BB ACADEMY
Governance, risk, compliance, and internal audit certification programs delivered in partnership with The British University in Egypt.
BB Course Catalogue
Explore our professional learning tracks. Select a course to view its full outline and enrollment options.
A foundational program for Board members, executives, and governance, risk, compliance, and audit professionals who need a working command of how corporate governance actually operates — from principles to practice.
Course Rounds
Who This Course Is For
Built for Board members, senior management, and the governance, risk, compliance, and audit professionals who support them:
- Board Members & Committee Members
- Senior Executives & Business Owners
- Corporate Secretaries & Governance Officers
- Risk Managers & Compliance Officers
- Internal Audit Professionals
- Professionals preparing for governance leadership roles
Course Outline
01 Module 1 — What Is Corporate Governance
- Defining corporate governance and why it exists
- The relationship between ownership, management, and oversight
- Why governance failures happen — and what they cost
02 Module 2 — History of Corporate Governance
- From the Cadbury Report to Sarbanes-Oxley and the OECD Principles
- How major corporate scandals reshaped global governance codes
- The evolution of governance in Egypt and the MENA region
03 Module 3 — The 4 Core Principles
- Accountability, Fairness, Transparency, and Responsibility
- Applying the four principles to real board and management decisions
04 Module 4 — Board of Directors: Roles & Responsibilities
- Board composition, independence, and committee structures
- Fiduciary duties and the boundary between governance and management
- Board evaluation and succession planning basics
05 Module 5 — Company Strategy
- The Board's role in setting and overseeing strategy
- Aligning strategic objectives with risk appetite
- Strategy monitoring and course-correction mechanisms
06 Module 6 — Policies & Procedures
- Designing a policy framework that supports governance objectives
- Delegation of Authority (DOA) as a governance control
- Keeping policies living documents, not shelf-ware
07 Module 7 — Risk Management
- The Board's risk oversight responsibility
- Risk appetite statements and their governance implications
- Connecting enterprise risk management to strategic decision-making
08 Module 8 — Compliance
- The compliance function's place in the governance structure
- Regulatory obligations and the cost of non-compliance
- Board and Audit Committee oversight of compliance
09 Module 9 — Internal Audit
- Internal audit as the Board's independent assurance function
- The Three Lines Model and internal audit's reporting relationship to the Audit Committee
- Case study: Enron — where governance broke down, and why
- Closing assessment and certificate requirements
Learning Outcomes
- Explain the four core principles of corporate governance and apply them to real decisions
- Describe the Board's role and responsibilities in strategy, risk, and oversight
- Understand how risk management, compliance, and internal audit function as governance safeguards
- Recognize the governance failures that lead to corporate scandals — and how to prevent them
- Earn a joint BB Academy × The British University in Egypt certificate of completion
Course investment
EGP 12,000
Places are limited and allocated on a first-come, first-served basis.
A hands-on program built for risk managers, compliance officers, and internal audit professionals who need to design, run, and defend an Enterprise Risk Management framework in real organizational conditions.
Who This Course Is For
Built for professionals who own, support, or interface with the risk management function:
- Risk Managers & Risk Officers
- Compliance Officers & MLROs
- Internal Audit Professionals
- Corporate Secretaries & Governance Officers
- Business Unit & Operations Managers
- Professionals transitioning into Risk Management roles
Course Outline
01 Module 1 — Foundations of Enterprise Risk Management
- What risk is — and how ERM differs from traditional, siloed risk management
- The COSO ERM Framework: components and principles
- Risk appetite, risk tolerance, and risk capacity — defining the boundaries
- Linking risk management to strategy and organizational objectives
02 Module 2 — Risk Governance & The Three Lines Model
- Positioning the risk function within the Three Lines Model
- Roles of the Board, Risk Committee, and management in risk oversight
- Risk Management vs. Compliance vs. Internal Audit: boundaries and handoffs
- Building a risk governance structure and reporting lines
03 Module 3 — Risk Identification & Assessment Methodology
- Risk identification techniques: workshops, interviews, process walkthroughs
- Assessing likelihood and impact — qualitative and quantitative approaches
- Building and reading a risk heat map
- Constructing and maintaining a corporate risk register
04 Module 4 — Risk Response & Treatment Strategies
- The four risk response strategies: avoid, mitigate, transfer, accept
- Designing proportionate control activities for identified risks
- Cost-benefit thinking in risk treatment decisions
05 Module 5 — Risk Monitoring, KRIs & Reporting
- Designing Key Risk Indicators (KRIs) and setting thresholds
- Continuous risk monitoring vs. periodic reassessment
- Reporting risk to the Board, Risk Committee, and Executive Management
- Workshop: building a mini risk register with KRIs for a business process
06 Module 6 — Business Continuity & Operational Risk
- Operational risk fundamentals and common failure points
- Business continuity and disaster recovery planning basics
- Crisis management and incident response coordination
07 Module 7 — Embedding Risk in Decision-Making
- Integrating risk assessment into strategic and investment decisions
- Case study discussion: risk failures and lessons learned
- Closing assessment and certificate requirements
Learning Outcomes
- Design and operate an Enterprise Risk Management framework aligned to COSO ERM
- Build a risk register, heat map, and KRI-based monitoring plan
- Select and defend risk response strategies for real organizational risks
- Position risk management correctly within governance and the Three Lines Model
- Earn a joint BB Academy × The British University in Egypt certificate of completion
Course investment
EGP 10,000
Places are limited and allocated on a first-come, first-served basis.
