POL-U30.21 Managing Enterprise Risk
Jump to section
Dates and Approval
Effective Date:
April 23, 2026
Approval Date:
April 22, 2026
Approved by:
President Sabah Randhawa
Who does this policy apply to?
This policy applies to all University employees and organizational units.
Overview
Western Washington University has established an Enterprise Risk Management (ERM) program that provides a framework to proactively identify, assess, and manage risks that may affect the University’s ability to achieve its mission, goals, and strategic objectives.
The University will provide management support and commitment to safety and loss control, and develop awareness of ERM through education, training, and information sharing per RCW 43.19.760 and the Governor’s Executive Order 16-06.
Definitions
Enterprise Risk
The potential for loss or harm that could prevent the University from achieving its mission, goals, and strategic objectives.
Enterprise Risk Management (ERM)
The process of planning, organizing, leading, and controlling the activities of an organization to minimize the effects of risk. It is an enterprise-wide approach that proactively identifies, assesses, and prioritizes strategic risks, followed by the allocation of resources to minimize, monitor, and control the likelihood and impact of risks occurring, or to maximize opportunities. ISO 31000 is the international standard for the practice of enterprise risk management.
Executive Owner
The cabinet-level team member who has oversight of the risk. This means that the risk resides in the division that the executive owner is responsible for.
Risk Register
A list of identified risks, the risk rating and score of each risk, the current controls, treatment plan, risk metrics and who is accountable for managing the risk. The Risk Register, pursuant to the Governor’s Executive Order 16-06, is part of this ERM policy, and will be updated at least annually. The University’s risk register is maintained within the web-based system owned by the Washington State Department of Enterprise Services, which provides state risk managers with a software solution for streamlining all ERM processes.
Risk Identification
The process of identifying risks that might enable or impede the university’s ability to provide its core mission services or meet its strategic objectives.
Risk Owner
The person delegated by the Executive Owner with the authority and accountability for managing a particular risk.
Risk Prioritization
The process of evaluating identified risks to determine the likelihood and impact of each risk, resulting in a risk score and rating.
Policy Statements
1. The University ERM Program is an Organization-Wide, Structured Approach to Managing Enterprise Risks
The University proactively identifies, assesses, and responds to risks that may affect its ability to provide core mission services and the achievement of strategic and performance-based objectives and their intended outcomes. The University uses a consistent, integrated, and transparent enterprise risk management (ERM) approach to support informed decision-making and resource allocation at both the strategic and operational levels.
The University will provide training and apply ERM best practices to identify and manage internal and external risk to protect resources, employees, contract staff, and the public. ERM best practices will be used as an integral part of considering risk in the decision-making process through identifying risks and opportunities across all university divisions, facilities, programs, and areas of operation. Once a risk has been identified and prioritized, the university will develop, implement, and monitor risk treatment strategies.
2. The Director, Risk Management and Compliance Oversees the Enterprise Risk Management program
The Director of Risk Management, under the direction of the AVP of Risk, Ethics, Safety and Resilience (RESR), coordinates and facilitates the enterprise-wide effort necessary to identify, evaluate, mitigate, and monitor the agency’s strategic/operational, legal/compliance, financial, reputational, health/safety and employment risks. This includes facilitating risk identification and prioritization, providing ERM training, consulting on risk response plans, and documenting ERM activities as required by the governor’s Executive Order 16-06.
3. All University Employees Have a Role in Implementing ERM
All employees are responsible for understanding and supporting the agency's efforts to identify, eliminate or manage risk. Employees will identify and communicate risks to their supervisor or the Risk Manager. In addition:
- The University President and Board of Trustees lead, support, and ensure commitment to implementing the University ERM process, establish and communicate the university’s risk appetite and risk tolerance to all employees to support efficient and effective risk mitigation and make a commitment to adopting and integrating ERM into the organizational culture.
- The President's Cabinet provides management support and commitment to ERM, participates in risk identification and risk prioritization, and includes risk consideration as an integral part of the University’s decision-making process. It ensures appropriate allocation of resources to support risk management activities. Members of the cabinet will individually take on the role of Executive Risk Owner for risks that fall within their purview.
- Finance, Audit and Enterprise Risk Management (FARM) Committee assists the full Board in fulfilling its responsibility for oversight of the identification, assessment, monitoring and response to enterprise risks, in fulfillment of the University’s mission and strategic plan. The Committee provides strategic oversight of matters related to the integration of ERM into existing decision-making, strategic planning and budgeting processes. The Committee’s duties do not replace or duplicate established responsibilities and delegations for University leadership and management.
- As Executive Risk Owners, cabinet members delegate and work with Risk Owners to review, approve and support the implementation of risk responses strategies, review risk response strategy effectiveness for risk and ensure the reallocation resources for managing risks.
- Risk Owners will develop and implement response plans and controls, monitor and report on their assigned risks.
- Internal Audit provides ongoing independent assurance functions which evaluates the University's activities to assist the Board of Trustees.
- Internal Audit provides an ongoing independent assurance function which evaluates the University's activities to assist the Board of Trustees, the FARM Committee and Executive Leadership in the discharge of their oversight and management responsibilities, which include the ERM effort. Internal Audit will manage the ERM process by identifying and evaluating entries risk; providing advice regarding management's responses to those risks (but not make decisions about or implement those responses); and evaluating the ERM process itself from the perspective of Internal Audit.
4. President’s Cabinet Members and their Designees Will Participate in Identification and Prioritization of University Enterprise Risks on a Bi-Annual Basis
A Risk Identification exercise will take place every two years in a manner consistent with state requirements and industry best practices, as recommended by the Risk Manager and approved by the Cabinet.
Identified Risks will be prioritized based on a risk rating system using a likelihood/impact matrix. The Cabinet will select a manageable number of risks (e.g. no more than 5 to 10) that will be monitored by the FARM Committee and President’s Cabinet.
5. The Performance of the ERM Program Will be Evaluated Based on Established Metrics
The effectiveness of the ERM framework will be evaluated based on the following:
- Enterprise risks have been reviewed at least bi-annually by President’s Cabinet.
- Actionable response plans have been developed and successfully implemented by Risk Owners for each enterprise risk assigned to them.
- Movement of risk toward lower likelihood and/or lesser impact on the enterprise risk rating matrix.
- Documentation of the review of enterprise risks within routine and strategic University management functions,
- ERM frameworks training established and made available for University stakeholders.