1. Purpose
City St George’s is committed to a consistent, proportionate and embedded approach to managing risk in order to support delivery of the University’s strategy and objectives; protect students, staff, patients/service users, visitors and partners; meet statutory, regulatory and contractual obligations; safeguard financial sustainability, reputation, information and assets; and enable informed decision-making, innovation and improvement.
This Policy sets out the University’s framework for identifying, assessing, managing, monitoring and reporting risk and defines responsibilities for risk management across the organisation.
Risk management is embedded within planning, performance management, change initiatives (including post-merger integration activity) and governance processes. It is not a standalone compliance exercise.
This Policy supports compliance with relevant Senate Regulations and external regulatory and statutory requirements, including those of the Office for Students (OfS), UK Visas and Immigration (UKVI), the Charity Commission, and follows international standards (ISO 31000:2018).
2. Freedom of Speech and Academic Freedom
2.1. City St George’s, University of London, regards freedom of speech and academic freedom to be fundamental to delivering its mission as the University of business, practice and the professions. Its values in this respect are set out in a code of practice on freedom of speech and academic freedom, which explains how the University will uphold, secure, and promote freedom of speech within the law: https://www.citystgeorges.ac.uk/about/governance/policies/code-of-practice-on-freedom-of-speech.
2.2. Nothing in this policy should be interpreted in any way that would be inconsistent with the code of practice and – in the event of any inconsistency – the provisions of the code will prevail.
3. Equality, Diversity and Inclusion
3.1. The University is committed to promoting equality, diversity and inclusion in all its activities, processes, and culture for our whole community, including staff, students and visitors.
3.2. The University will meet its obligations under the Equality Act 2010 in all its policies and will seek to eliminate discrimination on the basis of age, caring responsibilities, disability, gender identity, gender reassignment, marital status, nationality, pregnancy, race and ethnic origin, religion and belief, sex, sexual orientation and socio-economic background.
4. Scope
This Policy applies to the University (all Schools/Faculties/Directorates/Professional Services) and to subsidiary entities where the University has governance responsibility.
The University's risk management framework applies to all levels of risk across the institution, including strategic, operational, financial, compliance, research, education, clinical, partnership, environmental, and project risks.
Project risks must not be managed in isolation, as uncertainties affecting major projects and programmes can have significant implications for the University's strategic objectives, financial sustainability, and reputation. Project risks are those uncertainties that could affect the successful delivery of projects, programmes, and initiatives, including impacts on timeline, budget, scope, quality, or expected benefits. All significant projects and programmes must maintain risk registers using the University's standard risk management system and methodology. Project risks that exceed defined thresholds or could materially impact the University's strategic ambitions must be escalated through appropriate governance structures for inclusion in divisional or institutional risk registers.
This Policy applies to risks recorded in 4Risk V2 including Strategic Risk Register; Department/School/Professional Services Risk Registers; Project/Programme Risk Registers; and Thematic risk logs (e.g., information security, health & safety, estates, climate, major incidents). This integrated approach ensures that project delivery risks receive appropriate oversight alongside other institutional risks and enables informed decision-making across all University activities.
5. Policy statement
City St George’s will manage risk as an integral part of strategy and business planning, governance and assurance, operational management, project and change delivery, and continuous improvement.
Risk management is not a periodic reporting exercise; it is part of day-to-day management and decision-making. The University will: take risks where necessary and beneficial to deliver objectives within agreed Risk Appetite; ensure risks are owned and actively managed at the appropriate level; maintain accurate, timely risk information to support oversight; use risk information to prioritise resources, controls and assurance activity; and achieve appropriate balance between stability and innovation.
5.1. Recording and consistency
All strategic, School, Professional Service, project and change risks must be recorded, maintained and monitored in 4Risk V2 as the University’s single corporate record for risk reporting and assurance.
5.2. Strategic risk reporting categories
To support prioritisation and governance oversight, strategic risks will be categorised as:
Most Prevalent Strategic Risks – Strategic risks that present high institutional exposure and/or high-risk velocity, such that material impact would be felt rapidly once triggered. These risks typically require enhanced central oversight, more frequent reporting and additional assurance, regardless of numeric score.
Keep Monitoring Strategic Risks – Strategic risks that remain institutionally relevant but typically have slower risk velocity or more cumulative impacts over time. These remain visible at institutional level to ensure early identification of any material change that would warrant escalation.
This dual categorisation ensures risks with high velocity and/or low tolerance receive appropriate oversight, while maintaining visibility of cumulative or slower-burn risks.
6. Principles
The University’s risk management approach is underpinned by the following principles:
- Leadership and accountability – clear ownership for each risk and clear oversight
- Proportionate and practical – controls commensurate with the level of risk
- Integrated – risk considered alongside performance, finance, compliance and delivery
- Forward-looking – risks and opportunities considered with horizon scanning
- Consistent – common language, scoring, appetite and reporting across the University
- Evidence-based – risk assessments supported by data, assurance and lessons learned
- Continuous improvement – learning embedded through review, audit, incidents and feedback
- Best practice alignment – follows ISO 31000:2018 and sector guidance
7. Definitions
| Term | Definition |
|---|---|
| Risk | The effect of uncertainty on objectives. May be positive (opportunity) or negative (threat). |
| Risk Management | Co-ordinated activities to direct and control an organisation with regard to risk. |
| Inherent Risk | Level of risk before controls/mitigations. |
| Residual Risk | Level of risk after current controls/mitigations are applied. |
| Risk Appetite | The amount and type of risk the University is willing to accept in pursuit of its objectives. |
| Risk Tolerance | The acceptable variation around appetite; points requiring escalation. |
| Risk Velocity | The speed at which a risk materialises and the pace at which its impact is felt at an institutional level once triggered. High velocity risks require enhanced monitoring and preparedness even if numeric scores appear moderate. |
| Assurance | Evidence that controls are designed appropriately and operating effectively. |
| Three Lines Model | 1st line: operational management owns risks; 2nd line: oversight/frameworks (risk/compliance); 3rd line: independent assurance (internal audit). |
| 4Risk V2 | The University’s risk management system. |
| Most Prevalent Strategic Risks | Strategic risks with high institutional exposure and/or high-risk velocity requiring enhanced oversight and frequent reporting. |
| Keep Monitoring Strategic Risks | Strategic risks with slower velocity or cumulative impacts, maintained for visibility and early escalation if context changes. |
| Risk Lead/Assignee | The person responsible for the day-to-day management and review of a risk in 4Risk. The Risk Lead/Assignee undertakes regular monitoring, updates the risk record, progresses actions, and ensures the risk remains current. |
| Risk Owner | The person with accountability for managing a specific risk, ensuring appropriate controls are in place and the risk is reviewed regularly. |
| Control | A measure that modifies risk. Controls may be preventative (stop risk occurring) or detective (identify when risk has occurred). |
| Project Risk | An uncertain event or condition that, if it occurs, could positively or negatively affect one or more project objectives such as scope, schedule, cost, quality, or benefits realisation. Project risks are managed within individual project governance structures but are integrated into the University's enterprise risk management framework to ensure risks that could impact strategic objectives are appropriately escalated and managed. |
The following definitions align with ISO 31000:2018:
8. Risk Appetite and Risk Categories
8.1. Risk appetite approach
The University maintains an approved Risk Appetite Framework (Appendix A) to guide decision-making. Appetite statements are aligned to strategic priorities, expressed by risk category, define acceptable vs. escalation thresholds, and supported by practical indicators where possible.
In pursuing its objectives, the University will generally accept a level of risk proportionate to the expected benefits. The University has a HIGH appetite for risk in contexts of critical enquiry, academic freedom, innovation and strategic partnerships. The University has a VERY LOW appetite for risk where there is likelihood of: significant reputational damage, harm to research/teaching quality, major financial loss, harm to people, illegal/unethical activity, regulatory sanction, or environmental harm.
8.2. Risk categories
Risk categories maintained in 4Risk include Student experience & outcomes; Research & innovation; People/workforce; Finance & sustainability; Compliance & legal/regulatory; Information, cyber & data; Estates, safety & resilience; Partnerships & reputation; Governance & strategic delivery; Climate and environmental sustainability.
