5.1 Update on Revised Corporate Risks
The Committee reviewed with the CRO, the papers circulated in advance of the Committee meeting for the Corporate Risk Review and Risk Update. The CRO updated the Committee on the EMTs Corporate Risk review 2021, noting that the 2021 process involved two dedicated workshops with the EMT in September and December 2021, individual meetings with EMT members, and a workshop with the Corporate Risk Support Team. As part of this review the EMT considered the observations on current risks contained in the Moody Report 2021 and the criteria for the inclusion and removal of risks on the CRR along with reconciliation with the current risks on it.
The approach adopted to the refresh corporate risks was welcomed by the Committee and the Committee provided the following feedback, which the CRO will report to the EMT for further consideration.
Criteria/ guidance for including risks on the CRR
The ARC wishes to take a look at a later meeting at the proposed set of ‘criteria’ these would be used to define risks to be included on the Corporate Risk Register (CRR). The Committee also provided the CRO with some suggested wording changes to the individual proposed criteria to ensure that these could be made clearer.
Commentary on proposed risks
Risk 10 Workforce Recruitment - The ARC is of the view that ‘recruitment and retention’ remains a principal risk.
Risk 16 Healthcare Regulatory non-compliance - The ARC suggested that the retention of this risk be considered further as it specifically referred to ‘healthcare’ non-compliance [e.g. HIQA/ MHC etc].
Risk 20 Individual Performance – In response to questions from ARC about accountability being seen as a critical organisational risk, the CRO advised that the risk as described was not a wider ‘accountability’ risk but related specifically to the performance achievement process.
Risk 25 Funded Agencies - The ARC view is that with the scale of funding involved and the challenges in many of the relationships with large providers this remains as one of the principal risk areas for the organisation.
The Committee referred again to the risks around data protection needing to be highlighted as part of the ‘top’ risk register.
ARC Risk Workshop
The ARC suggested it would be beneficial for it to dedicate more time to considering the EMT’s approach and agreed to consider it more fully at the Committee’s March meeting.
Update on the Corporate Risk Support Team recruitment process
The CRO informed the Committee that the following posts has been concluded and are at job offer stage:
- Assistant National Director: Enterprise Risk and Business Continuity Management
- General Manager: Enterprise Risk Management
- Grade VIII (7posts): EMT members’ risk teams
The Committee noted that the Letter of Engagement between the HSE and the State Claims Agency for the Risk Information System was signed in December 2021 and that it is intended that the revised CRR will be uploaded to the system.
Actions:
- the CRO will report the feedback provided by the Committee to the EMT for further consideration
- the Committee will further consider the CRR, including the criteria list at its March meeting to ensure a wider understanding of the register.