Developing and implementing a compliance management system in accordance with the requirements of the international standard ISO 37301:2021

Duration 2 days

The seminar can be held online on the official International Business Academy platform. On completion of the training you will be given a link to the recording, which will be available for one month.
*dates are subject to additional confirmation

Seminar dates

Schedule: 10:00 to 17:30
Cost 296 500 tenge

excluding VAT

* VAT of 16% will be added to the invoice

The price includes:

  • Seminar
  • Exclusive handout materials
  • IBA certificates
  • Notepads, pens
  • Lunches and 2 coffee breaks
Register

Programme goal:
Training managers and specialists in methods of building a real rather than formal, risk-based Compliance Management System (CMS) and integrating it into the company's existing management systems and processes, to obtain the maximum effect from the CMS with minimal additional documentation under the requirements of ISO 37301 and integration of the CMS with the Anti-Bribery Management System (ISO 37001).

The programme focuses on:
— Developing competencies in identifying, analysing and managing corruption and compliance risks
— Building effective and transparent decision-making processes
— Increasing the effectiveness of internal audit: moving from formal audit to a risk-based approach
— Creating a mature anti-corruption corporate culture — an environment intolerant of corrupt behaviour

Objectives:
— Study the requirements of ISO 37301 for building a CMS
— Master methods of identifying, analysing and evaluating compliance risk (including corruption risks) (ISO 31010), including the use of artificial intelligence
— Develop a risk-based model of CMS processes taking the company's context into account
— Define process KPIs and key risk indicators
— Master methods of internal audit of the CMS (ISO 19011)
— Consolidate the knowledge gained in practical cases, interactive games and group work (built on the Client company's business processes and its internal regulatory documentation)

Skills developed:
— Risk-based thinking — applying methods of analysing and evaluating compliance risks
— Strategic management — integrating compliance functions into the corporate structure
— Monitoring and control — evaluating the effectiveness of the CMS
— Internal audit methods — planning and conducting compliance checks
— Developing the CMS policy and regulations — managing documented information
— Data-driven decision-making

Using artificial intelligence tools — mastering the skills of applying AI for analysing, planning and documenting processes; participants are given a ready-made prompt that they can use independently in their further work.

Expected changes in employees' work after the training:
— Managers are able to integrate compliance mechanisms into the company's existing processes
— Compliance officers know how to develop CMS tools and use the information generated
— Legal services are able to analyse and minimise legal risks more effectively
— Internal auditors have increased the effectiveness of monitoring compliance programmes
— HR specialists will be able to introduce compliance training mechanisms
— The company's key managers have recognised the need for a CMS and gained the skills to integrate the CMS into their processes

Key Account Manager

Natalya Batukhtina
ns@iba.kz +7 702 777 44 11 WhatsApp

Key Account Manager

Юлия Копцева
manager@iba.kz +7 702 777 44 11 WhatsApp
Seminar programme Download programme as PDF
Get a personalised commercial proposal in PDF format
Download proposal as PDF

Programme

Day 1

Introduction

Getting acquainted / introduction / course overview / participants introduce themselves.

The history of standardisation. Introduction to ISO.

The seven management principles.

The company's context

Understanding the organisation and its context in relation to risks and the company's structure.

The «5C» method, Michael Porter's «5 Forces», SWOT analysis, PEST analysis.

Interested parties, their requirements and expectations

Understanding interested parties. The link between interested parties and context.

Compliance obligations and their link to the company's context.

Assessing the degree of fulfilment of compliance obligations.

Examples of methods for assessing fulfilment of compliance obligations.

Scope of the compliance management system (CMS)

The scope of the CMS and its link to context.

Business processes

The process approach.

The link between context and processes.

The procedure for identifying processes — best practices.

Options for describing processes.

Process criteria (KPI)

Types of criteria: input KPI and output KPI.

The link between criteria and the company's strategy.

Introduction to risk management

Common myths in the field of risk management and debunking them.

System 1, System 2 and the concept of «mental traps».

Risk identification

Mental traps at the risk identification stage.

Risk identification methods (from ISO 31010:2019):

— Goal decomposition and the MECE method (Mutually Exclusive & Collectively Exhaustive)

— «Brainstorming»

— A database of materialised risks

— The «RIR — Risk Identification Report» method

— Control «checklists»

— Business impact analysis (the «process approach»).

Risk analysis

Mental traps at the risk analysis stage.

Risk analysis methods (from ISO 31010:2019):

— The «5 Whys» method

— The «bow-tie» method

— The «decision trees» method

— The «Monte Carlo» simulation method, etc.

Examples of risk analysis and completing the Risk Register.

Determining the level of risk

Mental traps at the risk evaluation stage.

Different options for evaluating risk (qualitative, quantitative and their combination, from ISO 31010:2019).

Assessing and analysing the influence of risks on the decision being made

Ways of visualising the results of evaluation: Risk maps, Decision trees, the Scoring model.

Day 2

Risk treatment

Mental traps at the risk treatment stage.

Six ways of treating risk.

Choosing the risk treatment method.

Examples of risk treatment.

Risk monitoring and review

Key risk indicators (KRI). The relationship between KRI and KPI.

Leadership

Risk-based decision-making.

Methods of improving the quality of corporate decisions from the «Decision Quality» methodology.

The relationship between strategy, context and the CMS Policy.

Recommendations on developing the CMS Policy.

Responsibility and authority

Methods of describing actions by process (in the form of regulations / control procedures).

Designing business processes and controls.

Basic requirements / recommendations for developing control procedures, and common mistakes.

CMS objectives

The standards' requirements for objective setting.

The relationship between strategy, context, the Policy and the CMS Objectives.

Best practices in risk-based objective setting.

Resources

Determining the competence of personnel needed for the processes to function.

Determining the infrastructure needed for the processes to function.

The in-house knowledge base.

Effective communication. Documented information.

Operations

Establishing control procedures

Investigation processes

Investigation procedures — best practices

Performance evaluation

Internal audit of the CMS.

The procedure for planning, conducting and analysing the results of a risk-based internal audit of the CMS.

CMS review. Best practices.

Improvement

Corrective actions. Examples and best practices.

Continual improvement.

Group game «interactive review of requirements and situations from ISO 37301»

All areas