ISFB Certificate in Internal Control and Risk Management

Category
Law, Risk and Compliance
Support and Transversal Functions
Level
Maîtrise
Format
Presential
Duration
7 non-consecutive days
Language
French
Location
ISFB Geneva premises
Director
Gilles Chantrier
Manager
Oscar Marano
Type
ISFB Certificates
Description
Prices & Admission
Content
Testimonials
Stakeholders

Context

This continuing education course aims to provide an in-depth understanding of internal control and risk management in the financial sector, particularly in Switzerland. Based on industry best practices and Swiss regulations, it addresses the main risks encountered in modern finance. Participants will develop skills to assess and mitigate risks, align management practices with regulatory requirements, and develop business continuity strategies. The program incorporates real-life case studies to promote practical application of concepts and strengthen organizational resilience in the face of today's challenges.

Key objectives

At the end of the course, participants will be able to:
1. Formulate recommendations for risk management strategies in a given institution
2. Design a risk management plan integrating the different types of risk and internal control mechanisms
3. Compare risk management strategies used by different financial institutions
4. Use internal control principles to evaluate existing processes within an organization
5. Explain the implications of strategic, market, credit, liquidity, operational, human and fraud risks on banking activities
6. Identify the main types of financial risk and the applicable regulatory standards.

Target audience

- Risk management and internal control specialists
- Auditors
- Banking and finance executives with an interest in risk management and internal control

Stakeholders

ISFB lecturers have been working in the banking and financial world, or in their respective fields, for many years and are recognized as some of the best experts in our ecosystem in French-speaking Switzerland.

Reviews

The validation of the certificate is done through a written exam of the QCS type (simple choice questionnaire, one and only one correct answer) of 120 minutes. The emphasis is on understanding, application and the ability to analyze and solve concrete cases using the tools and methods seen in training. Candidates are allowed to consult course materials, appendices and personal notes (open-ended exam concept)

Practical information

Participants who pass the final exam will be awarded the ISFB Internal Control and Risk Management Certificate.
ISFB Certificates are recognized and particularly appreciated by our institutional members.


Partnership

Program offered in partnership with Swiss Risk Association.
Sphere

Price

  • Public: CHF 5,670
  • Member: CHF 4,250
  • HG / OCAS / OCE : CHF 2'835.-
  • FFPC : CHF 0.-
CIGR1

Regulatory framework for risk management

Content: This module enables participants to understand FINMA's fundamental requirements in terms of corporate governance, risk management and internal control, as defined in particular in Circular 2017/1. It highlights the principles of accountability, transparency and oversight that must guide the governing bodies of financial institutions, while integrating control mechanisms tailored to their risk profile.
Participants will learn to identify and articulate the main FINMA circulars applicable to risk management, in particular those relating to operational risks and resilience, such as circular 2023/1. The latter introduces reinforced requirements in terms of business continuity, critical data management and cyber risks, in line with the international standards of the Basel Committee
Finally, the module places risk management in a broader perspective of banking resilience, in line with current prudential requirements. It provides an integrated reading of the regulatory framework, enabling professionals to better anticipate vulnerabilities and reinforce the robustness of their organization.
Duration: 4h00
Format: In-person
Possible speakers: CHANTRIER Gilles
CIGR2

Strategic risk management

Content: This module enables participants to analyze the risks associated with a financial institution's strategic choices - such as business model, market orientation or M&A operations - within the framework of the governance requirements defined by FINMA. It highlights the importance of proactive and structured governance, capable of anticipating the impact of strategic decisions on the organization's stability and compliance.
Participants will learn how to identify and integrate strategic steering tools into an overall risk management system, in line with FINMA circulars 2017/1 and 2023/1. These texts provide a framework for corporate governance, internal control and operational resilience, emphasizing the coherence between strategy, risk tolerance and business continuity.
Finally, the module explores the links between strategy, long-term resilience and adaptability in an uncertain environment, drawing on the prudential principles and international standards of the Basel Committee. It thus offers an integrated reading of strategic governance issues in a demanding regulatory framework.
Duration: 4h00
Format: In-person
Possible speakers: GOETSCHIN Blaise
CIGR3

