LONDON BOROUGH OF ENFIELD RISK MANAGEMENT STRATEGY

Size: px
Start display at page:

Download "LONDON BOROUGH OF ENFIELD RISK MANAGEMENT STRATEGY"

Transcription

1 LONDON BOROUGH OF ENFIELD RISK MANAGEMENT STRATEGY JANUARY

2 Version Control Reference Comments Approval date

3 FOREWORD Welcome to the Council s Risk Management Strategy. We are all required to manage risks on a daily basis. When we consider our collective responsibility on behalf of the Council, this requires a formal, structured approach, a positive culture, and appropriate standards for the way we behave. The current pressures on public spending, service demands, and new legislation coupled with demands for increased transparency and accountability, mean that robust and effective risk management is more essential than ever. The responsibility for managing risk is not restricted to any one person or group of specialists. It is the duty of every member of staff and elected Members. Effective risk management allows us to: Be risk aware, not risk averse; Have increased confidence in achieving the Council s priorities and in achieving key objectives; Manage threats so that the impact on effective and efficient service delivery is minimised; Make informed decisions about seizing opportunities for the Council; Ensure that there is a balance between risks and rewards; Enhance the likelihood of success of projects; and Improve the Council s partnership working arrangements and corporate governance. Effective risk management will help ensure that the Council seizes opportunities and minimises the consequences of the risks it faces in delivering priorities and improved outcomes. 3

4 CONTENTS Foreword RISK MANAGEMENT STRATEGY 1. Introduction 2. Mission statement 3. Aims and objectives 4. Risk appetite and tolerance 5. Benefits of risk management 6. Implementing risk management 7. Implementing risk management approach 8. Monitoring and reporting 9. Corporate Risk Register and Risk Champions 10. Partnerships and significant contracts 11. Programme and project management 12. Covalent system 13. Further advice and assistance Appendix A Risk and Opportunity Scoring Appendix B Roles and Responsibilities Appendix C How to set the Risk Appetite 4

5 RISK MANAGEMENT STRATEGY 1. INTRODUCTION No organisation, whether in the private, public, or third sector can achieve its objectives without taking risk. The only question is how much risk do they need to take? And yet taking risks without consciously managing those risks can lead to the downfall of organisations. (Source: UK Corporate Governance Code) 1.1 Risk is the threat that an event or action will adversely affect the Council s ability to achieve its objectives and to successfully execute its strategies. An opportunity can be defined as the opposite of a risk i.e. that an event or action will enhance the Council s ability to achieve its objectives and to successfully execute its strategies. 1.2 Risk management is the culture, processes, and structure that are directed to the proactive identification, understanding, and management of potential threats and opportunities. 1.3 Pressures on public spending and demands for increased transparency and accountability mean that robust and effective risk management is an essential part of the Council s decision-making framework. The CIPFA/SOLACE Good Governance Framework, for example, includes the principle of Taking informed and transparent decisions which are subject to effective scrutiny and managing risk. Similarly, working against the background of the current economic downturn means there is particular need for robust risk identification and management to achieve resilience. 1.4 Each manager needs to take their key objectives for the year (including relevant corporate objectives) and identify the risks to achieving these objectives. Where opportunities are identified, due diligence needs to be exercised to ensure they are realistic and afford value for money. 1.5 Action plans need to be produced to mitigate identified risks and seize relevant opportunities. 1.6 Risk management is both a statutory requirement and an indispensible element of good management. As such, its implementation is crucial to the Council and essential to its ability to discharge its various functions to stakeholders. 1.7 This Strategy provides a comprehensive framework designed to support officers in ensuring that the Council is able to discharge its risk 5

6 management responsibilities. It therefore outlines the objectives and benefits of managing risks and describes the responsibilities for risk management. (NOTE: Risks and Opportunities need to be considered at the same time. Therefore when this strategy refers to risk, opportunities should also be considered. In the case of opportunities the aim is to increase, rather than decrease, scoring probability). 1.8 Risk management is a key part of corporate governance, which is essentially the way the Council manages its business (including an Annual Governance Statement). It is essential that risk management is embedded into corporate processes including: Strategic planning; Financial planning; Service delivery; Policy making and review; Project management; Significant partnerships; Performance management; Change management / transformation; Emergency Planning; and Business continuity planning. 1.9 In order to ensure that the strategy remains current and responds to changing environments it is reviewed / updated annually and approved by the Audit Committee Risk management is a key part of the good management of the Council and, properly used, can add value. In addition to the Corporate Risk Register and departmental risk registers every service should have an up to date risk register usually as part of the annual service planning process To be effective, attention is paid to the Council s risks from the top to the bottom of the organisation. (Source: Solace, Chance or Choice ). This is because whilst senior managers have a bird s eye overview of the Council they cannot have the detailed knowledge and appreciation of individual service areas that other staff will have All known risks are considered and not simply a sub-set such as financial risks. Similarly, it is not only the impact of an incident in financial terms that needs to be evaluated but also the potential damage that such an incident could inflict upon the reputation of the organisation and the adverse effect on service delivery. Simply put, it is anything that could prevent the Council from achieving its aims and objectives. 6

7 1.13 Risk and opportunity assessments, undertaken as part of the strategy, will cover all aspects of services including known risk, existing controls and their significance It contains a new section on setting the risk appetite. This is for guidance only, however officers may find it helpful in deciding on the acceptable target score for a risk The risk appetite scoring seeks to determine the target risk score. In the case of a significant risk that needs to be reduced, for example, low scores are allocated so as to provide a low risk appetite target. Conversely, where management can accept greater risk then there would usually be a higher risk appetite The risk management strategy does not seek to replace but complement processes for managing specific risks, including, for example, health & safety, safeguarding, business continuity and information governance This Strategy aims to provide an overarching framework for the management of threats and the taking of opportunities (subject to due diligence). It seeks to help officers to do more with less by reviewing the effectiveness of what they do, why they do it and how they do it. 7

8 2. MISSION STATEMENT The overall objective of this strategy is to set best practice for the Council to actively identify and manage its risks and opportunities. 8

9 3. AIMS AND OBJECTIVES 3.1 This Strategy seeks to improve the Council s ability to deliver its strategic priorities by managing threats and opportunities, and creating an environment that adds value to ongoing operational activities. It supports the vision to make Enfield a better place to live and work delivering fairness to all, growth and sustainability, and strong communities. 3.2 Specific objectives of the strategy are to: Help managers meet Council objectives and support the overall governance framework; Support and work alongside existing policies and procedures to mitigate risk; Make better management decisions by embedding risk management practices across the Council including use of the Covalent performance management system to facilitate risk management; Further embed the risk management strategy and practices within the Council; including further training for both officers and members; Further integrate risk / opportunity management into the culture of the Council and into the Council s strategic planning and decision making processes; Ensure the framework for identifying, evaluating, controlling, reviewing and communicating risks is implemented and understood across the Council; Communicate to stakeholders the Council s approach to risk and opportunity management; Ensure that Members, CMB, and external regulators can obtain the necessary assurance that the Council is mitigating the risks of not achieving its objectives and complying with good corporate governance practice; and Ensure consistency throughout the Council in the management of threats and opportunities. 3.3 Specific aims and objectives to further embed risk management at Enfield during 2012/13 include the following: Embed risk management around the Council s new public health responsibilities commencing from April 2013; Consideration of the composition of the Risk Management Working Group and the role of the Risk Champions; Ensuring that greater focus and time is spent on identifying and monitoring mitigating actions; 9

10 Closer working with the internal audit section to facilitate enhanced working and management of risks; Use of horizon scanning to identify new/potential challenges and production of action plans to meet these challenges; Provision of further training including Corporate Governance Briefings and risk workshops; and Encouraging users to make better use of Covalent to manage risks and opportunities including more officers being trained on Covalent and greater volume of risks being captured on Covalent. 10

