Agenda item

Strategic Risk Register - June 2024

This report provides the latest update on the Strategic Risk Register 2024/25.

 

Minutes:

The Committee considered a report outlining the updates to the Strategic Risk Register (SRR), in line with the requirements of the Council’s Risk Management Strategy. A copy of the SRR was attached to the report at Appendix 1.  The Risk Register covered the actions completed by the Council for April to June 2024 and the future risk ratings.  The SRR had been reviewed by CMT on 3 September 2024 and ‘Failure to respond appropriately to a major incident that includes a public health hazard’ had been de-escalated. This risk was now recorded as a ‘green, low risk’ for the second consecutive quarter and had been moved to the relevant Directorate Risk Register.

 

The Committee was asked to note there were now six red risk cards, as follows:

 

  • Cyber - Risk of loss from cyber-attack.
  • BFfC - Lack of local special educational needs and disabilities (SEND) placement provision to meet current and future levels of demand.
  • Failure to deliver zero carbon commitments.
  • Unable to deliver a balanced budget because of cost-of-living increases, demand pressures and achieving income targets.
  • Care Act Statutory duties were not met as Residents were waiting for an assessment or access to services in Adult Social Care.
  • Failure to mitigate risks or manage issues, associated with health & safety, appropriately.

 

The report stated there were now seven amber cards with ‘Failure to safeguard vulnerable adults’ being reduced from a ‘red’ to an ‘amber’ rating. This was due to new ‘concerns’ raised, being screened within 48 hours, enabling immediate actions to be taken where necessary and for enquiries to identify risks and consider safety measures.  In addition, ‘Companies Risk – That the council fails to have in place appropriate oversight and scrutiny of its companies’ had moved from ‘amber’ to ‘green’ due to increased awareness of the risks and implementing measures to oversee and scrutinise RBC's companies.

 

The Committee discussed the risk of the Council incurring a loss from a cyber security attack, which had a high inherent and residual risk score due to the nature of the threat.  The Committee felt it would be useful to have an interim report and be given the opportunity to meet the new AD of Digital and ICT Services (final job title to be decided) to explore areas for further investigation and mitigation to guard against cyber attacks.

 

Resolved:      

 

(1)        That the Council’s Strategic Risk Register, as of September 2024, as set out in Appendix 1 to the report, be noted;

 

(2)        That an interim report be submitted to the next meeting on the Cyber Security risk and to provide the Committee with the opportunity to meet the new Assistant Director responsible for this area and start a discussion of mitigating action that could be taken against potential cyber threats to the Council.

 

Supporting documents: