Integrated Risk Management: Implementation Guide
Integrated Risk Management: Implementation Guide
Risk
Management
Implementation
Guide
© Her Majesty the Queen in Right of Canada,
represented by the President of the Treasury Board, 2004
Implementation
Guide
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Table of Contents
Introduction .................................................................................... 1
Overview of the IRMF .................................................................... 3
iii
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
3. Practising Integrated Risk Management .......................... 37
The Fundamentals........................................................................ 38
How to Do It ............................................................................... 38
Questions to Consider .................................................................. 44
Examples ..................................................................................... 44
Appendix A
Who Does What in Implementing Integrated
Risk Management ..................................................................... 69
Appendix B
A Common Risk Management Process .......................................... 71
Appendix C
Common Risk Management Model ............................................... 81
Appendix D
Sample Templates for Identifying, Assessing,
Recording, and Reporting Risk Information ............................... 83
Appendix E
Sample Risk Identification Lists..................................................... 87
Appendix F
TBS Management Accountability Framework –
Risk Management Expectations ................................................. 93
iv
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Introduction
This guide is a companion to the Government of Canada’s Integrated Risk Management
Framework (IRMF) of April 2001. It is intended for use with the IRMF in
implementing integrated risk management in a federal organization.
The Independent Review Panel highlighted a new philosophy for comptrollership. The
philosophy combines a strong commitment to four key components: performance
reporting (both financial and non-financial); sound risk management; the application
of an appropriate system of control and reporting; and values and ethics. The vision
for modern comptrollership is that management decisions, at every level, integrate risk
management, financial and non-financial performance information, appropriate
controls, and values.
With regard to risk management, the panel report highlighted the need to:
£ ensure that employees are risk-attuned (not only in identifying, but also in
managing risks);
1
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
In June 2003, TBS released the Management Accountability Framework (MAF), which
continues the emphasis on corporate risk management. A key expectation of the MAF is
that the executive team clearly defines the corporate context and practices for managing
organizational and strategic risks proactively as part of achieving management
excellence. The MAF presents indicators and measures for risk management and the
other expectations placed on modern public service management.
This guide recognizes that managers have many roles and responsibilities. Managers
are expected to achieve specific results, while taking into account numerous competing
demands. The IRMF and this guide support managers by emphasizing results and
priority setting while promoting approaches and tools that build on existing
management systems and practices. In fact, a primary aim of integrated risk
management is to improve results through more informed strategic and operational
decisions that contribute to achieving an organization’s overall objectives.
2
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Overview of the IRMF
This section provides an overview of the concepts, purpose, and expected results of the
IRMF, offering readers a basic understanding of the underlying risk management
concepts and the linkages among the IRMF’s four elements. Individuals new to the
subject are encouraged to read the framework, available on the TBS risk
management Web site at [Link] Practitioners and risk
champions already familiar with the IRMF may choose to go directly to the sections
on implementing the framework’s four elements.
There are three critical concepts that are cornerstones of the IRMF: risk, risk
management, and integrated risk management. The IRMF adopted the following
descriptions, developed for the Public Service of Canada in the context of the IRMF
and explained in the framework in greater detail:
Risk refers to the uncertainty that surrounds future events and outcomes.
It is the expression of the likelihood and impact of an event with the
potential to influence the achievement of an organization’s objectives.
Risk management is a systematic approach to setting the best course
of action under uncertainty by identifying, assessing, understanding,
acting on, and communicating risk issues.
Integrated risk management is a continuous, proactive, and
systematic process to understand, manage, and communicate risk
from an organization-wide perspective. It is about making strategic
decisions that contribute to the achievement of an organization’s
overall corporate objectives.
The framework provides guidance on adopting a more holistic approach to managing
risk, emphasizing four related elements: Developing the Corporate Risk Profile;
Establishing an Integrated Risk Management Function; Practising Integrated Risk
Management; and Ensuring Continuous Risk Management Learning. More detail can
be found in the IRMF and throughout this guide.
3
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
The expected results for the four elements are summarized below:
4
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
The IRMF also presents a risk management model that lets managers
assess where a particular risk falls in terms of likelihood (low,
medium, or high) and impact (minor, moderate, or significant) and
determine the level and nature of response necessary to manage the
risk. This model is reproduced in Appendix C. (See Exhibit 3 from
the IRMF.)
Element 4: Ensuring Continuous Risk Management Learning
Synopsis: A supportive work environment is established where
learning from experience is valued and lessons are shared; learning
plans are built into the organization’s risk management practices;
results of risk management are evaluated to support innovation,
learning, and continuous improvement; experience and best practices
are shared internally and across government.
5
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
About This Guide
This guide provides practical advice to those leading and facilitating implementation of
integrated risk management in their organizations. It will be useful as well in increasing
understanding and collaboration where needed. Risk champions familiar with the
IRMF can look to the guide for what to do next. The guide is also a reference tool for
assessing progress and identifying gaps in organizations where integrated risk
management is already underway.
The guide’s focus is integrated risk management, not risk management. Much material
is available on various aspects of risk management (project, financial, health and safety,
etc.), more than could even be usefully summarized in this guide. The guide section on
Element 3 therefore focusses, as its title suggests, on “practising integrated risk
management.” For material on risk management in specific circumstances, readers are
directed elsewhere (e.g. to the appendices, references, and the TBS Web site).
1 The mandate of the Implementation Council is to advance the implementation of the IRMF across the
federal government. The Implementation Council is composed of representatives of departments and
agencies whose deputy heads have agreed to be IRMF implementation leaders. Members of the
Implementation Council include Agriculture and Agri-Food Canada, Canada Customs and Revenue
Agency, Citizenship and Immigration Canada, Environment Canada, Fisheries and Oceans Canada,
Human Resources Development Canada, Indian and Northern Affairs Canada, Industry Canada,
National Defence, Natural Resources Canada, Royal Canadian Mounted Police, Transport Canada,
Treasury Board of Canada Secretariat, and Veterans Affairs Canada. At the time of writing this guide,
Health Canada, the Immigration and Refugee Board, and Public Works and Government Services
Canada were not formal members of the Council but nevertheless have been actively engaged in
implementing integrated risk management in their organizations.
6
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Structure and Format
Following the introductory material and tips for getting started, the guide is divided
into four sections, reflecting the four elements of the IRMF:
1. Developing the Corporate Risk Profile;
2. Establishing an Integrated Risk Management Function—Integrating Risk
Management into Existing Decision–making Processes and Reporting;
3. Practising Integrated Risk Management; and
4. Ensuring Continuous Risk Management Learning.
For ease of reference, these sections contain common sub-sections offering practical
advice and examples. The sub-sections are as follows:
Also at the end of the guide is an overview chart summarizing the steps in
implementing an integrated approach to risk management within an organization.
It describes key requirements and decisions for the critical stages in the process.
Following the overview are summaries of what and how for establishing each IRMF
element—practices and techniques for what organizations have done or need to do
to develop and implement the particular element.
7
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
8
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Getting Started—Committing and
Sustaining Senior Management Support
This is about building the will and capacity for change—leading the initiative and
managing the change.
Expected Results
£ Organizational readiness is assessed—understanding the organizational culture and
the workforce’s capacity for change, in light of the organization’s mandate and
resources.
£ Key risks (threats and opportunities) in achieving overall corporate objectives are
considered initially by an executive forum from an organization-wide perspective;
senior management discusses roles and approaches to address the risks collectively.
£ A senior management risk champion is identified who can exercise strong leadership
to inspire and manage the required change and who believes in the value of
integrated risk management and has a clear vision of how it links to corporate
objectives.
For example, consider the concepts and strategies outlined in Changing Management
Culture: Models and Strategies to Make It Happen (TBS, March 2003). The paper
focusses on modern comptrollership, but its approach is generic and can be applied to
any attempt to change management culture in support of modernizing and enhancing
excellence in the Public Service. As well, The Conference Board of Canada’s report,
9
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Integrating Risk Management Through a Change Management Process (2001), shows
how change initiatives progress through a series of steps. It describes how change
management can be a valuable guide to developing, implementing, and maintaining
an integrated risk management program tailored to the organization.
Also recognize that there will be start-up costs (time, attention, training, systems, and
communications) until the practice becomes an integral part of departmental planning
and business processes.
2 An assessment tool known as The Capacity Check is available to departments and agencies to
perform a self-assessment of current capabilities relative to modern comptrollership management
practices. Risk management is one of seven key areas assessed. This baseline assessment,
involving interviews with executives and managers, allows for the identification of priority areas for
improvement (e.g. processes, competencies, systems, etc.).
10
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
appreciate the interdependencies and connections among the different types of risk—
the source and level of control of the risk and the opportunities to innovate within the
boundaries of responsible risk-taking.
It will help for senior managers to be familiar with the Integrated Risk Management
Framework, as well as risk management reports and guidance developed by the Privy
Council Office and the Canadian Centre for Management Development (CCMD).
