Risk Management Strategy Overview
Risk Management Strategy Overview
Strategy
Introduction
An effective risk management strategy will ensure the Council maximises its
opportunities and manages those threats that may hinder the delivery of its
priorities so that the opportunities for continuous improvement are maximised.
This risk management strategy aims to integrate risk management into the
Council’s culture and processes and raise awareness amongst all employees
1 Orange book link: This links you to an online PDF version of The Orange Book Management
of Risk – principles and concepts, Crown Copyright, 2020
2 The Orange Book Management of Risk – principles and concepts, Crown Copyright, 2020.
P.3
and members of the benefits and opportunities that successful management of
risk can bring.
Definitions
The aim is to manage risk, rather than eliminate it. Too little attention to
the control of risk will lead to unnecessary losses and poor performance,
while an over devoted approach may suppress creativity and increase the
cost of and/or impede service delivery. Successful risk management
means getting the balance right.
The Council also recognises its legal, moral and fiduciary duties in taking
informed decisions about how best to control and minimise the downside of risk,
whilst still maximising opportunity and benefiting from positive risks.
The Council will ensure that Members and staff understand their responsibility
to identify risks and mitigate the possible consequences.
The Risk Management Process
The purpose of the risk management process guide is to describe the key steps
required to ensure risks are successfully identified, assessed, and controlled.
A standard risk management process will be used throughout the Council. This
will ensure that risks are considered in the same fashion whether at a project,
partnership, corporate or operational level.
1. Identification
There are many ways of identifying risk, including making use of:
Staff experience and knowledge
Review of objectives in Corporate and Service Plans
Performance indicators, financial/budgetary and management
information
Service reviews by internal/external audit and other inspection bodies
Risk assessments
Directorate / Service meetings / workshops
Amendments to legislation
Insurance claims / loss information
When describing a risk it is important that it can be easily understood. The risk
description should consist of the cause, event and effect. This information
should be logged onto the council’s risk register (4Risk).
Risk Cause:
What would cause the risk to happen, e.g., a fire, loss of key personnel.
This is where we consider what we could have done to prevent it.
Risk Event:
What could go wrong. This is an uncertain event which may or may not
materialise, that if it does would most likely have an impact.
Risk Effect:
This is the potential outcome of the event, the consequence.
As mentioned above the HDC holds its own risk register on 4Risk, which can
be found on the intranet. Staff should use 4Risk to track, update, add and review
risks.
HDC holds a single risk register which maintains risks across all levels of the
organisation including Corporate and Operational level risks. Corporate risks
are likely to affect the medium to longer term priorities and objectives of the
Council and require longer term planning to be addressed. Operational risks
tend to be related to ongoing service activities and have a more immediate
impact and generally need to be treated on a shorter time frame. By having a
single risk register, risks are collectively reviewed and mitigating actions applied
consistently. There is also less likelihood of duplication of risks e.g., budget
affordability can be included as a risk across all areas of the Council, rather
than each service registering this as a risk.
2. Evaluate
Once a risk has been identified, we need to assess how big a risk it is; how
much of an impact would it have, and how likely is to happen? Once we have
prioritised the risks, we must look in more detail at the risk to understand the
balance of threats and opportunities presented.
Estimation Techniques:
Probability/Likelihood assessment: How likely is the risk to happen?
This technique involves assigning a value to the likelihood of a risk
occurring, which aids the prioratisation of risks.
Impact assessment: What impact would it have were it to happen?
This technique involves assigning a value to the impact a risk will have
on the organisation and/or relevant department, which aids the
prioratisation of risks.
Proximity assessment: How close (time) is it to happening?
Assessing the potential timing of a risk (when it is likely to occur and how
long it may last) helps to make informed risk responses and create any
possible mitigation strategies.
- Expected value assessment
Calculating the expected value of a risk using its potential likelihood and
impact provides a quantitative measure of the potential cost of a risk and
helps to prioratise risk responses.
Evaluation Techniques:
- Summary risk profiles
By summarising the risks associated with a project/programme in a
concise and accessible format, you can see a high level overview of the
most critical risks which aids decision making.
