IT Governance, Risk and Compliance

Wishlist Share

About Course

Executive Certificate Programme for Board Members, Senior Executives and Technology Leaders
Duration: 5 Days (40 Hours)
Level: Executive / Board / Senior Management Level
Delivery Mode: Classroom, Virtual or Hybrid

International Standards Alignment: ISO 38500 (Corporate Governance of IT), COBIT 2019, ISO 27001 Information Security Management Systems, ISO 31000 Risk Management, NIST Cybersecurity Framework (CSF 2.0), COSO Enterprise Risk Management Framework, GDPR, EU Digital Operational Resilience Act (DORA), Sarbanes-Oxley Act (SOX), Basel Committee Operational Risk Principles, PCI-DSS, ISACA Governance Frameworks, and OECD Corporate Governance Principles.
Course Overview
Technology is now a strategic business enabler rather than merely an operational function. Boards and senior executives are increasingly responsible for overseeing technology investments, digital transformation initiatives, cybersecurity resilience, data governance, technology risks, regulatory compliance, and IT performance.
Failure to effectively govern technology can expose organizations to cyberattacks, operational disruptions, regulatory penalties, reputational damage, data breaches, and strategic failures. Consequently, effective IT Governance, Risk and Compliance (IT GRC) has become a board-level priority.
This executive programme equips Board Members, CEOs, CIOs, CROs, Audit Committee Members, and senior leaders with the knowledge, tools, and governance frameworks required to oversee IT strategy, technology risks, cybersecurity, regulatory compliance, digital resilience, and technology-enabled value creation.
Participants will engage in practical workshops, board simulations, cyber crisis exercises, governance assessments, case studies, and a capstone project designed around real-world governance challenges.

Training Outcomes
Upon successful completion of the programme, participants will be able to:
1. Understand board and executive responsibilities in IT governance.
2. Establish effective IT governance frameworks aligned with corporate strategy.
3. Strengthen oversight of technology risks and cybersecurity threats.
4. Evaluate technology investments and digital transformation initiatives.
5. Develop enterprise-wide IT risk management frameworks.
6. Improve compliance with global IT and data protection regulations.
7. Enhance organizational cyber resilience and operational continuity.
8. Strengthen board reporting through technology performance metrics.
9. Oversee data governance, privacy, and emerging technology risks.
10. Build a future-ready IT governance and compliance programme.
Target Audience
• Board Chairpersons
• Non-Executive Directors
• Executive Directors
• Chief Executive Officers (CEOs)
• Chief Information Officers (CIOs)
• Chief Technology Officers (CTOs)
• Chief Information Security Officers (CISOs)
• Chief Risk Officers (CROs)
• Chief Compliance Officers (CCOs)
• Audit Committee Members
• Risk Committee Members
• Corporate Secretaries
• Internal Auditors
• IT Governance Managers
• Regulators and Supervisory Authorities
• Financial Institution Executives
• Public Sector Leaders

