RISK MANAGEMENT AND BUSINESS CONTINUITY ANNUAL REPORT



Similar documents
COUNCIL TAX There is a statutory requirement for the Council Tax for 2015/16 to be set before 11th March 2015.

Equality Impact Assessment Form

EQUALITY IMPACT ASSESSMENT TEMPLATE - TRAFFORD COUNCIL

CARDIFF COUNCIL. Equality Impact Assessment Corporate Assessment Template

LONDON BOROUGH OF WALTHAM FOREST

Solihull Clinical Commissioning Group

BUSINESS CONTINUITY MANAGEMENT POLICY

Essex Clinical Commissioning Groups. Business Continuity Management System. Scope and Policy

39 GB Guidance for the Development of Business Continuity Plans

Business Continuity Policy

Business Continuity Policy

NHS Hardwick Clinical Commissioning Group. Business Continuity Policy

EQUALITY AND DIVERSITY POLICY AND PROCEDURE

INFORMATION GOVERNANCE OPERATING POLICY & FRAMEWORK

There are several tangible benefits in conducting equality analysis prior to making policy decisions, including:

South Downs National Park Authority

Council meeting, 31 March Equality Act Executive summary and recommendations

CARDIFF COUNCIL. Initial Equality Impact Assessment Corporate Assessment Template. Job Title: Service Area:

Business Continuity Policy

Accounts Receivable - Guidance to staff responsible for the collection of income following the supply of goods or services V4.0

Business Continuity Management (BCM) Policy

Colchester Borough Council. Equality Impact Assessment Form - An Analysis of the Effects on Equality. Section 1: Initial Equality Impact Assessment

Business Continuity Management

The Newcastle upon Tyne Hospitals NHS Foundation Trust. Employment Policies and Procedures

The Newcastle upon Tyne Hospitals NHS Foundation Trust. IT Change Management Policy and Process

Community Safety Overview and Scrutiny Committee 3 September Report of the Director of Communities and Neighbourhoods

STEP1 Equality Impact Assessment Team

Equality Impact Assessment

BUSINESS CONTINUITY MANAGEMENT POLICY

Job Application form

2016/17 Budget proposal Integrated Impact Assessment (IIA)

Time limiting contributory Employment and Support Allowance to one year for those in the work-related activity group

Business Continuity Policy and Business Continuity Management System

Summary of the Equality Act 2010

Initial Equality Impact Assessment

BUSINESS CONTINUITY POLICY RM03

Equality with Human Rights Analysis Toolkit

The Newcastle upon Tyne Hospitals NHS Foundation Trust

PROTOCOL FOR DUAL DIAGNOSIS WORKING

Risk Management & Business Continuity Manual

BUSINESS CONTINUITY MANAGEMENT FRAMEWORK

All CCG staff. This policy is due for review on the latest date shown above. After this date, policy and process documents may become invalid.

HRODE Alyson Sargeant ext Name of service/policy/strategy/guidance/project proposal

17 SEPTEMBER 2015 NOT EXEMPT FACTORING CHARGES ON ACQUISITIONS

Equality Analysis. Page 307. Wheelie bin collection service (PILOT) Stage 1: Overview

Appendix 1 EQUALITY IMPACT: SCREENING AND ASSESSMENT FORM

BRISTOL CITY COUNCIL HUMAN RESOURCES COMMITTEE. Richard Billingham (Service Director: Human Resources)

LIST OF BACKGROUND PAPERS AS REQUIRED BY LAW (papers relied on to write the report but which are not published and do not contain exempt information)

How Wakefield Council is working to make sure everyone is treated fairly

Cambridge Judge Business School Further particulars

3 Aims. 4 Duties (Roles and responsibilities)

Collecting data on equality and diversity: examples of diversity monitoring questions

Full Equality Impact Assessment Pro- forma (Stage 2)

As part of our VC2020 Lectureship programme, we are looking for an outstanding new Lecturer in Information Systems.

