This manual outlines the policies that form the basis of the College’s Risk Management Plan and covers all activities within the College and its operations and entities, as well as defining the College’s risk management objectives, framework, roles, responsibilities, communication, and process.
| Accept | Informed decision to take a particular risk. |
| Actions | The measures put into place to reduce and/or control the risk. |
| Avoid | Not to proceed with the activity or choosing an alternative approach to achieve the same outcome. |
| Control | Measure that is modifying the risk. |
| Establishing the context | Defining the external and internal parameters to be taken into account when managing risk and setting the scope and risk criteria for the risk management policy. |
| Event | Occurrence or change of a particular set of circumstances. |
| Hazard | Source of potential harm. |
| Impact | The consequences of an event affecting objectives using a scale of 1 (insignificant) to 5 (catastrophic) – Appendix 5. |
| Inherent Risk | The initial risk, before risk treatment. |
| Level of risk | Magnitude of a risk or combination of risks expressed in terms of their consequences and their likelihood. Also known as the risk rating. |
| Mitigate | Use controls to reduce the probability or impact. |
| Monitor | Continual checking, supervising, critically observing or determining the status in order to identify change from the performance level required or expected. |
| Probability | The likelihood of a risk occurring using a scale of 1 (remote) to 5 (almost certain) – Appendix 5. |
| Residual risk | Remaining risk after risk treatment. |
| Responsibility | A person or entity with the accountability and authority to manage a particular risk. |
| Review | Activity undertaken to determine the suitability, adequacy and effectiveness of the subject matter to achieve established objectives. |
| Risk | Effect of uncertainty on objectives. |
| Risk analysis | Process to comprehend the nature of risk and to determine the level of risk. |
| Risk appetite | Amount and type of risk that an organisation is willing to pursue or retain. |
| Risk assessment | Overall process of risk identification, risk analysis and risk evaluation. |
| Risk attitude | Organisation’s approach to assess and eventually pursue, retain, take or turn away from risk. |
| Risk category | Risks are complex and diverse, necessitating groupings so that risks can be properly classified, evaluated and managed. |
| Risk decision | How to immediately deal with the risk – either accept, mitigate, transfer or avoid. |
| Risk description | Structured statements of risk usually contain four elements: sources, events, causes and consequences. |
| Risk evaluation | The process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its magnitude is acceptable or tolerable. |
| Risk identification | Process of finding, recognising and describing risks. |
| Risk management | Coordinated activities to direct and control an organisation with regard to risk. |
| Risk management framework | Set of components that provide the foundations and organisational arrangements for designing, implementing, monitoring, reviewing and continually improving risk management throughout the organization. |
| Risk management policy | Statement of the overall intentions and direction of an organisation related to risk management. |
| Risk management process | Systematic application of management policies, procedures and practices to the activities of communicating, consulting, establishing the context and identifying, analysing, evaluating, treating, monitoring and reviewing risks – Appendix 4. |
| Risk matrix | Tool for ranking and displaying risks by defining ranges for impact and probability – Appendix 1. |
| Risk owner | A person or entity with the accountability and authority to manage a risk. |
| Risk profile | Description of any set of risks – Appendix 2. |
| Risk rating | Defining the risk using the College Threat and Opportunity Matrix (Appendix 1) so that risks can be prioritised |
| Risk register | Record of information about identified risks. |
| Risk reporting | Form of communication intended to inform particular internal or external stakeholders by providing information regarding the current state of risk and its management. |
| Risk source | Element, which alone or in combination has the intrinsic potential to give rise to risk. |
| Risk tolerance | Organisations or stakeholders’ readiness to bear the risk after risk treatment in order to achieve its objectives. |
| Risk treatment | Process to modify risk. |
| Transfer | Shifting responsibility of the risk, either as a whole or shared. |
| The College | Melbourne School of Theology |
This manual outlines the policies that form the basis of the College’s Risk Management Plan and covers all activities within the College and its operations and entities, as well as defining the College’s risk management objectives, framework, roles, responsibilities, communication, and process.
The College undertakes teaching, research and community activities across a wide range of departments, disciplines and environments. This diversity of activities creates an equally diverse and complex range of risks and opportunities for the College. The overall aim of risk management is to understand and manage these risks whilst at the same time making the most of new opportunities to preserve and protect the College’s values, reputation, resources, and standing in the local, national and international context.
The College utilises risk management both within its day-to-day operations as well as more broadly at a Higher Education Provider’s facility level, which means that risk management is an integral component to running all aspects of the College in the most efficient and effective manner.
