0% found this document useful (0 votes)
12 views27 pages

Managing Risks in Government: Best Practices

This guide addresses the challenges of managing risks in government and offers ten approaches for senior leaders and risk practitioners to enhance their risk management capabilities. It emphasizes the importance of leadership, capability, risk appetite, and a forward-looking view in effectively navigating risks. The guide draws insights from various sources, including the National Audit Office, and aims to improve public sector resilience and decision-making through better risk management practices.

Uploaded by

AbstractObtuse
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views27 pages

Managing Risks in Government: Best Practices

This guide addresses the challenges of managing risks in government and offers ten approaches for senior leaders and risk practitioners to enhance their risk management capabilities. It emphasizes the importance of leadership, capability, risk appetite, and a forward-looking view in effectively navigating risks. The guide draws insights from various sources, including the National Audit Office, and aims to improve public sector resilience and decision-making through better risk management practices.

Uploaded by

AbstractObtuse
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

INSIGHT

Overcoming challenges to
managing risks in government

Good practice guide

December 2023

This guide outlines the


challenges to managing
risks in government and
ways senior leaders and risk
practitioners can overcome
these challenges.

We are the UK’s independent


public spending watchdog

Communications Team
DP Ref 013702
Good practice guide: Overcoming challenges to managing risks in government 2

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

About our guide


Who is the guide for? What does the guide cover? Where have we drawn our
The guide is designed to equip senior leaders (‘leaders’) The guide sets out some of the key risk management
insights from?
and risk practitioners (‘practitioners’) across government challenges facing the public sector. It then outlines 10
We have drawn our insights and good practice primarily from:
with ways to help overcome the challenges to managing approaches leaders and practitioners can take to help
risks in government. overcome these challenges. Each approach is supported by: • the National Audit Office’s (NAO’s) back catalogue of
value‑for‑money work, lessons learned reports and
• an explanation of why this should be a priority
good practice guides, as well as government guidance
for government;
relating to risk management;
• illustrative case studies and quotes; and
• the experience and expertise from our own specialist
• practical tips for leaders and practitioners to take. insight teams; and

This guide complements existing government guidance on • interviews with a wide range of leaders and
risk management, including the Orange Book: management practitioners from our audited bodies and external
of risk – Principles and Concepts, and published guidance organisations across industry and academia.
notes, the requirements set out in Managing Public Money
A full methodology is included in the Appendix.
and the Government Financial Reporting Manual (FReM).1,2,3
Examples drawn from past NAO reports in this guide reflect
the situation when these reports were published. We have
not included follow-up action that departments may have
taken post-publication.

1 Government Finance Function and HM Treasury, Orange Book: Management of risk – Principles and Concepts, May 2013.
2 HM Treasury, Managing Public Money, May 2012, Annex 4.3.
3 HM Treasury, Government Financial Reporting Manual: 2023-24, December 2022.
Good practice guide: Overcoming challenges to managing risks in government 3

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Overview
Risk management Figure 1
Timeline showing recent developments (2020–2023) for risk management in government
in government
landscape May 2021
December 2022 May 2023
The UK Government • New edition of
The Orange Book sets out the The Boardman May 2022 The UK Government
Resilience Framework
Resilience framework the Orange Book The Orange Book Portfolio Risk

review outlines sets out how which includes Management


Management of Risk –

key principles and concepts for


December 2022
Principles and Concepts
Guidance

recommendations Introduction government can the Risk Control


Orange Book Annex

how risk should be managed by October 2020


to improve risk of the Head of strengthen systems and Framework
central government organisations.4 Risk Appetite management Government capabilities to support
Guidance Note v1.0 across government Risk Profession collective resilience • Portfolio Risk
It outlines that “risk management Management Guidance
shall be an essential part of
governance and leadership,
and fundamental to how the 2020 2021 2022 2023
organisation is directed, managed
and controlled at all levels.”

The Risk Centre of Excellence is February 2020 August 2021 January 2022 September 2022 August 2023
part of the Government Finance Revision of the • Risk Management Skills and Risk Management Launch of the 2023 edition of
Function (within HM Treasury) and Orange Book1 Capabilities Framework Strategy and first formal the National Risk
works to improve risk management Delivery Plan accreditation for Register sets out
• Good Practice Guide
risk managers the most serious
across government. It developed Risk Reporting
across risks facing the UK
a Risk Management Strategy • Risk Appetite Guidance Note v2.0 government
and Delivery Plan in 2022, in National
Risk Register

which it set out an ambition


2023 edition

to improve risk management


across government to strengthen
leadership and enhance credibility,
collaborate across boundaries,
enhance capabilities and Notes
drive professionalism.5 1 The Orange Book was first published in 2004 setting out government’s approach to risk management.

Source: National Audit Office analysis of government announcements

4 See footnote 1.
5 HM Treasury, Risk Management Centre of Excellence (requires login), accessed 24 November 2023.
Good practice guide: Overcoming challenges to managing risks in government 4

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Risk management challenges for the public sector


The scale and variety of the risks which government have Our work has identified numerous challenges impacting the • There are complex long-term challenges facing the
to deal with makes risk management in the public sector way that risks are managed across government: public sector and risk assessments do not always
challenging. Recent global events have only added to feed into funding decisions. Risk management helps
volatility and complexity. Significant risk events over the last • Government needs to understand the relationship
organisations to make informed decisions leading
between short-term efficiencies and long-term
few years have included a pandemic, cost-of-living crisis, to better value-for-money for the taxpayer – not just
resilience so that attempted efficiencies in one area do
rise in inflation and interest rates, and geopolitical conflicts. in avoiding threats, but by being innovative in taking
not inadvertently increase costs or risks in another.
Government must carefully balance short-term demands opportunities by making good spending decisions.
with long-term preparedness, making tough choices and • Government needs to be clear on accountability for
trade-offs with finite resources and capacity. risks that are shared across organisations. Effective
• Government has responsibility for delivering
major programmes over long periods of time.
risk management relies on identifying and managing
Our value-for-money and lessons-learned reports routinely Risk management has a key role to play in critically
risks that impact across departments and sectors –
highlight challenges for government in managing risks. examining and being realistic about delivery schedules
and doing this well requires quality data to be shared
Robust and effective risk management is essential to to help identify when programmes are becoming
effectively. Experts in resilience have noted there is no
achieving government’s ambitions and objectives and increasingly challenging.
cross-government accountability mechanism to ensure
securing long-term value for money. It can lead to better
action is taken to check the quality and viability of risk From page 7, our guide sets out clearly how leaders and
public service delivery and decision making, more efficient
planning and mitigation strategies.6 practitioners can begin to overcome these challenges.
use of resources, and help to minimise waste and fraud,
promote innovation and opportunity taking. • Building capability and expertise is vital for government
organisations to manage their risks effectively.

• It can be difficult for government to demonstrate the


value of risk management to the public: often this does
not become apparent until something has gone wrong.
Sound risk management prepares government to
respond more effectively to events as they occur – so
organisations are less reactive and respond with their
appetite and tolerance for risk front of mind.

6 The Centre for Long-Term Resilience, Future Proof: a roadmap to boost the UK’s resilience to extreme risks, June 2021.
Good practice guide: Overcoming challenges to managing risks in government 5

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Summary of approaches
This summarises the 10 approaches to overcoming the challenges to managing risks in government. It outlines why each one is important to
government organisations, and the actions organisations can take. Each of the 10 approaches is considered in detail from page 7.

Approach Why is this a priority? What actions can organisations take?

A tone from the top that establishes the importance of • Set the right tone at and from the top of the organisation
risk management and promotes a positive risk culture
will have greater success in driving the right behaviours • Strengthen leadership, accountability and assurance arrangements for
risk management
and actions throughout the organisation.
1 Establish strong leadership • Reduce the risk of optimism bias through independent challenge
and risk culture
• Promote a culture of psychological safety to have open dialogues around risk

Developing risk management expertise and credibility • Assess the skills and capabilities needed and address gaps
will strengthen the organisation’s ability to make
risk‑informed decisions that achieve strategic • Deliver interventions to raise risk awareness and capability across the organisation
objectives and deliver value-for-money outcomes. • Upskill and develop risk practitioners to strengthen risk management credibility
2 Build capability and expertise
• Engage risk experts and specialists where appropriate

Expressions of risk appetite and risk tolerance • Clearly articulate the levels of risk the organisation is willing to accept and tolerate
that are understood across the entire organisation
will set parameters for individuals to operate and • Base risk appetite and tolerance on good information
enable risk‑taking that supports the achievement of • Communicate risk appetite across the organisation so it can be understood
strategic objectives. and put into action
3 Define and embed risk
appetite and tolerance • Flex risk appetite to reflect changing dynamics in the environment and
management’s preferences

Anticipating future risks will enable organisations to • Continually scan the horizon for emerging and future risks and opportunities
be better prepared and more responsive to changes
and shocks. • Build in diversity to risk identification by including expert viewpoints

• Use foresight tools and futures thinking to understand uncertainty and inform
4 Take a forward-looking view risk identification

• Be imaginative in planning for severe but plausible scenarios

Decisions that are informed by robust risk management • Align risks with the organisation’s strategy, goals and objectives
will take threats and opportunities into account so the
organisation can better achieve its objectives. • Design risk management into the governance architecture

5 Make risk-informed decisions


• Be deliberate about risks and opportunities in decision making

• Engage risk expertise early in the decision-making process


Good practice guide: Overcoming challenges to managing risks in government 6

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Summary of approaches continued


Approach Why is this a priority? What actions can organisations take?

