
Five weeks, face to face
Governance, Risk and Compliance Practitioner
Build a management system, run an internal audit, and survive a certification audit. 130 contact hours, workshop-led, producing real documents.
Most GRC training teaches you what the standards say. That is the easy half, and it is available free. The hard half is producing evidence an auditor accepts, writing a policy people follow, and holding a position under questioning when the answer is inconvenient. This programme is workshop-led rather than lecture-led: you leave with a management system you built, an internal audit you conducted, and an evidence pack you have defended, for a fictional organisation, so you can be wrong in front of somebody whose job is to tell you.
~60%
Time in workshop
Producing documents, not taking notes about documents.
7
Modules
Grouped into three blocks, available separately.
This is for you if
- You have been made responsible for ISO 27001 or an audit programme and have not done it before.
- You work in risk, audit or compliance and need the technical grounding to challenge what you are told.
- You are a consultant asked to deliver certification readiness and want a method rather than a template pack.
- You are an IT or security manager whose organisation has just been asked for a certificate by a customer.
It is not, if
- You want a lead auditor certificate. That is sat with an accredited body, and this programme is preparation for it rather than a substitute.
- You need deep technical security skills. The Career Pathway covers that ground.
- You are looking for downloadable templates. You will produce documents here, which is slower and is the point.
What you will be able to do
- Scope and build an ISO 27001 information security management system from nothing.
- Run a risk assessment whose output visibly drives your control selection, rather than the other way round.
- Write a Statement of Applicability covering all 93 Annex A controls, with defensible exclusions.
- Plan and conduct an internal audit, raise nonconformities, and track corrective action to closure.
- Prepare an organisation for stage 1 and stage 2, and know what an assessor will sample.
- Assess scope against NIS2, DORA and the UK Cyber Security and Resilience Bill, and record the reasoning.
- Run a Cyber Essentials readiness check and know which answers fail outright.
- Build an AI management system aligned to ISO 42001 and distinguish an AI impact assessment from a DPIA.
- Assess a third party properly, including the questions that actually reveal something.
Curriculum
Session days are either four or six hours, so day counts are approximate while the hours are exact. 30 days, 130 contact hours in total.
Governance foundations
4 days · 18 hours · Governance structure drafted
What governance is for and how it fails. Governance structures, roles and accountabilities, the three lines model and where it breaks down in a small organisation. Policy hierarchy: what belongs in a policy, a standard, a procedure and a work instruction. Writing policy people follow rather than policy that exists. Management review, board reporting, and translating technical risk into language a director can act on.
Risk management, end to end
5 days · 22 hours · Working risk register
Asset and information identification. Threat and vulnerability analysis. Qualitative and quantitative approaches, and the honest limits of each. Risk appetite and tolerance, and why most published appetite statements are unusable. Building a register that is maintained rather than archived. Treatment options, residual risk, and formal acceptance. Linking risk to control selection so the trace is visible, which is what an auditor is checking.
ISO 27001: building the management system
7 days · 30 hours · ISMS built
Clauses 4 to 10 in full, worked as a build rather than read as a syllabus. Scoping, and why scope is the decision everything else depends on. Leadership and the documented commitments. Planning, objectives, and the risk treatment plan. Support: competence, awareness, communication, documented information. Operation. Performance evaluation, monitoring and measurement. Improvement and corrective action. Then Annex A across all four themes and 93 controls, and producing a Statement of Applicability with justified exclusions.
Internal audit and audit readiness
5 days · 22 hours · Audit conducted
The audit lifecycle: programme, plan, checklist, opening meeting, evidence gathering, closing meeting, report. Sampling, and how an assessor actually chooses what to look at. Interview technique, including how to ask a question that gets an answer rather than a rehearsed statement. Writing a finding that will not be argued away: statement, evidence, requirement, impact. Grading nonconformities. Corrective action, root cause, and verifying closure. Then a full internal audit conducted against the management system built in Module 3, with a written report.
The wider regulatory landscape
5 days · 22 hours · Scope assessments recorded
NIS2, DORA and the UK Cyber Security and Resilience Bill: jurisdiction, sector annexes, size thresholds, and how to record a scope decision you can defend. UK GDPR and the Data Protection Act 2018, including data protection impact assessments and breach notification against the clock. Cyber Essentials and Cyber Essentials Plus, including the answers that fail outright. NIST CSF 2.0 and where it complements rather than duplicates ISO 27001. SOC 2, and how its evidence expectations differ from ISO's.
AI governance and ISO 42001
2 days · 8 hours · AI management system mapped
ISO/IEC 42001 and what transfers from an ISO 27001 management system, which is the machinery rather than the subject matter. Building an AI system inventory, which is usually where the surprises are. AI system impact assessment and why relabelling a DPIA fails both requirements. Where the EU AI Act imposes legal obligations that a voluntary standard does not discharge.
Third-party risk and the capstone
2 days · 8 hours · Evidence pack defended
Supplier due diligence that reveals something: what to ask, what an answer is worth, and how to assess a certificate you have been shown. Contractual security schedules, concentration and fourth-party risk, ongoing monitoring. Then the capstone: you present your management system, your Statement of Applicability, your audit report and your evidence pack, and defend them under questioning.