Course Units and Sub-Units

Unit 1: Foundations of IT Governance
Sub-Units
• Evolution of IT Governance
• Strategic Importance of Technology Governance
• Board Responsibilities for IT Oversight
• Governance Principles under ISO 38500
• COBIT Governance Framework
• Governance Structures and Accountability
• IT Governance Maturity Models
• Global Governance Trends
Unit 2: Aligning IT Strategy with Business Strategy
Sub-Units
• Strategic Alignment Principles
• Enterprise Digital Strategy
• Technology Value Creation
• Business-IT Alignment Models
• IT Investment Governance
• Strategic Technology Roadmaps
• Innovation Governance
• Measuring Strategic Technology Outcomes
Unit 3: Enterprise IT Risk Management
Sub-Units
• IT Risk Fundamentals
• Risk Governance Structures
• Risk Appetite and Tolerance
• Enterprise Technology Risk Assessment
• Third-Party and Vendor Risks
• Cloud Computing Risks
• Emerging Technology Risks
• Risk Reporting and Monitoring
Unit 4: Cybersecurity Governance and Oversight
Sub-Units
• Cybersecurity Governance Frameworks
• NIST Cybersecurity Framework
• Cyber Threat Landscape
• Board Cybersecurity Responsibilities
• Cyber Risk Management
• Incident Response Governance
• Cybersecurity Investment Decisions
• Cybersecurity Metrics and Dashboards
Unit 5: Information Security and Data Governance
Sub-Units
• Information Security Governance
• ISO 27001 Framework
• Data Governance Principles
• Data Classification and Protection
• Data Ownership and Stewardship
• Data Lifecycle Management
• Information Security Policies
• Board Oversight of Information Assets
Unit 6: Technology Compliance and Regulatory Requirements
Sub-Units
• IT Regulatory Environment
• GDPR Compliance Requirements
• DORA Requirements
• SOX Technology Controls
• PCI-DSS Standards
• Compliance Risk Management
• Regulatory Reporting Obligations
• Board Compliance Oversight
Unit 7: Digital Operational Resilience and Business Continuity
Sub-Units
• Operational Resilience Frameworks
• ICT Risk Management
• Business Continuity Planning
• Disaster Recovery Governance
• Crisis Management Structures
• Resilience Testing and Simulations
• Third-Party Resilience Management
• Board Resilience Oversight

Unit 8: IT Audit, Assurance and Internal Controls
Sub-Units
• IT Audit Fundamentals
• Internal Control Frameworks
• Technology Assurance Models
• Audit Planning and Execution
• IT General Controls (ITGCs)
• Audit Committee Responsibilities
• Control Deficiency Management
• Audit Reporting and Follow-Up
Unit 9: Emerging Technologies, AI and Innovation Governance
Sub-Units
• Artificial Intelligence Governance
• Responsible AI Principles
• AI Risk Management
• Cloud Governance
• Blockchain Governance
• Internet of Things (IoT) Risks
• Emerging Technology Oversight
• Ethical Technology Governance
Unit 10: Board Leadership in IT Governance and Digital Transformation
Sub-Units
• Digital Leadership Competencies
• Board Technology Committees
• Technology Performance Dashboards
• Digital Transformation Governance
• Technology Investment Oversight
• Stakeholder Communication
• Future Technology Trends
• Building Future-Ready Organizations

