Enterprise Risk Management

Framework Objective

This Enterprise Risk Management (ERM) Framework outlines guidelines and procedures for managing, monitoring, and improving risk management practices at the University of San Francisco (USF). It embraces a proactive approach to risk management, emphasizing the importance of understanding the uncertainties that affect our objectives while focusing on our most important risks. 

 

Although risk-taking is often necessary to achieve our objectives, we will manage that risk by using this framework to gain a more comprehensive understanding of the threats and opportunities that we face as an educational institution. This understanding will guide our decision-making, helping us succeed and remain resilient as we manage internal and external risks. Effectively navigating uncertainty will strengthen our performance while creating and preserving value.

 

This framework aligns with the International Standards Organization (ISO) 31000:2018, Risk Management Principles and Guidelines. The ISO framework is globally recognized and respected and is utilized by a wide variety of public and private organizations. 

Open All

USF’s Board of Trustees and President are committed to cultivating an environment that supports innovative, risk-informed decision-making as we work together to achieve our objectives.

 

The Vice President and Chief Financial Officer is accountable for implementing this framework and working collaboratively with the Enterprise Risk Committee and Director of Risk Management to provide updates to the Board of Trustees and President on the progress of the ERM program.

 

The Director of Risk Management is responsible for cultivating and promoting a culture that values and actively practices ERM.

 

Vice Presidents and the Provost are responsible for reviewing, approving, and attesting to understanding the risks that have been identified by the Risk Owner/s in their area.

 

Deans, Department Heads, Faculty, and Staff are expected to incorporate the ERM process into decision-making and operational processes. Existing and new risk management activities at USF will align with this framework.

Organizational Overview and Guiding Principles

Overview 

USF was founded in 1855 as St. Ignatius Academy, a one-room schoolhouse on a cow path that would become Market Street. Like the city that surrounds it, USF is progressive. USF was one of the first universities in the country to be racially integrated. 

 

USF offers undergraduate programs in the arts and sciences, business, and nursing and health professions, and graduate programs in business, law, arts and sciences, education, and nursing and health professions. 

 

As a Jesuit Catholic institution, the University of San Francisco is guided by:

  • Our Mission  USF exists to change the world for the better.
  • Our Values  At USF, we value three things in particular: cura personalis, being people for others, and diversity in all its forms.
  • Cura Personalis – We practice cura personalis, or care for the whole person. We believe that your mind, body, and spirit deserve equal attention and consideration.
  • Being People for Others – Social service is as important as professional success. When students leave USF with a calling to serve others — in their career, in their community, in their life — they are proof that we are living our mission.
  • Diversity – USF welcomes all, whatever their creed, culture, color, country, identity, and orientation.

All USF employees are expected to apply the following ERM principles in their work:

  • ERM supports sound decision-making. Risk-informed decision-making analyzes various courses of action, applies values and ethics, uses a consistent process to identify, assess, treat and communicate risk, and supports accountability through documentation of the process.
  • ERM makes our organization dynamic and responsive to change, facilitates continuous learning and improvement, encourages collaboration, and supports innovation.
  • Risk is managed using a process that is focused on our objectives to help us identify and respond proactively, appropriately, and effectively to positive and negative risk.
  • ERM is tailored to USF’s external and internal environment (or context) and is sensitive to how it affects the process.
  • An effective ERM process depends on timely and transparent communication. All stakeholders are expected and encouraged to communicate promptly, openly, and clearly when fulfilling their responsibilities herein.  

Key Framework Concepts

1. Risk Culture and Governance

The Board of Trustees and the President are responsible for:

  • Receiving semiannual confirmation from the Director of Risk Management that the ERM framework continues to be implemented and that key risks are identified, prioritized, and treated in accordance with this ERM framework; 
  • Assisting the Enterprise Risk Committee with establishing USF’s risk-taking view, prioritizing risks, and validating expectations; and
  • Approving the allocation of resources necessary to implement and sustain an effective ERM program.
  • Supporting a risk-aware culture.

The Vice President and Chief Financial Officer is responsible for:

  • Dedicating resources that support and enable the practical implementation of this ERM framework across the organization;
  • Allocating resources that have been dedicated to support and enable the practical implementation of this ERM framework across USF;
  • Working with the Board of Trustees and President to establish USF’s view of risk-taking; and
  • Promoting a risk-aware culture.

