Back to Top

 Skip navigation

Risk Board (RB)

 Terms of Reference


1. Role of the Risk Board 

The Risk Board (RB) is accountable to the Management Board (MB) and is responsible for the overall governance of risk management within the CSO. The Board will be chaired by the Chief Risk Officer (CRO).

The RB is responsible for

  • Examining internal and external factors for risk that could impact the business but with a specific view to external, medium and long-term threats to the Office;
  • Developing appropriate policies, procedures, guidance, systems and a CSO Risk Management Framework;
  • Overseeing the implementation of the CSO’s Risk Management Framework and reporting on a regular basis to the MB, and the Audit Committee (AC);
  • Preparing an annual Corporate Risk Register for submission to the MB and the AC and for internal publication;
  • Reviewing the Corporate Risk Appetite (CRA) for submission to the MB;
  • Review and challenge risk management and mitigation arrangements to provide assurance that risk management performance is as expected, to consider whether it can be improved or whether change to the framework or the process is required;
  • Providing an analysis of risk findings for the MB as part of bi-annual reporting;
  • Ensuring standardisation of risk description, scoring and use of templates across the Office;
  • Reviewing and interrogating all of the red, amber and escalating risks identified across the Office via MB, the business planning process, by the Governance Boards or any other process with a view to advising on further mitigation or increased monitoring or escalation to MB as agreed by the Board;
  • Reviewing quarterly updates from risk reporters on any aspect of their risk that may have changed or materalised;
  • Identifying new or emerging risks to the Office in a proactive and agile manner;
  • Coordinating the management of risk for business processes that may cross the boundaries of business areas, divisions and locations (“cross cutting” issues);
  • Reviewing risk events as reported as part of the business planning process; and
  • Reporting to the MB on the lessons learned from such risk events and transfer this knowledge across the Office.

2. Decision Making & Escalation Structure

MB has delegated responsibility for the oversight of risk management to the RB, which remains accountable to MB. It is the responsibility of the RB to keep MB informed of progress and to make MB aware of any issues of significance in a timely fashion. The RB will provide reports to MB on a bi-annual basis and may decide to escalate issues to MB more often if necessary. The RB will be held accountable for the decisions made regarding managing risk escalation and events in the Office.

3. Criteria for Escalation of Issues/Projects from the RB to MB

  • A formal decision of the Board is required to determine whether to escalate a risk to MB if:
    • All mitigation measures that can be applied at the business level have been exhausted;
    • The Board considers that an intervention is required at MB level; or
    • The Board is presented with a risk event that has raised the risk status to a crisis situation.
  • Following a decision to escalate an issue/project, the secretary to the RB will contact the secretary to the MB with a description of the issue/project, the decision being sought and supporting documentation; and
  • In assessing risks, the RB should consider the CSO’s appetite for risk as expressed in the CRA.

4. General Information

  • At the beginning of each year, the RB shall agree and publish a schedule of meetings;
  • Extraordinary meetings may be convened at short notice by the Chair under exceptional circumstances where a serious risk is anticipated, imminent or has been realised;
  • Risk reporters may be invited to RB, by the Chair, to report on risks in their areas of responsibility or may be asked for a written report between meetings;
  • The secretary to the RB shall maintain a log for recording longer term actions and will keep the Chair informed of any outstanding actions;
  • The RB shall ensure that all data and information accessed or available to board members as part of their role will be securely & appropriately managed according to Office policies.

5. Working Methods

Pre-Meeting:

  • The secretary shall arrange a pre-meeting briefing with the CRO at least 2/3 days in advance of the meeting;
  • Documentation shall be circulated to the RB at least 4 days in advance of the meeting;
  • RB members shall familiarise themselves with the material in advance of the meeting.

At the Meeting:

  • Meetings can proceed provided there is quorum of 51% of membership present;
  • RB members shall participate in a professional manner adopting a corporate perspective rather than representing any sectional interest;
  • Participation shall be professional and courteous with open, critical, challenging and objective input from Board members;
  • Decisions shall be made collectively as a Board and members shall respect the confidentiality of board discussions regarding individual opinions expressed.

Post-Meeting:

  • Actions arising shall be circulated as relevant within the agreed timeframe;
  • Draft minutes and actions shall be circulated to the Board within a reasonable timeframe of the meeting and Board members shall respond with feedback/corrections within a week of receipt of the minutes; and
  • Minutes shall be published within 2 weeks of being agreed.

6. Membership of the RB

  • MB shall appoint the CRO, who shall be a member of the MB;
  • The members of the RB should be representative of different functional areas (technical, specialist, business as well as policy) and expertise will be considered in the process of appointing new RB members;
  • The term for each member is set at three years with an option to extend for a further three years Replacement of members should commence on a phased basis – two Risk Board members should be replaced each year at the end of June (A more delayed or accelerated replacement schedule may be warranted to ensure an appropriate balance between refreshing membership composition and maintaining continuity of operations);
  • Members of the RB should be at Senior Statistician/Principal Officer grade; and
  • The secretary shall maintain a record of attendance of RB members.

7. Annual Review:

The effectiveness of operation, the terms of reference and the membership of the RB will be reviewed on an annual basis in December of each year.