Employee Monitoring Report

Version Number Date Issued Review Date V1 25/01/ /01/ /01/2014. NHS North of Tyne Information Governance Manager Consultation

1.0 Policy Statement / Intentions (FOIA - Open)

Information Governance Policy

INCOME COLLECTION AND DEBT MANAGEMENT POLICY

Huntingdonshire District Council Equality Impact Assessment

Equality Impact Assessment Report

Policy for the Management of People with Dual Diagnosis. Document Title NTW(C)44. Reference Number. Executive Director of Nursing and Operations

Liverpool Hope University. Equality and Diversity Policy. Date approved: Revised (statutory changes)

South West Lincolnshire NHS Clinical Commissioning Group Business Continuity Policy

Information Governance Policy

Information & ICT Security Policy Framework

DORSET & WILTSHIRE FIRE AND RESCUE AUTHORITY Performance, Risk and Business Continuity Management Policy

School Disaster Recovery Policy

Policy Title: Information and Communication Technologies (ICT) Service Management Policy. Policy Number: P60122

FACULTY OF BUSINESS AND LAW

The Newcastle upon Tyne Hospitals NHS Foundation Trust. Medical Equipment Library Access to Service Procedure

FINANCIAL POLICY PAYMENT FOR SUPPLIER INVOICES

The Newcastle upon Tyne Hospitals NHS Foundation Trust. Claims Management Policy

Teaching and Learning Together. Equal Opportunities Policy (see also Disability Non-Discrimination; EAL; Gifted and Talented; Racial Equality; SEN)

Transcription:

Agenda Item No. 7 EECUTIVE - 25 JUNE 2015 RISK MANAGEMENT AND BUSINESS CONTINUITY ANNUAL REPORT Executive Summary Risk Management and Business Continuity Management are the two main disciplines through which the Council identifies, manages and mitigates its business and operational risks. Risk Management is the process whereby the organisation methodically identifies and manages the threats and opportunities that might exist within a Council activity. Business Continuity sets out to enhance the strategic and tactical capability of the organisation to plan for and respond to incidents and business disruptions in order to continue business operations at an acceptable pre-defined level. Since the last annual report all business area risk registers have been reviewed and updated in conjunction with Corporate Strategy and each Business Manager. Corporate strategic risks have also been reviewed and updated by CMG. The risks that have been identified have been logged, owners have been allocated and progress to mitigate each risk has been recorded. The Council adopted a Business Continuity Management Strategy and Policy in 2006 and it has been in place ever since. Despite having been reviewed in the past, it is clear that it is now time to undertake a full review of the strategy and associated plans to ensure that it remains as fit for purpose as possible. The review of Business Continuity will take several months to complete. Once done, the revised approach will be presented to a future meeting of the Executive for review and formal adoption. Reasons for Decision The continuous development of the Council s Risk Management Strategy and Business Continuity Management Plan is essential to ensure the security of services to citizens. Recommendations The Executive is requested to: RESOLVE That the report be noted and there are no issues of concern. The Executive has authority to determine the above recommendations. Background Papers: None. Sustainability Impact Assessment Equalities Impact Assessment 1 EE15-010

Reporting Person: Mark Rolt, Strategic Director Ext. 3002, E Mail: Mark.Rolt@woking.gov.uk Contact Persons: Lara Beattie, Senior Policy Officer Ext. 3013, E Mail: Lara.Beattie@woking.gov.uk Pino Mastromarco, Senior Policy Officer Ext. 3464, E Mail: Pino.Mastromarco@woking.gov.uk Portfolio Holder: Cllr John Kingsbury E Mail: cllrjohn.kingsbury@woking.gov.uk Shadow Portfolio Holder: Cllr Will Forster E Mail:cllrwill.forster@woking.gov.uk Date Published: 17 June 2015 2

