Attachment C - Project Risk Register.xlsx

XLSX spreadsheet 146 KB Posted

Attached to
National Dialysis Services Contract (NDSC) Federal contract opportunity
Solicitation number
36C10G25R0022
Issued by
Department of Veterans Affairs Headquarters

About this file

This file is a comprehensive risk management template for the Veterans Health Administration (VHA) Enterprise Risk Management (ERM) program. The document provides detailed guidance for identifying, scoring, and managing organizational risks across multiple domains including operational, patient safety, human capital, technology, financial/fraud, legal/regulatory, strategic, and hazard categories.

The template includes sophisticated risk scoring scales that assess likelihood, impact, velocity, complexity, adaptability, reputation, and persistence of risks. A specific example risk is included related to recruiting and onboarding, which highlights potential inefficiencies in personnel placement and skill monitoring. The document offers structured tools like a Risk Register, Control Register, Monitor Log, and Risk Tolerance Template to help VHA leadership systematically track, evaluate, and respond to potential organizational risks. The template is designed to enable informed decision-making by providing a standardized framework for risk assessment and mitigation across the organization.

View the file

Other files for this federal contract opportunity

Other files attached to National Dialysis Services Contract (NDSC), newest first.
File Type Posted
36C10G25R0022 0005.pdf PDF
Preconference QA_0005.pdf PDF
36C10G25R0022 0004.pdf PDF
Preconference QA_0004.pdf PDF
Attachment 4 - Non-VA Dialysis Care Data for FY24.pdf PDF
Attachment B - Facilities Status Report_0004.xlsx XLSX spreadsheet
Postconference QA_0004.pdf PDF
36C10G25R0022_amended_0004.pdf PDF
Attachment 1 - Facility List_0004.xlsx XLSX spreadsheet
36C10G25R0022 0003.pdf PDF
NDSC Preproposal Conference-Final.pdf PDF
36C10G25R0022 0002.pdf PDF
36C10G25R0022 0001.pdf PDF
Attachment 3 - Past Performance Questionnaire.docx DOCX document
Attachment F - Contract Discrepancy Report.pdf PDF
36C10G25R0022.docx DOCX document
Attachment D - Progress Report.pdf PDF
Attachment 1 - Facility List.xlsx XLSX spreadsheet
Attachment B - Facilities Status Report.xlsx XLSX spreadsheet
Attachment A - Quality Assurance Surveillance Plan.pdf PDF
Attachment 2 - Attestation Statement.docx DOCX document
Attachment E - Contractor Training Report.pdf PDF
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Instructions DRAFT VHA ERM Templates

Introduction
The purpose of this workbook is to provide an all inclusive location to record risk and control information. The following sheets will walk you through all of the information that you are responsible for identifying, analyzing, reporting, and recording risk and control information so that informed and actionable decisions can be made.
Risk Scoring Scales
The risk scoring scales support deciding how to assign a score for the likelihood a risk will occur and its potential impact to the organization. Additional scoring scales to help users prioritize risks for response are included as well.
Risk Tolerance Template
The Risk Tolerance Template helps define a performance range for a metric that aligns with the organization's appetite for risk. When actual performance is above/below tolerance levels, responses are needed to bring the organization's performance back to tolerance and remain in alignment with risk appetite. VHA's most recent risk appetite levels have been pre-populated but are subject to change based on governance outcomes.
Risk Register
A risk register is a list of the organization's risks, risk scores and other analysis elements, responsible individuals, and the organization's response to each risk. Each column has specific instructions along the top to follow.
Review the Heat Map
This map automatically plots the risks on the register based their associated risk scores and risk resourcing scores.
Control Register
The control register is a list of the control activities implemented through policies and procedures that support achieving objectives. Control activities must be monitored to ensure they are designed and operating effectively. Each column has specific instructions along the top to follow.
Monitor Log
The monitor log allows you to document all monitoring results for one control in a single location.

