30.3 Core Elements of a Federal Risk Profile
Key Takeaways
- Public sector ERM addresses specialized institutional domains, including Continuity of Operations Planning (COOP - essential functions, alternate facilities, devolution of command), cybersecurity risk management, and human capital succession.
- OMB Circular A-123 formally integrates ERM with strategic planning under GPRAMA and internal control under the GAO Green Book, requiring agencies to build and maintain an annual agency Risk Profile.
- Risk Appetite articulates the broad amount and type of risk an agency is willing to accept in pursuit of strategic goals, while Risk Tolerance establishes the acceptable variance in operational performance thresholds.
Core Elements of a Federal Risk Profile
- Risk Identification & Description: A concise narrative describing the potential risk event, its root drivers, and its impact on specific strategic goals.
- Risk Category: Classification across core public sector categories:
- Strategic: External policy changes, shifting public needs, or mission reauthorizations;
- Operational: Process failures, technological vulnerabilities, or human capital shortages;
- Financial / Reporting: Material misstatements, improper payments, or budgetary shortfalls;
- Compliance: Statutory violations, regulatory penalties, or Antideficiency Act breaches;
- Reputational: Loss of public trust, negative congressional scrutiny, or adverse media exposure.
- Risk Owner: A designated assistant secretary or bureau chief directly responsible for monitoring the risk.
- Inherent and Residual Risk Ratings: Quantitative or qualitative scoring before and after control implementation.
- Risk Response and Planned Mitigations: Specific initiatives, milestones, and funding allocations designed to treat the risk.
- Key Risk Indicators (KRIs): Specific operational metrics tracked by executive leadership.
Visualizing Risk: The Heat Map Matrix
Agencies plot identified risks on a Risk Heat Map (typically a 5×5 matrix of Likelihood versus Impact). Risks clustering in the upper-right quadrant (High Likelihood / Severe Impact) represent critical threats requiring immediate executive intervention, formal CAP development, and priority budget allocation.
+-----------------------------------------------------------------------------------+
| 5x5 AGENCY RISK HEAT MAP MATRIX |
+-----------------------------------------------------------------------------------+
| I 5 | [LOW] [MODERATE] [HIGH] [EXTREME] [EXTREME] |
| M 4 | [LOW] [MODERATE] [HIGH] [HIGH] [EXTREME] |
| P 3 | [LOW] [LOW] [MODERATE] [HIGH] [HIGH] |
| A 2 | [LOW] [LOW] [LOW] [MODERATE] [MODERATE] |
| C 1 | [LOW] [LOW] [LOW] [LOW] [LOW] |
| T +---------------------------------------------------------------------------+
| 1 2 3 4 5 |
| LIKELIHOOD |
+-----------------------------------------------------------------------------------+
Risk Appetite vs. Risk Tolerance: Definitions and Calibration
A vital conceptual requirement for both professional practice and the CGFM examination is understanding the precise distinction between Risk Appetite and Risk Tolerance.
+-----------------------------------------------------------------------------------+
| RISK APPETITE VS. RISK TOLERANCE COMPARISON |
+-----------------------------------------------------------------------------------+
| DIMENSION | RISK APPETITE | RISK TOLERANCE |
|---------------------|------------------------------|------------------------------|
| Definition | The broad, aggregate amount | The specific, measurable |
| | and type of risk an agency | operational boundary of |
| | is willing to accept in | acceptable variation around a|
| | pursuit of strategic goals. | specific performance target. |
| Governance Level | Strategic / Board / Cabinet | Operational / Programmatic |
| Form of Expression | Broad qualitative statements | Specific quantitative metrics|
| Example | "The agency has zero | "Disaster grant turnaround |
| | appetite for compliance or | target is 14 days; variance |
| | life-safety risk, but an | of +/- 2 days is acceptable; |
| | open appetite for IT pilot | >16 days triggers executive |
| | innovation." | escalation." |
| Relationship | Sets the overall boundary | Operates within appetite; |
| | for enterprise strategy. | guides day-to-day operations.|
+-----------------------------------------------------------------------------------+
Calibrating Risk Appetite in Government
Unlike commercial firms that take aggressive calculated risks to earn high financial returns, public agencies operate under statutory charters. Consequently:
- Compliance and Ethics: Agencies virtually always maintain a zero or extremely low risk appetite for legal noncompliance, Antideficiency Act breaches, and ethical infractions.
- Mission Delivery and Innovation: Agencies may establish a moderate to high risk appetite when testing cutting-edge technologies (e.g., artificial intelligence pilot projects or cloud migrations) to modernize citizen services, provided operational safeguards are in place.
Integrating ERM with Internal Control
ERM and internal control are not competing or duplicative systems; they are complementary, mutually reinforcing disciplines:
- ERM operates at the Macro/Strategic Level: It surveys the broad external and internal horizon, identifies emerging uncertainties, establishes enterprise risk appetite, and compiles the Agency Risk Profile.
- Internal Control (Green Book) operates at the Micro/Tactical Level: It provides the specific operational control activities (segregations of duties, reconciliations, supervisory approvals, IT access restrictions) that mitigate identified risks so that operations remain within established risk tolerances.
Green Book Principles 6 through 9 (Risk Assessment) serve as the formal operational bridge connecting enterprise-wide ERM to day-to-day internal control activities.
