Risk Management Policy Framework
Risk Management Policy Framework
1
Contents
Section
Section Heading Page
Page
1. Introduction 3
2. Purpose 3
3. What is Risk Management? 3
4. Risk Management Principles 4
5. Strategic Framework for the Management of Risk 4
6. The Risk Management Process 5
7. Identification of New Risks 10
8. Risk Appetite 11
9. Risk Registers 13
10. Annual Reviews 13
11. Assurance Statements 14
12. Roles and Responsibilities 15
13. Other Areas of Risk Assessment 19
14. Useful References 19
15. Review 19
2
PPS Policy and Framework for Risk Management
1. Introduction
The policy of the Public Prosecution Service (PPS) is to ensure that effective
risk management processes are maintained which serve to improve the quality
of decision making and the ability to deliver on strategic and operational
objectives.
2. Purpose
For the purpose of this document risk can be defined as “…the effect of
uncertainty on outcomes, usually expressed in terms of causes, potential events
and their consequences.” (The Orange Book: Management of Risk – Principles
and Concepts, updated 2019).
3
It has an integral role in internal corporate governance and accountability
arrangements and is should be regarded as a governance requirement
(e.g. as set out in HMT ‘DAOs’).
4
Within the PPS Risk Management Framework, all risks will be managed at one
of three levels:
Corporate Risks: These are high level risks which could have a major
impact on the Service’s business objectives. They may also include inter-
agency risks and involve interdependencies with other CJSNI initiatives or
activities. These risks are managed primarily by the Management Board,
in conjunction with the Senior Management Group, and are subject to
challenge / scrutiny by the PPS Audit and Risk Committee.
Region / Section Risks: These are risks that relate to activities within the
control of an Assistant Director (SCS Grade 5), which could have a major
impact on the delivery of service or achievement of objectives for that area.
These risks are managed by Assistant Directors, and may be escalated to
corporate level or de-escalated to section level as appropriate.
Branch / Unit Risks: These are risks which could impact on the delivery
or timescale of activities or deliverables at branch level (for example, within
Corporate Services Branches). These risks will be managed by the Heads
of the individual branches and may be escalated to region / section or
corporate level as appropriate.
Project Risks also exist and will usually be managed within the methodology
used to manage the project level by way of a project management methodology
(e.g. PRINCE 2). Managers responsible for projects must assure themselves
that risks are being tracked and dealt with effectively. The mechanisms in place
for monitoring and reporting risk will vary according to the size and complexity
of the project. For larger projects, we will have a governance structure which is
set up broadly in line with the OGC Gateway process. These include a Senior
Responsible Owner (SRO) and a project board, supported by a project team
and project manager. This represents best practice and is essentially about
accountability for managing and delivering the project. In each case the SRO
will be a senior Civil Servant who provides support and assurance to the
Director.
Identification of risk;
5
Assignment of ownership;
Prioritisation of risks;
Risk Responses;
Assurance; and
Embedding and review.
Risks should be related to objectives as set out in the relevant business plan /
Balanced Scorecard; some risks and targets may be relevant to more than one
objective. However risk identification and assessment should not be confined to
the process of drawing up annual business plans. Risk management should be
a continuous process which identifies new risks, changes in existing risks and
risks which are no longer relevant to the PPS.
Identification of Risk
Any statement of risk should encompass the cause of the impact and the impact
to the objective (cause and consequence). In identifying risks, managers should
not just consider threats to the achievement of their objectives but also consider
opportunities for improved performance and enhanced capacity.
Assignment of Ownership
The Director has overall responsibility for the Service’s Risk Management
Framework. However in order for risk management to be effective it is essential
that responsibility for individual risks is delegated to the appropriate level.
Therefore all identified risks will have an ‘owner’, so that responsibility and
authority for implementing action plans is clearly understood.
6
Within the PPS ownership of corporate risks will usually be assigned at Grade
5 level or above. Although the owner of the risk may not always be the person
tasked with the assessment or management of the risk, they are responsible for
ensuring the risk framework is applied.
Rating of Risks
There is a degree of risk in all of the Service’s activities and its ability to take
positive action about some risks may be limited or the cost of taking that action
may be disproportionate to the potential benefit gained. Control costs money
and it is important that any potential loss associated with a risk materialising
should be weighted against the cost of controlling it. Each risk is therefore
graded using rankings on the likelihood of the risk occurring and the impact it
would make if it did occur.
7
(a) Likelihood x (b) Impact = Risk Priority
(a) Likelihood Score Probability Description
8
PPS Risk Assessment Matrix
3
Likelihood
1 2 3 4
Impact
Key
The consequences of the risk materialising would be severe and possibly disastrous. Some
immediate action is required plus the development of a comprehensive action plan. Red risks
require immediate action.
