Skip to content Skip to navigation

SMU Professional Certificate in Governance, IT Risk Management and Compliance (IBF Level 2)


As organizations embrace digitalization to transform business and operations, it is critical to develop policies, procedures and controls to manage technology related risks. The frequency and scale of cyber attacks and breaches have escalated. The disruptions to systems and operations can greatly damage an organization’s reputation, public trusts and bottom line.

It is imperative for professionals in technology & operations (T&O) to be able to develop and implement effective controls to manage operational risk, activate technology disaster plans to ensure business continuity. 

This 3-day certification program adopts an experiential learning approach. Participants works on an extended case study to implement risk management controls to comply with regulatory requirements and industry best practices. 


  • Determine and justify risk tolerance & appetite
  • Assess risk and select risk treatment option
  • Develop and test business continuity plan & remedial actions
  • Design risk reporting process & tools
  • Apply data protection principles to device policies & processes
  • Use the Six Sigma approach to manage compliance risk
  • Enhance professional excellence with small group coaching
  • Expand perspectives through peer interactions & review  


  • Professionals with minimum 3 years relevant experience in IT risk management & security related function (e.g. security engineer, senior information security officer, senior risk officer, senior compliance or control officer, security administrator)
  • Participants who have completed IBF Standards Technology Level 1 program or show proof of competency at Level 1


Leonard Ong has over 15 years of information and corporate security experiences gained in telecommunication, enterprise and banking industries. He held various roles within the security profession, with responsibilities in information security, corporate security, project management, consulting and business development. Currently Associate Director at Merck, Leonard also serves on the ISACA Board of Directors.


Candidates will be assessed on the following competency unit in Technology & Operations: Technology: IT Risk Management and Security (IBF Level 2):

CU2: Governance, Risk Management and Compliance

Upon successful completion of the course, paticipants will be awarded the SMU Professional Certificate in Governance, IT Risk Management and compliance (IBF Level 2)


Risk Identification & Assessment

  • Determine risk appetite & tolerance
  • Identify risk factors & scenarios
  • Assess risk using risk models
  • Case study activities
    1.Identify business & technology Issues
    2.Determine & justify risk appetite
    3.Identify & list key risk exposures & scenarios
    4.Develop risk matrix and heatmap

Risk Response Options & Action Plan

  • Weigh risk response options
  • Prioritize based on quick wins & business case
  • Develop & execute risk action plan
  • Define monitoring metric & threshold
  • Define key risk indicators & triggers
  • Case study activities
    5.Select risk treatment & prioritize action plan
    6.Determine frequency, data source & metrics

Reporting, Escalation & Risk Ownership

  • Assign risk ownership
  • Escalate risk along the three lines of defense
  • Design risk tools
  • Develop business continuity plan
  • Manage crisis & response to breaches
  • Case study activities
    7.Design reporting process & tools
    8.Create risk register & identify tools

Compliance Risk Management

  • Know the regulatory requirements & landscape
  • Case study activities
    9.Apply Six Sigma approach to manage compliance risk
    10.Derive polices & procedures using data protection principles
    11.Determine compliance rating with reference to MAS Technology Risk Management Guidelines


Programme Date

11 - 13 Apr  2018
Wed-Fri 09:00 - 17:00

SGD $3,000 (excluding GST)

Net fee payable upfront for eligible self-sponsored applicants:

Singaporeans and PRs
S$900 (excl. GST)
Singaporeans aged 40 years and above
S$300 (excl. GST)

Terms & conditions apply.

Continuing Professional Development (CPD)

24 hours

ibf-sts funding

The programme has been accredited under the IBF Standards, and is eligible for funding under the IBF Standards Training Scheme (IBF-STS), subject to all eligibility criteria being met.

Candidates are advised to assess the suitability of the programme and its relevance to participants’ business activities or job roles.

IBF-STS provides 70% funding for direct training costs subject to a cap of S$7,000 per candidate per programme.

For programmes commencing on and after 1 July 2016, Singapore Citizens aged 40 years old and above are eligible for 90% co-funding of direct training costs, subject to a cap of S$7,000 per participant per programme

For more information, please visit:


Singapore Management University

contact us

For enquiries, please contact Chiew Yee at 6828 0971, Jaclyn at 6828 0254 or email


Last updated on 06 Dec 2017 .