Developing a Strategic Enterprise Risk Management COSO Framework Masterclass
The revised COSO ERM framework put to work — integrating risk with strategy-setting and performance instead of managing it from an IT silo.
Format
Classroom · Live Virtual
Upcoming sessions
Pick a session to applyADMISSIONS OPENThe programme
Technology risk cannot be managed from an IT department silo any longer — the revised Committee of Sponsoring Organizations (COSO) Enterprise Risk Management Integrated Framework makes that explicit, considering the impact of technology risk in strategy-setting as well as in driving performance. This programme takes participants through the concepts and principles of the updated framework and prepares them to integrate it into their organisation’s strategy-setting process. The cohort works component by component — governance and culture; strategy and objective-setting; performance; and information, communication and reporting — applies the framework to situational examples, and confronts the challenges that stall ERM programmes before they change how the business decides.
What you will do
Who attends
- Risk professionals and heads of enterprise risk
- Compliance professionals
- Internal auditors
- CEOs, managing directors, chairs and board directors
- Strategic planners
Programme agenda
Built for the decisions no textbook prepares you for
I.Why COSO revised the framework
- Technology risk beyond the IT silo
- ERM in strategy-setting and performance
- Requirements for building an effective ERM framework
II.Governance, culture and strategy
- The governance and culture component
- The strategy and objective-setting component
- Applying ERM concepts to internal processes
III.Performance and reporting
- The performance component
- The information, communication and reporting component
- The value of ERM when setting and carrying out objectives
IV.Making it stick
- Applying the framework to situational examples
- Integrating ERM with strategy and performance in practice
- Anticipating the potential challenges to ERM
Frequently asked
Which security frameworks do the programmes work with?
The frameworks security teams are audited against — including ISO 27001, the NIST Cybersecurity Framework and GDPR obligations — plus industrial control-system security for oil, gas and utilities environments. BIZENIUS does not certify against these standards; participants leave able to run the risk assessments, write the ISMS documentation and prepare the evidence an auditor asks for.
Is there cybersecurity content for boards and non-technical executives?
Yes. Dedicated programmes address risk and cybersecurity for board members, and cyber governance, risk and compliance for executives, alongside practitioner-level depth for security teams — from emerging threats and countermeasures to fraud detection and investigation. Boards leave knowing which questions to put to their CISO, and what a satisfactory answer looks like.
How is pricing handled for cybersecurity programmes?
There is no public rate card. The fee arrives in the proposal, shaped by format, location and any tailoring — request the brochure and a senior practitioner replies within one business day with the details.
Can security training run inside our own environment?
Yes. Every programme runs in-house, tailored to your threat model, your sector and your control environment — including operational-technology settings such as process-control systems. Delivery is in English or French, on site or as a private live virtual cohort.
Share this programme
Know the right person for this seat?Nominate a colleague →
In their words
Knowledge transfer, emphasised throughout
“We worked with BIZENIUS for our Fresh Graduates Programme — they are simply amazing. Knowledge transfer and practical learning were emphasised throughout.”
Kuwait Investment Authority
The Capability Arc™
Fix it · Advisory
Risk Appetite & Enterprise Risk Governance
An appetite framework wired into daily decisions.
Automate it · Smart IT
Risk Data, Controls & MI (BCBS 239)
Risk data and controls built to BCBS 239.
Learning is one point on the Capability Arc. Many institutions pair this programme with the advisory engagement — and automate what the framework demands.
Teams from these institutions train with BIZENIUS
Related programmes
Risk Management & Cybersecurity for Board Members Masterclass
Cyber oversight for directors who approve the budgets and set the policy — the questions to ask, the framework to ask them in, and the line between secure and resilient.
View programmeCyber Security Governance, Risk and Compliance (GRC) Masterclass
The governance system behind cyber compliance — laws and regulations translated into policy, controls, audit and a culture of documented accountability.
View programmeFraud Detection, Investigation and Prevention Masterclass
Fraud accounting combined with digital forensics — detecting fraudulent activity, investigating it properly and collecting evidence that survives legal scrutiny.
View programmeCybersecurity & IT
Take the brochure with you.
One request — the full agenda, the faculty and the next cohort dates, sent personally by the admissions team.







































