case, including criteria, a scenario register, scoring matrix, treatment plan, RACI and executive-reporting format. These are designed as adaptable working templates rather than generic presentation slides.

Upcoming sessions

New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.

Ask about dates

Group of 5+?

Request in-house delivery or group rates →

Related courses in Business Continuity

5 Days Certificate

Business Continuity Leadership for HSE Managers Training Course

HSE managers are often expected to protect people, the environment, critical assets and regulatory obligations during events that disrupt no…

5 Days Certificate

Business Continuity Planning and Crisis Response Fundamentals Training Course

Business continuity failures are rarely caused by a missing document alone. They occur when critical activities, dependencies, recovery prio…

5 Days Certificate

NFPA 1600 Continuity and Emergency Management Training Course

Organizations cannot demonstrate resilience merely by keeping an emergency plan on file. They need an integrated program that connects risk …

5 Days Certificate

ISO 22317 Business Impact Analysis Methods Training Course

Business continuity plans often fail at the point where recovery priorities are set. Teams may have process lists, risk registers and recove…