Risk awareness can also be raised by briefings, seminars, and retreats and by formal
courses, such as those offered by CCMD.
For information on which to base briefings for the executive team, departmental
officials may wish to consult the TBS Risk Management Centre of Expertise about the
concepts contained in the IRMF, the thinking around integrated risk management and
the state of implementation government-wide. It is also important to seek information
from other departments and agencies or other external sources that have similar
interests or operating environments.
The most effective lead for implementing integrated risk management is certainly at the
deputy head level, but it is also common to place the lead in a corporate function at the
assistant deputy head level, for example, in the strategic or business planning unit or
corporate services branch. The risk champion is not a figurehead. Implementing
integrated risk management involves major change requiring significant leadership
capacity to show the value of change and inspire enthusiasm and support for a
common vision.
11
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Time and effort are needed to gain momentum, provide training for managers and
specialists, and establish good tools and processes. Consider an initial investment in
start-up to support the champion with appropriate resources, such as time at the
executive table, people, and funds. For example, a group of specialists can be formed to
provide expertise and promote a systematic approach to the process of integrating risk
management. This can begin where the expertise resides (e.g. finance or internal audit)
and migrate as appropriate (e.g. to strategic planning). The group can provide
direction and co-ordination for integration with corporate planning and priority
setting, along with guidance for common processes to set priorities among major risk
areas, allocate resources, and conduct a corporate-level environmental scan.
Organizations without an internal source of expertise on integrated risk management
often collaborate with an external consultant or practitioner.
A new or existing executive forum chaired by the deputy head can direct and sustain
integrated risk management by considering corporate risk issues, approaches, and
performance. Organizations do this by making integrated risk management a key
agenda item for an existing committee chaired by the deputy head or by convening
the executive committee as a departmental risk management committee. First
discussions are an opportunity to get a sense of the senior management team’s risk
culture and knowledge and for the risk champion to take stock of where alliances can
be created and where more work is needed to ensure a common understanding,
purpose, and goals. As the organization’s practice matures, discussion will move toward
implementation strategy and progress in light of the organization’s key high-risk areas.
The departmental audit committee, in its broad oversight role, could also review
departmental risk management strategies and practices.
To support the executive team in its decision-making and advisory roles, larger
departments typically create or use an existing department-wide working group (director
general, director, or senior officer levels) to propose and advise on corporate approaches,
implementation plans, systems, and practices. This is an opportunity to raise awareness
in the organization and communicate the importance of the practice, while improving
horizontal linkages, enhancing team spirit, and creating collective ownership.
12
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Assessing Organizational Readiness and Roles
Existing Knowledge and Systems. Consider whether existing committees, systems, and
processes can be used (executive and operational committees, planning and reporting
processes). Some organizations already have a common risk management language
and framework or parts of it. Consider whether people are using a common language
13
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
and process and build on existing understanding of risk or risk management. It may be
helpful to transfer such knowledge and skills. Put the current culture and system to the
acid tests: Is risk management factored into policies and advice to ministers? Does
failure to address risk management prevent plans from being approved?
The risk champion leads preparation of the departmental or agency action plan. Since
implementation progresses in phases of focussed effort, with each phase providing
significant information and requiring key decisions, the plan is updated and detail
added as implementation progresses.
In collaboration with the IRMF Implementation Council, TBS has developed the
Illustrative Template for Developing Action Plans for Federal Departments and Agencies
Implementing the Integrated Risk Management Framework. The template builds on the
Modern Comptrollership Action Plan template and is available on the TBS risk
management Web site. It proposes an action plan consisting of six sections:
1. context and background;
2. approach and priorities;
3. alignment with the IRMF;
4. accountability for integrated risk management;
5. challenges; and
6. implementation plan time frame.
As outlined in the following paragraphs, the action plan should provide direction,
consider the challenges commonly encountered in implementation, and identify the
areas where focussing first efforts is most useful.
14
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
management implementation. Directions should be consistent with existing decision-
making processes and structures and establish and communicate implementation goals
(and timelines, where appropriate). Create opportunities for input as documents
providing direction are being developed and use a common risk management language
and consistent messages in all communications.
15
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
First Areas of Focus. Organizations beginning integrated risk management find it
most useful to focus initial efforts in three areas.
selected for the champion. The risk £ Attempting to quantify all risks the first time.
management message is
communicated throughout these
organizations through key corporate and strategic planning processes.
Business and operational plans, viewed through the lens of integrated
risk management, recognize risks, incorporate measures to avoid
adverse consequences, and embrace opportunities for innovation.
Building Capacity. Providing tools and training based on the analysis
and results of the corporate risk profile are important ways to
strengthen risk management capacity and communicate expectations
and direction.
16
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
1. Developing the Corporate
Risk Profile
Developing a corporate risk profile involves taking stock of the organization’s operating
environment and its capacity to deal with key high-level risks linked to achievement of
corporate objectives.
Expected Results
£ Threats and opportunities are identified and adjusted through ongoing internal and
external environmental scans and analysis.
£ Current status of risk management within the organization is assessed—
challenges/opportunities, capacity, practices, culture—and recognized in planning to
manage organization-wide risks.
£ The organization’s risk profile is identified—key corporate risk areas, stakeholders’ risk
tolerance, ability and capacity to mitigate risk, and learning needs.
To develop the profile, risk information at both the corporate and operational levels is
analyzed to understand the key characteristics of the broad range of internal and external
risks facing the organization. Senior management attention is focussed on a manageable
number of risks (five to ten) in the context of the organization’s mandate, objectives,
available resources, and capacity for integrated risk management. In managing key risks,
decision makers must also take into account risk tolerances of key stakeholders.
17
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
back into departmental strategic planning documents and processes. In a mature practice
of integrated risk management, a robust strategic and business planning process should
assimilate the corporate risk profile, eliminating the need to present it separately.
The Fundamentals
£ support the risk champion by providing a clear mandate for the development
of the corporate risk profile;
£ ensure that the corporate risk profile is linked in a meaningful way to corporate
priority setting and resource allocation exercises;
£ be aware that the contents of the profile are evergreen: the profile and process
must be dynamic and respond to changes (e.g. major events such as those of
September 11, 2001, significantly influenced key high-level risks for several
departments); and
18
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
How to Do It
19
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
This may require separate briefings of individuals or consideration at several meetings,
depending on factors such as the team’s comfort level with the integrated risk
management concept and the anticipated benefits of developing the corporate
risk profile.
£ what integrated risk management is, including the four interrelated elements;
£ the benefits of integrated risk management in general and specifically for
the organization in terms of advancing its priorities (how the organization
and its executive team will benefit in the short term and be better positioned
for the future);
£ what information needs to be collected to develop the corporate risk profile, how
this will be done, and what will be done with the information collected; and
£ key roles, reporting relationships, and timelines for development of the profile.
Most organizations can build the corporate risk profile using existing sources. For
example, existing information and/or data collection mechanisms can help guide
development of the corporate risk profile.
These internal and external factors and risks are identified through an environmental
scan or preliminary data collection and analysis. Major trends and changes to them over
time are particularly relevant in providing early warning of potential risks that may
adversely affect departmental outputs and ultimately objectives, results, and outcomes.
The IRMF provides several suggestions about risk identification techniques, such as
brainstorming, scenario planning, and surveys. Other sources of risk information include
audit reports, performance reports, and other management information systems.
20
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Internal Scan
The following sources provide insights that may help to determine the state of the
organization in terms of what is at risk and types and sources of risk (threats,
opportunities, strengths, and weaknesses).
For additional data collection or surveys, an interview guide or model that classifies
or groups risk areas (identification of what is at risk, types and/or sources of risk,
a ranking scale and methodology) will facilitate consolidation and analysis of
information collected. Data can be organized by program, business line, discipline or
functional area, geographic location, type of risk, sources of risk, or a combination of
these and other relevant categories.
The following activities could supplement the information gathered from the sources
already discussed:
£ Seek key managers’ assessments of risk areas, ranking of the risks from highest
to lowest priority, and how the risks are currently being managed.
21
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
External Scan
Understanding the organization’s risk universe helps identify and assess key high-level
risks for the corporate risk profile. External factors to be considered include the
political, economic, social, and technological environments, as well as trends and
changes that could influence the conduct of the organization’s activities or achievement
of its objectives. The interests and risk tolerance of key external stakeholders are also
important considerations in developing the risk profile and establishing the
organization’s risk tolerance(s).
Consider the following in understanding the organization’s risk tolerance level and that
of its key stakeholders:
22
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
£ the organization’s performance expectations and actual performance;
£ how the organization or stakeholders have reacted to past risk events and issues;
£ formal or informal mechanisms to track, report, and act on performance;
£ employees’ understanding of the risks taken by themselves, their team or group
and the department;
The following diagram presents risk tolerance in relation to the cost of managing
to different levels of risk.
