The CFO's Playbook:
Enterprise Risk Management Curriculum

From Compliance Checklists to Strategic Boardroom Leadership

Welcome to the practitioner's guide to Enterprise Risk Management (ERM). Designed exclusively for aspiring Financial Controllers and future CFOs, this self-paced curriculum replaces dry theory with mathematical decision logic and continuous, real-world executive storylines.

Begin with our expanded 19-Session Core Pilot to build your universal governance foundation, heavily focused on the APRA, RBNZ, and SEBI regulatory baselines. Then, customize your expertise by selecting from 8 Specialized Framework Tracks tailored to your industry's specific demands.

100% Self-Paced On-Demand Access

Study anytime, anywhere. Immediate access upon subscription with full downloadable playbooks and interactive templates.

✔ Executive Boardroom Simulations
✔ Build your own Risk Registers
✔ Certificate of Completion Issued
Need assistance? Contact Support:
support@tillskill.com

Self-Study Subscription Options

Choose your path. Start with the core foundation, or unlock a specialized combo pass for maximum value and networking.

Core ERM Pilot

AUD 199 / 19 Sessions

The practitioner's foundation covering APRA, ISO 31000 & COSO.

  • ✔ 19 Interactive Study Sessions
  • ✔ Risk Register & Matrix Templates
  • ✔ Core Capstone Project Included
  • ✔ Certificate of Completion
View & Subscribe
Best Value for Aspiring CFOs

The Combo Pass

AUD 299 / 27 Sessions

Save AUD 49 instantly

  • Includes the 19-Session Core Pilot
  • Plus 1 Specialized Framework Track
  • ✔ Advanced Framework Capstone
  • ✔ Exclusive access to Alumni Network Group
Select Track & Get Combo

Single Track Upgrade

AUD 149 / Per Track

For students who have already completed the Core program.

  • ✔ 8 Advanced Framework Sessions
  • ✔ 1 Final Track Capstone Project
  • ✔ Certification Pathway Guidance
Select Track Below

Part 1: The Core ERM Pilot

The Core Storyline: "The Zephyr Expansion"

Throughout these 19 foundational sessions, you will step into the role of the newly appointed Risk Director at Zephyr Dynamics, a mid-sized US company attempting a massive $50M expansion into the Australia/New Zealand (ANZ) and APAC markets. You must build their ERM framework from scratch, managing strict APRA compliance, emergent cyber risks, and executive demands.

Core Module 1: Governance, Compliance & Analytics

Sessions 1 to 9

Session 1: Global Governance & APAC Baseline

Introduction: Aligning with APRA (Australia), SEBI (India), and RBNZ mandates.
Theory: Navigating strict-liability operational risk regulations internationally.
Boardroom TaskDrafting Zephyr's initial multi-jurisdictional Risk Governance Directive.

Session 2: Framework Architecture

Introduction: Blending ISO 31000 processes with COSO ERM strategy.
Theory: Structural differences between strategy-focused and operations-focused standards.
Boardroom TaskSelecting the correct framework architecture for venture capital backers.

Session 3: Operational Resilience (CPS 230)

Introduction: Managing third-party and supply chain dependencies.
Theory: Mapping critical operations to comply with APRA CPS 230.
Boardroom TaskAuditing a critical logistics vendor to prevent statutory management failure.

Session 4: Information Security (CPS 234)

Introduction: Cyber threats and shadow-IT data leakage.
Theory: Implementing mandatory data safeguards under APRA CPS 234.
Boardroom TaskIsolating an immediate breach risk caused by staff using unvetted AI tools.

Session 5: Risk Assessment & Matrix Design

Introduction: Calculating inherent vs. residual risk.
Theory: Building a 5x5 Heat Map and establishing financial impact thresholds.
Boardroom TaskQuantifying a supplier bankruptcy threat and plotting it on the matrix.

Session 6: The 4 T's of Risk Response

Introduction: Tolerate, Treat, Transfer, Terminate.
Theory: Cost-benefit analysis of mitigation versus insurance premium costs.
Boardroom TaskDeciding whether Zephyr should buy a $150k policy or exit the market.

Session 7: Quantitative Analytics

Introduction: Translating risk events into hard financial data.
Theory: Expected Monetary Value (EMV) and basic Monte Carlo concepts.
Boardroom TaskCalculating the EMV of a potential Sydney port strike disrupting Q3 revenue.

Session 8: Scenario Planning

Introduction: Preparing for black swan events and unpredictable crises.
Theory: Red teaming, tabletop exercises, and scenario war-gaming.
Boardroom TaskRunning a tabletop exercise for a sudden regional sovereign crisis.

Session 9: Controls & Assurance

Introduction: Executing the Three Lines Model in practice.
Theory: Preventative vs. Detective controls and internal audit hand-offs.
Boardroom TaskAuditing a failed control that led to a minor fraud event in Auckland.

Core Module 2: Execution, GRC Systems & Crisis PR

Sessions 10 to 18

Session 10: Key Risk Indicators (KRIs)

Introduction: Building early warning systems before a risk event occurs.
Theory: Leading vs. Lagging indicators and setting threshold triggers.
Boardroom TaskDesigning 3 effective KRIs for a highly volatile FX exposure.

Session 11: Technology & GRC Platforms

Introduction: Moving away from fragile Excel spreadsheets.
Theory: Evaluating major GRC platforms (e.g., AuditBoard, ServiceNow).
Boardroom TaskSelecting the right GRC vendor based on APRA data localization rules.

Session 12: Automated Risk Workflows

Introduction: Removing human error from risk tracking and alerts.
Theory: API integrations and establishing automated GRC alerts.
Boardroom TaskSetting up an automated alert protocol for when FX rates breach established KRIs.

Session 13: Risk Culture & Change

Introduction: Getting employees to actually care about risk frameworks.
Theory: Overcoming silo-mentality and embedding risk into daily KPIs.
Boardroom TaskAddressing a toxic sales culture that continually bypasses credit risk checks.

Session 14: Board Reporting & Dashboards

Introduction: Presenting complex risk metrics effectively to the C-Suite.
Theory: Visual communication, executive summaries, and data storytelling.
Boardroom TaskDistilling a 50-page risk assessment into a 3-slide Board Pack.

Session 15: Enterprise Resilience & BCP

Introduction: Planning for when the worst-case scenario becomes reality.
Theory: Business Continuity Planning (BCP) and disaster recovery scoping.
Boardroom TaskDrafting the recovery steps for a warehouse destroyed by a natural disaster.

Session 16: Crisis Communication & PR

Introduction: Managing the optics and stakeholder panic during a risk event.
Theory: External communication strategies and regulatory disclosure timelines.
Boardroom TaskDrafting the emergency press release following a major data breach leak.

Session 17: Risk Financing

Introduction: Funding catastrophic losses that breach the risk appetite.
Theory: Lines of credit, insurance deductibles, and self-insurance reserves.
Boardroom TaskAllocating a $2M contingency budget across competing departmental risks.

Session 18: Continuous Improvement

Introduction: Keeping the ERM framework alive and adaptable to macro changes.
Theory: Feedback loops, post-incident reviews, and maturity model assessments.
Boardroom TaskConducting a post-mortem on a near-miss operational failure.
Core Program Finale

Session 19: The Zephyr APAC Master Triage

Zephyr Dynamics has been hit by a sudden geopolitical tariff shock, an AI data leak breaching APRA CPS 234, and a major internal fraud scandal simultaneously. You must independently build the revised risk appetite, construct the heat matrix, utilize GRC parameters, handle the PR crisis, and present the final dashboard to the board to pass the core program.

Part 2: Specialisation Framework Tracks

Select one track below to master the specific regulatory and strategic requirements of your industry. Each track includes 8 specialized sessions (including a certification roadmap) and a unique storyline. Subscribe to a single track, or bundle it with the Core Pilot. (Click on any track title below to expand and view its full syllabus).

Track 1: Finance & Basel III Standard (Click to Expand)
🏦

Storyline: The Meridian Bank Crisis. Meridian is a rapidly growing regional bank facing severe liquidity pressure due to sudden interest rate hikes and a spike in defaulting commercial real estate loans. You must implement the Basel III capital frameworks to prevent central bank intervention.

Session 1: Basel Frameworks

Theory: Capital Adequacy Ratios (CAR) math and Tier 1 vs Tier 2 requirements.
Boardroom TaskCalculate Meridian's Tier 1 shortfall after a major loan write-off.

Session 2: Liquidity Coverage (LCR)

Theory: 30-day stress outflow modeling and managing High-Quality Liquid Assets.
Boardroom TaskDetermine which assets to liquidate to meet the 100% LCR threshold.

Session 3: Credit Risk Modeling

Theory: Probability of Default (PD) and Loss Given Default (LGD).
Boardroom TaskProvision exact capital buffers for a defaulting real estate portfolio.

Session 4: Market Risk & VaR

Theory: Value at Risk (VaR), interest rate shocks, and duration gaps.
Boardroom TaskHedge a sudden 100bps interest rate hike using swaps.

Session 5: Operational Risk

Theory: Internal fraud controls and segregation of duties.
Boardroom TaskInvestigate and close a loophole being exploited by a rogue desk trader.

Session 6: Stress Testing

Theory: CCAR principles and adverse economic macroeconomic forecasting.
Boardroom TaskModel the bank's survival against a 20% housing market crash.
Track 1 Capstone

Session 7: The Meridian Triage

Execute a 48-hour liquidity crisis triage for Meridian Bank using Basel III models.

Session 8 (Bonus): Certification Pathway Guidance
Guidance on navigating external credentialing bodies (e.g., FRM, PRMIA) and exam prerequisites. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 2: NIST RMF & Cyber Standard (Click to Expand)
💻

Storyline: The NexaHealth Migration. NexaHealth, a SaaS healthcare startup, is executing a sensitive patient data migration to the cloud while fending off active ransomware threats. Apply the NIST Risk Management Framework to secure the perimeter.

Session 1: NIST Fundamentals

Theory: System categorization based on impact levels (Categorize, Select, Implement, Assess).
Boardroom TaskCategorize the new patient database to determine required security controls.

Session 2: Threat Landscapes

Theory: Analyzing threat vectors, ransomware, and blast radiuses.
Boardroom TaskMap the potential blast radius of a phishing attack on the HR department.

Session 3: Access & Identity

Theory: Zero-trust architecture and principle of least privilege.
Boardroom TaskAudit and revoke excessive admin privileges across the engineering team.

Session 4: Data Privacy

Theory: Encryption standards and mapping data flows in transit and at rest.
Boardroom TaskAssess and close a critical encryption gap in an external API.

Session 5: Incident Response

Theory: Containment, eradication, and recovery strategies post-breach.
Boardroom TaskDraft the 24-hour executive playbook for a potential data leak.

Session 6: Vendor Risk

Theory: Third-party risk management and SLA security audits.
Boardroom TaskConduct a severe security audit on a new cloud hosting provider.
Track 2 Capstone

Session 7: The NexaHealth Breach

Contain an active server breach at NexaHealth using the NIST framework without violating health privacy laws.

Session 8 (Bonus): Certification Pathway Guidance
Steps to leverage your knowledge toward external IT risk and CRISC credentialing. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 3: COSO ERM (The Strategy Standard) (Click to Expand)
💊

Storyline: The BioGen Activist Siege. BioGen, a publicly traded pharmaceutical firm, faces aggressive activist investors demanding a board overhaul amidst critical drug pipeline delays. Align strategy and performance using COSO to restore confidence.

Session 1: Governance & Culture

Theory: Operating models, board oversight, and culture evaluation.
Boardroom TaskRestructure the risk committee to appease activist shareholders.

Session 2: Strategy & Objectives

Theory: Evaluating alternative strategies and their risk profiles.
Boardroom TaskDefine the hard risk appetite for acquiring a new experimental drug.

Session 3: Performance Execution

Theory: Risk prioritization and portfolio view of risk against strategic goals.
Boardroom TaskPrioritize 10 overlapping risks delaying BioGen's Q4 pipeline.

Session 4: Integration

Theory: Applying COSO principles to broader organizational frameworks.
Boardroom TaskAddress a major public relations risk regarding clinical trial diversity.

Session 5: Information & Reporting

Theory: Leveraging info systems and communicating strategy shifts.
Boardroom TaskDraft a public risk disclosure response to counter the activist memo.

Session 6: Entity-Level Controls

Theory: Control environments, top-down compliance, and SOX basics.
Boardroom TaskRemedy a systemic entity-level control failure in R&D expenditure.
Track 3 Capstone

Session 7: The BioGen Turnaround

Present a comprehensive strategic turnaround risk defense to BioGen's activist board members.

Session 8 (Bonus): Certification Pathway Guidance
Guidance on COSO-specific certifications and advanced strategic management credentials. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 4: ISO 31000 (The Global Standard) (Click to Expand)
🛒

Storyline: The OmniRetail Expansion. OmniRetail is aggressively expanding physical and digital storefronts into the European market. Use the iterative ISO 31000 principles to build a flexible, globally compliant operational risk net across borders.

Session 1: ISO Principles

Theory: The core mandate and principles of creating organizational value.
Boardroom TaskAlign OmniRetail's fragmented European operations to the ISO mandate.

Session 2: Framework Design

Theory: Designing the framework architecture and securing leadership commitment.
Boardroom TaskDesign the risk organizational chart for the new Berlin headquarters.

