SHARED GOVERNANCE APPROACH

 

Consistent with traditional risk management frameworks throughout higher education, the shared governance structure for enterprise risk management will comprise two distinct committees, and various resiliency teams. The focus of the teams’ work varies from year to year as different issues arise, but the consistent task is to ensure that the policies, practices, and operations are aligned with the risk appetite and proactively managed. 


The Senior Risk Advisory Council, chaired by the Vice President for ERM, will help lead thinking about the costs and benefits of taking risks, and how the institution manages risks through a strategic planning process and beyond. Risk is inherent in every activity and through ERM, SBU has established a robust risk-aware mindset and appropriate risk appetite by linking institutional governance, risk management, and campus safety.

 

A diagram titled 'Enterprise Risk Management Shared Governance Structure' showing a three-tiered hierarchy connected by bidirectional arrows.  The top tier is the Senior Risk Advisory Council (SRAC). The text states: 'Senior Risk Advisory Council (SRAC) includes members of the senior executive leadership team that meet to review and discuss significant high-level risk and compliance issues that could impact the strategic goals for the Stony Brook enterprise. The mission of SRAC is to provide strategic oversight/guidance to the integrated risk-management framework implementation and the review of significant risks. SRAC will integrate risk management into SBU's business and strategic processes, allowing SBU to take the right risks to create value and respond and mitigate risks that do not.'  The middle tier is the Risk & Compliance Owner Committee (RCOC). The text states: 'Risk & Compliance Owner Committee (RCOC), a team assembled from institution-wide risk and compliance owners representing functional areas to identify, assess and draft recommendations to mitigate potential risks. Through its members, the committee facilitates communication across functional areas and campuses.'  The bottom tier is ERM Resiliency Teams & Unit Specific Risk Owners, represented by ten icons and labels for different functional areas:  Finance & BFPA (piggy bank icon)  Space Planning & FMP (building icon)  Campus Safety, Public Health & EM / Business Cont. (shield icon)  Stony Brook Medicine System (cross icon)  Human Capital (East & West) HR / LR / ER (people and magnifying glass icon)  Information Technology (ISPC, Digital Gov, Cyber & Info Sec) (computer monitor icon)  Governance & Compliance / Policy (gears and people icon)  Academic Affairs & Enrollment (graduation cap icon)  Student Affairs (two people icon)  Research Security & Compliance (magnifying glass icon)  A footer note at the bottom reads: '*AD HOC TEAMS MAY BE CREATED TO ADDRESS SPECIFIC / EMERGING RISKS AND/OR STRATEGIC PRIORITIES'.