IT Risk Management for Banking Professionals Training Course
| Course code | SD-IT-010 |
|---|---|
| Duration | 10 days |
| Level | Intermediate |
| Category | Information Technology |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Banks depend on technology for payments, lending, customer onboarding, trading, treasury, regulatory reporting and digital channels. A control failure in an API, cloud service, core banking interface or third-party platform can create operational losses, data exposure, service outages and supervisory action. Risk professionals and technology managers need a disciplined way to identify these exposures, assess their business impact, assign ownership and demonstrate that controls are operating effectively.
This course teaches participants to build and run an IT risk management process suited to banking. Participants work with risk taxonomies, inherent and residual risk assessment, control design, key risk indicators (KRIs), risk and control self-assessments (RCSAs), issue management, scenario analysis and third-party technology risk. They apply NIST CSF 2.0, ISO/IEC 27001:2022 and COBIT 2019 concepts to banking use cases, including cyber risk, resilience, data risk, change risk, cloud risk and critical outsourced services.
Teaching combines instructor-led briefings with bank-specific case work, facilitated control workshops, risk-register design and reporting exercises. Participants analyse a simulated digital banking service, document its assets and dependencies, score its risks, map controls, define KRIs, record treatment actions and prepare a committee-ready risk report. They leave with a completed IT risk management pack that can be adapted for their function, business line or technology programme.
The course is designed for intermediate practitioners who already work with technology, operational risk, information security, audit, compliance or bank transformation initiatives and now need to connect technical risk evidence to accountable business decisions.
Course objectives
By the end of this course, participants will be able to:
- Construct a banking IT risk taxonomy covering cyber, resilience, data, change, cloud and third-party exposures
- Perform inherent and residual risk assessments using likelihood, impact, velocity and control-effectiveness criteria
- Create a risk and control self-assessment (RCSA) for a digital banking service
- Map technology controls to NIST CSF 2.0, ISO/IEC 27001:2022 and COBIT 2019 requirements
- Design key risk indicators with thresholds, data sources, owners and escalation triggers
- Evaluate cloud and outsourced-service risks through due diligence, contractual controls and exit planning
- Document risk treatment plans, issues and exceptions in a bank-ready risk register
- Produce a concise IT risk report for technology risk committees and senior management
Benefits of attending
For you
- Gain a repeatable method for turning technical weaknesses into clearly prioritised banking risk statements
- Build credibility in technology risk committees by presenting KRIs, control evidence and treatment decisions clearly
- Learn to challenge cloud and supplier assurances using structured due-diligence and resilience questions
- Develop a portfolio-quality IT risk pack that demonstrates practical RCSA and reporting capability
- Prepare for broader roles in technology risk, operational resilience, information security governance or IT audit
For your organisation
- Establish more consistent risk scoring and control documentation across technology teams and business lines
- Improve escalation of deteriorating control performance through measurable KRIs and defined thresholds
- Strengthen oversight of critical cloud, fintech and outsourced technology services before incidents occur
- Produce risk reporting that links technical findings to customer impact, financial exposure and regulatory obligations
- Reduce duplicated assurance effort by mapping controls across recognised governance and security frameworks
Target competencies
Who should attend
- IT Risk Managers — who need to maintain risk profiles, control assessments and treatment plans for banking technology
- Information Security Managers — who must translate security control evidence into business risk decisions
- Operational Risk Managers — who oversee RCSAs, KRIs and loss prevention across technology-dependent processes
- IT Audit Professionals — who need to test technology controls and report findings in risk-based terms
- Technology Service Owners — who are accountable for resilience, change and control performance in critical services
- Third-Party Risk Managers — who assess cloud, fintech and outsourced technology providers supporting bank operations
Requirements and prerequisites
Participants should have practical exposure to banking operations, technology delivery, information security, operational risk, audit or compliance. They should understand basic concepts such as assets, threats, vulnerabilities, controls, incidents, access management and business impact. Familiarity with spreadsheets and with reading policies, audit findings or risk registers is assumed, as exercises use structured assessment templates and simple scoring models. Prior experience with ServiceNow Integrated Risk Management, formal certifications in ISO 27001, COBIT or NIST frameworks, programming skills and advanced quantitative modelling are not required. Participants should bring examples of non-confidential technology risks or controls from their own environment.
Training methodology
The instructor uses short technical briefings to establish each method, followed by guided application to a simulated mobile and payments banking service. Participants work in groups to map assets and dependencies, identify threats, assess controls, define KRIs and challenge a cloud-provider risk assessment. Case material includes incidents, audit findings, service-level data and supplier evidence. Individual and peer review sessions improve the quality of risk statements and committee reporting. On the final day, each participant converts the course work into an application plan for a live service, programme or risk process in their organisation.
Course outline
Day 1: Banking technology risk foundations
- Banking technology value chains and critical business services
- IT risk, operational risk and information security risk distinctions
- Technology risk appetite and tolerance statements
- Banking IT risk taxonomy design
- Risk ownership across the three lines model
- Inherent risk versus residual risk concepts
- Risk event, cause, control and impact statement structure
Workshop: Participants deconstruct a mobile banking outage and produce a structured risk statement with causes, impacts, owners and affected services.
