Business Continuity Risk Assessment and Governance Fundamentals Training Course
| Course code | SD-BC-012 |
|---|---|
| Duration | 5 days |
| Level | Intermediate |
| Category | Business Continuity |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Business continuity programmes often fail at the point where risk information must be converted into defensible priorities, recovery requirements and management decisions. Teams may hold a business impact analysis (BIA), risk register and emergency plans, yet lack a consistent way to identify disruption scenarios, set recovery time objectives, assess supplier dependencies or present residual risk to senior leadership. This course addresses the governance gap between operational risk assessment and an auditable, actionable business continuity management system (BCMS).
Participants learn to structure a continuity risk assessment using ISO 31000 principles and ISO 22301 requirements; define risk criteria; identify internal, external, digital, site, people and third-party disruption scenarios; and evaluate likelihood, consequence and control effectiveness. They practise linking risk assessment findings to BIA outputs, maximum acceptable outage, recovery time objectives (RTOs), recovery point objectives (RPOs), treatment plans, continuity strategies, ownership and escalation thresholds. The course also covers governance roles, BCMS policy, reporting dashboards, assurance activity and management review.
Instructor-led briefings are combined with worked examples, spreadsheet-based scoring, scenario workshops and peer review of continuity decisions. Across the week, participants build a continuity risk assessment pack for a realistic operating unit, including a risk appetite statement, scoring matrix, scenario register, treatment plan, governance RACI and executive reporting format. This practical pack can be adapted as a starting point for use in their own organisation.
The course is suited to practitioners who already contribute to resilience, risk, safety, security, IT service continuity or operational assurance and now need a disciplined method for governing business continuity risk.
Course objectives
By the end of this course, participants will be able to:
- Define business continuity risk criteria, appetite statements and escalation thresholds aligned to ISO 22301 governance requirements
- Construct a disruption scenario register covering people, premises, technology, suppliers, utilities and regulatory dependencies
- Apply likelihood, consequence and control-effectiveness scoring to produce a prioritised continuity risk register
- Link business impact analysis outputs to maximum acceptable outage, recovery time objectives and recovery point objectives
- Evaluate existing preventive, response and recovery controls using residual-risk and control-gap analysis
- Develop proportionate risk treatment plans with named owners, milestones, resource requirements and acceptance decisions
- Create a BCMS governance RACI, management-review agenda and risk reporting dashboard for senior decision-makers
- Present a documented continuity risk assessment pack that supports strategy selection, assurance and audit evidence
Benefits of attending
For you
- Gain a defensible method for converting disruption scenarios into prioritised continuity actions
- Produce risk scoring and treatment documentation that can withstand management and audit scrutiny
- Build confidence challenging unrealistic recovery assumptions, unowned dependencies and weak controls
- Strengthen credibility when briefing executives on residual risk, risk acceptance and continuity investment
- Prepare practical evidence for progression into business continuity, resilience, operational risk or assurance roles
For your organisation
- Creates a consistent basis for assessing disruption risks across sites, functions and critical services
- Improves alignment between risk registers, BIA results, recovery objectives and continuity strategies
- Makes risk ownership, treatment deadlines and acceptance decisions visible to accountable leaders
- Reduces overlooked exposure from third parties, utilities, single points of failure and shared services
- Provides structured governance evidence for ISO 22301 programmes, internal audit and management review
Target competencies
Who should attend
- Business Continuity Managers — who need a repeatable method for prioritising disruption risks and governing the BCMS
- Operational Risk Managers — who must connect enterprise risk registers with recovery requirements and resilience actions
- HSE Managers — who assess operational disruption, duty-of-care exposures and emergency preparedness arrangements
- Resilience and Crisis Management Officers — who need to translate scenarios into accountable prevention and recovery measures
- IT Service Continuity Managers — who must align technology recovery objectives with business impact and risk decisions
- Internal Auditors and Compliance Officers — who review continuity controls, management oversight and ISO 22301 evidence
Requirements and prerequisites
Participants should understand their organisation’s core products or services, key operational dependencies and current continuity or emergency arrangements. Familiarity with basic risk-register fields—risk event, likelihood, consequence, control, owner and action—is assumed, as is confidence reading simple spreadsheets. Prior exposure to a business impact analysis, incident management plan, ISO 22301 or ISO 31000 is helpful but not essential; these concepts are introduced and applied during the course. No certification, specialist continuity software, statistical modelling experience or prior audit experience is required. Complete beginners should expect a structured intermediate-level pace and should review their organisation’s risk or continuity documents beforehand.
Training methodology
The course uses instructor-led explanation of ISO 22301, ISO 31000 and ISO 22317 concepts, followed by guided application to a running disruption case. Participants work individually and in small groups to define risk criteria, score scenarios in Microsoft Excel, challenge control assumptions, map dependencies and choose treatment responses. Facilitated case discussions focus on decisions that continuity managers must defend: recovery priorities, risk acceptance, investment justification and escalation. Each day ends with a practical output, culminating in an individual application plan for adapting the assessment pack to a live organisational area.
Course outline
Day 1: Continuity risk foundations and governance context
- Business continuity risk versus operational, enterprise and emergency management risk
- ISO 22301:2019 clauses for leadership, planning, performance evaluation and improvement
- ISO 31000:2018 principles, framework and risk management process
- BCMS scope statements, interested parties and continuity governance boundaries
- Risk appetite, tolerance, capacity and acceptance authority
- Risk criteria for safety, service, financial, legal, environmental and reputational consequences
- Three-lines roles, accountability and escalation within continuity governance
Workshop: Participants draft risk criteria, a risk appetite statement and an approval hierarchy for the course case organisation.
Day 2: Scenario identification and business impact integration
- Structured scenario identification using PESTLE, dependency mapping and horizon scanning
- Disruption categories covering workforce, facilities, IT, cyber, suppliers, utilities and transport
- Business impact analysis inputs: critical activities, impact categories and maximum acceptable outage
- Recovery time objectives, recovery point objectives and minimum business continuity objectives
- Process, asset, data, people and third-party dependency mapping
- Single points of failure and concentration-risk identification
- ISO 22317:2021 guidance for business impact analysis and continuity priorities
Workshop: Teams create a disruption scenario register and dependency map for a critical service, linking each scenario to BIA impacts.
Day 3: Assessment, controls and residual risk
- Inherent-risk, residual-risk and target-risk definitions
- Likelihood scales, consequence scales and qualitative risk matrices
- Control design, operating effectiveness and control-assurance evidence
- Preventive, detective, response and recovery control categories
- Risk aggregation, interdependency and cascading-failure considerations
- Microsoft Excel risk register formulas, conditional formatting and heat-map views
- Risk validation workshops and challenge questions for subject-matter experts
Workshop: Participants score prioritised scenarios in a spreadsheet risk register, assess control effectiveness and identify residual-risk gaps.
Day 4: Treatment strategies and BCMS decision-making
- Risk treatment options: avoid, reduce, transfer, accept and prepare
- Continuity strategy selection for alternate sites, remote work, manual workarounds and redundancy
- Supplier continuity due diligence, contractual recovery requirements and exit planning
- Treatment-plan design with owners, milestones, budget assumptions and completion evidence
- Cost, benefit and feasibility tests for resilience investment decisions
- Formal risk acceptance, exception registers and review dates
- Linking treatment actions to incident, crisis, recovery and exercise plans
Workshop: Each group develops a prioritised treatment plan and presents a recommendation for accepting, reducing or transferring selected risks.
Day 5: Assurance, reporting and implementation planning
- BCMS policy content and documented-information controls
- Continuity risk RACI and committee terms of reference
- Key risk indicators, key performance indicators and management dashboard design
- Management review inputs, decisions, actions and retained evidence
- Internal audit testing of risk assessment quality and treatment completion
- Exercise, incident and audit findings as inputs to continual improvement
- Ninety-day implementation roadmap for deploying the assessment method
Workshop: Participants assemble and peer-review their continuity risk assessment pack, then complete a 90-day implementation roadmap for their workplace.
Tools & standards covered
ISO 22301:2019, ISO 31000:2018, ISO 22317:2021, Microsoft Excel
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Business Continuity
Business Continuity Leadership for HSE Managers Training Course
HSE managers are often expected to protect people, the environment, critical assets and regulatory obligations during events that disrupt no…
Business Continuity Planning and Crisis Response Fundamentals Training Course
Business continuity failures are rarely caused by a missing document alone. They occur when critical activities, dependencies, recovery prio…
NFPA 1600 Continuity and Emergency Management Training Course
Organizations cannot demonstrate resilience merely by keeping an emergency plan on file. They need an integrated program that connects risk …
ISO 22317 Business Impact Analysis Methods Training Course
Business continuity plans often fail at the point where recovery priorities are set. Teams may have process lists, risk registers and recove…