Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Enterprise Risk Management topic
No spam. Unsubscribe anytime.
Committee told universities must submit enterprise risk management reports by Jan. 1
Summary
A committee member said the board adopted an enterprise risk management policy requiring each university to submit a written ERM report by January 1; reports will be distributed to community members for feedback and may vary across campuses.
Get email alerts on the Enterprise Risk Management topic
No spam. Unsubscribe anytime.
A committee speaker reported that the board adopted two policy changes at its September meeting: one establishing minimum IT security standards and another requiring universities to adopt enterprise risk management policies and submit reports to the system.
The speaker said the ERM reporting requirement is new this year and that institutions are expected to submit written reports by January 1 for policy compliance. "That reporting will be new this year and it's due by January 1," the speaker said. The reports should identify campus risks, document risk-management processes and indicate who is involved in mitigation.
The speaker said he had already discussed the new requirement with council business officers and chief counsel offices and had received an initial draft of one campus report. He said the reports will be distributed to community members once collected and invited committee feedback on what items the committee would like to see in future submissions. Because the ERM requirement is new, the speaker warned there will likely be variance across campuses and encouraged committee members to flag items they would prefer be standardized.
The committee did not record additional formal direction at the meeting beyond confirming the reporting timetable and distribution plan.