Taken in blocks, or in full
The programme runs end to end, and each block can also be taken on its own if you would rather commit one at a time.
Block 1: Governance and Risk
Modules 1 to 2 · 9 days · 40 hours
Structures, policy, and a risk register that drives control selection. Available separately.
Block 2: ISO 27001 and Audit
Modules 3 to 4 · 12 days · 52 hours
Build the management system, then audit it. The core of the programme. Available separately.
Block 3: Regulation, AI and Third Party
Modules 5 to 7 · 9 days · 38 hours
The wider landscape, ISO 42001, supplier assurance and the capstone. Available separately.
Week by week
Six days a week, 26 contact hours: five days of four hours and one longer day of six, which is reserved for extended lab work because that needs uninterrupted blocks.
| Week | Focus | Modules |
|---|---|---|
| 1 | Governance structures, three lines, policy hierarchy and writing policy people follow. Management review and board reporting. Risk management begins: asset and information identification, threat and vulnerability analysis. | M1 / M2 |
| 2 | Qualitative and quantitative risk, appetite and tolerance, building a maintained register, treatment and residual risk. ISO 27001 begins: scoping, leadership, planning and the risk treatment plan. | M2 / M3 |
| 3 | ISO 27001 clauses 4 to 10 worked as a build. Support, operation, performance evaluation and improvement. Annex A across all four themes, and producing a Statement of Applicability with justified exclusions. | M3 |
| 4 | Internal audit: programme, plan, checklist, sampling, interview technique, writing findings, grading nonconformities, corrective action and closure. A full internal audit conducted against the system you built. | M4 / M5 |
| 5 | NIS2, DORA and the UK Bill. UK GDPR and DPA 2018. Cyber Essentials. NIST CSF 2.0 and SOC 2. ISO 42001 and AI governance. Third-party risk. Capstone presentation and defence. | M5 / M6 / M7 |
Workshops and artefacts
This programme is workshop-led rather than lab-led, and the distinction matters: the deliverable is a document somebody would accept, not a machine you configured. Roughly sixty per cent of contact time is spent producing artefacts against a fictional organisation, which is deliberately detailed enough that the decisions are real.
- A worked fictional organisation with an estate, a supply chain, real constraints and inconvenient facts.
- Templates you complete rather than read: risk register, Statement of Applicability, audit checklist, finding report, corrective action log.
- The free tools published on this site, used as working instruments: the Annex A browser and SoA builder, the regulatory scope checker, the Cyber Essentials readiness check and the ISO 42001 assessment.
- A mock audit in which you are interviewed as the auditee, and a second in which you audit somebody else.
- A capstone defence, deliberately uncomfortable, because holding a position under questioning is the skill the role requires.
Equipment: A laptop capable of running a word processor and a spreadsheet is sufficient. There is no virtualisation requirement, which is the main practical difference from the Career Pathway.
How it can be delivered
All three programmes are instructor-led and live. That is the distinction that matters: almost everything sold as online security training is recorded video you watch alone. This is a person teaching, answering the question when you ask it rather than in a forum three days later.
Face to face
Cambridge, or at your site
In the room. Best where a team is learning together, where the discussion matters as much as the material, or where somebody benefits from being able to turn a screen round and point at it.
Live online
Anywhere
The same sessions, same schedule, same labs, delivered over video with screen sharing both ways. Every lab already runs on your own laptop, so the practical work is identical rather than reduced.
Hybrid
Mixed
Common for corporate delivery where part of a team is on site and part is not, and for individuals who want the intensive blocks in person and the rest remote.
What actually differs
The material, the labs and the schedule do not change between modes. Two things genuinely do. Reading a room is easier in person, so remote delivery relies more on asking directly whether something has landed, which I do more often as a result. And the informal conversation either side of a session, the question somebody asks while the laptops are booting, happens less online. Neither is a reason to avoid remote delivery, and both are worth knowing before choosing.
Certification
This programme does not issue a lead auditor or lead implementer certificate, and it would be dishonest to imply otherwise: those are sat with accredited certification bodies. What it does is prepare you to pass one and, more usefully, to do the work afterwards. Many people hold the certificate without ever having built a management system; the portfolio you leave with here is the part employers and clients actually test.
ISO/IEC 27001 Lead Auditor
The natural next step. Sat with an accredited body. This programme covers the practice the exam assumes you already have.
ISO/IEC 27001 Lead Implementer
Appropriate if you will be building rather than auditing. Same accredited-body route.
ISO/IEC 42001 Lead Implementer
Emerging credential, best attempted with practical AI governance work behind you.
ISACA CRISC or CISA
Well matched to this material, and both carry experience requirements you may not yet meet.
Next step
Start with a conversation.
Every delivery is scoped to who is in the room. Before anything is quoted we talk through where you are starting from, what you need to be able to do afterwards, and whether this programme is honestly the right one. If it is not, I will say so.
Last reviewed: