The CFO's Playbook:
Enterprise Risk Management Curriculum
From Compliance Checklists to Strategic Boardroom Leadership
Welcome to the practitioner's guide to Enterprise Risk Management (ERM). Designed exclusively for aspiring Financial Controllers and future CFOs, this self-paced curriculum replaces dry theory with mathematical decision logic and continuous, real-world executive storylines.
Begin with our expanded 19-Session Core Pilot to build your universal governance foundation, heavily focused on the APRA, RBNZ, and SEBI regulatory baselines. Then, customize your expertise by selecting from 8 Specialized Framework Tracks tailored to your industry's specific demands.
Study anytime, anywhere. Immediate access upon subscription with full downloadable playbooks and interactive templates.
support@tillskill.com
Self-Study Subscription Options
Choose your path. Start with the core foundation, or unlock a specialized combo pass for maximum value and networking.
Core ERM Pilot
The practitioner's foundation covering APRA, ISO 31000 & COSO.
- ✔ 19 Interactive Study Sessions
- ✔ Risk Register & Matrix Templates
- ✔ Core Capstone Project Included
- ✔ Certificate of Completion
The Combo Pass
Save AUD 49 instantly
- ✔ Includes the 19-Session Core Pilot
- ✔ Plus 1 Specialized Framework Track
- ✔ Advanced Framework Capstone
- ✔ Exclusive access to Alumni Network Group
Single Track Upgrade
For students who have already completed the Core program.
- ✔ 8 Advanced Framework Sessions
- ✔ 1 Final Track Capstone Project
- ✔ Certification Pathway Guidance
Part 1: The Core ERM Pilot
The Core Storyline: "The Zephyr Expansion"
Throughout these 19 foundational sessions, you will step into the role of the newly appointed Risk Director at Zephyr Dynamics, a mid-sized US company attempting a massive $50M expansion into the Australia/New Zealand (ANZ) and APAC markets. You must build their ERM framework from scratch, managing strict APRA compliance, emergent cyber risks, and executive demands.
Core Module 1: Governance, Compliance & Analytics
Sessions 1 to 9
Session 1: Global Governance & APAC Baseline
Session 2: Framework Architecture
Session 3: Operational Resilience (CPS 230)
Session 4: Information Security (CPS 234)
Session 5: Risk Assessment & Matrix Design
Session 6: The 4 T's of Risk Response
Session 7: Quantitative Analytics
Session 8: Scenario Planning
Session 9: Controls & Assurance
Core Module 2: Execution, GRC Systems & Crisis PR
Sessions 10 to 18
Session 10: Key Risk Indicators (KRIs)
Session 11: Technology & GRC Platforms
Session 12: Automated Risk Workflows
Session 13: Risk Culture & Change
Session 14: Board Reporting & Dashboards
Session 15: Enterprise Resilience & BCP
Session 16: Crisis Communication & PR
Session 17: Risk Financing
Session 18: Continuous Improvement
Session 19: The Zephyr APAC Master Triage
Zephyr Dynamics has been hit by a sudden geopolitical tariff shock, an AI data leak breaching APRA CPS 234, and a major internal fraud scandal simultaneously. You must independently build the revised risk appetite, construct the heat matrix, utilize GRC parameters, handle the PR crisis, and present the final dashboard to the board to pass the core program.
Part 2: Specialisation Framework Tracks
Select one track below to master the specific regulatory and strategic requirements of your industry. Each track includes 8 specialized sessions (including a certification roadmap) and a unique storyline. Subscribe to a single track, or bundle it with the Core Pilot. (Click on any track title below to expand and view its full syllabus).
Track 1: Finance & Basel III Standard
Storyline: The Meridian Bank Crisis. Meridian is a rapidly growing regional bank facing severe liquidity pressure due to sudden interest rate hikes and a spike in defaulting commercial real estate loans. You must implement the Basel III capital frameworks to prevent central bank intervention.
Session 1: Basel Frameworks
Session 2: Liquidity Coverage (LCR)
Session 3: Credit Risk Modeling
Session 4: Market Risk & VaR
Session 5: Operational Risk
Session 6: Stress Testing
Session 7: The Meridian Triage
Execute a 48-hour liquidity crisis triage for Meridian Bank using Basel III models.
Guidance on navigating external credentialing bodies (e.g., FRM, PRMIA) and exam prerequisites. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 2: NIST RMF & Cyber Standard
Storyline: The NexaHealth Migration. NexaHealth, a SaaS healthcare startup, is executing a sensitive patient data migration to the cloud while fending off active ransomware threats. Apply the NIST Risk Management Framework to secure the perimeter.
Session 1: NIST Fundamentals
Session 2: Threat Landscapes
Session 3: Access & Identity
Session 4: Data Privacy
Session 5: Incident Response
Session 6: Vendor Risk
Session 7: The NexaHealth Breach
Contain an active server breach at NexaHealth using the NIST framework without violating health privacy laws.