The, COO, Audit Risk Committee (“ARC”), and the College Board are ultimately responsible for risk management within the College.
The overall objectives of this policy are to provide a formal process to assist The College:
The College has adopted the principles of risk management as set out in the International Risk Management Standard (AS/NZS ISO 31000:2009 Risk Management – Principles and guidelines) and continuously works towards applying these principles to ensure that risk management is effective.
All organisations face various challenging influences that make their operating environment uncertain. Risk is simply the impact this uncertainty has on the achievement of the College’s objectives.
It is important to note that risks are numerous and can arise from both external sources (for example political, natural and economic influences) and internal sources (for example new projects, new staff/faculty, infrastructure and capacity challenges).
Risk management refers to the coordinated activities that an organisation takes to direct and control risk. It is usually either value enhancing or value protecting, however sometimes it can be both.
Value enhancing risk management occurs when the actions, processes and controls set in place to manage the College’s risks increase the potential for achieving strategic outcomes that add value to the College.
Value protecting risk management occurs when the actions, processes and controls set in place manage risks that have a negative consequence. This means that they protect the value of the College by preventing or minimising the impact of negative events.
Overall, risk management helps organisations become more efficient and effective by improving forward planning and critical thinking and enabling better-informed decision making.
Effective risk management generally goes unnoticed, however when risk management is absent or fails the consequences can be highly visible, far-reaching, publically embarrassing, and can compromise the College’s brand and reputation. The College is committed to incorporating and sustaining a risk management culture using the Standard so that risks are dealt with both efficiently and effectively.
In general, Risk Management:
| Enhances: | Reduces: |
| Good governance | Inconsistency |
| Brand and Reputation | Embarrassment or Discredit |
| Communication | Adverse events/ Negative consequences |
| Reliability | Procrastination |
| Decision making | Hasty, rash or poor decisions |
| Ability and Confidence | Uncertainty |
The eleven principles of risk management as outlined in the Standard must be implemented at all levels within the College in order to be effective.
Specifically, Risk Management:
The College’s risk management framework integrates the process for managing risks into the College’s overall governance, strategy and planning, management, reporting processes, policies, values and culture.
The success of risk management depends on this framework to provide the foundations and arrangements that will embed it throughout the College at all levels. The framework assists in managing risks effectively through the application of the risk management process at varying levels and within specific contexts. The framework also ensures that information about risk derived from the risk management process is adequately reported and used as a basis for decision making and accountability.
Risks are an intrinsic aspect of everyday life, originating from both internal and external sources. This means that everyone who engages at the College – including but not limited to visitors, volunteers, students, employees, and lease holders – are impacted in some way by risk and therefore need to take an active role in being ‘risk aware’.
Being ‘risk aware’ means:
The College has certain people who will be more active in risk management than others, such as the Audit and Risk Committee (”ARC”) and the COO (“COO”). However, all people who engage or work for the College are encouraged to both identify and report risks.
The ARC and the COO, will help staff and students to understand and adhere to any and all controls put into place by the College to mitigate certain risks. Additionally, it is not the role of the ARC or COO to manage risks on behalf of other parties. It is the responsibility of management and staff to manage risks and controls for which they are accountable, and everyone is expected to work individually and collectively towards actively promoting a positive risk management culture within and across the College and all its holdings.
| Visitors, volunteers, students: |
|
| Academic & professional staff: |
|
| Senior academic & professional staff (inc. deans, managers and heads of department) |
|
| Executive team: |
|
(including but not limited to their employees, volunteers and visitors).
| Visitors, volunteers, staff & employees of Lessees. |
|
| Chief executives and/ or managers of Lessees |
|
The College’s Risk Management Specialists are responsible for the College’s risk management culture, processes, reporting and framework. This specialist team is composed of the General Manager, OH&S Chair, ARC members, and the COO, and is overseen by the College Board.
The principal has delegated to the COO responsibility for the establishment of an effective risk management framework throughout the College. Each of these bodies are active in risk management and therefore have certain roles and responsibilities that are integral to both safe business practice and the sustainability of the College. The table below highlights their main purposes.
| Risk Management Specialist (e.g., General Manager and OH&S Chair): |
|
| COO: |
|
| The College Board and ARC: |
|
The ARC, General Manager and COO are responsible for reviewing the effectiveness of the College’s processes for managing particular areas of risk. This is to ensure that the College’s risk management program is being run at its most optimum level, and that all processes are effective, efficient, understood and implemented across the entire college.