The Enterprise Risk Committee is responsible for:

  • Evaluating risk management processes for efficiency and effectiveness;
  • Approval of the recommendations of the Director of Risk Management; 
  • Reviewing, evaluating, finalizing, and approving the recommendations of the Director of Risk Management;
  • Reviewing and approving USF’s risk register (periodically or as needed); 
  • Reviewing the appropriateness of USF’s risk management treatment plans;
  • Communicating ERM information, recommendations, and decisions; and
  • Fostering a risk-aware culture.

The Enterprise Risk Committee Working Group is responsible for:

  • Evaluating risk management processes for efficiency and effectiveness;
  • Reviewing, evaluating, and finalizing the recommendations of the Director of Risk Management; 
  • Reviewing USF’s risk register (periodically or as needed); 
  • Reviewing the appropriateness of USF’s risk management treatment plans;
  • Communicating ERM information and recommendations to the Enterprise Risk Committee; 
  • Fostering a risk-aware culture.

The Director of Risk Management is responsible for:

  • Providing leadership on the design and implementation of this ERM framework;
  • Supporting the implementation of this ERM framework;
  • Providing tools, guidance and industry best practices to apply this ERM framework;
  • Monitoring and reporting on risks, and advising risk owners on risk treatment strategies;
  • Maintaining an USF-wide risk register;
  • Generating recommendations to address risks and gaps, and providing them to the Enterprise Risk Committee, Vice President and Chief Financial Officer, the President, and the Board of Trustees as appropriate;
  • Leading and coordinating ERM efforts in coordination with the risk owners, risk oversight, risk champions, Vice Presidents, the Provost, and departments;
  • Facilitating training, risk assessments, and workshops;
  • Serving as an ERM consultant to employees and departments; 
  • Ensuring that this ERM framework becomes embedded in all business activities; and
  • Developing and maintaining a risk-aware culture.

Risk Oversight (Vice Presidents and the Provost) are responsible for:

  • Applying this ERM framework to decisions and business processes;
  • Adhering to industry best practices, USF’s policies, all local, state and federal regulations, and reporting to the Director of Risk Management any inconsistency that may threaten USF’s achievement of its mission or objectives;
  • Ensuring that risks for which they are responsible are reported timely, monitored, reviewed and approved; 
  • Assigning risk owners and risk champions; and
  • Supporting a risk-aware culture.

Risk Owners are responsible for:

  • Providing information on assigned risks and initial risk ratings;
  • Providing input on current risk treatment strategies and giving recommendations for any needed modifications;
  • Providing information to the Director of Risk Management and their area Vice President/Provost as requested;
  • Adding new risks (as they emerge) to the risk register; and
  • Monitoring assigned risks and ensuring that appropriate plans of action are implemented.

Risk Champions are responsible for (optional role in each area):

  • Facilitating risk identification within their area by engaging stakeholders;
  • Coordinating risk assessments and ensuring risks are evaluated using the framework; 
  • Providing input on who should own the risk but does not assign accountability;
  • Promoting risk awareness; 
  • Monitoring and reporting risks; and 
  • Supporting mitigation efforts with the risk owner and risk oversight.

All Staff/Faculty are responsible for:

  • Proactively identifying, documenting and escalating risks and opportunities;
  • Being aware of USF’s organizational risks as well as all applicable departmental risks; and
  • Applying USF’s ERM resources (tools and guidance).

Effective ERM involves identifying, describing, assessing, and prioritizing the risks that can affect our organizational objectives. The process outlined in Figure 1 shall be used to assess all risks at USF.

 

Risk Assessment Process

State Objective: Since risk is the effect of uncertainty on objectives, risk assessment begins with stating the objective. Objectives are goals or targets that USF dedicates time, resources and efforts to attain or achieve.

Identify Risk: Briefly state the uncertainty that will impact or effect USF’s ability to achieve the objective.

Describe Risk: Describe the risk in greater detail. The description should include identifiers such as triggers, sources, causes and consequences.

Categorize Risk: Classify the risk using the categories in the Risk Identification section of this Framework. It should also be determined if the risk is a Threat or an Opportunity.

Describe Existing Treatments: Indicate what is currently being done to manage the risk.