Steps to leverage your knowledge toward external IT risk and CRISC credentialing. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 3: COSO ERM (The Strategy Standard)
Storyline: The BioGen Activist Siege. BioGen, a publicly traded pharmaceutical firm, faces aggressive activist investors demanding a board overhaul amidst critical drug pipeline delays. Align strategy and performance using COSO to restore confidence.
Session 1: Governance & Culture
Session 2: Strategy & Objectives
Session 3: Performance Execution
Session 4: Integration
Session 5: Information & Reporting
Session 6: Entity-Level Controls
Session 7: The BioGen Turnaround
Present a comprehensive strategic turnaround risk defense to BioGen's activist board members.
Guidance on COSO-specific certifications and advanced strategic management credentials. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 4: ISO 31000 (The Global Standard)
Storyline: The OmniRetail Expansion. OmniRetail is aggressively expanding physical and digital storefronts into the European market. Use the iterative ISO 31000 principles to build a flexible, globally compliant operational risk net across borders.
Session 1: ISO Principles
Session 2: Framework Design
Session 3: The Risk Process
Session 4: Operational Resilience
Session 5: Supply Chain Risk
Session 6: Recording & Reporting
Session 7: The Berlin Launch
Finalize the unified operational risk architecture for OmniRetail's Berlin launch under intense deadline pressure.
Exploring external ISO 31000 Lead Risk Manager certification requirements. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 5: CAS / RIMS (The Actuarial Model)
Storyline: The Apex Logistics Fleet. Apex manages a global transport fleet facing skyrocketing commercial insurance premiums and rising claims. Utilize quantitative actuarial models to justify funding an alternative captive insurance company.
Session 1: Maturity Models
Session 2: Loss Forecasting
Session 3: Risk Capital (RAROC)
Session 4: Alternative Risk Transfer
Session 5: Advanced Monte Carlo
Session 6: Total Cost of Risk (TCOR)
Session 7: The Captive Defense
Present the financial viability of a captive insurance model to the Apex CFO using quantitative models.
Navigating professional pathways like the RIMS-CRMP or quantitative actuarial exams. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 6: ESG & Climate Risk (ISSB / ASRS)
Storyline: The TerraCorp Disclosure. TerraCorp, an international mining giant, is facing strict new mandatory climate-reporting laws and activist blockades. Using the active ISSB (IFRS S1/S2) and Australian ASRS frameworks (which recently superseded TCFD), you must build a robust, auditable ESG risk architecture to avoid massive regulatory fines and investor divestment.
Session 1: The New ESG Mandate
Session 2: Physical vs. Transition Risk
Session 3: GHG Emissions Scoping
Session 4: Climate Scenario Analysis
Session 5: Social & Governance Risk
Session 6: Audit & Assurance Prep
Session 7: The TerraCorp Sustainability Report
Finalize and present the inaugural ISSB-aligned Sustainability Report to the TerraCorp board, securing approval before the statutory filing deadline.
Guidance on sustainability reporting credentials (e.g., SCR, IFRS Sustainability degrees). Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 7: IT Governance & Audit (COBIT Standard)
Storyline: The FinTech Pre-IPO Crisis. A rapidly scaling financial technology company is failing its pre-IPO regulatory audit due to phantom IT spending, undocumented system patches, and poor data governance. Use the COBIT framework to align IT goals directly with the enterprise's financial objectives.
Session 1: COBIT Principles
Session 2: Aligning IT & Business Goals
Session 3: Process Capability Models
Session 4: Risk & Resource Optimization
Session 5: Information Governance
Session 6: Performance Measurement
Session 7: The IPO Audit Defense
Defend the newly overhauled IT governance structure against external SOX auditors to clear the path for the company's IPO.
Pathways for CISA (Certified Information Systems Auditor) and COBIT framework credentials. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.
Track 8: Public Sector Risk (Orange Book / ALARP)
Storyline: The Mega-Rail Project. A government contractor is managing a highly scrutinized $5 billion public rail infrastructure project. It is over budget and facing intense media scrutiny. Master the Orange Book principles and the ALARP (As Low As Reasonably Practicable) model to satisfy government oversight committees.
Session 1: The Orange Book Basics
Session 2: The ALARP Principle
Session 3: Optimism Bias & Cost Estimation
Session 4: Political & Reputational Risk
Session 5: Complex Procurement Risk
Session 6: Assurance & Gateway Reviews
Session 7: The Parliamentary Inquiry
Defend the Mega-Rail project's risk profile, budget blowouts, and ALARP safety justifications in a simulated government oversight hearing.
Guidance on public sector specific risk management credentials. Note: We are not an authorized training partner. This guidance is for strategic career planning only. Students are expected to independently verify certification prerequisites with the respective credentialing bodies.