Market risk management

Content: This module enables participants to identify the main market risks - in particular interest rate, currency and equity risks - and to understand FINMA's requirements for measuring, monitoring and limiting these risks. It is based in particular on FINMA circular 2008/20, which defines capital standards and calculation methods for trading portfolios.
Participants will learn how to integrate these risks into the ICAAP (Internal Capital Adequacy Assessment Process), in line with the principles defined by the ECB and the standards of the Basel Committee. ICAAP plays a central role in risk management strategy, ensuring a forward-looking and consistent assessment of vulnerabilities and capital requirements.
Finally, the module explores best practices in market risk control and regulatory reporting expectations, to ensure effective governance and enhanced transparency in a constantly evolving financial environment.
Duration: 4h00
Format: In-person
Possible contributors: DESPONDS Jérôme
CIGR4

Credit risk management

Content: This module enables participants to understand the fundamental principles of credit risk management in line with FINMA requirements. It covers the key stages of the process: granting, monitoring, provisioning, as well as assessing counterparty quality, defining credit limits and handling bad debts.
The module also explores the integration of credit risk into an overall resilience framework, in line with the Basel Committee's recommendations on expected loss accounting and prudential practices.
Participants will learn how to articulate regulatory requirements with risk management tools, in order to reinforce their organization's financial strength and ability to adapt in an uncertain environment.
Duration: 4h00
Format: In-person
Possible speakers: KIRCHHOFF François
CIGR5

Operational risk management

Content: This module enables participants to identify the main types of fraud, whether internal (abuse of office, misappropriation of assets) or external (cyberfraud, identity theft), and to understand the prevention mechanisms expected by governance standards, particularly those defined by FINMA. It highlights internal control systems as essential levers for detecting red flags, limiting risks and guaranteeing compliant operations.
Participants will learn how to analyze fraud scenarios, implement reporting policies and integrate these elements into an overall compliance and risk management approach. The module emphasizes the importance of a coherent framework combining training, awareness, operational control and ethical governance, in order to strengthen organizational resilience in the face of fraudulent threats. 
Duration: 8h00
Format: In-person
Possible speakers: CHANTRIER Gilles
CIGR6

Operational risk management - Cyber risk

Content: This module enables participants to understand FINMA's requirements in terms of IT security and cyber resilience, as defined in Circular 2023/1. This introduces a strengthened framework for managing risks related to information and communication technologies (ICT), with an emphasis on prevention, detection and response to cyber-attacks.
Participants will learn how to implement concrete measures to protect critical functions, ensure business continuity and respond to serious incidents in a structured way. The module also covers FINMA reporting obligations and expectations in terms of documentation and governance.
Finally, particular attention is paid to assessing the maturity of the cyber system, in relation to prudential requirements and international standards. Participants will be able to situate their organization within a logic of operational resilience, capable of coping with severe but plausible disruptions.
Duration: 8h00
Format: In-person
Possible speakers: FONTIGNIE Jacques
CIGR7

Liquidity risk management

Content: This module enables participants to master Swiss regulatory requirements for liquidity management, in particular the Liquidity Coverage Ratio (LCR), as defined in FINMA circular 2015/2 . It covers the principles of measuring, monitoring and limiting liquidity risks, in relation to liquid asset holding obligations and steering mechanisms tailored to each institution.
Participants will learn how to integrate liquidity stress tests into their management framework, based on FINMA practices and Basel Committee standards. These exercises help to assess the organization's ability to cope with severe crisis scenarios, and to document responses in robust, operational contingency plans.
Finally, the module highlights the links between liquidity management, long-term funding plans and the structural resilience of financial institutions. It offers a strategic reading of prudential requirements, integrating the dimensions of governance, planning and adaptation to an uncertain environment.
Duration: 4h00
Format: In-person
Possible speakers: SOLANET Georgiana
CIGR8

Operational risk management - Compliance

Content: This module enables participants to understand FINMA's expectations in terms of regulatory compliance and their integration into the overall internal control system. The compliance function is an essential component of the second line of defense, alongside the internal control system (ICS), aimed at guaranteeing rule-compliant operations and anticipating risky situations.
Participants will learn to identify the risks of non-compliance - whether legal, financial or reputational - and to mobilize the appropriate prevention tools, such as internal policies, operational controls and reporting mechanisms. The module also highlights the strategic role of the compliance function in detecting and dealing with operational incidents, in line with prudential requirements and international standards.
By promoting a proactive and integrated approach, this module helps to strengthen the compliance culture within financial organizations, while ensuring their resilience in the face of a constantly changing regulatory environment.
Duration: 4h00
Format: In-person
Possible contributors: BAYAT Nezam Alexandre
CIGR9