A holistic approach to risk management enables • Identify risks in the organisation and third-party ecosystem
interdependent and interconnected risks to be identified
and managed in a robust and integrated manner. • Map interdependencies and connections for cross-cutting risks

• Assess the range of impacts and consequences of risks


6 Adopt a whole-system approach
• Take a joined-up approach to managing risks and break down silos

Thorough assessment and evaluation will enable • Use the right tools and expertise to assess and evaluate risks
the impact of risks to be consistently understood
and help prioritise the different risks the organisation • Leverage good quality data to support the risk assessment effort
is managing. • Deploy qualitative and quantitative methods to assess impact
7 Assess risk impact
• Identify and assess the aggregate impact of risks across the organisation

An organisation where individuals understand their • Have clear ownership and accountability for risks
responsibilities for managing risks – and how risk
appetite and tolerance can be applied in practice – • Develop appropriate responses in line with the organisation’s risk appetite
and tolerance
will be better equipped to take effective action as
8 Take action to address risks risks develop. • Have clear criteria for escalating risks that fall outside of appetite or tolerance

• Gain assurance over the effectiveness of risk management processes

Continuous risk monitoring and effective risk reporting • Set meaningful performance metrics and indicators to monitor risks
will help focus attention on the risks that should matter
most to the organisation. • Apply tools which enable real-time and dynamic monitoring of risks

• Promote timely and accurate reporting of significant risks to key


decision‑makers
9 Monitor and report on
the risks that matter • Ensure risk registers are robust and ‘living documents’ that reflect
significant risks

Learning lessons from others and assessing risk • Assess the current level of maturity to identify gaps and areas for development
maturity will enable the organisation to continually
develop and improve its approach to risk management. • Identify and share good practice across the organisation

10 Drive continuous improvement


• Learn and share lessons from beyond the organisation

• Validate, benchmark and seek assurance over risk management arrangements


Good practice guide: Overcoming challenges to managing risks in government 7

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Establish strong leadership and risk culture


Case study
A tone from the top that establishes
the importance of risk management Why is this important?
Promoting a positive risk culture
and promotes a positive risk culture The tone and behaviours at the top of the organisation play
Background: The Risk Centre of Excellence (CoE)
will have greater success in driving a significant role in both demonstrating and reinforcing the
is working to improve risk management across
the right behaviours and actions importance of risk management. A strong risk culture enables
government. A key aspect of this is strengthening
throughout the organisation. and rewards individuals and groups for taking the right risks in
leadership and enhancing credibility.
an informed manner.7 For government organisations to respond
quickly and responsibly to risks they need up-to-date risk Approach: The CoE produces guidance and toolkits
Quote information – an organisational culture which actively encourages in ‘short sprints’ with departments and makes them
individuals to report risks without fear helps enable this. available to others in the public sector. The CoE
“Risk culture is driven from all parts of collaborated with a main ministerial department
an organisation; however, setting the Our work has shown that organisations must have effective
to develop a toolkit for addressing risk culture.
right tone from the top along with open leadership if they are to deliver their objectives: leaders must
The exercise brought together relevant internal
leadership is critical. Without that it set a clear direction and harness the talents of employees and
and external approaches to design an enhanced
can be challenging to get people to be delivery partners towards achieving that vision.8 Organisations
approach that worked within the department.
open and transparent about the risks an should aspire to have risk leaders with the seniority, skill and
The toolkit is available for other departments to
organisation might be facing. If focus experience to influence decision making.
adopt and adapt in line with Orange Book principles.
is placed on the potential negative
What did leaders and practitioners say? Benefit: The CoE was able to support a
outcome of the risk, rather than the
Strong leadership and a positive risk culture were recognised as department in taking its approach to addressing
positive of being open and transparent,
being critical to good risk management. Having senior leaders risk culture to a new level of maturity – and develop
there could be a reluctance to call
who encourage conversations around risk and incentivise the right a toolkit that allows other departments to start to
attention to risks in future.”
behaviours can overcome a blame culture in which individuals are address this issue.
Elizabeth Lupton, Head of Enterprise overly cautious or unresponsive to risks. Senior leaders should
Source: Discussion with Risk Centre of Excellence
Risk, Money and Pensions Service emphasise the value of risk management to the organisation and
support this with learning and development opportunities. This can
address issues individuals have in misunderstanding the purpose
or importance of risk management, or a wider lack of workforce
engagement in conversations around risk management.

7 The Institute of Risk Management, Risk culture Under the Microscope Guidance for Boards, October 2012.
8 Comptroller and Auditor General, Leadership development in the civil service, Session 2022-23, HC 798, National Audit Office, October 2022.
Good practice guide: Overcoming challenges to managing risks in government 8

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Establish strong leadership and risk culture continued

What actions can Set the right tone at and from the Strengthen leadership, Reduce the risk of optimism bias Promote a culture of psychological
top of the organisation accountability and assurance through independent challenge safety to have open dialogues
organisations take? arrangements for risk management around risk

The Accounting Officer, supported When there is clear and Independent and objective An open and positive culture
by the Board, will determine how transparent accountability for risk analysis of risk processes where risk can be discussed freely
to integrate risk into the normal management, individuals have a can challenge whether risk enables individuals to constructively
management systems of the sense of personal responsibility management considerations are challenge existing risk management
organisation. Consistent and strong for their actions. This influences grounded in realism and reflect practices and use their expertise
promotion of risk management from behaviours across the organisation a true assessment of the threats and knowledge in order to drive
the very top of the organisation and can help to build a strong risk being faced. improvement.
can incentivise the best risk management culture.
management behaviours.

Where have we In Managing risks in government In The challenges in In Over-optimism in government In Improving the UK’s science
(2011) we set out the role of the implementing digital change (2021) projects (2013) we looked at the capability for managing animal
seen this issue in Board in setting the tone at the top we recommended that the Central difficulties caused by unrealistic diseases (2022) we noted that The
our work? of the organisation.9 The behaviour Digital and Data Office, along with expectations and over-optimism, Department for Environment, Food
and actions of the Board and the Government Digital Service recognising them as a “particularly and Rural Affairs established a risk
the senior management team, and the Cabinet Office, should persistent risk management board to provide additional challenge
particularly how they communicate work to provide clear leadership.10 problem”.11 Issues caused by and scrutiny through a detailed
with and challenge the business, In particular, they need to revise over‑optimism, such as cost review of the Science Capability in
reinforces the importance of risk existing training programmes to overruns, delays in completion Animal Health programme’s risks.12
management, and drives and better equip and train all decision and failure to deliver the benefits At the time the report was published,
encourages a consistent approach makers with responsibility of a project, can undermine the there were indications that Defra was
to safeguarding the business. for digital transformation likely success of the project. developing a strong risk management
programmes. This should include culture across the programme,
education on legacy systems, the with evidence of recognition that a
importance of data and the risks of diversity of perspective is important
‘build before buy’ and of opting for to ensure the ‘status quo’ and ‘group
unproven technology. thinking’ are consistently challenged.

