Governance, Risk & Compliance training courses
Keep the organisation sound with strong governance, risk and compliance practice.
Delivered in-house at your premises, as public sessions in Johannesburg, Cape Town, Durban, Pretoria, Dubai and London, or live online. Courses run 2 Days, 3 Days, 5 Days, from R10,000 per delegate.
Enterprise Risk Management under ISO 31000
Delegates learn to build and run an enterprise risk management framework aligned with the principles and process of ISO 31000. The course covers risk appetite, identification, analysis, evaluation, and treatment, together with the governance and reporting that hold it all together. Practical sessions include building a risk register and calibrating a risk matrix for a real organisation.
Anti-Money Laundering and Financial Crime Compliance
This course equips compliance staff to detect, prevent, and report money laundering and related financial crime. Delegates study customer due diligence, sanctions screening, transaction monitoring, and suspicious activity reporting within a risk-based framework. The programme reflects the recommendations of the Financial Action Task Force and regional regulatory expectations.
Regulatory Compliance Management Frameworks
Delegates learn to design and operate a structured compliance function that keeps the organisation ahead of its legal and regulatory obligations. The course covers obligation registers, compliance risk assessment, monitoring and testing, and breach management. Emphasis is placed on embedding compliance into business processes rather than treating it as a separate policing activity.
Internal Controls and Fraud Prevention
This course helps delegates design and evaluate the internal controls that protect an organisation from error and fraud. Participants study the components of a recognised control framework, segregation of duties, and the red flags and schemes that fraudsters exploit. Practical work includes assessing control gaps and designing cost effective remediation.
Data Protection and Privacy Compliance under POPIA and GDPR
Delegates learn to bring an organisation into compliance with modern data protection law, focusing on the South African Protection of Personal Information Act and the European General Data Protection Regulation. The course covers lawful processing, data subject rights, breach response, and cross-border transfers. Practical exercises include mapping data flows and drafting the core privacy governance documents.
Operational Risk Management for Financial Institutions
This programme develops the specialist skills needed to identify, measure, and control operational risk in banks and other financial institutions. Delegates study risk and control self-assessment, key risk indicators, loss data collection, and scenario analysis within the Basel framework. The course connects operational risk management directly to capital adequacy and regulatory expectations.
Business Continuity Management under ISO 22301
Delegates learn to build a business continuity management system that keeps critical operations running through disruption. The course follows ISO 22301 through business impact analysis, continuity strategy, plan development, and exercising. Practical work includes prioritising critical activities and drafting a workable recovery plan.
Governance, Risk and Compliance Integration
This course shows leaders how to knit governance, risk, and compliance into a single coordinated discipline rather than three competing silos. Delegates study the three lines model, shared risk taxonomies, integrated reporting, and supporting technology. The programme helps organisations cut duplication and give the board one coherent view of assurance.
Third Party and Vendor Risk Management
Delegates learn to manage the risks that arrive through suppliers, outsourcing partners, and other third parties. The course covers due diligence, contract risk clauses, ongoing monitoring, and the handling of concentration and fourth party risk. Practical exercises include tiering a vendor portfolio and building a proportionate assessment process.
Ethics, Integrity and Whistleblowing Programmes
This course helps organisations move from a paper code of conduct to a living ethical culture. Delegates study values based versus rules based approaches, conflict of interest management, and the design of trusted speak up and whistleblowing channels. The programme addresses how to investigate concerns fairly and protect those who raise them.
Anti-Bribery and Corruption Compliance under ISO 37001
Delegates learn to build an anti-bribery management system that meets ISO 37001 and withstands regulatory scrutiny. The course covers bribery risk assessment, gifts and hospitality controls, due diligence on business associates, and the handling of facilitation payments. Real enforcement cases illustrate what regulators expect and where programmes commonly fail.
Compliance Monitoring and Assurance Testing
Delegates learn to design and run the monitoring programme that gives the second line of defence real assurance over compliance. The course covers risk-based monitoring plans, sampling, testing techniques, and clear reporting of findings and root causes. Practical work includes building a monitoring plan and documenting a test with defensible conclusions.
Risk-Based Internal Auditing
This programme develops internal auditors who focus their effort where the risk to the organisation is greatest. Delegates learn to build a risk-based audit universe and plan, conduct assurance engagements, and evaluate the design and operation of controls. The course aligns with the international professional practices framework for internal auditing.
Sanctions Compliance and Screening
Delegates learn to build a sanctions compliance programme that keeps the organisation clear of prohibited parties and jurisdictions. The course covers the major sanctions regimes, name screening and fuzzy matching, alert investigation, and the management of false positives. Practical exercises walk through screening decisions and escalation of potential breaches.
Combined Assurance and the Three Lines Model
This course helps organisations coordinate their many assurance providers into a coherent map that reassures the board without gaps or wasteful overlap. Delegates study the updated three lines model, assurance mapping, and how management, risk, compliance, and internal audit should divide the work. The programme results in a clearer, cheaper, and more reliable assurance picture.
Contract Risk and Compliance Management
Delegates learn to identify and control the legal and commercial risks that live inside contracts across their whole lifecycle. The course covers risk allocation clauses, obligation tracking, compliance with contractual terms, and dispute avoidance. Practical work includes reviewing a contract for risk and building an obligations tracker.