This internal audit is to be completed annually, with the initial review to be completed by the General Manager and the COO, the subsequent review completed by the ARC, and the College board undertaking the final review.
Risk Management is a necessary aspect of decision making within the College. It is not optional or an afterthought, but a vital consideration each time a decision is made so that positive outcomes are maximized whilst negative outcomes are minimised. This is risk management. In order to manage risk, we apply the steps outlined in the Standard, which are discussed in this section and highlighted in the Risk Management Flowchart (Appendix 4).
Establishing the context sets the framework within which the risk assessment should be undertaken, ensures the reasons for carrying out the risk assessment are clearly known, and provides the backdrop of circumstances against which risks can be identified and assessed.
Risk management takes place within the goals and objectives of the College and must consider both internal and external contexts. Internal risk identification involves analysing and investigating the College’s various capabilities, goals, objectives, strengths and weaknesses. This is also called the operational context and is different from the external, strategic context which involves the relationship between the College and the broad external community/environment.
When establishing the context of a risk it is important to consider both the strategic and operational contexts where possible, so that a complete picture can be obtained.
Internal context can include:
External context can include:
The Risk Assessment phase of the risk management process has three parts: (1. Identifying the risk, 2. Analysing the risk, 3. Evaluating the risk, 4. Prioritising the risk, 5. Treating the risk.
Risk identification is a critical activity at both strategic and operational levels. This process identifies the risks that might have an impact on the objectives of the College or relevant faculty, department, area or entity.
This part aims to identify sources of the risk, areas of impact, events (including changes in circumstances) and their causes and potential consequences. It needs to include all significant sources of risk, including those beyond the College’s control. If a risk/threat is not identified, there can be no strategy to defend against it.
Describe those factors that might create, enhance, prevent, degrade, accelerate or delay the achievement of objectives. It is also important to identify the issues associated with not pursuing an opportunity; that is, the risk of doing nothing and missing an opportunity. The objective of this step is not to create an onerous and lengthy list of all possible risks, but to identify all significant risks that could impact the College.
Enterprise wide risks to the College are identified and reviewed annually by the ARC, General Manager, and COO for final review by the College Board. These risks form the basis of the overall risk profile for the organisation. The risk profile format is included in Appendix 3.
When identifying the risk, consideration should be given to these questions:
Categories of Risk:
The following broad categories of risk are used to enable appropriate aggregation and to assist with the identification of systemic issues and trends across the College.
Risk analysis can be undertaken with varying degrees of detail, depending on the risk, the purpose of the analysis, and the information, data and resources available. Analysis can be qualitative, semi-quantitative or quantitative, or a combination of these, depending on the circumstances.
Once the risk has been identified and the context, causes, contributing factors and consequences have been described, look at the strengths and weaknesses of existing systems and processes designed to help control the risk. Knowing what controls are already in place, and whether they are effective, helps to identify what – if any – further action is needed.
The objectives at this step are to separate the minor risks from major ones. The level of risk is determined by measuring the probability of each event arising and the associated consequences (impact).
Risk Analysis Criteria
Once the controls have been identified, and their effectiveness analysed, an assessment is made of the probability of the risk occurring and the impact if the risk were to occur. This produces an accurate, albeit subjective, assessment of the level of risk – or risk rating – and helps in the next step to determine whether risks are acceptable or need further treatment.
Impact is generally found using the consequence criteria of the College – potential financial loss, reputation impact, legal and regulatory compliance and management time and effort. Whilst most significant risks will relate to the direct financial and operational impact to the College, for some risks the most significant consequence is the impact on the College’s reputation. For such risks, the direct financial consequence of a risk may be negligible, but continuing reoccurrences may result in significant damage to the College’s reputation and standing.
The purpose of risk evaluation is to assist in making decisions, based on the outcomes of risk analysis. This tells us which risks need treatment and the priority for treatment implementation.
Risk evaluation involves comparing the level of risk found during the analysis process with risk criteria established when the context was considered. Based on this comparison, the need for treatment can be considered.
Decide whether the risk is acceptable or unacceptable by using the information gathered during the Risk Assessment phase to make decisions about future actions. Decisions about future actions may include:
Whether a risk is acceptable or unacceptable relates to a willingness to tolerate
the risk. The attitude, appetite and tolerance for risk is likely to vary over time, across the College as a whole and for individual faculties, departments, divisions, areas and controlled entities.
