Information & Communications Technology

IT Risk Register Design and Control Self-Assessment

Build an IT risk register that captures genuine exposure, then run control self-assessments that test whether documented controls actually operate as designed.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

A risk register that lists forty generic entries such as cyberattack and system failure tells management nothing they can act on, and a control self-assessment that simply asks owners whether their control works produces confident answers that are frequently wrong. This course teaches you to build both properly. You will identify and describe IT risks with enough specificity to support a real decision, score likelihood and impact using the organisation's own risk appetite rather than a generic scale, and map each material risk to the specific controls intended to mitigate it, following ISO 31000 principles throughout. You will then design and run control self-assessments that test control operation with evidence, sampling and challenge, rather than accepting owner self-report at face value. Practical exercises include building a risk and control matrix for a realistic IT environment and facilitating a self-assessment workshop that surfaces uncomfortable but accurate findings.

Expected Learning Outcomes

01

Identify and describe IT risks with enough specificity to support a genuine mitigation or acceptance decision.

02

Score likelihood and impact against the organisation's documented risk appetite rather than a generic scale.

03

Build a risk and control matrix that maps each material IT risk to its mitigating controls and control owners.

04

Apply ISO 31000 risk management principles to structure the register's identification, analysis and treatment stages.

05

Design control self-assessment questionnaires and testing steps that verify operation with evidence, not self-report alone.

06

Facilitate a control self-assessment workshop that surfaces genuine control weaknesses without triggering defensive responses.

07

Report risk register and self-assessment results to a risk committee with clear treatment recommendations.

Who Should Attend

01

IT risk managers building or maturing a risk register

02

Second-line risk and compliance staff overseeing control self-assessment programmes

03

Internal auditors validating control self-assessment results

04

IT control owners responsible for evidencing their own control operation

05

Enterprise risk management professionals extending frameworks into IT-specific risk

06

Governance, risk and compliance platform administrators configuring risk register workflows

Course Modules

Select any module to see its sessions and points.

01

Identifying and Describing IT Risk

2 sessions · 8 points

Session 1Structuring Risk Identification

  • Identify IT risks through structured workshops, incident history and threat intelligence rather than a single brainstorm.
  • Write risk statements that name a specific cause, event and consequence rather than a vague category label.
  • Distinguish inherent risk, before controls, from residual risk, after controls, throughout the register.
  • Group related risks to avoid duplicate entries that fragment the organisation's view of a single underlying exposure.

Session 2Applying ISO 31000 Principles

  • Apply the ISO 31000 risk management process stages of identification, analysis, evaluation and treatment consistently.
  • Align the register's structure with the organisation's existing enterprise risk management framework.
  • Document risk ownership clearly so accountability for treatment does not default to the risk function itself.
  • Establish a review cadence that keeps the risk register current as the IT environment changes.
02

Scoring Risk and Mapping Controls

2 sessions · 8 points

Session 1Scoring Likelihood and Impact

  • Score likelihood using historical incident data and threat intelligence rather than intuition alone.
  • Score impact against the organisation's own risk appetite statement, covering financial, operational and reputational dimensions.
  • Calibrate scoring across different risk owners so scores remain comparable across the register.
  • Flag risks that exceed appetite clearly so they receive priority attention in governance reporting.

Session 2Building the Risk and Control Matrix

  • Map each material risk to the specific controls designed to reduce its likelihood or impact.
  • Identify risks with no mapped control, or with controls that address only part of the exposure.
  • Assign a named control owner accountable for each control's design and ongoing operation.
  • Distinguish preventive, detective and corrective controls within the matrix to clarify each control's role.
03

Designing Control Self-Assessment

2 sessions · 8 points

Session 1Building the Assessment Methodology

  • Design self-assessment questionnaires that ask for evidence of control operation, not a simple yes or no answer.
  • Define sampling approaches that test a representative subset of control instances rather than relying on assertion.
  • Set assessment frequency based on the criticality of the risk each control addresses.
  • Train control owners on how to gather and present evidence before their self-assessment is due.

Session 2Testing and Challenging Results

  • Review submitted evidence critically, distinguishing genuine control operation from documentation that merely describes intent.
  • Apply independent challenge or spot-testing to a sample of self-assessments to validate their accuracy.
  • Identify common patterns of self-assessment inflation and address them through training rather than blame.
  • Escalate significant control failures discovered during self-assessment to risk governance promptly.
04

Reporting Risk Outcomes to Committees

2 sessions · 8 points

Session 1Facilitating the Assessment Workshop

  • Facilitate a self-assessment workshop that encourages honest disclosure of control weaknesses.
  • Manage discussions where control owners disagree about a risk score or control effectiveness rating.
  • Capture agreed remediation actions during the workshop rather than as a separate follow-up exercise.
  • Document dissenting views where consensus cannot be reached, for resolution by the risk committee.

Session 2Reporting to the Risk Committee

  • Prepare a risk committee report that highlights risks exceeding appetite and controls found ineffective.
  • Recommend specific treatment options, including mitigation, transfer, avoidance or acceptance, for each flagged risk.
  • Track remediation actions from self-assessment findings through to verified closure.
  • Trend self-assessment results over successive cycles to demonstrate whether control effectiveness is improving.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course