🇲🇾 You are viewing Malaysia — uniform global pricing in USD🌐 Global site
Enroll Now 💬 WhatsApp Us
⚖️ Governance & Compliance  ·  Executive

Certified IT Compliance and Risk Management Expert

Online Certification  ·  12 Weeks  ·  Globally Recognised  ·  (CCOM6)

✅ 2026 Edition 🎓 CPD Accredited 🌍 100+ Countries 📜 Digital + Physical Certificate 100% Online
Executive Summary

Certified IT Compliance and Risk Management Expert

Designed for today’s high-impact professionals, the Certified IT Compliance and Risk Management Expert (CCOM6) delivers a rigorous Executive-level curriculum that equips participants with the knowledge, tools and frameworks needed to excel in security risk management, physical protection and investigations.

This 12 Weeks programme is structured around ASIS, ISO and recognised security-management standards, ensuring every graduate applies internationally validated methods to real-world challenges.

GLI’s CCOM6 holders are recognised by leading organisations across Africa, the Gulf, Europe and the Americas as qualified, results-driven professionals. Whether you are advancing your current career or transitioning into new responsibilities, this certification provides the competitive edge you need in 2026 and beyond.

Programme Overview

Certification at a Glance

Certification
Certified IT Compliance and Risk Management Expert
Acronym
CCOM6
Category
Governance & Compliance
Level
Executive
Duration
12 Weeks
Delivery Mode
100% Online
Assessment
Online Examination
Certificate
Digital + Physical
CPD Eligibility
CPD Accredited
Alumni Benefits
GLI Network Access
Self-Paced
USD 399
Live Virtual
USD 599
Target Audience

Who Should Enrol?

  • Security Officers and Supervisors
  • Security Managers and Consultants
  • Investigators and Intelligence Analysts
  • Loss Prevention and Protection Specialists
Programme Inclusions

Everything Included in Your Enrolment

  • All study materials and study guide
  • Access to GLI online learning portal
  • Online examination and assessment
  • Digital certificate and digital badge
  • Physical certificate (shipped to you)
  • CPD credits for professional bodies
  • GLI alumni network membership
  • Facilitator and tutor support
  • Resource downloads and reference library
  • Automatic enrolment confirmation
Certification Benefits

Why This Certification Matters for Your Career

Career Advancement
Accelerate your career towards senior security-management and CSO roles
Professional Recognition
Credential aligned with ASIS, ISO and recognised security-management standards
Operational Excellence
Apply world-class frameworks to improve performance and outcomes
Strategic Thinking
Develop the analytical and strategic skills demanded at the executive level
Compliance Readiness
Master the standards, compliance and ethical governance central to security risk management
Global Employability
Qualify for security risk management roles across corporates, regulators, government and civil-society organisations worldwide
Competency Framework

Core Competencies You Will Develop

Corporate Governance Principles and Boards
Regulatory Compliance and Risk Management
Policy Analysis, Research and Development
Ethics, Integrity and Anti-Corruption
Consumer Protection and Stakeholder Rights
Professional Ethics and Governance
Course Curriculum

Programme Modules

Click any module to explore the detailed curriculum topics included in this certification.

