.crc-hook{background:#f8fafc;border:1.5px solid #d0dce8;border-radius:16px;padding:36px 40px;margin-bottom:32px}.crc-hook p{font-size:1rem;color:#2d3a4a;line-height:1.85;margin:0 0 20px}.crc-stats{display:flex;flex-wrap:wrap;gap:14px;margin-top:24px}.crc-stat{background:#fff;border:1.5px solid #d0dce8;border-radius:12px;padding:16px 20px;flex:1;min-width:150px;text-align:center}.crc-stat strong{display:block;font-size:1.4rem;font-weight:800;color:#a14d47;line-height:1.2}.crc-stat span{font-size:.75rem;color:#5a6a7e;line-height:1.5;display:block;margin-top:5px}.crc-source{font-size:.72rem!important;color:#6b7788!important;margin:16px 0 0!important}.crc-pain{background:#fcf4f3;border-left:5px solid #a14d47;border-radius:0 14px 14px 0;padding:30px 34px;margin-bottom:44px}.crc-pain ul{margin:12px 0 0;padding-left:20px;line-height:2.05;color:#532522}.crc-h{font-size:1.45rem;font-weight:800;color:#532522;border-bottom:3px solid #a14d47;padding-bottom:10px;margin:44px 0 24px}.crc-cards,.crc-regions{display:grid;grid-template-columns:repeat(auto-fit,minmax(230px,1fr));gap:18px;margin-bottom:44px}.crc-card,.crc-region{border:1.5px solid #e3c0bd;border-radius:14px;padding:22px 20px;background:#fff}.crc-card h4,.crc-region h4{margin:8px 0;color:#532522;font-size:.95rem;font-weight:700}.crc-card p,.crc-region p{margin:0;font-size:.84rem;color:#3a5578;line-height:1.65}.crc-gains{background:#fcf4f3;border-radius:16px;padding:36px;margin-bottom:44px}.crc-gg{display:grid;grid-template-columns:repeat(auto-fit,minmax(240px,1fr));gap:14px}.crc-g{background:#fff;border-radius:10px;padding:16px 20px;display:flex;gap:12px;align-items:flex-start;font-size:.88rem;line-height:1.65;color:#2d3a4a}.crc-g i{color:#a14d47;font-size:1.25rem;flex-shrink:0;font-style:normal}.crc-m{border:1.5px solid #e3c0bd;border-radius:14px;overflow:hidden;margin-bottom:16px}.crc-mh{background:#532522;color:#fff;padding:16px 24px;display:flex;align-items:center;gap:16px}.crc-mn{background:#a14d47;width:38px;height:38px;border-radius:50%;display:flex;align-items:center;justify-content:center;font-weight:800;flex-shrink:0}.crc-mb{padding:22px 26px}.crc-mb p{margin:0 0 14px;color:#444f5e;line-height:1.8;font-size:.93rem}.crc-mb ul{margin:0;padding-left:20px;color:#444f5e;line-height:1.95;font-size:.9rem}.crc-work{margin:14px 0 0!important;padding:12px 16px;background:#fcf4f3;border-radius:8px;color:#532522!important;font-weight:600}.crc-faq{border-bottom:1px solid #e3c0bd;padding:18px 0}.crc-faq b{display:block;color:#532522;margin-bottom:8px;font-size:.95rem}.crc-faq span{color:#3a5578;font-size:.88rem;line-height:1.75}.crc-rel{display:grid;grid-template-columns:repeat(auto-fit,minmax(220px,1fr));gap:14px;margin-bottom:44px}.crc-rel a{border:1.5px solid #e3c0bd;border-radius:10px;padding:16px 18px;text-decoration:none;color:#532522;font-weight:600;font-size:.88rem}.crc-cta{background:linear-gradient(135deg,#a14d47,#532522);border-radius:16px;padding:44px;text-align:center;color:#fff;margin-top:44px}.crc-cta h3{font-size:1.5rem;font-weight:800;margin:0 0 12px;color:#fff}.crc-cta p{opacity:.9;margin:0 0 28px;font-size:.97rem;line-height:1.7;color:#fff}.crc-tbl{width:100%;border-collapse:collapse;font-size:.9rem}.crc-tbl td{padding:14px 24px;border-bottom:1px solid #e3c0bd}
A Compliance Programme Is Not Effective Because the Policy Exists. It Is Effective When the Controls Work Against the Risks They Were Designed For.
Many compliance functions can list policies, training completions and hotline statistics.
The harder question is whether the programme is actually controlling the organisation's most important compliance risks.