Decision Options:
Risk is acceptable – A risk is regarded as acceptable or tolerable if the decision has been made not to treat it. It is important to remember that designating a risk as acceptable does not imply that the risk is insignificant. In fact, these risks may still need to be monitored.
Risk is unacceptable – Risks in this category progress to the next step, Treating the Risk, where solutions are decided upon.
A risk may be acceptable or tolerable in the following circumstances:
The purpose of prioritising is to determine the level of action needed for the identified and analysed risks.
| Risk Rating: | Management Action: | |
| Extreme Risk | Immediate action required. | |
| High Risk | Action plan required, senior management attention needed. | |
| Moderate Risk | Specific monitoring or procedures required, management responsibility must be specified. | |
| Low Risk | Manage through routine procedures. Unlikely to need specific application of resources. | |
| Minimum Risk | Manage through routine procedures. Unlikely to need specific application of resources. | |
The objective of this step is to identify how the identified risks will be treated. Risk treatment involves identifying the options for treating each risk, evaluating those options, assigning accountability (for Extreme, High and Moderate residual risks) and taking relevant action. The following options are available for treating risks and may be applied individually or in combination, with due consideration of risk appetite:
| Risk Decision | |
| Mitigate the risk | Reduce the likelihood – Improving management controls and procedures. Reduce the consequence – Putting in place strategies to minimise adverse consequences, e.g. contingency planning, Business Continuity Plan, liability cover in contracts. |
| Transfer the risk | Shifting responsibility for a risk to another party by contract or insurance. Can be transferred as a whole or shared. |
| Accept the risk | Controls are deemed appropriate. These must be monitored and contingency plans developed where appropriate. |
| Avoid the risk | Not to proceed with the activity or choosing an alternative approach to achieve the same outcome. Aim is risk management, not aversion. |
Work out what kind of treatment is desirable – mitigate, transfer, accept or avoid.
Identify and design a preferred treatment option.
Evaluate treatment options and assess their feasibility. Do the controls appear to have the desired treatment effect? Will the controls trigger any other risks? Are the controls beneficial or cost efficient? Is the cost of implementing the control reasonable for this risk?
The cyclical process of treating a risk, deciding whether residual risk levels are tolerable and assessing the effectiveness of that treatment are all case-by-case assessments that depend on a good understanding of the risk and a focus on the end objective of the activity being assessed.
Document the risk treatment – using the Risk Management Profile (Appendix 2). Treatment plans should identify responsibilities for action, time frames for implementation, budget requirements or resource implications, performance measures and review process where appropriate.
Implement agreed treatments – once any options requiring authorisation for resourcing, funding or other actions have been approved. The person assigned with the primary responsibility for the risk is accountable for the treatment of the risk.
Once the risk has been treated, assess the level of residual risk. Even when a risk has been treated, and the controls are in place the risk may not be completely eliminated. The level of residual risk refers to the likelihood and consequence of the risk occurring after the risk has been treated. Once implemented, treatments provide or modify the controls. The residual risk rating is generally lower than the original risk rating otherwise the controls were not effective. The residual risk should be documented and monitored and reviewed. Where appropriate, further treatment might be prudent. Having a good awareness of residual risk is important in monitoring and reviewing risk on an ongoing basis.

Use this table to determine how likely it is that the College will be exposed to each specific risk after taking into account internal controls and considering factors such as:
| Likelihood | Level | Description | Probability |
| Remote | 1 | May only occur in exceptional circumstances | <20% |
| Unlikely | 2 | Could occur during a specified period | 21-40% |
| Possible | 3 | Might occur in 1–2-year period | 41-60% |
| Likely | 4 | Will probably occur in most circumstances | 61-80% |
| Almost Certain | 5 | Expected to occur in most circumstances | >80% |
Use this table to guide the assessment of impact of each identified risk.