1
Foundations and Strategic Context of Certified IT Compliance and Risk Management Expert
  • Certified IT Compliance and Risk Management Expert: industry context, trends and professional standards
  • Security principles and protective concepts
  • The security profession, roles and standards
  • The threat landscape and security environment
  • Security governance and management systems
  • Physical, personnel and information security
  • Deterrence, detection, delay and response
  • Duty of care and legal framework
  • Ethics and professional conduct in security
  • Security as a business enabler
  • Career pathways and professional development
2
Three Lines and Ownership
  • The three lines model and who owns risk
  • Assurance mapping and avoiding duplicate assurance
  • Controls that work versus controls that exist
  • Public-sector and institutional reform
  • Sustaining reform and benefits
  • Measuring governance improvement
  • Professional ethics and integrity
  • Independence and objectivity
  • Confidentiality and information handling
  • Accountability and transparency
  • Conflicts of interest
  • Regulatory and legal duty
  • Fair treatment of stakeholders
  • Professional standards and self-regulation
  • Governance and compliance KPIs
3
Controls That Actually Work
  • Controls that work versus controls that exist
  • Risk appetite and tolerance in practice
  • Designing and testing a compliance programme
  • Integrity due diligence
  • Building an ethical culture
  • Consumer rights and protection law
  • Fair treatment and market conduct
  • Competition and antitrust
  • Complaints and redress mechanisms
  • Data protection and privacy
  • Vulnerable consumers and inclusion
  • Advertising and disclosure standards
  • Dispute resolution and ombudsman
  • Balancing business and consumer interests
  • GRC platforms and technology
4
Horizon Scanning and Emerging Risk
  • Regulatory mapping and horizon scanning
  • Risk appetite and tolerance in practice
  • Policy that changes behaviour
  • Conflicts of interest and related-party transactions
  • Whistleblowing and speak-up channels
  • Investigating misconduct
  • Governance in state, donor-funded and family-owned entities
  • Codes, standards and best practice (OECD)
  • Professional roles and ethics
  • Board and executive reporting
  • Regulator and investor relations
  • Policy and public engagement
  • Professional writing and briefings
  • Influencing and advising leaders
  • Managing sensitive disclosures
5
Assurance Mapping
  • Assurance mapping and avoiding duplicate assurance
  • The three lines model and who owns risk
  • Controls that work versus controls that exist
  • Research methods for policy
  • Stakeholder and impact analysis
  • Regulatory impact assessment
  • Policy development and drafting
  • Implementation and delivery
  • Monitoring and policy evaluation
  • Public consultation and engagement
  • Business ethics and ethical frameworks
  • Codes of conduct and values
  • Anti-bribery and anti-corruption
  • Fraud prevention and detection
  • Whistleblowing and speak-up
6
Reporting Risk Upward
  • Board effectiveness and the quality of board information
  • Risk appetite and tolerance in practice
  • Assurance mapping and avoiding duplicate assurance
  • Regulatory mapping and obligations
  • Enterprise risk management (ERM)
  • Internal controls and assurance
  • Managing regulator relationships
  • Compliance reporting and disclosure
  • Building a compliance culture
  • Policy cycle and evidence-based policy
  • Problem definition and analysis
  • Transparency and disclosure
  • Ethical decision-making
  • Data analytics for assurance
  • Regulatory technology (RegTech)
7
Risk Appetite in Practice
  • Risk appetite and tolerance in practice
  • The three lines model and who owns risk
  • Board effectiveness and the quality of board information
  • Implementation and assurance plan
  • Monitoring, evaluation and reporting
  • Stakeholder engagement plan
  • Directors' duties and responsibilities
  • Company secretarial practice
  • Governance in different ownership models
  • Reporting and disclosure tools
  • Audit and control automation
  • Compliance monitoring systems
  • Data governance and quality
  • Cybersecurity and information governance
  • Emerging governance technologies
8
Ethics and Anti-Corruption
  • AI, ethics and algorithmic accountability
  • Ethical supply chains
  • Culture, ethics and behaviour change
  • Digital ethics and responsible AI
  • Data ethics and privacy in finance
  • Ethics and transparency in tax
  • Conflicts of interest management
  • Ethics, confidentiality and professional conduct in HR