- Summary expected value assessment
By calculating the expected value of multiple risks and summarising
them in a clear and concise way decision making and the understanding
of the overall risk profile of a project or situation is made easier.
- Probability trees
This technique uses graphical representation of risks and their potential
outcome, allowing a better understanding of complex risks and their
impacts.
- Sensitivity analysis
This involves assessing the impact of changes in assumptions or inputs
on the potential outcomes of a project/programme/situation. This helps
decision makers understand the potential risks associated with different
scenarios and adjust risk responses accordingly.
Risk Categories
Risk categories are classifications of which business activity the risk relates to
and aids discussion on linked risks and mitigation. The categories below strike
the balance between completeness, focus on HDC’s risk profile, and usability
by end users. The risk category needs to be input into the risk register when
the risk is added.
People Risks arising from staff related Do you have a robust staffing structure?
matters, including culture, Are you able to recruit when need to?
capacity, knowledge and Do you have a risk or staff retiring or
capability, and non-compliance leaving?
with relevant employment Are your team appropriately trained?
legislation/HR policies resulting Do you have key responsibilities that rely
in negative impact on on a single individual?
performance. Are staff aware of their point of contact
and the order of communication for
when decisions needs to be made?
Do our operating processes carry any
risks to staff or the public?
How will changes in legislation impact
upon our people?
Are any changes to service delivery
planned, what will this affect?
What dependencies do you have on
other teams, how would disruption there
impact your service?
Financial and Resources Risks relating to financial Do you have a savings or income target
planning, financial control, and for the coming year?
insurance arrangements. Do you have plans in place?
Are you expecting any changes in terms
of demand, or fluctuation in your costs
that you need to plan for?
Do you have adequate insurance cover?
Are you aware of all opportunities for
income, funding and grants?
Does a planned capital investment
require an ongoing revenue budget to
support it?
Are external factors likely to impact upon
your service affordability, e.g., inflation?
Will new activities require increased
support costs, e.g., reporting and
monitoring associated with external
funding?
Will future funding changes impact your
service?
Operating Environment Risks relating matters which What changes are happening, or are
affect or impact the daily, there possible signs of happening which
operating environment. Such as may affect the demand for, or the way in
Economic and Conmercial, which your service operates?
Social, Physical and Think in terms of…
Environemantal risks. Competition from other organisations
Social changes in terms of behaviours,
need and demand or the profile of your
customers?Are there economic changes
which could change services people
need, or change your ability to buy or
sell things. How could environmental
changes such as hotter summers, or
wetter winters affect your services. What
impact would inflation or increases in
borrowing costs have on your service?
Who are your third party suppliers, what
happens if one of these fail?
What happens if one of your
dependencies changes?
Will future legislation require changes to
the Operatng Environment?
Policy and Process Risks relating to the Do you have an understanding of the
management, organisation and policy environment in which you are
understanding of all policies, operating?
regulations, and strategies and Are there any forthcoming policy
the relevant processes for the changes or emerging political priorities?
services you are responsible for. Is the prioritisation of this activity
Including at national, local and appropriate in your service plan and/or
where relevant international approved with your manager and
levels. portfolio holder?
Are you anticipating legislative or other
political changes either locally or
nationally to affect your service.
Legal and Contractual Risks stemming from legal and Do you have contracts expiring in the
contractual obligations, next 2 years?
challenges and the management Do you have plans in place?
of contracts and legal Are you actively managing contracts,
documents. and escalating any issues?
Income generation, are you able to
deliver all the services detailed in the
Service Level Agreement?
Supplier agreements - Do you have an
up to date register of change controls
and impacts, have they been
implemented?
Have you factored in contract
dependencies, e.g., agreed price
increases and know what the impact to
your budget is?
Are you aware of contract break clauses
and the impact of these?
Will a service transfer have TUPE
implications
Customer and Reputational Risks which are associated with Do you have clear cost-effective
the failure to meet the current processes that enable you to deliver
and changing needs and services to your customers?
expectations of the customer and Do you have documented processes?
residents (Reputational risk). Do you know the cost of your processes,
These risks may be associated and are you able to identify opportunities
with the processes you use to for improvement?
manage the work you deliver to Do you have clear performance metrics,
your customers. and do you understand how effectively
your services are meeting customer
needs?
