Course Home
Enterprise Risk Management in Practice
A nine-session written course on why ERM succeeds or fails through discipline and culture, not through the size of the policy manual.
|
Disclaimer This course is provided for general information and education only. It is not legal advice. Legislation, rules and regulatory guidance change, sometimes quickly. Readers should confirm the current position and obtain jurisdiction-specific professional advice where needed. The views and experience expressed are Russel Fielding's own and do not represent any employer or client organisation. |
Enterprise Risk Management in Practice: a practitioner's course
This nine-session written course explains how enterprise risk management actually works inside a regulated institution: how it is governed, how risk is identified, assessed, controlled and monitored, and why culture determines whether the framework changes decisions.
It is written for risk professionals, senior managers, board members and change professionals working on risk transformation. The perspective is practical: what a working ERM programme looks like from the inside, not how it appears in a policy document.
The course is principle-led. The discipline of enterprise risk management does not change materially between the UK, New Zealand, and Australia, even though the specific rules and supervisors do. Examples are drawn from wherever they illustrate a point most clearly, with the Basel framework as the shared international reference point running through the course.
The nine sessions
Each session is self-contained. Each ends with a Key Takeaways box and pointers to the underlying regulatory guidance and published Ārai Tika material.
Introduction: Why Enterprise Risk Management Is the Central Discipline of Banking
From siloed to integrated risk management, a working definition of ERM, and the core risk categories every institution has to manage.
Governance, the Board and Risk Appetite
What active board oversight of risk actually looks like, the documents a real ERM programme produces, and why so many risk appetite statements fail to constrain anything.
The Three Lines Model
How risk responsibility is distributed across an institution, what genuine independence looks like for the second and third lines, and how the model most often breaks down.
The Regulatory Framework: Basel and Capital Adequacy
The Basel framework, the evolution of capital adequacy, and what jurisdictional differences in implementation mean in practice.
Risk Identification and Assessment
The techniques used to surface risk before it materialises, and why the most damaging risks are usually the ones nobody adequately anticipated.
Risk Mitigation and Controls
The four responses to identified risk, what makes a control environment genuinely effective, and how institutions manage concentration risk.
Monitoring, Stress Testing and the ICAAP/ILAAP
Continuous monitoring versus periodic review, stress testing as a management tool rather than a submission, and what a strong internal capital assessment demonstrates.
Risk Culture, Maturity and Emerging Risks
Why culture is where ERM programmes succeed or fail, maturity models as a diagnostic, and the risk categories reshaping the landscape.
Implementation Summary
A consolidated checklist across governance, the three lines, capital, identification, controls, monitoring, and culture. A working reference to return to.
From this course
| Discipline over documentation | Written from the position of someone who has worked inside the governance, risk, and delivery functions of large regulated institutions. The course treats ERM as a management discipline first and a compliance framework second. |
| Principle-led, with examples | ERM does not change materially between jurisdictions, even where the specific rules and supervisors do. Examples are drawn from wherever they illustrate a point most clearly, with the Basel framework as the shared international reference point. |
| A working reference | Includes the consolidated implementation checklist in Session Nine, built for use when reviewing a live programme or benchmarking maturity, not for one-off reading. |
Primary frameworks covered
The frameworks below recur throughout the course. They are included as orientation points for the reader, not as an exhaustive taxonomy of ERM standards or prudential rules.
| Basel Committee on Banking Supervision | The international standard-setting body behind the Basel framework, and the shared prudential reference point for the jurisdictions this course draws on. |
| Basel 3.1 output floor | Once fully phased in, banks using internal models must still hold capital based on the higher of that model's output and 72.5% of the standardised approach result. |
| The Three Lines Model | The Institute of Internal Auditors' governance model distributing risk ownership, oversight, and assurance across an institution. Updated from the Three Lines of Defence in 2020. |
| COSO and ISO 31000 | The two most widely referenced ERM frameworks: COSO's five interrelated components, and ISO 31000's principles-based, non-prescriptive standard. |
| RIMS Risk Maturity Model | A risk maturity framework used in Session Eight as a practical diagnostic tool for assessing how consistently risk management is embedded, governed and improved. |
Start with Session One
Begin with Session One: Why Enterprise Risk Management Is the Central Discipline of Banking
Read the opening session →For other practitioner material across AML, fraud and financial crime, transformation, and information security and data privacy, visit araitika.com.