Are you ready for a cyberattack on your organisation’s website? How about a key staff member resigning and taking years of organisational knowledge with them? Floods? Fires?
Most NFP leaders don’t need to be told that unexpected things can go wrong in their organisation on any given day. But how ready are you for what might go wrong tomorrow?
At its core, risk management is simply about knowing what could get in the way of your organisation’s objectives – and taking action before it becomes a crisis.
We’re delving into some of the key people-related risks that NFPs face in the 21st century, and how to manage them. In future posts we’ll look more closely at issues such as cybersecurity, losing critical knowledge and staff burnout. But first, we’re going to start with the fundamentals.
Drawing on the NSW Government’s Risk Management for Not-for-Profit Organisations guide, this post explains the essentials of risk management and how – whatever size your organisation is – you can begin understanding and addressing your biggest risks thoroughly and systematically.
What is risk management?
Risks are uncertainties that could affect what your organisation is trying to achieve. The aim of risk management isn’t to eliminate risks or avoid doing anything uncertain – it’s to understand the potential consequences of different risks, and make deliberate decisions about how to minimise bad outcomes or respond when unexpected things happen.
Because the environment in which NFPs operate is constantly changing, risk management also needs to be an ongoing process rather than something you do once – or even once a year.
The different types of risks NFPs face
Risks facing NFPs generally fall into three broad categories: compliance risks, organisational risks and opportunity risks.
Compliance risks are those where an organisation fails to meet its corporate or legal obligations. These can include reporting, accounting, licensing, workplace relations and work health and safety activities.
Organisational risks are those where an organisation fails to achieve it’s goals or objectives, such as the standard of its service delivery or meeting stakeholder expectations. The consequences can include loss of reputation or staff turnover.
Opportunity risks are those that arise from pursuing opportunities that could benefit your organisation. Sometimes described as “positive risks”, they should be weighed against the potential gains and resources required to pursue them.
Of course, risks don’t always fit into one category. They’re often interconnected, and one problem can quickly create consequences elsewhere in an organisation. An issue such as burnout, for example, could quickly become an organisational risk affecting service delivery and organisational knowledge.
How much risk is too much?
This is where the concepts of risk appetite and risk tolerance come in. Risk tolerance is “the amount of risk an organisation is prepared to bear”, while risk appetite is “the level of risk an organisation is prepared to retain or pursue”.
Every organisation will have a different attitude to risk, depending on its objectives, circumstances and values. The important thing is that decisions about which risks to take – and which to avoid – are deliberate rather than accidental.
For example, an organisation might have a low tolerance for risks involving the safety of staff or clients, but a greater appetite for financial or operational risk when launching a new program with the potential to significantly advance its mission – even if there’s a chance it could fail and affect the organisation’s reputation.
How to manage risk
Best practice for managing risks can be broken down into six steps, which can be repeated regularly.
A risk register is the main tool you can use to document and keep track of this process. It doesn’t need to be complicated – a simple spreadsheet can record your key risks, their likelihood of happening, their potential impact, how you’re managing them and who’s responsible. The NSW Government has created a risk register template for NFPs you can use as a starting point.
1. Establish the context
Start by getting clear on what your organisation is trying to achieve and the environment you’re operating in. Consider your objectives, stakeholders, services and the internal and external factors that could affect them.
This helps you focus on the risks that genuinely matter to your organisation, rather than trying to anticipate every possible thing that could go wrong.
2. Identify the risks
Next, consider what could happen, why it could happen and how it might affect your organisation’s objectives.
Think broadly across different areas of your organisation, from finances and governance to service delivery, technology and your workforce. It’s also worth involving people with different perspectives – for example, staff working directly with clients or delivering services may identify risks that aren’t immediately visible to senior leaders or boards.
Record the risks you identify in your risk register, along with their potential causes and consequences. It’s worth including every risk you can think of – you never know what might turn out to be significant until you start to analyse them.
3. Analyse the risks
For each risk you’ve identified, consider two things:
- How likely it is to happen; and
- How serious the consequences would be if it did.
The consequences might be financial, legal or regulatory, reputational, operational, or related to work health and safety. Some risks may affect more than one area of your organisation, so consider the full range of possible impacts.