Do you understand your Service Level
Agreement?
Are your customers financially stable?
Are these services we are permitted to
deliver/charge for?
Information and Technology Risks relating to the systems and Do you understand and have developed
technology you use to deliver plans for all the technology that you use
your services – software, in your service?
appliances, phones, etc. As well Do you have a list of all the systems,
as matters relating to the way in technology and software that your team
which you manage information, uses?
particularly relating to sensitive Do you have system owners,
and personal information. champions, to maximise the benefits of
the systems?
Do you have an information governance
lead?
Do you have information management
plans for all of the data you hold, and
data sharing arrangements you have in
place?
Will a process change require additional
software licences?
Are you a data processor or controller,
how does this impact your data storage
and use?
How will software updates impact your
service, risk of unforeseen downtime?
Do you know how long you should keep
data for? Can you achieve this?
3. Planning
This involves balancing the potential benefits of mitigating the risk – in terms of
improved delivery, with the cost of doing so. The cost is not just an economic
one, and needs to be reviewed against the objectives of the organsiation as
whole, e.g., broader economic, social, and environmental impacts. The delivery
of some activity is so important, that even expensive mitigation activity may be
welcome.
Planning techniques:
Risk response planning: what can we do?: avoid, reduce,
transfer/share, accept
o Avoiding the risk, if feasible, by deciding not to start or continue
with the activity that gives rise to the risk;
o Reducing the risk or changing the likelihood, where possible or
changing the consequences, including planning contingency
activities;
o Sharing the risk (e.g. through commercial contracts[12]).
o Retaining (accepting) the risk by informed decision or taking or
increasing the risk in order to pursue an opportunity;
Cost benefit analysis: what is the cost vs the benefit, is the risk
avoidance work worth doing?
o This technique involves weighing the potential costs of risk
responses against their potential benefits. This aids the
identification of the most effective risk response and ensures risk
management efforts are cost effective.
Decision trees
o This involves a graphical representation of decisions and their
potential outcomes to aid decision making with understanding the
potential risks associated with different options.
Risk register details: risk owner, risk actionees, risk register, risk
response
o By maintaining a detailed record of identified risks and their details
(such as associated risk responses, descriptions etc) a central
information point for risk is there to inform decision making and
track risk management efforts over time.
4. Implementation
Once the risk management plan has been made it must be implemented,
monitored for effectiveness and corrective action taken when and where
needed. These implementation steps should generally feature in your service
plan, or within your project plan, so they can be reviewed and monitored.
Implementation techniques:
- Updated risk summary profile / risk register information
This technique involves regularly reviewing and updating the summary
risk profile to ensure changes are reflected, which ensures that the risk
management plan remains relevant and effective.
- Risk exposure trends
This involves tracking and analysing trends in risk exposure over time.
This helps to identify emerging risks and opportunities and inform
adjustments to risk responses and risk management strategies, if
needed.
- Risk progress report
By regularly reporting on the progress of risk management efforts,
including the status of risk responses and any changes to the risk
landscape, this ensures risk management efforts remain on track and
effective.
Once an approach and process has been put in place it is essential to continue
applying it across the organisation and that it undergoes continual
improvement.
The table below explains how risk management processes link into the
Council’s planning process.
Risk Assessment
The risk assessment model is detailed in Appendix A3. The model requires
potential risks to be evaluated against a set of pre-determined criteria for
likelihood/frequency and impact at both the inherent (without controls) and
residual (with controls) risk levels. Individual risk levels are determined by
plotting the risks onto a risk matrix. Health and Safety risks will be plotted
against the smaller inset matrix.
Almost
ue
nc
d/
lih
eq
ke
Fr
Li
Certain
3Appendix A Link: Takes you to the section in the document which shows HDC’s Risk
Assessment Model.
Likely 4 Medium High High Very High Very High
1 2 3 4 5
Trivial Minor Significant Major Critical
Impact
Risk Appetite
The Cabinet shall determine the Council’s risk appetite; that is the amount of
risk it is prepared to accept, tolerate, or be exposed to at any point in time before
taking any action.