Ethics

Content: This module explores the close links between corporate culture, ethical behavior and risk management in the financial sector. It highlights FINMA's governance expectations, as set out in Circular 2017/1, which emphasizes the importance of a corporate culture based on integrity, accountability and transparency.
Participants will learn to identify the typical ethical dilemmas encountered in banking - conflicts of interest, commercial trade-offs, internal pressures - and assess their potential impact on the organization's reputation, compliance and resilience. The module emphasizes the need to integrate ethics into decision-making processes, internal policies and control systems, in order to reinforce consistency between stated values and actual practices.
By fostering a living, shared ethical culture, this module contributes to building sustainable governance, capable of coping with uncertainties and preserving stakeholder confidence in a demanding regulatory environment.
Duration: 4h00
Format: In-person
Possible contributors: PENNONE Grégoire
CIGR10

Internal control system

Content: This module enables participants to understand the essential components of an ICS that complies with FINMA requirements, as defined in Circular 2017/1. It addresses the principles of separation of functions, rigorous documentation and structured reporting, which guarantee transparency and risk control within financial institutions.
The module is based on the three lines of defense model, widely recognized in the banking sector. It enables the effectiveness of key controls to be assessed: the first line is ensured by operational staff, the second by control functions (risk, compliance), and the third by internal audit, the guarantor of the independence and quality of the system.
Finally, particular attention is paid to the role of the Board of Directors, which assumes ultimate responsibility for overseeing the ICS. It ensures that the system is adequate, appoints the internal auditors and makes sure that control mechanisms are adapted to the company's risk profile and strategy.
Duration: 4h00
Format: In-person
Possible speakers: ZANOTA Xavier-Yves
CIGR11

Business continuity management

Content: This module enables participants to understand FINMA's expectations in terms of business continuity, as defined in circular 2023/1 on risks and operational resilience. It covers the fundamental principles of Business Continuity Management (BCM), including the identification of critical functions, impact analysis, the definition of severe but plausible scenarios, and the implementation of appropriate recovery procedures.
Participants will learn how to design an operational crisis management plan, integrating process dependencies, key resources and disruption tolerances. The module emphasizes the importance of regularly testing the BCP, keeping it up to date and documenting it, with a view to systemic resilience, in line with the Basel Committee's international standards.
This module is aimed at professionals involved in governance, risk management, information systems security and business continuity, in a constantly evolving regulatory context.
Duration: 8h00
Format: In-person
Possible speakers: SANCHEZ José
CIGR

Review

Content: The aim of the final exam is to validate the skills acquired during the course, by consolidating the practical and theoretical knowledge developed throughout the program. It enables participants to demonstrate their mastery of the concepts covered, their ability to articulate the various contributions of the course within a professional logic, and to identify the evolution of their personal skills.

The test takes the form of a 40-question MCQ, in open book format: participants can consult their course materials, appendices and personal notes. The exam lasts 120 minutes, i.e. 3 minutes per question. Each question has only one correct answer, and no negative marks are awarded for incorrect answers.

The questions are general, with no traps, and are based exclusively on content clearly covered in the course or in the training materials.
Duration: 2h00
Format: In-person
Training for a cross-disciplinary view of risk: interview with Jérôme Desponds, lecturer on the new ISFB Internal Control and Risk Management certificate.

Training for a cross-disciplinary view of risk: interview with Jérôme Desponds, lecturer on the new ISFB Internal Control and Risk Management certificate.

Jérôme Desponds - Managing Partner (ad fidem sàrl)

"With a 360° view of the world of risk, the certificate gives participants the opportunity to think across the board and break down silos in order to assess practices, regardless of the type of risk involved."


Read the interview

Interview with Xavier-Yves Zanota - Internal control and risk management: from theory to practice

Interview with Xavier-Yves Zanota - Internal control and risk management: from theory to practice

Xavier-Yves Zanota - Global Head of Operational Risk (EFG Bank)

"To succeed in this field, you need to combine technical rigor, adaptability, and the ability to communicate with all stakeholders, from the board of directors to the operational teams."


