Skip to content
BIZENIUS.

Digital Operational Resilience & ICT Third-Party Risk

Regulators stopped asking whether you can prevent every incident and started asking what happens when you can’t — resilience is the ability to take the hit and keep serving.

Format

Classroom · Live Virtual

The programme

Europe’s DORA regime has set the template — ICT risk management, resilience testing, incident classification and reporting, and a controlled register of every critical third party — and supervisors across the Gulf, Africa and Asia are issuing parallel rules. This programme builds the working system behind the acronyms: mapping critical business services and setting impact tolerances; the ICT risk framework that connects technology risk to board appetite; scenario-based resilience testing that proves tolerances rather than asserting them; incident response with the classification and reporting clocks regulators now run; and the third-party dimension — concentration risk, exit plans, contract clauses and the register — where most institutions are most exposed. Read as a design specification for any supervised institution, wherever its regulator sits on the adoption curve.

What you will do

Map critical business services and set defensible impact tolerances
Build an ICT risk framework connected to board appetite
Run scenario-based resilience testing that proves tolerances
Operate incident classification and reporting on regulatory clocks
Control third-party ICT risk: concentration, contracts, exit plans, the register

Who attends

Operational-resilience, business-continuity and ICT risk teams; CISOs and technology leaders; outsourcing and vendor managers; compliance and internal audit; executives and board members of banks, insurers and market infrastructures.

Cohorts bring together board members, executives and the rising leaders behind them — kept deliberately small, so every seat is a peer’s.

Programme agenda

Built for the decisions no textbook prepares you for

I.The resilience frame
  • From continuity to resilience: what changed in the supervisory ask
  • Critical business services and impact tolerances that mean something
  • The ICT risk framework and board accountability
II.Proving it
  • Scenario-based testing: severe-but-plausible, run honestly
  • Incident classification, reporting clocks and the communication drill
  • Lessons-learned loops that actually change the estate
III.The third-party exposure
  • The register: every critical ICT provider, mapped and owned
  • Concentration risk, cloud dependency and exit plans that could run
  • Contract clauses, audit rights and the supervisory dialogue

Frequently asked

Will these programmes prepare our team for supervisory review?

That is what they are built for. Casework is structured around the evidence supervisors request — risk-appetite articulation, documentation, attestation — and participants leave able to assemble the evidence trail before it is asked for and defend the framework in examination. Faculty include practitioners who have sat on the supervisor’s side of the table.

Which risk frameworks does the curriculum cover?

The risk and compliance curriculum spans enterprise risk management on the COSO framework, credit, market, liquidity and operational risk, IFRS 9 provisioning, stress testing, and financial-crime disciplines including fraud detection and AML/CFT. Each programme page states the frames it works in and what participants will build with them.

Can we attend in French?

Yes. BIZENIUS delivers in English and French, in classroom, live virtual and hybrid formats. French-language cohorts serve institutions across BCEAO jurisdictions and other francophone markets.

What happens after we enquire about a programme?

A senior practitioner replies within one business day with the brochure attached. The conversation then covers dates, format, any tailoring your institution needs, and the fee — BIZENIUS shares fees in that proposal, not on a public price list.

Share this programme

LinkedInWhatsAppFacebookEmail

Know the right person for this seat?Nominate a colleague →

In their words

Knowledge transfer, emphasised throughout

“We worked with BIZENIUS for our Fresh Graduates Programme — they are simply amazing. Knowledge transfer and practical learning were emphasised throughout.”

Kuwait Investment Authority

From the Mandate Record

Mandate № 04 · Africa

Capital frameworks built to run the bank, not to satisfy a filing

Most frameworks are written to satisfy the regulator. We build the kind that run the bank.

Open the dossier →

The Capability Arc™

Fix it · Advisory

Advisory & Consultancy

A senior bench across risk, treasury and regulation.

Learning is one point on the Capability Arc. Many institutions pair this programme with the advisory engagement — and automate what the framework demands.

Teams from these institutions train with BIZENIUS

  • Citi
  • Barclays
  • ExxonMobil
  • Total
  • Gazprom
  • Standard Bank
  • QNB
  • Crédit Agricole
  • Nedbank
  • Absa
  • Raiffeisen
  • Halliburton
  • Baker Hughes
  • ConocoPhillips
  • Ooredoo
  • National Bank of Kuwait
  • Kuwait Finance House
  • Bank Muscat
  • Bank Audi
  • SABB
  • Garanti BBVA
  • Ecobank
  • Arab Bank
  • National Bank of Egypt
  • ADIB
  • Access Bank
  • Afreximbank
  • Repsol
  • QNB ALAHLI
  • Stanbic Bank
  • Equity Group Holdings
  • KCB Bank
  • Lombard Odier
  • NOV
  • Weatherford
  • Subsea 7
  • Al Baraka
  • Banque Misr
  • Burgan Bank
  • Bank ABC

BIZENIUS

Speak to an expert

Tell us where you stand — an expert replies within one business day.

Phone *
Area of interest
Number of participants
+ Add a message or details (optional)

We only use your details to respond to your enquiry. See our Privacy Policy.