The Council’s appetite for risk will be considered as ‘exceeded’ when the
residual risk score (the likelihood and impact of threats after mitigations put in
place) have a score of 15 or above in accordance with the Council’s risk scoring
matri, as seen above.)
If the risk remains outside of tolerance, or the Assurance Board does not believe
the proposed action plan sufficiently mitigates the risk, it will escalate the risk to
the Senior Leadership Team, and the respective manager who owns the risk
will be asked to follow the Options Appraisal and Risk Treatment process.
(Appendix B for options Appraisal and Appendix C for risk appetite exceeded
diagram).
For all individual residual risks that exceed their risk area targets as described
above, consideration shall be given as to what further cost-effective mitigation
could be introduced to reduce the residual risk score so that it falls within its risk
appetite.
Before a decision is made on the way the risk is to be treated, the respective
risk manager, who owns the risk, shall carry out an option appraisal (Appendix
B). The appraisal shall consider how to deal with the risk on the following basis:
Reduce or treat the risk by controlling the likelihood of the risk
occurring or controlling the impact of the consequences if the risk does
occur.
Avoid or eliminate the risk by not undertaking the activity that may
trigger the risk.
Accept or tolerate the risk. This option will only be accepted when the
ability to take effective action against a risk is limited or the cost of
taking action is disproportionate to the potential benefits gained.
The appraisal will consider cost, resources, time and the potential financial and
non-financial benefits of each treatment option. Advice from specialist staff such
as the Risk and Controls team members shall be taken where appropriate.
Ideally risk treatments should be self-funding. Where this is not the case there
will need to be a prioritisation process to ensure that any funding is
concentrated first on those items that will be most beneficial to the achievement
of the Council’s priorities.
Action Plans
The results of the option appraisal shall be recorded by the risk owner on a risk
treatment option form (Appendix B) within four weeks of the risk having been
recorded in the risk register. The form shall identify the risk, the current control
environment, control actions to be introduced, the Officer responsible and the
timescales for implementation.
The risk owner shall send the option appraisal form to the Senior Leadership
Team Member for the service within six weeks of the risk being recorded in the
risk register. They will review and challenge the form. The form shall be
updated if required and then considered by the Senior Leadership Team who
will determine if the mitigation outlined is to be introduced. If the additional
mitigation cannot be met from the current Service budget the matter shall be
reported to the Cabinet for a decision. If further mitigation is agreed, the risk
owner shall update the risk register and put in place procedures to introduce
the agreed mitigation.
Corporate LeadershipTeam
To ensure effective risk management throughout the Council in
accordance with the risk management strategy.
To make recommendations at least once a year to the Cabinet on the
Council’s risk appetite.
To ensure that Members are advised of the risk management
implications of decisions.
To review and challenge Corporate risk register entries at least once
every three months.
To prioritise risk treatments and requests for additional funding.
Senior LeadershipTeam
To develop a culture of risk management throughout the Council.
Balancing an acceptable level of risk (as described by the risk appetites)
against the achievement of corporate and/or service plans, project
objectives and business opportunities.
To identify and resolve any risks associated with compliance with the
Council’s agreed rules, procedures and processes.
Ensure that risks relating to significant partnerships are identified and
effectively managed, within the partnership and at service level.
To review and challenge Operational risk register entries at least once
every three months.
To review and challenge risk treatment option forms submitted by the
Management Team and passing them onto the Corporate Management
Team if additional control measures cannot be funded from Service
budgets.
Management Team
Ensuring that effective control procedures are in place to manage the
risks affecting their services.
Review (as risk owner) their Corporate and Operational risk register
entries at least once every three months, reporting all new risks or
significant changes to risk entries to their Head of Service and/or
Director.
Maintain all risk register entries fully, updating them promptly with any
perceived new risks or opportunities, failures of existing control
measures and closing them when appropriate.
Update at least once every six months risk register assurance
statements that describe the effectiveness of the risk mitigating controls.
Prepare (as risk owner) for risks that exceed risk appetite levels, risk
treatment option forms for consideration by the Senior Management
Team.