  • Conflicts of interest and integrity
  • Ethical use of AI and analytics in HR
  • Conflict resolution and mediation
  • Professional ethics in technology
  • Data ethics, privacy and protection
  • Ethical and responsible technology
  • Communication and conflict patterns
9
Public and Donor Context
  • Preparing financial statements
  • Interpreting financial statements
  • Psychoeducation and public communication
  • Media and public communication
  • Reporting quality and governance
  • Facilitation, training and public presentation skills
  • Financial statement and cash-flow analysis
  • Presentation and public speaking
  • Financial statements and the accounting equation
  • Public, private and non-profit governance
  • Public versus private procurement
  • Real estate marketing channels and property portals
  • Real estate regulation, licensing and professional conduct
  • Real estate development and project appraisal
  • Proposal development and donor reporting
10
Standards and Certification
  • Data quality and stewardship
  • Quality and delivery metrics
  • Delivery, quality and stakeholder plan
  • Quality planning and assurance
  • Quality control and continuous improvement
  • Integrated risk and quality control
  • Data quality and governance
  • Data quality, analysis and reporting
  • Sustainability certification and standards
  • Traceability, recall and quality assurance systems
  • Quality management systems and audits
  • Certification and continual improvement
  • Design review and quality
  • Quality management and standards
  • Data quality and master data management
11
Governance Practice
  • Building trust through data governance
  • Capstone scoping: a real governance or policy issue
  • Designing a governance, compliance or policy solution
  • Risk-based internal audit
  • Audit planning and execution
  • Control testing and evidence
  • Leading governance projects and change
  • Team leadership in governance
  • Governance transformation and reform
  • Building governance maturity
  • Regulatory and digital transformation
  • Data governance frameworks and roles
  • Data privacy law and compliance (GDPR)
  • Cybersecurity governance
  • Data breach and incident governance
12
Legal and Regulatory
  • Consent, rights and data subject requests
  • Risk, legal and feasibility analysis
  • Contracting and the three-way agreement
  • Statutory compliance and filings
  • The regulatory and legal environment
  • Shareholder and stakeholder rights
  • Employment relationship and the psychological contract
  • Legal and regulatory responsibility
  • Environmental legal compliance
  • Legal, cost and feasibility analysis
  • Contractor and visitor safety
  • Contract performance and exit
  • Contract governance and compliance
  • Vendor, venue and supplier contracting for events
  • Budget vs actual and variance
13
Financial Oversight
  • Data visualisation for finance
  • Communicating financial results
  • Complaints, accountability and fitness to practise
  • Accountability and follow-through
  • Meaning, purpose and values
  • Earned value and forecasting
  • Cost-benefit and investment appraisal
  • Project budgeting and financial control
  • Funding, cash flow and financing
  • Value and benefits management
  • Financial risk in projects
  • Make-versus-buy and total cost of ownership
  • Cost and price analysis
  • Key account management
  • Income capitalisation and investment value
14
Risk and Resilience
  • Crisis and reputation communication
  • Risk assessment and safety planning
  • Wellbeing and resilience coaching
  • Risk identification and analysis
  • Qualitative and quantitative risk analysis
  • Risk response and contingency
  • Managing growth, risk and resilience
  • Implementation planning and risk management
  • Enterprise risk management in banks
  • Credit risk measurement and mitigation
  • Liquidity risk and asset-liability management
  • Business continuity and crisis management
  • Interest-rate risk and gap analysis
  • Derivatives and risk instruments
  • Governance, risk and compliance
15
Data and Reporting
  • Cross-border data and transfers
  • Findings, reporting and remediation
  • Stakeholder trust and reputation metrics
  • Information lifecycle and records management
  • Regulation, ethics and misinformation in media and telecoms
  • Health records, data and confidentiality
  • Analytical techniques and bias
  • Financial reporting frameworks (IFRS/GAAP)
  • Integrated and sustainability reporting
  • Psychodynamic and psychoanalytic approaches
  • Cost and profitability analysis
  • Data protection and customer privacy
  • Regulatory reporting and audits
  • Data, analytics and customer insight
