Executive programme · Online · Self-paced
The first resilience governance certification fully available in Arabic — online, at your own pace.
Fully in Arabic. Also available in English.
A programme for executives who answer for resilience before the board and the regulator. 94 chapters in six modules, six working artefacts and a regulatory layer that runs from NCEMA 7000 to DORA — studied as a structured text course at your own pace, proven through tests and a capstone defended before the examiner.
Contracts increasingly ask for NCEMA-aligned continuity. The programme gives your executives the language and the artefacts that procurement and auditors expect to see.
Head of Risk, governance-risk-compliance (GRC) manager, business continuity (BCM) lead on the way to Chief Risk Officer (CRO): an executive credential about governance — accountability, boards, regulators — that matches the roles you are applying for.
Groups with several business units get one resilience framework across the whole management team, delivered as a cohort on your own cases.
NCEMA 7000 alignment is becoming a condition of access to UAE government work — across logistics, construction, IT services, healthcare, energy, transport and telecom. The requirement lands on organisations; the competence lands on people.
Until now, executive education in resilience has spoken English. ERGP is the first certification of its kind that you can complete entirely in Arabic — at your own pace, from the first chapter to the defended capstone.
If you plan to build a career or win business in the Gulf, this credential answers the questions every employer, client and regulator here asks: do you know the national standards, can you speak to a board about resilience, and can you prove it? You leave with a verifiable certificate, six working documents for your own organisation, and the regulatory fluency that sets senior risk candidates apart across the GCC.
Each module ends with a working document you build for your own organisation. 94 chapters in total — you set the pace.
Risk appetite for disruption, committee architecture, delegated authority, three lines of defence, the Chief Risk Officer (CRO) role.
Artefact: a resilience governance policy and governance map
ISO 31000, the risk register, key risk indicators (KRIs), scenario analysis and stress-testing, linking ERM to continuity — including the use of AI for risk monitoring and an early-warning dashboard (ISO 42001).
Artefact: a resilience risk register with KRIs
Business impact analysis (BIA); recovery targets — maximum acceptable outage (MAO), minimum business continuity objective (MBCO), recovery time and recovery point objectives (RTO / RPO); impact tolerance — the language of the new operational resilience regulators; cost of downtime; the investment case for measures.
Artefact: a completed BIA with defended targets
The crisis team, escalation, communications, decision making under pressure, the exercise programme and its reports.
Artefact: a crisis response plan and an exercise scenario
AE/SCNS/NCEMA 7000 in depth and its mapping to ISO 22301; the global layer — DORA (EU), the Bank of England and FCA operational resilience regime (UK), CBUAE; sector regulators and government-contract expectations.
Artefact: an organisation mapping matrix against NCEMA 7000 and ISO 22301
The resilience dashboard and AI-assisted risk monitoring (ISO 42001), the board report, audit readiness, the maturity model.
Artefact: a dashboard and a board report template

Live screenshots from the actual course — real chapters exactly as participants see them: the authored text, the diagrams and the checkpoint questions.
Click any screenshot to view it full size.
Capstones are examined by the Chief Examiner, Evgeny Telenkov, PhD, together with the invited circle of senior practitioners. Who we are →
No lectures to sit through and no attendance to log. Progress is earned step by step, and every result can be verified.
Every part of a module ends with a block of checkpoint questions — 24 blocks across the programme. Answering them opens the next step.
Each of the six modules ends with a final test: 8 questions, a pass at 6, with questions shuffled on every attempt.
A board-level resilience report on your own organisation, defended live before the examiner.
Entered in the public register with a unique number and QR verification on risk-place.org.
By invitation · Founding expert circle
We are inviting a small circle of leaders with twenty or more years in risk, continuity or crisis management to go through the fully Arabic edition before anyone else — and tell us, frankly, where it can be stronger. Full access, all materials and certification are our gift; your experience is the contribution we ask for. Invitations are few by design.
AE/SCNS/NCEMA 7000:2021 is the UAE national standard for business continuity — mandatory for government entities and critical infrastructure, and increasingly referenced in supplier requirements across the economy.
Its structure is deliberately aligned with ISO 22301: one well-designed system covers both. The differences — terminology, supplier-evaluation duties, recovery during response — are exactly what Module 5 teaches.
Module 5 gives you the ability to read your organisation against both standards at once and to speak with a UAE regulator, client or auditor in their language — the layer this programme was built around.
The same module carries the global layer: DORA in the European Union, the Bank of England and FCA operational resilience regime in the United Kingdom, and CBUAE requirements for banks. One vocabulary — impact tolerance, severe but plausible scenarios — read the same way in Dubai, London and Brussels.
