Risk Management E-learning Courses for Regulated Firms - IIRSM Approved
Learn to manage risks in multiple scenarios with our Risk Management course library. Packed with IIRSM-accredited modules, our library trains your employees in the fundamentals of risk management.
Identify, prevent and manage risks
Best for…
Companies seeking to upskill their employees on the fundamentals of risk management.
Hosted on…
The Skillcast Learning Management System (LMS) or your existing platform.
Learn with…
Nine fundamentals of risk management (FoRM) modules and business risk courses.
Available in...
All of the courses in our Risk library are available in Brazilian Portuguese, Chinese Simplified, Dutch, English, French, German, Italian, Japanese, Polish and Spanish.
Train your teams to understand and apply key risk management principles
Available in multiple languages, our Risk Management course library equips your team with the knowledge of crucial risk management principles. With teachings on specific risks, such as financial crime, fraud, and health and safety, our risk management courses provide education on identifying and preventing common business risks.
You can host this library on our managed LMS portal or use your own. Plus, you can customise your learning experience by exploring our bespoke training plans.
Learning styles in this library
In-depth
These are our more detailed e-learning courses that include practice scenarios and typically last between 25 and 45 minutes.
Refresher
These targeted courses help reinforce your employees' knowledge and notify them of any updates they might not be aware of. These typically last between 15 and 20 minutes.
Express
Our focused training courses deliver employee learning in smaller chunks, typically lasting between 10 and 15 minutes.
Microlearning
These bite-sized animated training videos can be delivered as: standalone, embedded in detailed e-learning courses, or compiled into a learning path.
What you'll find in our Risk Management course library
Browse our Risk Management course library below. Looking for something specific? Use the search bar to find what you need. If you have any questions, reach out and tell us more about your requirements - we’re here to help.
Operational Risk
Operational risk frameworks usually fail at the reporting layer, not the design layer, because staff never learned what counts as a risk event worth escalating. A shared way of describing cause and consequence fixes more of that than another policy revision will. This course gives every function the same language, which is what makes aggregated risk data mean something to a board.
Explore the course
The Three Lines of Defence
Most firms have the model on a slide and confusion in practice, usually where the first and second lines meet. Ownership gaps at that boundary are where risks sit unmanaged. Giving every function a shared understanding of the model turns an organisational chart into working accountability, and it makes internal audit findings considerably easier to act on.
Explore the course
Risk Management
Risk registers age badly when they belong to one team. Organisations that manage risk well are the ones where operational staff escalate early because they know what the framework does with the information. Spreading that understanding wide enough is the difference between a risk framework that informs decisions and one that merely documents them after the fact.
Explore the course
Risk Assessment
Assessment output shapes risk appetite, and risk appetite shapes almost every governance decision that follows. When assessments are inconsistent, the aggregated picture the board sees is wrong in ways nobody can see. Training staff on a common method is the least glamorous and most effective improvement available to a risk programme, and it makes comparison across business units meaningful.
Explore the course
Cyber Risk
Technical controls fail at the point where a person makes a decision, which is why attackers spend their effort there. Regulators now treat cyber resilience as a governance matter rather than an IT matter, and expect board-level oversight. Training all staff rather than the technology function alone is the control that scales, and it is the one supervisors ask to see evidenced.
Explore the course
Risk Identification
Poorly worded risks are worse than missing ones because they create false confidence. A register full of vague statements cannot be assessed, prioritised or assigned. Teaching staff to separate cause from event from consequence is a small discipline with a large effect on the quality of everything downstream, including your board reporting and your control testing.
Explore the course
Business Travel Risk
Duty of care does not pause at the airport. Employers remain responsible for staff safety abroad, and that responsibility is tested when something goes wrong in a location where support is thin. Briefing travellers properly before departure is far cheaper than managing an incident remotely, and it gives your organisation a documented position on how it discharges that duty.
Explore the course
Developing Secure Applications
Vulnerabilities introduced in development are the cheapest to fix and the most expensive to ignore. Security testing at the end of a pipeline finds what is already built. For firms subject to DORA, NIS2 or supplier security assessments, evidence that development teams are trained in secure practice is increasingly requested directly, not inferred from your policy set.