Risk Scoring Scales

DRAFT VHA ERM Risk Scoring Scales

Risk Appetite Scoring Scale (Used on "Risk Appetite & Tolerance Input" Tab)
Approach1. Very Low2. Low3. Medium4. High5. Very High
Risk Taking vs. RewardAgency is vigilant and accepts as little risk as possibleAgency takes a cautious approach to risk takingAgency takes a balanced approach to risk takingAgency is willing to take greater than normal risksAgency believes aggressive risk taking is justified
Impact on ObjectivesNot willing to accept any negative impact to pursue strategic goal(s) or objective(s)Only willing to accept a small negative impact to pursue strategic goal(s) or objective(s)Equal considerations given to potential negative impact and strategic goal(s) or objective(s) achievementWilling to accept some negative impact to pursue strategic goal(s) or objective(s)Willing to accept a large negative impact to pursue strategic goal(s) or objective(s)
Related Risk Score1-56-1011-1516-2021-25
Risk Assessment Scoring Scale (Used on the "Risk Register" Tab)
Likelihood1. Remote2. Unlikely3. Possible4. Probable5. Very Likely
<10% chance of occurrence10% up to 35% chance of occurrence35% up to 65% chance of occurrence65% up to 90% chance of occurrence>90% chance of occurrence
Impact (by Category)1. Minor Impact2. Moderate Impact3. Significant Impact4. Major Impact5. Extreme Impact
OperationalRisks resulting from inadequate or failed internal processes, people, or systems that affect business operations. Included are risks related to: adverse event management, credentialing and staffing, documentation, chain of command, and deviation from practice.
Localized operational inefficiencies (e.g. access delays, procedural breakdown) with no impact to the tactical objectives or financial position of the larger organization.Localized operational inefficiencies (e.g. access delays, procedural breakdown) impacting immediate up/downstream operations but no impact to ability to achieve tactical objectives or the financial position of the larger organization.Significant operational inefficiencies broadly impacting operations and impeding the larger organization's ability to achieve tactical objectives and/or the organization's financial position is impacted.Major operational failures being realized with the larger organization's ability to achieve one or more tactical objectives threatened and/or the organization's financial position significantly impacted.Catastrophic operational failure leading to the larger organization's inability to achieve one or more tactical objectives and/or significantly impacting the organization's financial position.
Patient SafetyRisks associated with the delivery of care to Veterans, beneficiaries, and other healthcare customers. Clinical risks include: failure to follow evidence based practice, medication errors, hospital acquired conditions (HAC), serious safety events (SSE), and others.
Potential for a minor health incident not related to the natural course of the patient's illness or underlying condition leading to increased length of stay and/or increased level of care.Potential for a moderate health incident not related to the natural course of the patient's illness or underlying condition leading to increased length of stay and/or increased level of care.Potential for a significant health incident not related to the natural course of the patient's illness or underlying condition leading to increased length of stay and/or increased level of care.Potential for a critical health incident not related to the natural course of the patient's illness or underlying condition leading to increased length of stay and/or increased level of care requiring new treatment plans that would have been otherwise unnecessary.Potential for a catastrophic incident not related to the natural course of the patient's illness or underlying condition, to include permanent shift in quality of life, disability, and/or death.
Human CapitalThis domain refers to the organization’s workforce. Included are risks associated with employee selection, retention, training and development, turnover, staffing, absenteeism, on-the-job work-related injuries (workers’ compensation), work schedules and fatigue, productivity and compensation.
Minor impact to staffing levels or ability to recruit, train, retain, and maintain competence in key positions. Localized operational impact being realized but not impeding operations of the larger organization.Moderate impact to staffing levels and/or ability to recruit, train, retain, and maintain competence in key positions. Localized operational impact is affecting other aspects of the organization's operations but not impeding operations of the larger organization.Significant impact to staffing levels and/or ability to recruit, train, retain, and maintain competence in key positions. Operational impact not isolated to small segment of the organization and is beginning to impede larger organizational operations.Major impact to staffing levels and/or ability to recruit, train, retain, and maintain competence in key positions. Widespread impact impeding larger organizational operations.Major operational failure realized and directly attributed to inability to maintain staffing levels and/or inability to recruit, train, retrain, and maintain competence in key positions.
TechnologyRisks within this domain are associated with the role of information technology in the organization's operations. This domain covers machines, hardware, equipment, devices and tools, but can also include software, techniques, data integrity, systems and methods of organization.
Localized impact to operational efficiencies but larger system integrity remains in tact. Localized data integrity issues that can be resolved by manual correction. No impact to organizational reporting requirements or data warehouses.Localized operational inefficiencies impacting immediate up/downstream operations but larger system integrity remains in tact. Moderate data integrity issues that can be resolved by manual correction but require workaround fixes. Minor impact to organizational reporting requirements or corporate data warehouses.Regional operational inefficiencies impacting operations. Significant data integrity issues that require system restoration action, manual adjustment to correct. Moderate impact to organizational reporting requirements but no impact to corporate data warehouses, requiring manual workarounds be implemented to minimize operational impact but larger system integrity remains in tact.National operational inefficiencies impacting operations. Manual workarounds implemented to reduce operational impact but inefficiencies remain and create control vulnerabilities and/or put system integrity at risk. Significant data integrity issues that requires system restoration action, significant manual adjustment to correct. Corrected reports must be issued, corporate data warehouses involved to correct deficiency.National operational inefficiencies impacting operations. Manual workarounds cannot overcome operational impact, control vulnerabilities being realized and/or system integrity compromised. Major data integrity issues that requires system restoration action, significant manual adjustment to correct. Corrected reports must be issued, corporate data warehouses involved to correct deficiency.
Financial/FraudRisks that affect the financial sustainability of the organization make up this domain. Risks might include: costs associated with malpractice, litigation, insurance, conflicts of interest, appropriations constraints, growth in programs and facilities, capital equipment, FWA, and billing and collection.
Minor impact to organization's financial position but does not disrupt operations or result in financial reporting misstatements. Impact represents less than 1% of total budgetary resources.Moderate impact to organization's financial position with small operational disruption but does not result in financial reporting misstatements. Impact represents 1-2% of total budgetary resources.Significant impact to organization's financial position with moderate operational disruption. Financial reporting may be impacted but is identified, corrected, and does not warrant change in rating. Impact represents 3-4% of total budgetary resources.Major impact to organization's financial position with major operational disruptions realized. Financial reporting may be impacted but is identified, corrected, and may warrant change in rating. Parent organization impacted but rating not affected. Impact represents 5% of total budgetary resources.Catastrophic impact to organization's financial position with resulting operational failure. Financial reporting is impacted and affects parent organization's rating. Impact represents more than 5% of total budgetary resources.
Legal/RegulatoryRisk within this domain incorporates the failure to identify, manage and monitor legal, regulatory, and statutory mandates on a local, state and federal level. Such risks are generally associated with fraud and abuse, licensure, accreditation, product liability, management liability, as well as issues related to intellectual property.
Represents violation of VISN/VAMC policy but does not violate VHA directive, program office policy, or federal regulation/law.Represents violation of multiple VISN/VAMC policies but does not violate VHA directive, program office policy, or federal regulation/law.Represents violation of program office policy but does not violate formal VHA directive or federal regulation/law.Represents violation of formal VHA directive as well as lower level policies and procedures but does not violate federal regulation/law.Represents violation of federal regulation/law.
StrategicRisks associated with the focus and direction of the organization. Risks within the strategic domain are associated with industry brand and positioning, reputation, competition, failure to adapt to changing times, academic affiliate relationships, research initiatives, and media relations are other areas generally considered as potential strategic risks.
Minor impact to organization's ability to achieve strategic objectives.Moderate impact to organization's ability to achieve strategic objectives.Significant impact to organization's ability to achieve strategic objectives and impacts parent organization's ability to achieve strategic objectives.Major impact to organization's ability to achieve strategic objectives and impacts parent organization's ability to achieve strategic objectives.Catastrophic impact to organization's ability to achieve strategic objectives and impacts parent organization's ability to achieve strategic objectives.