High ‘Showstopper’ risks are those that would:
•Stop you from meeting your objectives or targets;
•Be likely to have major impact on your processes;
•Cause severe damage to corporate reputation or public embarrassment.
Consequences of risk not severe and can be managed via contingency plans. Action plans
developed later and budget bids mobilised. Status of risk should be monitored regularly.
Amber risks need to be monitored and managed down to yellow / green.
Medium
Potential risks are those that could:
•Prevent you from meeting certain objectives/targets but do not endanger others;
•Inconvenience the Department.
9
Risk Responses
Once a risk has been identified consideration must be given to the appropriate
response. Responses to risk can be divided into four categories:
Transfer;
Tolerate;
Treat (Mitigate); or
Terminate.
In many cases PPS risks will fall into the ‘Mitigate’ category. Where this is the
case, actions will be identified and put in place to manage these risks and
contain them to as low a level as is reasonably practical (i.e. adopt a
proportionate response).
Assurance
The Service integrates risk management within all aspects of the business
planning process. Relevant induction / awareness training sessions are also
provided to all managers and staff.
A risk assessment will be carried out on all new business activities or functions
and the results will be incorporated in the appropriate risk register (see below).
10
8. Risk Appetite
The risk appetite sets out the level of risk that management is prepared to
accept, tolerate, or be exposed to at any point in time. It also takes account of
the adequacy of the control to manage the risk.
Corporate risk appetite (Statement of Risk Appetite – see Annex 5) is the overall
amount of risk judged appropriate for an organisation to tolerate. The purpose
of the corporate risk appetite is to identify general boundaries for unacceptable
risk (or at least for risks that should always be referred to / escalated up to the
Management Board for discussion and decision when they arise). It should be
used as an adjunct to the risk management process and is intended to assist
Assistant Directors and other managers in the compilation of their risk registers.
Managers should set clear boundaries for unacceptable risk and risks that
should be escalated to a higher level (see below). The following principles have
been agreed:
Risks assessed as high (in the red area of the Risk Matrix – see
above) require urgent proactive actions to be taken in order to ensure
they are managed effectively and risks are reduced to an acceptable
level (i.e. medium or below).
All risks assessed as low (green area in the Risk Matrix) require
minimal risk management. However, although no actions may be
required at this time these risks should be kept under continuous
review.
11
Risk Escalation
When escalated to a new level there must be an objective review process. This
should include consideration of whether the risk is within the remit or area of
effective control of the new level of management. Risk severity will also be
reviewed to reflect the impact of the risk at the level to which it has been
escalated.
When it has been agreed that a risk should be escalated, the existing risk
register should be annotated accordingly and the risk included in the higher-
level risk register.
Risks outside of the control of individual managers (or that are not felt to
be effectively managed at the current level of responsibility);
Risks with a wider impact than solely within a specific project or function;
Risks which will have a significant impact on wider strategic objectives,
business processes or key operational activities;
Cross cutting dependencies and resource conflicts;
Risks with ineffective mitigation measures and / or inadequate control
measures; and
ICT / technology risks that may have a significant impact on service
delivery.
It will be acceptable for management at the higher level to decide not to accept
the escalation of a risk, for example where it is felt that the existing risk owner
12
has not taken sufficient action to manage the risk effectively. The reasons for
such a decision will need to be recorded in a similar manner to those risks that
have been escalated (i.e. in the appropriate risk register).
9. Risk Registers
All agreed risks will be recorded in the appropriate ‘risk register’ (i.e. corporate,
region / section or branch / unit). The template to be used for all registers is
attached at Annex 6.
At the end of the financial year the Director and Management Board:
13
The annual assessment of internal controls considers:
The changes since the last annual assessment in the nature and extent
of corporate risks;
The scope and quality of the ongoing monitoring of risks and of the
system of internal control;
Reports received from review bodies, e.g. Internal Audit, Criminal Justice
Inspection etc.; and
The effectiveness of the Service’s reporting processes.
In reviewing the effectiveness of the system of internal control and preparing the
overall Governance Statement on an annual basis, all Assistant Directors and
Corporate Services Heads of Branch are required to sign quarterly Assurance
Statements for their areas of responsibility. By completing the Assurance
Statements, Assistant Directors and Heads of Branch acknowledge their
responsibility for managing relevant corporate risks / risks appropriate to their
business areas and for monitoring the risks assigned to members of their team.
The statements also provide assurance to the Director, as Accounting Officer,
that risks are being managed appropriately. The Assurance Statements should
therefore:
14
12. Roles and Responsibilities
Accounting Officer
The Director, as Accounting Officer, provides the top level commitment and
support for the risk management process and has overall responsibility for
managing corporate risks. He is responsible for ensuring that risks faced by the
PPS are appropriately managed and that the necessary controls are in place.
