Document Comments

Bulletin Board - Review and Comment

Step 1 of 4: Comment on Document

How to make a comment?

1. Use this Comment Icon to open a comment box for your chosen Section, Part, Heading or clause.

2. Type your feedback into the comments box and then click "save comment" button located in the lower-right of the comment box.

3. Do not open more than one comment box at the same time.

4. When you have finished making comments proceed to the next stage by clicking on the "Continue to Step 2" button at the very bottom of this page.

 

Important Information

During the comment process you are connected to a database. Like internet banking, the session that connects you to the database may time-out due to inactivity. If you do not have JavaScript running you will recieve a message to advise you of the length of time before the time-out. If you have JavaScript enabled, the time-out is lengthy and should not cause difficulty, however you should note the following tips to avoid losing your comments or corrupting your entries:

  1. DO NOT jump between web pages/applications while logging comments.

  2. DO NOT log comments for more than one document at a time. Complete and submit all comments for one document before commenting on another.

  3. DO NOT leave your submission half way through. If you need to take a break, submit your current set of comments. The system will email you a copy of your comments so you can identify where you were up to and add to them later.

  4. DO NOT exit from the interface until you have completed all three stages of the submission process.

 

Risk Management Framework

Section 1 - Introduction

(1) This Framework has been developed to support the Risk Management Policy. It outlines how risk management is embedded into day-to-day activities, providing tools and guidance for stakeholders to manage risk in a manner that is:

  1. Consistent – applying the Council's risk appetite uniformly across diverse University activities.
  2. Proportionate – focusing on risks that are material to achieving strategic objectives.
  3. Prioritised – enabling clear identification and prioritisation of activities that significantly impact the University of Newcastle (the University) objectives.
Top of Page

Section 2 - Scope

(2) The Framework applies to all staff of the University and its controlled entities

Top of Page

Section 3 - Background

(3) The University's Risk Management Policy and Framework is aligned with the international standard for risk management – ‘ISO 31000:2018 Risk Management – Guidelines’. The Framework outlines how those principles of effective risk management are applied at the University

Top of Page

Section 4 - Risk Management at The University of Newcastle 

Risk Assessment and Management Process

(4) The risk management process should form part of decision-making across the University and be integrated into structures and processes (See Risk Management Process - Visual). This means adopting a process that incorporates the following attributes: 

  1. establishing the risk context by defining the environment in which the risks will be managed;
  2. assessing and analysing risks based on their consequence and likelihood to determine the risk rating and risk level (risk analysis);
  3. evaluating the risks in comparison with the risk appetite, risk threshold and risk tolerance
  4. determining and implementing appropriate treatment of risks (risk treatment); 
  5. monitoring and review to respond to indicators including changes in controls or emerging risks; and
  6. continuously being informed by appropriate consultation, communication, and reporting throughout the process. 

Risk Identification

(5) This is the process of capturing risks that may help (opportunity) or prevent (threaten) the achievement of the University's objectives or the objectives of a particular project, research activity or event. The identified risks and opportunities should be documented in risk profiles or in detailed risk assessments.

(6) The source of risk, the event that could trigger the risk (cause) and the impact on the University's objectives (effect) must be considered. 

(7) Common risk identification techniques include workshops, process reviews, incident analysis, scenario planning, SWOT analysis, and consultation with subject matter experts. 

Risk Analysis

(8) The risk analysis process informs whether risks need to be treated (managed) and if so, how. It supports the prioritisation of risks which may have the most significant impact on achieving objectives.  

(9) Risks should be measured by considering the likelihood (frequency or probability of occurrence) and the consequence (impact or magnitude of effect) if the risk occurs. 

(10) The assessment of each risk is determined at both the inherent risk (i.e. if there were no controls in place to reduce the risk) and residual risk (the remaining risk with effective controls in place). Understanding the inherent position helps to determine the importance and prioritisation of controls. 

(11) Internal controls which are in place to prevent the risk will affect the likelihood of occurrence (preventative controls). Detective internal controls support early identification of issues. Internal controls which support the rectification or lower the impact will affect the consequence (corrective controls). In considering the adequacy of internal controls, effectiveness needs to be considered.

Table 1 - Control effectiveness criteria

Control Effectiveness
Effective Partially Effective Not Effective
Controls are designed correctly, are in place and are effective. Controls are operating 90-99% of the time.

Controls are subject to regular monitoring and review. The existing controls are well designed and addresses the risk. Controls are effective and reliable at all times. 
The existing controls have some impact on mitigating the risk. Controls are inconsistent in their application, monitoring and effectiveness. Controls are operating 50-89% of the time. Scope for improved effectiveness. Some additional work is required to ensure operational effectiveness and reliability. The existing controls are missing or ineffective and do not support the risk mitigation. Controls are poorly communicated and are not subject to monitoring. Controls are operating at <50% of the time. Enhancement required.

Risk Evaluation

(12) Risk evaluation determines whether a risk is acceptable within the University's risk appetite statement or whether further treatment or escalation is required. Evaluation considers the residual risk rating, the effectiveness of existing controls, and the University's risk appetite, tolerance, and thresholds.

(13) Risks outside the approved appetite must be escalated in accordance with the Risk Management Policy

Risk Treatment

(14) Residual risk ratings guide appropriate prioritisation and allocation of resources for the management of identified risks.

(15) Subject to the University risk appetite, risks may be accepted or treated to reduce likelihood or impact. 

Risk Acceptance

(16) The University acknowledges that accepting some level of risk is necessary to enable innovation and pursue opportunities aligned to the University's strategy. However, risk acceptance must always be based on a clear understanding of potential benefits and consequences, supported by proportionate mitigation measures.