11 4. RISK APPETITE AND TOLERANCE 4.1 Risk appetite is defined as the degree of risk that the Council is willing to accept in the pursuit of its objectives. It defines the acceptable level of risk in each area of the Council s operations. This links in with the acceptable level of variation around the achievement of a specific objective often called the risk tolerance. 4.2 No organisation can achieve its objectives without taking risk, yet taking risks without consciously managing those risks can lead to significant problems. This is illustrated by the current economic downturn where banks failed to effectively manage their risks. As a consequence Risk Appetite and Risk Tolerance are now on the agenda for all listed companies. 4.3 At corporate, department, and service level, management need to be clear what significant risks they are willing to take and equally what significant risks they are not willing to take. This is also true of partnership working. 4.4 Deciding what risks management are willing to take is called risk appetite. Risk appetite will, by definition, vary from department to department and even from service to service - for example the risk appetite for safeguarding would be different from say the allotments service. It may well vary according to time electoral services being a case in point. 4.5 Risk tolerance is closely linked to risk appetite. It simply means that whilst our usual risk appetite, say for investments, might be set at an agreed level, there may be exceptional circumstances where this might be exceeded. This would be the maximum risk tolerance management would be willing to take. Where the usual risk appetite is exceeded this should be reported to the relevant individuals and members for clearance. 4.6 Risk appetite is not a single, fixed concept. There will be a range of appetites for different risks and these appetites may well vary over time. 4.7 The key question in calculating risk appetite and tolerance is What does successful performance look like? 4.8 All the hazards around non-achievement of identified successful performance would comprise the risk universe. 4.9 Those hazards which, in exceptional circumstances, management might tolerate would be termed the risk tolerance and would form a narrower band within the overall risk universe. 11

12 4.10 An even narrower band would those hazards and risks that management are usually comfortable in dealing with - this is called the risk appetite Risk appetite and risk tolerance should be used as part of the decision making process. Accepting a potential higher level of risk in one area but less risk in another will help the Council to focus its resources on mitigating key risks to achieving key objectives The Council seeks to be risk aware, not risk averse. Being clear as to what risks a service is willing and not willing to accept can really assist in decision making Help in deciding what level of risk or risk appetite may be acceptable is provided. This is for guidance only and officers may find it a useful tool to determine risk appetite and tolerance The guidance may initially appear counter-intuitive with scoring opposite to risk identification. Low scores are allocated to significant risks and high scores allocated to less important risks This is because where there is a significant risk (e.g. safeguarding) the target would be to reduce the risk to the lowest practical score. It is this target score that comprises the risk appetite. Note: Guidance on setting the risk appetite is contained in Appendix C. 12

13 5. BENEFITS OF RISK MANAGEMENT 5.1. Benefits of risk management include the following: Helps to drive decision making and the achievement of key objectives; Reduced time spent fire fighting ; Increased confidence moving into new areas, or undertaking new projects; Improved management information; Enhanced service planning and service delivery; Focused financial performance and resource management - the cost-effectiveness of actions; Enhanced reputation through the delivery of community outcomes and meeting external standards; Assisting managers in their strategic thinking and enhanced service delivery leading to enhanced reputation; Effective Human Resources management; Targeted Business Continuity Management (BCM). (Risk management links in with business continuity management by seeking assurance that BCM plans are in place and are up to date); Improved corporate governance and compliance issues; and Consideration of Opportunities. Effective risk management assists in the identification and assessment of opportunities to improve service delivery. Note: Management must always carry out due diligence when considering possible opportunities and these would also be subject to the Council s financial regulations and procedures including report writing. 13

14 6. IMPLEMENTING RISK MANAGEMENT (LIKELIHOOD, IMPACT, AND INHERENT / RESIDUAL RISK) 6.1 The basic steps to undertaking a risk assessment are: Provide a succinct description of the risk, its cause and consequence; Link the risk to the relevant corporate / departmental / service objective; Use the 5x5 risk scoring matrix for likelihood and impact (see below); Include risk rating at Gross or Inherent Risk (initial rating without any controls), current rating with existing set of controls, and target score (level of risk the owner is prepared to accept); Decide how to manage the risk treat, tolerate, terminate, or transfer (please see below); Measure the effectiveness of existing controls; Identify actions required to fill any gaps with the set of existing controls and to achieve the required target risk rating; Ensure any actions are cost effective that the cost of managing risk does not exceed potential outcomes; Allocate a named individual with responsibility for implementing actions together with a target date; and If applicable identify reasons for closing risks. 6.2 When following these steps it is helpful to categorise risks in seven ways: Strategic risk those risks affecting the medium (say next twelve months) to long term goals and objectives; Operational risk those risks that managers and staff will encounter in the daily course of their work; People risk risks associated with employees and management; Financial risk covering budgets and costs. Losing monetary resources or incurring unacceptable liabilities; Reputation risk relating to the image of a service / department or to the whole Council; Information risk relating to loss or inaccuracy of data, systems, or reported information (including non-it information); and Regulatory risk relating to the regulatory environment. 6.3 In addition, opportunities need to be considered. These will frequently be ways of dealing with identified risks and therefore often appear in risk management action plans. 14

15 6.4 For every decision there is an associated risk that delivery will not take place. This risk is broken down into two components: Likelihood and Impact. Relevant guidance is provided in Appendix A. To be effective there must be a culture of risk awareness throughout the Council to engage all Members and officers in the process of risk identification and of risk mitigation. 6.5 Likelihood represents the statistical chance of an event taking place. Such events are classified at Enfield in a number of statistical ways summarised into these five broad stratified headings: Remote, Unlikely, Possible, Probable, and Highly Probable. 6.6 Impact represents the expected disruption to the Council. Such events are classified in a number of statistical ways, summarised into these five broad stratified headings: Insignificant, Minor, Moderate, Major, and Catastrophic / systemic failure. (NOTE: in the case of opportunity management this final level of impact would be termed Transformational). 6.7 The above defines gross or inherent risk i.e. it takes no account of the controls the Council has in place or can put in place to manage the identified risk. 6.8 To offset this, Council managers apply controls to reduce the gross risk and to obtain the net or residual risk. The controls come in many forms but the means of prioritising them are as follows: Terminating a risky activity, Transference of Risk (possibly by insurance), Treating the Risk (such as taking certain action that may reduce the likelihood and/or impact of a future event taking place) and Tolerating the Risk. Tolerating a risk is where a risk cannot be reduced to a tolerable level but is essential to the delivery of an operational objective. 6.9 Another way of expressing this is through the 4 T s whereby risks can be: Treated (such as by appropriate remedial actions); Tolerated (where they fall below the risk appetite ); Transferred (such as for the 20% or so of risks that can be insured); and Terminated (where it may be possible not to embark on an activity deemed to be very high risk). 15

16 7. IMPLEMENTING RISK MANAGEMENT THE RISK MANAGEMENT APPROACH 7.1 Identification. Across the Council a number of techniques are used for risk identification of which the most common are individual interviews and workshops including SWOT analyses (strengths, weaknesses, opportunities, and threats). Horizon scanning technique is also used in accordance with HM Treasury Management of Risk Principles and Concepts to identify new risks and opportunities that the Council is likely to face. 7.2 Analysis. We measure or analyse this in two ways: By the likelihood or frequency of the risk occurring; and By the severity or impact on the Council of the risk event occurring. 7.3 Risk Mapping is utilised to plot risks according to the above analysis on a 5 x 5 matrix so that High (Red), Medium (Amber), and Low (Green) categories can be seen at a glance. These are defined as follows: High (Red) scoring risks have scores of 16 and over; Medium (Amber) scoring risks have scores from 9 to 15 inclusive; and Low (Green) scoring risks have scores from 1 to 8 inclusive. 7.4 Control of risks is effected therefore by management action plans for medium and high scoring risks to determine the best course of action i.e. should the risk be avoided, eliminated, reduced, transferred, or accepted. 7.5 Action plans must also identify the individual to deliver the improvements, with key dates and deadlines. 16

17 Risk scoring matrix LIKELI HOOD IMPACT NOTE: The above table records the scoring for Risk Management where we are trying to decrease the scores by aiming for the green areas. Opportunity scoring matrix LIKELI- HOOD IMPACT NOTE: The above table records the scoring for Opportunity Management where we are trying to increase the score (rather than decrease as in the case of risk management) by aiming for the green coloured areas. 17

18 8. MONITORING AND REPORTING 8.1 Progress in managing risks will be monitored and reported as part of a continuous cycle so that losses are minimised and intended actions are achieved. Appendix B lists relevant roles and responsibilities. Every service centre must produce an up to date risk register this should usually be done as part of the service planning process. 8.2 Risks scoring 16 and above will usually be escalated to the next level e.g. from service risk registers to department risk registers, and from departmental risk registers to the Corporate Risk Register. Management actions will be checked by relevant departmental management teams, CMB, and Audit Committee as appropriate. 8.3 Directors and key staff will review their risks at least quarterly at their DMTs so that the whole management team are aware of the key risks faced by the service / department and the mitigations in place to control them. There is a timetable for risk reporting. 8.4 CMB will review the Corporate Risk Register on a quarterly basis and this can be more frequent for key risks (e.g. as happened with the Olympics). 8.5 The Terms of Reference of the Audit Committee include the words, To monitor the effective development and operation of risk management and corporate governance in the Council. This duty is exercised through: Six monthly review of the Corporate Risk Register; and On a rolling programme, review of Departmental Risk Registers. 8.6 Cabinet will review the Corporate Risk Register every six months. 8.7 A report will go to full Council at least once per annum. 8.8 All reports include a section on KEY RISKS. 18

19 9. CORPORATE RISK REGISTER AND RISK CHAMPIONS 9.1 The Corporate Risk Register contains those risks and opportunities that could have a significant impact upon the Council. A risk is included on the Corporate Risk Register if it would have a significant adverse effect on the achievement of corporate aims and objectives, or to the delivery of the Medium Term Financial Strategy and Financial Plan. 9.3 A major (but not exclusive) source of information for the corporate risk register are those risks found on departmental risk registers. Where these are red risks they will usually be considered for inclusion on the Corporate Risk Register. 9.4 Management of risks is a function of management at all levels under the auspices of CMB. Each risk is allocated a risk owner whose responsibility is to ensure mitigating actions are carried out by the stated deadline. 9.5 Each department has one or more Risk Champions. Their role is to act as a liaison between the Risk Manager and their departments and to help identify risks and opportunities. They also feed back confirmation that mitigations identified within the action plans have been implemented within agreed timescales. They may be the Assistant Director (Resources) from each department or at senior officer level. 19

20 10. PARTNERSHIPS AND SIGNIFICANT CONTRACTS 10.1 The risk management process will specifically identify risks in relation to significant partnerships and contracts and provide for assurances to be obtained about the management of those risks. This will include joint ventures, the extended enterprise, and potential for risks arising from Council funding of community and voluntary groups under the Big Society Officers will provide information and work in a proactive way to ensure that opportunities as well as threats are considered Risk management monitoring will take place on an ongoing basis during the life of partnerships to ensure that the Council s interests are safeguarded NOTE: partnership risks need to be considered in terms of: 1. Risks to the Council from the partnership; and 2. Joint risks (in which case a joint risk register should be prepared). 20

21 11. PROGRAMME AND PROJECT MANAGEMENT 11.1 The Risk Manager is involved in discussions on aligning the risk element of the Council s Programme and Project management approach with the current corporate risk management framework Programme and Project management includes transformational projects and capital works projects in addition to IT projects Proposals support alignment through the adoption of Office of Government Commerce (OGC) good practice guidance for Programme and Project management e.g. the Managing Successful Programmes (MSP) methodology for managing Programme level risks and the PRINCE 2 methodology for managing project-level risks This will enhance the way the Council manages the links and dependencies between corporate and Programme / Project level risk management A system specific to programme and project management, Verto, is being rolled out and this should be used to capture detailed risks to programmes and projects. The broader programme and/or project risks, however, should still be held on the Corporate Risk Register or Departmental Risk Registers, via Covalent, as appropriate. 21

22 12. COVALENT SYSTEM 12.1 Risk assessments at any level should usually be carried out using the Covalent computer system that the Council uses to record, manage and report risk and associated controls and action plans Users are encouraged to make better use of Covalent to track risks and risk actions. An external review of Covalent during 2012/13 will help in forming a view on how the system can further help users Covalent can be used to capture an unlimited number of risks and as such can be particularly helpful in horizon scanning to record and evaluate potential future issues facing the Council s services. As a result it can be used to reflect those risks that are not designated significant, at a point in time, but could develop to have a significant adverse impact if circumstances and the Council s operating environment change. 22

23 13. FURTHER ADVICE AND ASSISTANCE 13.1 Further advice and assistance on risk management can be obtained from the Risk Manager on or Detailed guidance on conducting a risk assessment is available on the Enfield Eye. 23

24 Appendix A RISK AND OPPORTUNITY SCORING RISK LIKELIHOOD Score 1 = Remote: Extremely unlikely; Happens less than once in ten years. Score 2 = Unlikely: Happens no more than once in ten years. Score 3 = Possible: Could occur; Happens once every five years on average. RISK IMPACT Score 1 = Insignificant: Minimal financial impact of less than 250,000; Local newspaper comment only - a one-off event. Score 2 = Minor: Not material but still relevant adverse impact on financial objectives. From 250,000 up to 500,000; Repeated coverage on local level. Score 3 = Moderate: Material impact on financial objectives for the year (Over 500,000 up to 2.5 million); National newspaper coverage. Score 4 = Probable: Score 4 = Major: Very likely to take place - say a Material critical impact on financial minimum of once in every two years. objectives for the current and subsequent years. Over 2.5 million up to and including 5 million. TV coverage of incident. Score 5 = Highly Probable; A near certainty. Likely to occur every year. Score 5 = Catastrophic / systemic failure Abuse resulting in death of the vulnerable (e.g. Baby P tragedy); Special Measures for a department or the Council overall; Financial loss of over 5 million; Sustained national campaign on all media. 24

25 NOTE: Financial thresholds should be reviewed periodically as the ability to absorb the impact of loss will change, particularly in the current economic environment. Risk Scoring Red / High = 16 to 25 inclusive Amber / Medium = 9 to 15 inclusive Green / Low = 1 to 8 inclusive 25

26 OPPORTUNITY LIKELIHOOD Score 1 = Remote: Extremely unlikely; Happens less than once in ten years Score 2 = Unlikely: Happens no more than once in ten years. Score 3 = Possible: Could occur; Happens once every five years on average. Score 4 = Probable: Very likely to take place - say a minimum of once in every two years. Score 5 = Highly Probable; A near certainty. Likely to occur every year. OPPORTUNITY IMPACT Score 1 = Insignificant: Minimal financial impact of less than 250,000; Beneficial effect on one service. Score 2 = Minor: Positive impact on financial objectives from 250,000 up to 500,000; Beneficial influence on several services. Score 3 = Moderate: Material positive impact on financial objectives for the year (Over 500,000 up to 2.5 million); Beneficial impact on departmental aims and objectives; Positive effect on a division. Score 4 = Major: Material positive impact on financial objectives for the current and subsequent years. Over 2.5 million up to and including 5 million. Positive/beneficial effect on one or more departments and achieving corporate aims and objectives; Sustained local press coverage. Score 5 = Transformational. A recurring and material annual saving, or a one-off saving of material significance say of over 5 million; Significant beneficial effect on longterm corporate aims and objectives; Sustained national press coverage; A national lead. NOTE: Financial thresholds will be reviewed periodically as the impact of a saving will change, particularly in the current economic environment. Opportunity Scoring High = 16 to 25 inclusive Medium = 9 to 15 inclusive Low = 1 to 8 inclusive

27 Appendix B ROLES AND RESPONSIBILITIES Groups The risk management service is primarily that of an advisory, support, and critical friend function and to support this, the following groups have responsibilities: Reviewing Group Corporate Management Board Cabinet (and Elected Members) Audit Committee (and Chair of Audit Committee) Departmental Management Teams (DMT s) Responsibilities Express duty to act on concerns where the risk appetite and risk tolerance are exceeded to ensure risk is mitigated to acceptable levels. Defines the risk appetite and risk tolerance framework. Reviews Corporate Risk Register prior to submission to Audit Committee; Ensuring that there is dynamic management of corporate risk; Ensuring that risk is given due consideration in all management processes and decisions and ensure ownership of corporate risks. Reviews the Corporate Risk Register; Monitors and acts on escalated risks from Audit Committee. Overall Member responsibility and accountability for Councilwide risk management; The lead councillor body which approves the Risk / Opportunity Management Strategy, which will include the process for managing risks and opportunities; Raising any concerns on risk management with Cabinet; Reviewing the annual Risk Management Report prior to its presentation to Cabinet; Monitors the effective development and operation of risk management in the Council; Receives periodic updates on the corporate and department risks and opportunities; Periodically asks for further detailed information about actions to mitigate key risks. Monitor risk appetite and tolerance for their department risks. Acts to effect change where the risk appetite and risk tolerance are exceeded. Ensuring that there is dynamic management of risk across their department;

28 Project Boards and Strategic Procurement Board. Internal Audit Risk and opportunity management to be included within the department planning process; Departmental risk registers to be reviewed quarterly or more regularly as necessary; Ensuring that agreed actions to manage risk exposure to an acceptable level are undertaken on a timely basis and in accordance with departmental risk registers; Ensuring that risks identified within the department are managed at an appropriate level, including escalation to a corporate level where appropriate; Ensuring that risk is given due consideration in all management processes and in taking key decisions. Participates in the identification, assessment, planning and management of threats and opportunities; Understands the Risk Management Strategy and their accountabilities; Ensures risk management is actively considered before, during, and after key projects / procurement including lessons learned. Understands Council s risk management strategy; Supports the risk management process including discussing risks with management; Focus internal audit plan on significant risks via risk registers and liaison with Risk Manager; Provides the Risk Management Service with updates on risks identified from audits; Provides assurance on risk management across the Council based on reviews though audit risk assessments. Risk Management Service Providing guidance, advice & support on the Council s Risk Management approach including risk appetite and tolerance; Co-ordinating risk management across the Council; Running risk workshops across the Council as required; Ensuring that the risk management process is operated on a current basis; Performing quality and performance checks on RM documents as first line assurance; Arranging risk management awareness, support and training interventions for managers, staff and councillors; Liaison with various specialists across the Council such as Insurance, Internal Audit, Health & Safety, and Emergency Planning to assess the risks in specific areas.

