A tailored course, built for your situation
Sources and specific examples on hand when peers push back
Build unshakable reasoning for governance choices that hold up in real conversations
Who this is for
Senior governance practitioner in asset management or wealth services, regularly involved in control design, audit response, and cross-functional justification cycles
Who this is not for
Entry-level compliance staff, consultants without domain exposure, or teams seeking off-the-shelf policy templates
What you walk away with
- Articulate the rationale behind control selections using cited sources such as COSO, NIST, and FFIEC
- Deploy specific examples from peer institutions when defending design choices
- Map controls directly to regulatory expectations, not just internal checklists
- Anticipate challenges to exemption requests and prepare counterpoints in advance
- Turn pushback into a demonstration of depth, not a negotiation setback
The 12 modules (with all 144 chapters)
- Difference between approval and defensibility
- When pushback signals respect, not resistance
- Three components of a defendable choice
- How regulators assess reasoning, not just outcomes
- Example: Justifying a manual control override
- Using audit trails as reasoning anchors
- Why 'because policy' fails under pressure
- From checklist follower to decision explainer
- Case: Client data access exception at peer firm
- Linking control gaps to actual risk exposure
- Building reasoning muscle across cycles
- Defensibility as repeatable asset
- COSO the current cycle as baseline for reasoning
- FFIEC handbooks for operational controls
- SEC enforcement actions as negative examples
- NIST CSF for cyber-adjacent decisions
- Using IA guidance from IIA
- When to pull from internal audit reports
- Benchmarking against G-SIB practices
- Avoiding vague 'industry standard' claims
- How to excerpt frameworks properly
- Building a source library by control type
- Attribution without over-reliance
- Tailoring sources to audience level
- Documenting the 'why' behind decisions
- Creating decision memos that last
- Storing precedents in accessible formats
- Linking past exceptions to current asks
- Example: Wire approval thresholds right now
- How to reference past peer reviews
- Avoiding tribal knowledge traps
- Versioning control justifications
- Using precedents in real-time meetings
- When not to reuse old logic
- Updating reasoning libraries quarterly
- Precedent index by risk category
- Top five objections to manual controls
- How auditors challenge automation claims
- Pushback on risk appetite interpretations
- When 'materiality' becomes debated
- Responding to 'but other teams don't'
- Handling requests to bypass controls
- Dealing with urgency-based overrides
- Managing senior-level exceptions
- Addressing 'this didn’t happen before'
- Counterpoints for resource constraints
- Framing risk in business terms
- When to escalate versus justify
- Start with scope, not solution
- Naming the risk being mitigated
- Linking control to specific threat
- Explaining design alternatives considered
- Why we didn’t choose the simpler path
- Using diagrams to show logic flow
- Tying control to fiduciary duty
- Adjusting detail for audience
- Walking through a sample escalation
- Avoiding jargon, keeping clarity
- Pacing the explanation
- Closing with confidence, not compromise
- Case: Client onboarding delay resolution
- How one firm justified dual controls
- Handling documentation gaps in audit
- Responding to regulator questions on access
- Example: Exception for family office client
- Justifying control changes mid-cycle
- Using past breaches as rationale
- Benchmarking control timing against peers
- Explaining deviations in reporting
- Handling internal audit findings
- Managing scope creep in engagements
- When precedent stopped escalation
- Start with risk, end with control
- Three-part justification structure
- Using 'because' with specificity
- Linking to regulatory references
- Including data points where possible
- Avoiding circular logic
- Naming assumptions explicitly
- Stating limitations with confidence
- How to handle incomplete information
- Using proportionality arguments
- Framing trade-offs honestly
- Closing with decision clarity
- Justifying a manual approval step
- Explaining deviation from standard process
- Defending temporary access grant
- Responding to audit finding on logs
- Handling late documentation
- Rationale for control frequency
- Why quarterly works over monthly
- Choosing sample size for testing
- Explaining lack of automation
- When to accept residual risk
- Handling vendor-related gaps
- Using operational reality as factor
- Finding firm risk appetite statements
- Using internal policies as anchors
- Balancing conservatism with efficiency
- When to lean into precedent
- How culture shapes acceptable risk
- Reading between policy lines
- Tailoring depth to audience
- Explaining decisions to leadership
- When to involve legal
- Navigating unwritten rules
- Respecting chain of command
- Using tone in communications
- Predicting line-item challenges
- Preparing for follow-up requests
- How to respond to 'explain this'
- Using data to back assertions
- When to say 'we monitor it'
- Handling requests for evidence
- Avoiding overcommitment
- Staying within remit
- When to pause and consult
- Managing tone under pressure
- Using silence as tool
- Closing with clarity
- Template for decision memos
- Building a precedent library
- Standard responses for common asks
- Creating leader-facing summaries
- Using visuals in documentation
- Versioning control explanations
- Tagging by risk domain
- Indexing for searchability
- Integrating with audit tools
- Sharing selectively across teams
- Updating for new regulations
- Making artefacts actionable
- Scenario: New client with complex structure
- Responding to internal audit finding
- Justifying control in M&A integration
- Handling urgent access request
- Explaining deviation in process
- Responding to regulator inquiry
- Managing cross-border risk
- When policy doesn’t cover case
- Balancing client service and control
- Using reasoning in escalation
- Documenting real-time decisions
- Closing with artefact creation
How this maps to your situation
- Responding to audit findings
- Justifying control design choices
- Handling peer challenges to exemptions
- Preparing for regulatory review
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 2.5 hours per module, designed to be completed incrementally across 3-4 weeks.
How this compares to the alternatives
Unlike generic GRC courses that focus on framework familiarity, this course delivers a structured method for defending decisions, grounded in actual asset management governance challenges and calibrated to firms like the firm.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.