Information Security Governance under ISO 27001
This course prepares delegates to establish and govern an information security management system aligned with ISO 27001. Participants cover risk assessment, the Annex A controls, statements of applicability, and the governance and audit activities that keep the system alive. The programme balances the management system requirements with the practical selection of security controls.
Public Sector Governance and Accountability
This programme addresses the distinctive governance challenges of government departments, municipalities, and state owned entities. Delegates study accountability arrangements, public financial management, oversight bodies, and the management of conflicts between political and administrative roles. The course emphasises transparency, value for public money, and defensible decision making.
Model Risk Governance and Validation
This course helps organisations govern the growing population of models that drive credit, pricing, and capital decisions. Delegates study model risk frameworks, independent validation, ongoing performance monitoring, and the documentation that regulators expect. The programme addresses both traditional statistical models and the newer machine learning approaches entering regulated use.
Risk Appetite and Tolerance Setting
Risk appetite statements are often written once and then ignored because they cannot be applied to a real decision. This course covers how to express appetite in measurable terms and cascade it so it changes behaviour.
Conducting Workplace Investigations
A botched investigation can cause more damage than the original allegation. This course covers planning, evidence, interviewing and reporting so that findings are fair, defensible and survive challenge.
Policy Writing and Management
Policies fail when nobody can find them, read them or tell what they must actually do. This course covers writing usable policy, managing the approval and version cycle and retiring policy that has outlived its purpose.
Health and Safety Legal Compliance
Safety duties fall on individuals as well as organisations, and ignorance is not a defence. This course sets out the legal framework, who carries which duty and what an organisation must be able to prove if an inspector or a court asks.
Fraud Risk Assessment and Prevention Programmes
Fraud prevention works when it is targeted at where the organisation is genuinely exposed rather than spread evenly. This course covers assessing fraud risk by scheme and designing controls proportionate to that exposure.
Crisis Communication and Reputation Management
Reputational damage is usually done in the first hours by silence or a badly judged statement. This course covers preparing for crisis communication, deciding what to say while facts are incomplete and rebuilding trust afterwards.
Assurance Mapping and Coordinated Oversight
Large organisations are assured repeatedly in some areas and not at all in others, at considerable cost. This course covers mapping assurance activity against risk to find the duplication and the genuine gaps.
Conflict of Interest and Ethics Management
Conflicts of interest cause damage mainly when they are undeclared. This course covers building declaration processes people actually use, assessing declared conflicts and managing them without paralysing normal business.
Environmental, Social and Governance Reporting
Reporting on non financial performance now attracts the same scrutiny as financial reporting, without the same maturity of controls. This course covers selecting frameworks, gathering defensible data and reporting without overstating.
Business Impact Analysis
Continuity planning without impact analysis protects whatever the loudest department claims matters. This course covers establishing objectively which activities matter, how quickly they must resume and what they depend on.
Regulatory Change Management
Regulatory change arrives constantly and organisations discover the ones they missed during an inspection. This course covers monitoring change, assessing what it means for you and implementing it before the deadline.
Third Party Due Diligence and Screening
Organisations inherit the conduct of the parties they contract with. This course covers proportionate due diligence on suppliers, agents and partners, and what to do when screening produces a hit.
Whistleblowing and Speak Up Programmes
People stay silent when they doubt anything will happen or fear the consequences. This course covers building reporting channels that get used, handling reports properly and protecting those who come forward.
Insurance and Risk Financing
Insurance is one of several ways to finance risk and is often bought without comparing the alternatives. This course covers deciding what to retain, what to transfer and how to structure cover across a programme.
Contract Compliance Monitoring
Organisations negotiate good contract terms and then never check whether they are being honoured. This course covers monitoring compliance with contractual obligations on both sides.
Corporate Investigations Management
Complex investigations involve multiple workstreams, legal exposure and people whose careers are at stake. This course covers managing an investigation as a controlled process rather than an escalating scramble.
Governance of Outsourced and Cloud Services
Outsourcing a service does not outsource accountability for it. This course covers governing third parties who run critical processes, including the concentration risk few organisations measure.
Climate Risk and Transition Planning
Organisations face physical risk from a changing climate and transition risk from the response to it. This course covers assessing both and building a plan that stands up to investor and regulator scrutiny.
Managing Regulatory Inspections and Visits
How an organisation behaves during an inspection shapes the findings as much as the underlying compliance. This course covers preparing for, hosting and responding to a regulatory visit.
Codes of Conduct and Ethical Standards
A code of conduct changes behaviour only if people can apply it to the situations they actually face. This course covers writing a usable code and embedding it beyond an annual signature.
Export Controls and Dual Use Goods
Some goods, software and technical data cannot be exported freely, and breaches carry criminal exposure. This course covers classifying items and controlling what leaves the organisation.
Compliance Awareness Training Programmes
Compliance training is delivered to satisfy an obligation and forgotten immediately. This course covers building awareness programmes that change what people do when nobody is watching.
Insider Threat and Personnel Security
The most damaging incidents often involve someone with legitimate access. This course covers reducing insider risk through vetting, access control and noticing the changes that precede harm.
Combined Assurance Reporting
Boards receive assurance from audit, risk, compliance and management separately and cannot tell what is actually covered. This course covers consolidating assurance into one credible picture.






















