Effective risk management is crucial at ACU. Our Risk Management system, known as CARM, is designed to address and mitigate risks across the University.
Effective risk management is crucial at ACU. Our Risk Management system, known as CARM, is designed to address and mitigate risks across the University.
CARM, custom built by ACU, adds a new level of automation and sophistication to our existing risk management processes.
CARM captures the management of risks in ACU's Enterprise Risk Registers. Enterprise Risk Registers (Organisational, Strategic and Major) help us identify risks and assess the threat they present. We can then develop strategies to respond to the risks and assign actions to reduce the threat as efficiently and effectively as possible.
Enterprise Risk Registers are not to be confused with WHS risk reporting via Riskware or other function-specific systems.
ACU's Enterprise Risk Registers are prepared by the Senior Executives (Strategic Risk Register) and organisational units such as faculties, directorates etc (Organisational Risk Registers). These registers capture all the key risks faced by different parts of our institution. Risks are identified in CARM, where they are assessed for likelihood and consequence, and actions are assigned for mitigation and control.
The acronym CARM represents the four key processes for managing risks: Capture, Assess, Respond and Monitor. The system guides users through each step of the risk management process, allowing them to construct and manage their Risk Register more effectively.
Key features of the CARM system include:
Everyone should report risks. If a risk can be addressed and resolved immediately, staff should act accordingly. Risks that require further attention should be escalated to supervisors or managers.
For risks that are potentially significant or recurring, they should be registered in the CARM Risk Management System. If you identify a risk that you believe should be recorded in CARM, please escalate to your manager and CARM team member for assessment.
Note: With regards to all WHS incidents and hazards, all risks should continue to be reported within the WHS Riskware system. Similarly, all cyber-related risks should be reported via Service Central, or to IT directly. For concerns regarding emails received, that potentially represent a threat to ACU's system integrity or are fraudulently sent, report the email asap using the function key on the top right-hand side of the Outlook toolbar.
The CARM Risk Management System registers risks that could impact the success of ACU's strategic plan mission, and vision. They may be for example, once-off but potentially material, or smaller but recurring (therefore presenting an ongoing or larger aggregate threat to ACU's operations or priorities).
ACU has identified ten key categories of risk that should be recorded in CARM:
Categories | Description | |
---|---|---|
1 |
Community Wellbeing |
Risks that threaten the wellbeing of our community, including students, staff and the environment |
2 |
Values & Culture |
Risks that threaten or impact our Catholic identity, values or ethics |
3 |
Learning and Teaching |
Risks related to the delivery of quality education |
4 |
Financial |
Risks that threaten our financial viability or sustainability |
5 |
Governance |
Risk related to our framework of governance and control |
6 |
Operational |
Risks related to our operating capacity |
7 |
Innovation, Projects & Transformation |
Risks relating to projects |
8 |
Reputation & Brand |
Risks that impact our reputation and brand |
9 |
Research & Enterprise |
Risks relating to research and enterprise activities |
10 |
Strategic |
Risks that cause a material impediment to the achievement of ACU's Strategic Priorities and are identified and monitored by the Senior Executive management team via Assurance Unit |
Each organisational unit maintains its own Risk Register, with the head of the unit serving as the Risk Register Owner. This individual is responsible for managing the risks associated with their unit.
The Risk Register Owner will nominate members who have direct access to CARM to update and manage their units' Risk Register accordingly.
Visit Service Central to access Corporate Services.