1.0 Introduction 1.1 The purpose of this report is to provide Members with an update on Risk Management and Business Continuity Management arrangements that are in place within the Council. The status of both of these functions are reported on an annual basis. 1.2 The Risk Management and Business Continuity Strategies provide the framework through which the Council identifies, manages and mitigates its business and operational risks. The key elements of this framework are designed to: ensure that Risk Management and the adoption of Business Continuity becomes part of the culture of the whole organisation; manage risk in accordance with best practice; prevent injury and damage and reduce the cost of risk; consider legal compliance as a minimum standard; and anticipate and respond to changing social, economic, environmental and legislative requirements. 1.3 Risk Management is the process whereby the organisation methodically identifies and manages the threats and opportunities that might exist within a Council activity. Business Continuity sets out to enhance the strategic and tactical capability of the organisation to plan for and respond to incidents and business disruptions in order to continue business operations at an acceptable pre-defined level. 1.4 Risk Management and Business Continuity Planning are not one off activities. They are part of a continuous process that runs throughout the Council s activities, taking into account all aspects such as projects as well as day to day work that is undertaken. It must be integrated into the culture of the Council with an effective strategy and led from the top. 1.5 The functional responsibility for corporate Risk Management and Business Continuity planning rests with the Corporate Management Group (CMG) and Corporate Strategy is the Business Area accountable for overall delivery and review. All Business Area Managers are responsible, with guidance and support from Corporate Strategy, for ensuring appropriate risk management and business continuity arrangements are deployed in their functions, services and areas of responsibility. 2.0 Risk Management 2.1 Risk can be defined as the combination of the probability of an event and its consequences. In any organisation there is the potential for events and consequences that either provides opportunities for benefits or threats to success. Risk Management is more than just Health and Safety or insurable risks it includes, amongst other things, political and management risk, financial exposure and reputation. 2.2 Over the past year all business area risk registers have been reviewed and updated in conjunction with Corporate Strategy and each Business Manager. Corporate Strategic Risks have also been reviewed and updated by CMG. 2.3 Both Business Area and Corporate Strategic Risks are reviewed and updated on a 6 monthly basis by Business Managers and CMG respectively. 3

3.0 Business Continuity 3.1 The Council adopted a Business Continuity Management Strategy and Policy in 2006 and it has been in place ever since. Despite having been reviewed in the past, it is clear that it is now time to undertake a full review of the strategy and associated plans to ensure that it remains as fit for purpose as possible. 3.2 Recent events, such as the burning down of South Oxfordshire District Council Civic Offices, along with significant changes to other internal and external factors, have highlighted the need to refresh the plans that the Council currently has in place. 3.3 Business Continuity Management (BCM) is about identifying those parts of our organisation that we cannot afford to lose such as information, premises, staff, services to the community and planning how to maintain these, if an incident occurs. 3.4 The review of BCM will focus on the following three key steps: 1. Reviewing and re-writing the Council s Business Continuity Plan: The purpose of this document is to set the scene for Business Continuity and to provide the overall framework for its application. The Business Continuity Plan will assist the organisation to be able to define an incident response structure that will enable an effective response and recovery from disruptions. 2. Reviewing and re-writing the Council s Business Impact Analysis: The purpose of this document is to make informed decisions around which of the Council s critical activities need to be recovered first and in what order. The Impact Analysis will also define the resources required and support arrangements for each critical activity. Typical critical activities will be priority key services such as Benefits, Contact Centre, Careline, Meals Service etc. as well as core functions such as ICT and access to suitable premises. 3. Development of the Critical Activity Action Cards: Once the Critical Activities have been identified through the Business Impact Analysis, we then need to plan in more detail how each scenario could be managed. Every Critical Activity will have an associated Action Card that will list what steps need to be taken to get a service up and running again and who should be involved in tackling the issue. 3.5 Any incident, large or small, whether it is natural, accidental or deliberate, can cause major disruption to our organisation. But if we plan now, rather than waiting for it to happen, we will be able to get back to business in the quickest possible time. 3.6 The review of Business Continuity and the completion of steps 1 to 3 listed above will take several months to complete. Once done, the revised approach will be presented to a future meeting of the Executive for review and formal adoption. 4.0 Conclusions 4.1 The application of risk management and business continuity management remains a priority for the Council. Risk management, having been reviewed and updated recently is considered to be sound and will continue to be implemented as per the Risk Management Strategy throughout the coming year. Business continuity management is in need of an update and work on this will begin imminently. This phase of review will also provide the opportunity to further align risk and business continuity principles with emergency planning, to ensure that the Council can achieve a robust and joined up approach in all of these areas for the future. 4

