Committee of the Whole · February 04, 2025 · Item 10.2
Report titled “Enterprise Risk Management Policy and Framework Overview” be received.
Main motion under the agenda item Enterprise Risk Management Framework & Policy Overview, 2025-57
Carried (10 to 0)
10 in favour, 0 against — unanimous
What was voted on
The motion in its exact words, as recorded in the minutes.
That the report titled “Enterprise Risk Management Policy and Framework Overview” be received.
Moved by Mayor Guthrie, seconded by Councillor O'Rourke.
How the room voted
In favour (10)
- Allt
- Billings
- Caron
- Caton
- Chew
- Downer
- Gibson
- Goller
- Guthrie
- O'Rourke
Who spoke to it
Robert Jelacic, General Manager, Internal Audit, introduced Enterprise Risk Management Framework & Policy Overview.
What council was given
The staff reports and correspondence attached to this item. The summaries are written automatically, so you can tell what a document is without opening a ninety-page PDF.
- Enterprise Risk Management Framework and Policy Overview - 2025-57.pdf
An information report describing a new Enterprise Risk Management policy and framework, to be used across City departments starting in 2025, aimed at spotting and handling risks in a consistent way when making decisions. Council is asked only to receive it. Staff note that acting on future risk-reduction recommendations could carry costs.
- Attachment-1Enterprise Risk Management Policy.pdf
- Attachment-2 Enterprise Risk Management Framework.pdf
- Attachment-3 Enterprise Risk Management Council Presentation.pdf
A summary is this site’s description of a document, not the City’s. Open the document before relying on one.
What was said
2,814 words from the meeting recording, transcribed automatically. Times are from the start of the recording.
Read the debate(click to open)
1:43:42Sorry, and its expectations and guidelines for the risk assessment process provide the how to details.
1:43:48In meeting the policies objectives.
1:43:50Let's look at some roles and responsibilities and expectations as outlined in the year and policy.
1:43:58Since this is an enterprise level tool, the overall accountability lies within the CAO's office.
1:44:03Senior leadership's role is to set the tone of expectation, including review, including regular review of risk reporting.
1:44:10For the first few years of implementation, the IA and SIS teams will get the ball rolling.
1:44:16Risk ownership and coordination will be the responsibilities of all of us.
1:44:20Initially, this will include helping to review department risk assessments to help identifying the common themes that come with this.
1:44:27These themes will be summarized and become the organizational risk register.
1:44:38Many of you have likely heard of the concept of the three lines of defense.
1:44:41A quick recap of how the RM and the lines of defense are meant to function.
1:44:45The first line lies with the frontline business and process owners with management expected to maintain effective controls to manage risks on a day to day basis.
1:44:58The second line is oversight through risk management and compliance functions used to monitor and guide the front lines.
1:45:04The third line, which includes internal audit as well as external auditors, is an independent group with no day to day duties and risk mitigation,
1:45:16providing assurance to senior management and council on the effectiveness of risk management practices.
1:45:21Moving to the RM framework, here are some highlights.
1:45:28Firstly, the framework describes a general approach that will be used across the organization to help manage risks.
1:45:33The key risk assessment process is used, has four key steps.
1:45:37Identify the risk using a formal risk assessment process exercise.
1:45:41Analyze the risk noted using a five point likelihood and impact scale.
1:45:45During this step, consideration should also be given to the velocity of the identified risk and its impact on the risk keep map.
1:45:51Once risks have been identified and their impacts determined, the evaluation to prioritize the risks is accomplished with the use of a risk keep map.
1:46:04Finally, for all higher risks identified risk owners develop treatment plans that aim to put practices in place to reduce risk levels in a cost effective manner.
1:46:14Higher risk items are then, sorry, higher risk items get more attention, including reporting to the executive team and council.
1:46:25So let's move to the highlights of the implementation plan.
1:46:30Where do we want to be in the near future?
1:46:33The goal is to be an integrated state of maturity from an ERM perspective within three to four years.
1:46:38This will be done in a stepped approach with the intent of building on existing business planning activities we are all involved in.
1:46:45This includes formal ERM framework and supporting policy and guidelines with consistent tools for identifying, assessing and monitoring risks at the enterprise, divisional and project levels.
1:46:56Defined risk appetite and tolerance that is agreed upon by both management and council.
1:47:01Coordinated and integrated approach to risk management enabled by accountable risk coordinators embedded in operational areas and supported by the office of the CAO.
1:47:09And regular reporting and monitoring on higher priority risks at the enterprise and divisional levels supported by a core set of KPIs that are aligned with risks identified and are used to detect changes in risk levels and trends.
1:47:22So how are we going to get to the integrated state in the next three to four years?
1:47:34Implementation of the ERM framework has been identified as a strategic initiative for the organization.
1:47:40The goal for 2025 is to develop an enterprise level risk register for senior management and council consideration.
1:47:46And this will be presented to council in quarter two.
1:47:49The ERM policy framework and guidelines will be circulated throughout the city for use.
1:47:54We will finalize the enterprise strategic risk assessment exercise, which we're currently in the process of doing, and we'll develop ERM training and communication items.