Read the interview

Internal control and risk management: ISFB and Swiss Risk Association combine their expertise

Internal control and risk management: ISFB and Swiss Risk Association combine their expertise

Mathias Baitan - General Manager (ISFB) & Jean-Pierre Colombara - Manager of the Suisse romande Chapter (SRA)

"The idea is always the same: to partner with the best players in each field in French-speaking Switzerland in order to offer our members skills development programs that combine excellence, practical relevance, and sector influence."


Read the interview

Banking Risk Management: Vision, Issues and Transmission with Gilles Chantrier

Banking Risk Management: Vision, Issues and Transmission with Gilles Chantrier

Gilles Chantrier - Chief Risk Officer (Swissquote)

"This training aims to equip participants with the knowledge and skills necessary to navigate effectively in an ever-changing risk environment, while ensuring the compliance and resilience of their organization."


Read the interview

Gilles CHANTRIER

Gilles CHANTRIER

Gilles Chantrier est un professionnel de la finance spécialisé dans la gestion des risques et le contrôle financier. Il est diplômé en économie de la HEG de Lausanne et a suivi une formation en gestion des risques bancaires à l’INSEAD. Il travaille chez Swissquote depuis le début des années 2000, où il a occupé plusieurs postes de direction dans la comptabilité, le contrôle interne, le reporting et la gestion des risques. Depuis 2017, il est Chief Risk Officer du groupe Swissquote. En parallèle, il est membre de plusieurs conseils d’administration au sein des entités du groupe Swissquote en Europe, au Royaume-Uni, au Moyen-Orient et en Asie.
Blaise GOETSCHIN

Blaise GOETSCHIN

Blaise Goetschin a mené une carrière de chef d’entreprises dans le secteur bancaire, industriel et l’administration publique, et il est actuellement administrateur de sociétés dans la finance et la technologie.
Jérôme DESPONDS

Jérôme DESPONDS

Jérôme Desponds est consultant en gouvernance, gestion des risques et gestion de projet. Il dispose de plus de 28 ans d’expérience dans le domaine bancaire. Titulaire d’un master en droit et expert-comptable diplômé, il a débuté dans le domaine de l’audit où il a servi des clients en Suisse romande et au Tessin chez Arthur Andersen et EY. Après 15 ans, au bénéfice également d’une expérience auprès de la Commission fédérale des banques et en tant que compliance officer auprès de la BCV, il a rejoint Mirabaud en tant que responsable risque et compliance pour le groupe. En charge également des domaines crédits, fichier central, fiscalité et sécurité informatique, il a, durant 9 ans, conduit plusieurs projets de transformation organisationnelle et opérationnelle. Après deux ans et demi chez KPMG en charge des services de conseil en gestion des risques pour les banques, Jérôme Desponds poursuit ses activités de conseil pour son compte.
François KIRCHHOFF

François KIRCHHOFF

Titulaire d’une licence en droit de l’Université de Genève et diplômé de la Swiss Banking School, François Kirchhoff débute sa carrière bancaire en 1989 à la Société de Banque Suisse, avant de rejoindre la Banque Cantonale de Genève en 1994. Après avoir développé les relations avec la clientèle commerciale genevoise, il dirige plusieurs départements spécialisés dans le financement des entreprises, des PME, des indépendants et de la clientèle privée, ainsi que dans le pilotage de réseaux de vente. Depuis octobre 2020, il est responsable du département Expertise et risques de crédit, avec pour missions principales : le contrôle interne des activités de crédit l’optimisation continue des processus et réglementations la participation aux comités de décision la validation des provisions de financement Parallèlement, il intervient comme formateur dans des certifications en financements commerciaux et hypothécaires. Nommé Directeur en juillet 2001, il place la formation et l’épanouissement professionnel de ses collaborateurs au cœur de ses priorités managériales.
Jacques FONTIGNIE

Jacques FONTIGNIE

Jacques Fontignie est un professionnel de la cybersécurité disposant d’une solide expérience dans la définition et la mise en œuvre de stratégies de sécurité de l’information au sein d’environnements IT complexes et fortement réglementés. Son expertise couvre la gestion des risques, l’architecture de sécurité ainsi que la conformité aux principaux cadres et réglementations tels que NIST, GDPR, DORA et la FINMA.
Georgiana SOLANET

