Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Enterprise Risk Management topic
No spam. Unsubscribe anytime.
Consultants, trustees test enterprise risk tools in Minnesota State study session
Summary
Baker Tilly led a board study session on enterprise risk management using a live collaboration tool. Trustees and consultants discussed board oversight responsibilities, five risk components, and areas for improvement, with trustees identifying strategic oversight as the greatest need.
Get email alerts on the Enterprise Risk Management topic
No spam. Unsubscribe anytime.
Audrey Lindquist of Baker Tilly and John Regula, Baker Tilly managing director, led a study session on enterprise risk management for the Minnesota State Colleges and Universities System board, demonstrating a live collaboration tool and asking trustees to assess the system’s readiness across five oversight areas.
The session, presented as a facilitated workshop rather than an action item, aimed to clarify “the board’s responsibility for risk oversight,” show how an enterprise risk framework supports that role and surface opportunities to strengthen board reporting and monitoring, the presenters said.
Lindquist told trustees that a board’s “foremost duty is to safeguard and advance the institution’s mission, reputation and resources,” and said that duty requires balancing protection with taking strategic risks to advance the system. Regula said enterprise risk management should not be “just a threat detector” but also “an opportunity identifier.”
Baker Tilly organized the discussion around five oversight components: risk governance, strategic oversight, policy and compliance, monitoring and reporting, and crisis management. Trustees used a QR-linked tool Baker Tilly calls a risk-synergy collaboration platform to vote on the program’s maturity. The aggregated results shown during the session indicated trustees saw strategic oversight as the area most in need of improvement and policy/compliance as the strongest area.
Trustees asked how enterprise risk work differs from internal audit and whether the system has a single compliance officer. Lindquist and system staff said audit is an assurance component that validates whether mitigation plans are working, and described compliance as a distributed function: academic accreditation sits in academic and student affairs, legal compliance in general counsel and other areas “depending on which particular compliance,” a staff member said.
Trustees pressed on practical topics such as how the board can set risk appetite to prevent “people going rogue,” how to scale risk reporting for a multi-campus system, and how to balance public transparency with the need for candid discussions about sensitive risks. Regula outlined a “top-down and bottom-up” approach in which trustees set strategic objectives and campuses supply tactical execution and warning indicators.
The presenters shared recommended practices—establishing a risk framework, performing regular risk assessments, integrating risk into decision-making, improving communications and dashboards, training trustees, leveraging technology, considering a dedicated risk committee and engaging external experts—and asked trustees to rank those priorities. Trustees ranked establishing a risk framework, integrating risk into decision-making and leveraging technology as the highest priorities.
Trustees and presenters agreed on next steps: pursue clearer, data-driven reporting with key risk indicators that show whether mitigation measures are working; consider targeted closed-session reviews for high-sensitivity topics; and follow up with more detailed dashboard examples and training. The session closed with a planned Q&A window and an acknowledgement that the board would reconvene later to evaluate specific reporting formats and any charter or policy language to anchor board expectations.

