Executive programme · Online · Gulf regulatory layer
aligned to ISO 22301, ISO 31000 and AE/SCNS/NCEMA 7000
A programme for executives who answer for resilience before the board and the regulator. You gain the governance language, six working artefacts and the Gulf Cooperation Council (GCC) regulatory layer; your organisation gains a leader who can take it toward ISO 22301 and NCEMA 7000 readiness.
Contracts increasingly ask for NCEMA-aligned continuity. The programme gives your executives the language and the artefacts that procurement and auditors expect to see.
Head of Risk, governance-risk-compliance (GRC) manager, business continuity (BCM) lead on the way to Chief Risk Officer (CRO): an executive credential about governance — accountability, boards, regulators — that matches the roles you are applying for.
Groups with several business units get one resilience framework across the whole management team, delivered as a cohort on your own cases.
NCEMA 7000 alignment is becoming a condition of access to UAE government work — across logistics, construction, IT services, healthcare, energy, transport and telecom. The requirement lands on organisations; the competence lands on people.
If you plan to build a career or win business in the Gulf, this credential answers the questions every employer, client and regulator here asks: do you know the national standards, can you speak to a board about resilience, and can you prove it? You leave with a verifiable certificate, six working documents for your own organisation, and the regulatory fluency that sets senior risk candidates apart across the GCC.
Each module ends with a working document you build for your own organisation. The measure of the programme is completeness and artefacts — you set the pace.
Risk appetite for disruption, committee architecture, delegated authority, three lines of defence, the Chief Risk Officer (CRO) role.
Artefact: a resilience governance policy and governance map
ISO 31000, the risk register, key risk indicators (KRIs), scenario analysis and stress-testing, linking ERM to continuity — including the use of AI for risk monitoring and early warning (ISO 42001).
Artefact: a resilience risk register with KRIs
Business impact analysis (BIA); recovery targets — maximum acceptable outage (MAO), minimum business continuity objective (MBCO), recovery time and recovery point objectives (RTO / RPO); cost of downtime; the investment case for measures.
Artefact: a completed BIA with defended targets
The crisis team, escalation, communications, the exercise programme and its reports.
Artefact: a crisis response plan and an exercise scenario
AE/SCNS/NCEMA 7000 in depth, mapping to ISO 22301, sector regulators, government-contract expectations.
Artefact: an organisation mapping matrix against NCEMA 7000 and ISO 22301
The resilience dashboard and AI-assisted monitoring, the board report, audit readiness, the maturity model.
Artefact: a dashboard and a board report template
AE/SCNS/NCEMA 7000:2021 is the UAE national standard for business continuity — mandatory for government entities and critical infrastructure, and increasingly referenced in supplier requirements across the economy.
Its structure is deliberately aligned with ISO 22301: one well-designed system covers both. The differences — terminology, supplier-evaluation duties, recovery during response — are exactly what Module 5 teaches.
Module 5 gives you the ability to read your organisation against both standards at once and to speak with a UAE regulator, client or auditor in their language — the layer this programme was built around.
| Standard | Covers | Module |
|---|---|---|
| ISO 22313 | BCMS guidance | M1 |
| ISO 22317 | Business impact analysis | M3 |
| ISO 22331 | Continuity strategy | M3 |
| ISO 22332 | Plans and procedures | M4 |
| ISO 22318 | Supply chain continuity | M2 · M5 |
| ISO 22330 | People aspects | M4 |
| ISO 22316 | Organisational resilience | M1 |
| ISO 22361 | Crisis management | M4 |
| ISO 22320 | Incident management | M4 |
| ISO 22398 | Exercises | M4 |
| ISO/IEC 27031 | ICT readiness | M6 |
| ISO/IEC 27001 | Information security | M6 |
| IEC 31010 | Risk assessment techniques | M2 |
| COSO ERM 2017 | Enterprise risk framework | M2 |
| ISO 37301 | Compliance management | M1 |
| ISO 37000 | Governance of organisations | M1 |
| ISO 42001 | AI management | M2 |
| UAE: NCEMA 7000 · TDRA IAS · DESC ISR · ADHICS v2 · UAE PDPL | Gulf regulatory layer | M5 |
| KSA: NCA ECC | Saudi cybersecurity controls | M5 |
| Qatar: NCSA NIA | Qatar information assurance | M5 |
This table is the promise of completeness: from board appetite to the auditor's report.
A proctored exam plus a defended capstone. There is a pass mark — the certificate is earned.
Six working documents leave the programme with you and go straight into your organisation.
Every certificate carries a unique number and a QR resolving to the register on risk-place.org. An employer verifies it in ten seconds.
Renewal through evidence of practice and professional development keeps the credential alive.
The certificate: personalised, numbered, QR-verified. Sample shown.
Every certificate number can be checked here.
PhD in Economics. Best Risk Manager of the Year 2020 (RusRisk). 15+ years leading risk functions. Built business continuity from zero at Nornickel — 20+ continuity plans. CRO of a $20bn petrochemical megaproject (AGCC, SIBUR) with 200+ construction risk indicators. Risk consulting at Ernst & Young.
Founding-cohort terms: this fee applies to the first cohort only and rises as the register grows. Payment by invoice; corporate purchase orders welcome.
Tell us who the programme is for — yourself or a leadership cohort — and we will come back the same day.
It is self-paced, with access that stays open. We measure the programme by completeness — the full cycle from board risk appetite to the auditor's report — and by the six artefacts you build. You choose the pace that fits your calendar.
It is an independent educational credential issued by risk-place, and we say so openly. Its weight comes from the strict requirements of the programme: completing all six modules and passing both the proctored exam and the capstone defence.
NCEMA assesses organisations against the national standard; recognition of private programmes is outside its role. This programme certifies your personal competence in that landscape — the ability employers and clients actually hire for.
Compliance belongs to organisations and is assessed by authorities. The programme equips you to lead your organisation toward it — the Module 5 mapping matrix is exactly that starting point.
Those are respected practitioner credentials for the people who build continuity systems. This programme certifies the executive layer — governance, board accountability and regulatory navigation — and is built around the GCC regulatory landscape, which is its home ground.
One exam re-take and one capstone re-submission are included; further attempts are scheduled at cost. The pass mark is what makes the certificate worth showing.
The personalised, numbered certificate with QR verification, the six artefacts you built, and continued access to the materials as they are updated.
Yes — the in-house track runs as a cohort on your own cases, and the capstone becomes a real board report for your organisation.
Invoice with a corporate purchase order — standard practice for learning and development budgets.
The Executive Certificate in Enterprise Resilience Governance is an independent educational programme by risk-place. It is not affiliated with, endorsed by or accredited by NCEMA, ISO or any other standardisation or certification body. The certificate confirms completion of the programme and successful assessment; it does not attest any organisation's compliance with any standard.