Score Risk: Based upon what is currently being done to manage the risk, score the likelihood and impact of the risk using the criteria in the Risk Prioritization section of this Framework.

Develop Additional Treatments: Decide if additional risk treatments are needed to improve the management of the risk, remembering that additional treatments are not always necessary.

Assign Risk Owner, Risk Oversight and Risk Champion (optional) : Determine who has both the authority and accountability to manage the risk (owner), who will have final approval of risk (oversight), and who will be responsible for coordination, but not accountable for the risk (champion). 

 

Risk Categorization

The following 14 categories shall be used when assessing each risk:

Category

Description

Academic

Risks connected to enrollment, student experience and expectations, and accreditation.

Athletics

Risks arising from developing, sustaining and growing athletic programs.

Compliance

Risks due to conflicts of interest, governance and compliance, regulatory requirements, contracts, policies and procedures, and litigation.

Facilities

Risks arising from failure of equipment, processes, and systems critical to continuance of operations and providing public services.

Financial

Risks from the effect of market forces on financial assets or liabilities (such as increases/decreases in revenue, changes in pricing for services and supplies), financial reporting, and revenue cycle management.

Governance

Risks arising from decision-making and rule / policy setting.

Human Capital

Risks associated with hiring and retention, succession planning, employee behavior, diversity and inclusion initiatives, training, and culture.

Information Technology

Risks associated with the use of technology to communicate internally and externally, store and manage data, and carry out organizational activities.

Reputational

Risk of potential harm or damage to the organization's reputation, credibility, or standing in the eyes of others. Includes negative public perception or loss of trust due unethical behavior, poor business practices, service failures, legal issues, data breaches, or negative media coverage.

Safety

A risk that arises from property, liability, or personnel loss exposures (i.e. property damage, claims/lawsuits, employee injuries).

Sponsored Programs

Risks associated with the financial funding and departmental support of special programs.

Strategic

Risks that can impact the organization's ability to achieve its strategic objectives or goals. It arises from factors such as changes in market conditions, technological advancements, competitive pressures, regulatory changes, or shifts in student preferences.

Student Life

Risks connected to student activities (such as clubs and campus events), student mental health, and drug / alcohol use. 

Travel

Risks associated with traveling, particularly to unfamiliar or high-risk destinations. It encompasses various factors that can pose a threat to the safety, security, and well-being of travelers, such as natural disasters, political instability, civil unrest, terrorism, crime, health emergencies, transportation accidents, or cultural misunderstandings.

Risk Prioritization

Risks included as part of the risk register will be ranked on a two-dimensional scale considering both the likelihood of the risk occurring and the impact on the organization if the risk should occur. Using a four-point scale, each risk shall be rated using the following classifications:

 

Likelihood:

Rating

Name

Description

4

Almost Certain

Almost certain to occur, expected in most circumstances

3

 

Likely

Likely to occur or will probably occur

2

 

Possible

Possible, this could occur

1

 

Rare

Rare, would occur only under exceptional circumstances

Impact:

Rating

Name

Description

4

Critical

Severe impact on operations; critical financial loss; impact will last years

3

High

Significant impact on operations; substantial financial loss; impact will last months

2

Moderate

Noticeable impact on operations; moderate financial loss; impact will last weeks

1

Low

Minimal to minor impact, negligible to small financial loss, impact will last days

The above impact scale’s primary focus is on risks that are threats to USF in achieving its objectives. Risks that accompany new opportunities should also be identified, analyzed, and treated to increase the likelihood of success.

 

3. Risk Appetite, Tolerances and Limits

At USF, we recognize the importance of managing risks effectively to ensure the achievement of our strategic objectives while maintaining our reputation and financial stability. We are committed to fostering a culture of innovation and continuous improvement, while also acknowledging the need to balance risk-taking with effective decision-making. USF’s goal is to responsibly pursue opportunities that reinforce our priorities, maintain sustainability, support growth, and advance our mission. We avoid taking risks if their consequences hinder our objectives or conflict with our values, code of conduct, or policies.

Risk appetite refers to the level of risk that USF is willing to accept in pursuit of its objectives. It is a strategic decision made by the President, senior management and the Board of Trustees, considering factors such as the organization's mission, values, and overall business strategy. Risk appetite sets the tone for risk-taking within the organization and guides decision-making processes. 

