1.1 Enterprise Risk Management
- An integrated, consistent approach to identifying and managing all risks across the enterprise including strategic, operational, cyber, financial, political, environmental and market risks.
- Establish risk appetite, tolerances and effective risk controls.
- Practical application of managing and maintaining an enterprise-wide view of all known risks.
1.2 Catastrophic Risk Management
A process to identify the types of risks that could be considered ‘catastrophic’ ‘extreme’ or ‘significant disabling events’. The consequences of these risks are usually related to community impact, reputation, financial impact or loss of life. Some of these risks may be too difficult or expensive to mitigate but the high consequences nature of these events requires that:
- ‘Catastrophic’ / extreme event risks are identified, monitored and reported to the board.
- ‘Catastrophic’ risks are treated differently to other risks already being managed.
- The capability to respond to these risks is developed and maintained.
1.3 Emerging Threats
- A formal, structured and consistent approach to managing emerging threats to provide confidence to teams and assurance to key stakeholders.
- Ensuring teams can quickly identify, monitor and build contingency plans for a range of potential emerging threats.
1.4 Critical Dependencies
- Ensuring risks related to third parties are identified and managed effectively in the increasingly complex and interconnected operating environment.
- Developing a mature risk management culture that extends the focus to building a shared capability to respond with third party providers.
1.5 Scenario based Modelling
- A scenario-based modelling and planning process that uncovers vulnerabilities and provides decision-makers with context in which they can make decisions. By considering a range of possible futures, potential risks can be identified and managed proactively. Strategies based on deeper insights are more likely to succeed.


