Services · Scale-Up

Risk Management Framework and Architecture

RMF

Develops or strengthens the risk management framework, including risk governance, risk policy, protocols, risk registers, escalation routes, ownership across the three lines of defence and reporting arrangements.

What changes

The National Society has clearer risk ownership, more consistent risk assessment and escalation, stronger governance oversight and better-informed decision-making.

What you get

  1. Risk management policy and framework document RMF001
  2. Risk governance architecture diagram and three-lines-of-defence model RMF002
  3. Risk roles and responsibilities matrix (RACI) RMF003
  4. Risk register template with scoring scales and assessment methodology RMF004
  5. Risk reporting and escalation protocol pack RMF005
  6. Risk management implementation roadmap RMF006

What has to come first

Who is involved

From the National Society's side. This is what the engagement asks of your people.

Your own staff work alongside the adviser throughout, so this is a commitment of their time as well as the Centre's. Ask in the request and you are given the day estimate per role before anything is signed.

RoleWhat they do
NS Board / Risk & Audit CommitteeRisk oversight and final approval
Secretary General / Senior Management TeamExecutive ownership and sign-off
Risk management focal point or coordinatorCoordinates the risk cycle where available
FD Manager and Finance DepartmentRisk reporting and control environment input; service owner
Internal audit, compliance and integrity functionsAssurance and advisory
Legal and complianceRegulatory and policy input
Human resourcesPeople and safeguarding risk input
Heads of department and branch leadershipRisk owners
PMER, operations and programmesProgramme risk integration
GFDC delivery teamDesigns and facilitates the framework

How it is measured

IndicatorTargetEvidence
Risk management framework and policy approved by the Board or Risk & Audit Committee Within 12 weeks of kick-off Approved policy; Board or RAC minutes
Enterprise risk register populated with assessed priority risks and named owners At least 90% of priority risks with an owner and a mitigation plan Risk register; owner sign-off
Risk reporting integrated into management and governance cycles Quarterly risk report to SMT and Board or RAC Meeting agendas and risk reports
Implementation roadmap adopted and on track in the first cycle At least 80% of roadmap milestones met on schedule Roadmap tracker; progress reports

Tools

6 of 6 ready to download.

  • RMF001 Risk management policy and framework document Template DOCX
  • RMF002 Risk governance architecture diagram and three-lines-of-defence model Template XLSX
  • RMF003 Risk roles and responsibilities matrix (RACI) Template XLSX
  • RMF004 Risk register template with scoring scales and assessment methodology Template XLSX
  • RMF005 Risk reporting and escalation protocol pack Template DOCX
  • RMF006 Risk management implementation roadmap Template DOCX

Standards

  • HNS Delegation of Authority (DoA) and governance ToRs
  • COSO Enterprise Risk Management (ERM) Framework
  • ISO 31000 - Risk Management Guidelines
  • HNS statutes, bylaws and Board rules of procedure
  • IIA Three Lines Model
  • IFRC enterprise risk management guidance for National Societies

Describe the problem, not the service

You do not need to know which of the 124 to ask for.