Flagship course

Defensible Risk Scoring

A cohort programme for United Kingdom practitioners who need a risk scoring audit platform that can explain every number it produces.

Learner reviewing structured notes during a workshop

Learning outcomes

  • Write control criteria that separate severity from likelihood without collapsing them into a single vague adjective.
  • Build weighting schemes that remain stable when one high-profile control fails.
  • Run a calibration session that reduces reviewer spread to an agreed band.
  • Produce a model memo suitable for board or audit committee reading.
  • Maintain an override log that documents exceptions without silently rewriting history.

Who it suits

GRC analysts, security leads, and internal auditors who already collect evidence but struggle to turn it into scores others accept. You should be comfortable reading control language; deep coding skill is not required.

Teams that need a full platform build-out may prefer Assurance Circle seating so calibration uses your own sample set.

Syllabus

Eight modules

  1. Score purpose and audience

    Decide what the number is for before choosing a formula. Map readers and failure modes.

  2. Criteria sheets that survive staffing changes

    Definition patterns, examples, and non-examples for each band.

  3. Evidence quality tiers

    How to discount incomplete artefacts without inventing false precision.

  4. Weighting without vanity

    Lab: remove metrics that inflate scores without changing decisions.

  5. Calibration rituals

    Paired scoring, reconciliation scripts, and when to escalate disagreement.

  6. Vendor and third-party extensions

    Inherited certifications, residual risk, and double-counting traps.

  7. Override logs and drift checks

    Quarterly hygiene for thresholds that slowly move without anyone noticing.

  8. Model memo and stakeholder language

    Write the short document that makes the platform usable outside the GRC team.

Instructor

Portrait of course instructor Amira Kline

Amira Kline

Amira has led scoring redesigns for mid-market United Kingdom firms across financial services and professional networks. She teaches the weighting and calibration modules and reviews every Scorecraft Lab model memo.

Informational pricing

Scorecraft Lab seat — £1,240

Includes live sessions, materials, memo review, and 12 months of alumni clinic access. No payment is taken on this site; invoices follow a confirmed place.

Reviews from this course

“Module four’s weighting lab was uncomfortable in a useful way — we retired a control family that only existed to make the dashboard look busy.”
Priya S., Information Security Manager

★★★★★

“The calibration script alone justified the seat. Our reviewers finally argue about criteria instead of personalities.”
Anonymous client in insurance
“Strong on method. The vendor module moves quickly if you have never mapped suppliers before — budget prep time.”
Owen · Bristol

FAQ

Do I need an existing platform to enrol?

No. Spreadsheets are fine for the exercises. If you already use a GRC tool, bring sample exports — we will show how criteria transfer, not how to click through one vendor’s UI.

How much live time is required?

Plan for six live sessions of 90 minutes across five weeks, plus asynchronous labs. Recordings are available, but calibration sessions work best live.

What is a real limitation of this course?

We do not teach you how to select or configure a commercial GRC product. Tooling choices, connector setup, and licence negotiations are outside the syllabus. If your main problem is software procurement, this programme will feel incomplete until that work is separate.

Can a whole team join?

Yes — see Assurance Circle on the pricing page for up to six seats with a private calibration using your controls.

Ready for the next cohort?

Tell us your role and what you currently score. We will confirm dates and whether Signal Map foundations should come first.