Also take into account any controls you already have in place to manage the risk. These might include policies, procedures, staff training, internal audits or other systems designed to reduce either the likelihood or impact of a risk.
Then use a risk matrix to help you assess and compare risks by combining their likelihood and potential consequences. For example, assign a number out of 5 for how likely the risk is, and a number out of 5 for how consequential it would be if it occurred. Then multiply the two numbers to get a “risk score”. (See the examples here.)
Your organisation should develop consequence and likelihood criteria that reflect its size, activities, objectives and operating environment. Smaller organisations may only need simple categories such as low, medium and high, while others may use more detailed scales.
It can also be helpful to assign each risk to a risk owner – usually someone with enough authority to understand the risk, manage it and allocate resources to any actions that may be required to mitigate it.
4. Evaluate the risks
Once you’ve analysed each risk, decide which ones need further action and in what order they should be addressed.
Compare the level of each risk against your organisation’s risk appetite and tolerance – in other words, how much risk the organisation is prepared to accept in pursuit of its objectives. Some risks may be acceptable with existing controls in place and simply need to be monitored. Others may sit above an acceptable level and need to be treated as a priority.
It can be useful to establish simple guidelines for what should happen at different risk levels. For example, a low risk might be monitored, while a high or extreme risk may require immediate action or escalation to senior management or the board.
This is particularly important when resources are limited. Not every risk can receive the same level of attention, so focus first on those most likely to affect your organisation or that could have the most serious consequences.
5. Treat the risks
For risks that require action, decide what you’re going to do about them.
You might reduce the likelihood of the risk occurring, minimise its consequences, avoid the activity creating the risk or accept the risk where the consequences are minor or potential benefits outweigh the consequences.
Possible approaches include:
- avoiding the activity that creates the risk, or changing how the activity is undertaken;
- removing the source or cause of the risk;
- reducing the likelihood of it occurring;
- minimising the consequences if it does occur;
- sharing the risk with another party, such as through insurance, contracts or partnerships; or
- accepting the risk where this is an informed decision and the remaining risk is within the organisation’s tolerance.
The right response will depend on the risk. It could involve introducing a new policy, improving staff training, strengthening a process, changing an activity, taking out insurance or putting safeguards in place. In some cases, a combination of treatments may be most effective.
When choosing between options, consider the cost and resources required, how practical the treatment is, how effectively it is likely to reduce the risk, and whether it could create unintended consequences or new risks.
Record any agreed actions in your risk register, including what will be done, who is responsible, what resources are required and when the action should be completed.
6. Monitor and review
Risk management doesn’t end once you’ve identified your risks and decided what to do about them.
Circumstances change, new risks emerge and existing controls may no longer be effective. Create a weekly, fortnightly or monthly meeting to regularly review your key risks and ask whether anything has changed and whether your current controls are working.
Your risk register should be a living document, updated as your organisation and operating environment change. Significant risks should be discussed as part of regular leadership or board meetings rather than treated as a separate exercise.
Communication and consultation should happen throughout the entire process. Make sure the people closest to particular risks have opportunities to raise concerns and flag new issues as they emerge.
Risk management should never stop
Risk management works best when it’s embedded into everyday organisational practices – connected to governance, planning, culture and decision-making rather than left to the board or to one assigned person.
While boards and senior leaders have an important role in overseeing organisational risk, the people closest to your day-to-day work are often the first to spot when something is changing or a new risk is emerging. Frontline teams and leaders should understand which risks they’re responsible for monitoring and when they need to escalate a concern.
Over time, these conversations can help build a more risk-aware organisation – one that is better at recognising potential problems early and responding before they become crises.
—
Effective risk management is about understanding what could affect your organisation and making the time and space to think about how to mitigate or respond to them. But what that looks like in practice will depend on the different risks your organisation faces. In the articles to come, we’ll take a closer look at some of the key risks facing NFPs and explore practical ways to manage them before they become bigger problems.
—
Not-For-Profit People is an initiative of EthicalJobs.com.au — Australia’s top job-search site for the not-for-profit sector and beyond. 10,000 Australian charities, not-for-profits and social enterprises use EthicalJobs.com.au to find dedicated and passionate staff and volunteers to help them work for a better world. Find out more at EthicalJobs.com.au/advertise
Related Posts


