# Risk management with adaptive policy delivery

Creating the conditions for evidence-based policy, even when urgent
Karen Joyce, New Zealand Government
I mentored a group of young policy professionals at the Ministry of
Social Development. I promised them, despite the craziness of a high priority and Prime Minister-led busy work programme, Wednesday at
9.00am to 10.00am were non-negotiable training/learning time. It is always possible to set aside time if something is seen as valuable and one looks across a diary for “less busy” times. Policy shops too often get in cycles of urgency which they feel they can’t step out of. In this constant urgency, brainstorming advice becomes the norm and there is little to no evidence basis when that happens, so it should not be the norm. It is useful and important to consider and implement the small and manageable things a busy policy shop can do to help everyone get out of the cycle of craziness and towards doing good evidence based policy.
Risk management with adaptive policy delivery
It is important to see risk management as a continuous and dynamic process, rather than as a once off or periodic exercise. Dynamic risk management goes hand in hand with continual evaluation, as it means keeping a finger on the pulse of new and unexpected risks, and proactively mitigating them as they emerge. You need to ensure you have enough decision making authority and flexibility in your operating model to not just identify and monitor risks, but to proactively mitigate them as circumstances change. You should not require a new funding proposal or policy change to mitigate emergent risks, though it is important to keep the relevant authorities informed and to engage them where new authorities are required. This means being clear on who has decision making authority for your policy program and relevant interventions, and to make sure you have a clear protocol for escalation and access if and when required.

The following high level guides provide the basics to risk management for your policy agenda, but you should also invite your departmental risk experts and domain specific risk professionals into the process. These basics are complemented by the same mindset, skills and tools used for continual evaluation, including data-driven and continuous risk monitoring, modelling, escalation and a combination of real time tools and risk management as a continuous practice.
Our thanks to Donald S. Williams and Pierre Skorich for their contributions below on risk.
Risk Policy and risk—the art of making the complex simple
Author: Donald S.  Williams.
A policy is raised to achieve outcomes. Risk is the “effect of uncertainty on objectives” (ISO 31000). Risk management of the policy is required during both the Policy Preparation Phase and the Policy Navigation Phase.
Risk must be managed at two levels:
1. The whole of policy level: assessing and managing risk for the overarching policy objectives (usually at a program or portfolio level).
2. Individual interventions level: assessing and managing risk for all individual policy interventions (often a project level).
Consideration must be given to what is uncertain:
- what could change
- why it might change
- how the change could be recognised particularly in the early stages
- the effect on the intended outcomes
- whether the effect is beneficial, detrimental or potentially both.

The risk is managed by deciding if it is to be encouraged, for beneficial outcomes, or minimised for detrimental outcomes. What factors, external and internal to the organisation, can be influenced to:
- change the likelihood of the risk occurring
- maximising or minimising the consequences should the risk be realised
- avoiding the risk by not undertaking the action.
The key to the process is understanding the context in which the policy, and hence risks, exist:
- not just the context visible to the particular manager but the larger organisational and societal context
- seriously considering the effects and implications of the outcomes of policy in the broad context
- objectively determining the balance between beneficial and detrimental outcomes
- recognising risk analysis is consideration of “what if” and is not dealing in certainties
- being willing to make decisions, or recommendations to the decision makers, based on the risk assessment.
Risk management techniques, tools and skills are available from many sources. It is critical that any risk management process be firmly focused on the real outcomes that will be affected by the uncertainty.

Dynamic risk management
Author: Pierre Skorich
What is risk?
All organisations, across every facet of the public, private and not-for- profit sectors, have finite resources to manage their operations and deliver value. Such constraints mean that it is critical that resources be invested in the things that really matter, while foregoing those that create less or no value. This is acutely the case for public servants due to the source of resources flowing from tax revenue.
The International Standards Organisation in ISO31000 defines risk as
“the effect of uncertainty on objectives”. We make good decisions about allocating our resource effort by considering the relative risks and applying resources to the issues which are going to impact most on those objectives.
At a strategic level, government always has the same objectives: to protect and preserve a productive economy, promote social cohesion, safeguard healthy people and a healthy environment. “Policy problems” can then be seen as “uncertainties” that may impact on those objectives.

