Skip to main content
Image coming soon

Risk Advisory Partner Delivery Playbook

$199.00
Adding to cart… The item has been added

A focused course, tailored for you

Risk Advisory Partner Delivery Playbook

Build the engagement artefacts risk partners actually hand to audit committees, not the ones that get re-asked at the next session.

Risk partners spend weeks on a heat map that generates one question from the board: what are you doing about it? The answer requires three artefacts the heat map does not contain. This course builds them.

$199 one-time
Tailored to your situation. Access within 24 hours. 30-day money-back.

Includes a hand-built implementation playbook delivered alongside course access, generated for your specific situation.

Why this course

The risk heat map has become the default board deliverable for risk advisory engagements. It rates likelihood and impact, it colour-codes the top risks, and it tells the committee what the partner already knows. What it does not contain is a control-gap brief, a residual-risk ownership memo, or a regulatory-update summary timed to land before the next examination cycle. The result is that the same risks appear on the same heat map at the same board meeting every quarter, rated identically, with the same three action items that have been in progress since last year. Audit committee chairs have started asking, directly, whether the risk advisory work is producing anything that changes the answer. Partners who can answer that question with three specific documents hold the engagement and expand the mandate. Partners who cannot are cycling through renewals with declining scope.

What you walk away with

  • Build a control-gap brief that names specific gaps, specific owners, and specific remediation timelines rather than repeating the heat-map rating.
  • Write a residual-risk memo structured for audit committee action rather than for internal risk-team review.
  • Produce a regulatory-update summary timed to arrive before the examination cycle opens, not after the regulator has already signalled concerns.
  • Structure an engagement delivery cadence that reduces the number of re-asked questions at successive board sessions.
  • Map the three core artefacts to the client's own risk appetite statement so the committee sees the connection without being walked through it.
  • Handle the conversation when the committee asks whether the prior year's risk programme actually reduced residual risk.

The 12 modules

Module 1. Why the Heat Map Keeps Generating the Same Question
Audit committees ask follow-up questions when the artefact answers the rating but not the action. This module diagnoses the structural gap between a heat-map output and a board-actionable deliverable. You will map the specific moment in a typical engagement where the question recurs and identify the three artefact types that close it. The module includes a worked example drawn from a financial services engagement where the same top risk appeared for three consecutive quarters.
Module 2. The Control-Gap Brief: Structure and Ownership
A control-gap brief is not a list of findings. It is a structured document that names each gap, the control that is absent or deficient, the owner accountable for remediation, and the date by which the committee should expect an update. This module walks through the four-section structure, the language conventions that make ownership unambiguous, and the common drafting errors that let ownership slip back to the risk team rather than land with the client. Templates included.
Module 3. Calibrating Gap Severity Without the Heat-Map Scale
The heat-map likelihood-impact scale is useful for prioritisation. It is not useful for describing why a specific control gap matters to this client at this moment. This module builds an alternative severity framing keyed to the client's regulatory exposure, their existing control inventory, and the current examination focus of their primary regulator. You will draft a severity rationale paragraph for a real gap from your current engagement portfolio using the module's worked template.
Module 4. The Residual-Risk Memo: What Stays After Controls
Residual risk is the risk that remains after the named controls operate as designed. Most engagement memos describe inherent risk and then list controls. Few describe what the residual risk actually is, who owns it, and what the client's board has accepted. This module structures the residual-risk memo as a three-part document: the residual position, the acceptance decision, and the monitoring trigger that should prompt the committee to revisit the acceptance. Annotated example included.
Module 5. Naming Risk Owners at the Right Level
Risk ownership lands at the wrong level when the memo names a function rather than a role and a person. Audit committees cannot act on 'the treasury function owns this'. This module works through the ownership-naming convention that survives committee scrutiny: role title, name, the specific decision authority they hold, and the escalation path if the remediation timeline slips. You will rework three ownership statements from a prior engagement using the module's convention and compare the committee response.
Module 6. Regulatory-Update Summary: Timing and Scope
A regulatory-update summary that arrives after the examiner has already signalled concerns is retrospective, not advisory. This module builds the calendar logic for a proactive regulatory-update summary: which regulatory calendars to track, how to map upcoming examination cycles to the client's risk register, and how to write the summary so the committee reads it as intelligence rather than compliance reporting. Covers the primary financial services regulatory bodies and their publication cadences.
Module 7. Linking the Three Artefacts to the Risk Appetite Statement
Risk appetite statements exist in most large organisations. Few engagement deliverables reference them explicitly. When the control-gap brief, the residual-risk memo, and the regulatory-update summary each cite the relevant appetite threshold, the committee does not need to be walked through the connection. This module maps the three artefacts to a standard risk appetite structure and shows how to insert the appetite citation without making the document read as a compliance checklist.
Module 8. Structuring the Engagement Delivery Cadence
Re-asked questions at successive board sessions are a cadence problem as much as an artefact problem. If the control-gap brief arrives at the same session as the heat map, the committee cannot act before the next session requests an update. This module designs the delivery cadence: which artefact arrives at which session, what the handoff document says between sessions, and how to set the committee's expectation for the update cycle. Includes a calendar template for a quarterly board cycle.
Module 9. The Re-asked Question: Diagnosing and Closing It
When the audit committee asks the same question at the third consecutive session, the engagement has a structural problem the partner needs to name directly. This module works through the conversation: how to acknowledge the recurrence without undermining the prior work, how to identify whether the gap is in the artefact, the ownership, or the client's remediation capacity, and how to propose a modified delivery that resolves the loop. Includes a script for the partner-to-committee conversation.
Module 10. Handling the 'Is the Risk Programme Working?' Question
Audit committee chairs increasingly ask whether the prior year's risk programme actually reduced residual risk. Answering this question requires a before-and-after residual-risk comparison that most engagement files do not contain. This module builds the comparison document: how to reconstruct the prior-year residual position from the engagement file, how to measure the movement, and how to present the answer in a way that is honest about partial progress without undermining the programme's credibility.
Module 11. Expanding the Mandate: From Heat Map to Programme Advisory
Partners who can answer the committee's follow-up questions with specific artefacts create the conditions for a broader mandate. This module maps the conversation that moves the engagement from periodic heat-map delivery to ongoing risk programme advisory: the moment to raise it, the framing that distinguishes programme advisory from additional compliance work, and the scope document that makes the expanded mandate legible to the client's procurement function. Worked scope outline included.
Module 12. Building the Implementation Playbook for Your Current Engagement
The final module consolidates the three artefacts, the delivery cadence, and the mandate conversation into a single implementation playbook scoped to your current engagement portfolio. You will select one active engagement, apply the module frameworks to the specific client context, and produce a working draft of the control-gap brief, the residual-risk memo framing, and the regulatory-update summary calendar. The hand-built playbook delivered alongside course access extends this work with your specific regulatory environment and client mix.