29 Roles To help clarify an individual s responsibility for managing risks within their role, a set of risk management competencies have been developed. Role Chief Executive Directors and Assistant Directors Chair of Audit Committee Responsibilities Overall executive responsibility and accountability for Council-wide risk management; Ensuring that the Corporate Risk Register and Departmental Risk Registers are subject to regular review. Responsibility to ensure risks are mitigated to agreed levels of risk appetite and tolerance; In addition, individuals may have specific responsibilities in relation to the role of local authority statutory officers including the following roles: The head of paid service; The officer responsible for financial administration (aka the section 151 officer); The monitoring officer; Director of Public Health; Director of social services; and Director of children s services. Some of these offices may be held by the same person. Each of these posts have specific legal responsibilities attached to it along with a limited range of legal powers to compel a local authority to take (or restrain from) certain courses of action. Such individuals will need to ensure that risks relating to these additional roles are adequately identified and mitigated to acceptable risk appetite levels. Overall Member responsibility and accountability for Councilwide risk management. Risk Manager Senior Managers / Heads of Service To update the Council s Corporate Risk Register and link it with the Council s aims and objectives; To consider new risks and opportunities via Horizon Scanning ; To raise the level of management awareness and accountability for the business risks of the Council; To provide guidance on setting risk appetite and tolerance; Help to embed risk management as part of the culture of the Council; To facilitate risk workshops, and general facilitation and coordination of risk management activities. Agree calculation of risk appetite and tolerance for each risk identified for their service; Operational responsibilities for controlling threats and

30 Report Authors Risk Management Champions Risk Action Owners All Staff managing opportunities (subject to due diligence); Ensuring that there is dynamic management of risk across their service, formally reflected in quarterly review of risk registers; Ensuring that agreed actions to manage risk exposure to an acceptable level are undertaken on a timely basis; Ensuring that risks identified within the service are managed at an appropriate level; Reporting on the adequacy of risk management arrangements to the relevant director on a regular basis; Ensuring that risk is given due consideration in all management processes. Consider key risks in their reports including those to Council, Cabinet, and CMB, must include a summary of the key risks and opportunities arising from or being addressed by the content / actions of the report. Main contact for the department for risk management including liaising with the Risk Manager; Oversees the corporate approach to risk management within their department; Ensure Covalent is updated to ensure key risks are captured and updated regularly; Working with relevant senior managers within their department to use the risk management approach in assisting the delivery of service and departmental objectives; Driving the development and embedding of effective risk management across their department / service area; Contributing to the development of the Council s risk management processes. Ensure effective action is taken to manage risk within target timeframe; Ensures the integrity of information recorded on the risk register; Monitors progress against mitigating actions. Identifying opportunities as well as hazards and risks in performing day-to-day duties; Taking appropriate action to take advantage of opportunities or to limit likelihood and impact of risks; Awareness of risk management policies; Understand their role in managing risk.

31 APPENDIX C HOW TO SET THE RISK APPETITE This Appendix provides help to determine the maximum acceptable risk score, through determining a risk appetite. It is provided for guidance only and officers may wish to use another method to determine risk appetite and a target risk score for each risk that they are managing. The key steps are as follows: 1. Identify risks as normal, including scoring the risks based on the five by five matrix set out in Appendix A. 2. Assess each risk according to the following five criteria: i) Priority ii) Safeguarding issues (human risk) iii) Financial Impact iv) Reputational Impact v) Legal / statutory requirement. 3. Score each criteria from 1 to 5 as follows: Risk Appetite Scoring CRITERIA Key objective, aim, or priority Safeguarding issues (human risk) IMPACT Insignificant Minor Moderate Major Catastrophic Financial impact Reputational impact Legal / statutory requirement Where criteria are considered important this should be reflected by a low score i.e. low risk appetite.

32 Conversely, where it is considered there would be little financial impact if a risk crystallised then this should be given a high score i.e. high risk appetite. Scores are added up for each of the five criteria with a minimum possible score of 5 and a maximum of 25. The lower the score the lower the amount of risk we are willing to tolerate in this area. Scores can then be used to generate a target risk score (i.e. where we would like to be). Risk Appetite Scoring Criteria Definitions Score 5 = Insignificant Score 4 = Minor Score 3 = Moderate Score 2 = Major Score 1 = Catastrophic / systemic failure Key objective aim, or priority No key objective, aim, or priority. Ongoing aims e.g. general staff training. Enhancements to corporate planning e.g. to Project Management or to Business Continuity Management. A fundamental aim or objective e.g. delivery of regeneration projects. A key objective, aim, or priority e.g. safeguarding of vulnerable children and adults. Safeguarding issue (human risk) Virtually no human risk (e.g. hire of allotments). Minor human risk (e.g. ensuring safeguards over contractors carrying out maint-enance work in schools). Possible risk to vulnerable members of society (e.g. those with access to sensitive information). Potential for abuse of the vulnerable (e.g. recent national issues involving the elderly in care homes). Abuse resulting in death of the vulnerable (e.g. Baby P tragedy). Financial impact Minimal financial impact of less than 250,000. Not material but still relevant adverse impact on financial objectives. From 250,000 up to 500,000. Material impact on financial objectives for the year. Over 500,000 up to 1m. Material critical impact on financial objectives for the current and subsequent years. Over 1m up to 5m. Financial loss of over 5m. Reputati onal impact Local newspapers comment only a one-off Repeated coverage at a local level. Social media One-off national newspaper coverage. Local TV National TV coverage of incident. Repeated Sustained national campaign on all media.

33 Score 5 = Insignificant Score 4 = Minor Score 3 = Moderate Score 2 = Major Score 1 = Catastrophic / systemic failure event. Limited social media coverage. Minor / temporary service failure. coverage. Service failure with minimal financial or reputational impact Recommenda tions for improvement in external inspections. coverage. Extensive social media coverage. Major service failure with notable financial or reputational impact. national newspaper coverage. Major service failure involving material financial loss or significant reputational damage. Adverse external inspection. Catastrophic service failure involving safeguarding incident. Adverse external inspection coupled with intervention. Some censure in external inspection. Legal / statutory requirement No legal or statutory requirement or best practice. No legal or statutory requirement or best practice, but where there is public pressure to provide a service (e.g. refuse collections carried out every week rather than every fortnight). No statutory requirement but best practice (e.g. accounting standards). Best practice with a specific urgency / time constraint (e.g. implementation of International Financial Reporting Standards). A statutory / legal requirement e.g. having to provide children s education.

34 Worked example 1: Provision of allotments: CRITERIA IMPACT Key objective, aim, or priority 4 Safeguarding issue (human risk) 5 Financial impact 4 Reputational impact 3 Legal / statutory requirement 2 TOTAL MAXIMUM RISK APPETITE 18 Therefore the total target score for this risk needs to be at or below 18 (high risk appetite). Worked example 2: Safeguarding of children: CRITERIA IMPACT Key objective, aim, or priority 1 Safeguarding issue (human risk) 1 Financial impact 2 Reputational impact 1 Legal / statutory requirement 1 TOTAL MAXIMUM RISK APPETITE 6 Therefore the total target score for this risk needs to be at or below 6 (very low risk appetite). Worked example 3: Financial / budgetary pressures CRITERIA IMPACT Key objective, aim, or priority 2 Safeguarding issue (human risk) 3 Financial impact 1 Reputational impact 2 Legal / statutory requirement 2 TOTAL MAXIMUM RISK APPETITE 10 Therefore the total target score for this risk needs to be at or below 10 (low risk appetite).