| Impact | Level | Financial | Reputation | Legal | Management Time |
| Insignificant | 1 | <$5000 | Isolated adverse Media reference Public complaint |
Minor breach Informal complaint | Requires minimal time and effort to resolve |
| Minor | 2 | $5000-$50,000 | Repeated adverse coverage | Formal complaint | Causes some business disruption |
| Moderate | 3 | $50,000-$250,000 | Sustained adverse coverage | Regulatory investigation | Causes business disruption |
| Major | 4 | $250,000 – $1m | Extended adverse coverage | Penalties for breach of code Temporary closure | Requires concerted management effort for couple of months |
| Catastrophic | 5 | > $1m | Permanent closure | Fines, prison sentence | Requires management for multiple months |
AS/NZS ISO 31000:2018 Risk Management – Principles and Guidelines – International Risk Management Standard

| Accept | Informed decision to take a particular risk. |
| Actions | The measures put into place to reduce and/or control the risk. |
| Avoid | Not to proceed with the activity or choosing an alternative approach to achieve the same outcome. |
| Control | Measure that is modifying the risk. |
| Establishing the context | Defining the external and internal parameters to be taken into account when managing risk and setting the scope and risk criteria for the risk management policy. |
| Event | Occurrence or change of a particular set of circumstances. |
| Hazard | Source of potential harm. |
| Impact | The consequences of an event affecting objectives using a scale of 1 (insignificant) to 5 (catastrophic) – Appendix 5. |
| Inherent Risk | The initial risk, before risk treatment. |
| Level of risk | Magnitude of a risk or combination of risks expressed in terms of their consequences and their likelihood. Also known as the risk rating. |
| Mitigate | Use controls to reduce the probability or impact. |
| Monitor | Continual checking, supervising, critically observing or determining the status in order to identify change from the performance level required or expected. |
| Probability | The likelihood of a risk occurring using a scale of 1 (remote) to 5 (almost certain) – Appendix 5. |
| Residual risk | Remaining risk after risk treatment. |
| Responsibility | A person or entity with the accountability and authority to manage a particular risk. |
| Review | Activity undertaken to determine the suitability, adequacy and effectiveness of the subject matter to achieve established objectives. |
| Risk | Effect of uncertainty on objectives. |
| Risk analysis | Process to comprehend the nature of risk and to determine the level of risk. |
| Risk appetite | Amount and type of risk that an organisation is willing to pursue or retain. |
| Risk assessment | Overall process of risk identification, risk analysis and risk evaluation. |
| Risk attitude | Organisation’s approach to assess and eventually pursue, retain, take or turn away from risk. |
| Risk category | Risks are complex and diverse, necessitating groupings so that risks can be properly classified, evaluated and managed. |
| Risk decision | How to immediately deal with the risk – either accept, mitigate, transfer or avoid. |
| Risk description | Structured statements of risk usually contain four elements: sources, events, causes and consequences. |
| Risk evaluation | The process of comparing the results of risk analysis with risk criteria to determine whether the risk and/or its magnitude is acceptable or tolerable. |
| Risk identification | Process of finding, recognising and describing risks. |
| Risk management | Coordinated activities to direct and control an organisation with regard to risk. |
| Risk management framework | Set of components that provide the foundations and organisational arrangements for designing, implementing, monitoring, reviewing and continually improving risk management throughout the organization. |
| Risk management policy | Statement of the overall intentions and direction of an organisation related to risk management. |
| Risk management process | Systematic application of management policies, procedures and practices to the activities of communicating, consulting, establishing the context and identifying, analysing, evaluating, treating, monitoring and reviewing risks – Appendix 4. |
| Risk matrix | Tool for ranking and displaying risks by defining ranges for impact and probability – Appendix 1. |
| Risk owner | A person or entity with the accountability and authority to manage a risk. |
| Risk profile | Description of any set of risks – Appendix 2. |
| Risk rating | Defining the risk using the College Threat and Opportunity Matrix (Appendix 1) so that risks can be prioritised |
| Risk register | Record of information about identified risks. |
| Risk reporting | Form of communication intended to inform particular internal or external stakeholders by providing information regarding the current state of risk and its management. |
| Risk source | Element, which alone or in combination has the intrinsic potential to give rise to risk. |
| Risk tolerance | Organisations or stakeholders’ readiness to bear the risk after risk treatment in order to achieve its objectives. |
| Risk treatment | Process to modify risk. |
| Transfer | Shifting responsibility of the risk, either as a whole or shared. |
| The College | Melbourne School of Theology |
This manual outlines the policies that form the basis of the College’s Risk Management Plan and covers all activities within the College and its operations and entities, as well as defining the College’s risk management objectives, framework, roles, responsibilities, communication, and process.
The College undertakes teaching, research and community activities across a wide range of departments, disciplines and environments. This diversity of activities creates an equally diverse and complex range of risks and opportunities for the College. The overall aim of risk management is to understand and manage these risks whilst at the same time making the most of new opportunities to preserve and protect the College’s values, reputation, resources, and standing in the local, national and international context.
The College utilises risk management both within its day-to-day operations as well as more broadly at a Higher Education Provider’s facility level, which means that risk management is an integral component to running all aspects of the College in the most efficient and effective manner.
