Identify and describe IT risks with enough specificity to support a genuine mitigation or acceptance decision.
IT Risk Register Design and Control Self-Assessment
Build an IT risk register that captures genuine exposure, then run control self-assessments that test whether documented controls actually operate as designed.
Course Overview
A risk register that lists forty generic entries such as cyberattack and system failure tells management nothing they can act on, and a control self-assessment that simply asks owners whether their control works produces confident answers that are frequently wrong. This course teaches you to build both properly. You will identify and describe IT risks with enough specificity to support a real decision, score likelihood and impact using the organisation's own risk appetite rather than a generic scale, and map each material risk to the specific controls intended to mitigate it, following ISO 31000 principles throughout. You will then design and run control self-assessments that test control operation with evidence, sampling and challenge, rather than accepting owner self-report at face value. Practical exercises include building a risk and control matrix for a realistic IT environment and facilitating a self-assessment workshop that surfaces uncomfortable but accurate findings.
Expected Learning Outcomes
Score likelihood and impact against the organisation's documented risk appetite rather than a generic scale.
Build a risk and control matrix that maps each material IT risk to its mitigating controls and control owners.
Apply ISO 31000 risk management principles to structure the register's identification, analysis and treatment stages.
Design control self-assessment questionnaires and testing steps that verify operation with evidence, not self-report alone.
Facilitate a control self-assessment workshop that surfaces genuine control weaknesses without triggering defensive responses.
Report risk register and self-assessment results to a risk committee with clear treatment recommendations.
Who Should Attend
IT risk managers building or maturing a risk register
Second-line risk and compliance staff overseeing control self-assessment programmes
Internal auditors validating control self-assessment results
IT control owners responsible for evidencing their own control operation
Enterprise risk management professionals extending frameworks into IT-specific risk
Governance, risk and compliance platform administrators configuring risk register workflows
Course Modules
Select any module to see its sessions and points.
01Identifying and Describing IT Risk
2 sessions · 8 points
Session 1Structuring Risk Identification
- Identify IT risks through structured workshops, incident history and threat intelligence rather than a single brainstorm.
- Write risk statements that name a specific cause, event and consequence rather than a vague category label.
- Distinguish inherent risk, before controls, from residual risk, after controls, throughout the register.
- Group related risks to avoid duplicate entries that fragment the organisation's view of a single underlying exposure.
Session 2Applying ISO 31000 Principles
- Apply the ISO 31000 risk management process stages of identification, analysis, evaluation and treatment consistently.
- Align the register's structure with the organisation's existing enterprise risk management framework.
- Document risk ownership clearly so accountability for treatment does not default to the risk function itself.
- Establish a review cadence that keeps the risk register current as the IT environment changes.
02Scoring Risk and Mapping Controls
2 sessions · 8 points
Session 1Scoring Likelihood and Impact
- Score likelihood using historical incident data and threat intelligence rather than intuition alone.
- Score impact against the organisation's own risk appetite statement, covering financial, operational and reputational dimensions.
- Calibrate scoring across different risk owners so scores remain comparable across the register.
- Flag risks that exceed appetite clearly so they receive priority attention in governance reporting.
Session 2Building the Risk and Control Matrix
- Map each material risk to the specific controls designed to reduce its likelihood or impact.
- Identify risks with no mapped control, or with controls that address only part of the exposure.
- Assign a named control owner accountable for each control's design and ongoing operation.
- Distinguish preventive, detective and corrective controls within the matrix to clarify each control's role.
03Designing Control Self-Assessment
2 sessions · 8 points
Session 1Building the Assessment Methodology
- Design self-assessment questionnaires that ask for evidence of control operation, not a simple yes or no answer.
- Define sampling approaches that test a representative subset of control instances rather than relying on assertion.
- Set assessment frequency based on the criticality of the risk each control addresses.
- Train control owners on how to gather and present evidence before their self-assessment is due.
Session 2Testing and Challenging Results
- Review submitted evidence critically, distinguishing genuine control operation from documentation that merely describes intent.
- Apply independent challenge or spot-testing to a sample of self-assessments to validate their accuracy.
- Identify common patterns of self-assessment inflation and address them through training rather than blame.
- Escalate significant control failures discovered during self-assessment to risk governance promptly.
04Reporting Risk Outcomes to Committees
2 sessions · 8 points
Session 1Facilitating the Assessment Workshop
- Facilitate a self-assessment workshop that encourages honest disclosure of control weaknesses.
- Manage discussions where control owners disagree about a risk score or control effectiveness rating.
- Capture agreed remediation actions during the workshop rather than as a separate follow-up exercise.
- Document dissenting views where consensus cannot be reached, for resolution by the risk committee.
Session 2Reporting to the Risk Committee
- Prepare a risk committee report that highlights risks exceeding appetite and controls found ineffective.
- Recommend specific treatment options, including mitigation, transfer, avoidance or acceptance, for each flagged risk.
- Track remediation actions from self-assessment findings through to verified closure.
- Trend self-assessment results over successive cycles to demonstrate whether control effectiveness is improving.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