Risk Monitoring and Review

(17) Risks do not remain static, and risk monitoring should be ongoing as well as event driven. This ensures risk information and assumptions remain relevant; controls remain effective, and that changing environmental conditions are considered in risk assessments

Top of Page

Section 5 - Assessing risk via the Risk Matrix

(18) The risk matrix (See: Risk Matrix) provides a consistent way for staff to assess and rate risks in their day-to-day work. It should be applied to strategic, operational, and project risks. It translates the Council approved risk appetite into defined, quantifiable, and measurable risk thresholds. These thresholds are embedded within consequence definitions, likelihood assessments, risk ratings, and escalation requirements. Residual risk ratings guide appropriate prioritisation and allocation of resources for the management of identified risks.

(19) During the risk analysis process, the likelihood table within the Risk Matrix must be used to assess the probability of occurrence. The consequence table must be used to assess all potential impacts to the University, with the highest impact rating applied to determine the risk rating.

(20) Risks should be assessed based on the greatest consequence to the University rather than the impact on an individual business unit or project. For example, a serious matter of integrity may cause limited operational disruption, but the reputational impact can be major, leading to erosion of public trust. 

(21) Once the likelihood and consequence have been assessed, use the risk map (within the Risk Matrix) to determine the risk rating (for example, likelihood of ‘Possible’ and consequence of ‘Major’, provides a risk rating of ‘Medium’). 

(22) Table 2 details the protocols for escalating risks, findings, and issues, along with timeframes for addressing these matters based on their residual risk rating.

Table 2 - Residual Risk Rating and Management Requirements:

(23) Where a risk is rated as outside the Council's risk appetite, Council consideration is required.

Residual Risk Rating Management Requirements
Extreme - Council oversight, escalation and consideration is required.
- Active risk treatment required with immediate action; cease, redesign, or significantly mitigate activity. – A detailed treatment plan should be developed.
- Continuous monitoring of the risk, controls and treatment strategies is required.
- Reporting to the Risk Committee is required.
- Target remediation should be within 6 months.
High - Council / Vice-Chancellor oversight, escalation and consideration is required.
- Active risk treatment required to reduce risk. A detailed treatment plan should be developed.
- Ongoing monitoring of the risk, controls and treatment strategies is required.
- Reporting to relevant management and Risk Committee is required.
- Target remediation should be within 6 to 12 months.
Medium - Executive Leader oversight, escalation, and consideration required.
- Strengthen controls or reduce exposure and implement targeted treatment plan where feasible based on cost/benefit.
- Regular monitoring is required of changes to the nature of risks, controls and treatments.
- Target remediation should be within 12 to 18 months.
Low - Head of Unit or School oversight, escalation, and consideration is required.
- Monitor and improve controls where feasible based on cost / benefit.
- Managed by established, routine processes / procedures. There is a need to be mindful of changes to nature of risks and controls.
Very Low - Department Leader oversight, escalation, and consideration is required.
- Accept or manage through BAU controls, routine processes / procedures and be mindful of change to nature of risks.
Top of Page

Section 6 - Material Risk Categories

(24) Risk management covers all types of risks across the University's activities, including risks relating to core teaching, learning and research functions, and material operational risks which impact everyone such as people and capability, health and safety, and information, technology and cyber. 

(25) The University's Enterprise Risk Profile identifies the most material risks facing the University that could affect strategic, operational, and financial outcomes. These risks fall into three main categories:

  1. Strategic risksRisks that could affect the University's long-term direction, priorities, or goals. This includes risks from poor decisions, weak implementation, or external changes that impact the strategy.
  2. Operational risksRisks arising from failures in processes, systems, people, or external events that disrupt operations. These risks often have direct financial impacts.
  3. Financial risksRisks related to the University's financial position, including its ability to meet short- and long-term financial and capital objectives.

(26) Each of these categories includes more detailed risk areas under the full risk taxonomy. Categories are not fixed and will change over time as new risks emerge, and circumstances evolve.

(27) Risk management should occur at all levels of the University as part of normal planning and operations (see Section 7). Strategic planning, business planning, and risk management operate as a continuous cycle: 

  1. Strategy sets the direction. 
  2. Business plans put it into action. 
  3. Risk assessments test whether plans are achievable within the University's risk appetite
  4. Risk insights are then used to refine and improve both strategy and planning.
Top of Page

Section 7 - Risk Governance 

(28) The University's risk governance structure is a multi-faceted, depicted by the ‘Enterprise Risk Management Ecosystem’ which includes the Policy and this Framework, the Risk Matrix, and the Risk Appetite Statement and strategy detailed above. Additionally, the University's approach to risk governance includes the following Risk Profiles:

  1. Enterprise Risk Profile – identifies and reports major strategic and operational risks. These are reviewed by the Executive and approved by the Risk Committee and Council.
  2. Operational Risk Profiles – used by Colleges, Schools, Divisions, and Units to identify and manage their risks, with support from Risk Services.
  3. Specialised Risk Profiles – relate to specific projects or technical areas (e.g. health and safety, construction, regulatory change). These are managed by the relevant business area and aligned to the overall Risk Framework.
  4. Controlled Entity Risk Profiles – maintained by controlled entities and approved by their Boards. These are considered as part of the University's overall risk exposure.

(29) Managing risk is a shared responsibility. All staff are responsible for identifying and managing risks, with specific roles outlined in the Risk Management Policy.

Top of Page

Section 8 - Review

(30) This Framework will be reviewed every three years.

Top of Page

Section 9 - Appendices

(31) Enterprise Risk Management Ecosystem - Depiction

(32) Risk Management Process - Visual 

(33) Risk Matrix (Consequence & Likelihood Tables)