A practitioner-built program for compliance officers, risk managers, and internal audit professionals who need a working command of regulatory compliance, financial crime controls, and governance integration — not just theory.
Who This Course Is For
Designed specifically for professionals who own or support the compliance function, and for adjacent risk and audit roles that must work closely with it:
- Compliance Officers & MLROs
- Risk Managers & Risk Officers
- Internal Audit Professionals
- Legal & Regulatory Affairs staff
- Corporate Secretaries & Governance Officers
- Professionals transitioning into Compliance roles
Course Outline
01 Module 1 — Foundations of Compliance
- What compliance is — and what it is not
- Positioning the compliance function within the Three Lines Model
- Compliance vs. Risk Management vs. Internal Audit: boundaries and overlaps
- Independence, authority, and reporting lines of the compliance function
02 Module 2 — Regulatory Landscape
- Key Egyptian regulators: CBE, FRA, and sector-specific bodies
- Relevant international frameworks: FATF, ISO 37301, OECD principles
- Reading and interpreting regulatory requirements into internal obligations
- Building and maintaining a compliance obligations register
03 Module 3 — Compliance Risk Assessment & Monitoring
- Compliance risk assessment methodology
- Designing a risk-based compliance monitoring plan
- Key Risk Indicators (KRIs) and early warning signals
- Workshop: building a mini compliance monitoring plan
04 Module 4 — AML/CFT & Financial Crime Compliance
- AML/CFT fundamentals and typologies
- KYC, Customer Due Diligence, and Enhanced Due Diligence
- Sanctions screening and suspicious activity reporting obligations
05 Module 5 — Policies, Procedures & Governance Integration
- Designing effective compliance policies and procedures
- Code of conduct and whistleblowing mechanisms
- Embedding compliance into board and committee governance structures
06 Module 6 — Compliance Breaches, Investigations & Reporting
- Handling and escalating compliance breaches
- Investigation fundamentals: evidence, documentation, confidentiality
- Reporting to the Board and Audit Committee
- Case study discussion drawn from a real compliance breach scenario
07 Module 7 — Ethics & Culture of Compliance
- "Tone from the top" and its practical translation into culture
- Building and sustaining an ethical organizational culture
- Designing compliance training and awareness programs
- Closing assessment and certificate requirements
Learning Outcomes
- Design and run a risk-based compliance monitoring program aligned to regulatory obligations
- Apply AML/CFT, KYC, and sanctions screening requirements in practice
- Handle a compliance breach from detection through Board-level reporting
- Position the compliance function correctly within governance and the Three Lines Model
- Earn a joint BB Academy × The British University in Egypt certificate of completion
Course investment
EGP 10,000
Places are limited and allocated on a first-come, first-served basis.
A rigorous, standards-based program for internal auditors, risk managers, and compliance professionals who need to plan, execute, and report audit engagements to a defensible professional standard.
