Microcourse

Auditing Quality Risk and Resilience

Plan and perform an integrated audit that tests whether quality, risk, and resilience processes work together and produce reliable outcomes.

60 minutes Self-paced Waitlist planned

About this microcourse

About this microcourseMove beyond separate compliance checklists. This microcourse shows how to set integrated objectives, scope, criteria, and evidence trails; follow a process through risk and continuity interfaces; evaluate control effectiveness; write traceable findings; and verify corrective action. The applied task produces an audit plan and criteria-evidence matrix.What you will learnDefine audit objectives, scope, boundaries, criteria, methods, competence, and independence for an integrated engagement.Prioritize processes using importance, change, prior results, disruption exposure, and consequences for intended outcomes.Trace evidence across QMS, ERM, and continuity processes without treating guidance as certifiable requirements.Construct findings that separate requirement, evidence, condition, significance, cause, and corrective-action follow-up.Effort: Exactly 60 minutes   Pacing: Self-pacedProgram relationship: Standalone specialist; optional elective for AUD601 Module 6.CBA provides education and certificate preparation. IRRCB independently administers professional certification. Completion does not confer or guarantee IRRCB certification.

Move beyond separate compliance checklists. This microcourse shows how to set integrated objectives, scope, criteria, and evidence trails; follow a process through risk and continuity interfaces; evaluate control effectiveness; write traceable findings; and verify corrective action. The applied task produces an audit plan and criteria-evidence matrix.

What you will learn

  • Define audit objectives, scope, boundaries, criteria, methods, competence, and independence for an integrated engagement.
  • Prioritize processes using importance, change, prior results, disruption exposure, and consequences for intended outcomes.
  • Trace evidence across QMS, ERM, and continuity processes without treating guidance as certifiable requirements.
  • Construct findings that separate requirement, evidence, condition, significance, cause, and corrective-action follow-up.

Syllabus

Course structureOne Section -> one Subsection -> seven Units; Units 1-6 required and Unit 7 optionalCompletion requirementsComplete required Units 1-6 and earn at least 80% on the scored completion check; Unit 7 resources are optional

References

  • ASTM E3502-25, Standard Practice for Enterprise Risk Management.
  • ISO 31000:2018, Risk management - Guidelines.
  • ISO 9001:2026, Quality management systems - Requirements, especially clauses 4-10 and Annex A.
  • ISO 19011:2018, Guidelines for auditing management systems, or the current CBA-controlled edition.
  • ISO 22301:2019, Security and resilience - Business continuity management systems - Requirements, including applicable amendments.
  • ISO 37301:2021, Compliance management systems - Requirements with guidance for use, including applicable amendments.
  • Reference control: use the licensed CBA copy of ISO 9001:2026 and the current controlled editions of all other sources. Paraphrase protected standards text unless permission authorizes quotation. Alignment does not imply standards-body approval, accreditation, or endorsement.