Risk magnitude
Risk cannot be
Intolerable justified except in
extraordinary
Region circumstances
L
E
V
E As Tolerable only if risk
L reduction is impracticable
Low or if its cost is greatly
O disproportionate to
F As the improvement gained
R
I Reasonably
S Tolerable if cost of
K Practicable reduction would exceed the
improvements gained
23
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Assess Current Risk Management Capacity
It is important to identify the nature, adequacy, and usefulness of existing organizational
tools, techniques, human resources skills, and expertise for managing risk.
By taking stock of the risk management tools and techniques now in use, as well as the
risk management skills available in the organization, it will be possible to assess the
state of risk infrastructure in terms of organizational stability and system capacity.
Management must ensure that this infrastructure is capable of supporting the
organization’s current and anticipated integrated risk management needs.
Each member of the executive committee should rank the key high-level risks by
priority and be prepared to explain the ranking and linkages to corporate objectives
and other risks. Anonymous voting technology or similar approaches can be used to
rank risks. Based on the discussion, the executive committee can decide on the
corporate ranking of risks and determine the steps the organization will take to
manage the risks. These steps should be informed by the findings of the environmental
scan, the organization’s capacity to manage risk, and stakeholders’ risk tolerance, as
well as the management team’s knowledge and experience.
In developing the initial risk response, the organization should ideally seek to engage
key stakeholders in dialogue to gain their support for the proposed steps. The
organization should attempt to strengthen and ensure a common understanding of
the possible options and trade-offs and seek stakeholders’ help in formulating plans
that contribute to the achievement of organizational objectives to the greatest
extent possible.
The results of the risk assessment and ranking must be linked to the department’s
priority setting and resource allocation processes so that management attention and
resources flow to the highest risks.
24
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Portray the Corporate Risk Profile
The final step is to produce a document depicting the corporate risk profile. It sets out
the results of the environmental scans, risk assessment, and analysis and identifies areas
requiring corporate decisions or direction regarding risk management strategies.
Organizations have developed various ways to present results, including matrices, risk
maps, and reports with summaries by risk area. The reader may find it useful to refer
to the sample risk map reproduced in Appendix D.
Questions to Consider
Ask the following questions to confirm that the organization is achieving the expected
results of developing a corporate risk profile.
1. Are the key high-level risks for the department identified?
2. Is there evidence that the deputy head and departmental executive are
engaged and committed to corporate risk profile development and related
action? (That is, have they made it a departmental priority? Have start-up
resources been allocated? Will findings be linked to decision-making
processes, including priority setting and resource allocation exercises?)
3. In determining the initial departmental response and action to manage key
high-level risks, has consideration been given to the risk tolerance of key
stakeholders and is senior management mindful of the organization’s capacity
to manage such risks? (Are employees aware of risk management theory and
practices? Are systematic risk management processes already being applied
and can the organization leverage this knowledge and expertise? Do
employees have the necessary knowledge, skills, and tools to manage risks
within their areas of responsibility?)
25
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Examples
£ the identification and description of internal and external risks that significantly
influence the achievement of the organization’s objectives (key risk areas);
£ systematic methods of managing risk for the priority target risk units.
The corporate risk profile also sets out an organization-wide view of risk tolerances
and how they are communicated to managers and employees. The department’s
executive board reviews all components of the profile annually.
26
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Use of a Corporate Risk Profile
One department, with a significant regional presence in program delivery, depends on
its corporate risk profile to explain how its two types of risk (inherent risks arising
from its department’s mandate and risks arising from the changing operating
environment) interact dynamically to affect the achievement of business objectives.
The corporate risk profile is also intended to inform staff and stakeholders about
the following:
£ the prevailing departmental perspective on inherent risks (key risk areas) arising
from the mandate;
The corporate risk profile is updated annually and approved by senior management.
Recently, all regions and sectors of this department have been asked to identify two
projects and/or programs where risk tools could be applied beneficially. In doing so,
regions and sectors are required to review their risks. In 1998 and again in 2000, all
senior managers were interviewed and asked to identify their top risks. In 2002, there
was an identification of areas where risk would be applied and an operational planning
exercise involving a ‘SWOT’ assessment (strengths, weaknesses, opportunities, and
threats) for each region and sector. The results covered operations and business lines
within each region or sector.
27
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Another department undertakes an extensive environmental scanning process at the
start of each annual planning cycle. This scan is intended to provide intelligence and
context for setting priorities as well as planning and decision making over the next
year. Such a broad scan allows for consistent analysis of horizontal trends across sectors
and regions and provides an important vehicle for reaching consensus within the
department on key trends (political, economic, social, and technical), opportunities
and threats that could influence the department.
One of the smaller departments uses environmental scanning to identify internal and
external risks, which supports the development of risk profiles for each of the business
lines. The risk profiles and scan results are integrated into a corporate risk profile and
then discussed by the departmental senior executive committee at a strategic planning
retreat. The environmental scanning is conducted under the co-lead of their strategic
planning and corporate services groups. To get started more quickly, the department
decided on a simple approach, avoiding overly elaborate methodology. This learning-
by-doing approach is expected to build organizational commitment and result in a
more integrated set of tools.
Many other examples exist among lead implementation departments. The TBS risk
management Web site links readers with updated information on progress in these and
other federal organizations.
28
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
2. Establishing an Integrated Risk
Management Function—Integrating Risk
Management into Existing Decision-
making Processes and Reporting
Integrated risk management means establishing appropriate infrastructure by building
on what exists.
Expected Results
£ Management direction on risk management is communicated, understood, and
applied—vision, policies, and operating principles.
£ Integrated risk management is operationalized through existing decision-making
structures: governance, clear roles and responsibilities, and performance reporting.
£ Building capacity—learning plans and tools are developed for use throughout the organization.
The Fundamentals
29
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Integrated risk management becomes a key agenda item for executive committees,
helping to communicate senior management commitment throughout the
organization. Demonstrating executive commitment promotes staff engagement at all
levels in a risk management culture and helps ensure a common understanding of
what integrated risk management entails. Leading by example, senior managers raise
awareness and communicate the importance of the practice, while improving
horizontal linkages, enhancing team spirit, and creating collective ownership. This
helps sustain integrated risk management when corporate-wide risk issues, approaches,
and performance are considered.
The deputy head and risk champion must ensure support by managers at various
levels who will legitimize and sanction implementation of integrated risk management
with their words and actions. The champion speaks authoritatively about integrated
risk management in the context of achieving corporate objectives and is an
enthusiastic and knowledgeable supporter. The champion will be most effective by
leading, supporting, and broadly communicating benefits and reporting progress.
The corporate risk profile (Element 1) provides fundamental guidance for establishing
an integrated risk management function. A key component of the profile is the
assessment of the readiness of the organization’s governance, decision-making and
accountability structures, and mechanisms. The profile allows senior management to
make strategic plans for expanding capacity in terms of human resources, tools, and
processes at both the corporate and the local level.
How to Do It
Clarifying who, what, and how is the first step in creating the groundwork for
integrated risk management. Four key actions are involved in establishing the function
and integrating risk management into existing decision-making systems:
30
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Establish a Corporate Focus for Risk Management
Integrated risk management requires a corporate focus, whether an existing structure
or a new one. The groundwork may have been laid in action plans for getting started
and in developing the corporate risk profile. The following steps can help establish a
corporate focus for risk management.
One or more working groups should also be established to support the executive
forum with cross-functional and organizational analyses of corporate risk issues.
31
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
The corporate risk champion should be supported with appropriate resources; this
might include specialists to provide expertise on and a systematic approach to the
process of integrating risk management. The champion will also need time at the
executive table to sustain the focus on integrating risk management as a priority in the
organization’s culture.
32
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
This network of interested individuals can assist senior management in developing
work plans that reflect a corporate perspective on risk-related issues. It is also an
appropriate channel for communicating implementation concepts and timing
throughout the organization.
Aligning risk management vision and objectives with corporate objectives and strategic
direction helps make risk management meaningful and relevant to all employees. As
implementation progresses, individuals should come to understand managing risk as
part of their daily work, not something superimposed on their usual activities.
Acceptance of the concepts of integrated risk management will be commensurate with
the extent that the organization has been successful in establishing and using common
risk terminology in corporate tools and documentation.
Throughout the strategic planning process, the risk champion or specialist group
should act as a catalyst in guiding both the process and the officials involved.
Corporate planners must drive the process by integrating risk awareness and thinking
to support senior managers in carrying out corporate-wide planning, priority setting,
and resource allocation.
Assessing and building on existing capacity helps tailor the approach to deal with the
department’s or agency’s specific situation and risk exposure. Guidance and advice can
be sought as required from the TBS Centre of Expertise and through liaison with other
federal organizations to share their lessons learned.
33
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Human Resources
The IRMF identifies four principal areas that may require attention in building human
resources capacity:
£ increasing the knowledge base by sharing best practices and experiences; and
£ building capacity, capabilities, and skills to work in teams.
34
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Questions to Consider
1. Is there a designated departmental risk champion or unit to oversee the
implementation of integrated risk management?
