Every risk register is a record of what has already happened to somebody. That is what makes it defensible, and that is also its blind spot. An emerging risk has no loss history, no frequency to count and no comparable incident to anchor on, so the methods that make a register credible are exactly the methods that leave it out.
ISO/TS 31050 is the technical specification that addresses that gap. It sits inside the ISO 31000 family, uses the same framework and the same process, and adds what is needed to handle a risk that is new, fast-moving or not yet understood.
What the two days cover
The course works through the specification clause by clause, then applies it to risks you bring with you. Expect to leave with a scanning routine you can run next quarter, not a reading list.
- What makes a risk emerging, and how the specification defines it
- Where emerging risk work attaches to the ISO 31000 framework and process you already run
- Horizon scanning, weak signals and the sources that feed them
- Assessing a risk you cannot honestly score, and reporting it without pretending to a number
- Treatment that builds capacity to respond, rather than controls against a specific scenario
- Monitoring, review and the communication that keeps the subject alive between reviews
Who teaches it
Christophe Mazzola, a practising CISO and PECB Gold Certified Trainer. The examples come from audits and implementations he is running now, not from the slide deck.
Certification
The course prepares the PECB Certified ISO/TS 31050 Emerging Risks Manager examination. The exam and the certification fee are included in the price, in every delivery format. PECB sets the exam content, the duration and the credential terms; its official programme page is the source for those.