Session 3: The Risk Process

Theory: External vs. Internal context mapping and scope definition.
Boardroom TaskMap the specific regulatory and economic context of the German retail market.

Session 4: Operational Resilience

Theory: Recovery Time Objectives (RTO) and cross-border continuity planning.
Boardroom TaskDraft a critical BCP for the central European distribution warehouse.

Session 5: Supply Chain Risk

Theory: Single points of failure, multi-tier dependencies, and vendor redundancy.
Boardroom TaskSource alternative suppliers after a primary logistics partner goes bankrupt.

Session 6: Recording & Reporting

Theory: Continuous improvement and transparent, iterative risk recording.
Boardroom TaskSet up the monthly risk review dashboard for the European Director.
Track 4 Capstone

Session 7: The Berlin Launch

Finalize the unified operational risk architecture for OmniRetail's Berlin launch under intense deadline pressure.

Session 8 (Bonus): Certification Pathway Guidance
Exploring external ISO 31000 Lead Risk Manager certification requirements. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 5: CAS / RIMS (The Actuarial Model) (Click to Expand)
🚛

Storyline: The Apex Logistics Fleet. Apex manages a global transport fleet facing skyrocketing commercial insurance premiums and rising claims. Utilize quantitative actuarial models to justify funding an alternative captive insurance company.

Session 1: Maturity Models

Theory: The RIMS Risk Maturity Model attributes and baseline enterprise assessment.
Boardroom TaskAssess Apex's fragmented fleet maturity and present the baseline score.

Session 2: Loss Forecasting

Theory: Actuarial triangulation and historical claims modeling.
Boardroom TaskForecast next year's accident frequency and severity based on a 5-year dataset.

Session 3: Risk Capital (RAROC)

Theory: RAROC mathematics and evaluating risk-adjusted capital returns.
Boardroom TaskCalculate the RAROC for upgrading the entire fleet with autonomous braking.

Session 4: Alternative Risk Transfer

Theory: Captives, CAT bonds, and bypassing traditional insurance carriers.
Boardroom TaskStructure the initial framework for an Apex-owned captive insurance cell.

Session 5: Advanced Monte Carlo

Theory: Advanced simulation distributions (Normal, Lognormal) and probabilistic ruin.
Boardroom TaskRun 10,000 loss scenarios to determine the 99th percentile capital requirement.

Session 6: Total Cost of Risk (TCOR)

Theory: TCOR formula (Premiums + Losses + Admin).
Boardroom TaskCalculate Apex's enterprise TCOR and identify the biggest cost leakage.
Track 5 Capstone

Session 7: The Captive Defense

Present the financial viability of a captive insurance model to the Apex CFO using quantitative models.

Session 8 (Bonus): Certification Pathway Guidance
Navigating professional pathways like the RIMS-CRMP or quantitative actuarial exams. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 6: ESG & Climate Risk (ISSB / ASRS) (Click to Expand)
🌍

Storyline: The TerraCorp Disclosure. TerraCorp, an international mining giant, is facing strict new mandatory climate-reporting laws and activist blockades. Using the active ISSB (IFRS S1/S2) and Australian ASRS frameworks (which recently superseded TCFD), you must build a robust, auditable ESG risk architecture to avoid massive regulatory fines and investor divestment.

Session 1: The New ESG Mandate

Theory: Transitioning from TCFD to ISSB / ASRS mandatory standards.
Boardroom TaskDetermine which reporting group TerraCorp falls into and establish compliance deadlines.

Session 2: Physical vs. Transition Risk

Theory: Modeling climate hazards versus regulatory/market transitions.
Boardroom TaskAssess the financial impact of a new carbon-tax legislation on mining output.

Session 3: GHG Emissions Scoping

Theory: Accounting for Scope 1, 2, and the complexities of Scope 3 supply chain emissions.
Boardroom TaskAudit a heavily flawed Scope 3 emissions report provided by a logistics partner.

Session 4: Climate Scenario Analysis

Theory: Using differing temperature pathways (1.5°C vs 3°C) to stress test assets.
Boardroom TaskModel the devaluation of a coastal mining asset under a severe climate event scenario.

Session 5: Social & Governance Risk

Theory: Modern slavery in supply chains, indigenous rights, and board accountability.
Boardroom TaskResolve an escalating dispute over supply chain labor practices flagged by an NGO.