Who This Course Is For
Built for professionals who deliver, oversee, or rely on the internal audit function:
- Internal Audit Professionals & Managers
- Risk Managers & Risk Officers
- Compliance Officers & MLROs
- Finance & Control professionals moving into audit
- Audit Committee support staff
- Candidates preparing for the CIA certification
Course Outline
01 Domain 1 — Internal Audit FundamentalsModule 1 — Role of Internal Audit & The Three Lines Model
- Mandate and value proposition of internal audit
- Positioning internal audit within the Three Lines Model
02 Domain 1 — Internal Audit FundamentalsModule 2 — Independence, Organizational Positioning & Objectivity
- Functional vs. administrative reporting lines
- Threats to objectivity and safeguards
03 Domain 1 — Internal Audit FundamentalsModule 3 — Governance, Risk, and Control Concepts
- How governance, risk management, and control interrelate
- The internal auditor's assurance role across all three
04 Domain 1 — Internal Audit FundamentalsModule 4 — Engagement Planning Basics
- Building an engagement plan and scope
- Overview of the CIA certification structure
- Case discussion: "Is this internal audit or internal control?"
05 Domain 2 — IIA Standards & EthicsModule 5 — Core Principles & Code of Ethics
- The IIA's Core Principles for the Professional Practice of Internal Auditing
- Applying the Code of Ethics in practice
06 Domain 2 — IIA Standards & EthicsModule 6 — Audit Charter
- Purpose and required content of an audit charter
- Approval and periodic review process
07 Domain 2 — IIA Standards & EthicsModule 7 — Quality Assurance & Improvement Program (QAIP)
- Internal and external quality assessments
- Building continuous improvement into the audit function
08 Domain 3 — Risk-Based AuditingModule 8 — Risk Assessment Methodology
- Building the annual audit plan on a risk-based methodology
- Linking the audit universe to organizational risk
09 Domain 3 — Risk-Based AuditingModule 9 — Risk vs. Control & Control Types
- Preventive, detective, and corrective controls
- Distinguishing inherent risk from residual risk
10 Domain 3 — Risk-Based AuditingModule 10 — Risk & Control Matrix (RCM)
- Structuring an RCM: objectives, risks, controls, and testing procedures
- Using the RCM as the backbone of fieldwork
11 Domain 3 — Risk-Based AuditingModule 11 — Sampling Basics
- Statistical vs. judgmental sampling
- Determining sample size and selection method
12 Domain 3 — Risk-Based AuditingWorkshop — Build a Mini-RCM: Procurement Cycle
- Hands-on construction of a Risk & Control Matrix for a real business cycle
13 Domain 4 — Internal Audit Report WritingModule 12 — Attributes of Observations & Recommendations (5C Model)
- Condition, Criteria, Cause, Consequence, Corrective Action
- Writing observations that withstand management pushback
14 Domain 4 — Internal Audit Report WritingModule 13 — Risk-Based Rating Methodology
- Rating findings and overall engagement results consistently
- Aligning ratings with the organization's risk appetite
15 Domain 4 — Internal Audit Report WritingModule 14 — Quality of Communications (Perf. Standard 2420)
- Accurate, objective, clear, concise, constructive, complete, and timely reporting
- Communicating findings to management and the Audit Committee
16 Domain 5 — Fieldwork Execution & Quality AssuranceModule 15 — Testing Techniques & Evidence Gathering
- Inquiry, observation, inspection, and re-performance
- Gathering sufficient, reliable, and relevant audit evidence
17 Domain 5 — Fieldwork Execution & Quality AssuranceModule 16 — Working Papers & Documentation Standards
- Documentation requirements that support conclusions
- Review and sign-off protocols
18 Domain 5 — Fieldwork Execution & Quality AssuranceModule 17 — Follow-Up & Closing Assessment
- Tracking management action plans to closure
- Closing assessment and certificate requirements
Learning Outcomes
- Plan and execute a risk-based internal audit engagement end to end
- Build a Risk & Control Matrix and apply appropriate testing and sampling techniques
- Write audit observations using the 5C Model and a defensible risk-based rating
- Apply IIA Standards, the Code of Ethics, and QAIP principles in practice
- Earn a joint BB Academy × The British University in Egypt certificate of completion
Course investment
EGP 12,000
Places are limited and allocated on a first-come, first-served basis.
A 12-week, cohort-based executive education program for sitting and next-generation Chief Audit Executives, aligned with the IIA Global Internal Audit Standards (2024) — assessed through applied work on the participant's own organization, not attendance alone.
Who This Course Is For
Admission requires a minimum of 10 years' audit, risk, or finance experience, including 3 years in a supervisory role. Employer nomination is encouraged.