5.0 Implications Financial 5.1 None arising specifically from the report but any proposals to further improve or enhance resilience is likely to have cost implications and these would be identified in any such proposal. Human Resource/Training and Development 5.2 Work continues to make staff aware of the arrangements and train those with specific responsibilities. This will be an on-going requirement to reflect staff turnover and changes. Community Safety 5.3 There are no specific environmental or sustainability issues arising as a consequence of this report. Business continuity is a key contributor to community safety in ensuring critical services are maintained but there are no issues arising specifically from this report. Risk Management 5.4 As outlined in the report. Sustainability 5.5 None arising from the report. Equalities 5.6 None arising from the report. 6.0 Consultations 6.1 None. REPORT ENDS EE15-010 5

APPENDICES 6

Eliminate discriminatio n Advance equality Good relations Equality Impact Assessment The purpose of this assessment is to improve the work of the Council by making sure that it does not discriminate against any individual or group and that, where possible, it promotes equality. The Council has a legal duty to comply with equalities legislation and this template enables you to consider the impact (positive or negative) a strategy, policy, project or service may have upon the protected groups. Positive impact? Negative impact? No specific impact What will the impact be? If the impact is negative how can it be mitigated? (action) THIS SECTION NEEDS TO BE COMPLETED AS EVIDENCE OF WHAT THE POSITIVE IMPACT IS OR WHAT ACTIONS ARE BEING TAKEN TO MITIGATE ANY NEGATIVE IMPACTS Gender Men This report relates to a review of the last year and covers generic activities of the Council, therefore there are no specific Women impacts. Gender Reassignment Race White Mixed/Multiple ethnic groups Asian/Asian British Black/African/Caribbean/ Black British Gypsies / travellers Other ethnic group This report relates to a review of the last year and covers generic activities of the Council, therefore there are no specific impacts. 7

Eliminate discriminatio n Advance equality Good relations Positive impact? Negative impact? No specific impact What will the impact be? If the impact is negative how can it be mitigated? (action) THIS SECTION NEEDS TO BE COMPLETED AS EVIDENCE OF WHAT THE POSITIVE IMPACT IS OR WHAT ACTIONS ARE BEING TAKEN TO MITIGATE ANY NEGATIVE IMPACTS Disability Physical This report relates to a review of the last year and covers generic activities of the Council, therefore there are no specific Sensory impacts. Learning Difficulties Sexual Orientation Age Religion or Belief Mental Health Lesbian, gay men, bisexual Older people (50+) Younger people (16-25) Faith Groups Pregnancy & maternity This report relates to a review of the last year and covers Marriage & Civil Partnership generic activities of the Council, therefore there are no specific impacts. Socio-economic Background The purpose of the Equality Impact Assessment is to improve the work of the Council by making sure it does not discriminate against any individual or group and that, where possible, it promotes equality. The assessment is quick and straightforward to undertake but it is an important step to make sure that individuals and teams think carefully about the likely impact of their work on people in Woking and take action to improve strategies, policies, services and projects, where appropriate. Further details and guidance on completing the form are available. 8

Sustainability Impact Assessment Officers preparing a committee report are required to complete a Sustainability Impact Assessment. Sustainability is one of the Council s cross-cutting themes and the Council has made a corporate commitment to address the social, economic and environmental effects of activities across Business Units. The purpose of this Impact Assessment is to record any positive or negative impacts this decision, project or programme is likely to have on each of the Council s Sustainability Themes. For assistance with completing the Impact Assessment, please refer to the instructions below. Further details and guidance on completing the form are available. Theme (Potential impacts of the project) Use of energy, water, minerals and materials Waste generation / sustainable waste management Pollution to air, land and water Factors that contribute to Climate Change Protection of and access to the natural environment Travel choices that do not rely on the car A strong, diverse and sustainable local economy Meet local needs locally Opportunities for education and information Provision of appropriate and sustainable housing Personal safety and reduced fear of crime Equality in health and good health Access to cultural and leisure facilities Social inclusion / engage and consult communities Equal opportunities for the whole community Contribute to Woking s pride of place Positive Impact Negative Impact No specific impact What will the impact be? If the impact is negative, how can it be mitigated? (action) This report relates to a review of the last year and covers generic activities of the Council, therefore there are no specific impacts. 9