HazardThis domain covers assets and their value as related to natural exposure and business interruption. Specific risks can also include risk related to: facility management, plant age, parking (lighting, location, and security), valuables, construction/renovation, earthquakes, windstorms, tornadoes, floods, fires.
Minor impact to business functions and agency goals attributable to natural disasters or factors at the physical facility or building.Moderate impact to business functions and agency goals attributable to natural disasters or factors at the physical facility or building.Significant impact to business functions and agency goals attributable to natural disasters or factors at the physical facility or building.Major impact to business functions and agency goals attributable to natural disasters or factors at the physical facility or building.Catastrophic impact to business functions and agency goals attributable to natural disasters or factors at the physical facility or building.
Prioritization (by Category)12345
VelocityHow quickly the risk's impact will be felt by the organization.
Several years before risk impacts organization1-2 years before risk impacts organization6-12 months before risk impacts organization3-6 months before risk impacts organizationLess than 3 months before risk impacts organization
ComplexityThe scope and nature of a risk's impact on the organization's success.
No dependencies, no system modifications required, minor training or procedural impact1-2 dependencies, no system modifications required, minor training or procedural impact3+ dependencies, 1-2 system modifications required, moderate training or procedural impact3+ dependencies, 3+ system modifications, system interfaces required, major training or procedural impactStand-down required to assess complexity, major system modifications required, new system interfaces required, major training and procedural impact
AdaptabilityThe ease at which the organization can adapt to and respond to a risk.
Organization requires less than a month to adapt to riskOrganization requires 1-2 months to adapt to riskOrganization requires 3-5 months to adapt to riskOrganization requires 6 months-year to adapt to riskOrganization requires greater than one year to adapt to risk
ReputationHow a risk impacts stakeholder perception of the organization.
Isolated VAMC/VISN experiencing adverse reputational impact among external stakeholder group, no media coverage, no national dialogue, minor level of stakeholder disengagement.Isolated number of VISNs, VAMCs and/or VHA program offices experiencing adverse reputational impact among external stakeholder groups, increased regional level conversations, local media coverage only, moderate level of stakeholder disengagement.Multiple VISNs, VAMCs and/or VHA program offices experiencing adverse reputational impact among external stakeholder groups, increased national level conversations with regional media coverage, major levels of stakeholder disengagement.Major reputational impact among external stakeholder groups, active national conversations with national media coverage, loss of stakeholder engagement and support.Major reputational impact among external stakeholder groups, national media coverage with active congressional dialogue, loss of stakeholder engagement and support.
PersistenceHow long a risk impacts the organization (time).
Less than a month that the risk will impact the organization1-2 months impact that the risk will impact the organization3-5 months impact that the risk will impact the organization6 months-year impact that the risk will impact the organizationGreater than one year impact that the risk will impact the organization
RecoveryHow long it takes the organization to return to normal after the risk's effect are realized.
ResourcingThe type and amount of resources required to address the risk.
Minor impact to funding or FTEE levels that can be accounted for by strategically reallocating existing resources.Minor impact to funding or FTEE levels that cannot be accounted for by strategically reallocating existing resources. One-time increase in medical services funds needed to address resource constraints. No IT funds required.Moderate impact to funding or FTEE levels that cannot be accounted for by strategically reallocating existing resources. Multiyear medical services funds needed to address resource constraints. Existing IT appropriations available to address technology requirements.Major impact to funding or FTEE levels that cannot be accounted for by strategically reallocating existing resources. Multiyear medical services funds needed to address resource constraints. One-time increase in IT funds required to address technology requirements.Major impact to funding or FTEE levels that cannot be accounted for by strategically reallocating existing resources. Multiyear medical services funds needed to address resource constraints. New multi-year IT funds required to address technology requirements.

