Flagship course
Defensible Risk Scoring
A cohort programme for United Kingdom practitioners who need a risk scoring audit platform that can explain every number it produces.
Learning outcomes
- Write control criteria that separate severity from likelihood without collapsing them into a single vague adjective.
- Build weighting schemes that remain stable when one high-profile control fails.
- Run a calibration session that reduces reviewer spread to an agreed band.
- Produce a model memo suitable for board or audit committee reading.
- Maintain an override log that documents exceptions without silently rewriting history.
Who it suits
GRC analysts, security leads, and internal auditors who already collect evidence but struggle to turn it into scores others accept. You should be comfortable reading control language; deep coding skill is not required.
Teams that need a full platform build-out may prefer Assurance Circle seating so calibration uses your own sample set.
Syllabus
Eight modules
-
Score purpose and audience
Decide what the number is for before choosing a formula. Map readers and failure modes.
-
Criteria sheets that survive staffing changes
Definition patterns, examples, and non-examples for each band.
-
Evidence quality tiers
How to discount incomplete artefacts without inventing false precision.
-
Weighting without vanity
Lab: remove metrics that inflate scores without changing decisions.
-
Calibration rituals
Paired scoring, reconciliation scripts, and when to escalate disagreement.
-
Vendor and third-party extensions
Inherited certifications, residual risk, and double-counting traps.
-
Override logs and drift checks
Quarterly hygiene for thresholds that slowly move without anyone noticing.
-
Model memo and stakeholder language
Write the short document that makes the platform usable outside the GRC team.
Instructor
Amira Kline
Amira has led scoring redesigns for mid-market United Kingdom firms across financial services and professional networks. She teaches the weighting and calibration modules and reviews every Scorecraft Lab model memo.
Informational pricing
Scorecraft Lab seat — £1,240
Includes live sessions, materials, memo review, and 12 months of alumni clinic access. No payment is taken on this site; invoices follow a confirmed place.
Reviews from this course
“Module four’s weighting lab was uncomfortable in a useful way — we retired a control family that only existed to make the dashboard look busy.”Priya S., Information Security Manager
“The calibration script alone justified the seat. Our reviewers finally argue about criteria instead of personalities.”Anonymous client in insurance
“Strong on method. The vendor module moves quickly if you have never mapped suppliers before — budget prep time.”Owen · Bristol
FAQ
Do I need an existing platform to enrol?
No. Spreadsheets are fine for the exercises. If you already use a GRC tool, bring sample exports — we will show how criteria transfer, not how to click through one vendor’s UI.
How much live time is required?
Plan for six live sessions of 90 minutes across five weeks, plus asynchronous labs. Recordings are available, but calibration sessions work best live.
What is a real limitation of this course?
We do not teach you how to select or configure a commercial GRC product. Tooling choices, connector setup, and licence negotiations are outside the syllabus. If your main problem is software procurement, this programme will feel incomplete until that work is separate.
Can a whole team join?
Yes — see Assurance Circle on the pricing page for up to six seats with a private calibration using your controls.
Ready for the next cohort?
Tell us your role and what you currently score. We will confirm dates and whether Signal Map foundations should come first.