Skip to main content

The content below has been generated by an AI model. If anything is unclear, check the source document (opens in new tab) .

Risk Management Policy and Strategy

2022 to 2024

IMAGE: The Orkney Islands Council crest appears above the words “ORKNEY ISLANDS COUNCIL”.

Contents

  • Document Control sheet — 2
    1. Policy Statement — 4
    1. Introduction — 4
    1. Terminology — 5
    1. Objectives — 5
    1. Approach — 6
    1. Benefits diagram — 7
    1. Status of Risk Management — 7
    1. Management Arrangements — 7
    1. Business Continuity — 9
    1. Monitoring and Accountability — 9

Document Control sheet

Review / Approval History

DateNamePositionVersion Approved
11 December 2018.General Meeting of the Council.N/A.Version 1.0
6 October 2020.General Meeting of the CouncilV1.1
4 October 2022General Meeting of the CouncilV1.2

Change Record table

DateAuthorVersionStatusReason
October 2018.Malcolm Russell.1.0.Final.Reviewed and updated earlier version.
July 2020Les Donaldson1.1Final.Reviewed and updated earlier version.
July 2022.Les Donaldson1.2Final.Reviewed and update.

1. Policy Statement

The Council understands that it is important to recognise and manage the many risks which are inherent in its activities, and in the services which it provides for the benefit of the community. The Council has therefore adopted this policy on risk management, has established the Risk Management Strategy and has implemented procedures in support of the policy and strategy.

The Council wishes to acknowledge that risk can never be eliminated in its entirety. The Council also wishes to recognise that managing risk can also identify positive opportunities which, with the appropriate level of control, may lead to service improvements. Therefore, the measures which the Council adopts are principles of good management practice which seek to control and balance risk and opportunity. Specifically, in the area of risk management, the Council seeks to:

  • Always meet its statutory obligations, and to act within the law.
  • Safeguard the public at large, the Council's members, employees, pupils, tenants and all persons to whom the Council has a duty of care.
  • Protect its property, including buildings, equipment, vehicles or any other assets and resources.
  • Preserve and enhance service delivery.
  • Maintain effective control of public funds.
  • Maintain and enhance the Council's reputation.
  • Safeguard and enhance the quality of Orkney's environment.

The Council will promote these objectives by systematically identifying, evaluating, and thereafter seeking to control and monitor all risks which would potentially endanger, or which could have a detrimental effect upon the aims and objectives stated above.

The Council will support its members and officials in developing the necessary skills and competencies to enable the provision of good quality risk management to the Council.

2. Introduction

The objective of this strategy is to ensure that risk management is an integral part of the Council's corporate and service management, forms part of the Council's governance, planning and service delivery operations and allows for monitoring and reporting on the effectiveness of that strategy.

The strategy acknowledges that risks occur at all levels of the Council's functions and activities and includes strategic or corporate risks as well as innumerable operational risks.

Risk management is part of the Council’s Strategic Planning and Performance Framework, and the monitoring of risk is part of the Council’s Corporate Performance and Risk Management System.

3. Terminology

Governance

The system by which local authorities fulfil their purpose and achieve their intended outcomes for citizens and service users and operate in an effective, efficient, economic and ethical manner. Good governance leads to good management, good performance, good stewardship of public money, good public engagement and, ultimately, good outcomes for citizens and service users.

Risk

The chance or possibility of loss, damage, injury or failure to achieve objectives caused by an unwanted or uncertain action or event. This can be further defined as “the combination of the likelihood of an event occurring (or not occurring, as the case may be) and its impact on the organisation”.

Risk Management

The planned and systematic approach to the identification, evaluation and control of risk. The objective of risk management is to secure the assets and reputation of the organisation and to ensure the continued financial and organisational well-being of the Council. All organisations exist to achieve their objectives. The purpose of risk management is to manage the barriers in achieving these objectives.