9 National Audit Office, Good practice guide, Managing risks in government, June 2011, paragraph 1.1.
10 Comptroller and Auditor General, The challenges in implementing digital change, Session 2021-22, HC 575, National Audit Office, July 2021, paragraph 8.
11 National Audit Office, Insight – Lessons learned, Over-optimism in government projects, December 2013, page 3.
12 Comptroller and Auditor General, Improving the UK’s science capability for managing animal diseases, Session 2022-23. HC 64, National Audit Office, June 2022, paragraph 3.4.
Good practice guide: Overcoming challenges to managing risks in government 9

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Build capability and expertise


Case study
Developing risk management
expertise and credibility will Why is this important?
Raising risk capability across government
strengthen the organisation’s Building capability and expertise for specialist functions
Background: In response to recommendations made by the
ability to make risk‑informed within government organisations is a big challenge.
Boardman review, the Risk Centre of Excellence (CoE) is
decisions that achieve Our own work has reported that the government faces
working to enhance capabilities and drive professionalism
strategic objectives and deliver substantial challenges to attract and retain civil service
in risk management across government.
staff.13 Developing risk management expertise in the
value‑for‑money outcomes.
organisation helps achieve strategic objectives and deliver Approach: The CoE is a single point of access to guidance
outcomes effectively and efficiently. Leading government and publications, networks, and learning and development
Quote risk management functions will have a balance of technical across government. It has taken a proactive approach to
expertise and a deep knowledge of risk management in making information widely available and sharing examples of
“A central profession has been a practice in central government. Building strong capability good practice in risk management. In addition to developing
positive move for the risk community within the risk management function establishes credibility and launching a professional accreditation, the CoE is
across government. Driving cohesion and makes a compelling case for decision makers to organising webinars bringing together cross-departmental
in how we do things and building maintain a strong risk culture within the organisation. risk management leads to discuss a range of topics,
the professionalism in people and recordings of which are available online.14 Some of the
upskilling. Having this network helps What did leaders and practitioners say? topics covered in the seminars include portfolio risk thinking,
to identify common problems, share Leaders we talked to said risk management may not risk management improvement planning, risk appetite, risk
best practice, and gives us the ability always be seen as a priority. Organisational leaders must be implications in decision making and risk assurance mapping.
to address risks across the system not convinced of its importance and value to the organisation so
Benefit: By bringing together risk management leads
just departmental level.” that the challenge of building capability and expertise can
the CoE is building communities and networks across
be properly addressed. Some also mentioned the difficulty
Upasna Sagar, Chief Risk Officer, government, and by sharing guidance, publications and
of competing with the private sector to attract and retain
Ministry of Defence examples of good practice it can help to create a common
accredited or qualified risk practitioners and the need for
language, drive consistency in approaches and enable
developing risk management training.
developments in the profession to be applied.

Source: Discussion with Risk Centre of Excellence

13 Comptroller and Auditor General, Civil service workforce: Recruitment, pay and performance management, Session 2023-24, National Audit Office, November 2023.
14 See footnote 5.
Good practice guide: Overcoming challenges to managing risks in government 10

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Build capability and expertise continued

What actions can Assess the skills and capabilities Deliver interventions to raise risk Upskill and develop risk Engage risk experts and specialists
needed and address gaps awareness and capability across practitioners to strengthen risk where appropriate
organisations take? the organisation management credibility

Risk leaders should use a skills Raising risk awareness increases Creating opportunities to The organisation should know
matrix to assess the function’s the likelihood of people across the professionalise the risk function where in-house capability is
existing capability and then organisation understanding the will help to promote risk insufficient so that external expertise
identify gaps. This will enable the importance of risk management. management, drive value and build can be targeted in the right areas.
organisation to target efforts on Risk leaders can develop training credibility across the organisation. Knowing when to bring in expertise
building resilience by equipping to increase risk management Professional development should enables organisations to make
the organisation with the right risk capability across the organisation. be tailored to the current and well‑informed risk-based decisions.
management skills and capabilities More routinely, they can share future needs of the organisation
for the future. knowledge, insights and outcomes so it can respond to existing and
to promote the ongoing importance emerging risks.
of risk activities.

Where have we In Improving services – In Government resilience: extreme In Financial management in In Tackling fraud and corruption
understanding and managing weather (2023) we noted that government: enablers of success against government (2023) we
seen this issue in demand (2022) we recognised that the Cabinet Office now produces (2023) we noted that technical and noted that the Public Sector Fraud
our work? people providing the service must a regular UK Resilience Lessons professional skills are essential.17 Authority (PSFA) brought together
have the skills and tools they need Digest, which summarises lessons Professional skills enhance counter‑fraud experts to reduce the
to do their jobs.15 A skills matrix from a range of sources to share confidence and help to establish impact of fraud in departments and
can help you to see the capabilities insights across government and credibility with stakeholders, such public bodies.18 To assist HM Treasury
needed to undertake the work wider partners.16 For example, the as individual budget-holders, and (HMT) in embedding counter-fraud
and identify any training gaps first issue in October 2022 shared provide a level of assurance to the measures into its policy making, the
and needs. lessons from Storm Arwen in 2021. Accounting Officer on the quality of PSFA developed and implemented
financial management information a process to apply counter‑fraud
produced. This principle also expertise to the development of new
applies in risk management. spending initiatives through the use
of Initial Fraud Impact Assessments.

15 National Audit Office, Good practice guide, Improving services – understanding and managing demand, February 2023, page 7.
16 Comptroller and Auditor General, Government resilience: extreme weather, Session 2023-24, HC 314, National Audit Office, December 2023, paragraph 16.
17 National Audit Office, Good practice guide, Financial management in government: enablers of success, July 2023, page 16.
18 Comptroller and Auditor General, Tackling fraud and corruption against government, Session 2022-23, HC 1199, National Audit Office, March 2023, paragraph 2.5.
Good practice guide: Overcoming challenges to managing risks in government 11

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Define and embed risk appetite and tolerance


Case study
Expressions of risk appetite
and risk tolerance that are Why is this important?
Using risk appetite to inform trade-offs
understood across the entire Risk appetite sets the guardrails for the level of risk an organisation
Background: In designing employment support
organisation will set parameters is willing to take and those that can be absorbed in pursuit of the
schemes during the COVID-19 pandemic, HM Revenue
for individuals to operate organisation’s strategic plan and objectives; it provides a framework that
& Customs (HMRC) acknowledged that it would
and enable risk taking that enables an organisation to make informed management decisions and
need to make certain trade-offs between preventing
trade-offs. Government organisations need to decide the level of risk
supports the achievement as much fraud and error as possible and ensuring
they are willing to tolerate or accept – ideally for each significant risk.
of strategic objectives. Risk appetite can apply to whole organisations or be specific to different
grants reached claimants quickly.

business or policy areas – the key thing for government organisations is that Approach: HMRC drew up longlists of potential
Quote it is well understood and can be applied in practice by decision makers. controls for both its employment schemes. In total it
identified 42 potential controls for the Coronavirus
In our own work we have reported that government needs to define its risk
“It is important to be clear Job Retention Scheme (CJRS), of which 24 were
appetite to make informed decisions and prepare appropriately so that
on the parameters for risk implemented by the go-live date and 57 for the
value for money can be protected.19 Organisations sometimes fail to clearly
appetite: where are we now, Self‑Employment Income Support Scheme (SEISS),
articulate desired end states and what needs to be done to get there in terms
where do we ideally want to of which 38 were delivered by the end of April 2020.
of investment and resources. Overcoming this challenge requires a clear
be, and what is the position HMRC’s planning assumptions were that between
understanding of the gap between current performance and position and the
we are having to tolerate? 5% and 10% of payments from the CJRS and
desired end state – only with this foundation will organisations then be able to
The tolerable risk position is a between 1% and 2% of payments from the SEISS
monitor and track progress in driving risk down to an acceptable level.
band that moves: it can expand were due to fraud and error. In September 2020, this
or shrink to take account of What did leaders and practitioners say? amounted to between £2 billion and £3.9 billion for
available funding, facilitate the CJRS and between £130 million and £270 million
A particular challenge our interviewees raised was that many risks are for the SEISS.
delivery of outcomes and
unavoidable or cannot be mitigated – government organisations cannot
reflect the appetite of ministers Benefit: HMRC was able to act quickly by making
simply ‘opt out’ of some significant risks that they are legislatively
and the government of the day.” decisions that were informed by its understanding of
required to undertake. Some of our interviewees cited transparency in
Jo Collins, Chief Risk Officer, decision making as an additional challenge, particularly when operating its risk appetite and risk tolerance levels.
Ministry of Justice outside of appetite.
Source: Initial learning from the government’s response to
the COVID-19 pandemic20

19 Comptroller and Auditor General, The government’s preparedness for the COVID-19 pandemic: lessons for government on risk management,
Session 2021-22, HC 735, National Audit Office, November 2021.
20 Comptroller and Auditor General, Initial learning from the government’s response to the COVID-19 pandemic, Session 2021-22, HC 66,
National Audit Office, May 2021.
Good practice guide: Overcoming challenges to managing risks in government 12

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Define and embed risk appetite and tolerance continued

What actions can Clearly articulate the levels of Base risk appetite and tolerance on Communicate risk appetite Flex risk appetite to reflect changing
risk the organisation is willing good information across the organisation so dynamics in the environment and
organisations take? to accept and tolerate it can be understood and management’s preferences
put into action

Having a consistent and Having good information enables leaders A common understanding Unexpected systemic risks, such as the
up-to‑date understanding of to set risk appetite and put it into action of risk appetite can help pandemic, have shown that risk appetite
risk appetite and tolerance with greater confidence. This will enable to tackle confusion and cannot be static and remain useful.
on an individual risk basis management to come to an informed positively influence risk A dynamic approach that reflects changes
will help to inform decisions conclusion on what is and is what is not behaviours. Individuals to the internal and external environment
around prioritisation and tolerable – so they can make informed across the organisation helps to ensure that risk appetite can be
trade-offs and create a more choices and trade-offs. benefit from understanding applied confidently when it is most needed.
transparent understanding how their day‑to‑day
of consequences. decisions can and should be
informed by risk appetite.