9. Governance, Roles and Responsibilities
9.1. Council
Council has ultimate responsibility for effective risk management. Approves this Policy and Risk Appetite Framework, defines and reviews risk appetite, reviews the Strategic Risk Register termly, receives assurance on effectiveness of risk management, and makes active contribution through challenge.
9.2. Audit & Risk Committee
Reviews adequacy and effectiveness of risk framework; scrutinises Strategic Risk Register at least every six months, including trends, appetite alignment, and controls adequacy; seeks assurance on risk management and escalation; oversees relationship between risk, internal audit and external audit; provides annual opinion to Council and recommends the Strategic Risk Register for Council's consideration.
9.3. Senior Leadership Team/University Leadership Team
Oversees and reviews the Strategic Risk Register, including emerging risks; ensures appropriate ownership and resourcing; and advises the President, as Accountable Officer, on risk response, prioritisation and escalation. Ensures that risks appropriately inform strategic planning and performance management.
9.4. President
As Accountable Officer, is accountable to the Office for Students (OfS) for ensuring effective risk management in accordance with the Accounts Direction. Is also accountable to Council, under the University’s Ordinances, for the discharge of risk management responsibilities.
9.5. Risk & Business Continuity Steering Group
Oversee development and implementation of risk framework, guidance, training and system use; advises Senior Leadership Team on risk management process; reviews quality and consistency of registers; monitors reporting timetables; coordinates cross-cutting risks and themes.
9.6. Executive Deans/Directors of Professional Services
Hold strategic accountability for risk management within their Schools and Professional Services. Ensure their areas maintain a current risk register in 4Risk; identify top risks with appropriate actions and controls; escalate risks exceeding appetite or tolerance; and ensure risk identification, evaluation and reporting processes are in place. Day-to-day operational delivery of these responsibilities is discharged through School COOs and Directors of Operations, who maintain the risk register and manage the review cycle on behalf of the Executive Dean or Director.
9.7. Risk owners
Risk owners define risk clearly using cause-event-impact structure in the description, with specific causes and effects identified in the respective 4Risk fields; ensure controls and actions are appropriate and resourced; ensure risk is reviewed and updated per this Policy; ensure assurance sources are identified and monitored; escalate when thresholds triggered.
Risk owners may delegate day-to-day management to a Risk Lead/Assignee who maintains the risk record in 4Risk and progresses actions, whilst retaining overall accountability for the risk.9.8. All staff
Manage risk within their roles; comply with policies and procedures; report incidents, near misses and concerns promptly; contribute to culture of learning and improvement; familiarise themselves with this Policy.
9.9. Specialist functions
Risk, compliance, information security, health & safety, HR, finance and other specialist teams provide frameworks, advice, oversight and monitoring (2nd line). Internal Audit provides independent assurance and annual opinion (3rd line).
9.10.Professional Services Risk Registers
Professional Services (including Finance, Human Resources, Estates, Environment and Facilities, Information Technology, Academic Services, Student Experience Directorate, Library Services, Legal, Governance, Risk and Compliance, and others) maintain dedicated risk registers that support effective institutional risk management by:
- Identifying operational risks specific to their service delivery and ensuring appropriate mitigation
- Ensuring service continuity and operational resilience across critical university functions
- Managing compliance with sector-specific regulations, standards and professional requirements
- Supporting Schools and Faculties through reliable, effective service provision
- Identifying cross-cutting risks that may impact multiple areas of the University
- Contributing to horizon scanning and emerging risk identification through sector networks and professional bodies
- Monitoring sector developments and regulatory changes affecting their professional domains
Professional Services risk registers operate at two levels:
a) Service-specific operational risks managed and monitored within the directorate through local governance arrangements
b) Strategic service risks that may require escalation where they could materially impact the University's strategic objectives, reputation, compliance position or financial sustainability
Professional Services Directors are responsible for ensuring their risk registers appropriately reflect both:
- Internal service delivery risks (e.g., system failures, capacity constraints, skill gaps, resource limitations)
- External-facing risks that could affect academic delivery, student experience, research capability, partnership delivery or institutional reputation
Where Professional Services support critical institutional functions, for example, Finance supporting financial sustainability; Estates supporting health, safety and environmental compliance; IT supporting cyber resilience and digital infrastructure; HR supporting workforce capability; Legal and Governance supporting regulatory compliance; their risk management directly enables the University's ability to manage Strategic Risk Register priorities and maintain operational effectiveness.