1:48:03And lastly, I'm sorry, identify and integrate with existing governance work being done.
1:48:07For example, work that's being done on the strategic plan, the KPI updates that we do.
1:48:12We will then initiate department business unit risk assessments and also regular reporting to executive team, leadership team and council.
1:48:20As, sorry, as mentioned, the deliverable for 2025 is development of an enterprise risk registry.
1:48:31The next steps is to focus on operational risk risk management.
1:48:35The ERM strategic initiative KPI strives for implementing ERM at a departmental level with targets of 25% uptake in 2025, 50% in 2026 and 75% in 2027.
1:48:47That concludes the presentation. Are there any questions?
1:48:51Thank you very much for the presentation. I do have mayor Guthrie with a question and then I'll ask third over to councillor Gibson.
1:48:59Go ahead, your worship.
1:49:01Sure. Thanks, chair. Do you want me just to, I'm happy to move, move it as well before I ask the question if you want to get it on the floor.
1:49:07Let's do it and seconded by councillor O'Rourke.
1:49:09Okay, perfect.
1:49:11I've got two quick questions. One is probably directly to you. One might be to one might be to the deputy CAO team CAO team.
1:49:18So to you is why the 25% adherence and then 50 and then, you know, like, like I'm asking very sincerely, like if it's a, if you have a great answer, which I'm sure you do, tell me, tell us, but I, there's, there's another part of me that sees the legitimacy and the reasoning why we need this, this
1:49:42this management's this risk management system in place. And to me, it kind of feels like if council, you know, agrees to moving forward with it, like it should just be done.
1:49:51Like there should be just, it should just be adhered to. So why the ability to allow the departments to do this kind of slow ramp up over a three year period.
1:50:03I can understand that better. I appreciate it.
1:50:05Yeah, through through chair Gullo to the mayor.
1:50:07Quite honestly, mayor, it's about resourcing. So from an internal artists perspective perspective, we are a team of two. So we don't have enough manpower to execute this.
1:50:16And also we have to sort of identify where this is going to sit in the organization.
1:50:22We've had some preliminary discussions with with with my colleagues. And so it'll, it'll be a matter of time as we sort of implement this into the work plans of our, of our colleagues into the into the city.
1:50:34And quite honestly, I mean, it is, it is a big undertaking. I mean, it's taking us a bit of time to get to this phase.
1:50:40You know, we've we've been kind of working on this since 2018 or so and it's taken a number of years to get to here. So it will take a bit of time to sort of get down to that operational level and educate people on the risk assessment process.
1:50:52Help us to identify where the risk trends are in those particular areas. And then also to develop those strategies where we need to reduce those risks.
1:50:58So it's simply a question of just not having enough time and resources to do it right away out of the gate.
1:51:04Okay, so as a takeaway on that topic, if during budget time as reports come back, could you identify for counsel? If you had more time or if you had more resources, you could initiate the the alignment and any adherence to the to the risk management sooner.
1:51:24Like, I don't know what that answer would be today, but can you identify that for us in the future? If there's the ability to fast track that through the chair to the mayor, absolutely, we can do that.
1:51:33Okay, so I'd appreciate that. Thank you. And then my last one, as I said, it might be through to you, Tara, to the CEO or WCA group. But I like I just find the importance of this.
1:51:45Like really key to sort of moving forward through a lens, almost, because your report talks about the enterprise risk management being almost embedded in each department of the city. So as counsel gets a report, would we maybe start seeing the risk management being identified on each report of how it aligns to each report.
1:52:08And I'm viewing it in a similar way that we have how on every single one of our reports, how it shows how it aligns to the strategic plan.
1:52:16It would, is this something that maybe could be added where necessary that it's embedded in each report. So this report aligns with the strategic plan in these ways.
1:52:26Oh, and it also aligns as a as an initial filter on almost every report to our enterprise risk management as well in this way. That way it's like really kind of this embedded your presentation in the report said tone from the top that we see that this is being used in everything we start to do on a on a regular basis moving forward.
1:52:47Have you have you thought of doing it in the way that I'm mentioning it.
1:52:52Um, so through the chair to the mayor.
1:52:57Sorry.
1:52:59At this point we have not considered. Sorry.
1:53:07At this point we haven't considered changing the templates. I'll definitely will take that away for consideration. I just want to say that I think, you know, the process that we're talking here what I'm excited about is more of the bringing the, the, the enterprise.
1:53:23The enterprise level risk conversation to council in a closed way where we can have like real conversation and have those then linked to budget and other decisions. And so I think you'll like that'll be phase. That'll be the thing that you see next.
1:53:38Um, and, and I just don't I don't want to leave any, um, any kind of concern that that we don't already manage risk. I would say that that we do really well across the like every department in the city. I would say has a very.
1:53:53Um, you know, in depth understanding of the risks and what what we're doing here is we're trying to roll it up so that we can have corporate conversations about it and use that data a little bit better.