Where have we In Government resilience: In COVID-19 business grant schemes In Managing risks in In Environmental Sustainability Overview
extreme weather (2023) (2023) we reported that in the pandemic government (2011) (2023) the Department for Education (DfE)
seen this issue in we recommended that the ministers made decisions to accept we recommended the recognised – in response to risks from
our work? Cabinet Office, working additional risks in the set-up and delivery question be asked “are climate change – that it was operating
with lead government of grant support for businesses.22 we clear about where we outside its risk appetite for the education
departments, should: We recognised in our other work on the are prepared to tolerate system, particularly the education estate.24
COVID-19 response that the government differing levels of risk and, Its departmental risk appetite statement
• assess the current level of needed to make urgent decisions with in turn, how this influences set out a need for investment to match
risk and how that risk is limited information to respond to an and drives the actions of DfE’s sustainability ambition, a need to limit
changing over time; unprecedented public health emergency. management?”23 By defining financial risk by piloting new approaches,
• decide what is the tolerable However, even in emergency situations we and communicating tolerance and an emerging risk of physical damage or
and acceptable level for noted that we would expect officials to: of risk, staff are empowered school closure without investment to improve
that risk (or sets of similar to make decisions, identify the resilience of the education estate.
risks) and set out ‘what
• consider risks at the start and put in priority areas for investment DfE committed to publish a risk assessment
place basic controls; and and be clear about when of flood, overheating and water scarcity of
good looks like’ now and in
the future; and • improve their understanding of issues need to be escalated the education estate, to be reviewed on an
risks and the effectiveness of for their attention. annual basis from 2023. It plans to use the
• identify the gap between
controls over time, refining the assessment to increase its understanding of
this and the current climate risk and target its intervention.
programme accordingly.
performance and position.21

21 See footnote 16, paragraph 29c.


22 Comptroller and Auditor General, COVID-19 business grant schemes, Session 2022-23, HC 1200, National Audit Office, March 2023, paragraph 5.
23 National Audit Office, Good practice guide, Managing risks in government, June 2011, page 5.
24 Comptroller and Auditor General, Environmental Sustainability Overview, Session 2022-23, HC 1514, National Audit Office, June 2023, paragraph 3.29.
Good practice guide: Overcoming challenges to managing risks in government 13

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Take a forward-looking view


Case study
Anticipating future risks
will enable organisations The challenge for government
Integrating futures thinking
to be better prepared Risk management is inherently future focused.
Background: Futures thinking is an important part of the Crown
and more responsive to It requires foresight to look ahead to future risks
Prosecution Service’s (CPS) organisational strategy. The CPS aims
changes and shocks. and opportunities that extend beyond the long-term.
to lead on futures thinking to understand issues across the criminal
This enables government to anticipate and be better
justice system to prepare today for tomorrow’s challenges.
prepared for potential threats and opportunities before
Quote
they materialise and ensure decisions are made with Approach: The CPS Strategy Team has designed a bespoke model
short and long-term impacts in mind. to apply futures thinking and drive preparedness. Horizon scanning
“We need to pay greater involves casting a wide net, using desk research and a network of
attention to extreme event Our work has highlighted the need for the government
contacts to identify the issues that could affect the CPS in years to
scenarios, emerging risks to balance immediate and competing demands with
come. The team uses a bespoke sifting tool to narrow down the list of
and the different futures that long-term value for money. These near-term demands
potential issues to a longlist, which they analyse in detail. They then
might ensue. If we anchor risk make it harder to invest time in forward-looking risk
engage with internal and external stakeholders to explore insights and
thinking to problems that are management strategies, identification exercises and
test assumptions, agree on a short list and decide on actions.
merely inconvenient and thus scenario planning. Where scenarios are considered,
manageable, we will likely be they are often limited in range and imagination. Benefit: The clear annual process makes futures work focused,
blindsided by eventualities Organisations should consider how technology can practical and accessible, and helps to better understand uncertainty
due to a failure of imagination. be used to enhance future planning. Overcoming this and prepare for challenges in the future.
We will have squandered the challenge ultimately requires time and resources to be
Source: Integrating futures thinking in the Crown Prosecution Service –
opportunity for anticipatory dedicated to looking ahead. Futures, Foresight and Horizon Scanning25
adaptation by relying on
What did leaders and practitioners say?
risk management practices,
resilience strategies and During our interviews, leaders and practitioners told us
levels of investment that are that they constantly make trade-offs between short-term
increasingly unfit for purpose.” issues and long-term objectives, and that although they
want to encourage more long-term thinking it is difficult to
Richard Smith-Bingham,
prioritise when there are immediate demands. Often the
Executive Director,
focus ends up being more towards short-term threats.
Marsh McLennan

25 Government Office for Science, Integrating futures thinking in the Crown Prosecution Service, November 2023.
Good practice guide: Overcoming challenges to managing risks in government 14

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Take a forward-looking view continued

What actions can Continually scan the horizon for Build in diversity to risk Use foresight tools and futures Be imaginative in planning for severe
emerging risks and future threats identification by including thinking to understand uncertainty but plausible scenarios
organisations take? and opportunities expert viewpoints and inform risk identification

Continuous and dynamic horizon A robust risk identification should Organisations should apply a range Considering a range of scenarios,
scanning helps the organisation include different viewpoints, a of methods to assess uncertainty. including those that are severe
to consider scenarios which range of experiences and, where Foresight methods and futures but plausible, can improve the
could present emerging risks and appropriate, the views of subject thinking can help to identify and organisation’s response to
opportunities.26 Using real-time matter experts. Increasing the anticipate long-range threats and unexpected shocks. Scenarios
information to identify emerging diversity of individuals and thought opportunities. Balancing this with should consider multiple and parallel
risks will enable the organisation to will help tackle bias and groupthink retaining corporate memory and interactions and be stress tested.
be better prepared to respond with and allow less familiar risks to be monitoring trend data will inform
greater agility to future threats and identified and monitored. long-term outcome delivery.
exploit opportunities.

Where have we In The energy supplier market, In Delivery Environment In Cross-government working – In Monitoring and responding to
(2022) we concluded that by Complexity Analytic: Understanding Good practice guide (2023) we companies in distress – Good
seen this issue in allowing many suppliers to enter challenges in delivering project encouraged departments to use practice guide (2023) we stated
our work? the market and operate with weak objectives – Good practice guide data to support regular discussions that for scenario planning we would
financial resilience, and by failing (2022) we recommended that between partnering departments expect to see:
to imagine a scenario in which organisations take a range of to review performance, hold each
there could be sustained volatility different actions, including pilots, other to account and identify and • clear and consistent assessment
in energy prices, Ofgem allowed trials or testing of the complex assess emerging risks.29 of risks through scenario testing,
a market to develop that was or new elements of the project, both short and long term;
vulnerable to large-scale shocks to identify risks, and bring in • systematic testing of a range
and where the risk largely rested subject matters experts to advise of possible scenarios and
with consumers, who would pick up on potential sources of complexity.28 the implications for industry,
the costs in the event of failure.27 customers and citizens; and

• identification and mitigation of


any gaps in the government’s
ability to respond to different
possible scenarios.30

26 The Institute of Risk Management define an emerging risk as “a risk that is evolving in areas and ways where the body of available knowledge is weak”. Institute of Risk Management,
An introduction to emerging risks and how to identify them (accessed 14 December 2023).
27 Comptroller and Auditor General The energy supplier market, Session 2022-23, HC 68, National Audit Office, June 2022, paragraph 20.
28 National Audit Office, Good practice guide, Delivery Environment Complexity Analytic: Understanding challenges in delivering project objectives, November 2022, page 27.
29 National Audit Office, Good practice guide, Cross-government working, July 2023, page 10.
30 National Audit Office, Good practice guide, Monitoring and responding to companies in distress, October 2023, page 11.
Good practice guide: Overcoming challenges to managing risks in government 15

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Make risk-informed decisions


