Roles and Responsibilities
- Board of Governors - Finance and Audit Committee
- Provides oversight of all components of Enterprise Risk Management (ERM).
- Provides direction and support to the Vice President, People Services and the President on all matters related to ERM.
- Reviews on an annual basis, management's processes with respect to ERM and ensures management is positioned to identify, assess, and respond to risk, and to bring relevant information to the Board of Governors.
- Reviews on an annual basis that VCC's risk tolerance statement is suitable for the environment in which VCC operates.
- President
- Ensures strategic, financial, and capital planning activities are aligned with the ERM Framework and within the College's risk appetite and tolerance.
- Provides leadership and direction to senior management on all matters related to ERM, including VCC's commitment to implementing and maintaining an effective ERM process.
- Vice President People Services
- With the support and approval of the President, recommends and implements broad-based policies reflecting VCC's risk management philosophy and risk appetite.
- Oversees the maintenance of the Risk Register through the Department of Safety, Security, Risk and Privacy.
- Ensures risk mitigation activities are sufficient and appropriate such that VCC's residual risks are within its risk tolerance.
- Acts as the key liaison with the Finance and Audit Committee on all matters related to ERM and supports the President in their liaison with the Board of Governors.
- Senior Leadership Team
- Ensures identified risks in their areas of responsibility are being appropriately managed and mitigated within the ERM Framework.
- Oversees the implementation of high-level mitigation strategies for critical risks in their area(s) of responsibility (e.g. fraud risk, cyber risk, etc.).
- Executive Director, Safety, Security, Risk and Privacy
- Provides strategic direction and advice regarding the development and maintenance of the College's ERM program.
- Escalates key strategic risks to the Vice President, People Services.
- Associate Director, Risk Management and Privacy
- Supports the Vice President, People Services in reporting of risks and risk mitigation activities to the Finance and Audit Committee.
- Develops and manages the College's ERM Framework.
- Maintains and updates the College's Risk Register.
- Conducts annual reviews of identified risks and control measures in all College departments.
- Management and Employees
- Identifies and monitors department-level risks.
- Considers the impact of risk in strategic planning and operational priorities.
- Implements and maintains controls to help ensure that risks are within the College's risk tolerance.
Procedures
- The College will implement and maintain a risk management program to identify and mitigate risks that may impact the College's objectives, and incorporate risk management into core operations, including coordinating and overseeing:
- A Risk Register which identifies those risks with the potential to significantly impact the College's strategic innovation plan and operational objectives;
- The assessment, evaluation and prioritization of each risk using consistent criteria;
- The assignment of a risk owner responsible for identifying and mitigating risks in respective department(s);
- The development of risk response plans in order to manage each risk within the acceptable risk tolerance;
- Regular reviews and reports on the progress of risk response plans; and
- Education and awareness initiatives to increase the understanding of risk management across the College.
- The Associate Director, Risk Management and Privacy (the Associate Director), or delegate, will develop the College's ERM Framework and maintain VCC's Risk Register.
- A formal process to review and update the Risk Register will be conducted on an annual basis. Senior and department leaders are required to provide direct input into the identification and assessment of risks, and for monitoring and evaluating any implemented risk controls between annual reviews, upon request of the Associate Director or their designate.
- The Associate Director, or designate, will present an annual report to the Finance and Audit Committee on the College's most significant risks, and the controls in place to bring those risks within the established risk appetite and tolerance.
- The Finance and Audit Committee and Board of Governors will be presented with a summary of significant changes (if any) in VCC's risk profile upon their request.
- VCC will provide all records relating to the ERM Framework to any approved external auditors when requested.
- The College's institutional Risk Register is a highly sensitive and restricted document which is only shared in its entirety with the Finance and Audit Committee, Senior Leadership Team, and any external auditors. The Associate Director, or designate, will publish an annual report on the status of the ERM Framework, while keeping the details of risks and their mitigation strategies confidential.