2. Is risk management communicated, understood, and applied throughout
organizational processes? Is risk management integrated into existing governance
and decision-making structures and performance-reporting systems? Have risk
assessments been conducted for proposed business process or program innovations?
3. Have control and accountability systems been adapted to account for risk
management processes? Have key performance indicators and critical success
factors been identified and included in departmental reports? Does reporting on
risk and risk management take place through existing management processes
(e.g. performance reporting, ongoing monitoring, appraisals, internal auditing)?
4. Is there sufficient capacity to manage risk within the organization? Has the
department put in place effective initiatives to build risk management awareness?
Have employee workshops been run to disseminate risk management knowledge
and techniques? Do the managers make use of knowledgeable resources in the
types of issues they are facing?
Examples
Important lessons can be learned from the experiences of lead departments and
agencies that belong to the IRMF Implementation Council.
Success Factors
One lead department has identified eight factors that contributed to its success in
establishing an integrated risk management function:
1. Create a supportive environment.
2. Ensure commitment to the IRM concept.
35
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
3. Have a designated group of specialists.
4. Be prepared to make the necessary initial investment in integrated risk
management infrastructure.
5. There must be clear but distributed responsibility for integrated
risk management.
6. The organization must have senior management reporting requirements.
7. Ensure appropriate corporate planning and priority-setting processes.
8. Implementation of the integrated risk management function should
be scalable.
Working Groups
One department established an ADM-level departmental risk committee with the deputy
minister’s approval. As well, a risk management working group was established at the
management level with representation from all sectors. Its principal mandate is to foster
organization-wide risk awareness and attentiveness, to promote achievement of a risk-
smart organization, and to train local champions within business lines. The working
group gives sectors a forum for discussion; advises on initiatives to develop a
department-wide risk program; makes recommendations to the departmental risk
committee; and shares lessons learned and informs sectors of risk management activities.
36
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
3. Practising Integrated
Risk Management
Practise integrated risk management up, down, and across the organization for a full
picture in a way that makes sense for the organization.
Expected Results
£ A departmental risk management process is applied consistently at all levels so that
risks are understood, managed, and communicated.
£ Results of risk management practices at all levels are integrated into informed
decision making and priority setting—strategic, operational, management, and
performance reporting.
£ Tools and methods are applied as aids to decision making.
£ Consultation and communication with stakeholders is ongoing—internal and external.
37
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
The Fundamentals
The logical, commonsense, and intuitive nature of the process allows this to occur
smoothly as long as there is sustained commitment from employees, with direction
from senior management. Hence, organizations will be ready to practise integrated risk
management when the corporate culture has achieved the following:
£ sufficient capacity has been achieved as a result of developing and providing the
necessary guidance, tools, and staff training for integrated risk management.
How to Do It
38
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Engage the Whole Organization
When working well in mature practice, integrated risk management is seamless. For
initial implementation, it helps to think of three levels of practice: corporate
(organization-wide, highest level), business line (major functional area or unit), and all
other areas (programs, major projects, activities, and processes). Some approaches
characterize these levels as strategic, management, and operational or use other terms
suited to their situation. Some organizations may include additional levels or
categories, for example, they may consider programs and major projects separately.
No matter what terms are used, organizations find a layered perspective useful in
describing and carrying out integrated risk management. At the highest corporate level,
risk management results and key corporate risks are aggregated in the corporate risk
profile to inform an organization-wide strategy for managing risk to achieve corporate
objectives. The corporate risk profile generally derives from business line risk profiles
developed at the next level below the corporate level, that is, in branches and functional
units, typically led by assistant deputy ministers or, in smaller departments and agencies,
directors general or executive directors. The third or operational level is the lowest level
of risk assessment and aggregation. Results from this level are fed into business line and
corporate risk profiles. People working at the operational level know their operations
and risks best and are positioned to take any action required. Their involvement and
input are therefore essential in gaining access to their knowledge, ownership, and action.
39
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
common language in presenting or feeding their results into the corporate view so that
results are meaningful and useful across business lines. Better communication and
understanding increase the value of one unit’s work to other units and reveal links or
the previously unrecognized need for links.
The risk management specialist or working group and local change sponsors work
with or advise managers to ensure appropriate fit of the process with particular
local requirements.
The risk champion or specialist group provides overall direction and co-ordination for
integrating risk management with corporate planning and priority setting. Use the risk
management committee or working group as a sounding board and information source.
Local risk champions or change sponsors lead and facilitate alignment throughout the
organization, working to make the important micro-level changes to all polices and
local procedures, daily activities, processes, and systems.
£ Build risk assessment and response into local business plans at the activity,
division, and regional level.
40
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Decision makers and specialists have distinct roles in implementing integrated risk
management: decision makers need to understand their responsibilities and place a
premium on integrated analysis and advice, while specialists must understand
operations and provide relevant and credible information and analysis. To ensure that
the right information is available at the right time for value-based, results-oriented
decisions, information must be brought together from many sources; this in turn
requires partnership between specialists and decision makers.
The accompanying diagram was adapted from an approach used by Indian and
Northern Affairs Canada. It illustrates the point that risk management in general and
the application of the decision-making process in particular do not occur in isolation.
They take place in the context of and can inform and
be informed by continuing operational activities
at all levels of the organization.
Individual
Factors
Group
Factors
Organizational
Factors
Environmental
Factors
41
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Individual Factors: elements of
Knowledge Management
an individual’s experience,
• Is core knowledge captured and
personality, background, and related to strategic priorities and
preferences that affect his or her linked to key risk areas?
propensity to take risks • Is there timely access to the “people
in the know” for better re-use and
Group Factors: how others in creation of knowledge?
the immediate situation can affect • Is technology used to maximize flow
an individual’s willingness to take and know-how?
a risk • Is there a culture of trust that
supports the sharing of knowledge
Organizational Factors: the with knowledge associates and
direct and indirect messages an senior champions?
Enable People
Enable people to practise risk management locally in a way that informs and is
informed by organization-wide integrated risk management.
A risk management model (such as the IRMF model reproduced in Appendix C) can be
used to assess where a particular risk falls in terms of likelihood (low, medium, high)
and impact (significant, moderate, minor). The results of the risk assessment help
determine the risks of highest importance. The model can also be used to ascertain or
facilitate discussion of risk tolerance by establishing a zone defining acceptable and
unacceptable risk. Finally, the model can be used to present a summary map of risks—
plotting each risk’s likelihood and impact—for purposes of comparison or ranking.
42
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Using a common approach not only facilitates the process but supports comparability
when results are aggregated and considered at the corporate level.
Approaches and methods that are easy to understand are more likely to be used
correctly. Consider existing tools or those available from professional associations;
employees may already be familiar with them or find them useful in other contexts.
43
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Questions to Consider
1. Has the organization adopted a common process for risk management? Is there
a common understanding of risk and risk management in the organization?
Is a common risk management language being used?
2. How are risk management tools and methods being applied to decision-making?
What risk management tool kits are available (e.g. checklists, maps, electronic
questionnaires, and best practices)? Do they make use of existing guidance, such as
the Values and Ethics Code for the Public Service (2003)? Are they being used
effectively and consistently? Have scenario analysis and/or forecasting models been
used to understand various scenarios relating to business and contingency planning?
3. Do all business and operational plans consider risks and incorporate measures to
mitigate those risks and/or to maximize opportunities? Are systems and processes
in place to monitor risks and the effectiveness of risk mitigation strategies?
Is management accountable for risks and risk management processes?
4. Are processes in place to support regular communication with stakeholders
on risks, risk perception, and risk tolerances?
Examples
Appendix D provides sample templates for identifying, assessing, recording, and
reporting risk information. Additional examples are available on or through links at
the TBS Web site and more will be added as they become available.
44
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
4. Ensuring Continuous Risk
Management Learning
Continuous risk management learning is about leveraging and building on existing
knowledge and capacity to achieve the desired cultural shift to a risk-smart workforce
and operating environment.
Expected Results
£ Learning from experience is valued, lessons are shared—a supportive
work environment.
£ Learning plans are built into the organization’s risk management practices.
£ Results of risk management are evaluated to support innovation, capacity building,
and continuous improvement at the individual, team, and organizational level.
£ Experience and best practices are shared internally and across government.
The Fundamentals
45
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
£ Value exploratory learning and experimentation, particularly where the
anticipated benefits of success outweigh the cost of failure.
£ Invest in the power of knowledge; instead of fearing the unknown, find a way to
make it known. Good information is critical to good decisions. Teach the basics.
Promote conscious management and employee commitment to developing risk
management skills and to developing, applying, and refining risk management
tools (develop plans and invest in building risk management capacity at
organizational and individual levels).
46
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
in associations or institutes; processes and tools used by other departments; and
employee deployments to develop skills and knowledge.