  • Control monitoring and reporting
16
Stakeholders and Oversight
  • Stakeholder and investor engagement
  • Management accounts and dashboards
  • The project environment and stakeholders
  • Stakeholder and sponsor management
  • Reporting to boards and executives
  • Compliance and regulatory projects
  • Stakeholder identification and analysis
  • Stakeholder engagement strategy
  • Reporting and dashboards
  • Marketing and sales KPIs and dashboards
  • Dashboards and performance reporting
  • Regulatory liquidity ratios (LCR, NSFR)
  • Regulatory awareness (GDPR and beyond)
  • Stakeholder communications
  • Regulatory capital and ratios
17
Leadership and Decisions
  • Team leadership in sales and marketing
  • Capacity and performance management
  • Team leadership in field and project settings
  • Forecasting and planning
  • Data-driven decision support and analytics
  • Omnichannel and channel management
  • Queue management and service flow
  • Workforce management and scheduling
  • Front-office and reception management
  • Relationship management and retention
  • Performance management in service
  • Writing advisory reports that drive decisions
  • Project management standards (PMI, PRINCE2)
  • Project roles and the project manager
  • Organisational change management
18
People and Conduct
  • Managing resistance and capability
  • Maturity and capability assessment
  • Talent sourcing channels and pipelines
  • High-potential identification and talent reviews
  • Knowledge management and capability building
  • Communicating risk to the workforce
  • Managing resistance and capability building
  • Workforce and shift management in retail
  • Scaling delivery capability
  • Decision support and insight
  • Roles, standards and professional conduct
  • Bribery, corruption and conduct risk
  • Training needs analysis
  • Career and talent development
  • Capability and skills frameworks
19
Operations and Quality
  • Benchmarking against standards
  • Designing a banking solution or process
  • Principles of credit and the lending process
  • Automation, RPA and straight-through processing
  • Process and control documentation
  • Quality assurance of audit
  • Assurance engagements and standards
  • Competitive bidding processes
  • Customer journey mapping and service design
  • Continuous improvement of delivery
  • Business process mapping
  • Emerging service technologies
  • Growing value through service
  • Leading service teams
  • Coaching and quality monitoring
20
Programmes and Change
  • Leading project governance
  • Change and adoption in projects
  • Agile and digital transformation projects
  • Sustaining benefits and change
  • Measuring change and project impact
  • Sustainability and social impact in projects
  • Project KPIs and performance metrics
  • Developing the project business case
  • Realising and measuring project value
  • Capstone scoping: a real project or programme
  • Designing the project plan and schedule
  • Regulatory change management
  • Implementation and change plan
  • Supply analysis, gaps and scenario planning
  • Onboarding and induction programme design
21
Technology and Data Risk
  • Digital banking platforms and APIs
  • Payment technology and switches
  • Cybersecurity and fraud technology
  • Technology governance and change control
  • Digital credit and alternative data
  • Digital accessibility and inclusion
  • Treasury technology and systems
  • Performance management systems and cycles
  • Safety management systems (ISO 45001)
  • The finance function and digital transformation
  • Data ethics, privacy and responsible analytics
  • Water supply systems: sources, treatment and distribution
  • Telehealth and digital care delivery
  • Attachment and developmental theory
  • Practice management systems
22
Third Parties and Procurement
  • Sustainable procurement principles and standards
  • Fair trade and responsible supply
  • Professional roles, boundaries and settings
  • Procurement and stock management for health commodities
  • Conflicts of interest and procurement ethics
  • Procurement and contract management
  • Vendor selection and management
  • Supply market analysis
  • Procurement and supply chain: scope and value
  • The procurement cycle and operating models
  • Procurement’s contribution to organisational strategy
  • Supply markets and the enabling environment
  • Digital procurement and the future of the profession
  • Continuous improvement and lean procurement
  • Procurement maturity assessment
23
Sustainability and ESG
  • Social media customer care
  • Responsible and sustainable banking
  • Social performance and outreach
  • Sustainable and green banking