Case study
Decisions that are
informed by robust risk Why is this important?
Being deliberate about risks and opportunities in decision making
management will take Risk management should be a key driver to better and
Background: Defra has needed to manage the risks and opportunities
threats and opportunities informed decision making. Departments face challenges
associated with EU exit. EU exit created an unprecedented portfolio
into account so the in developing an integrated and consistent approach
of work that Defra needed to deliver, which brought a risk that less
organisation can better to managing risks in a dynamic environment, and
immediate issues such as metrics would not get sufficient resource
approaches that are tailored to their own circumstances
achieve its objectives. and senior management focus. At the same time, we considered that
are likely to be the most effective.
the EU exit could bring opportunities to review wider reporting to
Government departments need to aim for high-quality assess whether it all added value in relation to UK goals.
Quote
and robust strategic conversations in which relevant
Approach: Although there was a risk that some data would no longer
factors are being considered when making decisions
“Risk management needs be collected if it was not required to be reported to the EU, there may
on planning, long-term investment, prioritisation and
to be embedded in the also have been an opportunity to simplify or innovate dataflows that
trade-offs.
fabric of organisational were complex or included perverse incentives. Stakeholders identified
strategy and practice. What did leaders and practitioners say? waste and recycling reporting as an example: recycling metrics were
We need a holistic view of weight-based, which meant there was an incentive to recycle more
risks linked with strategic Although there is now a better understanding of the dense materials rather than lower-density materials such as plastics.
objectives. Without sufficient importance of risk-informed decision making, risk is
still not embedded at the core of the processes to drive Benefit: This example shows how considering both risks and
awareness, how can we
decisions. There can be a disconnect between different opportunities can lead to more-informed decision making.
manage risk effectively?”
functions – for example policy, operations and risk
Source: Environmental metrics: governments approach to monitoring the state
Dr Ini Enang, Senior management – which leads to these functions working of the natural environment31
Lecturer/Assistant Professor in isolation instead of informing each other to strengthen
in Risk Management, overall decision making.
Coventry University

31 Comptroller and Auditor General, Environmental metrics: government’s approach to monitoring the state of the natural
environment, Session 2017-2019, HC 1866, National Audit Office, January 2019.
Good practice guide: Overcoming challenges to managing risks in government 16

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Make risk-informed decisions continued

What actions can Align risks with the organisation’s Design risk management into the Be deliberate about risks and Engage risk expertise early in the
strategy, goals and objectives governance architecture opportunities in decision making decision-making process
organisations take?
Risk, by definition, is the impact Governance and oversight Well managed risk taking Engaging risk experts at the right
of uncertainty on objectives. arrangements need to clearly factor should consider both threats time during the formation of the
Linking risks to organisational in risk management considerations. and opportunities. At its best, decision-making process means
objectives is central to This will help keep risk management risk management can support threats and opportunities are not
meaningful risk management. at the centre of decision making. innovation, transformation only considered but are underpinned
Without a clear end goal, the and change, and help to by well informed assessments.
real value of risk management deliver efficiencies.
will not be achieved.

Where have we In Climate change risk: A In Decarbonising the power sector In Managing Risks to Improve In Energy bills support (2023) we
good practice guide (2021) we (2023) we noted that, in relation Public Services (2004) we noted noted that to introduce the Energy
seen this issue in recognised that climate change to power sector portfolio risk that well managed risk taking Price Guarantee and the Energy Bill
our work? risks have a range of impacts management, we would expect the presents opportunities to innovate, Support Scheme quickly, the then
across an organisation, and in Department for Energy Security experiment and develop new ideas, Department for Business Energy
order to properly manage these and Net Zero (DESNZ) to use risk where more traditional ways of and Industrial Strategy (BEIS) told
risks, they need to be understood information to inform decision working are not able to deliver real us that it used its experience from
and firmly integrated as part making, including through reporting change.34 Indeed, the greatest risk implementing projects at speed
of an organisation’s strategy.32 risks to critical stakeholders.33 of all may be not taking any risks, during the pandemic.35 This led to
As organisations are making where services and the way they collaborating from the outset with the
strategic decisions, it is essential are delivered do not anticipate Public Sector Fraud Authority, which
that climate change risk is fully change or evolve to meet new supported BEIS to better understand
understood and continually demands from citizens. fraud risks across the schemes.
evaluated alongside all other
principal risks.

32 National Audit Office, Climate change risk: A good practice guide for Audit and Risk Assurance Committees, August 2021, page 17.
33 Comptroller and Auditor General, Decarbonising the power sector, Session 2022-23, HC 1131, National Audit Office, March 2023, paragraph 2.26.
34 Comptroller and Auditor General, Managing Risks to Improve Public Services, Session 2003-2004, HC 1078-1, National Audit Office, October 2004, paragraph 2.
35 Comptroller and Auditor General, Energy bills support, Session 2022-23, HC 1025, National Audit Office, February 2023, paragraph 2.9.
Good practice guide: Overcoming challenges to managing risks in government 17

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Adopt a whole-system approach


Case study
A holistic approach
to risk management Why is this important?
Take a joined-up approach to break down silos
enables interdependent Delivering public services is often complex, involving
Background: Change delivery is often complex and has risks and
and interconnected different parts of the organisation, others across
dependencies associated with it. HM Land Registry (HMLR) believed
risks to be identified and government, and other sectors and third parties.
their governance was effective when it came to delivery – but
managed in a robust and Risks often have cross-cutting impacts that extend
sometimes they did not capture everything that was required to fully
across organisational boundaries. To effectively manage
integrated manner. understand a business problem in a structured way. This impacted
these interdependent and interconnected risks the
their ability to make the most effective risk-based decisions while
organisation needs to take a whole-system approach.
considering risk interdependencies.
Quote
Our work has often highlighted the challenges
Approach: HMLR use their Enterprise Design Hub to help address
associated with taking a whole-system approach to
“Systems are increasingly this issue. The approach consists of four main stages: Strategic
achieve a consistent view of risk that includes an
interdependent and Design, Product/Service Design, Planning & Prioritisation and
understanding of how risks interact and impact across
interconnected; when a Delivery. The Hub has been at the heart of shaping HMLR’s
organisational and departmental boundaries.36
problem hits the system, new ways of working from design through to delivery: working
it cascades. Yet risks are What did leaders and practitioners say? collaboratively with other groups from across the organisation,
being managed within silos, identifying interdependencies between risks, and giving risks
vertically not horizontally. Our interviewees told us that departments and greater visibility across the organisation.
We need to see collective arm’s‑length bodies (ALBs) tend to operate in
silos, which makes it difficult to manage shared Benefit: These new ways of working are helping HMLR to more
actions and coordination across
risks. They noted that there is a need for a effectively plan resources and investments to optimise successful
government to understand the
better understanding of shared risks and their delivery outcomes in order to meet organisational priorities. It has
risk better, how it translates
impacts across government, and improved sharing helped connect the strategic intent of HMLR with the changes
into preparedness and change
of information and good practice on how these risks required to deliver their Business Plan objectives and enabled more
the conversations to focus
can be managed effectively. effective management of cross-cutting risks. By adopting these
more on the risk consequence.”
new ways of working HMLR has begun to mitigate more effectively
David Denyer, Professor of the key risks associated with change and to ensure there is greater
Leadership and Organisational transparency of key change activities across the organisation.
Change, Cranfield University
Source: Interview with HM Land Registry

36 Comptroller and Auditor General, The government’s preparedness for the COVID-19 pandemic: lessons for government
on risk management, Session 2021-22, HC 735, National Audit Office, November 2021.
Good practice guide: Overcoming challenges to managing risks in government 18

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Adopt a whole-system approach continued

What actions can Identify risks in the organisation Map interdependencies and Assess the range of impacts and Take a joined-up approach to
and third-party ecosystem connections for cross-cutting risks consequences of risks managing risks and break down silos
organisations take?
Risks can cascade, amplify and To manage cross-cutting risks In addition to identifying risks that Risk management cannot be effective
compound, resulting in more effectively, risk teams should map cross departmental boundaries, in isolation. Taking a joined-up
significant impacts and unintended connections between risks and organisations require a strong approach may require collaboration
consequences. Risk teams should understand how they interact. understanding of the impact and across the departmental group, other
identify risk information from not Bringing together the right parties consequences of risks materialising. government departments and with
just across the organisation but will enable leaders to design This requires an appreciation of the delivery partners to create a shared
beyond – including delivery partners actions to manage risks in a impact of risks that exist outside of understanding of risks.
and the whole supply chain. holistic and joined-up way. the organisation’s direct control.

Where have we In Central oversight of arm’s-length In Achieving government’s In Decarbonising the power In Efficiency in government (2021)
bodies (2021) we recommended long-term environmental goals sector (2023) we noted that we outlined practical considerations
seen this issue in that departments and the Cabinet (2020) we recognised that DESNZ was developing and to identifying efficiency gains in
our work? Office should establish standards the Implementation Board and maturing its end‑to‑end portfolio government ahead of the Spending
and good practice for monitoring Environment Committee brought risk management framework.39 Review.40 For example, we noted the
ALB risks at departmental and together relevant parties from Risk management processes role of HM Treasury in providing a
cross‑government levels.37 different teams in Defra and its existed for each programme within cross-government perspective to
This should include establishing ALBs to discuss cross-cutting the portfolio, and information on identify potential consequences for
strong links between the Cabinet issues and to consider strategic each project’s most significant risks citizens that departments may have
Office and the Government Finance risks and issues for the delivery (that satisfy certain criteria) was missed, and to consider wider risk
Function on cross‑departmental of the 25 Year Environment Plan escalated for review by the energy implications such as the cumulative
risks, and between departmental as a whole.38 portfolio office. However, not all risk to different groups (for example,
heads of risk on risks across their risks were aggregated across age, location, ethnicity) and risk
respective ALBs. the portfolio and there was no exposure from efficiency plans.
portfolio-wide view of the top risks
to decarbonising the power sector.

