GRC Academy

Build Your GRC Career. Advance Your Expertise.

GRC Academy by GRCNexa offers professional training programs for individuals building or advancing a career in cybersecurity, GRC, risk management and compliance. Designed by practitioners. Delivered for real-world impact.

Intermediate

ISO 27001 Lead Implementer

Master the skills to design, implement and manage an ISO 27001-compliant ISMS. Covers scoping, risk assessment, Annex A controls, documentation and certification preparation.

3 days·Online / Cohort
ISMS scoping and context
Risk assessment methodology
Annex A control selection
Policy and procedure development

+2 more topics

Enquire
Advanced

ISO 27001 Lead Auditor

Develop the skills to plan, conduct and report on ISO 27001 audits. Covers audit principles, audit program management, conducting audits and writing findings.

3 days·Online / Cohort
Audit principles and types
Audit program management
Audit planning and preparation
Conducting audit interviews

+2 more topics

Enquire
Intermediate

SOC 2 Practitioner

Understand the SOC 2 framework, Trust Services Criteria and the audit process. Ideal for GRC professionals, compliance managers and security teams preparing for SOC 2.

2 days·Online / Cohort
SOC 2 framework overview
Trust Services Criteria deep-dive
Control design and mapping
Evidence collection best practices

+2 more topics

Enquire
Intermediate

Third-Party Risk Management (TPRM)

Build the skills to design and operate a TPRM program — from vendor tiering and questionnaire design to ongoing monitoring and risk reporting.

2 days·Online / Cohort
TPRM program design
Vendor risk tiering
Security questionnaire design
Conducting vendor assessments

+2 more topics

Enquire
Intermediate

IT General Controls (ITGC) for Auditors

Understand ITGC domains — access management, change management, operations and backup — and how to assess and audit them effectively.

2 days·Online / Cohort
ITGC domains and control objectives
Access management controls
Change management controls
IT operations and backup controls

+2 more topics

Enquire
Foundation

AI Governance & ISO 42001

Introduction to AI governance, responsible AI principles and the ISO 42001 AI Management System standard. For GRC professionals, compliance teams and technology leaders.

1 day·Online
AI risk landscape
Responsible AI principles
ISO 42001 overview
AI governance framework design

+2 more topics

Enquire
Foundation

Risk Management Fundamentals

A practical introduction to information security risk management — covering risk identification, assessment, treatment and monitoring aligned to ISO 31000 and ISO 27005.

1 day·Online
Risk management concepts
Risk identification techniques
Qualitative and quantitative risk assessment
Risk treatment options

+2 more topics

Enquire

How We Deliver

Live Online

Instructor-led sessions delivered via video — interactive, with Q&A and exercises.

Cohort Programs

Small-group cohorts with peer learning, case studies and collaborative exercises.

Corporate Training

Customized programs delivered to your team — tailored to your industry and context.

Ready to Advance Your GRC Career?

Explore our upcoming cohorts or enquire about corporate training for your team.

Enquire About Courses