The, COO, Audit Risk Committee (“ARC”), and the College Board are ultimately responsible for risk management within the College.
The overall objectives of this policy are to provide a formal process to assist The College:
The College has adopted the principles of risk management as set out in the International Risk Management Standard (AS/NZS ISO 31000:2009 Risk Management – Principles and guidelines) and continuously works towards applying these principles to ensure that risk management is effective.
All organisations face various challenging influences that make their operating environment uncertain. Risk is simply the impact this uncertainty has on the achievement of the College’s objectives.
It is important to note that risks are numerous and can arise from both external sources (for example political, natural and economic influences) and internal sources (for example new projects, new staff/faculty, infrastructure and capacity challenges).
Risk management refers to the coordinated activities that an organisation takes to direct and control risk. It is usually either value enhancing or value protecting, however sometimes it can be both.
Value enhancing risk management occurs when the actions, processes and controls set in place to manage the College’s risks increase the potential for achieving strategic outcomes that add value to the College.
Value protecting risk management occurs when the actions, processes and controls set in place manage risks that have a negative consequence. This means that they protect the value of the College by preventing or minimising the impact of negative events.
Overall, risk management helps organisations become more efficient and effective by improving forward planning and critical thinking and enabling better-informed decision making.
Effective risk management generally goes unnoticed, however when risk management is absent or fails the consequences can be highly visible, far-reaching, publically embarrassing, and can compromise the College’s brand and reputation. The College is committed to incorporating and sustaining a risk management culture using the Standard so that risks are dealt with both efficiently and effectively.
In general, Risk Management:
| Enhances: | Reduces: |
| Good governance | Inconsistency |
| Brand and Reputation | Embarrassment or Discredit |
| Communication | Adverse events/ Negative consequences |
| Reliability | Procrastination |
| Decision making | Hasty, rash or poor decisions |
| Ability and Confidence | Uncertainty |
The eleven principles of risk management as outlined in the Standard must be implemented at all levels within the College in order to be effective.
Specifically, Risk Management:
The College’s risk management framework integrates the process for managing risks into the College’s overall governance, strategy and planning, management, reporting processes, policies, values and culture.
The success of risk management depends on this framework to provide the foundations and arrangements that will embed it throughout the College at all levels. The framework assists in managing risks effectively through the application of the risk management process at varying levels and within specific contexts. The framework also ensures that information about risk derived from the risk management process is adequately reported and used as a basis for decision making and accountability.
Risks are an intrinsic aspect of everyday life, originating from both internal and external sources. This means that everyone who engages at the College – including but not limited to visitors, volunteers, students, employees, and lease holders – are impacted in some way by risk and therefore need to take an active role in being ‘risk aware’.
Being ‘risk aware’ means:
The College has certain people who will be more active in risk management than others, such as the Audit and Risk Committee (”ARC”) and the COO (“COO”). However, all people who engage or work for the College are encouraged to both identify and report risks.
The ARC and the COO, will help staff and students to understand and adhere to any and all controls put into place by the College to mitigate certain risks. Additionally, it is not the role of the ARC or COO to manage risks on behalf of other parties. It is the responsibility of management and staff to manage risks and controls for which they are accountable, and everyone is expected to work individually and collectively towards actively promoting a positive risk management culture within and across the College and all its holdings.
| Visitors, volunteers, students: |
|
| Academic & professional staff: |
|
| Senior academic & professional staff (inc. deans, managers and heads of department) |
|
| Executive team: |
|
(including but not limited to their employees, volunteers and visitors).
| Visitors, volunteers, staff & employees of Lessees. |
|
| Chief executives and/ or managers of Lessees |
|
The College’s Risk Management Specialists are responsible for the College’s risk management culture, processes, reporting and framework. This specialist team is composed of the General Manager, OH&S Chair, ARC members, and the COO, and is overseen by the College Board.
The principal has delegated to the COO responsibility for the establishment of an effective risk management framework throughout the College. Each of these bodies are active in risk management and therefore have certain roles and responsibilities that are integral to both safe business practice and the sustainability of the College. The table below highlights their main purposes.
| Risk Management Specialist (e.g., General Manager and OH&S Chair): |
|
| COO: |
|
| The College Board and ARC: |
|
The ARC, General Manager and COO are responsible for reviewing the effectiveness of the College’s processes for managing particular areas of risk. This is to ensure that the College’s risk management program is being run at its most optimum level, and that all processes are effective, efficient, understood and implemented across the entire college.