Risk Management Framework

Risk Management Framework Risk Management Framework Introduction The outgoing Corporate Strategy 2013-18 and incoming University Strategy 2018-23 continues on a trajectory towards Vision 2025 in an increasingly competitive Higher

More information

Nagement. Revenue Scotland. Risk Management Framework. Revised [ ]February Table of Contents Nagement... 0

Nagement. Revenue Scotland. Risk Management Framework. Revised [ ]February Table of Contents Nagement... 0 Nagement Revenue Scotland Risk Management Framework Revised [ ]February 2016 Table of Contents Nagement... 0 1. Introduction... 2 1.2 Overview of risk management... 2 2. Policy Statement... 3 3. Risk Management

More information

Bournemouth Primary MAT Risk Management Policy

Bournemouth Primary MAT Risk Management Policy Bournemouth Primary MAT Risk Management Policy 1. Introduction The Bournemouth Primary Multi-Academy Trust (the Trust) operates a risk management system in order to identify and manage key exposures and

More information

Nagement. Revenue Scotland. Risk Management Framework

Nagement. Revenue Scotland. Risk Management Framework Nagement Revenue Scotland Risk Management Framework Table of Contents 1. Introduction... 2 1.2 Overview of risk management... 2 2. Policy statement... 3 3. Risk management approach... 4 3.1 Risk management

More information

Risk Management. Policy and Procedures

Risk Management. Policy and Procedures Risk Management Policy and Procedures POLICY SCHEDULE Policy title Policy owner Policy lead contact Approving body Date of approval/review Related Guidelines and Procedures Review interval Risk Management

More information

Risk Management Framework

Risk Management Framework Risk Management Framework Anglican Church, Diocese of Perth November 2015 Final ( Table of Contents Introduction... 1 Risk Management Policy... 2 Purpose... 2 Policy... 2 Definitions (from AS/NZS ISO 31000:2009)...

More information

Scouting Ireland Risk Management Framework

Scouting Ireland Risk Management Framework No. SID 124A/15 Gasóga na héireann/scouting Ireland Issued Amended 20 th June 2015 Deleted Source: National Management Committee Scouting Ireland Risk Management Framework Revision Date Description # 20/06/2015

More information

Risk Management Strategy

Risk Management Strategy Risk Management Strategy 2016 2019 Version: 6 Policy Lead/Author & Deputy Director of Quality position: Ward / Department: Nursing Directorate Replacing Document: Version 5 Approving Committee Quality

More information

Risk Management Strategy

Risk Management Strategy Resources Risk Management Strategy Successful organisations are not afraid to take risks; Unsuccessful organisations take risks without understanding them. Issue: Version 3 - November 2011 Group: Resources

More information

Risk Management Strategy January NHS Education for Scotland RISK MANAGEMENT STRATEGY

Risk Management Strategy January NHS Education for Scotland RISK MANAGEMENT STRATEGY NHS Education for Scotland RISK MANAGEMENT STRATEGY January 2016 1 Contents 1. NES STATEMENT ON RISK MANAGEMENT 2 RISK MANAGEMENT STRATEGY 3 RISK MANAGEMENT STRUCTURES 4 RISK MANAGEMENT PROCESSES 5 RISK

More information

Practical aspects of determining and applying a risk appetite for SMEs

Practical aspects of determining and applying a risk appetite for SMEs Practical aspects of determining and applying a risk appetite for SMEs By Tim Timchur acis, Director, ActivePro Consulting Pty Ltd Important to determine appetite for risk before determining what risk

More information

NHS North Somerset Clinical Commissioning Group Risk Management Strategy and Framework

NHS North Somerset Clinical Commissioning Group Risk Management Strategy and Framework NHS North Somerset Clinical Commissioning Group Risk Management Strategy and Framework An Integrated Risk Management Framework Clinical Risk Management Financial Risk Management Corporate Risk Management

More information

Version: th November 2010 RISK MANAGEMENT POLICY

Version: th November 2010 RISK MANAGEMENT POLICY Version: 1.2-25th November 2010 RISK MANAGEMENT POLICY Document History Document Location To be completed. Revision History Date of this revision: 17/09/2010 Date of next revision: N/A Revision Number

More information

Risk Management Framework

Risk Management Framework Risk Management Framework Risk Management Framework 1. The University views Risk Management as integral to the successful execution of its Strategy. In order to achieve the aims set out in our strategy,

More information

RISK MANAGEMENT POLICY AND STRATEGY

RISK MANAGEMENT POLICY AND STRATEGY 1 RISK MANAGEMENT POLICY AND STRATEGY Version No: Reason for Update Date of Update Updated By 1 Review Timeframe September 2014 2 Review June 2017 Governance Manager Governance Manager 3 4 5 6 7 8 Introduction

More information

APPENDIX 1. Transport for the North. Risk Management Strategy

APPENDIX 1. Transport for the North. Risk Management Strategy APPENDIX 1 Transport for the North Risk Management Strategy Document Details Document Reference: Version: 1.4 Issue Date: 21 st March 2017 Review Date: 27 TH March 2017 Document Author: Haddy Njie TfN

More information

Risk Management Strategy Draft Copy

Risk Management Strategy Draft Copy Risk Management Strategy 2017 Draft Copy FOREWORD Welcome to the Council s Strategic & Operational Risk Management Strategy, refreshed in May 2017. The aim of the Strategy is to improve strategic and operational

More information

Risk Management Strategy Highland Council Pension Fund

Risk Management Strategy Highland Council Pension Fund Risk Management Strategy Highland Council Pension Fund Approved Pensions Committee 9 August 2018 3 1. Introduction 1.1 Risk management is a key element of Corporate Governance and the Highland Council

More information

Approved by: Diocesan Council 17 December 2015

Approved by: Diocesan Council 17 December 2015 DIOCESAN COUNCIL POLICY 39 Risk Management Approved by: Diocesan Council 17 December 2015 1 PREAMBLE The Perth Diocesan Trustees under the authority of the Diocesan Trustees Statute 1952 have the responsibility

More information

M_o_R (2011) Foundation EN exam prep questions

M_o_R (2011) Foundation EN exam prep questions M_o_R (2011) Foundation EN exam prep questions 1. It is a responsibility of Senior Team: a) Ensures that appropriate governance and internal controls are in place b) Monitors and acts on escalated risks

More information

Executive Board Annual Session Rome, May 2015 POLICY ISSUES ENTERPRISE RISK For approval MANAGEMENT POLICY WFP/EB.A/2015/5-B

Executive Board Annual Session Rome, May 2015 POLICY ISSUES ENTERPRISE RISK For approval MANAGEMENT POLICY WFP/EB.A/2015/5-B Executive Board Annual Session Rome, 25 28 May 2015 POLICY ISSUES Agenda item 5 For approval ENTERPRISE RISK MANAGEMENT POLICY E Distribution: GENERAL WFP/EB.A/2015/5-B 10 April 2015 ORIGINAL: ENGLISH

More information

MEMORANDUM. To: From: Metrolinx Board of Directors Robert Siddall Chief Financial Officer Date: September 14, 2017 ERM Policy and Framework

MEMORANDUM. To: From: Metrolinx Board of Directors Robert Siddall Chief Financial Officer Date: September 14, 2017 ERM Policy and Framework MEMORANDUM To: From: Metrolinx Board of Directors Robert Siddall Chief Financial Officer Date: September 14, 2017 Re: ERM Policy and Framework Executive Summary Attached are the draft Enterprise Risk Management

More information

RISK MANAGEMENT STRATEGY Version 3

RISK MANAGEMENT STRATEGY Version 3 RISK MANAGEMENT STRATEGY Version 3 Risk Management Strategy V3 - March 2018 1 Standard Operating Procedure St Helens CCG Risk Management Strategy Version 3.0 Implementation Date September 2014 Review Date

More information

Queen s University Belfast. Risk Management. Policy and Procedures

Queen s University Belfast. Risk Management. Policy and Procedures Queen s University Belfast Risk Management Policy and Procedures POLICY SCHEDULE Policy title Policy owner Policy lead contact Approving body Date of approval/review Related Guidelines and Procedures Review

More information

Integrated Risk Management Framework Sept Page 1 of 17

Integrated Risk Management Framework Sept Page 1 of 17 Integrated Risk Management Framework 2017-2018 Sept 2017 Page 1 of 17 Reference: Title: Author/Nominated Lead: Approval Date: Approving Committee: Review Date: Target Audience: Circulation List: Cross

More information

Contents INTRODUCTION...4 THE STEPS IN MANAGING RISKS ESTABLISH GOALS AND CONTEXT IDENTIFY THE RISKS...8

Contents INTRODUCTION...4 THE STEPS IN MANAGING RISKS ESTABLISH GOALS AND CONTEXT IDENTIFY THE RISKS...8 Contents INTRODUCTION...4 THE STEPS IN MANAGING RISKS...4 1. ESTABLISH GOALS AND CONTEXT...5 2. IDENTIFY THE RISKS...8 Identifying the risks... 8 Identify the sources of the risks... 8 Identify the impact

More information

INTEGRATED RISK MANAGEMENT FRAMEWORK (STRATEGY AND POLICY)

INTEGRATED RISK MANAGEMENT FRAMEWORK (STRATEGY AND POLICY) INTEGRATED RISK MANAGEMENT FRAMEWORK (STRATEGY AND POLICY) Version 1.5 (DRAFT) RATIFIED DATE BY WHOM Fylde and Wyre CCG Governing Body Fylde and Wyre CCG (F&W CCG) is committed to ensuring that, as far

More information

Risk Management Policy and Procedures.

Risk Management Policy and Procedures. Risk Management Policy and Procedures. Rev Date Purpose of Issue/Description of Change Date 1. June 2006 Initial Issue 2. November 2009 Revised and updated 6 th November 2009 3. September 2010 Revised

More information

Risk Management Policy

Risk Management Policy Risk Management Policy May 2018 Contents 1.0 Purpose... 3 2.0 Scope... 3 3.0 Risk appetite... 3 4.0 Risk management process... 4 5.0 Measuring success... 7 6.0 Review of policy... 7 Appendix A Definitions

More information

UNIVERSITY OF ABERDEEN RISK MANAGEMENT FRAMEWORK

UNIVERSITY OF ABERDEEN RISK MANAGEMENT FRAMEWORK UNIVERSITY OF ABERDEEN RISK MANAGEMENT FRAMEWORK 1 TABLE OF CONTENTS FIGURES AND TABLES... 3 1. INTRODUCTION... 4 2. KEY TERMS AND DEFINITIONS... 5 2.1 Risk... 5 2.2 Risk Management... 5 2.3 Risk Management

More information

University of Greenwich Risk Management Guide Revised October 2017

University of Greenwich Risk Management Guide Revised October 2017 University of Greenwich Risk Management Guide Revised October 2017 Purpose of the Guide 1. This document supplements the Risk Management Policy of the University of Greenwich. It explains why risk management

More information

Integrated Risk Management Framework

Integrated Risk Management Framework Integrated Risk Management Framework Author Patient Safety Manager Version 4.0 Version Date May 2017 Implementation/Approval Date May 2017 Review Date May 2018 Review Body Governing Body Policy Reference

More information

HSC Business Services Organisation Board

HSC Business Services Organisation Board Paper BSO 25/2009 HSC Business Services Organisation Board Risk Management 1. Purpose of this report The purpose of this report is to brief the Board on the BSO Risk Management process. 2. Background HSC

More information

Risk Management Policy and Framework

Risk Management Policy and Framework Risk Management Policy and Framework Risk Management Policy Statement ALS recognises that the effective management of risks is a fundamental component of good corporate governance and is vital for the

More information

PST Board Assurance Framework

PST Board Assurance Framework PST Board Assurance Framework 14 th January 2016 PST Board Assurance Framework Registered Address (No: IP030872) Fratton Park Frogmore Road Portsmouth PO4 8RA Prepared by Dr Mark Farwell PST Secretary

More information

Risk Management Strategy

Risk Management Strategy Risk Management Strategy Document Reference MLCSU CA_WL_V3 Version 3 Authors: Donna Bamber, Midlands & Lancashire Commissioning Support Unit Senior Risk Officer Smita Shetty, Service Redesign Manager,

More information

Risk Management. Seminar June Compiled by: Raaghieb Najjaar, Yaeesh Yasseen & Rashied Small

Risk Management. Seminar June Compiled by: Raaghieb Najjaar, Yaeesh Yasseen & Rashied Small Risk Management Seminar June 2017 Compiled by: Raaghieb Najjaar, Yaeesh Yasseen & Rashied Small Defining Risk Risk reflects the chance that the actual event may be different than the planned / expected

More information

RISK MANAGEMENT FRAMEWORK

RISK MANAGEMENT FRAMEWORK RISK MANAGEMENT FRAMEWORK Approving authority Approval date University Council 5 August 2013 (3/2013 meeting) Advisor Vice President (Corporate Services) vpcorporateservices@griffith.edu.au (07) 373 57343

More information

Risk Management Strategy and Board Assurance Framework

Risk Management Strategy and Board Assurance Framework Risk Management Strategy and Board Assurance Framework Version 1.1 Ratified by Health Commissioning Board Date ratified Audit Committee in Common: 10 th October 2017 Heath Commissioning Board: 8 th November

More information

University of the Sunshine Coast (USC) Risk Appetite Statement

University of the Sunshine Coast (USC) Risk Appetite Statement Vision and strategic goals University of the Sunshine Coast (USC) Risk Appetite Statement The University of the Sunshine Coast will be a university of international standing, a driver of capacity building

More information

Outline Capital Investment Strategy

Outline Capital Investment Strategy Outline Capital Investment Strategy INDEX FOREWORD 1. INTRODUCTION 2. PURPOSE 3. SUMMARY 4. INFLUENCES ON CAPITAL INVESTMENT 5. CURRENT CAPITAL EXPENDITURE 6. COMMERCIAL PROPERTY INVESTMENT STRATEGY 7.

More information

Perpetual s Risk Management Framework

Perpetual s Risk Management Framework Perpetual s Risk Management Framework Perpetual s Risk Management Framework Context Perpetual Limited (Perpetual) is a diversified financial services firm, listed on the Australian Securities Exchange.

More information

Enterprise Risk Management Program

Enterprise Risk Management Program Enterprise Risk Management Program David W Sundvall, Risk Manager 3/2/2016 Page 0 of 12 Table of Contents Introduction... 2 Approach... 2 Risk Appetite... 3 Roles and Responsibilities... 3 Process... 4

More information

Risk Management Plan PURPOSE: SCOPE:

Risk Management Plan PURPOSE: SCOPE: Management Plan Authority Source: Vice-Chancellor Approval Date: 16/05/2018 Publication Date: 17/05/2018 Review Date: 17/05/2021 Effective Date: 16/05/2018 Custodian: General Counsel and University Secretary

More information

Kidsafe NSW Risk Management Plan. August 2014

Kidsafe NSW Risk Management Plan. August 2014 Kidsafe NSW Risk Management Plan August 2014 Document Control Document Approval Name & Position Signature Date Document Version Control Version Status Date Prepared By Comments Document Reviewers Name

More information

Risk Management. Webinar - July 2017

Risk Management. Webinar - July 2017 Risk Management Webinar - July 2017 Compiled by: Raaghieb Najjaar, Yaeesh Yasseen & Rashied Small Adapted and Facilitated by: Professor Enslin J. van Rooyen Risk Management - June 2017 2 Defining Risk

More information

Risk Management Policy Adopted by:

Risk Management Policy Adopted by: Risk Management Policy Adopted by: Infigen Energy Limited Infigen Energy (Bermuda) Limited Infigen Energy RE Limited in its capacity as Responsible Entity of Infigen Energy Trust Adopted: 17 December 2009

More information

RISK MANAGEMENT FRAMEWORK

RISK MANAGEMENT FRAMEWORK RISK MANAGEMENT FRAMEWORK 1. INTRODUCTION (Company) acknowledges that risk is inherent in its business. The Company s risk management framework is an important tool to guide the organisation towards achieving

More information

Financial Management in the Department for Children, Schools and Families

Financial Management in the Department for Children, Schools and Families Financial Management in the Department for Children, Schools and Families LONDON: The Stationery Office 14.35 Ordered by the House of Commons to be printed on 28 April 2009 REPORT BY THE COMPTROLLER AND

More information

Fundamentals of Project Risk Management

Fundamentals of Project Risk Management Fundamentals of Project Risk Management Introduction Change is a reality of projects and their environment. Uncertainty and Risk are two elements of the changing environment and due to their impact on

More information

RISK MANAGEMENT FRAMEWORK

RISK MANAGEMENT FRAMEWORK Risk Management Framework RISK MANAGEMENT FRAMEWORK Purpose This Risk Management Framework introduces St. Michael s College s approach to risk management. It includes a definition of risk, a summary of