In terms of sharing best practices, departments and agencies can explore mechanisms
for encouraging risk management learning. For example, individuals in your
organization are likely to have and be willing to share ideas about understanding and
managing risk. Organizations can use existing vehicles or establish new mechanisms to
communicate, share, and facilitate access to such knowledge. Effective processes and
means to share best practices might include your organization’s risk management
working group, the intranet/Internet, learning events, information sessions, a
newsletter, and publications to share specific lessons learned about risk management or
integrated risk management.
47
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Questions to Consider
Examples
48
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
In addition to departmental efforts, TBS is contributing to continuous risk
management learning. For example:
The TBS Risk Management Directorate (RMD) has established a Web site and an
IRMF Implementation Council to facilitate the sharing of risk management
information broadly across the Public Service. RMD has organized and will continue
to organize and participate in learning events and venues that contribute to building
risk management awareness, knowledge, and capacity.
RMD and the TBS Comptrollership Modernization Directorate (CMD) have worked
collaboratively with CCMD and Training and Development Canada to develop risk
management learning products (courses, workshops, e-learning, armchair sessions).
CMD has also established a Web site to facilitate sharing of departmental practices on
comptrollership modernization, including risk management. In addition, as part of its
social marketing initiative, CMD has published testimonials on leading practices on
risk management.
49
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
50
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
An Overview and
Summary of What
and How for
Establishing Each
Element of
the Integrated Risk
Management
Framework
51
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Developing and Implementing
Integrated Risk Management:
an Overview
Getting Started—Commit and Sustain Senior Management Support
The deputy head and senior management set the tone. To build the will and capacity for implementation,
they must understand integrated risk management and its contribution to achieving corporate objectives.
Their engagement signals organizational commitment, while their active, continuing support is vital to
success.
£ Discuss organizational readiness, roles, and approaches at the executive table to gain
commitment to lead and manage the necessary change. Executives’ risk awareness can be raised
through briefings, retreats, workshops, and courses.
£ Assign a senior executive risk champion to lead and facilitate development of implementation
plans and guidance on integrating risk management with existing decision making.
£ Create or use an existing executive forum for risk management chaired by the deputy head;
consider an organization-wide working group to propose and advise on corporate approaches, plans,
systems, and practices.
£ Develop and communicate an action plan for implementing integrated risk management and
report on progress.
Understand the operating environment—threats and opportunities, strengths and weaknesses—to help set
strategic direction for integrated risk management. Take stock to create a corporate snapshot of key risks
and the capacity to deal with them.
£ Conduct internal and external environmental scans to identify and assess types and sources of
risk and what is at risk, taking into account interdependencies in risk areas cutting across the
organization and significant individual events or activities.
£ Understand risk tolerance to appreciate what sorts of risks and levels of risk stakeholders are
willing to accept.
£ Assess current risk management capacity (i.e. the usefulness of existing organizational tools,
techniques, skills, expertise, and resources for managing risk) to determine current abilities to control
risks and to identify gaps.
£ Develop the initial risk response by identifying mitigating strategies and consulting and refining
the results of the scan and response.
£ Portray the corporate risk profile (i.e. the results of the scan, assessment and response) in ways
useful to stakeholders, including top management. For example, present a one-page risk map and
snapshots by headquarters and regions, business lines, and programs.
Establish and communicate organizational direction and infrastructure, building on what exists.
£ Establish a corporate focus using existing structures or building new ones under the guidance of
an executive forum, with initial resources for mobilization and a designated corporate risk champion.
52
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
£ Communicate corporate direction throughout the organization. The risk champion leads the
development of written guidance, such as an integrated risk management policy or framework and
operating principles, to support individual units in building risk management into day-to-day
operations. Identify and provide guidance on roles and responsibilities, program targets, critical
success factors, performance measures, and sources and kinds of risk; make this guidance available on
the organization’s intranet.
£ Integrate risk management with existing decision-making structures in a seamless fashion.
Establish a common risk language and process or model; align the approach with corporate planning;
show how it supports the organization’s objectives.
£ Build organizational capacity. Identify risk management skills, processes, and practices that need
to be developed and strengthened; build on existing capacity, tailoring it as needed.
Manage risks at the organizational level and in functional units, programs, projects, activities, and
processes.
£ Engage the whole organization. Align integrated risk management fully with objectives in all policies,
plans, and operations. Encourage active leadership of the deputy head and champion, as well as
executive discussion of corporate and business-line risk profiles. Feed integrated risk management
plans and results into corporate planning and priority-setting processes.
£ Enable people with processes, tools, and techniques, making available effective and proven resources
and tools.
£ Sustain the initiative by building a supportive culture and processes that develop participation,
trust, and swift action on issues; continue to show executive support, devoting time in planning and
operational meetings; keep the corporate risk profile current; report on performance; document risks,
processes, decisions, plans, actions, and results.
£ Consult and communicate with internal and external stakeholders throughout the process.
Ensure Continuous Risk Management Learning
Create and maintain a supportive work environment for evaluation, feedback, and sharing of lessons.
Support innovation and encourage learning for people and processes at the individual, team, and
organizational levels.
£ Cultivate a supportive work environment. Show management commitment to learning by linking
learning to the departmental strategy and priorities; value knowledge, new ideas, new relationships, and
experimentation; get the incentives right by building in rewards and recognition; celebrate success
stories and significant contributions.
£ Build capacity. Build risk management into employee learning plans and learning plans into risk
management practices; leverage external learning; develop courses and provide learning events on
departmental approaches; include a range of perspectives (those of stakeholders and citizens) in
decision making; actively seek input and feedback as a basis for further action.
£ Learn from experience. Monitor, evaluate, and adjust systems, processes, and practices; document
and share lessons and best practices internally and externally; encourage learning from experience
rather than assigning blame.
53
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Summary of What and How for Establishing Each
Element of the Integrated Risk Management Framework
Getting Started—Commit and Sustain Senior
Management Support
Build the will and capacity for change—lead the initiative and manage the change.
What How
What your department or agency has There are a variety of ways to do it. Try these proven
already done or needs to do: techniques.
The executive team discusses • Brief and train senior management to gain
organizational readiness, roles, understanding and commitment, using internal
and approaches to get the expertise or in collaboration with an external
commitment to lead and manage practitioner, implementation leader, or consultant.
the necessary change. Managers • Consider executive retreats, seminars, workshops,
need to believe in the value of and formal courses.
integrated risk management.
• Encourage awareness of the IRMF and available
material from the Privy Council Office, CCMD,
and departments.
• Initial discussion of readiness, key factors (other
corporate initiatives and priorities, location of the risk
champion, etc.).
The deputy head assigns a risk • A risk champion at the deputy head level is most
champion, with appropriate effective; it is also common and effective to place the
resources, who leads the lead in a corporate function, at the assistant deputy
development and implementation of head level, such as strategic and business planning or
an integrated risk management corporate services.
framework and policy or guidance. • Invest in start-up—the champion is supported with
The risk champion role reflects employee(s) and funds. Effort is required to gain
the need for central co-ordination momentum, ensure training of managers and
and advice. specialists, and establish good tools and processes.
• Designate a group of specialists to provide expertise
and promote a systematic approach to the process of
integrating risk management. Begin where some
expertise resides (e.g. corporate services) and migrate
as necessary (e.g. to strategic planning).
• With the champion, the group can provide direction and
co-ordination for integration with corporate planning and
priority setting and for common processes to set priorities
among major risk areas and to allocate resources, as well
as for a corporate-level environmental scanning process.
54
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
The deputy head establishes and • Create a separate executive forum or use an existing
chairs a forum for risk management one, such as the departmental executive committee.
to build the will and capacity for • Demonstrate personal commitment and engagement.
implementation, to manage the The executive committee is useful to drive progress by
change, and for ongoing establishing events with and requiring reports to this
consideration of risk issues, most senior management level.
implementation approaches, capacity,
• Emphasize that deputy and senior executives must
and performance.
be willing to take ownership. Although it is centrally
co-ordinated, responsibility is clear and distributed, since
corporate risks are often managed by business line.
• Establish a representative, cross-functional working
group to propose and advise on corporate
approaches, plans, systems, and practices.
Assess organizational readiness • Use results of the modern comptrollership capacity
and roles to prepare for this major check and the organizational response/plan.
change initiative that will require an • Ask fundamental questions: how will integrated risk
investment of time and resources over management (IRM) help us meet our objectives, how
the longer term. do we ensure success, how will employees react?
• Apply high-level assessment tools to assess general
readiness: change models, organizational assessment
processes, cultural maps and surveys, situational
analysis tools, focus groups (see sources in the
Selected References section of this guide).
• Borrow and use the practices of change management.
• Use departmental or agency lessons learned and tools
already developed (e.g. Human Resources
Development Canada’s IRM benchmarking and
diagnostic tool).
• Use the risk management committee or working group
as a sounding board and information source.
• Hold sessions with management and other
stakeholders, using outside facilitators.
• Consult external sources and advisors.
• Use reference libraries (e.g. TBS, Risk and Insurance
Management Society—RIMS).