This internal audit is to be completed annually, with the initial review to be completed by the General Manager and the COO, the subsequent review completed by the ARC, and the College board undertaking the final review.
Risk Management is a necessary aspect of decision making within the College. It is not optional or an afterthought, but a vital consideration each time a decision is made so that positive outcomes are maximized whilst negative outcomes are minimised. This is risk management. In order to manage risk, we apply the steps outlined in the Standard, which are discussed in this section and highlighted in the Risk Management Flowchart (Appendix 4).
Establishing the context sets the framework within which the risk assessment should be undertaken, ensures the reasons for carrying out the risk assessment are clearly known, and provides the backdrop of circumstances against which risks can be identified and assessed.
Risk management takes place within the goals and objectives of the College and must consider both internal and external contexts. Internal risk identification involves analysing and investigating the College’s various capabilities, goals, objectives, strengths and weaknesses. This is also called the operational context and is different from the external, strategic context which involves the relationship between the College and the broad external community/environment.
When establishing the context of a risk it is important to consider both the strategic and operational contexts where possible, so that a complete picture can be obtained.
Internal context can include:
External context can include:
The Risk Assessment phase of the risk management process has three parts: (1. Identifying the risk, 2. Analysing the risk, 3. Evaluating the risk, 4. Prioritising the risk, 5. Treating the risk.
Risk identification is a critical activity at both strategic and operational levels. This process identifies the risks that might have an impact on the objectives of the College or relevant faculty, department, area or entity.
This part aims to identify sources of the risk, areas of impact, events (including changes in circumstances) and their causes and potential consequences. It needs to include all significant sources of risk, including those beyond the College’s control. If a risk/threat is not identified, there can be no strategy to defend against it.
Describe those factors that might create, enhance, prevent, degrade, accelerate or delay the achievement of objectives. It is also important to identify the issues associated with not pursuing an opportunity; that is, the risk of doing nothing and missing an opportunity. The objective of this step is not to create an onerous and lengthy list of all possible risks, but to identify all significant risks that could impact the College.
Enterprise wide risks to the College are identified and reviewed annually by the ARC, General Manager, and COO for final review by the College Board. These risks form the basis of the overall risk profile for the organisation. The risk profile format is included in Appendix 3.
When identifying the risk, consideration should be given to these questions:
Categories of Risk:
The following broad categories of risk are used to enable appropriate aggregation and to assist with the identification of systemic issues and trends across the College.
Risk analysis can be undertaken with varying degrees of detail, depending on the risk, the purpose of the analysis, and the information, data and resources available. Analysis can be qualitative, semi-quantitative or quantitative, or a combination of these, depending on the circumstances.
Once the risk has been identified and the context, causes, contributing factors and consequences have been described, look at the strengths and weaknesses of existing systems and processes designed to help control the risk. Knowing what controls are already in place, and whether they are effective, helps to identify what – if any – further action is needed.
The objectives at this step are to separate the minor risks from major ones. The level of risk is determined by measuring the probability of each event arising and the associated consequences (impact).
Risk Analysis Criteria
Once the controls have been identified, and their effectiveness analysed, an assessment is made of the probability of the risk occurring and the impact if the risk were to occur. This produces an accurate, albeit subjective, assessment of the level of risk – or risk rating – and helps in the next step to determine whether risks are acceptable or need further treatment.
Impact is generally found using the consequence criteria of the College – potential financial loss, reputation impact, legal and regulatory compliance and management time and effort. Whilst most significant risks will relate to the direct financial and operational impact to the College, for some risks the most significant consequence is the impact on the College’s reputation. For such risks, the direct financial consequence of a risk may be negligible, but continuing reoccurrences may result in significant damage to the College’s reputation and standing.
The purpose of risk evaluation is to assist in making decisions, based on the outcomes of risk analysis. This tells us which risks need treatment and the priority for treatment implementation.
Risk evaluation involves comparing the level of risk found during the analysis process with risk criteria established when the context was considered. Based on this comparison, the need for treatment can be considered.
Decide whether the risk is acceptable or unacceptable by using the information gathered during the Risk Assessment phase to make decisions about future actions. Decisions about future actions may include:
Whether a risk is acceptable or unacceptable relates to a willingness to tolerate
the risk. The attitude, appetite and tolerance for risk is likely to vary over time, across the College as a whole and for individual faculties, departments, divisions, areas and controlled entities.
Decision Options:
Risk is acceptable – A risk is regarded as acceptable or tolerable if the decision has been made not to treat it. It is important to remember that designating a risk as acceptable does not imply that the risk is insignificant. In fact, these risks may still need to be monitored.
