Risk Management Tool 1

Similar documents
Edwin Lindsay Principal Consultant. Compliance Solutions (Life Sciences) Ltd, Tel: + 44 (0) elindsay@blueyonder.co.

Waveney Lower Yare & Lothingland Internal Drainage Board Risk Management Strategy and Policy

Outsourcing and third party access

Reputation Impact of a Data Breach Executive Summary

TABLE OF CONTENTS Information Systems Security Handbook Information Systems Security program elements. 7

SPA PERFORMANCE MANAGEMENT PROGRAM GENERAL COMPARISON OF EXPECTATION LEVELS FOR ORGANIZATIONAL VALUES

Indiana University Internal Audit

Bedford Group of Drainage Boards

River Stour (Kent) Internal Drainage Board Risk Management Strategy and Policy

RISK MANAGEMENT MATRIX FOR ACADEMIES. Contents. Introduction. Mission/objectives. Law and regulation. Governance and management.

Assessment of natural hazards, man made hazards, technical and societal related risks and associated impact.

RESERVE BANK OF VANUATU OPERATIONAL RISK MANAGEMENT

Operational Risk Management Policy

Vendor Management Best Practices

The Cost of Insecure Mobile Devices in the Workplace Sponsored by AT&T

University of Sunderland Business Assurance Information Security Policy

Required Insurance Language for PRF Construction Contracts

Any business relationship between a bank and another entity, by contract or otherwise

Risk Assessment Tool and Guidance (Including guidance on application)

Risk Management Policy and Framework

TO GAS TRANSMISSION OPERATOR GAZ-SYSTEM S.A.

Performing Effective Risk Assessments Dos and Don ts

Nonprofit risk management

Continuity of Operations Planning. A step by step guide for business

What is required of a compliant Risk Assessment?

GUIDANCE FOR MANAGING THIRD-PARTY RISK

Supplier Code of Conduct Holcim (Switzerland) AG Procurement and Sustainable Development

SCDHSC0032 Promote health, safety and security in the work setting

RISK MANAGEMENT IN A FOR-

SECURITY RISK MANAGEMENT

RISK MANAGEMENT POLICY

GUYANA PROCUREMENT PLANNING MANUAL

Software Engineering Ethics and Professional Conduct SWENET OSE3 Module July 2003

OCC 98-3 OCC BULLETIN

Chapter 2: Quality Assurance and Legal Issues

Glossary of Insurance Terms

UF Risk IT Assessment Guidelines

SCOTTISH CHILDREN S REPORTER ADMINISTRATION

CRITICAL INFRASTRUCTURE PROTECTION BUILDING ORGANIZATIONAL RESILIENCE

Business Continuity and Capacity Building

REQUEST FOR QUALIFICATIONS PROFESSIONAL ARCHITECTURAL SERVICES

Service Children s Education

Departmental Solicitors Office

Fiscal Policies and Procedures Fraud, Waste & Abuse

Why Obtain Student Medical Malpractice Insurance?

Creating a Business Continuity Plan for your Health Center

AfDB New Procurement Policy: Training Program for the Bank s Procurement Staff. Risk Allocation in Construction Contracts

Use & Disclosure of Protected Health Information by Business Associates

How to conduct risk management & vulnerability assessments of medical devices using current ISO/IEC standards as a guidance

International Federation of. June Accountants. Ethics Committee. Code of Ethics for Professional. Accountants

MANAGEMENT LIABILITY BLIND SPOTS. Insurance coverage insights for Logistics, Transportation, Supply Chain, and Technology Companies

Risk assessment. made simple

MICHAEL D. WAKS LONG BEACH PERSONAL INJURY ATTORNEY

Audit, Risk and Compliance Committee Charter

Preparing for the HIPAA Security Rule

How To Manage Risk

Chapter 1: An Overview of Emergency Preparedness and Business Continuity

Information security risk management using ISO/IEC 27005:2008

Autoliv Business Conduct and Ethics for Suppliers

Ethical dilemma in professional practice. By Muhammad Iqbal

Information security incident reporting procedure

GUIDELINES FOR THE MANAGEMENT OF OPERATIONAL RISK FOR CREDIT UNIONS

Procedure for Managing a Privacy Breach

ACCIDENT / INCIDENT INVESTIGATION REPORT INSTRUCTIONS

Ethics Everywhere Jones Lang LaSalle Incorporated Annual Report for Calendar Year 2013 Program

ELEMENT FINANCIAL CORPORATION CODE OF BUSINESS CONDUCT AND ETHICS

Safety Management System (SMS) Guidelines

Business Continuity Planning Guide

Two dimensions of pure risk

Security Risk Assessment Tool

a. employees Company; or

Vendor Management. Outsourcing Technology Services

Risk Assessment / Risk Management Protocol

CALIFORNIA HOUSING FINANCE AGENCY INSURANCE REQUIREMENTS - CONSTRUCTION RISK

Legislative Language

Flood Insurance III. Common Violations and Consequences for Noncompliance

Code of Ethics and Corporate Compliance Program

Data Analysis: The Cornerstone of Effective Internal Auditing. A CaseWare Analytics Research Report

Internal Audit Standards

Study Report on Crane Incident Analysis. Prepared by: Mr Simon Lee Chairman of Crane Incident Analysis Workgroup

HORIZON OIL LIMITED (ABN: )

Builder's Risk and CGL Insurance for Construction Projects: Mitigating Developer and Contractor Risks

Risk & Innovation in Cybersecurity Investments. Sponsored by Lockheed Martin

Risk Management Guide

Managing EHS Incidents Using Integrated Managment Systems. By Matt Noth

JOB ANNOUNCEMENT. Chief Security Officer, Cheniere Energy, Inc.