37 Comptroller and Auditor General, Central oversight of arm’s-length bodies, Session 2021-22, HC 297, National Audit Office, June 2021, paragraph 24e.
38 Comptroller and Auditor General, Achieving government’s long-term environmental goals, Session 2019–21, HC 958, National Audit Office, November 2020, paragraph 14.
39 Comptroller and Auditor General, Decarbonising the power sector, Session 2022-23, HC1131, National Audit Office, March 2023, paragraph 2.27.
40 Comptroller and Auditor General, Efficiency in government, Session 2021-22, HC 303, National Audit Office, July 2021, paragraph 14.
Good practice guide: Overcoming challenges to managing risks in government 19

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Assess risk impact


Case study
Thorough assessment
and evaluation will enable Why is this important?
Use qualitative and quantitative methods to assess the impact of risks
the impact of risks to be The current risk environment under which the
Background: In 2020, a new team was established in the Nuclear
consistently understood government operates is highly complex and volatile,
Decommissioning Authority (NDA) to set standards, provide guidance, and
and help prioritise with many interconnected risks. The government has
facilitate good practice risk management. It became apparent that, over time,
the different risks the to robustly evaluate risks, their interdependencies and
approaches to risk management across the group had diverged. While there
their end‑to‑end impact, to inform decision making.
organisation is managing. were many pockets of good practice, there were also areas requiring attention.
Our work has sometimes shown that the government
does not always hold detailed information and relevant Approach: The NDA group approach to maturing risk management is
Quote data to assess the full impact of risk.41,42 multifaceted. However, three early interventions targeted consistency of risk
information and improvements in risk estimation:
Government organisations not only need the tools
“You need the right tools
and expertise to assess the impact of individual a Qualitative risk assessment and risk aggregation;
and access to intelligence
risks crystallising – but they also need to assess the b Common principles/approaches to quantitative risk analysis (QRA); and
to really understand
impact of multiple risks crystallising. Recent years
risks. Bringing different c Introduction of reference class forecasting (RCF) as a counter to
have shown how events like the COVID-19 pandemic
perspectives and thinking optimism bias.
and the energy crisis have disrupted organisations.
about other impacts
Risk leaders increasingly need to operate in this Each business area used its own variation of a probability-impact diagram
improves risk assessment
landscape of ‘polycrisis’.43 (PID) to qualitatively evaluate risks, making consolidated risk reporting –
and reporting. Tools need to
especially given differing risk appetites – difficult. This was addressed by
enable this to happen.” What did leaders and practitioners say? creating and mandating a new corporate PID that each business could use for
Richard Ryder, Head of Our interviewees mentioned both the lack of good NDA reporting. Differing approaches and gaps in QRA meant that the basis of
Risk & Control Framework quality data across government and the lack of risks underpinning business-case values was inconsistent, with nuances not
Team, HMRC tools necessary to make assessments. To tackle the well understood by decision makers. In response, a set of common modelling
challenge, they suggested using both qualitative and principles was established while retaining a proportionate approach to the use
quantitative methods to assess impact and bringing in of complex techniques.
a diversity of perspectives. Benefit: Applying RCF, by taking the ‘external view’, has allowed the NDA
group to combat early-stage underestimation that tends to set low and
narrow exposure range expectations for risks. The cumulative effect of these
interventions has been a more digestible summary of Group Strategic Risks and
41 Comptroller and Auditor General, Efficiency in government, Session 2021-22, HC 303, National Audit Office, July 2021.
greater confidence that forecasts are becoming less overly optimistic.
42 Comptroller and Auditor General, Electricity networks, Session 2019-20, HC 42, National Audit Office, January 2020.
43 Polycrisis is “a time of great disagreement, confusion, or suffering that is caused by many different problems happening Source: Discussion with Nuclear Decommissioning Authority
at the same time so that they together have a very big effect”, Cambridge Dictionary (accessed 23 November 2023).
Good practice guide: Overcoming challenges to managing risks in government 20

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Assess risk impact continued

What actions can Use the right tools and expertise to Leverage good quality data to Deploy qualitative and quantitative Identify and assess the
assess and evaluate risks support the risk assessment effort methods to assess impact aggregate impact of risk across
organisations take? the organisation

Organisations should consider how Data is essential for assessing A range of quantitative and Properly identifying and assessing the
Governance, Risk and Compliance the scale, likelihood and potential qualitative methods should be used impact of risks gives decision makers
advanced risk analytics, artificial impact of risks. Organisations need to ensure impact assessments are a better understanding of threats
intelligence, risk modelling, scenario to collect and access the right data realistic. Quantitative methods are and opportunities. Leaders and
and sensitivity analysis, and to improve their understanding of particularly helpful to decision practitioners need to develop a clear
stress-testing tools can improve how risks are developing, support makers in understanding the scale understanding of how risks and their
risk assessment and evaluation. their risk assessment and inform of risk impact. consequences interact.
Accessing the right expertise at the their risk treatment plans.
right time can also enhance how
well risks are assessed, understood
and prioritised.

Where have we In The rollout of the COVID-19 In Local authority investment In Financial modelling in government In Progress of the 2016–2021
vaccination programme in England in commercial property (2020) (2022) we recommended that National Cyber Security Programme
seen this issue in (2022) we noted that NHS England we recommended that the then HM Treasury (HMT) should build on (2019) we recommended that the
our work? and NHS Improvement (NHSE&I) Ministry of Housing, Communities its current approach to quantifying Cabinet Office should continue
were open about uncertainties & Local Government should uncertainty and risk analysis by to consult with other government
they faced.44 They made use improve the relevance and quality requiring departments to present departments to understand their
of techniques such as scenario of data and analysis it has on HMT with a range of plausible cyber security priorities.47 This would
planning and sensitivity analysis local authorities’ acquisition of outcomes from business‑critical allow them to contribute to any
to explore the impact of certain commercial property to understand models as a matter of routine.46 future strategy and programme and
patterns of vaccine availability, more fully any associated risks and This range should be driven by key enable the Department to aggregate
vaccine uptake and rollout speed. to provide greater assurance on inputs and model parameters to cyber opportunities and risks to
framework compliance.45 take account of where there might better prioritise overall government
be material uncertainties around activity in this area.
best estimates.

44 Comptroller and Auditor General, The rollout of the COVID-19 vaccination programme in England, Session 2021-22, HC1106, National Audit Office, February 2022, page 65.
45 Comptroller and Auditor General, Local authority investment in commercial property, Session 2019-20, HC 45, National Audit Office, February 2020, paragraph 28a.
46 Comptroller and Auditor General, Financial modelling in government, Session 2021-22, HC 1015, National Audit Office, January 2022, paragraph 23d.
47 Comptroller and Auditor General, Progress of the 2016–2021 National Cyber Security Programme, Session 2017-2019, HC 1988, National Audit Office, March 2019, paragraph 24b.
Good practice guide: Overcoming challenges to managing risks in government 21

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Take action to address risks


Case study
An organisation where
individuals understand their Why is this important?
Align actions with risk appetite and tolerance
responsibilities for managing Accountability for risks should be clear to everybody in the organisation
Background: The number of Universal Credit
risks – and how risk appetite – from the Board down. Responses to risks – including treatment options
claimants roughly doubled in 2020 and the
and tolerance can be applied to manage risks to an acceptable level – should be clearly articulated and
Department for Work & Pensions (DWP) suspended
in practice – will be better in line with the organisation’s risk appetite. Decisions on when and how
some controls such as face-to-face appointments
to address risks involve balancing costs of implementation – for instance
equipped to take effective to support vulnerable people during lockdown and
putting new controls in place – with the benefits of the overall impact on
action as risks develop. the risk itself – such as reducing harm or enhancing outcomes. Achieving
manage demand.

this balance can be challenging when operating in a dynamic environment. Approach: Of Universal Credit payments, £1.7 billion
Quote (9.4%) were overpaid in 2019-20 before COVID-19.
Many risks cut across organisational boundaries – leaders and practitioners
DWP accepted that the increased caseload and
need to coordinate actions with other organisations outside of their direct
“Risk response analytics easements made to the process of applying for
control. Complex cross-government challenges – for instance achieving
allow us to identify trends benefits would lead to a further increase in fraud
net zero – present risks that require leaders to engage with the centre of
and understand the impact of and error levels.
government and other departments to understand which actions are within
the controls and responses.
their control and which are not. Benefit: By being clear on risk appetite and tolerance
They allow the risk team to
and the impact of relaxing controls, DWP was able
look at the system objectively What did leaders and practitioners say? to adapt to changing circumstances and take action
and make suggestions –
It can be difficult to get assurance on whether the right actions are being to issue benefit payments quickly to claimants, in
allowing controls to be
taken to manage risks and the degree to which actions are effective. order to avoid hardship.
linked and shared, joining up
Leaders and practitioners suggested that one of the reasons is the lack
responses for similar threats.” Source: Initial learning from the government’s response to
of accountability for risks, resulting in a lack of ownership to take actions. the COVID-19 pandemic48
Fay Carradine, Departmental The challenge intensifies when there are activities that involve multiple
Risk Lead, Department for departments, or delivery bodies that have different priorities and different
Science, Innovation and appetites for risk, particularly if responsibilities for managing risks are not
Technology clearly defined.