  • Sustainability and green IT
  • Emerging assurance areas (ESG)
  • Corporate social responsibility communications
  • Sustainability, ESG and integrated value
  • Sustainability and responsible finance
  • Ethical principles and codes of practice
  • Trends: ESG, transparency and stakeholder capitalism
  • Embedding sustainability in sourcing
  • Mine water, tailings and environmental management
  • Social media management: platforms, communities and algorithms
  • Measurement and analytics for media and social campaigns
24
Communication and Disclosure
  • Management and board reporting
  • Safety communication and campaigns
  • Environmental monitoring and reporting
  • Incident reporting and record-keeping
  • Managing boundaries and dual relationships
  • Toolbox talks and safety communication
  • Communicating vision and telling stories
  • Executive communication and presence
  • Cross-cultural communication
  • Transparency, fairness and value for money
  • Sustainability reporting and disclosure
  • Professional and persuasive communication
  • Transaction monitoring and suspicious reporting
  • Ethics in communications
  • Communications strategy and planning
25
Strategic Context
  • Strategic analysis: PESTLE, SWOT and Porter’s Five Forces
  • Learning strategy and business alignment
  • Real options and strategic investment
  • Sustainability strategy and materiality
  • Reward strategy and total reward frameworks
  • Wellbeing and holistic health strategy
  • Building strategic relationships and coalitions
  • Negotiation strategy and tactics
  • Vision, mission and strategic intent
  • Competitive strategy and positioning
  • Business model design and innovation
  • Manufacturing strategies: make-to-stock, make-to-order and batch versus flow
  • Content strategy across platforms
  • Business case and strategic alignment
  • Strategic alignment of investments
26
Workforce Governance
  • The customer experience (CX) discipline
  • The sales pipeline and forecasting discipline
  • Analysis and diagnostic assessment
  • Brand strategy, identity and equity
  • Integrated marketing communications
  • Pricing strategy
  • Digital marketing strategy
  • Campaign planning and execution
  • Key account management strategy
  • Building strategic customer relationships
  • Account planning and whitespace analysis
27
International and Sanctions
  • Sanctions screening and PEP management
  • Transfer pricing and international tax
  • Global sourcing and international trade
  • Category management and strategy development
  • Spend analysis and demand aggregation
  • Sourcing strategies and portfolio (Kraljic)
  • Contract types and risk allocation
  • Materials requirements planning (MRP)
  • Capacity and production planning
  • ABC analysis and stock optimisation
  • Operations performance and throughput
28
Market Conduct
  • Ethics and fair customer treatment
  • Customer experience transformation
  • Professional ethics in customer service
  • Customer service and CX strategy
  • Designing voice-of-customer programmes
  • Sustaining strategic customer focus
  • Customer and journey analysis
  • Customer experience strategy
  • Customer journey mapping
  • Voice of the customer programmes
  • Reducing customer effort
  • Vehicle specifications, trims and options in customer language
  • Customer retention in the vehicle ownership cycle
  • Customer loyalty and repeat purchase in retail
  • Telecom products, tariffs and customer lifecycles
29
Safety and Environment
  • Peer support and consultation
  • Job safety analysis (JSA) and task risk
  • Sustaining ethical, effective practice
  • Predictive safety analytics
  • Automation and safety technology
  • Integration with quality and environment
  • Environmental, social and governance (ESG)
  • Event risk, safety and contingency planning
  • Industrial utilities, energy and process safety interfaces
  • Ethical frameworks and codes of practice
  • Duty of care and risk management
  • Driving measurable safety improvement
  • Environmental management systems (ISO 14001)
  • Continuous environmental improvement
  • Legal responsibilities and professional bodies
30
Records and Documentation
  • Record-keeping and data protection
  • Data, records and confidentiality tech
  • Professional documentation and presentation
  • Retention, loyalty and lifetime value
  • Tender planning and documentation
  • Customer retention, loyalty and lifetime value
  • Client feedback and satisfaction
  • Root-cause analysis techniques
  • Trend analysis and leading indicators
  • Leadership versus management and when each is needed
  • Situational and adaptive leadership
Learning Outcomes