Develop and communicate an • Prepare an action plan (TBS template available).
action plan for implementing • Plan for scalable implementation. IRM will likely
integrated risk management, based progress in stages; consider pilots.
on the assessment of readiness
• Have a strategy to move from pilots to full-scale
and roles.
integration to help keep implementation on track over
longer periods.
55
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
• Use the organization-wide risk management
framework self-assessment tool.
• Establish cross-functional advisory groups.
• Target and support early adopters whose acceptance
and demonstration of tangible benefits will engender
support from other management teams.
• Develop partnerships with others, e.g. change
sponsors (business line leaders) to keep IRM a priority
and change agents to implement the change in all
policies and daily activities, systems, and processes.
• Build in training and learning plans.
• Provide examples and benchmarks from similar
outside organizations, as follows:
– use reference libraries (TBS, CCMD, Conference
Board of Canada, RIMS);
– see the TBS Progress Review Plan for progress
indicators and tracking approaches; and
– use self-assessment tools (see Selected References).
56
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Developing a Corporate Risk Profile
The corporate risk profile is a snapshot of the organization’s operating environment
and its capacity to deal with key high-level risks linked to the achievement of corporate
objectives and results.
What How
What your department or agency has There are a variety of ways to do it. Try these
already done or needs to do: proven techniques.
Plan and Prepare
Engage senior management in • Brief and train senior management on integrated risk
corporate risk profile development, management and seek input and endorsement of the
including the development of a process model to develop the corporate risk profile.
process model. • The process model should include some basic
classification of risk areas and a rating scale; possible
categories of risk include health and safety;
financial/economic; social; environmental; operational;
public trust and confidence; asset; project; liability;
security; IT; HR; political).
• Use internal expertise to develop a process model or
develop it in collaboration with an external practitioner
or consultant.
• Benchmark the organization’s risk management status.
• Assess relevance of other approaches to
your organization.
Use the guiding departmental • Use the executive forum or committee to guide
forum or committee. development of the corporate risk profile.
• Consider use of a working group to support the
executive committee.
57
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Internal Scan
• Review results of the modern comptrollership capacity
check and the corresponding action plan.
• Review strategic planning documents, audit
observations, and recommendations.
• Consider performance reports and information.
• Review the policy framework.
• Consult with corporate planning, policy, audit, and
evaluation groups.
• Reach out to branch, program, business line, and
functional executives and key managers.
• Consider the use of interviews, surveys,
questionnaires, focus groups, and/or facilitated
sessions.
• Consider collecting risk data by program, business
line, discipline or functional area, geographic location,
type of risk, sources of risk, or a combination of these
and other relevant categories.
External Scan
• Consider media monitoring and public opinion research.
• Establish advisory groups, boards, or councils.
• Solicit input from consumer groups (users of programs
or services).
• Review the government’s policy agenda, including
the Speech from the Throne.
• Benchmark organizational status against that of
other departments.
• Review Statistics Canada survey results to
establish trends.
• Consult with think tanks, associations, as well as
interest and lobby groups.
Consider the following to collect the required information:
• Use the internal scanning services of an existing
corporate function (e.g. the corporate
communication group).
• Consult an external service provider for media
monitoring or research services.
• Consider targeted or omnibus survey or questionnaire.
• Make use of electronic bulletin boards, what-if
scenarios, and facilitated workshops to seek the
reaction of stakeholders.
• Develop focus test and pilot approaches to target
particular markets or geographic areas.
58
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Understand risk tolerance. Consider the following:
• Review the policy framework (governing instruments,
acts, regulations, etc.).
• Review performance expectations and
performance results.
• Determine employees’ understanding of the risks
taken by themselves, their team, and the department.
• Determine whether there is a common understanding
of risk tolerance.
• Consult key stakeholders to gain a better
understanding of their risk tolerance.
Assess current risk management • Identify risk management tools and techniques now in
capacity. use and where.
• Determine the level of human resources expertise in
risk management (current knowledge and skills).
• Assess infrastructure, i.e. organizational stability and
capacity of systems.
Develop the risk response. • Analyze information collected (environmental scan,
capacity to manage risk, and stakeholders’ risk
tolerance) and present an aggregate picture to the
executive committee for consideration.
• The executive committee collectively assesses the
broad spectrum of risks facing the organization in
terms of likelihood and impact on achievement of
corporate objectives.
• The executive committee decides on five to ten key
high-level risks that need to be managed at the
corporate level.
• The executive committee ranks key high-level risks
and determines steps the organization will take to
manage these risks.
• Seek to engage key stakeholders to garner support
for planned steps.
Portray the corporate risk profile. • Consider incorporating corporate key risk and related
information into departmental documents (strategic
plan, performance reports, etc.).
• Think of developing a separate document to list
corporate key risks and related information and
mitigation measures.
59
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Establishing an Integrated
Risk Management Function—Integrating
Risk Management into Existing
Decision–making Processes and Reporting
Set up an organizational infrastructure—the why, what, who, and how—to position risk
management as integral to organizational strategy and operations. Use the corporate risk
profile to shape risk management objectives and strategies that align with the organization’s
objectives. Build in risk management so that it becomes part of day-to-day efforts to achieve
objectives and is not seen as an additional requirement.
What How
What your department or agency has There are a variety of ways to do it. Try these proven
done or needs to do: techniques.
Establish a corporate focus for risk • Situate integrated risk management under the
management, using existing guidance of a high-level executive forum chaired by
structures or building new ones. the deputy head.
• Dedicate an initial investment of resources for
mobilization.
• Designate a corporate risk champion and provide
appropriate support in terms of executive time and
specialist resources.
• Give integrated risk management an appropriate
corporate focal point from which natural linkages can
be built to functional areas.
60
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
• Use a network of local risk champions as a sounding
board, information source, and channel for
communicating corporate risk messages.
Integrate risk management into • Establish a common risk language (such as what is
existing decision-making structures meant by risk, risk management, legal risk
in a seamless fashion. management) and use it consistently in organizational
guidance and documents.
• Establish a common risk management process.
• A goal of the process is to make risk management an
integral part of business practices, so that employees
do not see it as additional work.
• Align the approach with corporate planning. The risk
champion or specialist group provides direction and
co-ordination for integration with corporate planning
and priority setting, for common processes to set
priorities and allocate resources among major risk
areas, and for a corporate-level environmental
scanning process.
• Use the representative, cross-functional working group
to propose and advise on corporate approaches, plans,
systems, and practices, including resource allocation.
61
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Practising Integrated Risk Management
Implement flexible, dynamic approaches and processes to embed risk management in
policies, plans, operations, and day-to-day decision making. Practise risk management
up, down, and across the organization so the corporate view informs and is informed
by local practices.
What How
What your department or agency has There are a variety of ways to do it. Try these proven
done or needs to do: techniques.
Engage the whole organization by Guided by the corporate risk profile and the direction
aligning integrated risk management provided in establishing the integrated risk
fully with objectives in all policies, management function:
plans, and operations and integrating • The risk champion or specialist group provides
results of risk management into direction and co-ordination for integration with
practices at all levels. corporate planning and priority setting and for
common processes to set priorities and allocate
resources among major risk areas and for a
corporate-level environmental scanning process.
• Align with objectives at all levels so that people
can see the benefits individually and collectively
and how they contribute—this also clarifies and
improves accountability.
• Alignment is done or facilitated by local champions or
change sponsors who work to make the important
micro-level changes to all policies, local procedures,
daily activities, processes, and systems.
• Use the risk management committee or working group
as a sounding board and information source.
Enable people with processes, tools, • Use the common risk management process to identify,
and techniques, making available assess, respond to, monitor, and evaluate risk.
effective and proven resources • Encourage people to assess the ripple effects of
and tools. their work.
• Use a common risk management language to
facilitate communication.
• Provide training tools to enhance knowledge of risk
management, including common risk management
processes and special processes, such as control and
risk self-assessment.
62
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Sustain a supportive culture and • Active leadership of the deputy head, risk champion, and
build processes that develop senior managers, e.g. one-on-one discussion of key risks
participation, trust, and swift action between the deputy head and ADM/business line leaders;
on issues. collective executive discussion of corporate and business
line risk profiles; senior managers actively show
commitment and support by devoting time in planning and
operational meetings.
• Use the representative, cross-functional working group
to propose and advise on corporate approaches,
plans, systems, and practices.
• Keep the corporate risk profile current.
• Report on performance (e.g. against risk management
expectations in key performance indicators, employee
performance agreements, and work descriptions).
• Document risks, processes, decisions, plans, actions,
and results.
Consult and communicate with • Use the organization’s intranet to promote risk
internal and external stakeholders awareness and tools and to obtain and share risk
throughout the process. information, e.g. on risk in specific areas.
• Aim specific risk messages at target audiences—think
“What’s in it for me?” for every person or group.
• Understand and communicate effectively to the public
that risk—whether seen as good, bad or neutral—is
inherent and government needs to manage risk to get
a net reward.
