7. Be tailored
An agency’s risk management framework needs to include
its risk profile, as well as take into consideration its internal
and external operating environment.
8. Take into account human and cultural factors
Risk management needs to recognise the contribution
that people and culture have on achieving an agency’s
objectives.
9. Be transparent and inclusive
Engaging stakeholders, both internal and external,
throughout the risk management process recognises that
communication and consultation is key to identifying,
analysing and monitoring risk.
10. Be dynamic, iterative and responsive to change
The process of managing risk needs to be flexible. The
challenging environment we operate in requires agencies to
consider the context for managing risk as well as continuing
to identify new risks that emerge, and make allowances for
those risks that no longer exist.
11. Facilitate the continual improvement
of organisations
Agencies with a mature risk management culture
are those that have invested resources over time and
are able to demonstrate the continual achievement
of their objectives.