Building a common risk management language across a national investment holding company and 19 portfolio companies spanning hydropower, banking, aviation, telecommunications, mining, and manufacturing is not a task that a standard, one size fits all training programme can accomplish. This was exactly the challenge Druk Holding and Investments Limited, the commercial investment arm of the Royal Government of Bhutan, brought to RMAI, and the resulting three day Enterprise Risk Management Capability Building Programme, delivered onsite in Thimpu from 22 to 24 July 2026, offers a useful case study in how corporate risk training can be designed for genuinely diverse, cross sector cohorts.
Client Background and the Requirement
DHI professionally manages Bhutan’s government owned companies and oversees a portfolio ecosystem spanning hydropower and energy, banking and financial services, telecommunications, aviation, mining and natural resources, manufacturing, infrastructure development, and trading. Given the national importance of these organisations and the breadth of their risk exposures, DHI needed a consistent, enterprise wide risk management approach that could be understood, adopted, and applied across every portfolio company.
The requirement DHI brought to RMAI went well beyond conceptual awareness training. The programme needed to achieve four outcomes simultaneously, establishing a common enterprise risk language across 19 portfolio companies operating in entirely different industries, equipping designated risk focal points with the practical ability to build and maintain risk registers within their own companies, moving participating organisations from reactive, incident driven risk handling toward proactive identification, assessment, and management, and connecting risk management to strategy, governance, and board level decision making rather than treating it as a compliance exercise.
The central design challenge was heterogeneity. A hydropower engineer, a telecom network manager, a bank compliance officer, and a mining operations lead all needed to leave the room with the same underlying framework while also walking away with something directly usable inside their own organisation.
Programme Design and Delivery
RMAI designed the intervention as a workshop rather than a lecture series, with 45 risk focal points and professionals from DHI and its 19 portfolio companies working in groups on every day of the programme. Group composition was mixed deliberately across sectors, so that a risk identified in one industry could be stress tested against the operating realities of another, with faculty moving between groups to challenge assumptions and facilitate debriefs after each exercise.
A single structured handout was issued to all participants, supported by company specific case inserts mapped to the risk profile of each portfolio organisation and the topic being covered. This gave the cohort a shared reference framework while ensuring every participant worked on material relevant to their own business rather than a generic illustration. Over the three days, participants walked through the complete risk management cycle in practice, risk identification, risk assessment, inherent and residual risk evaluation, control effectiveness testing, advanced risk analysis, and the actual construction of a working risk register for their own organisation.
What the Curriculum Covered
The three day curriculum was structured around four connected modules, moving from foundations through to strategic integration. The first covered Enterprise Risk Management foundations, including the evolution and importance of ERM, the shift from siloed to enterprise wide risk thinking, and the transition from reactive response to proactive risk management. The second covered risk culture and governance, including the role of leadership in shaping risk culture, accountability and ownership of risks, the mandate and positioning of risk focal points, and escalation mechanisms. The third covered risk registers, assessment, and reporting, including building effective risk registers, distinguishing inherent from residual risk, and designing meaningful risk reporting. The fourth covered risk appetite and strategic integration, including aligning risk appetite with strategic objectives, risk maturity assessment, and embedding ERM into organisational planning.
Cross-Sector Learning in Practice
The diversity of the cohort became one of the programme’s strongest features rather than a complication to manage around. Cyber risk was examined across banking operations, telecommunications networks, utilities, and public services. Climate and environmental risk was examined across hydropower generation, infrastructure projects, mining operations, and supply chains. Operational resilience was examined across financial institutions, aviation, manufacturing, and technology driven businesses. Third party dependency was examined as an interconnected exposure running across multiple portfolio companies at once. This gave participants both a shared enterprise risk language across the DHI group and a practical appreciation of how the same framework needs to be calibrated differently in each sector.
Designed for a Mixed-Experience Cohort
The 45 participants ranged from professionals encountering formal ERM for the first time to practitioners with five to eight years of hands on risk experience. Rather than treating this range as a constraint, the programme structured it as an asset, establishing foundational concepts first so no participant was left behind on terminology or framework logic, deliberately mixing experience levels within groups so experienced practitioners raised the standard of group output while newer participants learned through application, and building advanced risk analysis and maturity assessment content in to give experienced participants sufficient depth. Interactive sessions allowed every participant to bring their own organisational problem directly to faculty during the programme itself.
Knowledge Reference Beyond the Classroom
A distinguishing feature of this engagement was the launch, during the programme, of the book Enterprise Risk Management, authored by Dr. Rakesh Agarwal, Secretary General of the Risk Management Association of India. Mr. Ujjwal Deep Dahal, Chief Executive Officer of Druk Holding and Investments Limited, launched the book alongside Dr. Rakesh, and a copy was provided to every participant. The programme curriculum was mapped to the structure of the book, giving participants a permanent reference resource that mirrored what they had been taught and that continued to serve the cohort as a working reference well after the classroom sessions concluded.
Participant Feedback and Programme Outcomes
A structured post programme survey, supported by recorded video testimonials from participants representing banking, hydropower, telecommunications, mining and natural resources, and other portfolio sectors, produced strong results across every evaluation parameter. Faculty experience and domain depth was rated 10 out of 10, the workshop and group exercise experience was rated 9.5 out of 10, overall programme experience was rated 9 out of 10, and concept clarity and programme coverage was rated 8.5 out of 10, giving an overall programme rating of 9.25 out of 10.
Recurring themes from the testimonials included the ability to put organisation specific questions directly to faculty, the value of building a real risk register during the programme rather than reading about one, and the depth of practitioner experience faculty brought into the room. The comparatively lower concept clarity score reflected honest feedback that certain areas, particularly advanced risk analysis and control effectiveness evaluation, were extensive and technical, a gap the programme handouts and the ERM reference book were specifically positioned to help participants work through after the sessions concluded.
Why This Programme Worked
Several design choices, taken together, explain the programme’s outcomes. The workshop format over a lecture format meant participants spent the majority of programme time working rather than listening, producing a usable output each day. Company specific case inserts maintained a shared framework while ensuring every participant worked on material mapped to their own organisation and sector. Practitioner faculty brought operating experience rather than academic instruction and remained accessible for direct, organisation specific questions throughout. Cross sector cohort design meant mixed industry groups produced sharper risk thinking and established a common risk language across the entire portfolio group. And permanent reference material, in the form of the curriculum mapped ERM book issued to every participant, extended the learning well beyond the three days themselves.
Conclusion
The DHI programme demonstrates that a genuinely diverse, multi sector cohort does not need to be a constraint on effective risk training, it can become the programme’s strongest asset when the design deliberately uses that diversity to sharpen thinking across the group. A workshop led, practitioner delivered format that produces a real, usable output each day remains one of the clearest ways to move risk management from a classroom concept to organisational practice.
Build This Capability with RMAI
RMAI delivers customised capability building programmes across Enterprise Risk Management, Operational Risk, Credit Risk, Cyber and Technology Risk, Business Continuity, Fraud Risk Management, Compliance and Governance, and ESG and emerging risks, delivered onsite and virtually, in India and internationally. Organisations can start with RMAI’s Online Certificate Course in Enterprise Risk Management, which covers the same foundations, risk register construction, and risk appetite concepts featured in this programme, or explore the complete suite of risk management courses.