Professional Services contribute to effective institutional risk management through:
- Regular review and escalation of service-level risks
- Input to strategic planning and changing programmes
- Participation in cross-cutting risk assessments
- Provision of subject matter expertise to risk owners across the institution
- Monitoring of sector trends and regulatory developments
- Support to Schools and Faculties in managing shared or dependent risks.
9.11.School Risk Registers
Each School maintains a risk register in 4Risk covering risks to the delivery of its academic, research, and operational objectives. School risk registers are the primary mechanism through which academic risk is identified, owned and managed at a local level, and are a key input to institutional risk oversight.
Executive Deans hold strategic accountability for School risk registers. School COOs or Directors of Operations are responsible for maintaining the register, coordinating risk reviews, and ensuring risks are current, owned, and escalated where required. Where a school risk meets escalation thresholds, it must be reported to the Risk and Business Continuity Manager for consideration at RBCSG and, where appropriate, inclusion in the institutional Risk Report.
10. Risk Management Process
Risk management follows a consistent cycle aligned with ISO 31000:2018:
10.1.Identify
Risks identified through: strategic planning, operational delivery, change programmes, audit findings, incidents, complaints, data trends, regulatory updates, horizon scanning, engagement with third parties including NHS (where applicable).
10.2.Assess
Risks assessed using approved scoring methodology (Section 11 and Appendix C) within 4Risk. Assessments must consider inherent and residual risk; quality and coverage of controls; timeframe/trajectory (increasing/stable/decreasing); dependencies and interconnections; alignment with risk appetite; risk velocity; both positive (opportunity) and negative (threat) aspects.
10.3.Respond (risk treatment)
Appropriate responses: Treat/mitigate (strengthen controls/actions); Tolerate/accept (within appetite with monitoring); Transfer/share (insurance/contractual allocation); Terminate/avoid (stop activity if outside appetite and unjustified); Exploit/enhance (for opportunities, maximise benefits).
10.4.Monitor and report
Risks monitored via: KPIs and management information; assurance sources and scheduled reviews; internal/external audit; incident and lessons learned processes; governance reporting routes.
10.5.Risk aggregation and interdependencies
The Senior Leadership Team and Risk Business Continuity Steering Group will: identify interconnected and cascading risks; consider cumulative risk exposure across categories; evaluate how one risk may trigger/amplify others; ensure risk responses address interdependencies; provide aggregated risk reporting to Council and ARC.
11. Risk Assessment Methodology and Scoring
The University uses a non-linear risk scoring methodology combining a linear likelihood scale (1–5) with non-linear impact values (1, 2, 4, 7, 11) to produce a risk score that better reflects the disproportionate consequences of higher-impact events. Full details are set out in Appendix C.
11.1.Risk Scoring
Risk exposure is determined by multiplying Impact Value × Likelihood Score. Impact is scored using non-linear values (1, 2, 4, 7, 11) and likelihood on a scale of 1–5, giving a maximum base score of 55 (Catastrophic × Almost Certain). Scores are recorded in 4Risk and mapped to Low, Medium or High ratings as set out in Appendix C.
11.2.Risk Rating and Review Frequency
Risk ratings and minimum review frequencies are aligned to the University’s non-linear scoring methodology, as reflected in Appendix C and the system-generated Priority Score in 4Risk.
- High (16 and above): Monthly review — escalate to RBCSG and SLT
- Medium (7–14): Quarterly review
- Low (1–6): Review every six months
Critical: Risk velocity should be assessed alongside numeric scores. High velocity risks (rapid onset, limited warning time) should be categorised as Most Prevalent Strategic Risks even if numeric score appears moderate, as they require enhanced monitoring.
12. Risk Registers and Review Cadence
12.1.Minimum standard
All Schools and Professional Services must maintain a risk register in 4Risk. Where an area lacks a mature register, it must as minimum capture its top three risks with clear ownership and actions. It is acknowledged that risks vary widely, and divisions/departments retain flexibility to manage risk appropriately.
