Risk Standard (31000)
Risk management at the University is based on the International/Australian Risk Management Standard AS/NZS ISO 31000:2009 which provides the principles and guidelines for risk management.
Within the Standard the expressions 'risk management' and 'managing risks' are both used. In general terms;
- risk management refers to the architecture, that is the principles, framework and process for managing risks effectively; and
- managing risks refers to the application of that architecture to particular risks.
The Standard outlines eleven principles that an organisation should comply with to ensure risk management is effective:
Risk Management:
- Creates value and protects value
- Is an integral part of all organisational processes
- Is part of decision making
- Explicitly addresses uncertainty
- Is systematic, structured and timely
- Is based on the best available information
- Is tailored
- Takes human and cultural factors into account
- Is transparent and inclusive
- Is dynamic, iterative and responsive to change
- Facilitates continual improvement of the organisation