What You Will Achieve

  • Establish a comprehensive understanding of Certified IT Compliance and Risk Management Expert principles aligned with ASIS, ISO and recognised security-management standards
  • Apply evidence-based methods to improve security risk management, physical protection and investigations
  • Master security risk management principles and boards and regulatory compliance and risk management
  • Apply policy analysis, research and development and ethics, integrity and anti-corruption in real-world settings
  • Lead risk management, quality and compliance relevant to your field
  • Design stakeholder engagement and professional communication strategies
  • Use data-driven decision-making and performance-measurement tools effectively
  • Apply internationally recognised best practice to advance your career in security risk management
Enrolment Process

How to Get Certified

🎯
Step 1: Choose Your Certification
You are viewing Certified IT Compliance and Risk Management Expert — one of GLI's 1,990+ globally recognised professional certifications.
💳
Step 2: Enrol & Pay Online — Instantly
Click Enrol & Study Online to register and pay securely via Paystack, Visa, Mastercard, M-Pesa or bank transfer. Access is granted the moment payment is confirmed.
📚
Step 3: Study in the GLI Learning Portal
Work through 30 structured modules and 150 lessons at your own pace, with downloadable resources and expert-designed content — all inside the LMS.
🎓
Step 4: Pass, Get Certified & Verified
Sit your final examination online, earn your certificate instantly, and receive a globally verifiable Certificate ID — plus GLI Alumni Network access.
🎓 Enrol & Study Online — Instant Access
Secure checkout · Instant LMS access · Globally verifiable certificate
Frequently Asked Questions

Common Questions

What is the CCOM6 certification?

Yes. GLI certifications are recognised across 100+ countries and are aligned with ASIS, ISO and recognised security-management standards. Graduates receive a digital certificate, a physical certificate and CPD credits recognised by employers worldwide.

Who should enrol in the CCOM6?

This certification is ideal for Security Officers and Supervisors, Security Managers and Consultants, Investigators and Intelligence Analysts and Loss Prevention and Protection Specialists, and other professionals seeking to formalise their expertise in security risk management, physical protection and investigations with a globally recognised credential.

How long does the CCOM6 certification take to complete?

The programme is structured over 12 Weeks and offers flexible learning modes. Self-paced learners can progress at their own schedule, while live virtual participants follow a structured cohort schedule with facilitator-led sessions.

Is the CCOM6 internationally recognised?

Yes. GLI certifications are recognised across 100+ countries and are aligned with ASIS, ISO and recognised security-management standards. Graduates receive a digital certificate, a physical certificate and CPD credits recognised by employers worldwide.

What is the cost of the CCOM6 certification?

The Certified IT Compliance and Risk Management Expert is offered in two formats: Self-Paced at USD 399 and Live Virtual at USD 599. Corporate group rates are available for organisations enrolling 5 or more participants. Contact GLI for a bespoke corporate training quotation.

What does the CCOM6 certification include?

Enrolment includes all study materials and study guides, access to GLI's online learning portal, online examination, digital certificate and badge, physical certificate (posted), CPD credits, GLI alumni network membership, and ongoing facilitator support.

What is the assessment format for the CCOM6?

The Certified IT Compliance and Risk Management Expert is assessed through an online examination consisting of multiple-choice questions, case study analysis, and practical application assignments. The assessment is designed to evaluate real-world competency, not just theoretical recall.

What CPD credits do I earn from the CCOM6?

The Certified IT Compliance and Risk Management Expert carries Continuing Professional Development (CPD) credits, which can be applied towards professional body requirements including recognised international professional associations.

Can I study the CCOM6 while working full-time?

Absolutely. The self-paced option is designed for busy working professionals and allows you to study when and where it suits you. Live virtual sessions are typically scheduled in the evenings or on weekends to accommodate professional commitments.

What career outcomes can I expect from the CCOM6?

Graduates progress towards senior security-management and CSO roles. The CCOM6 strengthens your expertise in security risk management, physical protection and investigations and positions you for advancement across corporates, regulators, government and civil-society organisations.

Graduate Voices

What Our Alumni Say

The curriculum was directly applicable to my daily work. I immediately applied what I learned and saw results within weeks of completing the programme.

Head of Governance
Private Sector

GLI's certification is the most practical professional programme I have attended. The international frameworks gave me credibility with my employer and clients.

Compliance Manager
NGO Sector

I earned my CCOM6 while working full-time. The self-paced format made it possible, and the quality of the content is genuinely world-class.

Policy Lead
Government
Related

You May Also Like

All Information Technology Certifications →
💬 WhatsApp 📝 Proposal
💬