48 See footnote 20.


Good practice guide: Overcoming challenges to managing risks in government 22

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Take action to address risks continued

What can senior Have clear ownership and Develop appropriate responses Have clear criteria for escalating Gain assurance over effectiveness of
accountability for risks for significant risks in line with risks that fall outside of appetite risk management processes
leaders and risk the organisation’s risk appetite or tolerance
practitioners do? and tolerance

This will ensure that actions to Aligning responses and risk actions Having clear criteria for escalating Risk leaders should embed oversight
manage risks are taken and can to risk appetite will ensure that risks improves transparency and and assurance into risk management
be independently challenged by mitigations are reducing risks to makes it easier for individuals to arrangements – particularly those
others. It is particularly important acceptable levels, or that actions know when to escalate risks that that assess how effective processes
to have clarity of ownership for are enhancing the benefits of are above tolerance and require are in managing risks.
complex risks that involve different opportunities. immediate action.
aspects of the organisation or
other delivery partners.

Where have we In Financial management In British Business Bank (2020) In Electronic monitoring: a progress In Local Authority governance
in government: enablers of we noted that the Bank’s update (2022) we noted that (2019) we recommended that local
seen this issue in success (2023) we set out that management recognised that HM Prison & Probation Service’s authorities need to ensure that
our work? responsibilities should be clear growth had placed pressure on plans for an improved integration they have robust risk management
in role descriptions and provide its governance and operations.50 assurance function, and its arrangements in place when making
individuals with the time to execute With the expectation of the Bank new risk escalation framework, commercial investments to generate
those responsibilities.49 Applying growing further, in 2018 the Bank’s would ensure more timely and new income, and that oversight
the three lines of defence model management chose to temporarily appropriate scrutiny.51 and accountability are clear when
to establish ownership of risk, operate outside its operational risk entering into shared service or
key roles and responsibilities, and appetite while adopting a number outsourced arrangements in order
accountabilities can significantly of initiatives to strengthen its to deliver savings.52
contribute to the organisation’s processes and controls. By the end
overall approach to managing risks. of 2018-19 the Bank concluded
that it had returned to within its
operational risk appetite, as a
result of these actions.

49 See footnote 17, page 13.


50 Comptroller and Auditor General, British Business Bank, Session 2019-20, HC 21, National Audit Office, February 2020, paragraph 16.
51 Comptroller and Auditor General, Electronic monitoring: a progress update, Session 2022-23, HC 62, National Audit Office, June 2022, paragraph 14.
52 Comptroller and Auditor General, Local authority governance, Session 2017–2019, HC 1865, National Audit Office, January 2019, paragraph 5.
Good practice guide: Overcoming challenges to managing risks in government 23

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Monitor and report on the risks that matter


Case study
Continuous risk monitoring
and effective risk reporting Why is this important?
Monitoring the risks that matter to
will help focus attention on the The risk landscape is constantly evolving, with new and emerging risks the organisation
risks that should matter most surfacing and evolving. Effective risk management demands that risks are
Background: Alongside its response to
to the organisation. monitored and reported to ensure risks are being focused on and managed.
the pandemic, HMRC needed to continue
Risk monitoring also entails assessing vulnerabilities in the organisation’s
monitoring and addressing new and emerging
operations or the system. This can include the condition of assets, existing
Quote risks. The tax system is a continual target for
IT or physical infrastructure, processes or business operations, and
fraud and criminal attacks.
workforce capacity to support organisational or project objectives.
“When it comes to risk reporting Approach: HMRC therefore needed to
we need to engage the Board by Given the many competing demands for management’s focus and attention,
maintain a base level of resource to monitor
ensuring information and insights it can be challenging to keep focused on the most important risks at any
risks of such attacks to address any criminal
provided meet their needs and given time. Cutting through multiple risks to focus on the most significant
activity it identified. For example, shortly
enables them to make effective ones requires a sound understanding of the extended risk environment
after lockdown in March 2020 the income
risk-based decisions. Using visuals and how risks interact, cascade, compound and amplify to create knock-on
tax self‑assessment repayment system was
such as flight paths, heat maps, effects and unintended consequences. If risks are not monitored effectively,
subject to a new type of attack, involving
assurance mapping along with reporting may be incomplete and inconsistent, and appropriate action may
fraudulent claims. The total value of
executive summaries can help drive not mitigate or manage the risk. A common failing is risks being reported
repayment claims rose by around £1.5 billion
the right conversations. To keep with little change in performance for long periods of time – with actions only
(19%) in 2020-21 compared with 2019‑20.
things dynamic, we also need to taking place when risks crystallise or become more challenging.
be discussing new areas of new Benefit: HMRC stopped around £1.1 billion
concern and emerging risks, and
What did leaders and practitioners say? of these payments before they were made,
asking questions such as: are we Leaders and practitioners emphasised the importance of monitoring but estimates that between £52 million and
taking sufficient mitigating action, risks along with the need for timely reporting. Good risk reporting can £219 million was extracted by fraudsters.
do we need to be doing something drive the right conversations, improve engagement with the Board, and HMRC strengthened systems and controls,
different or quicker?” reduce surprises. Notifying the Board of new threats and opportunities as and claims returned to expected levels by
they emerge, and informing them of material changes to the impact and July 2021.
Joanna Horrocks-Potts, Deputy
likelihood of existing risks – and the associated impact on the organisation’s
Director, Risk and Assurance, Source: Managing tax compliance following
or project’s risk profile – are ways risk leaders can enable appropriate action the pandemic54
HM Land Registry
to be taken through effective monitoring.53

53 Risk profiling involves a systematic and structured approach to risk management which provides an organisation with a detailed picture of all the risk elements of its operations,
the effectiveness of risk mitigation measures, and a framework for analysing and monitoring its higher risk priorities. Zurich Municipal, Understanding your risk profile, October 2023.
54 Comptroller and Auditor General, Managing tax compliance following the pandemic, Session 2022-23, HC 957, National Audit Office, December 2022.
Good practice guide: Overcoming challenges to managing risks in government 24

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Monitor and report on the risks that matter continued

What actions can Set meaningful performance Apply tools which enable real-time Promote timely and accurate Ensure that risk registers are robust
metrics and indicators to monitor and dynamic monitoring of risks reporting of significant risks to key and ‘living documents’ that reflect
organisations take? and report risks decision-makers significant risks

Leading performance and risk Risk leaders should design Risks can change suddenly and Risk registers are central to
indicators can provide early processes that enable increased organisations need to consider their reporting and communicating risks
warning signs of possible risk agility and responsiveness to risks. implications and act accordingly. in government – they need to be up
events or incidents, to trigger a Organisations should identify Timely and accurate reporting to date and reflect the risks of most
proactive response. Near miss cost‑effective opportunities to of risks – following appropriate importance to the organisation.
reporting should be encouraged deploy tools and techniques monitoring – increases the
so organisations anticipate future that make monitoring risks more chances of being able to plan,
risks more effectively. Indicators effective and efficient. treat and promptly respond to
help to understand changes in the risks. Risk registers and wider
likelihood or impact of risk and can risk information should be tailored
generate focused deliberations to the needs of different users,
to inform decision making, risk like Boards and Audit and Risk
treatment and response. Assurance Committees.

Where have we In Performance measurement by In Survival guide to challenging In Managing cross-border travel In Government shared services
regulators (2016) we highlighted costs in major projects (2018) we during the COVID-19 pandemic (2022) we recognised that the
seen this issue in that approaches to risks can observed that too often the need (2022) we noted that individual Cabinet Office introduced a central
our work? only be effective if they are for transparent reporting, good departments fed risks relating risk register as part of an operational
underpinned by high-quality data.55 cost forecasting and continuous to their border programmes end-to-end risk management
Lead indicators can be used to monitoring is only really recognised into departmental risk registers framework to allow for effective risk
provide ‘early warning’ signs of when a department faces a crisis and some border-specific risks mitigation.58 The central risk register
potential problems. in affordability, or when things featured in broader government is updated monthly following risk
have gone wrong.56 Performance assessments of the pandemic reviews with each workstream lead
updates should enable up‑to‑date response.57 However, for the overall where ongoing risks are discussed,
monitoring of critical risks. system, we found government had and risks which exceed tolerance
no assessment setting out all the levels are flagged for escalation
risks related to the management of with senior leaders.
cross-border travel in one place.