Transcription:

Risk Management Tool 1

Risk Identification Categories of Risk Project, Contract or Other Event Financial Technology Governance Reputation 1A 1B 1C 1D 2A 2B 2C 2D 3A 3B 3C 3D 4A 4B 4C 4D Prioritize Risk 1E 1F 1G 1H 2E 2F 2G 2H 3E 3F 3G 3H 4E 4F 4G 4H Hazard Compliance Client Service for Child Service Providers please note slide 9 Human Capital 2

Financial Risks (examples) Loss of Income Rising Costs Liquidity Economy Federal/State budget Investment risks Borrowing rates Inadequate budgeting or planning Unreliable accounting records Fraud Examples from Wipfli, LLP presentation at 9 th Annual Grant Funded Programs Management Conference 3

Technology Risks Obsolete equipment (leading to inefficiency or incompatibility) Access to current technology Lack of understanding of technology Examples from Wipfli, LLP presentation at 9 th Annual Grant Funded Programs Management Conference 4

Governance Risks Improperly prepared or engaged board of directors Inefficient governance practices Straying from the mission Lack of innovation Poor strategy Examples from Wipfli, LLP presentation at 9 th Annual Grant Funded Programs Management Conference 5

Reputational Risks Damage to public image Can be of various types (e.g. image of poor quality service, slow delivery, unethical environment, etc.) Poor relationships with donors Unsatisfied clients/program participants Examples from Wipfli, LLP presentation at 9 th Annual Grant Funded Programs Management Conference 6

Hazard Risks Fire, flood and other losses or impairments of physical assets Insurable Examples from Wipfli, LLP presentation at 9 th Annual Grant Funded Programs Management Conference 7

Compliance Risks Noncompliance with laws and regulations Grant-related Non grant-related Violating terms of contracts Compliance with donor restrictions Civil wrongs (torts) Examples from Wipfli, LLP presentation at 9 th Annual Grant Funded Programs Management Conference 8

Client Service Risks part A Harm caused to clients in connection with services we provide Theft of client property Transportation accidents Overall satisfaction of clients, program participants Changing client needs, desires Quality of service Breaches of confidentiality Examples from Wipfli, LLP presentation at 9 th Annual Grant Funded Programs Management Conference 9

Client Service Risks part B Child Service Providers Risk assessment of new service providers is a standard and ongoing process for CBC of Brevard. Thus, the majority of the risk assessment process has previously been completed and the levels of risk factors assigned. The risk identification process for Child Service Providers is completed during the procurement process using: The Request for Administrative Qualifications of Service Providers, and The Service Provider Risk Assessment Form (part of CBC Procedure: CG-360) 10

Human Capital Risks Loss or lack of availability of personnel (employees, volunteers, contractors) Loss or lack of availability of specific expertise (e.g. technical skills) Leadership; succession Diminished morale Diminished skills of existing personnel Examples from Wipfli, LLP presentation at 9 th Annual Grant Funded Programs Management Conference 11

RISK ASSESSMENT & PRIORITIZATION How likely is it to happen? What if it did happen? 12

RISK ASSESSMENT CHART Risk Assessment - Project, Contract or Other Event: Date of Assessment: Assessment: Completed By: List all Participants: Risk Category Identified Risk Probability of Occurrence Impact of Occurrence Consequence of Occurrence Response to Risk (List How) 13

Risk Prioritization Probability Chart Probability How likely is this risk to occur? H M L NA NI High Medium Low Not Applicable Need Information Exhibits high risk cue(s): Has happened frequently; Has a very significant chance of happening in the future; and/or, For a single event has already happened. Has happened occasionally or has a reasonable but not completely expected chance of happening in the future. Has happened very infrequently or is expected not to happen except infrequently. This risk is irrelevant to this project or operation. Impossible to determine probability with the current available information. Information must come from an outside source. Consider High Probability until otherwise identified. 14

Risk Prioritization Impact Chart Impact What will happen if the risk becomes an issue? H M L NA NI High Medium Low Not Applicable Need Information The issue will have a major impact on the system and is likely to cause significant disruption in service or a very visible event. The issue will have some impact on systems and be visible to a number of users. A possible disruption in service for some non-critical users is expected. No service disruption or negative effects are expected. Any negative impact can be corrected without significant effort or visibility. This risk is irrelevant to this project or operation. Impossible to determine probability with the current available information. Information must come from an outside source. Consider High Impact until otherwise identified. 15

RISK ASSESSMENT GRID Project, Contract or Other Event Probability Section 1: High Probability/ Low Impact Medium Probability/ Low Impact Medium Probability/ High Impact Section 2: High Probability/ High Impact High Probability/ Medium Impact Impact Low Probability/ Medium Impact Medium Probability/ Medium Impact Section 3: Low Probability/ Low Impact Section 4: Low Probability/ High Impact 16

RISK RESPONSE What do we want to do about it? 17

Risk Response Chart Response Decide how to respond to each risk? A E R ST AC Avoidance Elimination Reduction Sharing or Transferring Risk Acceptance List How (Involves changing the project plan to remove the treat. This can be done by changing or reducing the scope of the project.) List How (Could involve adopting a less complicated process, conducting additional tests on the product, building redundancy into a system, and/or designing a quality control or reconciliation process.) List How (Insurance, etc.) List How (Partnership, Use of Outside Contractor, etc.) No action to be taken. 18