How this addresses your situation

Specific modules that map to what you said you are dealing with.

Modules 1-3 address the structural gap between heat-map delivery and board-actionable output.
Modules 4-6 build the three core artefacts: control-gap brief, residual-risk memo, regulatory-update summary.
Modules 7-9 integrate the artefacts into the engagement cadence and handle the re-asked question.
Modules 10-12 handle the programme-level conversation and produce the implementation playbook.

What you get with this course

  • 12 written modules covering the full artefact architecture for risk advisory partner delivery
  • Downloadable templates for the control-gap brief, residual-risk memo, and regulatory-update summary
  • Worked examples drawn from financial services engagement contexts
  • Delivery cadence calendar template for a quarterly board cycle
  • Mandate expansion scope outline
  • Hand-built implementation playbook scoped to your engagement portfolio, delivered alongside course access

What you will have in hand by Day 1, Week 1, Month 1

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

Before and after

Before

The heat map goes to the board. The committee thanks the team and asks what they are doing about it. The same three action items appear at the next session. The engagement renews with the same scope.

After

The committee receives a control-gap brief before the next session. Ownership is named. The regulatory-update summary arrives before the examination cycle. The committee stops asking the same question and starts asking about expanding the programme.

What happens if you do not address this

Risk advisory partners who cannot answer the committee's follow-up questions with specific artefacts cycle through renewals with declining scope. The partners who hold mandates across multiple board cycles are the ones whose deliverables close the loop the first time.

Who it is for

Risk advisory partners and senior managers at professional services firms who lead risk engagements for financial services, infrastructure, or regulated-industry clients. They hold the client relationship, present to audit committees, and are accountable for the quality of the engagement deliverables. They know risk methodology well. What they need is the artefact architecture that turns methodology into board-level output the client acts on.

Who this is NOT for. Risk analysts building internal risk frameworks for a single organisation. Compliance officers managing a regulatory programme in-house. Partners whose primary deliverable is assurance opinions rather than risk advisory. Anyone whose board relationship is primarily through written reports rather than direct committee presentations.

How it arrives

Text-based course in the Art of Service learning environment, plus downloadable templates and worked examples for every module, plus the hand-built implementation playbook delivered alongside course access.

Time investment. Each module is designed to be completed in a single working session. The full course is workable across two weeks at one module per day, or in a concentrated three-day block.

Why $199 is the right number

Risk methodology training covers frameworks and rating scales. It does not build the specific artefacts that answer audit committee follow-up questions. This course is not methodology training. It is artefact architecture for partners who already know the methodology and need the delivery layer that makes it stick at board level.

FAQ

Is this relevant if my clients are not in financial services?
The three artefacts work across any regulated-industry engagement. The regulatory-update summary module covers financial services regulators in depth, but the artefact structure and the committee conversation apply equally to infrastructure, healthcare, and energy clients.
My firm has its own risk advisory methodology. Does this conflict with it?
The course builds the delivery layer, not the methodology. It works alongside any existing risk framework. The artefacts are designed to sit on top of whatever rating system your firm uses.
How is the implementation playbook tailored to my engagement?
After purchase, you receive a brief questionnaire covering your current engagement context: client sector, primary regulator, board meeting cadence, and current artefact set. The playbook is built from those inputs and delivered within 24 hours alongside course access.

30-day money-back guarantee. If after a week of working through the materials this is not what you needed, reply to the receipt email and a full refund is processed. No questions, no forms.

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.