12.2. Review frequency
Risk owners must review and update risks at a frequency proportionate to residual risk level and rate of change (see Section 11). Where an incident occurs, controls fail, major change happens, or risk exceeds appetite/tolerance, the risk must be updated promptly. The Risk and Business Continuity Manager has the authority to challenge and recommend revision of risk scores where assessments appear inconsistent with known evidence, organisational context or sector intelligence. An annual quality review of the Strategic Risk Register is conducted by the Risk and Business Continuity Manager and reported to RBCSG, assessing the realism and consistency of scoring across all risk owners. This review is informed by the finding of the Gillies Report (2025) that risk registers can be managed to appear acceptable rather than reflecting genuine institutional exposure.
Institutional risk reporting is aligned to the Audit and Risk Committee (ARC) reporting cycle. All Strategic Risks and any School or Professional Services risks that exceed defined appetite or escalation thresholds are consolidated into the Risk Report.
The Risk Report includes:
- Most Prevalent Strategic Risks
- Material risk movements
- High-level Professional Services and School risks requiring institutional oversight
- Emerging and cross-cutting risks
Internal review deadlines are set in advance of ARC submission to ensure appropriate executive scrutiny and governance challenge.
12.3.Why review matters
Regular risk review is essential because it ensures decisions based on current information; demonstrates active management and accountability; enables early escalation before incidents; supports effective resource use and prioritisation; strengthens assurance to Senior Leadership Team, ARC and Council. Risk management is a core management responsibility and enabler of delivery.
Failure to review risks in line with this Policy may result in reduced assurance and increased institutional exposure.
13. Escalation and Appetite Triggers
Risks must be escalated when: residual risk is outside appetite or materially beyond tolerance; risk score increases materially or controls fail; action plans are significantly off track; risk is cross-cutting and cannot be managed within one area; risk may attract regulatory scrutiny or has significant reputational impact; credible risk of serious harm or major service disruption; matters cannot be adequately resolved at lower levels.
Escalation routes: School/Professional Service → Senior Leadership Team → Audit and Risk Committee → Council.
The following quantified thresholds apply to all risk registers and must be observed by all Risk Owners and line managers: any risk with a residual score of 16 or above must be notified to the Risk and Business Continuity Manager and updated in 4Risk within five working days; any risk where the residual score increases by one full rating band must be escalated immediately regardless of absolute score; any risk outside appetite where no remediation plan exists must be formally accepted in writing at the appropriate governance level. Trigger events requiring immediate escalation regardless of score include failure of a key control, a regulatory notification, a data breach requiring ICO notification, or activation of the Incident Management Plan.
Full escalation decision guidance, including a tiered threshold matrix and trigger events table, is set out in Appendix D.
14. Assurance and Monitoring
Each material risk must identify appropriate assurance sources: management checks, reconciliations and compliance monitoring; performance reporting and KPI dashboards; policy compliance audits; internal audit reviews and follow-up; external reviews/assessments; incident reviews and lessons learned; committee oversight.
The University will align assurance plans to risk priorities and use risk information to inform internal audit planning.
Performance metrics tracked: % of risks reviewed within timeframes; % of actions completed by due date; number of risks outside appetite/tolerance; risk maturity scores by division; number/nature of escalations.
15. Emerging Risks and Horizon Scanning
The University conducts regular horizon scanning (at least annually) to identify potential future risks. This includes monitoring sector developments, regulatory changes and global trends; OfS and peer networks; maintaining standing item on emerging risks at Senior Leadership Team and Risk Steering Group; encouraging bottom-up identification through departmental registers; assessing emerging risks for velocity, potential impact and lead time. The Risk & Business Continuity Steering Group coordinates horizon scanning and ensures findings integrated into appropriate Risk Register.
Horizon scanning is a formal and recurring obligation within the University’s risk management cycle, not a discretionary activity. The following arrangements apply:
- The Risk and Business Continuity Manager is responsible for conducting a quarterly horizon scan and presenting findings to RBCSG as a standing agenda item.