- Sitting Chief Audit Executives (CAEs)
- Heads of Internal Audit
- Deputy CAEs
- Internal Audit Directors
- Senior Audit Managers
- CAE-succession candidates
Course Outline
01 Month 1 — Positioning & Governing the Internal Audit FunctionWeek 1 — Understanding the Business: Governance, Risk & Control Landscape
- Reading the organization's governance, risk, and control landscape as a leader, not just an auditor
- Framework briefing, Egyptian practice segment, and applied group work
02 Month 1 — Positioning & Governing the Internal Audit FunctionWeek 2 — The Mandate: Internal Audit Mandate & Charter
- Negotiating mandate, charter, and reporting lines under GIAS Domain III
- Aligning the charter with board and audit committee expectations
03 Month 1 — Positioning & Governing the Internal Audit FunctionWeek 3 — Building the Internal Audit Strategy
- Designing a forward-looking audit strategy reflecting industry, structure, and culture
- Aligning strategy with the organization's risk management maturity and team capability
04 Month 1 — Positioning & Governing the Internal Audit FunctionWeek 4 — Building the Risk-Based Internal Audit (RBIA) Plan
- Constructing a risk-based audit plan tied directly to the audit universe
- Prioritization logic for a defensible annual plan
05 Month 2 — Leading People & Managing the FunctionWeek 5 — Ethics, Professionalism & the Leader's Credibility
- Independence and objectivity as leadership disciplines, not compliance checkboxes
- Identifying and managing independence threats across the function
06 Month 2 — Leading People & Managing the FunctionWeek 6 — Leading the Audit Team: Competencies, Culture and Leadership Traits
- Building the collective competencies required by Standard 3.1
- Recognizing and correcting toxic leadership behaviors
07 Month 2 — Leading People & Managing the FunctionWeek 7 — Financial, Human & Technological Resources (incl. AI & Analytics)
- Budgeting and resourcing the audit function for growth
- Making the business case for AI and data analytics adoption in audit
08 Month 2 — Leading People & Managing the FunctionWeek 8 — Stakeholder Relationships & Communication
- Building trust-based relationships with boards, regulators, and other assurance providers (GIAS Principle 11)
- Designing recurring communication routines that build credibility over time
09 Month 3 — Assurance Impact & the BoardroomWeek 9 — Coordination, Reliance & Fraud Risk Ownership
- Coordinating with other assurance providers and managing reliance
- Clarifying internal audit's ownership of fraud risk oversight
10 Month 3 — Assurance Impact & the BoardroomWeek 10 — Quality Assurance & Improvement Programme (QAIP) and Performance Measurement
- Evaluating and strengthening the function's QAIP (Standards 8.3–8.4, 12.1–12.2)
- Setting performance objectives and measures that matter to the board
11 Month 3 — Assurance Impact & the BoardroomWeek 11 — Reporting to the Board Audit Committee
- Producing boardroom-grade reporting that influences governance decisions
- Structuring annual and quarterly reports for maximum impact
12 Month 3 — Assurance Impact & the BoardroomWeek 12 — Capstone: The CAE Simulation Before a Mock Audit Committee
- Live simulation presenting as CAE before a mock Audit Committee
- Assessed on boardroom communication, insight, and leadership presence
Assessment & Certification
The program is assessed, not attendance-only. Certification requires attendance at a minimum of 10 of 12 sessions and an overall pass across the following components:
Participants completing all requirements receive The British University in Egypt Executive Education Certificate, with 40 CPE hours — including 3 CPEs on Ethics — documented for participants maintaining professional designations.
| Component | Weight | Assessed Against |
|---|---|---|
| Attendance (min. 10 of 12 sessions) | 50% | Attendance logs |
| Participation | 10% | Engagement rubric |
| Capstone Project: Audit Committee report & live mock-AUCOM defense | 50% | Boardroom communication; insight; leadership presence |
Learning Outcomes
- Position the internal audit function strategically by negotiating the mandate, charter, reporting lines, and board relationships required under GIAS Domain III
- Design a forward-looking internal audit strategy and risk-based plan matched to the organization's risk maturity and team capability
- Lead, develop, and retain a high-performing audit team, correcting toxic leadership behaviors and building the competencies required by Standard 3.1
- Build trust-based relationships and communication routines with boards, audit committees, senior management, regulators, and other assurance providers
- Evaluate and strengthen the function's QAIP, performance objectives, and measures
- Provide leadership oversight of fraud risk assessment and emerging risks, including AI and data analytics
- Produce and defend boardroom-grade audit committee reporting that influences governance decisions
Course investment
EGP 50,000
Cohort size is limited to preserve peer-learning quality. Employer nomination is encouraged.