 

Risk tolerance is the amount of deviation in the amount of risk that USF is willing to bear within its risk appetite.

 

Risk limits are the specific boundaries or thresholds that USF sets to control and monitor its exposure to risks. They are typically derived from the risk appetite and risk tolerance levels and are designed to prevent USF from exceeding its desired risk exposure. Risk limits are crucial in ensuring that USF operates within acceptable risk parameters and enables timely actions to be taken when risk levels approach or breach the defined limits.

 

4. Risk Management and Controls

USF will apply this ERM framework to its processes and decisions as we think, plan, execute, measure, monitor and report on our work as shown in Figure 3.

 

Risks connected to USF’s strategic plan will be identified through periodic reviews of the strategic plan and/or as new risks are appropriately assessed, prioritized and managed. Operational and project risks are consistently managed at all levels of the organization including program management, review and reporting activities, and service delivery.

Figure 3. How a risk is escalated using the ERM Framework

 

All risks should be appropriately managed. However, some risks merit special attention, as their impact moves from an individual department to an organizational level. When such risks are identified, they are reported and acted upon. This intensified reporting and action is what this ERM framework describes as an “escalation” of the risk. Figure 3 above provides a visual representation of how risks are identified, assessed and escalated. As noted in Step 2 of the chart, managers will assess the risk, develop a treatment, and then report the risk to the Director of Risk Management.  As noted in Step 4 of the chart, the Enterprise Risk Committee is responsible for determining which risks should be reported to the President for potential management at an organizational level.  If the President determines that the risk should be escalated for management at an organizational level, the Director of Risk Management will report the risk to the Board of Trustees.

 

Resource requirements associated with this ERM process will be presented, considered and approved annually as a part of USF’s annual budget process.

USF’s ERM approach will align with its strategic priorities and objectives in an effort to:

  • Establish and track performance expectations for this ERM framework;
  • Track improvement in USF’s management practices; and
  • Monitor and track performance on the management of organizational risks.

Semiannually, in December and June, the Director of Risk Management will report on each area above to the President and to the Board of Trustees.

 

On a quarterly basis, the Director of Risk Management will communicate with risk owners, risk oversight, and risk champions to ensure that each area’s risk registers are being updated.    

 

At a minimum, the specific measures that will be used to track the effectiveness of implementing this ERM framework are: 

  • USF’s risk register is documented, analyzed, evaluated, communicated, and updated by risk owners and approved by the area Vice President and Provost at least semiannually and/or as new risks emerge;
  • Development of actionable treatment plans on each risk identified in the risk register;
  • Downward movement of overall risk ratings based on the ongoing implementation of risk treatment plans to a level that the Enterprise Risk Committee determines is controlled;
  • Monitoring the performance/effectiveness of risk treatment activities; and,
  • ERM training established and made available to all USF employees and training conducted for significant stakeholders.  

6. Quality Assurance and Continuous Improvement

Quality Assurance

 

Quality risk information helps to build confidence in USF’s ERM framework enhances stakeholder interactions. Quality assurance occurs at three levels in the organization:

  • All employees are responsible for considering risks and reporting those risks to their supervisors.  Vice Presidents and the Provost are responsible for approving and reporting risks in their area to the Director of Risk Management for review. 
  • The Director of Risk Management serves as the principal quality assurance expert by applying the ERM framework to risks that are reported by Vice Presidents and the Provost and reporting on the information that results from the application of the framework.
  • The Enterprise Risk Committee is responsible for testing assumptions around key risks and related risk treatments to ensure these plans are reasonable and appropriate and then reporting this to the President and Board of Trustees.

Continuous Improvement

This ERM framework and risk governance structure will be continuously improved by following industry best practices and obtaining stakeholder feedback. This feedback will be used to inform and adapt USF’s risk management approach so that it remains effective, efficient, and valuable. The Director of Risk Management will be responsible for keeping the framework and risk governance structure updated according to this process.

Appendix A: Key Terms

Enterprise Risk Management is a continuous, proactive, and systematic process to understand, manage and communicate risk from an organization-wide perspective. It is about making strategic decisions that contribute to the achievement of an organization’s overall objectives.

 

Enterprise Risk Management Process is a systematic approach to setting the best course of action under uncertainty by identifying, assessing, understanding, acting on, and communicating risk issues.