Specialized Public Sector ERM Applications
1. Continuity of Operations Planning (COOP)
Under National Security Presidential Directive (NSPD-51/HSPD-20) and Federal Continuity Directive 1 (FCD 1), all federal executive agencies must maintain a comprehensive Continuity of Operations Plan (COOP) to ensure the uninterrupted delivery of government services during catastrophic disruptions (natural disasters, terror attacks, cyber blackouts, pandemics). Core COOP pillars include:
- Primary Mission Essential Functions (PMEFs): Identifying functions that must be resumed within 12 hours of an incident and sustained for up to 30 days.
- Alternate Operating Facilities: Establishing geographically distributed physical sites (or secure virtual cloud infrastructures) with redundant power, secure IT systems, and life-support capabilities.
- Orders of Succession & Delegations of Authority: Codifying explicit, legally binding succession hierarchies to ensure constitutional continuity of lawful command if principal leaders are incapacitated.
- Vital Records Management: Safeguarding emergency operating records (personnel rosters, operational plans) and legal rights records (treaties, contracts, financial ledgers).
- Devolution of Control: Establishing procedures to transfer statutory authority and operational control from headquarters to regional field personnel if the primary headquarters is destroyed.
2. Cybersecurity Risk Management
In an era of sophisticated state-sponsored cyber warfare, public sector ERM integrates deeply with cybersecurity frameworks governed by the Federal Information Security Modernization Act of 2014 (FISMA), the NIST Cybersecurity Framework (NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover), and OMB Memorandum M-22-09 (Zero Trust Architecture). Agencies maintain continuous vulnerability scanning, multi-factor authentication, supply chain vendor auditing, and automated incident response protocols.
3. Human Capital & Succession Planning
The public sector faces acute demographic risks, commonly termed the "retirement cliff." A vast percentage of senior federal, state, and local civil servants are eligible for immediate retirement, threatening agencies with massive institutional memory loss in critical technical fields (accounting, procurement, engineering). ERM human capital planning deploys structured knowledge transfer programs, cross-training, targeted retention allowances, and executive candidate pipelines to mitigate human capital risk.
Practical Public Finance Scenario: State Department of Natural Resources Risk Profile & KRI Formulation
Scenario: The State Department of Natural Resources (DNR) oversees 4,000,000 acres of forestland and administers a $500,000,000 budget. The newly appointed Chief Risk Officer (CRO) leads the Executive Risk Steering Committee to develop the agency's annual Risk Profile. The committee evaluates four enterprise risks:
- Catastrophic Wildfire Suppression Overruns: Extreme climate conditions threaten to exhaust the state emergency fire fund within the first quarter of the fiscal year.
- Legacy IT Timber Permitting System: A 30-year-old COBOL mainframe system handles $90,000,000 in commercial timber harvesting permits; the system lacks technical support and vendor security patches.
- Senior Forestry Engineer Brain Drain: 45% of certified forest engineers are eligible to retire within 18 months, with zero trained junior replacements.
- Federal Environmental Grant Noncompliance: Inconsistent water testing documentation could trigger a retroactive clawback of $35,000,000 in federal Clean Water grants.
Professional ERM Profile Scoring & Calibration
+-----------------------------------------------------------------------------------+
| DNR ENTERPRISE RISK PROFILE SCORING MATRIX |
+-----------------------------------------------------------------------------------+
| RISK TITLE | CAT. | INHERENT (L x I) | RESPONSE | MITIGATION & CONTROLS |
|------------------|-------|------------------|----------|--------------------------|
| 1. Wildfire | Strat.| 5 x 5 = 25 (Ext) | Share & | Secure commercial cat- |
| Overruns | | | Mitigate | bond reinsurance; deploy |
| | | | | automated sensor network.|
| 2. Legacy IT | Oper. | 4 x 4 = 16 (High)| Avoid & | Issue RFP to migrate |
| System | | | Mitigate | permitting to FedRAMP |
| | | | | secure cloud platform. |
| 3. Engineer | Human | 5 x 3 = 15 (High)| Mitigate | Launch university fellow-|
| Retirements | Cap. | | | ship; initiate structured|
| | | | | knowledge transfer SOP. |
| 4. Grant Non- | Comp. | 3 x 4 = 12 (Mod) | Mitigate | Implement standard Green |
| compliance | | | & Control| Book compliance checks & |
| | | | | automated test uploads. |
+-----------------------------------------------------------------------------------+
Formulating Risk Appetite, Tolerance, and KRIs
- Wildfire Budget Risk:
- Risk Appetite: Moderate appetite for budget flexibility, but zero appetite for uncontained life-safety loss.
- Risk Tolerance: Operational fire suppression expenditure variance up to +15% before emergency legislative appropriation is formally triggered.
- Key Risk Indicator (KRI): Drought Palmer Index combined with weekly burn-rate percentage of the emergency fund.
- Permitting IT System Risk:
- Risk Appetite: Low appetite for IT failure impacting timber revenue.
- Risk Tolerance: Permit processing delays must not exceed 5 business days.
- Key Risk Indicator (KRI): Unscheduled mainframe server downtime hours per month (threshold: >2 hours triggers immediate incident team activation).
In an Enterprise Risk Management (ERM) framework established under OMB Circular A-123 and COSO ERM, how do Risk Appetite and Risk Tolerance differ in their scope and operational application?
During a catastrophic regional flood that destroys an agency's primary headquarters, leadership activates its Continuity of Operations Plan (COOP). Which set of core components must the COOP plan include to ensure the agency maintains operational resilience under federal continuity directives?