Read our full NCEMA 7000 guide → · What NCEMA 7000 training must cover →
| Standard | Covers | Module |
|---|---|---|
| ISO 22313 | BCMS guidance | M1 |
| ISO 22317 | Business impact analysis | M3 |
| ISO 22331 | Continuity strategy | M3 |
| ISO 22332 | Plans and procedures | M4 |
| ISO 22318 | Supply chain continuity | M2 · M5 |
| ISO 22330 | People aspects | M4 |
| ISO 22316 | Organisational resilience | M1 |
| ISO 22361 | Crisis management | M4 |
| ISO 22320 | Incident management | M4 |
| ISO 22398 | Exercises | M4 |
| ISO/IEC 27031 | ICT readiness | M6 |
| ISO/IEC 27001 | Information security | M6 |
| IEC 31010 | Risk assessment techniques | M2 |
| COSO ERM 2017 | Enterprise risk framework | M2 |
| ISO 37301 | Compliance management | M1 |
| ISO 37000 | Governance of organisations | M1 |
| ISO 42001 | AI management | M2 · M6 |
| EU: DORA | Digital operational resilience (finance) | M5 |
| UK: Bank of England · FCA | Operational resilience regime | M5 |
| UAE: NCEMA 7000 · CBUAE · TDRA IAS · DESC ISR · ADHICS v2 · UAE PDPL | Gulf regulatory layer | M5 |
| KSA: NCA ECC | Saudi cybersecurity controls | M5 |
| Qatar: NCSA NIA | Qatar information assurance | M5 |
This table is the promise of completeness: from board appetite to the auditor's report.
Six module tests with a pass threshold, plus a capstone defended before the examiner. The certificate is earned.
Six working documents leave the programme with you and go straight into your organisation.
Every certificate carries a unique number and a QR resolving to the register on risk-place.org. An employer verifies it in ten seconds.
Renewal through evidence of practice and professional development keeps the credential alive.
The certificate: personalised, numbered, QR-verified. Sample shown.
Enter the number printed on the document, or scan its QR code. Full verification page →
The certificate is the entry. Passing ERGP admits you to the Circle — a private community of certified practitioners, coordinated by the founders, small today and growing with every certificate issued.
Curated by Erzhena Khilko; engagements coordinated by Evgeny Telenkov. More about the Circle →
Chief Risk Officer of American Express Bank and its payment system operator, 2010–2024; chair of the Risk Committee, member of ALCO and the Credit Committee. Built risk governance across 12 business units on the Three Lines of Defence model with zero audit findings; ran ICAAP under Basel III Pillar 2, RCSA across 15+ core processes and the continuity plan with annual test cycles. Earlier: head of risk at Bank of Cyprus Russia, corporate finance at Deloitte, audit at Ernst & Young. She owns the learning design, the cohort schedule and the student experience across all our programmes — and curates the ERGP Circle: the quarterly sessions, the member directory and the invitation of examiners.
Best Risk Manager of the Year 2020 (RusRisk). 15+ years leading risk and continuity functions: Nornickel, where he built business continuity from zero with 20+ plans, Rosneft, Beeline, Ernst & Young. CRO of a $20bn petrochemical megaproject (AGCC, SIBUR) with 200+ construction risk indicators. Author of the programme; he chairs the examination board, signs every certificate issued and matches Circle members to engagements with organisations.
The people who answer for resilience rarely sit in one department: risk, continuity, internal audit, operations, IT. ERGP for teams enrols them on the same programme as a group, so the organisation ends up with one vocabulary and one standard of evidence.
What the sponsor gets: a single view of the group's progress and test results, a cohort schedule agreed with you, capstones built on your own organisation's scenarios where you choose, and an individual, verifiable certificate for each participant. In-house cohorts of up to 12 executives are priced as one engagement — see enrolment below.
Need the site crews covered as well? That is a different programme: SAFE, 32 chapters of workplace safety read on the phone within one shift. Both are listed on the page for organisations.
Per person, in either language. The examination, the certificate and admission to the ERGP Circle are included. Payment by invoice; corporate purchase orders welcome.
See the programme from the inside — the chapters, the questions, the tests and the register. Leave your details and we will email you an invitation.
Yes. All 94 chapters, the checkpoint questions, the module tests and the interface are available in Arabic — the first resilience governance certification for which that is true. The same content is available in English, and you can switch at any time.
It is self-paced, with access that stays open. We measure the programme by completeness — the full cycle from board risk appetite to the auditor's report — and by the six artefacts you build. You choose the pace that fits your calendar.
It is an independent educational credential issued by risk-place, and we say so openly. Its weight comes from the strict requirements of the programme: completing all six modules and passing both the module tests and the capstone defence.
NCEMA assesses organisations against the national standard; recognition of private programmes is outside its role. This programme certifies your personal competence in that landscape — the ability employers and clients actually hire for.
Compliance belongs to organisations and is assessed by authorities. The programme equips you to lead your organisation toward it — the Module 5 mapping matrix is exactly that starting point.
Those are respected practitioner credentials for the people who build continuity systems. This programme certifies the executive layer — governance, board accountability and regulatory navigation — and is built around the GCC regulatory landscape, which is its home ground.
Module tests can be re-taken — the questions are shuffled on every attempt. One capstone re-submission is included; further defence attempts are scheduled at cost. The pass threshold is what makes the certificate worth showing.
The personalised, numbered certificate with QR verification, the six artefacts you built, and continued access to the materials as they are updated.
Yes — the in-house track runs as a cohort on your own cases, and the capstone becomes a real board report for your organisation.
Invoice with a corporate purchase order — standard practice for learning and development budgets.
ERGP — the Executive Certificate in Enterprise Resilience Governance — is an independent educational programme by risk-place. It is not affiliated with, endorsed by or accredited by NCEMA, ISO or any other standardisation or certification body. The certificate confirms completion of the programme and successful assessment; it does not attest any organisation's compliance with any standard.
We read every application and reply personally. We invite leaders with 20+ years of practice.