Georgiana SOLANET

Georgiana Solanet est Directeur Financier de Crédit Agricole next bank, entité du Groupe Crédit Agricole.
Elle dispose de 20 années d’expérience dans le domaine financier et de gestion des risques financiers auprès des banques en Suisse (Banque Cantonale de Genève, Lloyds Bank TSB, Banque Lombard Odier & Cie) ainsi qu’auprès du cabinet Ernst & Young.
Elle est titulaire d’un Doctorat en Mathématiques appliquées (Paris VI), du Master in Banking and Finance (HEC Lausanne) ainsi que des certifications FRM (Financial Risk Manager, GARP) et CFA (CFA Institute).
Nezam Alexandre BAYAT

Nezam Alexandre BAYAT

Après des études de droit aux Universités de Fribourg et Durham (UK), Nezam Alexandre Bayat a obtenu le brevet d'avocat. Depuis 2012 il exerce au sein de la FINMA. Il est depuis 2025 Co-Head du groupe en charge des procédures d’enforcement, en particulier celles concernant la Suisse romande et le Tessin. Compte tenu de ses responsabilités et de son expérience, il a été un témoin privilégié de l'évolution des marchés financiers, des risques auxquels sont confrontés les banques et autres établissements assujettis à la FINMA, de l'évolution du cadre légal et prudentiel. Nezam Alexandre Bayat a également développé une expertise en matière de gouvernance d'entreprise, gestion des risques et conformité. Il est en outre diplômé de la Swiss Board School, de l'Université de Cambridge en matière de finance durable et dispose d'une licence de trader de la SIX.

Grégoire PENNONE

Grégoire PENNONE

Grégoire Pennone est notamment au bénéfice d’un Master en droit et d’un MBA de l’Université de Genève. Il a travaillé près de 14 ans dans le secteur bancaire mais également en fiduciaire, dans le conseil et le secteur de la santé. Il a occupé diverses fonctions de direction et s’est notamment intéressé aux questions de la gouvernance d’entreprise, des questions réglementaires et d’éthique. Il a notamment occupé la position de CEO de ONE swiss bank SA, laquelle était un temps cotée à la bourse suisse et a fusionné avec la banque privée Gonet & Cie SA en juin 2025. Depuis, il exerce des fonctions d’administrateur indépendant et de conseil pour des entreprise dans le secteur financier.
Xavier-Yves ZANOTA

Xavier-Yves ZANOTA

Xavier Yves Zanota est un dirigeant senior spécialisé en gestion des risques. Basé à Zurich, il est Managing Director et Global Head of Operational Risk chez EFG Bank AG depuis 2019, où il a piloté la transformation mondiale de la fonction. Auparavant, il conseillait la direction générale d’UBS sur les questions prudentielles et réglementaires. Il a passé plus de dix ans à la Banque des Règlements Internationaux, notamment au sein du Comité de Bâle sur le contrôle bancaire, contribuant aux grandes réformes post-crise et aux standards internationaux de gouvernance et de supervision. Il a débuté sa carrière chez Ernst & Young après une expérience à la Fédération Française des Sociétés d’Assurances. Engagé dans la profession, il copréside depuis 2025 le chapitre Risques non financiers de la Swiss Risk Association et a enseigné à l’Université de Strasbourg. Auteur et conférencier reconnu, ses travaux portent sur la supervision bancaire, la gouvernance des risques et le risque opérationnel.
José SANCHEZ

José SANCHEZ

Professionnel de la sécurité physique et logique, responsable de département avec plus de 20 ans d’expérience dans la gouvernance de la sécurité en environnement institutionnel international. Il définit et déploie la stratégie de sécurité au travers de plans d’actions structurés, pilote l’analyse des risques et met en œuvre des solutions adaptées pour en assurer la maîtrise. Son expertise en cybersécurité, protection des données et sécurité physique lui permet d’accompagner l’entreprise dans la conformité réglementaire et les enjeux de continuité d’activité et de résilience (2023/1, DORA).

Information

A question about this service? Our manager is at your disposal
Oscar Marano
Oscar Marano
Product Manager
Category
Law, Risk and Compliance
Support and Transversal Functions
Level
Maîtrise
Format
Presential
Duration
7 non-consecutive days
Language
French
Location
ISFB Geneva premises
Director
Gilles Chantrier
Manager
Oscar Marano
Type
ISFB Certificates

Information

A question about this service? Our manager is at your disposal
Oscar Marano
Oscar Marano
Product Manager
Registration
Spring 2026
Sold out soon