- Intelligence sources to be monitored include: Office for Students (OfS) regulatory updates, financial sustainability reports and sector bulletins; HEBCoN sector resilience intelligence; JISC cyber threat advisories; sector financial health data (OfS, HESA and UUK/PwC annual financial sustainability reports); Committee of University Chairs (CUC) governance guidance and the Higher Education Code of Governance; RSM UK governance and risk outlook publications; Government risk and resilience publications; and relevant professional body guidance. Outputs from the Gillies Report (2025) and subsequent OfS regulatory responses must be considered in each quarterly horizon scan.
- Horizon scan outputs must be assessed for relevance to the University's Strategic Risk Register. Where a new or emerging risk is identified, the Risk and Business Continuity Manager will present options and a recommended course of action to the relevant Risk Owner and RBCSG, who will determine whether a new risk should be added to the register or an existing risk updated.
- An annual horizon scan summary is included in the Risk and BCM annual report to SLT and ARC.
Schools and Professional Services are expected to contribute emerging risk intelligence to the Risk and Business Continuity Manager on an ongoing basis, particularly where operational or sector-specific risks are identified that may not be visible at institutional level.
16. Climate and Environmental Risk
Climate-related risks are managed through integration within Professional Services and academic risk registers, with directorates expected to identify and assess climate impacts relevant to their operational context. The University recognises particular exposure arising from its dependency on fossil fuel-based energy supplies across all campuses, including arrangements linked to NHS infrastructure at Tooting, and its obligations under relevant energy and sustainability legislation. Reducing this dependency through energy efficiency investment and transition to renewable sources is a strategic priority that informs both risk management and estates planning.
Risks are considered across:
- Physical risks – including extreme weather events, flooding, overheating, infrastructure stress, and supply chain disruption.
- Transition risks – including regulatory and policy changes, funding implications, reputational exposure, carbon reduction requirements, and sector expectations.
Climate risk management aligns with the Environmental Sustainability Strategy. Consideration of climate-related factors is expected within estates planning, business continuity arrangements and (where relevant) investment decision-making. Engagement with sector guidance supports development of the University’s approach. The University is committed to keeping mandatory climate disclosure requirements under review, including TCFD-aligned reporting obligations, and will update its approach as sector expectations and regulatory requirements develop.
16.1.Post-Merger Integration Risk
The merger of City, University of London and St George’s in August 2024 is itself a significant source of institutional risk. Post-merger integration risk is a named strategic risk theme for the period to August 2027, covering the following dimensions:
- Cultural integration — differing risk cultures, governance expectations and ways of working across legacy institutions
- Operational integration — systems, processes and data harmonisation across dual-campus operations
- Financial integration — budget consolidation, cost pressures and investment requirements arising from the merger
- Reputational risk — maintaining stakeholder confidence, student experience and rankings position during transition
A dedicated post-merger integration risk is maintained within the Strategic Risk Register with a named SLT-level Risk Owner. Progress against integration milestones is reviewed by RBCSG half-yearly and reported to SLT and ARC annually until August 2027, at which point the need for a continued dedicated risk category will be assessed.
16.2.NHS Estate and Third-Party Infrastructure Dependency
The University recognises its dependency on NHS-owned and NHS-managed infrastructure at the Tooting campus as a named strategic risk requiring dedicated governance oversight, separate from general estates and facilities risk management.
A named Director-level Risk Owner is assigned responsibility for this risk within the Strategic Risk Register. Business Continuity Plans for services delivered from the Tooting campus must explicitly address NHS estate dependency scenarios. Formal arrangements with St George’s University Hospitals NHS Foundation Trust will be governed through a Memorandum of Understanding, setting out respective responsibilities for estate management, service continuity and escalation. Development of this MOU is currently in progress. In the interim, arrangements are kept under review and reported through the standard governance escalation pathway: RBCSG, SLT, and ARC.
17. Risk Culture, Training and Support
The University will: provide practical guidance and training on risk management including 4Risk use; support risk owners with templates, examples and clinics; promote constructive challenge and learning; encourage timely reporting and escalation without blame; define and implement procedures for reporting and escalation; raise awareness of this Policy amongst staff.
Training requirements: All staff (risk awareness on induction and every 3 years); Risk owners (risk management essentials within 3 months of appointment); Heads of School/Directors (strategic risk management annually); Senior Leadership Team/Council members (risk governance briefing annually or on appointment).
