|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/iso31000/
课程评论:没有评论
课程名称:ISO31000将风险管理纳入决策制定 课程概述:风险管理不仅应帮助企业满足最低法律合规要求,还应为目标的可证明实现做出贡献,将风险与业绩紧密联系。根据ISO31000标准,将风险管理整合到组织中是一个动态的、迭代的过程,应根据组织的需求和文化进行定制。风险管理应该是组织治理、领导力、战略、运营和绩效管理中不可或缺的一部分,而不是一个孤立的过程。Alex Sidorenko创建了一个25步程序,以将风险管理整合到决策制定、核心业务流程和整体文化中。本课程涵盖了设计、实施和衡量风险管理有效性的实际步骤。 本课程将帮助您回答以下问题:关键利益相关者是否相信风险管理与战略、目标和文化相一致,并有助于实现组织目标?是否制定了风险管理声明或政策?管理层是否表现出对将风险管理纳入所有流程或决策类型的承诺,给予风险团队充足的资源和责任?责任是否定期由高层管理向管理层和员工沟通?监督机构是否相信在设定组织目标时风险已得到充分考虑?有关风险及其管理的信息是否在监督机构收到的报告中呈现,并纳入任何重大决策中?独立风险管理有效性评估的结果是否定期呈报给监督机构?风险管理的努力是否与内外部环境一致(满足监管要求和利益相关者期望)?风险管理原则是否已纳入现有政策和程序,而不仅仅是有一个单独的风险管理框架文件? 风险识别和分析的责任是否在委员会章程、政策、程序和职位描述中有记录?风险管理团队是否具备有效将风险管理纳入业务活动和决策所需的资源?有关风险及其管理的信息是否融入现有的财务和管理报告中?组织是否有计划将风险管理实施到所有活动中,包括决策过程?管理层是否在分析与决策相关的风险后,才做出重大决策和批准?风险管理是否融入规划、预算、激励和绩效管理流程,而不是作为独立的风险管理过程?战略目标、目标和关键绩效指标是否基于风险分析的结果设定?风险管理是否融入核心运营流程,操作活动中是否持续分析风险?关键支持(后台)流程是否以考虑风险及其处理的方式组织?基于风险的决策是否在子公司、关键供应商和供应链中一致适用?所有关键部门是否发展了风险管理能力?风险管理能力是否纳入员工的培训和发展计划中,是否定期针对各级管理层进行风险管理培训?在组织内申请工作时,风险管理能力是否是一个重要属性?您认为组织是否有强烈的文化,致力于基于风险的决策和风险管理? 本课程的内容与ISO31000:2018的结构和原则完全一致。对于风险管理人员、风险顾问、审计师以及所有希望了解更多风险管理知识的人来说,该课程将极具价值。
Risk management should not only help companies to achieve minimum legal compliance requirements but also contribute to the demonstrable achievement of objectives, linking risks with performance. According to ISO31000 standard, integrating risk management into an organization is a dynamic and iterative process, and should be customized to the organization's needs and culture. Risk management should be a part of, and not separate from, the organizational governance, leadership, strategy, operations and performance management.Alex Sidorenko has created a 25-step program to integrate risk management into decision making, core business processes and the overall culture of the organization. This course covers practical steps to design, implement and measure effectiveness of risk management. This course will help you answer the following questions: Do key stakeholders believe risk management is aligned with strategy, objectives and culture and helps the organization achieve its objectives?Is there a risk management statement or policy?Does management show commitment to the integration of risk management into all processes or decision types, giving risk team sufficient resources and responsibility?Is responsibility for risk management as part of business activities and decision making regularly communicated by top management to management and staff?Are oversight bodies confident that risks have been adequately considered when setting the organization's objectives?Is information about risks and their management presented in the reports that oversight bodies receive and included in any significant decisions they have to make?Are results of independent risk management effectiveness assessments presented to the oversight bodies on a regular basis?Is risk management effort consistent with internal and external environment (meeting both regulatory requirements and stakeholder expectations)?Have risk management principles been integrated into existing policies and procedures instead of just having a single aggregated risk management framework document?Has the responsibility for risk identification and analysis been documented in the committee charters, policies, procedures and job descriptions?Does risk management team have the necessary resources to effectively integrate risk management into business activities and decision making?Is information about risks and their management integrated in existing financial and management reporting?Does an organization have a plan to implement risk management into all activities throughout the organization, including decision-making?Are significant decisions and approvals made by the management only after analysing the risks associated with these decisions?Is risk management integrated into planning, budgeting, motivation and performance management processes instead of having a standalone risk management process?Are strategic goals, objectives and key performance indicators set based on the results of the risk analysis?Is risk management integrated in core operational processes, risks are analysed on an ongoing basis within operating activities?Are key supporting (back-office) processes organized in such a way, that risks and their treatments are considered?Is risk-based decision making consistently applied across subsidiaries, key suppliers and supply chains?Are risk management competences developed in all key departments?Are risk management competences integrated in the training and development program for employees, is there regular risk management training for different levels of management?Are risk management competences an important attribute when applying for jobs in the organization?Do you consider organization has a strong culture dedicated to risk-based decision making and risk management?The content of the course is 100% aligned with the structure and principles of the ISO31000:2018. This course will be immensely valuable for risk managers, risk consultants, auditors and everyone who want to learn more about risk management 2.