Good risk management

Having a process in place that can identify what might go wrong, what the consequences might be of something going wrong and finally, deciding what can be done to reduce the possibility of something going wrong. If something does go wrong, which inevitably happens, making sure that the impact is kept to a minimum. Good risk management is successfully managing the barriers to achieving objectives.

4. Objectives

Orkney Islands Council is committed to establishing and maintaining a systematic approach to the identification and management of risk.

The Council’s risk management objectives are to:

  • Ensure that risk management is clearly and consistently integrated and evidenced in the culture of the Council.
  • Manage risk in accordance with best practice.
  • Anticipate and respond to changing social, environmental and legislative requirements.
  • Consider compliance with health and safety, insurance and legal requirements as a minimum standard.
  • Prevent death, injury, damage and losses, and reduce the cost of incidents and accidents.
  • Inform policy and operational decisions by identifying risks and their likely impact.
  • Raise awareness of the need of risk management by all those connected with the Council's delivery of service.
  • Recognise that good risk management also includes positive risk taking and the identification of opportunities.

These objectives will be achieved by:

  • Clearly defining the roles, responsibilities and reporting lines within the Council for risk management.
  • Setting out clear risk management processes.
  • Continuing to demonstrate the application of risk management principles in the activities of the Council, its employees and members.
  • Reinforcing the importance of effective risk management as part of the everyday work of employees and members.
  • Maintaining a register of risks linked to the Council's business, corporate and operational objectives, including those risks linked to working in partnership.
  • Maintaining documented procedures of the control of risk and provision of suitable information, training and supervision.
  • Maintaining an appropriate system for recording health and safety incidents and identifying preventative measures against recurrence.
  • Preparing contingency plans to secure business continuity where there is a potential for an event to have a major impact upon the Council's ability to function.
  • Monitoring arrangements continually and seeking continuous improvement.

5. Approach

It is essential that a single risk management approach be utilised at all levels throughout the Council. By demonstrating good governance through effective management of risks and opportunities, we will be in a stronger position to deliver our objectives, provide improved services to the public, work better as a partner with other organisations and achieve value for money.

This approach to risk management will inform the Council's business processes, including:

  • Strategic planning.
  • Financial planning.
  • Service planning.
  • Policy making and review.
  • Performance management.
  • Project management.
  • Partnership working.

It is essential in order to achieve the objectives referred to in section 4 that processes are in place to identify and assess risks and opportunities, develop and implement controls and warning mechanisms, and to review and report on progress.

The identified risks and relevant control measures will be managed through the Council's Corporate Risk Register.

6. Benefits diagram

IMAGE: The benefits diagram places “Achieve Objectives/ deliver business services” at the centre and connects it to the following benefits: “Achieve and deliver good governance”; “Avoid impact of failure (perceived or otherwise)”; “Support value for money, project, finance and performance management”; “Comply with legal and regulatory requirements”; “Manage partnerships, suppliers, contractors and ongoing services”; “Control acquisitions or development of new services”; “Manage external changes in culture, political environment”; “Maintain service provision through adversity”; “Adapt to market changes and customer needs”; and “Achieve benefits and exploit opportunities enabling innovation.”

7. Status of Risk Management

Risk management is as much a part of the duties of Council officials as, for example, the control of budgets or the deployment of staff and assets. It is one of many substantive issues to be considered by elected members when making decisions. If the Council is to have reasonable assurance that risk management is effective, and is effectively part of the Council's operations, risk management must be carried out in a systematic and structured manner and be subject to monitoring and reporting on its effectiveness.

8. Management Arrangements

Risk management is a part of service and corporate management and accordingly should be integrated as far as possible within normal management processes.

The Chief Executive will have overall responsibility for the management of risk within Orkney Islands Council. In practice, this responsibility will be deferred to the four Corporate Directors and Chief Officer, Orkney Health and Social Care Partnership (HSCP).

