Risk Management in Business Continuity

The Risk Management in Business Continuity Course enables professionals to design, implement and improve risk management applied to business continuity. It addresses risk and opportunities, disruptive risk and change control in the BCMS context, supported by a case study and guided practical exercises.

Upcoming dates

Confirmed dates.
Synchronous, live training. Interaction with the trainer and the group.

1 June 2026
Live Online • next edition
17 August 2026
Live Online • base price
Duration: 3 days / 24h
Language: available in Portuguese or English
Training: practical and case-study based
Exam: 3h
SPECIALIST LEVEL — applied depth in risk and business continuity.

Why this course exists

To structure risk management for business continuity, aligning ISO 31000 with ISO 22301 and related practices, with a focus on disruptive risk, governance and continuous improvement.

Many organisations have business continuity initiatives without a solid model to identify, assess and treat risks affecting critical processes and assets, nor a consistent mechanism to manage risks and opportunities in the BCMS context.
This course establishes an advanced and applicable knowledge baseline, supported by theoretical and practical sessions and by a case study, enabling teams to design and operate a risk management framework oriented to business continuity.

What this course enables you to do

Structure

Define a framework and governance model for risk management in business continuity, aligned with the organisation’s needs.

Apply

Apply risk and opportunity management methodologies in business continuity programmes and management systems, with exercises and a case study.

Manage changes

Plan and control changes in the BCMS, understanding links and impacts with risk management.

Address disruptive risk

Assess and manage disruptive risks to business processes and critical assets, supporting preparedness, response and recovery.

Frameworks, standards and best practices addressed throughout the course

ISO 31000 (risk management)
ISO 22301 (business continuity / BCMS)
Governance and risk governance model
Risk and opportunities in the BCMS
Change management in the BCMS
Disruptive risk
Applicable legal and regulatory requirements (e.g. DORA, NIS2 — where relevant)
Correlated best practices

Value for the organisation

  • Establishes a consistent model to manage risks affecting critical processes and assets in the BCMS context.
  • Strengthens governance and prioritisation, reducing ad hoc decisions and reactive responses to disruptive events.
  • Supports maturity and continuous improvement through clear criteria, method and guided practice.
  • Improves the ability to demonstrate control and traceability in audits, to clients and in supervisory contexts, where applicable.

Introduction

The Risk Management in Business Continuity course enables participants to understand and apply risk management best practices, based on ISO 31000, to support risk requirements in an organisation with a formal or informal business continuity system, for example based on ISO 22301, and/or related practices.

The course addresses risk and opportunity management in the BCMS context, as well as disruptive risk management and change planning/control with impact on business continuity. The training is supported by a case study and exercises, oriented to the implementation and improvement of a risk management framework for business continuity.

This course prepares participants for the “Certified Business Continuity Lead Risk Manager” certification exam.

This Training Plan and all associated documents are protected by Copyright and registered as a literary work with IGAC.

General Objectives

At the end of this course, participants will be able to:

  • Identify business continuity, risk and associated framework concepts.
  • Understand the structure of related frameworks, legislation and regulation, sectorial and cross-sector, where relevant.
  • Establish a framework and governance model for risk management in business continuity, adapted to the organisation.
  • Define and apply a model for risk and opportunity management in business continuity programmes and management systems.
  • Plan and control changes in business continuity programmes and management systems.
  • Assess and manage disruptive risks to business processes and critical assets.
  • Prepare for the Certified Business Continuity Lead Risk Manager certification exam.

Target Audience

  • Business continuity managers and responsible professionals.
  • Risk managers and risk management professionals working in a BCMS context.
  • Consultants supporting the implementation or operation of business continuity systems.
  • Auditors of business continuity systems.
  • Professionals wishing to develop competences in the implementation and operation of a risk management programme for business continuity.

Prerequisites

There are no mandatory formal prerequisites. Familiarity with business continuity is recommended, for example the ISO 22301 framework. Specific requirements may apply depending on the quotation or proposal presented.

Programme

Introduction to the course and objectives
Review of fundamental business continuity concepts
Fundamental concepts for risk management
Frameworks, methodologies and applicable legal/regulatory requirements
  • Frameworks and methodologies for risk and continuity
  • Legal and regulatory requirements, where applicable, e.g. DORA, NIS2
Planning and design of the framework and governance model for risk management in business continuity
Risk and opportunity management in business continuity programmes and management systems
Planning and control of changes in business continuity programmes and management systems
Management of disruptive risks to business processes and related critical assets
Selection of strategy and solution options for before, during and after disruptive events

Exam(s) and Certification

Exam “Certified Business Continuity Lead Risk Manager”

The exam covers the following knowledge domains:

  • Domain 1: Business continuity, risk and framework concepts
  • Domain 2: Framework and governance model for risk management in business continuity
  • Domain 3: Risk and opportunity management in business continuity programmes and management systems
  • Domain 4: Planning and control of changes in business continuity programmes and management systems
  • Domain 5: Management of disruptive risks to business processes

 

Language(s): Portuguese and English (please confirm availability).
Duration: 3 hours.
Format: Knowledge assessment, according to applicable conditions.
Pass mark: 700/1000 points.
Results: Pass or Fail.
Issuing entity: Behaviour (legal entity), through its certification service Behaviour Certification Services.
Retake: 1 free retake within a maximum period of 2 months after the release date of the exam result.

