Document Comments

Bulletin Board - Review and Comment

Step 1 of 4: Comment on Document

How to make a comment?

1. Use this Comment Icon to open a comment box for your chosen Section, Part, Heading or clause.

2. Type your feedback into the comments box and then click "save comment" button located in the lower-right of the comment box.

3. Do not open more than one comment box at the same time.

4. When you have finished making comments proceed to the next stage by clicking on the "Continue to Step 2" button at the very bottom of this page.

 

Important Information

During the comment process you are connected to a database. Like internet banking, the session that connects you to the database may time-out due to inactivity. If you do not have JavaScript running you will recieve a message to advise you of the length of time before the time-out. If you have JavaScript enabled, the time-out is lengthy and should not cause difficulty, however you should note the following tips to avoid losing your comments or corrupting your entries:

  1. DO NOT jump between web pages/applications while logging comments.

  2. DO NOT log comments for more than one document at a time. Complete and submit all comments for one document before commenting on another.

  3. DO NOT leave your submission half way through. If you need to take a break, submit your current set of comments. The system will email you a copy of your comments so you can identify where you were up to and add to them later.

  4. DO NOT exit from the interface until you have completed all three stages of the submission process.

 

Risk Management Policy

Section 1 - Introduction

(1) Risk management creates and protects value by minimising the effects of negative risks or threats and enhances the effects of positive risks or opportunities. Risks (both positive and negative) influence the strategic and operational decisions of the University of Newcastle (University). 

(2) Risk management is an essential component of good governance that supports the University to achieve its strategic and operational objectives. Good risk management

  1. drives a risk aware culture where everyone takes responsibility for risk;
  2. empowers people to make informed decisions (freedom within boundaries); 
  3. supports informed risk taking to enhance growth, transformation and innovation; and
  4. enhances outcomes and resilience.

(3) Effective risk management provides assurance to the University Council, Risk Committee and Vice-Chancellor that risks are being identified and managed appropriately, in line with Council's risk appetite and objectives.

Top of Page

Section 2 - Purpose

(4) This policy sets out the University's commitment to risk management; the core principles supporting its operation and outlines key roles and responsibilities. 

Top of Page

Section 3 - Scope

(5) This Policy applies to all staff of the University and its controlled entities.

Top of Page

Section 4 - Principles

(6) The University's Risk Management Policy and Risk Management Framework align with the internationally recognised principles of risk management (ISO 31000) and the University's values.  

(7) The following overarching principles define how risk management should be applied at the University:

Table 1 – Overarching Risk Management Principles

Principles Illustrated by
Positive risk culture Driving a culture where risk management is seen as a business enabler. Identifying and managing risk is accepted as everyone’s responsibility, driven by the tone at the top.
Risk-based decision making Decision making, resource allocation, and investment are informed by risk analysis.
Sound corporate governance Risk management is integrated into strategy, systems, and processes, to enable timely response and escalation of risk exposures.
Iterative and adaptive Risk management anticipates, detects and responds to changes in the University's internal and external environment in a timely manner.
Proportionate and customised Risk treatment is informed by a proportionate assessment of risk and rewards and be appropriate for the University's operations and objectives.
Transparent and inclusive The risk management process includes the timely involvement of stakeholders and decision makers.
End to end risk identification A comprehensive approach to risk identification should be adopted which includes strategic, operational, and financial risks to enable a holistic enterprise view of the University.
Continuous improvement Risk management continues to improve with risk maturity, learning and experience.
Top of Page

Section 5 - Roles and Responsibilities

Three Lines of Assurance

(8) The University uses a tailored Three Lines of Assurance (3LoA) approach to define accountability for managing risk in a university context. This model ensures all staff and management remain accountable for risk identification and mitigation, supported by expert advice and constructive challenge to support assurance. By establishing three distinct layers of assurance, risks are identified, managed, and monitored effectively, ultimately protecting and enhancing the value for the University and providing confidence to stakeholders.

(9) The following table outlines the three lines of assurance, responsible areas and key responsibilities.

