Compliance and Compliance Risk Management

This course, presented by David Tattam, Chief Research and Content Officer at Protecht, covers both Compliance Management and Compliance Risk Management. The focus is on the development of an efficient risk-based approach to compliance management and what that means in practice from recording compliance obligations to setting up a risk-based approach to monitoring compliance. The management of compliance risk is also covered using an ERM framework.
  Course Launch: On-Demand
Course Access:  90 days from date of purchase

5 Hours


About This Course

Course Description

In this course, you'll learn:

1. Why we need compliance management

  • Why we have regulations – society's risk appetite
  • Organisation objectives related to compliance
  • The changing face of compliance

2. What is compliance management and compliance risk management?

  • Defining compliance
  • Mandatory and voluntary requirements
  • Scoping the compliance function
  • Defining compliance risk management

3. What are compliance obligations?

  • Sourcing obligations
  • Translating into plain language obligations

4. Compliance risk and compliance controls

  • ISO 31000 and ISO 37301 definitions of risk
  • A risk-based approach to compliance
  • The link to operational risk
  • Introducing risk bow ties and the components of risk
  • Controls over compliance a
  • nd compliance risks

5. Compliance management

  • Understand compliance obligations Convert to plain language
  • Risk rating obligations
  • Preparing the organization to comply
  • Manage ongoing compliance
  • Compliance attestations
  • Record and analyze results
  • Reporting and analytics

6. Compliance change management

  • Internal and external changes
  • Risk managing external regulatory change
  • Risk managing internal systems, process, people, product changes

7. Compliance risk management

  • Applying ISO 31000 risk processes to compliance
  • Assessing risks leading to noncompliance
  • Linking obligations to risk bow ties

8. Risk appetite for compliance

  • What is risk appetite for compliance risk?
  • Setting an appetite for compliance risk
  • What does “zero-appetite / tolerance” mean?

9. Compliance risk assessment

  • Linking compliance to risk processes
  • Incorporating compliance into risk and control self-assessments

10. Risk metrics for compliance risks

  • Identifying risk metrics for compliance risk
  • Determining thresholds for compliance risk metrics
  • The risk metrics process

11. Compliance controls management

  • Identifying key controls for compliance risk
  • Obtaining assurance over key controls
  • Controls testing and developing a test plan

12. Compliance incident management

  • Defining a compliance breach Identifying a compliance breach
  • Developing a process for breach management
  • Meeting external requirements
  • Setting up and managing a breach register

13. Compliance reporting

  • Objectives of reporting
  • Receivers of compliance reports
  • Types of compliance reports
  • Defining your reports

14. Compliance roles and responsibilities

  • Introduction to the 3 lines model
  • Compliance across the 3 lines
  • Features of strong compliance culture
  • Challenges and solutions for effective compliance management

Course Expectations:

  • Watch 16 videos
  • Answer 9 knowledge questions
  • Answer 10 quiz questions
  • 5 downloadable materials


  • 4.5 hours of video content
  • Approximately 5 hours for the whole course

About Our Experts


David Tattam is the Chief Research & Content Officer and co-founder of the Protecht Group. David's vision is to redefine the way the world thinks about risk and to develop risk management to its rightful place as being a key driver of value creation in each of Protecht's customers.

Michael Howell is Protecht's Research and Content Lead. He is passionate about the field of risk management and related disciplines, with a focus on helping organisations succeed using a ‘decisions eyes wide open’ approach.

Continued Risk Learning Credits: 5

PRMIA Continued Risk Learning (CRL) programs provide you with the opportunity to formally recognize your professional development, documenting your evolution as a risk professional. Employers can see that you are not static, making you a highly valued, dynamic, and desirable employee. The CRL program is open to all Contributing, Sustaining, and Risk Leader members, providing a convenient and easily accessible way to submit, manage, track and document your activities online through the PRMIA CRL Center. To request CRL credits, please email [email protected].

 Membership Type Price
 Members $479
 Non-members $599

If this is your first time accessing the PRMIA website you will need to create a short user profile to register. Save on registration by becoming a member.


Register Now

Virtual Course
Registration not available.

Sign In to Register for Event


Contact Us

Looking to further your career?

Become a Member

Sign Up for Mailing List

Thank you to our sponsors, including:


Contact Us

Looking to further your career?

Become a Member

Sign Up for Mailing List