Explore the course
ESG Risk
ESG risk has moved from a reporting exercise to a financial one, affecting cost of capital, insurance terms, supply chain access and litigation exposure. Treating it as a disclosure problem leaves the underlying risk unmanaged. This course puts ESG into the same risk language your organisation already uses elsewhere, which makes it possible to prioritise rather than simply report.
Explore the course
Business Continuity Management
Continuity plans are written by a small group and executed by everyone, usually at short notice and under stress. If staff first encounter the plan during an incident, it will not work as designed. Training the wider workforce is what converts documentation into capability, and it supports the resilience expectations that now apply across financial services and beyond.
Explore the course
Risk Appetite
A risk appetite statement approved by the board and unknown to the business achieves nothing. Appetite only functions when the people making operational decisions can tell whether a proposal sits inside it. This course pushes that understanding down to where the decisions happen, which is the difference between appetite as governance language and appetite as a working constraint.
Explore the course
Risk Treatment
Treatment decisions are where risk management either earns its place or becomes an overhead. Controls added without weighing cost against benefit slow the business and rarely get followed. Teaching staff to think in terms of proportionate response produces a control environment people actually use, and gives internal audit something more useful to test than whether a control exists.
Explore the course
Risk Reporting
Boards make decisions on what reaches them, and what reaches them depends on people at the operational level judging what is worth reporting. Poor input cannot be corrected further up the chain. Training staff on what good risk reporting looks like improves the raw material, which does more for governance quality than another layer of review ever will.
Explore the course
Risk Monitoring
Risk registers describe the world as it was on the day someone last reviewed them. Between reviews, exposures move and controls degrade quietly. Building monitoring awareness across the business means changes get noticed by the people closest to them rather than at the next quarterly cycle, which is usually the difference between managing a risk and reporting an incident.
Explore the course
Credit Risk for Financial Firms
Credit risk concentrates quietly. Exposures built individually look reasonable until they are aggregated against a common driver, and by then the position is hard to unwind. Giving staff beyond the credit function a working understanding of how exposure accumulates improves the quality of what gets escalated, and supports the risk culture prudential supervisors expect to see.
Explore the course
Credit Risk for Non-Financial Firms
In non-financial businesses credit risk usually sits with finance and is invisible to the commercial teams creating it. A large order from a weak counterparty looks like good news until it is not paid. Giving sales, procurement and operations a working grasp of the exposure they generate improves the quality of the decisions taken before a contract is signed.
Explore the course
Continual Improvement of Risk Management
Frameworks decay in predictable ways: the register stops matching the business, controls persist after the risk has moved, and incidents produce reports rather than changes. Building improvement into the cycle rather than into an annual review is what keeps the framework worth maintaining. It is also what supervisors look for when assessing whether risk management is genuinely embedded.
Explore the course
Introduction to Risk
Risk frameworks fail early when people cannot separate a cause from an event or an issue from a risk. Everything built on top of that confusion, including the register, the appetite statement and the board report, inherits the problem. Establishing shared definitions across the business is the cheapest improvement available to a risk function, and it makes every later stage of the framework work better.
Explore the course
Third-Party Risk
Concentration is the part firms underestimate. Several suppliers can depend on the same underlying provider, so a single failure removes what looked like a diversified arrangement. Regulators now ask about that directly. Training staff who select, onboard and manage suppliers gives your organisation the visibility a contract review alone will never produce.
Explore the course
Physical and Personal Security Risk
Physical security is often assumed to be someone else's responsibility, which is precisely what tailgating and social engineering rely on. The person holding the door open is the control that failed. Building awareness across the workforce protects staff directly and closes the entry route that defeats access control systems, which matters more as physical and cyber intrusion increasingly overlap.
Explore the course
Purpose-designed software to bolster your compliance efforts
The Skillcast Portal provides a centralised platform to handle your e-learning and policy management, staff disclosures, compliance registers, and other compliance automation tools. Available in three plans - Standard, Enhanced and Premium - the Skillcast Portal helps you to elevate your compliance training delivery, with all plans including our five-star managed services and security as standard.