Certified ISO 31000 Internal Controls Risk Analyst (CICRA) (REMOTE - EASTERN TIME)

Event Information

Event Date 01-19-2026 8:30 am
Event End Date 01-21-2026 4:30 pm
Cut Off Date 01-16-2026 5:00 pm
Cancel Before Date 01-05-2026
Individual Price USD $2,795.00
Location Remote attendance via ZOOM (Eastern Time)

Group Rate

Number of participants Rate/Person (USD $)
5 2,236.00

CIS Policy Workshop:
ISO 31000 Enterprise Risk Management

(For CICRA Certification)

CICRA social⬇️ Download Brochure

seperator

Overview

Learn ISO 31000 Enterprise Risk Management, and how to leverage the ISO 31000 standard to establish and maintain an ERM program for conducting risk assessments throughout the enterprise.

Then build-out the initial risk program policy right in class! iso 31000

A successful risk management initiative can affect the likelihood and consequences of risks materializing, as well as deliver benefits related to better informed strategic decisions, successful delivery of change and increased operational efficiency. Other benefits include reduced cost of capital, more accurate financial reporting, competitive advantage, improved perception of the organization, better marketplace presence and, in the case of public service organizations, enhanced political and community support. 

And since information security, business continuity/disaster recovery, environmental health and safety, and other critical management systems have the primary purpose of identifying and treating risk, it is essential that your organization establish a common platform and approach for managing risk. 

As the foundation session of CIS risk management training courses, this 3-day risk management training and policy  workshop session provides thorough coverage of the ISO 31000, 31010, 27005, and 23894 standards, as well as setting out advice on the implementation of an ERM initiative. The purpose of the training is to:

  • Describe the principles and processes of risk governance and management;
  • Provide a thorough overview of the requirements of ISO 31000, ISO 31010, 27005, and 23894;
  • Give practical guidance on designing and implementing a suitable enterprise risk management framework;
  • Establish a firm program starting point by using ISO standards 31000:2018, 31010, 27005, and 23894 to build out the initial ERM core policy. Soft-copy editable templates are provided in the instructor-led class:
    • Complete ERM Policy (18-Page template provided)
    • ERM Context and Scope Document (10-Page template provided)
    • ERM Risk Assessment and Risk Treatment Methodology Document (18-Page template provided)
    • Procedure for Training and Development Needs Analysis document (8-Page template provided)
    • ERM Program project kick-off document (9-Page template provided)
    • Procedure for Identification of ERM Project Requirements document (4-Page template provided)
    • Procedure for Identification of Statutory, Regulatory, and Contractual Requirements document (1-Page template provided)
  • Establish a well-developed risk assessment and risk treatment methodology based upon ISO 31010, ISO 27005 and ISO 23894 best practices
  • Leverage ISO best practices to properly identify, analyze, and evaluate risk 
  • Leverage ISO best practices to mitigate ant treat risk to align to the organization's pre-determined risk tolerance thresholds (risk acceptance criteria) 
  • Establish risk monitoring, communication, and reporting
  • Prepare participants for the ISO 31000 CICRA exam #RM101
    31000 CICRA

 

Class details

  • Duration: 3 days, 8:30 - 4:30
  • CPE Credit: 24
  • Materials included with live instructor-led training:
    • Class manual (complete hard copy of class presentation)
    • Hardcopy policy templates
    • Softcopy policy templates
    • 14 days of unlimited access to online practice exams for exam #RM101
    • 1 attempt for the online certification exam #RM101
    • Current-year membership in the CIS Body of Certified Professionals
  •  business continuity plan
  • Professional Certification: This course fulfills all prerequisite training requirements for certification exam #RM101 for professional ISO certifications:
  • Certificate included with class: Upon course completion, we will provide you with an achievement certificate for 24 continuing professional education (CPE) credits that can be used to fulfill requirements for maintaining a variety of professional credentials for fraud examination, accounting, auditing, and information security.
  • Recommended prerequisite training: None
  • Catering for participants attending in-person at location. (Not available for remote virtual classroom participants):
    • Morning refreshments and snack
    • Lunch
    • Afternoon refreshments
  • Hotel and/or Travel: Not included

 

* ISO Standards are NOT included in this risk management training, nor provided in class. ISO standards are available for purchase at www.iso.org.

 

 

seperator

 

Group discounts up to 20% are available!
Discounts are automatically applied when placing booking reservation.

Speakers

Allen Keele

Facilitator

For over 25 years, I’ve worked at the intersection of governance, risk, and cybersecurity. As Principal of Certified Information Security (CIS), I’ve advised Fortune 500 companies, enterprises, heavily regulated industries (banks, governments) worldwide on implementing and sustaining:

  • ISO 27001 Information Security Management Systems
  • NIST Cybersecurity Framework (CSF 2.0) programs
  • ISO 42001 AI Management Systems
  • Enterprise Risk & Compliance strategies based on ISO 31000, ISO 37301, and ISO 22301

𝗛𝗶𝗴𝗵𝗹𝗶𝗴𝗵𝘁𝘀 𝗶𝗻𝗰𝗹𝘂𝗱𝗲:

  • 4,000+ leaders and practitioners 𝘵𝘳𝘢𝘪𝘯𝘦𝘥 & 𝘤𝘦𝘳𝘵𝘪𝘧𝘪𝘦𝘥 𝘪𝘯 𝘎𝘙𝘊 and cybersecurity frameworks
  • 40+ 𝘥𝘪𝘨𝘪𝘵𝘢𝘭 𝘢𝘯𝘥 𝘭𝘪𝘷𝘦 𝘵𝘳𝘢𝘪𝘯𝘪𝘯𝘨 𝘱𝘳𝘰𝘨𝘳𝘢𝘮𝘴 used by corporate teams and government agencies globally
  • Enterprise engagements with organizations such as Amazon, the NSA, and dozens of central banks
  • Authored 7 books on enterprise risk, cybersecurity, and governance frameworks

My focus is helping organizations bridge the gap between policy and operational reality in information security, enterprise risk, and compliance. Whenever you’re ready, here’s how I can help:

1️⃣ Executive & Practitioner Training – train & certify your team in NIST CSF 2.0, ISO 27001, ISO 31000, ISO 22301.

2️⃣ Rapid ISO 42001, 27001, & NIST CSF 2.0 Readiness Assessments – pinpoint gaps and accelerate compliance.

3️⃣ Enterprise GRC Program Design – build practical governance and risk management systems that last.Explore programs at www.certifiedinfosec.com or drop me a message to arrange a quick discovery call.

Contact: allen.keele@certifiedinfosec.com; +1 (904) 406-4311.