The seminar can be held online on the official International Business Academy platform. On completion of the training you will be given a link to the recording, which will be available for one month.
*dates are subject to additional confirmation
excluding VAT
* VAT of 16% will be added to the invoice
Programme goal:
Training managers and specialists in methods of building a real rather than formal, risk-based Compliance Management System (CMS) and integrating it into the company's existing management systems and processes, to obtain the maximum effect from the CMS with minimal additional documentation under the requirements of ISO 37301 and integration of the CMS with the Anti-Bribery Management System (ISO 37001).
The programme focuses on:
— Developing competencies in identifying, analysing and managing corruption and compliance risks
— Building effective and transparent decision-making processes
— Increasing the effectiveness of internal audit: moving from formal audit to a risk-based approach
— Creating a mature anti-corruption corporate culture — an environment intolerant of corrupt behaviour
Objectives:
— Study the requirements of ISO 37301 for building a CMS
— Master methods of identifying, analysing and evaluating compliance risk (including corruption risks) (ISO 31010), including the use of artificial intelligence
— Develop a risk-based model of CMS processes taking the company's context into account
— Define process KPIs and key risk indicators
— Master methods of internal audit of the CMS (ISO 19011)
— Consolidate the knowledge gained in practical cases, interactive games and group work (built on the Client company's business processes and its internal regulatory documentation)
Skills developed:
— Risk-based thinking — applying methods of analysing and evaluating compliance risks
— Strategic management — integrating compliance functions into the corporate structure
— Monitoring and control — evaluating the effectiveness of the CMS
— Internal audit methods — planning and conducting compliance checks
— Developing the CMS policy and regulations — managing documented information
— Data-driven decision-making
Using artificial intelligence tools — mastering the skills of applying AI for analysing, planning and documenting processes; participants are given a ready-made prompt that they can use independently in their further work.
Expected changes in employees' work after the training:
— Managers are able to integrate compliance mechanisms into the company's existing processes
— Compliance officers know how to develop CMS tools and use the information generated
— Legal services are able to analyse and minimise legal risks more effectively
— Internal auditors have increased the effectiveness of monitoring compliance programmes
— HR specialists will be able to introduce compliance training mechanisms
— The company's key managers have recognised the need for a CMS and gained the skills to integrate the CMS into their processes
Introduction
Getting acquainted / introduction / course overview / participants introduce themselves.
The history of standardisation. Introduction to ISO.
The seven management principles.
The company's context
Understanding the organisation and its context in relation to risks and the company's structure.
The «5C» method, Michael Porter's «5 Forces», SWOT analysis, PEST analysis.
Interested parties, their requirements and expectations
Understanding interested parties. The link between interested parties and context.
Compliance obligations and their link to the company's context.
Assessing the degree of fulfilment of compliance obligations.
Examples of methods for assessing fulfilment of compliance obligations.
Scope of the compliance management system (CMS)
The scope of the CMS and its link to context.
Business processes
The process approach.
The link between context and processes.
The procedure for identifying processes — best practices.
Options for describing processes.
Process criteria (KPI)
Types of criteria: input KPI and output KPI.
The link between criteria and the company's strategy.
Introduction to risk management
Common myths in the field of risk management and debunking them.
System 1, System 2 and the concept of «mental traps».
Risk identification
Mental traps at the risk identification stage.
Risk identification methods (from ISO 31010:2019):
— Goal decomposition and the MECE method (Mutually Exclusive & Collectively Exhaustive)
— «Brainstorming»
— A database of materialised risks
— The «RIR — Risk Identification Report» method
— Control «checklists»
— Business impact analysis (the «process approach»).
Risk analysis
Mental traps at the risk analysis stage.
Risk analysis methods (from ISO 31010:2019):
— The «5 Whys» method
— The «bow-tie» method
— The «decision trees» method
— The «Monte Carlo» simulation method, etc.
Examples of risk analysis and completing the Risk Register.
Determining the level of risk
Mental traps at the risk evaluation stage.
Different options for evaluating risk (qualitative, quantitative and their combination, from ISO 31010:2019).
Assessing and analysing the influence of risks on the decision being made
Ways of visualising the results of evaluation: Risk maps, Decision trees, the Scoring model.
Risk treatment
Mental traps at the risk treatment stage.
Six ways of treating risk.
Choosing the risk treatment method.
Examples of risk treatment.
Risk monitoring and review
Key risk indicators (KRI). The relationship between KRI and KPI.
Leadership
Risk-based decision-making.
Methods of improving the quality of corporate decisions from the «Decision Quality» methodology.
The relationship between strategy, context and the CMS Policy.
Recommendations on developing the CMS Policy.
Responsibility and authority
Methods of describing actions by process (in the form of regulations / control procedures).
Designing business processes and controls.
Basic requirements / recommendations for developing control procedures, and common mistakes.
CMS objectives
The standards' requirements for objective setting.
The relationship between strategy, context, the Policy and the CMS Objectives.
Best practices in risk-based objective setting.
Resources
Determining the competence of personnel needed for the processes to function.
Determining the infrastructure needed for the processes to function.
The in-house knowledge base.
Effective communication. Documented information.
Operations
Establishing control procedures
Investigation processes
Investigation procedures — best practices
Performance evaluation
Internal audit of the CMS.
The procedure for planning, conducting and analysing the results of a risk-based internal audit of the CMS.
CMS review. Best practices.
Improvement
Corrective actions. Examples and best practices.
Continual improvement.
Group game «interactive review of requirements and situations from ISO 37301»