The seminar can be held online on the official International Business Academy platform. On completion of the training you will be given a link to the recording, which will be available for one month.
*dates are subject to additional confirmation
excluding VAT
* VAT of 16% will be added to the invoice
Programme goal:
Training managers and specialists in the principles and methods of building a NON-FORMAL, risk-based integrated management system (IMS) in accordance with international ISO standards. The programme aims to build practical skills that genuinely increase the company's effectiveness by covering the following areas:
— Reducing operational risks – cutting financial losses and downtime through systematic risk management
— Optimising processes – eliminating duplicated functions, cutting inefficient costs and integrating risk management into the company's key processes
— Increasing the effectiveness of internal monitoring – moving from formal audit to risk-based internal audit in planning and conducting internal audits
— Compliance with the requirements of regulators and certification bodies – greater transparency, fewer nonconformities in external inspections and certification audits
— Improving the quality of planning and management decisions – introducing modern decision-making methods based on quantitative risk assessment and process KPIs
Objectives:
— Study the requirements of the international ISO standards
— Master methods of identifying, analysing and managing risks based on ISO 31010 (including: «5 Whys», «bow-tie», decision trees, the MECE method, etc.)
— Learn to apply algorithmic tools (SWOT, PEST, «Porter's 5 Forces») to define the organisation's context
— Develop a risk-based model of the IMS business processes
— Master methods of quantitative risk assessment (Monte Carlo simulation, Tornado diagram)
— Build a system of KPIs (by process) and KRIs (key risk indicators – by risk)
— Learn to plan and conduct risk-based internal audits of the IMS (ISO 19011)
— Consolidate knowledge through practical cases, group work, interactive games and discussions based on the company's business processes
Skills developed:
— Strategic thinking – linking the company's strategy to process KPIs and the performance of top management
— The process approach – describing and optimising business processes taking ISO requirements into account
— Risk management – applying methods of identifying, analysing, evaluating and treating risks (ISO 31010)
— Decision-making based on quantitative risk assessment – improving the quality of planning and forecasting
— Auditing skills – conducting internal audits in accordance with ISO 19011
— Evaluating IMS performance – monitoring KPIs and KRIs, analysing nonconformities and corrective actions
— Working with interested parties – taking their requirements and expectations into account when building the management system
Using artificial intelligence tools – skills in applying AI for analysing, planning and documenting processes; a ready-made prompt is provided for participants' independent work
Criteria for participation in the programme:
Target audience and the value of participation for each group:
— Heads of structural units (business process owners) – integrating risk management into their processes, increasing manageability and performance
— Quality, environmental, occupational safety and energy managers and internal auditors – new methods of risk assessment and more effective internal audits
— Risk managers – expanding the risk analysis toolkit and integrating it into the corporate risk register
— Sustainable development and corporate governance managers – taking ESG factors and related risks into account when integrating the requirements of international standards into the company's activities
Introduction
Getting acquainted / introduction / course overview / participants introduce themselves.
The history of standardisation. Introduction to ISO.
The seven management principles.
The company's context
Understanding the organisation and its context in relation to risks and the company's structure.
The «5C» method, Michael Porter's «5 Forces», SWOT analysis, PEST analysis.
Interested parties, their requirements and expectations
Understanding interested parties. The link between interested parties and context.
Compliance obligations and their link to the company's context.
Assessing the degree of fulfilment of compliance obligations.
Examples of methods for assessing fulfilment of compliance obligations.
Scope of the integrated management system (IMS)
The scope of the IMS and its link to context.
Business processes
The process approach.
The link between context and processes.
The procedure for identifying processes — best practices.
Options for describing processes.
Process criteria (KPI)
Types of criteria: input KPI and output KPI.
The link between criteria and the company's strategy.
Introduction to risk management
Common myths in the field of risk management and debunking them.
System 1, System 2 and the concept of «mental traps».
Risk identification
Mental traps at the risk identification stage.
Risk identification methods (from ISO 31010:2019):
— Goal decomposition and the MECE method (Mutually Exclusive & Collectively Exhaustive)
— «Brainstorming»
— A database of materialised risks
— The «RIR — Risk Identification Report» method
— Control «checklists»
— Business impact analysis (the «process approach»).
Ways of conducting an energy review — best practices.
Ways of identifying energy performance indicators and determining energy baselines.
Risk analysis
Mental traps at the risk analysis stage.
Risk analysis methods (from ISO 31010:2019):
— The «5 Whys» method
— The «bow-tie» method
— The «decision trees» method
— The «Monte Carlo» simulation method, etc.
Examples of risk analysis and completing the Risk Register.
Determining the level of risk
Mental traps at the risk evaluation stage.
Different options for evaluating risk (qualitative, quantitative and their combination, from ISO 31010:2019).
Assessing and analysing the influence of risks on the decision being made
Ways of visualising the results of evaluation: Risk maps, Decision trees, the Scoring model.
Risk treatment
Mental traps at the risk treatment stage.
Six ways of treating risk.
Choosing the risk treatment method.
Examples of risk treatment.
Risk monitoring and review
Key risk indicators (KRI). The relationship between KRI and KPI.
Leadership
Risk-based decision-making.
Methods of improving the quality of corporate decisions from the «Decision Quality» methodology.
The relationship between strategy, context and the IMS Policy.
Recommendations on developing the IMS Policy.
Responsibility and authority
Methods of describing actions by process (in the form of regulations / control procedures).
Designing business processes and controls.
Basic requirements / recommendations for developing control procedures, and common mistakes.
IMS objectives
The standards' requirements for objective setting.
The relationship between strategy, context, the Policy and the IMS Objectives.
Best practices in risk-based objective setting.
Resources
Determining the competence of personnel needed for the processes to function.
Determining the infrastructure needed for the processes to function.
The in-house knowledge base.
Effective communication. Documented information.
Operations
The terms «verification» and «validation»: examples and explanations.
Managing procurement (externally provided processes, products and services).
Production and service provision.
Control of nonconforming outputs.
Emergency preparedness and response.
Performance evaluation
Internal audit of the IMS.
The procedure for planning, conducting and analysing the results of a risk-based internal audit of the IMS.
IMS review. Best practices.
Improvement
Corrective actions. Examples and best practices.
Continual improvement.
Group game «interactive review of requirements and situations from ISO»
Answers to questions
Course completion