Phase 4Week 11

Risk Management, Governance, and Organizational Resilience

Risk management is how the cooperative protects service continuity, public trust, people, information, finances, and compliance while still making decisions. Governance clarifies who oversees which risks; resilience prepares the organization to continue through disruption.

2 hr 25 min watch1 hr 40 min apply4 hr 5 min total

What you’ll be able to do

Week objectives

  • Identify and assess strategic, operational, financial, compliance, people, technology, privacy, and relationship risks.
  • Assign risk ownership and mitigation actions.
  • Distinguish governing oversight from management responsibility.
  • Create a basic continuity plan and compliance calendar.
  • Map succession and backup responsibility.

Core concepts

Build the mental model

01

Risk

Risk is uncertainty that could affect objectives. Describe a risk as cause, event, and impact rather than a vague topic such as 'staffing.'

02

Likelihood, impact, and velocity

Likelihood estimates probability; impact estimates consequence; velocity considers how quickly harm develops. A low-frequency privacy incident may still demand strong controls because impact and velocity are high.

03

Inherent and residual risk

Inherent risk exists before controls. Residual risk remains after controls. A control should have an owner, evidence, and testing method.

04

Risk appetite and tolerance

Risk appetite is the amount and type of risk the organization is willing to pursue or retain; tolerance is the acceptable variation around an objective. Public entities often have very low tolerance for student safety, privacy, fraud, and legal noncompliance.

05

Risk register

A register names the risk, category, causes, effects, ratings, controls, owner, actions, due dates, indicators, and status. It supports decisions rather than merely documenting anxiety.

06

Governance

The governing body sets direction, policy, approval boundaries, and oversight. Management operates the cooperative, maintains controls, and escalates material exposure. Counsel, auditors, and insurers advise but do not own management decisions.

07

Continuity

Continuity planning identifies essential functions, minimum service levels, dependencies, alternates, communication, data access, and recovery priorities.

08

Compliance calendar

Recurring obligations need an owner, due date, evidence, backup, and escalation. The calendar should reflect actual federal, state, local, district, grant, contract, credential, and policy requirements verified for the cooperative.

09

Succession and key-person risk

Map decisions, relationships, credentials, access, and knowledge concentrated in one person. Emergency backup and long-term succession are related but different plans.

In practice

What it looks like

  • A cyber incident could block access to evaluation records. Controls include approved systems, access review, backups, incident response, vendor terms, and manual continuity steps.
  • A single payroll specialist controls a critical process with no trained backup. Cross-training and documented approval controls reduce key-person risk without weakening segregation of duties.
  • The governing committee receives a quarterly top-risk view while management reviews operational indicators monthly and escalates immediately when thresholds are crossed.

Required viewing

Learn from trusted instructors

3 verified videos · 2 hr 25 min. Watch in order, then mark each complete.

Lesson 148:26

HSE Enterprise Risk Management Policy and Procedures 2023 Webinar

HSE Ireland

Demonstrates enterprise risk management in a public health system with professional, compliance, and service obligations. That context is closer to a cooperative than a purely commercial risk model.

Lesson 21:06:41

FEMA P-1000: Planning School Emergency Response and Disaster Recover (Module 3)

Applied Technology Council

Addresses emergency response and recovery in a school setting. Its continuity perspective helps the learner plan for essential functions, dependencies, and recovery priorities.

Lesson 329:38

Enterprise Resilience and Systemic Level Risk Management

MIT Sloan Executive Education

Expands the view from individual hazards to interconnected systems and resilience. It is useful for risks that cross districts, vendors, staffing, information, and governance.

Apply the ideas

Risk, Continuity, and Governance Worksheet

Use categories as prompts, not limits. Verify every compliance deadline with qualified internal or external sources.

1

Risk register

Risk statementCategoryLikelihoodImpactVelocityControlsOwnerActionTrigger
2

Continuity plan

Essential functionMinimum levelDependenciesMaximum disruptionAlternate methodRecovery owner
3

Compliance calendar

RequirementAuthority or sourceDue dateOwnerBackupEvidenceEscalation
4

Succession map

Responsibility or accessPrimaryEmergency backupReadiness gapDevelopment action
Download worksheet

Weekly deliverable

Turn the week into working practice.

A risk register, basic continuity plan, compliance calendar, and succession/backup-responsibility map.

  1. Identify at least twelve risks across all major categories and write cause-event-impact statements.
  2. Score likelihood, impact, and velocity; name controls and residual concerns.
  3. Assign an owner, action, due date, and indicator to every priority risk.
  4. Define essential functions, minimum service levels, dependencies, alternatives, and recovery owners.
  5. Create a compliance calendar framework and populate only requirements verified for your jurisdiction and agreements.
  6. Map emergency backups for critical decisions, relationships, credentials, systems, and processes.
Definition of done

The register contains at least twelve well-formed risks, priority risks have owners and actions, continuity covers essential functions and dependencies, calendar entries cite authoritative sources, and backup gaps have development actions.

Executive questions

Questions worth carrying

  1. What objective could be disrupted, by what event, and with what impact?
  2. Which control reduces the risk, and how do we know it works?
  3. Who owns management action and who provides oversight?
  4. What indicator requires immediate escalation?
  5. How would essential services continue if this person, facility, system, vendor, or district contact were unavailable?

Optional AI practice

Use AI as a thinking partner—not a records system.

Protect sensitive information. Do not upload personally identifiable student information, protected student records, confidential personnel information, unredacted contracts, credentials, or sensitive financial information to an AI system without explicit authorization. Follow FERPA, IDEA, district policy, employment-confidentiality duties, contractual restrictions, records rules, and approved data-security procedures.

Week 11 in one sentence

Practical risk management connects uncertainty to objectives, controls, owners, triggers, and governance. Resilience focuses on continuing essential services when prevention is not enough.