[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"detail-sidebar-cat-1-en-105":3,"doc-seo-164435-105":53,"doc-detail-164435-en":126},{"code":4,"msg":5,"data":6},0,"success",[7,14,19,24,29,34,39,44,49],{"id":8,"doc_module":9,"doc_module_name":10,"category_name":11,"show_sort_weight":12,"slug":13},11,1,"Template","Presentations",90,"presentations",{"id":15,"doc_module":9,"doc_module_name":10,"category_name":16,"show_sort_weight":17,"slug":18},12,"Resumes",80,"resumes",{"id":20,"doc_module":9,"doc_module_name":10,"category_name":21,"show_sort_weight":22,"slug":23},14,"Invoices",70,"invoices",{"id":25,"doc_module":9,"doc_module_name":10,"category_name":26,"show_sort_weight":27,"slug":28},15,"Posters",60,"posters",{"id":30,"doc_module":9,"doc_module_name":10,"category_name":31,"show_sort_weight":32,"slug":33},16,"Social Media",50,"social-media",{"id":35,"doc_module":9,"doc_module_name":10,"category_name":36,"show_sort_weight":37,"slug":38},17,"Forms",40,"forms",{"id":40,"doc_module":9,"doc_module_name":10,"category_name":41,"show_sort_weight":42,"slug":43},18,"Letters",30,"letters",{"id":45,"doc_module":9,"doc_module_name":10,"category_name":46,"show_sort_weight":47,"slug":48},21,"Paper Templates",5,"papers-templates",{"id":50,"doc_module":9,"doc_module_name":10,"category_name":51,"show_sort_weight":4,"slug":52},158,"General","general-158",{"code":4,"msg":54,"data":55},"ok",{"site_id":56,"language":57,"slug":58,"title":59,"keywords":60,"description":61,"schema_data":62,"social_meta":119,"head_meta":121,"extra_data":123,"updated_unix":125},105,"en","risk-management-policy","Risk Management Policy","","Risk Management Policy defines how NICE manages uncertainty to protect and advance organizational objectives. It sets out risk management principles, including identifying strategic and operational risks, assessing qualitative or quantitative impact, and categorising risks for evaluation. The policy explains how risk appetite guides escalation, de-escalation, and decision-making, and assigns clear responsibilities for risk owners and leads. It also specifies governance through oversight, annual reporting, audit involvement, and registers for projects, supported by appendices for quantifying and monitoring risks and version control.",{"@graph":63,"@context":118},[64,80,101],{"@type":65,"itemListElement":66},"BreadcrumbList",[67,71,74,77],{"item":68,"name":69,"@type":70,"position":9},"https://docshare.wps.com","Home","ListItem",{"item":72,"name":10,"@type":70,"position":73},"https://docshare.wps.com/template/",2,{"item":75,"name":51,"@type":70,"position":76},"https://docshare.wps.com/template/general/",3,{"item":78,"name":59,"@type":70,"position":79},"https://docshare.wps.com/template/risk-management-policy/164435/",4,{"url":78,"name":59,"@type":81,"image":82,"author":87,"headline":59,"publisher":90,"fileFormat":93,"inLanguage":57,"description":61,"dateModified":94,"datePublished":95,"encodingFormat":93,"isAccessibleForFree":96,"interactionStatistic":97},"DigitalDocument",{"url":83,"@type":84,"width":85,"height":86},"https://docshare.wps.com/thumbnails/risk-management-policy/164435.png","ImageObject",442,249,{"name":88,"@type":89},"Nguyễn Văn Học","Person",{"url":68,"name":91,"@type":92},"DocShare","Organization","application/vnd.openxmlformats-officedocument.wordprocessingml.document","2026-09-22","2026-08-31",true,{"@type":98,"interactionType":99,"userInteractionCount":47},"InteractionCounter",{"@type":100},"ViewAction",{"@type":102,"mainEntity":103},"FAQPage",[104,110,114],{"name":105,"@type":106,"acceptedAnswer":107},"What does the policy mean by “risk” and how does it relate to NICE objectives?","Question",{"text":108,"@type":109},"Risk is described as uncertainty about events and outcomes that may affect NICE, including threats that could harm objectives and failures to realize opportunities. The policy aims to manage that uncertainty so objectives can be achieved with a balanced approach.","Answer",{"name":111,"@type":106,"acceptedAnswer":112},"How are risks identified and assessed under the policy?",{"text":113,"@type":109},"Risk identification covers both strategic risks from strategic ambitions and external threats, and operational risks tied to objectives and delivery. Risk assessment is a qualitative or quantitative evaluation of likelihood and impact, informed by known vulnerabilities and threats.",{"name":115,"@type":106,"acceptedAnswer":116},"Who is responsible for managing risks, and what are the key actions for risk owners?",{"text":117,"@type":109},"Each risk has a single nominated risk owner responsible for coordinating the overall response. This includes setting current and target ratings and tolerance in line with the risk appetite, checking whether management is effective, and deciding whether escalation or de-escalation is needed.","https://schema.org",{"og:url":78,"og:type":120,"og:title":59,"og:site_name":91,"og:description":61},"article",{"robots":122,"canonical":78},"index,follow",{"doc_id":124,"site_id":56},164435,1788153325,{"code":4,"msg":5,"data":127},{"doc_id":124,"user_id":128,"nickname":88,"user_avatar":129,"doc_module":9,"category_id":50,"category_name":51,"doc_title":59,"doc_description":61,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":47,"is_deleted":4,"is_public":9,"is_downloadable":9,"audit_status":9,"page_count":25,"language":135,"language_code":57,"site_id":56,"html_lang":57,"table_of_contents":136,"faqs":137,"seo_title":138,"seo_description":61,"update_tm":125,"read_time":47},1374402739827,"https://ap-avatar.wpscdn.com/avatar/14000c97e7351f1a627?x-image-process=image/resize,m_fixed,w_180,h_180&k=1787885694763230660","Risk Management