Dynamic risk assessment recognises the fact that our world exists in a constant state of flux meaning that risk assessment cannot be a set and forget exercise, it needs to be continuous to create policy and resource allocation which is adaptive to change.
There are several levels of risk assessment which public sector organisations need to be adept at to create and administer good policy.
The example below considers risk in the biosecurity context.

The first is strategic risk, which considers and assesses the macro-level risks which are of national significance. These risks are driven by major changes happening around the globe which can be described as PESTELO:
Political, Economic, Scientific, Technological, Environmental, Legal and
Organisational1.
These major factors impact on whether our policy frameworks remain fit for purpose in our changing world and equally whether our administration of those policies through regulation and programmes is maintaining pace with emerging pressures.
The CSIRO published a report: Our Future World: Global megatrends impacting the way we live over coming decades (Hajkowicz and Naughtin).
These “megatrends” are trajectories of change that typically unfold over years or decades and have the potential for substantial and transformative impact.
1.PESTELO framework originally developed by Harvard professor Francis Aguilar in 1967.
Image from Global megatrends, the 2022 revision, CSIRO

Megatrends can provide a source of insight on how strategic risks will change in response to significant trajectories of change.
Operational risk describes the specific instantiation of a strategic risk.
In the context of government interventions which are often regulatory in nature, we often see this present itself as “compliance risk”, the risk that regulated entities will not comply with the obligations set on them to manage a policy problem. These compliance risks need to be assessed dynamically, as entities change and shift their behaviours or try to evade controls. Importantly, the strategic drivers will also be responsible for changes in compliance behaviours, for example in response to changing economic conditions.
As we continuously undertake our risk assessments, it is therefore important to keep in mind the relationships between the strategic and operational risk drivers.
Tactical risk describes the risk that presents itself on a day-to-day basis, affecting short term goals and activities. This type of risk is managed at the coal-face by public servants.
Finally, enterprise risk describes the range of risks that affect the performance of the organisation itself, for example quality risk, workplace health and safety risk, integrity risk. These risks impact on the ability of organisations to deliver their business.
Risk and control
Assessing risk is not enough. Identified risks need to be mitigated and we do this through “controls”. There are three broad typologies of controls to manage risks:
- Preventative controls: which stop a risk event from occurring
- Detective controls: which detect either a risk event which is going to occur or one that has occurred
- Responsive controls: which respond to a risk event once it has occurred, generally to mitigate the consequences of the risk.

Controls have to be implemented to genuinely be a control. An internal policy or document is not a real control as it does not have the effect of mitigating risk until it has been implemented and is followed. It is useful therefore to see controls as synonymous with organisational
“capabilities”–the functions that make the organisation able to do things. For example, Education is a capability that may prevent compliance risk, by informing a regulated entity about what it needs to do to comply with a legislative framework.
Capabilities are made up of a set of fundamental inputs, which can be described in different ways, but most easily as People, Process,
Information and Technology. These inputs are things that create cost and this brings us back to the relationship between dynamic risk and allocation of resources.
When we are investing in these risk controls we need to consider two things:
- Are we (still) investing in the right things?–that is, are they effective?
- Are we still investing in things right?–that is, are they efficient and cost effective?
The final element of our dynamic risk model is the controls on quality and performance that we put within the organisation. These controls could justify a chapter in their own right, so we will concentrate on a few elements. The diagram below shows how to think about these elements, effectiveness is about whether the actual effect of the control matches the desired effect, while efficiency is about how much investment we need to put in to operate it, and cost effectiveness is whether the cost is worth it when considering the actual effect.
Dynamic risk assessment is not just thinking about the upsides of our interventions and how to protect them, it is also important to consider the downsides of policy interventions–for example will they hamper productivity, create new costs, or impact on vulnerable people.