Certification

After successfully completing the exam and signing the agreement / Code of Ethics, candidates may apply for one of the scheme levels, depending on experience:

  • Certified Business Continuity Risk Associate: no experience requirements.
  • Certified Business Continuity Risk Manager: 2 years of relevant experience.
  • Certified Business Continuity Lead Risk Manager: 5 years of relevant experience.

 

A Certificate and a Digital Certification Badge will be issued to participants who successfully complete the certification exam and satisfy all requirements of the certification for which they are applying. Certification is issued by Behaviour (legal entity), through its certification service Behaviour Certification Services.

The personal certification programme “Certified Business Continuity Lead Risk Manager” is designed and maintained in accordance with ISO/IEC 17024.

Certification programmes are valid only for individuals, not companies, and the award and maintenance of certification depend on the exam result, professional experience and compliance with the applicable agreement / Code of Ethics.

If the professional does not comply with the agreement / Code of Ethics, certification is not granted or is revoked.

Other Information

General Information
  • Training available in Portuguese or English.
  • Online training materials available in Portuguese or English, with online access, in accordance with the awarded conditions.
  • Risk management methodology.
  • Behaviour digital Training Attendance Certificate with 24 CPD/CPE credits.
  • Online Certification Exam, in Portuguese or English. The exam may be taken up to 2 months from the course start date.
  • If the candidate does not pass the exam, they are entitled to one free retake within a maximum period of 2 months from the release date of the initial exam result.
  • Digital Certification Diploma and Digital Certification Badge after passing the exam and completing the application process. This process has no associated cost.
Trainer(s)
The trainers are consultants and auditors with experience in implementation, auditing and training in business continuity and risk management topics, with particular focus on ISO 22301 and ISO 31000, and related practices.

Benefits

View benefits
  • Strengthens the ability to manage risk and opportunities in the context of business continuity programmes and management systems.
  • Structures a risk management implementation and operation methodology, with step-by-step guidance and applied practice.
  • Introduces and consolidates disruptive risk management for critical processes and assets.
  • Supports exam preparation and progression in associated certification credentials.
  • In case of failure, there is 1 free retake within a maximum period of 2 months after the initial exam result.

Logistics

Useful information
  • Live Online (synchronous time): 09h30–17h30 (Lisbon time), with lunch break and short breaks
  • Classroom (synchronous time): 09h30–17h30 (Lisbon time), with lunch break and short breaks
  • 21 hours of synchronous training, distributed across 4 consecutive days
  • Estimated 3 hours of guided autonomous work, intended for content consolidation and exam preparation, carried out flexibly outside synchronous sessions
  • Requirements: computer with stable internet, browser, PDF reader and audio/video
Hotels in Lisbon
Find out where you can stay in Lisbon, near Behaviour, for classroom training.

Frequently Asked Questions

Objective answers to common questions about risk management in business continuity and the course framework.

Is this course suitable if the organisation does not have a formal BCMS?
Yes. The course applies to organisations where business continuity practices are less formalised. The focus is on structuring risk management applied to continuity, creating a method and governance that can evolve into a more mature system.
Does this course have practical application?
Yes. The training is supported by a case study and exercises, oriented to the design and implementation of a risk management framework for business continuity.
Does the course include disruptive risk and change management in the BCMS context?
Yes. The course addresses the assessment and management of disruptive risks with impact on critical processes and assets and includes practices for planning and controlling changes in the BCMS, supporting decisions and continuous improvement.
Does this course replace an ISO 22301 Lead Implementer course?
No. This course focuses on risk management for business continuity, including disruptive risk and change management. An ISO 22301 Lead Implementer course is oriented to the implementation of the BCMS as a management system.
In which professional contexts is this course most useful?
  • When the organisation needs to structure risk and opportunities in the BCMS and reduce ad hoc approaches;
  • When there is a need for governance and prioritisation of risks affecting critical processes and assets;
  • When the organisation wants to strengthen maturity for audits, clients and supervision, where applicable.

For general questions about registration, delivery modes, exams, certification and recertification, please consult the BEHAVIOUR® FAQs.

Registration

Complete the form to request your registration for the preferred edition. Check the upcoming dates.

Contact name
=

Request more information

If you would like help to frame the course within your professional or organisational context, contact us and we will indicate the most suitable path.
Request Information

Companies: request a proposal

For team registrations, we provide volume conditions and a proposal tailored to the organisational need.
Request Proposal

This course may be attended by individual professionals. It may also be integrated into capability-building paths for teams that need to identify, analyse and treat risks affecting critical activities and continuity objectives.