17.1.Annual Risk Maturity Self-Assessment
The University will conduct an annual risk culture and maturity self-assessment to provide a structured feedback loop on whether risk management is genuinely embedded across Schools and Professional Services.
The self-assessment will be completed by all School COOs, Directors of Operations, Executive Deans, Vice-Presidents with strategic risk ownership, and Professional Service Directors by 30 April each year, using a structured questionnaire administered by the Risk and Business Continuity Manager. The questionnaire covers five dimensions:
- Leadership and tone — whether risk is actively discussed and visible in local decision-making
- Risk register quality — whether registers are current, owned, and actively used
- Controls assurance — whether stated controls can be evidenced as operating effectively
- Training and awareness — whether staff with risk responsibilities have completed required training
- Incident and lessons learned — whether incidents have been debriefed and lessons tracked to completion in 4Risk
Each dimension is scored against a four-point maturity scale: 1 (Initial — ad hoc, no consistent approach); 2 (Developing — some processes in place but inconsistently applied); 3 (Established — consistent practice, documented and followed); 4 (Optimising — embedded, regularly reviewed, continuous improvement evident).
Results are collated and presented to RBCSG at its June meeting as a standing agenda item, with a heatmap showing maturity levels by area and dimension. Areas scoring below 2 in any dimension will be subject to targeted support and enhanced monitoring. Year-on-year trend data is included in the annual risk assurance report to ARC.
The self-assessment does not replace audit or assurance activity but provides a structured, evidence-based mechanism for tracking risk culture improvement across a large and complex post-merger institution.
17.2.Constructive Challenge and Psychological Safety
The University expects and actively protects the right to raise risk concerns, challenge risk assessments, and escalate issues without fear of repercussion. Constructive challenge is a governance obligation, not an optional behaviour.
This expectation applies at all levels — from Risk Owners challenging their own assessments, to RBCSG and ARC challenging the Risk and Business Continuity Manager, to Council challenging the executive. The absence of challenge is not evidence of confidence; it is a governance risk in itself.
The suppression, withholding or downward management of risk information — whether through optimism bias, omission, or active discouragement of challenge — constitutes a governance failure. This is directly evidenced by the Gillies Report (2025), which found that a culture in which challenge was actively discouraged was a primary causal factor in the University of Dundee's financial crisis.
Where any member of staff has concerns that risk information is not being accurately recorded, escalated or reported, they may raise this directly with the Risk and Business Continuity Manager, the General Counsel and Director of Governance, or via the University’s whistleblowing arrangements. No adverse action will be taken against individuals who raise concerns in good faith.
18. Records Management and Information
Risk records are corporate management information maintained per information governance requirements; retention rules; appropriate access controls within 4Risk; Data Protection Act 2018 and UK GDPR. Risk registers and reports published on intranet as appropriate, with controls for confidential/sensitive information.
All live risk records are maintained in 4Risk as the single system of record, with supporting documents held on the Risk and Business Continuity SharePoint Hub.
19. Interaction With Other Policies
This Policy interacts with: Financial Regulations (including insurance); Health and Safety Policy; Business Continuity and Incident Management Policy; Information Security Policy; Research Integrity and Ethics; Anti-Bribery, Corruption and Fraud; Data Protection; Environmental Sustainability Strategy; Safeguarding; Estates Management; Partnership Policies. It also accounts for wider legislative obligations including Financial Memorandum with OfS and Audit Code of Practice.
Where divisions/departments have significant interaction with third parties (NHS trusts, industry partners, collaborative institutions), Heads must ensure adequate steps to manage shared risks effectively.
20. Policy Compliance and Exceptions
Non-compliance may be escalated through management and governance routes and may result in escalation to SLT and ARC; withdrawal of delegated authority; additional oversight requirements; impact on internal audit ratings; consideration under staff policies. Any approved exceptions must be documented with rationale, compensating controls and time-bound review, requiring Senior Leadership Team approval with ARC oversight.
21. Review of This Policy
This Policy is reviewed at least annually (or sooner if required due to regulatory change, organisational change, or lessons learned). Amendments approved by the Audit and Risk Committee.
Next scheduled review: 12 months from the date of approval by Audit and Risk Committee.