Corruption Risk Management (CRM) Workshop
Corruption risk assessment goes wrong in a predictable way: the register lists risks like "bribery in procurement", scores them all as medium, attaches a policy as the control, and gets refreshed once a year by copying the previous version. This workshop takes the opposite approach. It works at process level, where the discretion and the opportunity actually sit, and it treats the control question seriously enough to ask whether the control would survive someone genuinely trying to get around it.
Programme Agenda
Why Corruption Risk Is Assessed Differently
What separates it from operational or financial risk: deliberate concealment, collusion, and the fact that the person best placed to exploit a weakness is often the one asked to describe the control.
Working at Process Level
Decomposing procurement, licensing, claims, enforcement, recruitment and disposal into steps. Finding where discretion exists, who exercises it, and what it is worth to someone outside.
Describing a Risk So It Can Be Managed
Actor, action, opportunity and benefit. Turning "corruption in tendering" into a specific scenario with a named role and a mechanism, which is the only version a control can be designed against.
Scoring Consistently
Likelihood and impact scales that two assessors apply the same way, including reputational and regulatory impact. Avoiding the compression that puts every risk in the middle.
Assessing Existing Controls Honestly
Design effectiveness versus operating effectiveness, controls that exist on paper only, and the segregation that collapses whenever someone is on leave. Testing rather than asking.
Designing Controls That Hold
Preventive, detective and corrective options; automation where discretion can be removed; and rotation, dual control and independent review where it cannot. Proportionality to the risk rather than to the budget.
Residual Risk and Acceptance
What remains after treatment, who is authorised to accept it, and recording that decision so it is a governance act rather than an omission.
Register Build and Challenge
Participants build a register for their own processes across the two days, then defend the scoring and control ratings against structured challenge.
Learning Outcomes:
Explain why corruption risk needs a different assessment approach
Decompose a business process to locate discretion and opportunity
Describe a corruption risk specifically enough to design a control against it
Apply likelihood and impact scales consistently across assessors
Test existing controls for operating effectiveness rather than accept assertions
Design proportionate preventive, detective and corrective controls
Record residual risk acceptance as a documented governance decision
Produce a corruption risk register for your own processes
Duration: 2 Days (16 Hours)
Training Hours: 9:00 AM to 5:00 PM
Level: All levels
Training Mode: Physical, Online, or Hybrid
HRD Corp SBL-KHAS Claimable
Certificate of Completion included
Frequently Asked Questions
More in Integrity and Governance
- Fraud Risk and Internal Control · All levels, 2 days
- Procurement Integrity and Conflict of Interest · All levels, 1 day
- Directorship Essentials for New Board Members · Beginner, 2 days
- Corporate Governance and Integrity · All levels, 1 day
- Leadership for Ethical Organisations · Leadership, 1 day
- Anti-Sexual Harassment Policy and Training · Beginner to Intermediate, 1 day
- Workplace Anti-Bullying Policy and Training · Beginner to Intermediate, 1 day
- Business Continuity Basics for Non-Technical Managers · Beginner to Intermediate, 1 day