Governance, risk & compliance
The standards that decide how an organization makes decisions, prices its risks, and proves it stayed inside the rules. Less glamorous than security, and usually the thing that fails an audit.
Four standards, four different questions
Risk management, anti-bribery, compliance management and IT governance are separate disciplines that share a vocabulary. Knowing which one your problem belongs to saves you buying the wrong credential.
Risk & compliance
How risk gets identified, priced and treated, and how compliance obligations get managed.
Ethics & anti-bribery
The management system for bribery risk, increasingly demanded in procurement.
IT governance & assurance
Board-level direction of IT, plus the internal audit capability that checks any of it.
The credential that travels furthest
ISO 31000 risk management is the one that shows up in every other standard in our catalogue — 27001, 22301, 42001 and 37301 all assume you can run a risk assessment. If you're picking one course from this family and don't have a specific driver, start there.
-
Risk is the shared foundationISO 31000 methodology underpins the risk clauses of most other management-system standards
-
Procurement pressureISO 37001 certification increasingly appears as a supplier requirement in public tenders
-
One auditor, many standardsThe MS Internal Auditor credential is standard-agnostic and covers whichever systems you run
-
Board-facing languageISO/IEC 38500 is written for directors, which makes it useful when you need budget
Foundation to Lead — pick the one that matches the job
Not every standard offers every level, but where they exist the ladder is consistent. Choose by the work you'll do, not by which title sounds most senior.
Three ways to take any course
Same accreditation, same exam, same certificate. The difference is how much structure and instructor access you want along the way.
Self-study
Course materials and exam voucher, worked at your own pace. The lowest-cost route, and a reasonable one if you already work in the subject.
Browse self-studyeLearning
Recorded instruction with structured modules and assessments. Fits around a working week without needing fixed dates.
Browse eLearningLive online
Scheduled cohorts with a practising instructor you can question in real time. The format most people pass first time with.
See upcoming datesEvery course in this category
16 courses. Current pricing, delivery formats, languages and the full session calendar are on each course page.
Before you enrol
ISO 31000 Foundation, then Risk Manager if the role is genuinely risk-focused. The methodology transfers to every other management system you'll touch, so it's rarely wasted money even if your job changes.
No — the driver is usually procurement rather than geography. Public-sector and large-enterprise tenders increasingly ask suppliers to demonstrate an anti-bribery management system, and having certified staff is the first step toward certifying the organization.
Internal auditing technique that isn't tied to one standard — planning, evidence gathering, nonconformity classification, reporting. Useful if you run several management systems, or one and expect to add more. It sits between Foundation and Lead Auditor in depth.
Introduction is a shorter, cheaper overview for people who need awareness rather than a credential — useful for wider teams. Foundation is the certified entry level and the prerequisite mindset for the Lead courses.
Which GRC standard does your problem belong to?
Describe the pressure you're under — an audit finding, a tender requirement, a board question — and we'll tell you which of these sixteen courses answers it.