5-Day Training Schedule
Day Time Session Methodology
Day 1 08:30 – 10:30 Unit 1: Foundations of IT Governance Interactive Lecture
10:45 – 12:30 Unit 2: Aligning IT Strategy with Business Strategy Executive Workshop
13:30 – 15:00 IT Governance Maturity Assessment Group Work
15:15 – 17:00 Case Study: Target, Equifax and British Airways Cyber Governance Failures Case Study Analysis
Day 2 08:30 – 10:30 Unit 3: Enterprise IT Risk Management Practical Workshop
10:45 – 12:30 Enterprise Technology Risk Mapping Exercise Group Work
13:30 – 15:00 Unit 4: Cybersecurity Governance and Oversight Expert Session
15:15 – 17:00 Cybersecurity Incident Response Simulation Simulation
Day 3 08:30 – 10:30 Unit 5: Information Security and Data Governance Interactive Workshop
10:45 – 12:30 Data Governance Framework Design Group Exercise
13:30 – 15:00 Unit 6: Technology Compliance and Regulatory Requirements Executive Session
15:15 – 17:00 GDPR and Compliance Gap Assessment Practical Exercise
Day 4 08:30 – 10:30 Unit 7: Digital Operational Resilience and Business Continuity Practical Workshop
10:45 – 12:30 Business Continuity and Disaster Recovery Exercise Simulation
13:30 – 15:00 Unit 8: IT Audit, Assurance and Internal Controls Interactive Lecture
15:15 – 17:00 IT Audit Committee Simulation Simulation
Day 5 08:30 – 10:30 Unit 9: Emerging Technologies, AI and Innovation Governance Expert Discussion
10:45 – 12:30 Unit 10: Board Leadership in IT Governance and Digital Transformation Strategic Leadership Session
13:30 – 15:30 Capstone Project: Enterprise IT Governance, Risk and Compliance Framework Team Exercise
15:30 – 16:30 Team Presentations and Board Governance Review Panel Presentation
16:30 – 17:00 Programme Evaluation and Certification Closing Session
Group Work Activities
Activity Objective
IT Governance Maturity Assessment Evaluate governance effectiveness
Technology Risk Mapping Identify and prioritize IT risks
Data Governance Framework Design Strengthen data oversight
Compliance Gap Assessment Evaluate regulatory readiness
Operational Resilience Planning Improve continuity capabilities
IT Governance Dashboard Development Enhance board oversight
International Case Studies
Case Study Learning Focus
Equifax Data Breach (USA) Cybersecurity governance failures
Target Cyber Incident (USA) Third-party risk management
British Airways GDPR Penalty (UK) Data privacy and compliance
SolarWinds Cyberattack (USA) Supply chain cyber risk
Colonial Pipeline Incident (USA) Operational resilience
Maersk NotPetya Attack (Denmark) Business continuity and recovery
Capital One Cloud Security Event (USA) Cloud governance and risk
Uber Data Governance Challenges (USA) Governance and compliance lessons
Simulation Exercises
Simulation Competencies Developed
Cybersecurity Incident Response Crisis decision-making
Board Cyber Risk Committee Meeting Governance oversight
IT Audit Committee Exercise Assurance and controls
Regulatory Compliance Review Compliance governance
Operational Resilience Testing Business continuity management
Technology Investment Review Strategic decision-making
Capstone Project
Enterprise IT Governance, Risk and Compliance Transformation Project
Participants assume the role of Board Members and Executive Leaders overseeing a multinational organization facing:
• Increasing cyber threats
• Regulatory compliance pressures
• Legacy technology infrastructure
• Data privacy concerns
• Third-party technology risks
• Digital transformation challenges
Capstone Deliverables
Teams will:
1. Conduct an IT governance maturity assessment.
2. Develop an enterprise IT governance framework.
3. Design a technology risk management strategy.
4. Establish cybersecurity governance structures.
5. Create a compliance and regulatory roadmap.
6. Develop resilience and business continuity plans.
7. Design board technology dashboards and reporting frameworks.
8. Present recommendations to a Board Technology and Risk Oversight Panel.

Assessment Framework
Assessment Component Weighting
Pre-Programme Assessment 10%
Participation and Engagement 10%
IT Governance Assessment Assignment 15%
Technology Risk Analysis Exercise 15%
Compliance and Audit Review Assignment 15%
Simulation Performance 15%
Capstone Project and Presentation 20%
Types of Assessments to Expect
Individual Assessments
• IT Governance Knowledge Assessment
• Technology Risk Evaluation
• Cybersecurity Governance Review
• Compliance Analysis Assignment
• IT Audit Assessment

Group Assessments
• IT Governance Framework Development
• Technology Risk Mapping
• Data Governance Framework Design
• Operational Resilience Planning
• Capstone Project Presentation
Practical Assessments
• Cyber Incident Response Simulation
• IT Audit Committee Exercise
• Compliance Review Workshop
• Business Continuity Testing Exercise
• Board Technology Oversight Simulation
• Digital Resilience Assessment
Certification Requirements
Requirement Standard
Attendance Minimum 80%
Participation in Simulations Mandatory
Completion of Group Exercises Mandatory
Capstone Project Submission Mandatory
Minimum Pass Mark 60%

Certification Award
Executive Certificate in IT Governance, Risk and Compliance (IT GRC)
CPD Credits: 40 Hours
International Alignment: ISO 38500, COBIT 2019, ISO 27001, ISO 31000, NIST Cybersecurity Framework, COSO ERM, GDPR, DORA, SOX, Basel Committee Operational Risk Principles, ISACA Governance Standards, OECD Corporate Governance Principles, and European Digital Governance Best Practices.

Show More

Course Content

Unit 1: Foundations of IT Governance

  • Lesson 1 : Evolution of IT Governance