Risk is unacceptable – Risks in this category progress to the next step, Treating the Risk, where solutions are decided upon.
A risk may be acceptable or tolerable in the following circumstances:
The purpose of prioritising is to determine the level of action needed for the identified and analysed risks.
| Risk Rating: | Management Action: | |
| Extreme Risk | Immediate action required. | |
| High Risk | Action plan required, senior management attention needed. | |
| Moderate Risk | Specific monitoring or procedures required, management responsibility must be specified. | |
| Low Risk | Manage through routine procedures. Unlikely to need specific application of resources. | |
| Minimum Risk | Manage through routine procedures. Unlikely to need specific application of resources. | |
The objective of this step is to identify how the identified risks will be treated. Risk treatment involves identifying the options for treating each risk, evaluating those options, assigning accountability (for Extreme, High and Moderate residual risks) and taking relevant action. The following options are available for treating risks and may be applied individually or in combination, with due consideration of risk appetite:
| Risk Decision | |
| Mitigate the risk | Reduce the likelihood – Improving management controls and procedures. Reduce the consequence – Putting in place strategies to minimise adverse consequences, e.g. contingency planning, Business Continuity Plan, liability cover in contracts. |
| Transfer the risk | Shifting responsibility for a risk to another party by contract or insurance. Can be transferred as a whole or shared. |
| Accept the risk | Controls are deemed appropriate. These must be monitored and contingency plans developed where appropriate. |
| Avoid the risk | Not to proceed with the activity or choosing an alternative approach to achieve the same outcome. Aim is risk management, not aversion. |
Work out what kind of treatment is desirable – mitigate, transfer, accept or avoid.
Identify and design a preferred treatment option.
Evaluate treatment options and assess their feasibility. Do the controls appear to have the desired treatment effect? Will the controls trigger any other risks? Are the controls beneficial or cost efficient? Is the cost of implementing the control reasonable for this risk?
The cyclical process of treating a risk, deciding whether residual risk levels are tolerable and assessing the effectiveness of that treatment are all case-by-case assessments that depend on a good understanding of the risk and a focus on the end objective of the activity being assessed.
Document the risk treatment – using the Risk Management Profile (Appendix 2). Treatment plans should identify responsibilities for action, time frames for implementation, budget requirements or resource implications, performance measures and review process where appropriate.
Implement agreed treatments – once any options requiring authorisation for resourcing, funding or other actions have been approved. The person assigned with the primary responsibility for the risk is accountable for the treatment of the risk.
Once the risk has been treated, assess the level of residual risk. Even when a risk has been treated, and the controls are in place the risk may not be completely eliminated. The level of residual risk refers to the likelihood and consequence of the risk occurring after the risk has been treated. Once implemented, treatments provide or modify the controls. The residual risk rating is generally lower than the original risk rating otherwise the controls were not effective. The residual risk should be documented and monitored and reviewed. Where appropriate, further treatment might be prudent. Having a good awareness of residual risk is important in monitoring and reviewing risk on an ongoing basis.

Use this table to determine how likely it is that the College will be exposed to each specific risk after taking into account internal controls and considering factors such as:
| Likelihood | Level | Description | Probability |
| Remote | 1 | May only occur in exceptional circumstances | <20% |
| Unlikely | 2 | Could occur during a specified period | 21-40% |
| Possible | 3 | Might occur in 1–2-year period | 41-60% |
| Likely | 4 | Will probably occur in most circumstances | 61-80% |
| Almost Certain | 5 | Expected to occur in most circumstances | >80% |
Use this table to guide the assessment of impact of each identified risk.
| Impact | Level | Financial | Reputation | Legal | Management Time |
| Insignificant | 1 | <$5000 | Isolated adverse Media reference Public complaint |
Minor breach Informal complaint | Requires minimal time and effort to resolve |
| Minor | 2 | $5000-$50,000 | Repeated adverse coverage | Formal complaint | Causes some business disruption |
| Moderate | 3 | $50,000-$250,000 | Sustained adverse coverage | Regulatory investigation | Causes business disruption |
| Major | 4 | $250,000 – $1m | Extended adverse coverage | Penalties for breach of code Temporary closure | Requires concerted management effort for couple of months |
| Catastrophic | 5 | > $1m | Permanent closure | Fines, prison sentence | Requires management for multiple months |
Policy Portal
ABN: 58 004 265 016
Copyright Melbourne School of Theology 2019