55 National Audit Office, Good practice guide, Performance measurement by regulators, November 2016, paragraph 2.24.
56 National Audit Office, Survival guide to challenging costs in major projects, June 2018, page 7.
57 Comptroller and Auditor General, Managing cross-border travel during the COVID-19 pandemic, Session 2021-22, HC 1148, National Audit Office, April 2022, paragraph 3.7.
58 Comptroller and Auditor General, Government shared services, Session 2022-23, HC 921, National Audit Office, November 2022, paragraph 2.13.
Good practice guide: Overcoming challenges to managing risks in government 25

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Drive continuous improvement


Case study
Learning lessons from others
and assessing risk maturity Why is this important?
Continuous learning and improvement
will enable the organisation Government organisations – in a time of scarce
Background: HMRC needed to update its risk maturity assessment to
to continually develop and resources – need to prioritise a culture of continuous
describe how well it was delivering each of the Orange Book principles.
improve its approach to learning and improvement so risk management is
The aim was to undertake a Department-wide risk maturity assessment
risk management. a primary focus for individuals. Central to this is a
to highlight and share areas of good practice and identify areas where
no‑blame culture that promotes open dialogue and
focus or improvement activity might be required.
knowledge sharing. This should include learning
Quote lessons from the past – including near-misses from Approach: Using a combination of interviews and questionnaires, HMRC
within the organisation – and relevant risk examples asked senior leaders, risk professionals and non-risk professionals a set
“Leaders need to be able to from other organisations. of questions against each of the Orange Book principles. Their responses
articulate what they want were collated and self-assessed. The central team then undertook a
risk management to achieve. Organisational leaders should emphasise the value of
consistency exercise and produced the overarching maturity assessment
This includes being clear feedback loops so learning can be taken from outcomes
for the Department, outlining a set of improvement activities it was
on what good looks like, and applied to make future improvements. Increasingly,
proposing to deliver. This was then ratified by the Executive Committee.
and setting expectations risk leaders can identify opportunities to make greater
that their teams will be use of data analytics and other advanced technology The immediate output from the exercise was an agreed improvement
following good practice. in risk management – to improve the quality and scope plan for risk managers to implement for the next 12–24 months.
Proper centrally managed of identification, assessment and monitoring, and make The improvement activities were incorporated into business plans to
validation arrangements, processes more efficient. support resource allocation and objective setting of the risk function.
and an assurance system The team monitored progress against the improvement activities and
What did leaders and practitioners say? regularly shared best practice across the Department on these
around them, which provide
Boards with confidence that Leaders and practitioners we talked to recognised the specific issues.
risks are genuinely being challenges in sharing information and good practice
Benefit: While it is important to undertake a consistent assessment, which
mitigated to an acceptable across government. Involving risk professionals in the
enables benchmarking to take place, HMRC gained greater insight from
level, are important in order learning process is a good way for learnings to be shared
having rich discussions with colleagues and in identifying the specific
to shift the dial on risk and implemented. The challenge extends beyond sharing
improvement activities themselves. It was also important to recognise that
management effectiveness.” of good practice to sharing information on shared risks
improvement plans had to be proportionate to activities and hence would
across government. Challenges to achieving net zero
Bruce Mann, Strategic vary across different business units. Understanding whether they were
were cited as an example where lots of departments are
Advisor on Resilience and at maturity level 2 or 3 felt less tangible, as there is always an element of
involved and there are opportunities to share approaches
Preparedness subjectivity associated with the assessment.
to improve risk action plans and strategies.
Source: Discussion with HMRC
Good practice guide: Overcoming challenges to managing risks in government 26

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Drive continuous improvement continued

What actions can Assess the current level of maturity Identify and share good practice Learn and share lessons from Validate, benchmark and seek
to identify gaps and areas for across the organisation beyond the organisation assurance over risk management
organisations take? development arrangements

Undertaking an honest assessment Organisations should invest time Learning lessons from others – like As part of a continual improvement
of the organisation’s current level in identifying examples of good other ALBs within a departmental mindset, risk leaders should look
of risk maturity enables risk leaders practice in risk management group or departments across for opportunities where their
to assess which areas should be that can be showcased to the government – helps inform processes can be independently
prioritised for future development. organisation to drive continuous risk‑based decision making assured. Benchmarking progress
improvement. across the organisation. against other organisations enables
leaders to find ways to improve
existing processes.

Where have we In Climate change risk: A good In The Transpennine Route In Managing risks in government In Supporting innovation – Managing
practice guide (2021) we Upgrade Programme (2022) (2011) we recognised the benefit risk in Government departments
seen this issue in recommended that organisations we noted that Network Rail put of the Risk Improvement Group, (2000) we recognised that
our work? should identify gaps in skills and in place a system to identify and which still operates today.61 assurance arrangements can help
knowledge, and plan for how incorporate relevant lessons This is a cross‑government group management to gain assurance
these can be addressed.59 This will learned into its management of coordinated by the Risk CoE in about the effectiveness or otherwise
increase their ability to respond the Programme.60 It identified 19 HM Treasury, which is a useful of the risk management system.62
effectively to climate change themes, drawing on lessons and forum for risk and assurance Internal Audit has an important role
risk and make the most of any good practice and experience on specialists to meet and discuss to play in reviewing the operation
opportunities. Organisations should the Programme to date and other risk management practices, of departments’ risk management
decide how regularly to review their major infrastructure projects. and provides the opportunity systems, and provides assurance
climate change risk identification These themes included behaviours to learn from others and share to senior management that the
and assessment, to make sure that and culture, risk management and good practice. department’s risk management
they are learning any lessons from collaborative planning. reflects good practice.
their experience and ensure that
the response to climate change risk
remains appropriate considering
their strategy to adapt to and
mitigate climate change risks.

59 See footnote 32, page 36.


60 Comptroller and Auditor General, The Transpennine Route Upgrade Programme, Session 2022-23, HC 572, National Audit Office, July 2022, paragraph 21b.
61 See footnote 23, paragraph 6.4.
62 Comptroller and Auditor General, Supporting innovation: Managing risk in government departments, Session 1999-2000, HC 864, August 2000, page 85.
Good practice guide: Overcoming challenges to managing risks in government 27

Leadership Capability Risk appetite Forward- Risk-informed Whole-system Assess Action to Monitor Continuous
and culture and expertise and tolerance looking view decisions approach risk impact address risks and report improvement

Methodology appendix
We have used the following methods to generate our insights:
a We conducted 18 semi-structured interviews and one b We held nine semi-structured interviews and one c We held a workshop discussion with officials from the
workshop with senior leaders and risk practitioners workshop with experts from the wider risk community Risk Centre of Excellence to discuss our emerging
from a range of our audited bodies. In some instances to discuss and gain their perspectives on the challenges findings and hear their views on the themes we
more than one interview was undertaken with different for government in managing risks and how to tackle had identified.
individuals from the same organisation. We met with these challenges. These included:
d We interviewed financial audit, value-for-money and
a Deputy Chief Executive, Group and Executive
Directors, Chief Risk Officers, Heads of Risk and • 2 institutions/professional bodies insights teams from the National Audit Office. We used
this information to gain insights into the variation in
Department Risk Leads from: • 1 regulator
risk management across different bodies, identify
• 9 ministerial departments • 3 academics good-practice examples and further our understanding
of what different government bodies require for robust
• 2 non-ministerial departments • 2 private sector companies
risk management. Our interviews were carried out
• 2 non-departmental public bodies • 2 industry experts between June and October 2023.

• 4 executive agencies The interviews and the workshop were carried out e We reviewed our back catalogue of value-for‑money
between July and October 2023. reports, investigations, and good practice guides.
We included organisations of different sizes and
We used this information to identify the main
complexity to capture a diversity of perspectives. For methods a and b we organised the notes from challenges for government in managing risks
The findings from the interviews were used to inform the interviews and workshops in an Excel matrix, and approaches to tackle these challenges.
our themes and identify examples of good practice. against the themes identified in our review of past
Our interviews and the workshop were carried out NAO reports. We used this analysis to refine, test and f We conducted external research on risk management.
between July and October 2023. supplement our findings and to identify and examine This constituted desktop research of risk management
case study examples to illustrate our findings. materials and documentation from central government
and the private sector, and discussions with
organisations from beyond central government to
deepen our understanding of the current challenges
for effective risk management.

You might also like