Management Board
15
Performance and Accountability Meetings
Assistant Directors
Agreeing the key risks, risk owners and controls to manage risks
identified in the Risk Management Framework at corporate and region /
section level as appropriate;
Taking decisions affecting the management of risk within their area of
responsibility;
Monitoring the management and control of key risks to reduce the
likelihood of unforeseen occurrence;
Highlighting emerging risks or control weaknesses at Performance and
Accountability meetings; and
Ownership of the region / section risk register.
Risk Owners
Each risk that is identified in a risk register will have a corresponding ‘risk owner’.
Ownership must sit at the appropriate level, ideally with the person who can take
effective action. For example risk owners must have the authority to assign
resources to manage key risks. They are responsible for managing assigned
risks by ensuring controls are in place and properly actioned at all levels
throughout their branch / unit. If a risk owner feels that they cannot take
appropriate action, then the risk needs to be escalated to the next level.
16
Line Managers
The Audit and Risk Committee (ARC) provides the Director with objective advice
on issues concerning the risk, control and governance of the organisation and
the associated assurances. To enhance the objectivity of the advice given, the
Committee is comprised of a non-executive chair and membership.
Although it has no authority in its own right over the operations of the
organisation, the Committee:
The ARC will ensure that the effectiveness, relevance and accuracy of the risk
register is kept under regular review by:
Internal Audit
17
The Head of Internal Audit provides the Director with an independent opinion on
the management and control of risk through the completion of individual audit
assignments which are agreed annually by the Management Board and the
Audit and Risk Committee. Additionally, findings and recommendations assist
management in the audited business areas in strengthening their risk
management and internal control processes and procedures.
The Northern Ireland Audit Office (NIAO) is headed by the Comptroller and
Auditor General (C&AG) and is independent of Government. NIAO audits the
accounts of all Government Departments and other public bodies. While the
Governance Statement, which forms part of the annual accounts is not audited
per se, the C&AG may report on it if does not meet the requirements for
disclosure specified by the Department of Finance (DoF), or if the statement is
misleading or inconsistent with other information he is aware of from his audit of
the financial statements.
A representative from NIAO may attend Audit and Risk Committee meetings at
which corporate governance, internal control and risk management matters are
considered.
The PPS Policy and Information Unit (PIU) supports the development of the
annual corporate risk register as an integral part of the business planning cycle
by coordinating the initial completion and monitoring of the corporate risk
register.
Advice may also be sought from Internal Audit and the Northern Ireland Audit
Office.
18
13. Other Areas of Risk Assessment
Useful references and websites which cover the risk management process are
listed at Annex 8.
15. Review
This policy and framework will be reviewed on an annual basis in order to take
into account the changing circumstances under which the Service operates.
19
ANNEX 1: COMMON CATEGORIES OF RISK
External Activity
Budgetary: availability and allocation of resources. Personnel: availability and retention of suitable manpower skill
Fraud or theft: unproductive loss of resources. mix.
Capital investment: making appropriate investment Health and Safety: safeguarding staff, clients and the public.
decisions. Equality: equal treatment for all.
Liability: the right to sue or be sued in certain Data Protection: protecting individuals rights under legislation.
circumstances. Training / Development: access for all to meet training and
development needs.
20
ANNEX 2: RISK IDENTIFICATION PROCESS –
PPS CORPORATE RISK REGISTER
21
ANNEX 3: POSSIBLE RESPONSES TO RISK
22
ANNEX 4: CORPORATE RISK MANAGEMENT PROCESS
23
ANNEX 5: RISK APPETITE AND TOLERANCE
Whilst core activities across operational PPS Regions and Sections are broadly
similar, it would be too simplistic to apply the same level of risk appetite across
all parts of the Service. However it is essential that any variations are set in a
context which defines a coherent decision making framework for those involved
in operational areas and provides the Director and Management Board with an
assurance that effective control measures are in place.
This framework defines the extent to which risk is encouraged and tolerated
across the Service’s responsibilities. It provides a profile which identifies the
areas of high and low risk tolerance and indicates where it may be necessary
to refer decisions up the chain of command. The latter is generally referred to
as ‘risk escalation’.
1
“Management of Risk - A Strategic Overview” (HM Treasury)
24
- Averse: Avoidance of risk and uncertainty is a key organisation objective.
- Minimal: Preference for ultra-safe options that are low risk and only have
a potential for limited reward.
- Cautious: Preference for safe options that have a low degree of risk and
may only have limited potential for reward.
- Open: Willing to consider all potential options and choose the one most
likely to result in successful delivery, while also providing an acceptable
level of reward and value for money.
The aim of the PPS is to deliver a fair, independent and effective prosecution
service. In the interests of justice, all actions must be undertaken with complete
impartiality, to the highest ethical and professional standards. Prosecutions may
only be initiated by the PPS where it is satisfied that the Test for Prosecution is
met. At all times prosecutors working for, or on behalf of the PPS, must act in
accordance with the Code for Prosecutors and Code of Ethics as issued by the
Director of Public Prosecutions. As a result, this is an area where the tolerance
of failure or non-compliance is low and hence the risk appetite should be averse
with associated levels of control to ensure an extremely low residual risk.
