Your Cart
Loading

Risk Management Toolkit 2026 — ISO 31000, COSO ERM & King Risk Governance: Appetite, KRIs & the Risk Process in Practice (Guide, Flash Cards & 50-Question Self-Assessment)

On Sale
$23.00
$23.00
Added to cart

Every board sets risk appetite. Every regulator expects a risk framework. Every job spec says "ISO 31000 and COSO." This toolkit is the working fluency behind all three sentences.

Most risk material picks one framework and ignores the other — and ignores South Africa entirely. The Risk Management Toolkit deliberately covers the full stack: King as the governance code, COSO ERM as the enterprise structure, ISO 31000 as the process methodology — three layers, one coherent story.


What's inside — one interactive file, three tools:

📘 Eleven chapters of risk craft:

  • ISO 31000:2018 properly explained — the eight principles, the framework cycle, the six-stage process, and the detail most guides miss: terminology now lives in ISO 31073:2022, which replaced ISO Guide 73
  • COSO ERM 2017 in full — all 20 principles walked component by component, from Governance and Culture through to Reporting, and why the 2017 revision moved risk from internal-control add-on to strategy-setting input
  • Choosing and combining the frameworks — including the three-layer South African stack used in practice
  • Risk appetite done properly — the capacity → appetite → tolerance → limits hierarchy, the Risk Appetite Statement, breach escalation, and a worked FSP example with actual rand thresholds. Plus the trap almost everyone falls into: "risk tolerance" means different things in the ISO vocabulary and in COSO practice — this toolkit names both and shows you how to avoid the confusion
  • The process in practice — risk registers, consistent scoring, the four treatment options (and where "Exploit" really comes from), KRIs with leading vs lagging indicators, scenario analysis and stress testing, a complete bow-tie walkthrough, the portfolio view, and honest risk-maturity benchmarking
  • King risk governance — the governing body's role, risk committees, and the current principle numbering: Principle 11 under King IV, Principle 8 under King V
  • Emerging risks — AI governance (COSO's supplementary guidance meets King V's AI expectations), climate risk with the TCFD-to-ISSB transition, and geopolitical disruption
  • Public sector risk — PFMA s38/s51 and MFMA s62 accountability, National Treasury's risk framework, and the link to risk-based internal audit
  • A key-numbers table and a 40-term glossary

🃏 40 Flash Cards — frameworks, numbers, and definitions, filterable by topic.

📝 50-question self-assessment — timed mode (75 minutes, 70% benchmark) or practice mode with instant explanations, per-topic results, and unlimited retakes with reshuffled questions.


Who it's for: Risk officers and second-line teams, CROs building appetite frameworks, risk and audit committee members, compliance officers expanding into risk, public sector risk managers, and candidates working toward professional risk designations.


Honesty, as on every product we publish: neither ISO 31000 nor COSO ERM certifies an organisation, there is no public "risk management exam" in South Africa, and this is not official material of any professional body. It is the conceptual grounding those designations assume — and the working fluency risk committees actually run on.


How it works: Instant download. One HTML file — any browser, any device, works offline. No account, no expiry.


Sovereignty by Char (Pty) Ltd is an independent publisher, not affiliated with ISO, COSO, the IoDSA, IRMSA, or National Treasury. This toolkit is education, not risk management advice — full disclaimers inside.

You will get a HTML (231KB) file