• Make use of organizational reports to advance risk
messages, e.g. how risk is being managed.
• Respect the Communications Policy of the
Government of Canada.
63
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Ensuring Continuous
Risk Management Learning
Leverage and build on existing knowledge and capacity to achieve the desired cultural
shift to a risk-smart workforce and operating environment.
What How
What your department or agency has There are a variety of ways to do it. Try these proven
done or needs to do: techniques.
64
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Selected References
and Appendices
65
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Selected References
Many integrated risk management and risk management resources, sources, examples,
and case studies are available on the TBS Web site ([Link]/rm-gr) in the
form of documents or links to other Web sites. Selected references follow.
Federal Government
Auditor General of Canada. April 2003 Report, in particular, the Auditor General’s Message
and Chapter 1—Integrated Risk Management. Available online at [Link].
£ Risk Management for Canada and Canadians: Report of the ADM Working Group
on Risk Management (March 2000).
£ Values and Ethics Code for the Public Service (2003). Available at
[Link]/veo-bve.
66
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
£ Putting it all Together: Leading Practices and Testimonials of Modern
Comptrollership, in particular, risk management case studies, pages 47–70.
(March 2003). Available at [Link]/cmo_mfc.
67
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Canadian Standards Association
Risk Management: Guideline for Decision-Makers, CAN/CSA-Q850-97 (October 1997).
Other Governments
Australia/New Zealand
Documents available through the Standards Australia portal at
[Link]:
£ HB 143:1999 Guidelines for managing risk in the Australian and New Zealand
public sector. A Joint Australian/New Zealand Handbook prepared by Joint
Technical Committee OB/7—Risk Management, Standards Association of
Australia, ISBN 0 7337 2815 4.
68
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Appendix A
Elements/Results in Implementing Deputy Heads or Equivalent and Senior Corporate Risk Champion/Focal Point Ma
Integrated Risk Management Management
Getting Started—Committing and Commit—build the will and capacity for change, lead the initiative, and manage the chang
Sustaining Senior Management
Support (Commit)
Expected Results: Assess organizational readiness. Become or stay current to talk Par
knowledgeably about integrated risk rea
£ Organizational readiness is assessed. Place integrated risk management on
management in the context of achieving
the executive team agenda; give it time Con
£ Key risks are considered initially by an corporate objectives.
at the executive table. aw
executive forum.
Raise executives’ risk awareness.
Assign a risk champion. Be
£ Roles and approaches to address risks are Lead and facilitate development and
discussed collectively by senior Demonstrate commitment and
dissemination of implementation plans
management team. support to create momentum across
and necessary guidance.
the organization.
£ A senior management risk champion
is identified.
Developing the Corporate Risk Profile Think strategically—take stock of the organization’s operating environment and its capaci
(Think)
Expected Results: Set strategic direction. Lead development of the corporate risk Con
profile or work with corporate planners thre
£ The organization’s risks are identified Consistently challenge assumptions.
in leading its development. ana
through environmental scanning.
Encourage managers to renew inte
£ The current status of risk management in their perspectives, keep their
the organization is assessed. analysis current.
I N T E G R A T E D R I S K M A N A G E M E N T
nagement
d Responsibilities.
rticipate in assessing organizational Advise on and participate in assessment Understand and be open to upcoming
diness. of organizational readiness. change.
ntribute to organization’s risk Support managers in their role as
areness. agents of change.
agents of change.
ty to deal with the key high-level risks linked to achievement of its objectives.
ntribute to environmental scan, Help managers identify and assess risk Stay aware of and attentive to risk
eat and opportunity identification, and effectiveness, efficiency, and management issues.
alysis, and assessment, including economy of existing measures to
ernal risk management capacity. manage risk.
on what exists.
mment and advise on proposed Advise on design and whether the Understand the corporate approach to
proaches and strategies in light of function being established or already establishing the function and contribute
al and corporate systems and established will meet the stated vision to advice on its design and
ues. and objectives. implementation.
derstand and communicate
porate direction and employee/
al advice and issues.
69
I M P L E M E N T A T I O N G U I D E
Practising Integrated Risk Management Act—practise integrated risk management up, down, and across the organization
(Act)
Expected Results: Provide strategic leadership that Facilitate and advise, such as risk
endorses the corporate risk profile, management centre of expertise
£ A common risk management process is strategic and business plans, drives approach, e.g. deal with organization-
applied consistently at all levels.
identification and review of top risks, wide policies and direction, developed b
£ Results of risk management practices at all and models the principles of good or with the units with functional expertis
levels are integrated into informed decision risk management. and to gain acceptance; co-ordinate for
making and priority setting. an overview (trends/changes) and to
Continue to show support, devote time
avoid duplication.
£ Tools and methods are applied. to planning and operational meetings.
70
I N T E G R A T E D R I S K M A N A G E M E N T
n for a full picture in a way that makes sense for the organization.
Systematically identify and manage risk Help managers design and implement Know that you are a risk manager.
strategically in functional units. tools for more effective risk
Understand how you contribute in your
management.
Always know who is managing. area and to the organization.
by
Advise on whether the function is
se Ensure employees are familiar with the Identify and assess risks.
operating as intended, whether it is
r latest risk management guidance.
meeting the stated vision and Report, respond to, monitor, and
Ensure particular risk management objectives, and whether local or evaluate risks as required by your
responsibilities are reflected in systemic changes are required. manager or organization.
employees’ work objectives.
Document decisions and supporting
information.
hieve the desired cultural shift to a risk-smart workforce and operating environment.
Put into operation the necessary Track and report on lessons learned Request and contribute to individual
practices, actions, and events to from corporate and functional learning plans.
achieve the expected results of perspectives.
Document decisions and supporting
continuous learning.
Conduct independent assessments information.
of risk managment strategies
p, and practices.
I M P L E M E N T A T I O N G U I D E
Appendix B
m
skills at all levels of an L
8
m
Con uous
Measuring
organization. The process provides Practise Likelihood
uni
and Impact
common language, guides decision Integrated Risk
Management
3
tin
cation
Implementing
making at all levels, and allows the Strategy From corporate
strategy and plans
organizations to tailor their to front-line
operations,
activities at the local level. people and
Documenting the rationale for
decisions strengthens 7 processes.
Ranking
Risks
Risk Identification
71
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Risk Assessment
Risk Response
6. Developing Options
£ Identify and analyze options (i.e. ways to minimize threats and maximize
opportunities), approaches, and tools.
7. Selecting a Strategy
£ Choose a strategy and apply decision criteria that are results-oriented and
problem- or opportunity-driven.
72
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Monitoring and Evaluation
Organizations can vary the basic steps and supporting tasks most suited to achieving
common understanding and implementing consistent, efficient, and effective risk
management. A focussed, systematic, and integrated approach recognizes that all
decisions involve management of risk, whether in routine operations or for major
initiatives involving significant resources. It is important that the risk management
process be applied at all levels, from the corporate level to programs and major projects
to local systems and operations. While the process allows tailoring for different uses,
having a consistent approach within an organization assists in aggregating information
to deal with risk issues at the corporate level.
Many other common processes for risk management are available, including the
Australian/New Zealand Standard, the Canadian Standards Association’s Q850, and
those of the Software Engineering Institute. (Links to these organizations’ Web sites are
available on the TBS Web site). Regardless of the process, number of steps, or
terminology, all processes cover the same four components:
£ risk identification;
£ risk assessment;
£ risk response; and
£ monitoring and evaluation.
Most models also emphasize the importance of communication throughout
the process.
Risk Identification
Search for and locate risks before they become problems.
Ways to do it
£ brainstorming
£ strength-weakness-opportunity-threat (SWOT) analysis
73
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
£ risk forms/identification sheets
£ surveys and questionnaires
£ interviews and focus groups
Questions to consider
£ What is at risk?
£ What are the major objectives?
£ What are the risks associated with each objective?
£ Who are the stakeholders?
Tips
£ Include contextual information, as well as the risk itself.
£ Multi-disciplinary teams improve the chances of identifying new risks.
£ Open communication and a forward-looking view are key.
£ Include stakeholder risk tolerances, positions, and attitudes.
Risk Assessment
Transform risk data into decision-making information by examining risks in detail to
assess key risk areas, determine the likelihood and impact of the risks, how they relate
to each other, and which are the most important.
Ways to do it
£ Determine the degree of exposure based on likelihood, impact, and time frame.
£ Qualitative methods include brainstorming, evaluation using multi-disciplinary
groups, specialist judgement, structured interviews, and questionnaires.
74
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Tips
£ Assess key risk areas by grouping risks based on shared characteristics, by
source, impact, or some other measure.
£ Impact and likelihood matrices can help visualize all risks together.
£ Consider both the empirical evidence and the public context.
Risk Response
Decide what to do about the risks identified by translating risk information into
decisions and mitigating actions.
Ways to do it
£ Set desired results and define objectives and expected outcomes for ranked
risks over the short and long term.
