Risk Management Framework
A Risk Management Framework is the overarching protocol or structure within
which an organization oversees and manages risk to help ensure the fulfillment
of its strategic objectives. It is a proactive approach to identification,
assessment, mitigation and reporting.
There are 4 components to the University of Victoria’s Risk
Management Framework. They are culture/philosophy, structure, strategies/tools
and monitoring and reporting.
In order for risk management to be successful, there must be knowledge
and support of the program at the executive level and organizational
awareness. As well, the organization must have policies that are
aligned with its strategic objectives to help guide the institution
in defining its risk appetite.
The University has strong executive support for the program however
organization awareness needs to be enhanced. The awareness level
on campus has been raised through the Risk
Management Steering Committee and will be further enhanced through campus consultation
in the development and updating of a University Risk Register.
The structure is the process to be used to identify, assess and
report on University risks. At the University of Victoria, the
Risk Management Steering Committee is the appropriate conduit for
development of a risk register for executive approval and
reporting to the Board.
There are 4 approaches to take when dealing with risk: avoid,
transfer, mitigate or accept.
The University of Victoria has developed a comprehensive risk
management programs that either transfer or mitigate risk when
the risk is accepted or can not be avoided. These include:
- Internal control systems;
- Emergency planning;
- Occupational Health and Safety Programs; and
- Business continuity planning.
4) Monitoring & Reporting
The University already has a comprehensive reporting program,
and therefore accountability, in place that includes:
- Strategic (A Vision to the Future, Research Plan, Service Plan)
- Academic Program and Support (multi year enrolment, access
and affordability, Information Technology)
- Performance (Academic Program Reviews, research reports, teaching
assessment, performance assessment)
- Financial Planning & Reporting (Student Financial Assistance,
Budget, Financial Statements, 5 year Capital Plan) ; and
- Governance (Board, Senate).
This program will be further enhanced with regular reporting of
top University risks.
See appendix I attached which diagrams the above UVic Risk Management
Framework. Click APPENDIX
I to view.