Policy\nResponsible Officer – Director, Finance\nAuthor – Corporate office\nDate effective from May 2017\nDate last amended May 2024\nReview date September 2026\n\u000fContents\nIntroduction\t\t\t\t\t\t\t\t\t3\nRisk management\t\t\t\t\t\t\t\t3\nRisk identification and assessment\t\t\t\t\t3\nCategorising risk\t\t\t\t\t\t\t\t4\nRisk appetite\t\t\t\t\t\t\t\t\t5\nOversight\t\t\t\t\t\t\t\t\t6\nAnnual report governance statement and the role of audit\t\t7\nReview \t\t\t\t\t\t\t\t\t8\nAppendix A – Quantifying and monitoring risks\t\t\t\t9\nAppendix B – Risk register \t\t\t\t\t\t12\nAppendix C – Version control sheet \t\t\t\t\t13\n\u000fIntroduction\nRisk is the uncertainty surrounding events and their outcomes that may have an impact on NICE. All our activities carry some risk, arising either from potential threats or the non-realisation of opportunities which may harm, prevent, hinder or interfere with the achievement of our objectives.\nRisk is inherent in every activity and this policy sets out how NICE will manage risks to ensure a balanced approach to opportunity and risk. It explains the approach to risk management; defines risk and how it is assessed, evaluated and escalated in the context of NICE’s risk appetite; and documents roles and responsibilities for the management of risks.\nRisk management\nRisk management enables organisations to evaluate and respond to risks and opportunities and seeks to manage the impact of uncertainty by increasing the probability of success and reducing the likelihood of failure.\nEffective risk management involves evaluating the uncertainties and implications within options and managing impacts once choices are made. It provides a process for identifying risks around new, proposed and current business activities, and involves the categorisation and evaluation of each risk and the application of management controls to mitigate the risk.   The evaluation is based on a judgement of the likely impact if no further action is taken, combined with an assessment of the likelihood of the risk re-occurring.\nRisk management should be both an integral part of all organisational activities to support decision-making in achieving objectives and embedded within the culture of the organisation.\nRisk identification\nLike all organisations, NICE faces risks, actual and theoretical, that range from the trivial to the existential. This policy is intended to address both the strategic risks which arise from our strategic ambitions and from the potential external threats to NICE from the developments in our operating environment, and the operational risks to our objectives and plans to manage and deliver our operational activities.\nRisk assessment is a qualitative or quantitative evaluation of the nature and magnitude of risk to our objectives and planned activities. The evaluation is based upon known vulnerabilities and threats and considers the likelihood of the threats being realised and their impact on our work.\nThe Executive Team (ET) will ensure the strategic risks that may affect delivery of NICE’s strategy are identified, assessed and included in the strategic risk register which is reviewed by the Audit and Risk Assurance Committee and Board. ET will continually review the strategic risks to ensure they remain relevant as the operating environment changes and recommend changes to the Audit and Risk Assurance Committee and Board. In identifying the strategic risks ET will also consider risk interdependencies with Department of Health and Social Care (DHSC) Arms-Length Bodies (ALBs), and other key partners. This will include the other ALBs NICE is dependent on to deliver its priorities. Directors will also ensure that risks in their directorate, which are not strategic in nature, are identified, assessed and incorporated in the operational risk register when they have a potential cross-organisational impact.\nDirectors are required to include a risk assessment in ET and Board reports where there is a substantive new development proposed or substantive change to existing activities.\nRisk registers ar","cbCaibLocZ7Fvx6X","https://ap.wps.com/l/cbCaibLocZ7Fvx6X","docx",88388,"English","# Introduction\n# Risk management\n# Risk identification and assessment\n# Categorising risk\n# Risk appetite\n# Oversight\n# Annual report governance statement and the role of audit\n# Review\n# Appendix A – Quantifying and monitoring risks\n# Appendix B – Risk register\n# Appendix C – Version control sheet","[{\"question\":\"What does the policy mean by “risk” and how does it relate to NICE objectives?\",\"answer\":\"Risk is described as uncertainty about events and outcomes that may affect NICE, including threats that could harm objectives and failures to realize opportunities. The policy aims to manage that uncertainty so objectives can be achieved with a balanced approach.\"},{\"question\":\"How are risks identified and assessed under the policy?\",\"answer\":\"Risk identification covers both strategic risks from strategic ambitions and external threats, and operational risks tied to objectives and delivery. Risk assessment is a qualitative or quantitative evaluation of likelihood and impact, informed by known vulnerabilities and threats.\"},{\"question\":\"Who is responsible for managing risks, and what are the key actions for risk owners?\",\"answer\":\"Each risk has a single nominated risk owner responsible for coordinating the overall response. This includes setting current and target ratings and tolerance in line with the risk appetite, checking whether management is effective, and deciding whether escalation or de-escalation is needed.\"}]","Risk Management Policy | DOCX"]