• No se han encontrado resultados

The Auditor General Victoria’s performance audit report in March 2003, “Managing Risk Across the Public Sector” aimed to “provide a timely assessment about risk management practices at individual agency and whole-of-government or State-sector levels”.

The report noted the effort to establish a formal and structured focus on risk across all industries and the integration of business risk with other more technical or financial risk assessment that began with first establishment of the Australian and New Zealand Standard, AS/NZS 4360:1999 Risk Management in 1995.

The report found that the Victorian State public sector was increasingly applying a structured risk management approach, though not necessarily that suggested by the Standard.

Key drivers in that State included the Victorian Managed Insurance Authority Act 1996, the Financial Management Act 1994, the Victoria Government’s Management Reform Program and policies

associated with private-public sector service and infrastructure delivery such as Partnerships Victoria. However, the Auditor General found that in over three quarters of public sector organisations,

Boards/CEOs and executive management were directly involved and taking leadership roles regarding risk management. Nevertheless he concluded:

- Although more than 90 percent of the State’s public sector organisations examined and applied risk management processes “in some part of their business and services”, risk management

- Improvement was needed in the ability of organisations to identify their key state-sector risks. While various entities might have an adequate view of their own risk exposures, they did not all understand how their exposures would impact other agencies or the State as a whole.

- The likelihood therefore existed that significant State-sector risks were going undetected and under managed. . There was “a lack of clarity around the responsibility for the escalation of these risks and a lack of a full understanding of State-sector risks within portfolios”. Certain risk types could therefor go undetected at a State-sector level and the risk persisted that insufficient risk mitigation strategies could be implemented from a whole-of-state perspective.

- Most agencies had no existing structure to share risk management best practice across the State-sector

- The practice was still prevalent of reviewing risk strategies and assessment as a separate annual exercise or through periodic Board presentations.

The Auditor General Victoria report advised that risk management should not be an annual or infrequent exercise, but should be imbedded into usual business processes. Is said, “Risk leadership, appetite and culture” should be monitored constantly. And there should be reliable access to demonstrated risk management good practices in other public sector organisations as well as up-to-date information on key success factors or benchmarks.

3.6.2. UK Strategy Unit Study

Britain’s Prime Minister, Tony Blair, recently directed his UK Strategy Unit to conduct an in depth study of modern risk, and how governments might better manage it.

Despite improvements across government, Blair admitted that risk management in the UK had been “found wanting in a number of recent policy failures and crises”. What government needed to know was how to get “the right balance between innovation and change on the one hand, and avoidance of shocks and crises on the other”. This was now “central to the business of good government”.

Blair instructed the Strategy Unit to draw on “good practice and thinking around the world - from across government, the private sector, and other experts and commentators”.

Even prior to Blair’s directive to the Strategy Unit, the UK government had already made changes to its approach to risk. Blair described these as “radical”, and referred in particular to bodies like the UK Food Standards Agency, the Human Genetics Commission and the Monetary Policy Committee.

He said these bodies illustrated the trend to “more open processes, based on evidence”, arguing that such processes were more effective at handling risks and winning public confidence than secrecy. He also pointed to the Civil Contingencies Secretariat whose aim was to improve the way the UK prepares for threats of serious disruption to the nation.

One of the Unit’s early conclusions was that it was not only the accelerating pace of change in science and technology and the greater connectedness of the world that was heightening the risk environment for government. Escalating risk, especially political risk, was also due to “rising public expectations... [and] declining trust in institutions, declining deference, and increased activism around specific risk issues, with messages amplified by the news media.”

The report concluded that, although improved, risk management by the UK government was still inadequate to the burgeoning challenge. It needed to keep constantly under review where risk management should best sit. It should strive for continuous improvement through “good judgement supported by sound processes and systems”.

On the changing nature and severity of risk it referred to “unforeseen events, programmes going wrong, projects going awry” including:

- manufactured risks. That is, those “requiring governments and regulators to make judgements about the balance of benefit and risk across a huge range of technologies – from genetically modified food and drugs, to industrial processes or cloning methods. - direct threats. For example, events of September 11 to the threat of chemical and

biological attack.

- risks resulting from the increasing vulnerability of citizens to distant events. For example, those ranging from economic crises on the other side of the world to attacks on IT networks, diseases carried by air travellers, or the indirect impact of civil wars and famines.

- safety risk issues. For example, those arising from BSE, the Measles, Mumps and Rubella (MMR) vaccine, and such other issues of risk to the public regarding, for example, rail safety, adventure holidays, flooding;

- imposed risks. Those imposed on the public by individuals or businesses that necessitate government regulatory intervention;

- risks of infrastructure disruption from industrial action, protest or failure of transport or IT networks;

- risks to government from the transfer of risk. For example, in capital projects and service delivery to the private sector;

- risks of damage to government’s reputation in the eyes of stakeholders and the public that impact government’s ability to carry out its programs.

The report recommended action in six main areas.

- “systematic, explicit consideration of risk should be firmly embedded in government’s core decision-making processes (covering policy making, planning and delivery)”

- “government should enhance its capacity to identify and handle strategic risks, with improved horizon scanning, resilience building, contingency planning and crisis management”

- “risk handling should be supported by best practice, guidance and skills development – organised around a risk ‘standard”

- “departments and agencies should make earning and maintaining public trust a priority in order to help them advise the public about risks they may face. There should be more openness and transparency, wider engagement of stakeholders and the public, wider availability of choice and more use of “arm’s-length” bodies such as the Food Standards Agency to provide advice on risk decisions. Underpinning principles for handling and communicating on risk to the public should be published for consultation”

- “ministers and senior officials should take a clear lead in handling risk in their

departments – driving forward improvements, making key risk judgements, and setting a culture which supports well judged risk taking and innovation”

Guideline principles were suggested to cover difficult areas. The report noted, for example, that governments normally seek to ensure that those who impose risks on others bear the consequences. But cases arise where responsibility cannot be attributed to any specific individual or agency. The report recommended that governments aim to ensure that responsibility rests with those best placed to manage the risk. It said that this should include protecting minority interests by balancing risks between different groups.

Where the consequences of a risk are too great for any one individual or business to bear, the Unit recommended that government should intervene to provide protection or to pool the risk. Where the market cannot provide sufficient cover and the consequences are unacceptable, it believed the government should step in as insurer of last resort.

Government might also need to intervene where market provision is withdrawn in response to an external shock. A case in point was the inability or unwillingness of airline companies after September 11 to bear the costs of enhanced airport and aircraft security.

When the study was completed the UK Prime Minister introduced the report with a caution against the sort of unwarranted risk avoidance that results in unnecessary loss of promising opportunities:

“All life involves some risk, and any innovation brings risk as well as reward - so the priority must be to manage risks better. We need to do more to anticipate risks, so that there are fewer unnecessary and costly crises, like BSE or failed IT contracts, and to ensure that risk management is an integral part of all delivery plans. But we also need to be sure that innovations are not blocked by red tape and risk aversion, and that there is a proper balance between the responsibilities of government and the responsibilities of the individual”.

(The UK Strategy Unit’s report itself is available on http://www.number10.gov.uk/SU/RISK/risk/home.html).