Table 2 – Risk Management Assurance Responsibilities

Line Responsible Areas Key Responsibilities
First Line – implements risk management as part of normal business operations. Executive management and all staff. Own and manage risk within their business area.

Implement controls and processes.

Identify and mitigate risks as part of daily operations.
Second Line – Independently provide oversight, strategic advice, check and challenge. Central Risk and Compliance teams Provide strategic advice, oversight and guidance on risks and opportunities.

Support executives in managing the risks they are accountable for.

Provide review and challenge.

Develop, implement and monitor risk management policies, frameworks, tools and resources.

Monitor and report on risk exposures.

Undertake in-house assurance activities including thematic reviews and controls testing (where required).
Third Line – Independent assurance Internal Audit Provide independent assurance and report findings to the Vice-Chancellor, Executive Leadership Team, and the Risk Committee.

Evaluate the effectiveness of controls and risk management.

 Governance and accountability

(10) The University Council is ultimately responsible for determining the University's risk appetite, including acceptance of risk outside of appetite or return to appetite plans. 

(11) The Council's responsibilities for risk are set out in the University of Newcastle Act (1989) and in the Matters Reserved for Council. These responsibilities include approving policies on risk oversight and risk management and being satisfied that management has developed, appropriately resourced and implemented a sound system of risk management and internal control.

(12) To assist the Council in discharging its responsibilities in relation to risk management, the Council has delegated certain risk activities to the Risk Committee and other standing Committees of Council. The responsibilities of the Committees are contained in the respective Committee Charters.

(13) The management of risk, in accordance with this Policy and its associated Risk Management Framework, is the responsibility of all staff, and will be incorporated into academic, strategic and operational planning and review processes at all levels across the University

Top of Page

Section 6 - Risk Management Strategy

Commitment

(14) The University is committed to maintaining an effective enterprise risk management capability that supports informed decision-making, continuous improvement, and achievement of strategic objectives. 

Philosophy and approach

(15) Risk embracing: The University recognises that taking risks is necessary to achieve its goals. Risk management focuses both on reducing harm and on identifying opportunities to create value. It aims to use limited resources as effectively and efficiently as possible.

(16) Iterative: Risk management is ongoing, not just reactive. Risks change over time, so they must be regularly monitored and reviewed to support good decision-making and to identify trends, issues, and improvements early.

(17) Integrated and inclusive: Risk management is most effective when it is part of everyday culture and behaviour, not just compliance. It should involve relevant stakeholders, encourage staff to speak up, and promote shared responsibility for outcomes.

(18) Aligned with strategy and planning: The Strategic Plan, and supporting Education, Research and Engagement sub-plans, along with College, School, Divisional and Unit plans and specific project plans set the strategic and operational objectives. This planning cycle supports the assessment of emerging or known risks that may impact objectives. 

Risk Appetite 

(19) The Council, in consultation with the Executive Leadership Team, determines the University's risk appetite, risk tolerance, and risk thresholds. In establishing these parameters, Council recognises that the elimination of all risk is neither feasible nor desirable in achieving the University's objectives.

(20) The University's risk appetite establishes the level and types of risks the University is willing to accept in pursuit of its vision, values and goals. It provides clear boundaries to guide decision-making while enabling appropriate flexibility within those boundaries. The University recognises that some risk is necessary to support innovation and seize opportunities, provided risks are well managed. 

(21) Risks that exceed the risk appetite must be escalated to Council for review and approval.

(22) The University's risk appetite must be applied to all decisions - strategic, operational, and project-related. Risks should be considered broadly, not just in financial terms. It also clarifies which risks can be managed locally and which must be escalated.

(23) Risk appetite varies across different activities. Decisions to accept risk must be based on a clear understanding of benefits and impacts, supported by appropriate controls.

Top of Page

Section 7 - Risk Management Framework

(24) The Policy is supported by the Risk Management Framework, which documents how this Policy is executed in practice.

Top of Page

Section 8 - Review Process

(25) This Policy will be reviewed every three years.

Top of Page

Section 9 - Appendices

(26) Risk Appetite Statement

(27) Risk Appetite Statement - Defined

(28) Risk Appetite Statement - Depiction