The PPS is concerned with the delivery of change in many areas of work. If
policy initiatives are to effect improvements, value for money etc., a high level
of innovative thinking is often required. Too much control would tend to lead to
over-cautiousness and stifle innovation. However the development of policy
must consider potential negative impacts on reputation and legal and
professional standards. Accordingly the PPS appetite for risk-taking in these
areas is cautious, provided appropriate controls are in place in the form of
consultation with staff and stakeholders, proper management scrutiny etc. as
appropriate.
As outlined above, the PPS is concerned with the delivery of change and
improved services and therefore innovative thinking is required in all aspects of
service delivery (e.g. through the use of ICT or re-engineering of processes) if
radical improvements are to be achieved. Therefore the PPS appetite for risk-
taking in these areas is open, provided that appropriate controls are in place in
25
the form of consultation with staff and stakeholders, pilot projects, gateway
reviews, management scrutiny etc. as appropriate.
4. Human Resources
Human Resource risk mainly involves ‘people’ issues that affect business
continuity and everyday working – e.g. recruitment, equal opportunities,
security, health and safety etc. These require precision and are largely
‘prohibited’ risk areas i.e. where compliance with organisational policies and
guidance is mandatory. As a result this is an area where the tolerance of failure
is low and hence the risk appetite should be averse with associated levels of
control to ensure a very low residual risk.
The PPS must comply with a wide range of central initiatives and Government
standards. These include regulations and codes on regularity, propriety and
accountability – particularly in relation to financial management. This requires
compliance with mandatory central guidance and therefore the risk appetite has
to be averse and needs to be supported by very high levels of control.
6. Reputation
The Service needs to maintain its reputation with key stakeholders and to
maintain public confidence in its fairness and effectiveness as a prosecution
service. It therefore has a low risk appetite in this area. On the other hand the
PPS is an organisation undergoing continuous change and which cannot avoid
an element of risk taking if it is to achieve the desired outcomes. It also takes
risks with its capability for delivering existing and new areas of work (e.g. via
new ICT systems) even though failure to deliver could damage its reputation.
In addition it is recognised that the PPS must deliver a prosecution service which
is independent of political, public or other pressures and in some instances
decisions (whilst fully in accordance with the PPS Test for Prosecution) may not
be viewed positively within the wider community. Therefore, on balance, the
overall appetite for reputational risk is cautious although this is a specific area
where the final evaluation will depend on context.
7. External
The PPS has limited control over its exposure to external risks, such as
economic change, infrastructure disruption etc. Efforts are made to mitigate the
effects of such risks by introducing control factors e.g. business continuity
planning and strict information assurance / security procedures and protocols.
However there are circumstances where, regardless of pre-planning, situations
26
emerge which cannot be predicted and where control is limited. Therefore the
risk appetite in this area is assessed as cautious.
Conclusion
The result of this analysis is to provide a corporate framework for the risk
appetite for the Service which looks like:
Legal and
Professional
Standards
Policy &
Guidance
Processes and
Service Delivery
Human
Resources
Regularity,
Propriety and
Accountability
Reputation
External
The framework sets out the context and risk profile for the Service. As a new
policy or work area is developed, a risk assessment should be carried out which
identifies the risk category and measures the level of risk using the
Departmental risk matrix. Where the assessment shows that the level of risk is
higher than the corporate profile for that category of risk, clearance should be
sought by passing the assessment up the decision making chain.
27
ANNEX 6: PPS RISK REGISTER TEMPLATE
Risk Summary Action Plan Risk Description Risk Owner Inherent
Risk Summary Action Plan
Inherent Assessment Residual Assessment
Action Owner
completion
completion
Actions)
Likelihood (1–4)
Likelihood (1–4)
Current Rating
Current Rating
Risk Mitigate Risk
Impact (1-4)
Impact (1-4)
Description
(R/A/G)
(R/A/G)
Risk Owner
28
ANNEX 7: OTHER AREAS OF RISK ASSESSMENT
In addition to identifying key risks against the Department’s strategic business
objectives and associated targets, risk assessments are also conducted against
specific areas of the business. This can include:
Business Resilience:
All business areas have a responsibility to develop & maintain a Business
Continuity Plan to deal with disruption at a local level - e.g. in the event that staff
are unable to gain access to a building or there is disruption to the delivery of
key services.
29
ANNEX 8: USEFUL REFERENCES AND WEBSITES
References
Websites
Department of Finance NI
[Link]
30
If you require any further information about the PPS, or a copy
of this document in an alternative format, please contact:
31