Assurance Board
To report as necessary to the Cabinet, Corporate GovernanceCommittee
or Corporate Leadership Team on risk management issues.
To identify best practice and consider its introduction within the Council.
To provide advice and guidance on systems to mitigate risk.
Ensure risk strategy is reviewed and updated annually/as needed.
Internal Audit:
Internal Audit will seek assurance from the risk register that the
organisation is assessing its risks on a regular basis and acting in a
responsible manner to mitigate them.
It will use the risk register as a basis for informing the annual Internal
Audit plan, assessing if risks are correctly recorded and the mitigating
actions appropriately deployed and reported.
It will escalate risks to Assurance Board where mitigating controls are
not deployed and the risk should be noted as unmitigated.
Employees
To co-operate with management and colleagues in matters relating to
the mitigation of risk.
To promptly inform the appropriate manager of any risks they become
aware of.
Appendix A
Risk Assessment Model
appendix
Likelihood / Frequency
Alternatively this could be
expressed as likely to
happen within the next:
When considering Health & Safety related risks, the likelihood should be
expressed as being likely to happen within the next:
4 = Likely Monthly
Further advice on assessing Health & Safety
3 = Occasional Yearly risks can be obtained from the Health & Safety
Manager
2 = Unlikely 5 years
Impact
Risks will be evaluated against the following scale. If a risk meets conditions for
more than one category, a judgement will need to be made as to which level is
the most appropriate. For example, if a particular health and safety risk was
significant, could result in minor short-term adverse publicity in the local media
but had only a trivial financial impact, it might still be categorised as significant.
a.
b.
c.
Actions requiring additional resources
1.
2.
3.
4.
Decision
Agreed Option:
Implementation Date Risk Owner
Note: Health & Safety risks that exceeed their risk appetite shall be treated with counter-
measures or be stopped immediately until the residual risk has been sufficiently reduced. The
action that must be taken is set-out below and mirrors the approach set-out in the Council’s
approved Health & Safety risk assessment form.
4New Residual Risk Score: after the action has been introduced
5Extra Resources: only complete if extra resources will be required to allow the proposed action to be introduced
e.g. financial costs and staff time
Remember, when considering treatment options that the Council’s aim is to
manage risk rather than eliminate it completely – successful risk management
is about improving risk taking activities whilst minimising the frequency of the
event occurring.
Issues that should be considered when making the risk treatment decision are listed
below.
Cost effectiveness Costs need to be estimated accurately as it’s the base against which
cost effectiveness is measured.
Does the lack of treating the risk (or the current method of control)
breach any laws or regulatory requirement?
Is the treatment option proposed, including its cost, totally
disproportionate to the risk?
Risk creation What new risks will be created from introducing the option?
Appendix C
1. Residual risk score (the likelihood and impact of threats after mitigations are put in place,
score calculated using the risk matrix) exceeds the risk appetite (the maximum residual
risk an organisation will accept after controls are put in place in order to achieve its
objectives).
2. Service to review the risk and identify any actions to treat the risk.
3. If risk tolerance (the maximum risk the organisation is willing to take regarding a specific
initiative) is exceeded, the service will be asked to produce a risk treatment plan on a
template and to report back to the Assurance Board to show the quantification of the
current risk and the proposed actions in response to it.
4. If the Assurance Board is satisfied the action plan will reduce the risk to be within risk
tolerance levels, the action is accepted and the risk will be returned to the service for
monitoring in the usual way.
5. If the risk remains outside of the risk tolerance, or the Assurance Board does not believe
the proposed action plan sufficiently mitigates the risk, it will escalate the risk to the
Senior Leadership Team, and the respective manager who owns the risk will be asked to
follow the Options Appraisal and Risk Treatment process.
Glossary
Risk appetite: The amount of risk the organization, or subset of it, is willing to
accept.
Risk capacity: The maximum amount of risk that an organization, or subset
of it, can bear, linked to factors such as its reputation, capital, assets, and
ability to raise additional funds.
Risk tolerance: The threshold levels of risk exposure that, with appropriate
approvals, can be exceeded, but which when exceeded will trigger some form
of response (e.g. reporting the situation to senior management for action).