More information

Risk Management Policy and Strategy

Risk Management Policy and Strategy Risk Management Policy and Strategy Version: 2.1 Bodies consulted: Approved by: Directors and Managers responsible for risk Board of Directors Date Approved: 28 March 2017 Lead Manager: Lead Director:

More information

APPENDIX I: Corporate Risk Register

APPENDIX I: Corporate Risk Register APPENDIX I: Corporate Register The following risk register represents those risks in place at the time of reporting at Quarter 1, the mitigation strategies in place for each risk and the proposed treatment

More information

Policy No. Contact Brian Orpin Version 3.0 Issue Date 28/11/2014 Telephone Review Date IA Date 09/08/2013

Policy No. Contact Brian Orpin Version 3.0  Issue Date 28/11/2014 Telephone Review Date IA Date 09/08/2013 Information Governance Management of Risk Policy Policy No. Contact Brian Orpin Version 3.0 Email Brian.orpin@nhs.net Issue Date 28/11/2014 Telephone 0131 314 5360 Review Date IA Date 09/08/2013 Change

More information

2.2 For Board Members to approve the five high risks the Trust is facing:

2.2 For Board Members to approve the five high risks the Trust is facing: HEREFORD HOSPITALS NHS TRUST PUBLIC BOARD MEETING 28 TH JANUARY 2011 COMPANY SECRETARY S REPORT NICOLA.LICENCE@HHTR.NHS.UK BOARD ASSURANCE FRAMEWORK 1.0 INTRODUCTION 1.1 The attached Board Assurance Framework

More information

Risk Management Policy. September 2015

Risk Management Policy. September 2015 Risk Management Policy September 2015 Contents Policy Statement... 3 AA s Commitment to Risk Management... 3 Risk Management Principles... 4 Governance Framework... 6 Roles and Responsibilities... 7 Board...

More information

RISK MANAGEMENT POLICY

RISK MANAGEMENT POLICY RISK MANAGEMENT POLICY TABLE OF CONTENTS PAGE 1. BACKGROUND 3 2. MATERIAL BUSINESS RISK 3 3. RISK TOLERANCE 4 4. OUTLINE OF ARTEMIS RESOURCE LIMITED S RISK MANAGEMENT POLICY 5 5. RISK MANAGEMENT ROLES

More information

GRINDROD SOUTH AFRICA//Policy Risk and opportunity governance framework

GRINDROD SOUTH AFRICA//Policy Risk and opportunity governance framework Document number GP24 Revision number 02 Issue date 23 May 2017 Author name Andrew Davies Approval Risk Committee 02 CONTENTS 1 Purpose 04 2 Objective 04 3 Risk and opportunity governance policy 04 4 Governance

More information

South Lanarkshire College Risk Management Policy and Procedures

South Lanarkshire College Risk Management Policy and Procedures 1. Purpose This policy and its procedures detail and communicate the College s approach to risk management. 2. Policy Statement South Lanarkshire College will effectively manage risk, taking all reasonable

More information

Procedure: Risk management

Procedure: Risk management Procedure: Risk management Purpose To outline the procedures involved for identification, assessment and management of risks. Procedure Introduction 1. This procedure outlines the University s Risk Awareness

More information

West Coast District Municipality. Risk Management Policy

West Coast District Municipality. Risk Management Policy West Coast District Municipality Risk Management Policy TABLE OF CONTENTS Page No. RISK MANAGEMENT POLICY 5 1. OVERVIEW 6 1.1. Policy Objective 6 1.2. Policy Statement 6 1.3. Risk Management Approach 6

More information

1.1. This document forms the Council s Risk Management Strategy. It sets out:

1.1. This document forms the Council s Risk Management Strategy. It sets out: 1. Introduction Bovey Tracey Town Council RISK MANAGEMENT STRATEGY 1.1. This document forms the Council s Risk Management Strategy. It sets out: - What is risk management - Why the Council needs a risk

More information

Effective Assurance Frameworks

Effective Assurance Frameworks Effective Assurance Frameworks NIGEL IRELAND, HEAD O F BARCUD S HARED S E R VICES @ barcudss w w w.barcudsharedservices.org.uk Today What an Assurance Framework is How an Assurance Framework can add value

More information

RISK MANAGEMENT POLICY. Head of Corporate Development and Change. Policy owners

RISK MANAGEMENT POLICY. Head of Corporate Development and Change. Policy owners POLICY RISK MANAGEMENT Policy owners Policy holder Author Head of Corporate Development and Change Risk and Policy Manager Head of Corporate Development and Change/ Programme Manager/ Risk and Policy Manager

More information

BERGRIVIER MUNICIPALITY. Risk Management Risk Appetite Framework

BERGRIVIER MUNICIPALITY. Risk Management Risk Appetite Framework BERGRIVIER MUNICIPALITY Risk Management Risk Appetite Framework APRIL 2018 1 Document review and approval Revision history Version Author Date reviewed 1 2 3 4 5 This document has been reviewed by Version

More information

Risk Management Strategy

Risk Management Strategy Risk Management Strategy Job title of lead contact: Corporate Services Manager Version number: Version 1 Group responsible for approving Executive Team / Governing Body the document: Date of final approval:

More information

Risk Management Policy

Risk Management Policy Risk Management Policy October 2014 Risks 1. Risks can be identified under four principal headings a. Financial risks b. Strategic Risks c. Operational Risks, and d. Hazard Risks 2. These are either externally

More information

An Introductory Presentation for ECU Staff

An Introductory Presentation for ECU Staff Risk Management at ECU An Introductory Presentation for ECU Staff Phillip Draber Manager, Risk and Assurance Outcomes By the end of this session you should: Be able to complete and document risk management

More information

PILLAR 3 DISCLOSURES MERCER UK AUGUST 2016

PILLAR 3 DISCLOSURES MERCER UK AUGUST 2016 PILLAR 3 DISCLOSURES MERCER UK AUGUST 2016 CONTENTS 1. Background... 1 1.1 Basis of Disclosures... 2 1.2 Frequency of Publication... 2 1.3 Verification... 2 1.4 Media & Location of Publication... 2 2.

More information

Topic RISK MANAGEMENT Procedure Category Risk Management Updated 07/2011

Topic RISK MANAGEMENT Procedure Category Risk Management Updated 07/2011 Topic RISK MANAGEMENT Procedure 07.01 Category Risk Management Updated 07/2011 RELATED POLICIES, PROCEDURES AND FORMS Policies Procedures Forms Risk Management Policy Code of Conduct Public Interest Disclosure

More information

Discussion. Information

Discussion. Information Item 10.8 To: From: Trust Board Kevin Turner, Deputy Chief Executive Date: 4 th July 2017 Title: Strategic Risk Management Report Responsible Director: Kevin Turner, Deputy Chief Executive Author: Karen

More information

D7 Risk Management Policy

D7 Risk Management Policy D7 Risk Management Policy Purpose and scope The aim of Kelda s policy is to establish and embed effective risk management in normal business process and culture. This will improve Kelda s ability to predict

More information

Guide. Risk Management For Community Service Organisations

Guide. Risk Management For Community Service Organisations Guide Risk Management For Community Service Organisations April 2010 Contents 1. Managing risk in community services... 3 1.1. What is risk management?... 3 1.2. Managing risk is about knowing your objectives...

More information

CITY OF JOHANNESBURG METROPOLITAN MUNICIPALITY GROUP RISK AND ASSURANCE SERVICES GROUP RISK MANAGEMENT POLICY

CITY OF JOHANNESBURG METROPOLITAN MUNICIPALITY GROUP RISK AND ASSURANCE SERVICES GROUP RISK MANAGEMENT POLICY CITY OF JOHANNESBURG METROPOLITAN MUNICIPALITY Effective Date 1 July 2015 TABLE OF CONTENTS 1. POLICY STATEMENT... 3 2. POLICY CONTEXT... 4 3. PURPOSE... 5 4. POLICY SCOPE AND APPLICATION... 6 5. RISK

More information

NOTTINGHAM CITY HOMES. THE BOARD REPORT OF Ian Rabett Head of Health & Safety 26 November 2015

NOTTINGHAM CITY HOMES. THE BOARD REPORT OF Ian Rabett Head of Health & Safety 26 November 2015 ITEM 9 NOTTINGHAM CITY HOMES THE BOARD REPORT OF Ian Rabett Head of Health & Safety 26 November 2015 RISK MANAGEMENT 1 SUMMARY 1.1 A review of our risk management arrangements was carried out earlier this