 

Key Risk refers to a specific risk that is identified as material or of significant importance to the organization. Key risks are reported to the President and Board of Trustees and require a higher level of engagement and oversight. Materiality is determined in consultation between the Vice President/Provost (Risk Oversight), Risk Owner and the Enterprise Risk Committee.

 

Innovation is the creative generation and application of new ideas that achieve a significant improvement in a product, program, process, service, structure, or framework.

 

Opportunity is a time, condition, or set of circumstances favorable to a particular action or purpose.

 

Risk Oversight (Vice Presidents and the Provost) are responsible for reviewing and approving risks that have been identified by Risk Owners in their area.  They ensure that risk management is integrated into all organizational activities, culture, and strategy, with clear accountability and reporting mechanisms.

 

Risk Owners are the individuals assigned to manage specific risks within an organization. They have the authority, responsibility, and expertise to manage the risk, develop and implement treatment strategies, report on their risk management activities, and collaborate with stakeholders.

 

Risk Champions are individuals responsible for promoting, supporting, and advocating for sound risk management practices.  They embed risk culture into daily activities without necessarily holding formal risk authority.  This is an optional role within each area’s governance structure.

 

Risk refers to the effect of uncertainty on objectives.

 

Risk Appetite is the amount and type of risk that an organization is willing to accept in pursuit of its objectives.

Risk Limit is the amount and type of risk considered unacceptable to the organization.

 

Risk Tolerance is the acceptable deviation from an organization’s risk appetite.

 

Risk Register is a summary of the organization’s risks developed through use of an explicit, documented, and rigorous process.

 

Risk Treatment refers to the risk mitigation measures or controls that are developed and implemented to address an identified risk. Typical risk treatment strategies include mitigating or reducing the negative impacts of risk, transferring, or sharing the risk, avoiding the risk, accepting the risk, or pursuing the risk (e.g. - seizing an opportunity) as appropriate.

 

Threat is a circumstance or event that negatively impact an organization's ability to achieve its objectives.

 

Treatment Owners are the individuals assigned to implement specific risk treatments in the organization.

 

Appendix B: Risk Management Process

From ISO/ANSI/ASSE 31000:2018 Risk Management Principles and Guidelines

 

Members

Provost: Eileen Fung

Director of Risk Management: Melissa Diaz

VP and CFO: Brent Gustafson

General Counsel & Acting Senior VP: Donna Davis

VP, Student Life: Shannon Gary

VP of Operations: Julie Orio

VP for Strategic Enrollment Management: Eric Groves

Interim VP, Development: Jayme Burke

VP, Information Technology and Chief Innovation Officer: Opinder Bawa

Interim VP, Marketing Communications: Anneliese Mauch

 

Term

Continuous and as recommended by the President.

 

Frequency of Meetings

Meetings should be held:

  • At least quarterly
  • As deemed necessary by the Director of Risk Management
  • As requested by any member of the committee

Meeting Documentation/Minutes

The Director of Risk Management shall document the discussions of all meetings and maintain the notes in an appropriate file for distribution to the committee members and others, as needed.

 

Alternate Attendance

Substitutions to membership representation will be at the discretion of the Vice President and Chief Financial Officer and/or the Director of Risk Management.

 

Enterprise Risk Committee Working Group

 

Members

Director of Risk Management: Melissa Diaz

AVP, Tax Compliance, Internal Audit, & Payroll Services: Dom Daher

AVP, Human Resources: Diane Nelson

AVP, Accounting & Business Services: Desmond Dair

Assistant Dean for Student Athlete Support: Liam Quinn

Vice Provost for International Initiatives: Anastasia Vrachnos

 

Term

One to two years, depending on the committee member’s role.

 

Frequency of Meetings

Meetings should be held:

  • At least monthly.
    • The rest of the ERC will meet quarterly and the Working Group will participate in those meetings
  • As deemed necessary by the Director of Risk Management
  • As requested by any member of the ERC Working Group and/or ERC

Meeting Documentation

The Director of Risk Management shall document the discussions of all meetings and maintain the notes in an appropriate file for distribution to the committee members and others, as needed.

 

Alternate Attendance

Substitutions to membership representation will be at the discretion of the Vice President and Chief Financial Officer and/or the Director of Risk Management.

 

Data Repository Site

Gallagher Risk Track (users must keep all risk register data confidential)