Risk Register

DRAFT Risk Register

Instructions: Each column has specific instructions along the top the user should follow. The Risk Score (Column L) will autopopulate. All other cells should be filled in.
Risk IDRisk NameRisk StatementRisk Detail/ContextRisk DriversRisk ManagerCategoryLikelihood ScoreImpact ScoreRisk ScoreRisk TypeResponse TypeInternal ControlResponse ActionRisk Velocity ScoreRisk Complexity ScoreRisk Adaptability ScoreRisk Reputational ScoreRisk Persistence ScoreRisk Recovery ScoreRisk Resourcing ScoreStrategic ObjectiveSpecial MissionCollaborating OfficesAssociated PoliciesBarriers to Mitigate
Each risk will be given a Risk IDA descriptive name that identifies the riskAn if/then statement that describes the impact of the risk if realized.A more detailed description of the risk that includes context from interviews.The root causes of the risk that contribute to its impact and/or likelihood. This can include resource deficits, political environment, public perception, and more.The stakeholder who is responsible for managing the risk.The categories of impact associated with the risk. More than one category can be assigned, however use the category with the lowest risk appetite to determine alignment with the organization's risk appetite.The probability that a given event will occur. Factors that may influence probability include time, operational volume, or seasonal presence of risk drivers.The effect of a risk on the organization. Consider all categories of impact and assign one overall score.The amount of risk that exists.Select "Residual" if the organization considered any previously implemented activities to address the risk while assigning a likelihood or impact score (column J or K). Otherwise select "Inherent", which means the risk score reflects the full risk likelihood and impact to the organization.Select which response type you are choosing for this risk. If you have already implemented activities and do not intend to implement more, select "Accept".Will any processes need to be implemented or modified to address this risk?Include a detailed response plan with explicit actions. If the response is to "Accept the Risk" provide rationale for that response plan, to include any already implemented activities.How quickly will the risk impact the organization?How complicated is this risk to address?How long will it take for the organization to adapt to the risk?How much will this risk affect the organization's reputation with stakeholders?How long will the actual risk impact the organization?How long will it take for the organizationWhat is the amount resources in terms of funding or FTEE required to address this risk?Which strategic objective is this risk associated to?Does this risk align to a mission that is separate from strategic objectives but has been identified as a priority through other means (i.e. GAO, OIG, etc)?Offices and stakeholders that are not the risk owner but require input and coordination to address the risk.Policies related to the risk that may inform why risk emerged, mitigation plan requirements, or monitoring requirements.Challenges and obstacles that could inhibit the implementation and success of mitigation plans.
P0001Recruiting & OnboardingIf Program does not standardize and enhance their recruitment and onboarding process, then they are at risk of not having necessary personnel or skillsets to serve Veterans and Beneficiaries.The absence of a standardized recruiting and onboarding process at Program leads to delays in placing new staff into their new role. This delay may cause inefficiencies and loss of productivity. Furthermore, inability to effectively monitor the skillsets of new and current employees increases the likelihood of preliminary knowledge gaps going unnoticed, resulting in a higher risk of errors, accidents, and other unfavorable outcomes. This risk is exacerbated by the human resources department being understaffed and struggling to keep up with hiring demands for vacant positions, which may further compromise the quality of new hires. A standardized onboarding process and effective monitoring of skillsets could mitigate these risks.Absent standardized recruiting and onboarding processSpecific Person from Office XHuman Capital236InherentReduceNoDevelop a candidate pipeline for internal promotion - Hire more staff at entry-level positions, set up organization structure to support succession planning, implement continuous education programs to enable employees develop and improve their skill sets.3424341Hire Faster and More CompetitivelyN/AHuman Resource Dept.N/AHuman resource department understaffed

Monitor Log

DRAFT Monitor Log

Instructions: Document outcomes of your monitoring activities over time for one control. Each column has specific instructions along the top the user should follow. Column H will autopopulate.
Control Description
A high-level description of the process being implemented to mitigate a risk. Description should clearly describe who is expected to take what actions, when the actions are to be taken, where the actions will be documented, how the process should occur, and how frequently it should occur.
Monitor Description
A high-level description of management's plan to evaluate if the process is implemented and functioning as intended. Description should clearly describe who is expected to take what actions, when the actions are to be taken, where the actions will be documented, how the monitor should be performed and outcomes determined, and how frequently the monitor should occur.
Monitor DateMonitorSample SizePassing SamplesFailing SamplesOutcomePerformance ExpectationDeterminationCorrective Action
Date the monitor was performedName of the individual that completed the monitoring activity.Number of cases reviewedNumber of samples that show the control was implemented and functioning as intendedNumber of samples that did not show the control was implemented and functioning as intendedPercentage of sample that passedWhat are the desired results for the monitor?Control is "effective" if the outcome meets or exceeds expectations or "deficient" if the results do not meet expectations.Describe the corrective action taken to address the findings if the outcomes do not meet expectations. Retain documentation to support any actions taken.
1/1/23Employee One4740785%90%DeficientCorrected the samples that were wrong, identified that SOP being used by staff was incorrect. Confirmed all staff have correct SOP and understand expectations.