Day 2: Frameworks and governance architecture
- NIST Cybersecurity Framework 2.0 functions and profiles
- ISO/IEC 27001:2022 control framework application
- COBIT 2019 governance and management objectives
- Framework crosswalks for banking control environments
- Technology risk policies, standards and procedures
- Risk committee mandates and management information
- Control ownership and accountability matrices
Workshop: Groups create a framework crosswalk and accountability matrix for identity and access management controls.
Day 3: Risk identification and service mapping
- Critical service and customer journey mapping
- Asset inventory and configuration item dependencies
- Data classification and data-flow analysis
- Threat modelling using attack paths
- Technology failure modes and single points of failure
- Risk identification interviews and control workshops
- Risk register data fields and quality criteria
Workshop: Participants map assets, data flows and dependencies for a digital loan-origination service and populate an initial risk register.
Day 4: Risk assessment and prioritisation
- Likelihood and impact scoring calibration
- Financial, customer, regulatory and reputational impact criteria
- Control design versus operating effectiveness scoring
- Residual risk calculation methods
- Risk velocity, persistence and concentration measures
- Scenario analysis for severe but plausible technology events
- Risk heat maps and prioritisation limitations
Workshop: Participants score a set of payment-platform risk scenarios, calculate residual ratings and defend the prioritisation to a review panel.
Day 5: Control design and RCSA practice
- Preventive, detective and corrective control types
- Control objectives and control activity wording
- Risk and control self-assessment lifecycle
- Evidence requirements for control operation
- Control testing sample selection and test procedures
- Control gaps, compensating controls and exceptions
- RCSA facilitation techniques for technology teams
Workshop: Participants conduct an RCSA workshop for privileged-access management and produce a risk-control matrix with evidence requirements.
Day 6: Cyber, data and change risk
- Cyber risk scenarios for banking attack surfaces
- Vulnerability management and patching risk indicators
- Identity, privileged access and segregation-of-duties controls
- Data protection, retention and encryption control risks
- Secure software development lifecycle control points
- Change management and release-risk assessment
- Security incident lessons learned and risk remediation
Workshop: Participants review evidence from a failed production release and create findings, corrective actions and KRI proposals.
Day 7: Resilience and operational continuity
- Operational resilience and important business services
- Business impact analysis for technology dependencies
- Recovery time objectives and recovery point objectives
- Disaster recovery testing and evidence review
- Capacity, availability and performance risk metrics
- Incident management, problem management and root-cause analysis
- Scenario testing for cyber and third-party disruption
Workshop: Teams assess a payment-service recovery scenario and produce a resilience risk assessment with recovery control actions.
Day 8: Cloud, third-party and fintech risk
- Technology third-party risk lifecycle
- Cloud shared-responsibility model analysis
- Supplier due diligence and control assurance evidence
- Service-level agreements and risk-based contractual clauses
- Concentration risk and fourth-party dependencies
- Data location, access and exit strategy risks
- Ongoing vendor monitoring and assurance reporting
Workshop: Participants evaluate a cloud banking provider dossier and create a due-diligence findings log, control requirements and exit-risk actions.
Day 9: KRIs, issues and risk reporting
- Key risk indicator design principles
- Leading, lagging and predictive technology risk metrics
- Threshold setting, breach logic and escalation routes
- Risk acceptance, exception and waiver governance
- Issue management lifecycle and action tracking
- Risk aggregation and concentration analysis
- Technology risk committee reporting formats
Workshop: Participants build a KRI dashboard and a one-page committee report for a deteriorating digital banking risk profile.
Day 10: Integrated banking IT risk application
- End-to-end IT risk management operating model
- Risk appetite alignment and management challenge
- Assurance planning across first, second and third lines
- Regulatory examination evidence preparation
- Risk treatment prioritisation and investment cases
- Stakeholder communication for technical risk decisions
- Ninety-day implementation planning
Workshop: Participants complete and present an IT risk management pack containing an RCSA, risk register, control map, KRI dashboard and 90-day action plan.
Tools & standards covered
NIST Cybersecurity Framework 2.0, ISO/IEC 27001:2022, COBIT 2019, ServiceNow Integrated Risk Management
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
-
28 Sep – 09 Oct 2026Book
Nairobi · USD 6,000 -
28 Sep – 09 Oct 2026Book
Live Online · USD 3,000 -
28 Sep – 09 Oct 2026Book
Kigali · USD 7,000 -
12 – 23 Oct 2026Book
Live Online · USD 3,000 -
12 – 23 Oct 2026Book
Cape Town · USD 8,400 -
19 – 30 Oct 2026Book
Nairobi · USD 6,000 -
19 – 30 Oct 2026Book
Dubai · USD 9,000 -
19 – 30 Oct 2026Book
Kigali · USD 7,000
49 more dates — ask us.
Group of 5+?
Request in-house delivery or group rates →Related courses in Information Technology
Microsoft Azure Cloud Administration Training Course
Organisations depend on Azure administrators to provision reliable services, control cloud spend, protect identities and data, and resolve i…
IT Governance for IT Managers Training Course
IT managers are routinely asked to deliver services faster, control technology risk, justify investment decisions, and prove that operationa…
Microsoft System Center Configuration Manager Administration Training Course
Managing Windows endpoints at enterprise scale requires more than deploying software packages. Administrators must maintain a reliable Confi…
Advanced Enterprise IT Infrastructure Design Training Course
Enterprise infrastructure teams must make design decisions that remain dependable when demand rises, sites multiply, vendors change, and sec…