Hub Nexus
Updated

AuthorNo author yetClaim it

See something to improve? Propose a change.

Support

On July 15, 2016, the Office of Management and Budget (OMB) issued guidance requiring federal agencies to practice enterprise risk management (ERM). ERM goes beyond compliance and financial risk, looking at risk across five categories: compliance, financial, operational, reputational and strategic.

Why ERM

The framework takes a whole-organization view of risk, with risks assessed and managed before they strike and a more open, risk-aware culture. Its benefits include:

  • standardized risk information to guide strategic decisions;
  • spotting risks that cut across the organization, and their root causes;
  • reducing or avoiding the impact of risks on business objectives through early action;
  • empowering employees at every level to manage risk.

CDC's risk philosophy

CDC practices what it calls intelligent risk management: gathering risk data, analyzing it and turning it into information decision-makers can act on, in service of its mission of protecting the nation's health security. No organization can survive, let alone thrive, by avoiding risk entirely. A culture of risk awareness across the agency, supported by management systems that reduce risk, is the foundation. A common risk vocabulary, integrated risk assessment and response, and frequent monitoring and communication keep risk information in front of decision-makers — and because CDC works in a fast-changing world that demands action, its framework has to keep pace.

Risk appetite

CDC works around the clock to protect the country from health, safety and security threats at home and abroad, and it accepts that avoiding all risk is neither desirable nor practical. Risk appetite is the amount and type of risk an organization is willing to accept to reach its goals; risks can bring good outcomes as well as bad.

  • CDC aims to balance its risks so that no single risk, and no combination of risks within a category or across the agency, goes beyond what senior leadership considers acceptable. Its appetite can shift as conditions change.
  • Managers are expected to use judgment within broad guidelines when applying it.
  • CDC is cautious about risks that could damage public trust and confidence. Legal, compliance, safety and scientific integrity risks tend to have little upside and a large downside, so CDC is unlikely to accept them.
  • It will accept more risk in mission-critical areas — during public health emergencies, for example — or when reducing a risk would cost more than the combined consequence and likelihood of the risk itself. Accepting a particular risk may depend on putting controls and monitoring in place.

CDC continues to develop and update policies and procedures that reflect its risk appetite.

Sources

Rewritten from the Centers for Disease Control and Prevention page "Enterprise Risk Management" (public domain), in hubnx's own words.

LanguagesEnglish

Licence: CC0 1.0 (public domain) · Adapted from www.cdc.gov

1

0

0

0

Spinner Logo

Comments

Spinner Logo
Version: 2CC0 1.0 — public domain
The runaway star that left the Tarantula Nebula
Version: 2CC0 1.0 — public domain
The Blackwell School, where segregation had no law behind it
Version: 2CC0 1.0 — public domain
The Eagle Nebula, seen in the infrared
Version: 2CC0 1.0 — public domain
The house where the Equal Rights Amendment was written
Version: 2CC0 1.0 — public domain
The Aleutians, the forgotten front of the Second World War
Version: 2CC0 1.0 — public domain
The Cosmic Cliffs are not cliffs