1:54:04So, um, so I just, I just to add to the context there, I, we are doing risk management at the department level and I think that, um, you know, the, the budget and every report that you see has, has kind of that risk management lens baked in, but we'll, we'll take away the consideration on how we can maybe make that pop a little bit more.
1:54:24Okay. Thank you. And thank you, chair. Um, yeah, I think more front facing in your face a little bit identified through a template or a natural way of having it in the reports.
1:54:36Um, in a repetitive way showing that it's meeting the criteria of the, of the risk management is something that would be interesting for you to consider. Thank you very much. Thank you chair. That's it for me.
1:54:47Thank you, your worship. I have counselor Gibson and then counselor work.
1:54:52Chair Goller. So, I like this conversation. Thanks very much. Just bringing it forward. Every corporation has the risk.
1:54:59Um, I, I contribute to the risk registry at my company quarterly on on some files. I guess my question in Miss Baker, you may have just touched on a little bit is just the open like the.
1:55:11Unfortunately, the transparency of this file quite a few times privilege and confidential information has to be registered through the risk registry and that is shared with our team, my company privately.
1:55:24What can the public expect from this process? I don't want to set expectations to pie, but I would assume everything from environmental compliance to building code to labor to all those things that may appear on our risk registry.
1:55:38We're probably not always be public facing as well and maybe a comment from staff. Again, just trying to set expectations of what this is going to look like.
1:55:46Or whether or not be a bit of a corporate.
1:55:49Yeah, thank you through the chair counselor Gowler to counselor Gibson. Yeah, you're absolutely right. I mean, a lot of the elements we're going to identify are going to be confidential in nature and not for public consumption.
1:56:03But I mean, there is always an avenue to present what we can to to the public through the process via an open.
1:56:11I'll report or an open information session. Absolutely.
1:56:16Do you want to add to that?
1:56:22No, I guess I would just say, I, you know, we will do our best to maybe have to report out at an open way, maybe through an annual work plan or through some kind of annual report.
1:56:38I'd say the other thing is that with our external audit, we do have the ability and we look, they look at risk as well through the audit lens.
1:56:46And so we can take that away and how we best communicate to the public what what the risk levers are maybe at a really high level.
1:56:54But but for me, I think it's really important for the you as a council to be able to have a close conversation about the details of those risks and and have those open conversations like real.
1:57:08Conversations about that that are confidential in nature. So, well, again, we'll take that away and see, see how we can we optimize our transparency as much as we can, but understanding that these will be sensitive conversations.
1:57:24Thank you. I agree. Just a brief comment from me again, nothing salacious here. These are these are conversations that all corporations have. So I appreciate the openness of staff bring forward to this point.
1:57:36And I'll support the recommendations and I look forward to look forward to our conversations.
1:57:44Thank you, Councillor Gibson over to Councillor O'Rourke.
1:57:47Thank you, Chair Goller. Can I make a comment and ask my question just because it follows the conversation.
1:57:55So through you to staff, I feel differently about changing the reporting template to council, because having worked for a crown corporation provincial crown and been on the board of a different provincial crown.
1:58:08The value of the risk registry is to see what the what all the risks are, what their probability is what the severity would be. And then you get to see the whole thing and judge what are the highest priority risks because there's lots of risks.
1:58:26It's the highest priority risk that we need to address. So my concern with adding it to staff reports to come to council regularly is that you're only seeing that one bite of the elephant without being able to judge it against other things happening in the organization.
1:58:42So just sort of responding to the conversation, not a real reflection, but the value I have seen in both contributing to and receiving those risk registries was that broad view.
1:58:56There might be a very, very high risk with a low probability. But if you were just getting that report at council, you would say, oh my gosh, it's a high risk and why aren't they doing anything?
1:59:06But it's the mature conversation likely in private to sort that out and to inform the budget decisions. So so that's my take on on the individual reporting.
1:59:19And then through you, chair Goller to Mr. Jelacic, again on slide 14 where it says you're going to start with 25% 50 are going to start with the highest priority areas. Do you determine which departments are on board at first?
1:59:34Through councillor or through the chair Goller to councillor or work.
1:59:38To be honest, I really got to that stage yet to determine where that or how that 25% would be. I think there will be some some merit to starting with areas where there's a higher.
1:59:52Higher likelihood of risk and where my risk plans and mitigation strategies need to be developed. That would that would make a lot of sense.
2:00:03Thank you.
2:00:06Thank you for those questions. Councillor or any other questions or comments from my council colleagues.
2:00:12Seeing none, I wanted to take a moment to thank you, Mr. Joseph and thank you, Mr. Can for the work that you do for the city. It's very important work and we look forward to seeing you here as you're reporting these items.
2:00:24I will call the vote all anyone against the report.
2:00:30Seeing none, we have received the enterprise risk management policy and framework overview.
2:00:39And I believe that it's it for me, your worship.
2:00:41Great. Thank you, chair.
Automatic transcription is imperfect. Treat quotes as a guide and check the recording before relying on exact wording.
The motion, the vote and the debate come from the City of Guelph’s published record, reproduced rather than interpreted. The document summaries above are the exception: those words were written for this site.