£ Do not lose sight of the end product when developing mitigation plans.
Ways to do it
£ periodic status reports
£ analysis of trends and patterns
£ reports on performance and results
75
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Questions to consider
£ Based on the effectiveness of the mitigation strategy, has the status of any risk
changed?
76
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Consultation and communication
This is essential in supporting sound risk management decisions and must be
considered at every stage of the risk management process.
Risk Identification
£ Define the issue and identify potential stakeholders.
£ Explore stakeholders’ needs, issues, and concerns.
£ Decide how to communicate with stakeholders.
£ Formulate initial messages and identify a spokesperson.
£ Develop initial briefing material for key officials, as appropriate.
Risk Assessment
£ Research background information on the risk issue and the history of
stakeholders’ concerns.
77
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
£ Anticipate possible incidents, events, or allegations that may arise and plan
responses.
£ adopt a high-visibility strategy in key locations to get the message out and to
respond to public concerns about the action plan;
£ Conduct a formal evaluation and develop contingency plans for the future.
£ Assess the impact of the action plan on affected stakeholders and compare to
what was predicted.
78
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Tips:
£ Common understanding does not necessarily lead to consensus.
£ Credibility and trust take a long time to develop but can be destroyed in an instant.
£ Base all discussions on fact.
£ Independent third-party support enhances credibility.
£ Perceived risk often differs dramatically from objectively measured risk.
£ Communicate early and often.
Departments and agencies have been sharing information on risk communication and
consultation. Readers interested in additional information are directed to the TBS Web
site or individual departmental or agency Web sites. For example, the Canadian Food
Inspection Agency prepared a paper entitled Risk Communication and Government:
Theory and Application for the Canadian Food Inspection Agency (available on-line at
[Link]). The paper, which includes an extensive reference list, was
designed to explore risk communication from a government perspective, including a
review of some of the recent theory on risk communication with a focus on food risk
and science-based communication.
79
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
80
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Appendix C
Other options for displaying key risks in relation to each other on a single page include
risk maps for the whole organization or for a business line or program.
The model can also be used for assessing ideas in the context of opportunity seeking
and innovation or experimentation—the thought being that an organization wants to
make investments appropriate to the likely return on those investments. In this context,
impact and likelihood could be considered by asking questions such as:
81
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
82
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Appendix D
Usually in the form of a table, this simple template is designed to allow managers
to list major risks, or risk sources, often within predefined risk areas or categories.
In most cases, the risk identification template also includes a section on a preliminary
risk assessment. Some more advanced forms may include a likelihood and impact
decision-making model to show a risk rating (i.e. a combination of impact and
likelihood) prior to implementing mitigation strategies (see Appendix C).
2.
3.
4.
5.
83
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Risk Analysis Template
Corporate Risk description Result of likelihood and Risk Existing Additional Manager
objective affected and its impact assessment rating moderation mitigation action responsible
consequences capacity or or strategy
Likelihood Impact capability
84
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Risk Maps
Risk maps are graphic representations of key risks facing an organization at any given
time. Key risks are plotted or superimposed on a matrix depicting their impact and
likelihood or severity and frequency. Risks can be colour-coded to show source,
predefined category, or other considerations (e.g. insured versus uninsured risks) that
may be relevant in the context of a particular organization, business line, or program.
Risks or risk areas are usually numbered or coded to link them to detailed information
in a risk analysis template or risk inventory. Organizations that have identified many
risks may also show the total number of risks in each cell.
Risks identified:
Impact Risk Distribution Economic and Financial
E1 L3 T2 F1 Interest rate
S2 F2 Securities
Significant E2 T1 TF1
F3 Cost of insurance
Environmental
E1 Climate change
T3 E2 Pollution
Moderate E3 Ozone depletion
F3
Legal
L2 S3
L1 Liabilities
L2 Human rights
F2 E3
L1 S1 L3 International agreements
Minor Technological
T1 Nuclear power
T2 Biotechnology
Low Medium High
T3 Genetic engineering
Likelihood
Safety and Security
S1 Invasion
S2 Terrorism
S3 Organized crime
Risks depicted are adapted from the Appendix E lists and shown in no particular order.
85
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Template for Capturing and
Reporting on Risk Information
Objectives at Risk:
■ Brief point-form statement of branch objectives that may not be fully met.
Such shortcomings may result from the challenges identified above and/or
from challenges in implementing the mitigating strategies identified below.
■ Trade-offs made in developing mitigating strategies tend to be made among
these objectives.
Pre-mitigation Considerations:
Assessment
Short, point-form statements of factors that should be taken into
account in making the right trade-offs in developing acceptable
mitigating strategies
Impact
Likelihood
Source: Reproduced from Integrated Risk Management in HRDC (October 2002), Human Resources
Development Canada.
86
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Appendix E
Systemic risks
Environmental Financial
Technological Property
Health Political Operational
and safety
Source: Canadian Centre for Management Development, A Foundation for Developing Risk Management
Learning Strategies in the Public Service (2001)
87
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
88
Potential Sources of Risk
Description of Views Strategic Perspective Business Line Corporate Compliance Government Agenda
or Perspective Perspective Management Perspective Perspective
Perspective
Sources that can impede the Sources that can impede the Sources that may not Sources that could embarrass Sources that are critical to
achievement of mandate and achievement of business line effectively support the the organization or cause ensure alignment with
objectives or program objectives achievement of results liabilities for not complying government-wide
I N T E G R A T E D
with laws and regulations commitments
• • • • •
R I S K
Sources of Risk STRATEGIC BUSINESS LINE CORPORATE COMPLIANCE GOVERNMENT
MANAGEMENT AGENDA
£ policy and strategy £ business line activities £ funding and appropriations
£ corporate reputation £ program activities £ structure and reporting £ statutory reporting £ citizen focus
relationships
£ political factors £ program delivery £ compliance with laws and £ values and ethics
£ planning and priority setting regulations £ accountability
£ public expectations £ client services
£ budgeting and resource £ compliance with central £ transparency
£ stakeholder relations £ service delivery allocation agency policies
£ media relations £ alliances, partnerships £ expenditure management £ responsible spending
£ agreements and contractual £ client satisfaction
£ industry developments £ major projects £ revenue and cost recovery obligations
£ changing demographics
M A N A G E M E N T
£ transfer payments £ workplace health and safety £ Government On-Line
£ globalization £ procurement and contracting £ environmental protection £ improved reporting
£ national security threats £ financial management £ security, privacy and £ modern comptrollership
£ business continuity confidentiality £ fairness and equity
£ performance management legal liabilities and litigation
£ emergency preparedness £ project management £ £ Results for Canadians
£ technology trends £ change management £ modern HRM
£ economic trends £ inventory management £ integrated risk management
£ competitive trends £ asset management
£ human resources
£ information and knowledge
£ information technology
I M P L E M E N T A T I O N
£ communications
£ risk management
Source: Risk-based Internal Audit Priorities Toolset for Small Departments and Agencies (March 2003).
G U I D E
Available at: [Link]
A Sample of Risks Subject to
Government Intervention
Environment Food
£ climate change £ food contamination during
£ air, water, land pollution (e.g. acid production and distribution
rain, urban smog, contaminated £ food labelling
sites) £ pesticide application and residuals
£ forestry practices in food
£ toxic substances £ bovine growth hormone in milk
£ biodiversity and endangered £ irradiation
species £ genetically modified foods
£ fisheries
£ ozone depletion
89
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Occupational Human Safety
£ workplace safety (a) Infrastructure
Adapted from W. T. Stanbury, 2000, unpublished working paper submitted to CCMD Roundtable members.
90
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Umbrella of Risk
Str litical
ge e &
Po
ate
an ral
Ch , Mo :
Cu
le
gic
2
Q sto
S& op
ua m
OH Pe
lit er
R
y
3
e
tur
Legal Ris st ruc ts
ks 4 ra e
Inf & Ass
ce Frau
li an Fi d
mp na
Co n
Inf
In ce
ks
ve &
orm terrup
st Tr
is
In
m ea
tR
uption
en s
atio tion
Interr ess
ts ury
ec
oj
:
nS
Busin
Pr
yst
e
ms
1 Management of specific
1 M business
t f risks
2 Insurable risks
91
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
92
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
Appendix F
TBS Management
Accountability Framework –
Risk Management Expectations
Risk Management
a key management expectation of the
Management Accountability Framework
Expectation Indicators Measures
The executive team clearly £ Key risks identified £ Corporate Risk Profile,
defines the corporate and managed reviewed regularly
context and practices for
managing organizational £ Risk lens in decision- £ Tools, training, support
making for staff
and strategic risks
proactively £ Risk smart culture £ Evidence of risk
considerations in
£ Capacity to strategic planning
communicate and
manage risk in £ Engagement of external
public context stakeholders in assessing/
communicating risks
93
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E
94
I N T E G R A T E D R I S K M A N A G E M E N T I M P L E M E N T A T I O N G U I D E