Corporate Director, Neighbourhood Services and Infrastructure will have responsibility for ensuring that the Council’s Risk Management Strategy, Policy and Corporate Risk Register are maintained and regularly reviewed. Risk owners will clearly be identified within the register. The Corporate Risk Register will be reviewed biennially or where a new risk is identified. The reviewed Corporate Risk Register will be presented to the Corporate Leadership Team for approval and thereafter to the Policy and Resources Committee.

Corporate Directors and Chief Officer, Orkney HSCP will have responsibility for ensuring a risk register is compiled and maintained in respect of their Service.

Service Risk registers will be reviewed biennially or where a new risk is identified. Any identified risk which falls out with the risk tolerance level will be escalated to the Corporate Risk Register.

Heads of Service will be responsible for ensuring a risk register is kept of all risks falling within their service and that service risk registers are reviewed biennially or where a new risk is identified. Risks which fall out with the risk tolerance level will be escalated to the respective Service Risk Register.

Corporate Leadership Team shall:

  • Determine the levels of risk and outcomes that are tolerable and acceptable to achieve the Council's objectives.
  • Provide advice to elected members on the type and amount of risk to accept when making policy decisions.
  • Assume ownership of the corporate risks recorded in the Corporate Risk Register.
  • Carry out a strategic overview of the Corporate Risk Register at least biannually.
  • Promote and support the implementation of the risk management policy and strategy throughout the Council.

Identified risks will be allocated to an officer and each risk will be accompanied by an assessment of whether the risk will be tolerated, treated, terminated or transferred. Registers will be accompanied by an action plan, highlighting the means by which the assessment will be achieved.

Identified risks will be divided into the appropriate cluster heading as follows:

IMAGE: A diagram lists the risk cluster headings: “Political”; “Economic”; “Reputational”; “Technological”; “Legislative/Regulatory”; “Environmental”; “Performance Management”; “Customer/Citizen”; “Managerial/Professional”; “Financial”; “Legal”; “Partnership/Contractual”; and “Physical”.

It is acknowledged that there are some aspects of operational risk management which would benefit from corporate support and co-ordination. There is also a need for the Council to be able to demonstrate that risk management arrangements are effective, through the Corporate Performance and Risk Management system.

The Integration Joint Board commissions integrated health and care services from both the Council and NHS Orkney, managed through Orkney Health and Care Partnership's Senior Management Team. To avoid duplication, this integrated service may follow the risk management system and documentation currently operated by either the Council or its partner, NHS Orkney. However, the monitoring and accountability procedures in respect of the Council remain the same.

The Performance and Risk Management Group will consist of at least one representative from each Service of the Council. This will not be a decision-making body, as recommendations would be referred to the Corporate Leadership Team and, as necessary, to the relevant service committee or in relation to Orkney Health and Social Care Partnership, to the Integration Joint Board or a service committee or sub-committee established with an appropriate remit.

The Risk Management Policy and Strategy should be reviewed every two years.

9. Business Continuity

The business continuity process is essentially risk management applied to the whole organisation and its ability to continue with its service provision in the event of a catastrophic event. The Council must ensure risk management processes are applied throughout the business continuity lifecycle.

10. Monitoring and Accountability

Formal monitoring and accountability procedures should form an integral part of the risk management process, covering the following three main issues:

  • Delivering the risk management strategy.
  • Implementing risk management action plans, both corporate and service.
  • Determining whether the action planning is making a difference to the risk, as appropriate.

The following monitoring arrangements are in place:

  • Risk registers are presented to the relevant committee or board annually to advise members of the risks which may affect the achievement of the Council’s strategic objectives.
  • Service risks are monitored through the Corporate Performance and Risk Management System so that any performance risks are highlighted to the Corporate Leadership Team through exception reporting.
  • Ensuring that the Performance and Risk Management Group continues to be an effective and streamlined means of maintaining an overview of risk management and supporting corporate consistency in the implementation of the risk management policy.
  • Internal Audit’s role may include the auditing of the risk management process across the Council and the reporting on the efficiency and effectiveness of internal controls.