ISO 37301 provides a management-system framework for establishing, implementing, evaluating, maintaining and improving compliance. The ISO governance catalogue now also includes ISO 37302:2025, dedicated specifically to evaluating compliance-management effectiveness. DOJ guidance similarly looks beyond the existence of a programme to whether it is well designed, resourced, tested, monitored and effective in practice.
That changes the job of compliance.
A risk assessment should drive the control environment. Controls should map to specific obligations and risk scenarios. Testing should generate evidence about whether controls are designed appropriately and operating as intended. Findings should be prioritised, remediated and retested. Monitoring should evolve as regulation, business models, third parties, products and geography change.
This course teaches that full risk-to-control-to-evidence cycle.
ISO 37301 confirmed current*
ISO 37301:2021 remains the international compliance-management-system standard and was confirmed current in 2026.
Source: ISO.*Effectiveness has its own standard ISO 37302:2025 provides guidance specifically on evaluating the effectiveness of a compliance management system.
Work in practice*
DOJ evaluation principles ask not only whether a programme is well designed, but whether it is properly implemented and actually works in practice.
Source: U.S. DOJ.*
ISO 37301 · ISO 37302:2025 · U.S. DOJ Compliance Evaluation. Evidence is contextual and does not guarantee participant or organisational outcomes.
Compliance programmes become fragile when:
- obligation registers exist but are not connected to actual risk scenarios
- risk assessments use generic high/medium/low labels without a repeatable methodology
- compliance controls are copied from policy documents rather than designed around root causes
- teams confuse a control's existence with evidence that it works
- testing samples are chosen without a rationale
- first-line monitoring, compliance testing and internal audit duplicate one another
- findings are documented but not prioritised by residual risk
- remediation closes when an action is completed rather than when effectiveness is demonstrated
- business changes, acquisitions, products or third parties are not reflected promptly in the risk assessment
- dashboards count training and policy attestations but cannot show control effectiveness
- compliance cannot explain how its testing plan reflects the organisation's highest risks.
How This Applies Across the Markets MATSH Serves
GCC
Applications include regulated financial and non-financial sectors, government-linked organisations, multinational operations, anti-bribery and third-party exposure, rapidly evolving regulatory environments and increasing expectations around governance and evidence.
Africa
Participants consider multi-country regulatory obligations, varying control maturity, third-party and intermediary risks, distributed operations and how to build proportionate testing where compliance teams may be small.
Asia
Applications include complex regulatory footprints, high transaction volumes, third-party ecosystems and rapidly changing products or technology that require risk-based monitoring rather than static checklists.
Europe
Participants examine mature compliance environments, data/privacy, competition, financial crime, ESG and other regulated domains where documentation, defensibility and evidence of control effectiveness matter significantly. These are contextual lenses. Specific legal obligations must always be identified and interpreted for the relevant jurisdiction and business.
Who Should Attend
🧭
Compliance Officers and Compliance Managers
Designing risk assessments, monitoring plans or compliance-control testing.
👔
Risk and Governance Professionals
Working at the interface between enterprise risk, compliance obligations and controls.
🏛️
Internal Control Professionals
Responsible for control documentation, testing, remediation and management assurance.
🔄
Legal and Regulatory Affairs Teams
Needing a structured method for translating obligations into operational controls.
🛡️
Internal Auditors Moving Into Compliance Assurance
Wanting to distinguish second-line compliance testing from independent third-line audit.
📊
Business Control Owners
Responsible for demonstrating that compliance controls embedded in operations actually work.
What You Will Leave With
A complete compliance risk and testing framework.
✓A compliance-obligation inventory, linking laws, regulations, licences, policies and commitments to business processes.
✓A risk-assessment methodology, defining likelihood, impact and inherent-risk criteria.
✓Risk scenarios, converting broad obligations into specific failure modes.
✓A control map, linking preventive and detective controls to each material risk.
✓Residual-risk logic, showing how control strength changes the risk view.
✓A risk-based testing plan, allocating testing effort according to materiality and change.
✓Control test scripts, covering design and operating effectiveness.
✓An evidence standard, defining what is sufficient to support a conclusion.
✓A findings and remediation framework, prioritising deficiencies and requiring retest before closure.
✓A compliance-effectiveness dashboard, reporting what leadership needs to know about risk and control performance.
Programme Curriculum
1
Compliance Obligations, Risk Universe and Assessment DesignWhy this module matters: Compliance testing cannot be risk-based if the organisation has not defined what obligations apply, where they touch the business and what failure could look like. Participants learn to:
- build a compliance-obligation inventory
- map obligations to entities, products, geographies and processes
- distinguish legal obligations, regulatory expectations, licence conditions, contractual commitments and internal policy
- translate obligations into specific risk scenarios
- define inherent-risk criteria
- evaluate likelihood and impact consistently
- include financial, legal, operational, customer and reputational consequences appropriately
- assess risk velocity and change where useful
- document assumptions and evidence behind ratings
- identify triggers for reassessment.