More information

RISK MANAGEMENT FRAMEWORK

RISK MANAGEMENT FRAMEWORK RISK MANAGEMENT FRAMEWORK 1. INTRODUCTION (Company) acknowledges that risk is inherent in its business. The Company faces a broad range of risks as a listed entertainment organisation. The Company s risk

More information

POLICY RISK MANAGEMENT AND REPORTING. Introduction

POLICY RISK MANAGEMENT AND REPORTING. Introduction POLICY RISK MANAGEMENT AND REPORTING Introduction Managing risk is a part of our everyday responsibilities for all of us. It enables us to make decisions about what we do and how we do things both strategically

More information

University Risk Management Policy

University Risk Management Policy Preamble University Risk Management Policy Approving Authority: Board of Governors Original Approval Date: June 7, 2007 Date of Most Recent Review/Revision: October 20, 2017 Responsible Officer: Vice-President

More information

Risk Management & Assurance Strategy. Audit Committee. See reference page 38

Risk Management & Assurance Strategy. Audit Committee. See reference page 38 BHH Brent Harrow Hillingdon Clinical Commissioning Groups Risk Management & Strategy Author: Policy Number: Version: Sponsor/Executive: Responsible committee: Gilbert George Dawn Crump Interim Head of

More information

Board Risk Appetite Statement

Board Risk Appetite Statement SH NCP 62 Version: 3 Summary: Keywords (minimum of 5): (To assist policy search engine) Target Audience: This document establishes the key areas of risk and guidance on the level of risk the Board is prepared

More information

Risk Management Framework Policy (incorporating the Risk Management Policy and Strategy)

Risk Management Framework Policy (incorporating the Risk Management Policy and Strategy) Corporate Risk Management Framework Policy (incorporating the Risk Management Policy and Strategy) Document Control Summary Status: Version: Replacement. Replaces: Management of the Assurance Plan and

More information

RISK AND BUSINESS CONTINUITY MANAGEMENT

RISK AND BUSINESS CONTINUITY MANAGEMENT RISK AND BUSINESS CONTINUITY MANAGEMENT EFFECTIVE: 18 MAY 2010 VERSION: 1.4 FINAL Last updated date: 29 September 2015 Uncontrolled when printed 2 Effective: 18 May 2010 CONTENTS 1 POLICY STATEMENT...

More information

RISK REGISTER POLICY AND PROCEDURE

RISK REGISTER POLICY AND PROCEDURE RISK REGISTER POLICY AND PROCEDURE Lead Manager: Head of Clinical Governance Responsible Director: Board Medical Director Approved by: Date Approved: Date for Review: Feb 2012 Replaces Version: 1.0 Page

More information

28 July May October 2016

28 July May October 2016 Policy Name Risk Management Policy & Procedure Related Policies and Legislation AISWA Guidelines Risk Management Policy Category Planning & Management Relevant Audience Date of Issue / Last Revision All

More information

Risk Management Policy

Risk Management Policy Risk Management Policy Date Published 6 th July 2016 Version 1 Approved Date 6 th July 2016 Review Cycle Annually Review Date June 2017 Learning together; to be the best we can be 1. Introduction 1.1.

More information

An Update On Association Policies, Health Checks & Guidelines To A Safer Hockey Association. Lauren Woods Member Engagement & Operations

An Update On Association Policies, Health Checks & Guidelines To A Safer Hockey Association. Lauren Woods Member Engagement & Operations An Update On Association Policies, Health Checks & Guidelines To A Safer Hockey Association Lauren Woods Member Engagement & Operations Association Health Checks Issues arising from the health check: 3/27

More information

Policy Number Functional Field. Governance and Management. Related Policies. Policy of Making University Policies.

Policy Number Functional Field. Governance and Management. Related Policies. Policy of Making University Policies. Policy Title Risk Management Policy Policy Number -0 Functional Field Related Policies Responsibility of Issuing Office Governance and Management Policy of Making University Policies Risk Management Office

More information

SOL PLAATJE MUNICIPALITY

SOL PLAATJE MUNICIPALITY RISK MANAGEMENT AND INTERNAL CONTROL Approved As Per Resolution CR 500 dd 17-11-05 INDEX 1. INTRODUCTION 2. PURPOSE AND SCOPE 3. OBJECTIVE OF THE RISK POLICY 4. RISK MANAGEMENT FRAMEWORK 5. ACCOUNTABILTY

More information

British Library Risk Management Policy Framework (2017)

British Library Risk Management Policy Framework (2017) Risk Management Policy Framework May 2017 1 British Library Risk Management Policy Framework (2017) 1. Introduction The Library defines risk as being the quantifiable level of exposure to the threat of

More information

Main Sections. Corporate Risk Policy Statement and Procedures AR-RMD-CR01. Executive Summary. Anglia Ruskin University Risk Management

Main Sections. Corporate Risk Policy Statement and Procedures AR-RMD-CR01. Executive Summary. Anglia Ruskin University Risk Management Corporate Risk Policy Statement and Procedures AR-RMD-CR01 Executive Summary This document is intended to assist Anglia Ruskin University, its subsidiaries and Joint Ventures in controlling business risks,

More information

RISK MANAGEMENT PROCEDURE GUIDANCE

RISK MANAGEMENT PROCEDURE GUIDANCE RISK MANAGEMENT PROCEDURE GUIDANCE East and North Hertfordshire Clinical Commissioning Group Page 1 of 25 DOCUMENT CONTROL SHEET Document Owner: Director of Nursing and Quality Document Author(s): Company

More information

INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS

INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS Guidance Paper No. 2.2.x INTERNATIONAL ASSOCIATION OF INSURANCE SUPERVISORS GUIDANCE PAPER ON ENTERPRISE RISK MANAGEMENT FOR CAPITAL ADEQUACY AND SOLVENCY PURPOSES DRAFT, MARCH 2008 This document was prepared

More information

Section Defining Risk Management. 11. Principles of Risk Management

Section Defining Risk Management. 11. Principles of Risk Management Section 2 10. Defining Risk Management Enterprise risk management is the process, affected by an entity's board of directors, management and other personnel, applied in strategy setting and across the

More information

ก ก Tools and Techniques for Enterprise Risk Management (ERM)

ก ก Tools and Techniques for Enterprise Risk Management (ERM) ก ก Tools and Techniques for Enterprise Risk Management (ERM) COSO ERM ISO ERM 31 2554 10:45 12:15.. 301, 302, 307 ก ก COSO Internal Control ERM Integrated Framework Application Technique ISO 31000 Guide

More information

Risk Management Procedure

Risk Management Procedure Risk Management Procedure 2017 Number: Date Written: Authorised by: Review Date: Version 4.0 15 December 2016 Bernie Wilson 30 December 2018 Contents Amendment and Review... 2 Document Control / Amendments...

More information

Risk Management Policy

Risk Management Policy DYNAMIC ARCHISTRUCTURES LIMITED Risk Management Policy DYNAMIC ARCHISTRUCTURES LIMITED Regd. Address: 409, Swaika Centre, 4A Pollock Street, Kolkata - 700001 (West Bengal) CONTENTS Sr. Particulars Page

More information

Risk Management Policy

Risk Management Policy Risk Management Policy Date First Published June 2016 Version 3 Date Last Approved 20 th June 2018 Review Cycle 1 Year Review Date June 2019 Learning together; to be the best we can be 1. Introduction

More information

RISK AND OPPORTUNITY ASSESSMENT GUIDE RISK CRITERIA

RISK AND OPPORTUNITY ASSESSMENT GUIDE RISK CRITERIA RISK AND OPPORTUNITY ASSESSMENT GUIDE RISK ASSESSMENT GUIDE TABLE OF CONTENTS 1. PURPOSE... 3 2. SCOPE... 3 3. RELATED DOCUMENTS... 3 4. PROCEDURE... 3 5. RISK MANAGEMENT PROCESS... 3 6. STEP 1 RISK ANALYSIS...

More information

Meeting of Bristol Clinical Commissioning Group Governing Body

Meeting of Bristol Clinical Commissioning Group Governing Body Meeting of Bristol Clinical Commissioning Group Governing Body To be held on Tuesday 30 June 2015 commencing at 13:30pm at the Greenway Centre, 119 Doncaster Road, BS10 5PY Title: Risk Appetite Statement

More information

RISK MANAGEMENT POLICY October 2015

RISK MANAGEMENT POLICY October 2015 RISK MANAGEMENT POLICY October 2015 1. INTRODUCTION 1.1 The primary objective of risk management is to ensure that the risks facing the business are appropriately managed. 1.2 Paringa Resources Limited

More information