-
- Provide oversight to ensure that management has implemented an effective system to identify, assess, manage, respond to, and monitor risks to the institution and its strategic objectives.
- Understand and assess the risks inherent in the University’s strategy, and encourage management to pursue prudent risk to generate sustainable performance and value.
- Understand the key drivers of success for the institution, and be knowledgeable about business management, governance, and emerging risks that may affect the institution.
- Work with management to establish and routinely and regularly (at least annually) review the institution’s risk philosophy.
- Review risk information provided by management and the Audit Committee, including ERM annual assessment reports and interim status reports, institutional risk portfolio, and reports on the status of risk response.
- Collaborate and actively engage with management in discussions of risk, especially regarding philosophy, interaction and aggregation of risks, and underlying assumptions.
- Define the role of the full Board vs. its standing or other committees about risk oversight.
- Understand and assess risks associated with Board decisions and key strategies identified by the Board.
- Provide for an appropriate culture of risk awareness across the University; monitor critical alignments of people, strategy, risk, controls, compliance, and incentives.
-
- Prepare an annual Strategic Risk Profile of risks and opportunities having the greatest potential impact on the University’s objectives for review by the Office of Strategic Planning and Implementation (OSPI).
- Assess and develop recommendations for newly identified risks, opportunities, or initiatives as requested by the ULC.
-
- Identify and prioritize business risks. Understand the University’s current risk environment, including a review of emerging risks, the interrelationships between risks, and in the context of the University’s risk appetite and tolerance.
- Evaluate the effectiveness of risk mitigation activities. Review risk mitigating strategies for effectiveness and consistency with the University’s risk tolerance.
- Ensure that gaps in effectiveness are addressed for high-priority risks. Provide recommendations for the allocation of resources and assignment of responsibilities for activities addressing business risks.
- Improve enterprise risk management infrastructure. Guide the ERM infrastructure, including systems, processes and organizational structure.
-
- Ensure that all risks in their areas of operations are identified and managed appropriately.
- Conduct local-level assessment of risks or opportunities at least annually (ideally concurrent with the annual strategic risk assessment) and ad hoc as issues arise.
- Develop and implement risk response plans.
-
Each UM employee should understand:
- The risks that relate to their roles and their activities.
- How the management of risk relates to the success of the institution.
- How the management of risk helps them to achieve their own goals and objectives.
- Their accountability for particular risks and how they can manage them.
- How they can contribute to continuous improvement of risk management.
- That risk management is a key part of the organization’s culture.
- The need to report in a systematic and timely way to senior management any perceived new or emerging risks and any near misses/good catches or failures of existing internal control measures within the parameters agreed.
Internal Audit
- UM
- Internal Audit
- Roles & Responsibilities