Design the control. Gather the evidence. Pass the audit.
Master the ETRM control environment: preventive, detective and corrective controls across trade capture, confirmation, valuation, scheduling and settlement; segregation of duties and access governance; stale prices and data quality; operational risk, issues and remediation; and the evidence an internal or external auditor will actually accept.
Trade controls · SoD & access · Stale prices · Confirmations · Settlement · Operational risk · Audit evidence
Cumulative, not modular
Chapter 130 should be impossible to complete properly without the artefacts built in the chapters before it. The programme follows one continuous fictional firm, NorthStar Energy Trading, so relationships between trades, positions, agreements, exposures and decisions accumulate rather than reset.
The learning chain
The technical build
NorthStar Energy Trading is a fictional firm created for teaching. It does not describe any real company, person or investigation.
12 modules · 130 chapters
M0 ETRM Controls & Operational Risk Primer Ch 1–8 · 8 chapters
Establish the control mental model
- What an ETRM Control Framework Actually Does
- Trade Lifecycle → Risk → Control
- Preventive, Detective and Corrective Controls
- Manual, Automated and IT-Dependent Manual Controls
- Control Objective vs Control Activity
- Control Design vs Operating Effectiveness
- Evidence and Reperformance
- NorthStar ETRM Control Operating Model
M1 Operational Risk & RCSA Ch 9–20 · 12 chapters
Build the risk taxonomy before designing controls
- What Operational Risk Means in ETRM
- Risk Event Taxonomy
- Inherent Risk
- Impact Assessment
- Likelihood Assessment
- Risk and Control Self-Assessment
- Residual Risk
- Key Risk Indicators
- Risk Appetite and Tolerance
- Operational Loss Events
- Scenario Analysis
- NorthStar ETRM RCSA
M2 Trade Capture & Booking Controls Ch 21–34 · 14 chapters
Control what enters the ETRM
- Trade Capture Risk
- Front-to-ETRM Trade Completeness
- Mandatory Field Controls
- Product Eligibility
- Counterparty Eligibility
- Book and Portfolio Controls
- Price Tolerance Controls
- Quantity and Notional Controls
- Backdated Trade Controls
- Late Booking Controls
- Amendment Controls
- Cancellation and Rebooking
- Trader vs Operations Approval
- NorthStar Trade Control Engine
M3 Segregation of Duties & Access Controls Ch 35–48 · 14 chapters
Control who can do what
- Why Segregation of Duties Matters
- Role-Based Access Control
- Least Privilege
- Joiner Controls
- Mover Controls
- Leaver Controls
- Periodic Access Recertification
- Privileged Access
- Emergency Access
- Service Accounts
- SoD Conflict Detection
- Access Override Monitoring
- Access Evidence
- NorthStar Identity & SoD Control Engine
M4 Market Data, Curves & Valuation Controls Ch 49–62 · 14 chapters
Prevent a good trade population from being valued badly
- Market Data Control Risk
- Source Authorization
- Market Data Completeness
- Stale Price Detection
- Price Outlier Detection
- Curve Construction Controls
- Curve Version Control
- Manual Price Overrides
- Independent Price Verification Control
- Valuation Model Controls
- Sensitivity Reasonableness
- Market Data Reconciliation
- Valuation Exception Governance
- NorthStar Market Data Control Framework
M5 Confirmations & Contract Controls Ch 63–74 · 12 chapters
Prove both counterparties agree on the trade
- Confirmation Control Objective
- Confirmation Population
- Confirmation Generation
- Confirmation Dispatch
- Counterparty Matching
- Confirmation Breaks
- Unconfirmed Trade Ageing
- Amendments After Confirmation
- Disputed Trades
- Electronic Confirmation Interfaces
- Confirmation Evidence
- NorthStar Confirmation Control Engine
M6 Settlements, Payments & Cash Controls Ch 75–88 · 14 chapters
Stop errors from becoming actual cash loss
- Settlement Risk in ETRM
- Settlement Population
- Final Price and Fixing Controls
- Invoice Calculation Controls
- Settlement Instructions
- Settlement Instruction Changes
- Payment Maker/Checker
- Duplicate Payment Controls
- Settlement Limits
- Cash Reconciliation
- Failed Settlements
- Payment Fraud Scenarios
- Settlement Evidence
- NorthStar Settlement Control Engine
M7 Interfaces, Batch Processing & Data Integrity Ch 89–100 · 12 chapters
Control what happens between systems
- Interface Risk
- Source-to-Target Reconciliation
- Duplicate Message Controls
- Missing Message Controls
- Schema and Mapping Controls
- Batch Scheduling Controls
- Batch Failure Detection
- Restart and Recovery
- End-of-Day Control
- Reference Data Integrity
- Data Lineage Evidence
- NorthStar Interface Control Framework
M8 Change, Incident & Operational Resilience Ch 101–112 · 12 chapters
Control the platform when technology changes or fails
- Change Risk
- Change Classification
- Requirements and Impact Assessment
- Testing Controls
- Production Deployment
- Emergency Changes
- Incident Detection
- Incident Severity
- Business Continuity
- Disaster Recovery
- Third-Party & Cloud Dependency
- NorthStar Operational Resilience Framework
M9 Control Testing, Audit & Assurance Ch 113–122 · 10 chapters
Prove the framework actually works
- Three Lines Applied to ETRM
- Control Design Assessment
- Control Population
- Sampling
- Reperformance
- Automated Control Testing
- IT-Dependent Manual Control Testing
- Audit Trail and Evidence Quality
- Audit Findings
- NorthStar ETRM Audit Program
M10 Issues, Root Cause & Remediation Ch 123–126 · 4 chapters
Fix the underlying weakness rather than close the ticket
- Issue Management
- Root Cause Analysis
- Remediation Design
- Closure Validation
M11 NorthStar Control Failure Capstone Ch 127–130 · 4 chapters
Reconstruct a failure that passed through multiple “effective” controls
- The €27M Control Incident
- Reconstruct the Failure Chain
- Determine Root Cause & Residual Risk
- Audit Committee & Operational Risk Defence
Three ways to take ETRM Controls, Audit & Operational Risk
| Feature | Self-paced | Cohort | Enterprise |
|---|---|---|---|
| Format | Written chapters, video explainers and podcasts | Everything in self-paced, plus scheduled live sessions | Everything in cohort, delivered privately to your team |
| Live sessions | None | Scheduled, instructor-led | Scheduled, instructor-led, private |
| Mentorship | Not offered | Not offered | Not offered |
| Access | Lifetime | Lifetime | Lifetime for every enrolled seat |
| Pace | Entirely your own | Guided schedule with a peer group | Agreed with your desk |
| Tailoring | Fixed curriculum | Fixed curriculum | Sequenced to your markets, systems and governance |
| Best for | Individuals learning around a job | Individuals who want structure and deadlines | Desks building the same capability together |
Get the programme guide
The full chapter list, what each module covers, and how the tiers compare - sent to your inbox as a PDF.
Run this for my desk
Private delivery for your desk, sequenced to your markets and systems. Tell us the team and we will scope it.
Run this for my deskBring this to your team
Download the full curriculum, or talk to us about running it for a desk or a control function.