Workshop: Build a compliance-risk register from a sample obligation set.
2
Control Design, Mapping and Residual RiskWhy this module matters: A policy statement is not a control. Effective compliance systems identify who performs the control, when, on what population, using which evidence and how exceptions are handled. Participants learn to:
- distinguish policies, procedures and controls
- identify preventive, detective and corrective controls
- map controls to specific risk causes and consequences
- define control owner, frequency, population and evidence
- assess whether a control is designed to address the stated risk
- identify gaps, duplication and over-control
- distinguish key controls from supporting controls
- consider manual, automated and IT-dependent controls
- assess residual risk after control design
- document accepted residual risk and escalation.
Workshop: Build a risk-control matrix and challenge the design of each key control.
3
Compliance Monitoring and Control Testing MethodologyWhy this module matters: Testing needs a repeatable method. Without clear objectives, population, samples, evidence and pass/fail criteria, conclusions become subjective and difficult to defend. Participants learn to:
- distinguish business monitoring, compliance monitoring/testing and internal audit
- define the testing objective and control assertion
- assess design effectiveness before operating effectiveness
- identify test population and period
- choose samples proportionately to risk and frequency
- define inspection, observation, reperformance and inquiry procedures
- establish evidence sufficiency and quality
- record exceptions consistently
- avoid treating one successful sample as proof of effectiveness
- conclude on effectiveness using defined criteria.
Simulation: Execute and document a control test from planning through conclusion.
4
Findings, Root Cause, Remediation and RetestingWhy this module matters: Compliance findings create value only when the underlying weakness is corrected. Closing an action because a document was updated does not prove the risk is controlled. Participants learn to:
- classify findings by risk and control significance
- distinguish isolated exceptions from systemic failures
- investigate root causes
- write findings that connect condition, criteria, cause and risk
- agree remediation with accountable owners
- set realistic milestones and interim controls
- track overdue remediation
- determine when risk acceptance is appropriate
- retest controls after remediation
- close findings only when evidence supports sustainable effectiveness.
Workshop: Rewrite weak compliance findings and build a remediation/retest plan.
5
Continuous Monitoring, Programme Effectiveness and ReportingWhy this module matters: A compliance-testing plan should evolve with the organisation. Static annual checklists become obsolete when products, third parties, technology, regulation or geographic exposure changes. Participants learn to:
- create a risk-based annual monitoring and testing universe
- allocate testing frequency based on risk and change
- use data analytics and exception monitoring where appropriate
- incorporate incidents, investigations and hotline trends into risk reassessment
- evaluate whether training and communications are addressing actual risk
- monitor third-party and transaction risks proportionately
- define programme-effectiveness indicators
- distinguish activity measures from evidence of effectiveness
- report control themes and residual risk to management and boards
- feed findings into continuous improvement of the compliance management system.
Capstone: Present a compliance risk assessment, control map and annual testing plan for a realistic organisation.
Course At a Glance
| Format | Comprehensive modular curriculum, delivered flexibly to match programme length |
| Locations | Multiple locations, online available |
| Methodology | Risk-register design, risk-control mapping, live testing simulations, findings workshops and a capstone annual compliance-testing plan |
| Best for | Compliance teams, risk professionals, control functions, legal/regulatory staff, internal auditors and business control owners |
| What's Included | Obligation register, compliance risk matrix, risk-control template, testing script, evidence checklist, findings log, remediation tracker and certificate |
Common Questions
How is this different from Risk Management Fundamentals?Risk Management Fundamentals covers the enterprise risk process across strategic, operational, financial and other risk categories. This course is specifically about compliance obligations and the controls/testing used to demonstrate that compliance risks are being managed.
How is this different from Internal Audit Fundamentals?Internal Audit provides independent third-line assurance over a broad range of organisational risks and controls. Compliance monitoring and testing is typically a second-line activity focused on compliance risks and programme effectiveness.
Does the course teach ISO 37301 certification?No. ISO 37301 informs the compliance-management context, but this is not an auditor/certification course. It focuses on the practical risk and testing work compliance teams need to perform.
Is this legal training?No. Participants must still obtain appropriate legal interpretation of applicable obligations. The course teaches how to convert identified obligations into a risk, control, monitoring and evidence framework.
Can an in-house cohort use our existing compliance risk assessment?Yes. That is often the strongest format. The cohort can challenge the current methodology, map controls and redesign the testing plan around the organisation's real risk universe.
Compliance Confidence Should Come From Evidence, Not From the Absence of a Recent Incident.
Build the risk assessment and testing discipline to show whether your compliance controls are actually working.