Control Register

DRAFT Control Register

Instructions: Populate each column for any risk on your Risk Register that has "Yes" for the response in Column O. Each column has specific instructions along the top the user should follow.
Risk IDRisk NameRisk StatementControl ObjectiveControl DescriptionControl OwnerControl DocumentationMonitoring DescriptionMonitor OwnerMonitoring DocumentationControl Status
Each risk will be given a Risk IDA descriptive name that identifies the riskAn if/then statement that describes the impact of the risk if realized.A high-level description of the goal you are trying to achieve by implementing this process. This is typically something associated with the risk you are attempting to address.A high-level description of the process being implemented to mitigate a risk. Description should clearly describe who is expected to take what actions, when the actions are to be taken, where the actions will be documented, how the process should occur, and how frequently it should occur.Name of the individual responsible for ensuring the process occurs as designedLink to supporting procedural documentationA high-level description of management's plan to evaluate if the process is implemented and functioning as intended. Description should clearly describe who is expected to take what actions, when the actions are to be taken, where the actions will be documented, how the monitor should be performed and outcomes determined, and how frequently the monitor should occur.Name of the individual responsible for completing the monitoring activities.Link to documents that show the monitoring resultsMark the control "effective" if the monitor shows the control is implemented and functioning as intended. Mark the control "deficient" if the monitor shows the control is not implemented and functioning as intended. Leave entries marked "deficient" until corrective action is taken and validated to be effective.

Risk Tolerance Template

DRAFT Risk Tolerance Template

Instructions: For this step, you will be using the Risk Tolerance Example tab as a guide while you fill out the Risk Tolerance Template tab. The purpose of these tabs is to track risk tolerance. At a minimum, the risk response requires re-evaluation when tolerance is outside the upper and lower levels (Columns I and J) as that could indicate the strategy is not working or additional strategies are needed.
Risk AppetiteRisk ToleranceResponse Action
Risk DomainRisk AppetiteObjectiveRiskTolerance MetricRisk ToleranceL/LU/LA/PResponse Action
OperationalMedium[Objective][Risk][Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
Patient SafetyVery Low[Objective][Risk][Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
Human CapitalLow[Objective][Risk][Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
TechnologyLow[Objective][Risk][Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
Financial/FraudVery Low[Objective][Risk][Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
Legal/RegulatoryVery Low[Objective][Risk][Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
StrategicMedium[Objective][Risk][Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
HazardMedium[Objective][Risk][Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]
[Tolerance Metric][Risk Tolerance][Lower Limit][Upper Limit][Actual Performance[Below/Within/Above Tolerance]
[Response Action]

Risk Tolerance Example EXAMPLE Risk Tolerance Template

Instructions: There are no actions required for this tab. This is an example.
Risk AppetiteRisk ToleranceActual Performance (A/P)
Risk TypeRisk AppetiteObjectiveTop RiskTolerance MetricRisk ToleranceL/LU/LA/PResponse Action
Human CapitalLowHire Faster and More CompetitivelyIf positions are gapped for a prolonged period of time, then the quality of care patients receive may begin to degrade.New hires will receive any necessary job-related training within 60 calendar days of their start date.10 days50 days70 days90 daysAbove Tolerance
Reduce the level of risk; seek additional response.
The percentage of new hires that are at entry-level positions should be approximately 90%.5%85%95%87%Within Tolerance
Accept the level of risk and monitor.
Employees should be reqiured to complete, on average, 25 hours of continuous education programs per year.10 hours15 hours35 hours32 hoursWithin Tolerance
Accept the level of risk and monitor.
Employees should be required to pursue 3 growth opportunities per year.1 opportunities2 opportunities4 opportunities1 opportunityBelow Tolerance
Reduce the level of risk; seek additional response.

Risk Heat Map

DRAFT Risk Heat Map

Instructions: This heat map is a tool to help facilitate the prioritization process and plots risks based on their 1) Likelihood Scores, 2) Impact Scores, and 3) Resourcing Scores. The size of the bubble indicates the level of resourcing required to mitigate the risk. This does not take the place of leadership discussions and management inputs into final risk prioritization.

Risk IDRisk NameLikelihoodImpactResourcing
P0001Recruiting & Onboarding231
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000
0.000000

Risk Heat Map

Risks [CELLRANGE]

[CELLRANGE]

[CELLRANGE]

[CELLRANGE]

[CELLRANGE]

2 0 0 0 0 3 0 0 0 0 1 0 0 0 0 P0001 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 0.00 Likelihood Score

Impact Score image1.png

File details come from the government source that posted it. Updated .