Session 6: Audit & Assurance Prep

Theory: Preparing the sustainability report for external limited assurance.
Boardroom TaskIdentify and cure data gaps before the external auditor arrives.
Track 6 Capstone

Session 7: The TerraCorp Sustainability Report

Finalize and present the inaugural ISSB-aligned Sustainability Report to the TerraCorp board, securing approval before the statutory filing deadline.

Session 8 (Bonus): Certification Pathway Guidance
Guidance on sustainability reporting credentials (e.g., SCR, IFRS Sustainability degrees). Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 7: IT Governance & Audit (COBIT Standard) (Click to Expand)
📊

Storyline: The FinTech Pre-IPO Crisis. A rapidly scaling financial technology company is failing its pre-IPO regulatory audit due to phantom IT spending, undocumented system patches, and poor data governance. Use the COBIT framework to align IT goals directly with the enterprise's financial objectives.

Session 1: COBIT Principles

Theory: Differentiating between IT governance (board level) and IT management.
Boardroom TaskEstablish the governance boundary between the CIO and the Board of Directors.

Session 2: Aligning IT & Business Goals

Theory: The goals cascade mechanism mapping IT metrics to enterprise ROI.
Boardroom TaskJustify a $5M cloud migration budget strictly using enterprise strategic objectives.

Session 3: Process Capability Models

Theory: Evaluating IT processes on a maturity scale of 0 to 5.
Boardroom TaskAudit the software deployment process and score its current maturity level.

Session 4: Risk & Resource Optimization

Theory: Identifying phantom IT spending and optimizing technology assets.
Boardroom TaskExecute a resource audit to cut 15% of redundant SaaS subscriptions.

Session 5: Information Governance

Theory: Managing data architecture, data quality, and compliance (SOX ties).
Boardroom TaskFix a critical data integrity flaw in the automated financial reporting system.

Session 6: Performance Measurement

Theory: Developing IT balanced scorecards and defining lag/lead indicators.
Boardroom TaskDesign the IT performance dashboard for the upcoming board meeting.
Track 7 Capstone

Session 7: The IPO Audit Defense

Defend the newly overhauled IT governance structure against external SOX auditors to clear the path for the company's IPO.

Session 8 (Bonus): Certification Pathway Guidance
Pathways for CISA (Certified Information Systems Auditor) and COBIT framework credentials. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 8: Public Sector Risk (Orange Book / ALARP) (Click to Expand)
🏛️

Storyline: The Mega-Rail Project. A government contractor is managing a highly scrutinized $5 billion public rail infrastructure project. It is over budget and facing intense media scrutiny. Master the Orange Book principles and the ALARP (As Low As Reasonably Practicable) model to satisfy government oversight committees.

Session 1: The Orange Book Basics

Theory: Public sector risk principles, public value, and taxpayer accountability.
Boardroom TaskDraft the core project risk strategy for parliamentary review.

Session 2: The ALARP Principle

Theory: Defining "As Low As Reasonably Practicable" vs absolute safety.
Boardroom TaskPerform a cost-benefit calculation to prove a safety measure reaches ALARP status.

Session 3: Optimism Bias & Cost Estimation

Theory: Reference class forecasting and adjusting for public sector optimism bias.
Boardroom TaskRecalculate the budget contingency reserve to account for a 30% optimism bias.

Session 4: Political & Reputational Risk

Theory: Navigating election cycles, media scrutiny, and policy shifts.
Boardroom TaskFormulate a mitigation strategy for a sudden change in government policy.

Session 5: Complex Procurement Risk

Theory: Probity, transparency, and managing massive contractor webs.
Boardroom TaskAudit a tier-1 contractor whose solvency is threatening project delivery.

Session 6: Assurance & Gateway Reviews

Theory: The Three Lines model applied to government Gateway Review processes.
Boardroom TaskPrepare the risk dossier required to pass the critical "Gate 3" investment review.
Track 8 Capstone

Session 7: The Parliamentary Inquiry

Defend the Mega-Rail project's risk profile, budget blowouts, and ALARP safety justifications in a simulated government oversight hearing.

Session 8 (Bonus): Certification Pathway Guidance
Guidance on public sector specific risk management credentials. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
CRITICAL LEGAL NOTICE: The educational insights, frameworks, and sandbox scenarios generated across this continuous professional development program are compiled solely for strategic business simulation and general instructional purposes. They do not constitute formal legal, accounting, compliance, or regulatory advice. TillSkill accepts no institutional liability for transactional execution failures, regulatory exposure mistakes, or compliance fines incurred by attendees implementing these generalized models. Consult a registered risk practitioner or legal counsel before executing enterprise-wide changes.