Risk Management, Governance, and Organizational Resilience
Risk management is how the cooperative protects service continuity, public trust, people, information, finances, and compliance while still making decisions. Governance clarifies who oversees which risks; resilience prepares the organization to continue through disruption.
What you’ll be able to do
Week objectives
- Identify and assess strategic, operational, financial, compliance, people, technology, privacy, and relationship risks.
- Assign risk ownership and mitigation actions.
- Distinguish governing oversight from management responsibility.
- Create a basic continuity plan and compliance calendar.
- Map succession and backup responsibility.
Core concepts
Build the mental model
Risk
Risk is uncertainty that could affect objectives. Describe a risk as cause, event, and impact rather than a vague topic such as 'staffing.'
Likelihood, impact, and velocity
Likelihood estimates probability; impact estimates consequence; velocity considers how quickly harm develops. A low-frequency privacy incident may still demand strong controls because impact and velocity are high.
Inherent and residual risk
Inherent risk exists before controls. Residual risk remains after controls. A control should have an owner, evidence, and testing method.
Risk appetite and tolerance
Risk appetite is the amount and type of risk the organization is willing to pursue or retain; tolerance is the acceptable variation around an objective. Public entities often have very low tolerance for student safety, privacy, fraud, and legal noncompliance.
Risk register
A register names the risk, category, causes, effects, ratings, controls, owner, actions, due dates, indicators, and status. It supports decisions rather than merely documenting anxiety.
Governance
The governing body sets direction, policy, approval boundaries, and oversight. Management operates the cooperative, maintains controls, and escalates material exposure. Counsel, auditors, and insurers advise but do not own management decisions.
Continuity
Continuity planning identifies essential functions, minimum service levels, dependencies, alternates, communication, data access, and recovery priorities.
Compliance calendar
Recurring obligations need an owner, due date, evidence, backup, and escalation. The calendar should reflect actual federal, state, local, district, grant, contract, credential, and policy requirements verified for the cooperative.
Succession and key-person risk
Map decisions, relationships, credentials, access, and knowledge concentrated in one person. Emergency backup and long-term succession are related but different plans.
In practice
What it looks like
- A cyber incident could block access to evaluation records. Controls include approved systems, access review, backups, incident response, vendor terms, and manual continuity steps.
- A single payroll specialist controls a critical process with no trained backup. Cross-training and documented approval controls reduce key-person risk without weakening segregation of duties.
- The governing committee receives a quarterly top-risk view while management reviews operational indicators monthly and escalates immediately when thresholds are crossed.
Required viewing
Learn from trusted instructors
3 verified videos · 2 hr 25 min. Watch in order, then mark each complete.
HSE Enterprise Risk Management Policy and Procedures 2023 Webinar
HSE Ireland
Demonstrates enterprise risk management in a public health system with professional, compliance, and service obligations. That context is closer to a cooperative than a purely commercial risk model.
FEMA P-1000: Planning School Emergency Response and Disaster Recover (Module 3)
Applied Technology Council
Addresses emergency response and recovery in a school setting. Its continuity perspective helps the learner plan for essential functions, dependencies, and recovery priorities.
Enterprise Resilience and Systemic Level Risk Management
MIT Sloan Executive Education
Expands the view from individual hazards to interconnected systems and resilience. It is useful for risks that cross districts, vendors, staffing, information, and governance.
Apply the ideas
Risk, Continuity, and Governance Worksheet
Use categories as prompts, not limits. Verify every compliance deadline with qualified internal or external sources.
Risk register
Continuity plan
Compliance calendar
Succession map
Weekly deliverable
Turn the week into working practice.
A risk register, basic continuity plan, compliance calendar, and succession/backup-responsibility map.
- Identify at least twelve risks across all major categories and write cause-event-impact statements.
- Score likelihood, impact, and velocity; name controls and residual concerns.
- Assign an owner, action, due date, and indicator to every priority risk.
- Define essential functions, minimum service levels, dependencies, alternatives, and recovery owners.
- Create a compliance calendar framework and populate only requirements verified for your jurisdiction and agreements.
- Map emergency backups for critical decisions, relationships, credentials, systems, and processes.
The register contains at least twelve well-formed risks, priority risks have owners and actions, continuity covers essential functions and dependencies, calendar entries cite authoritative sources, and backup gaps have development actions.
Executive questions
Questions worth carrying
- What objective could be disrupted, by what event, and with what impact?
- Which control reduces the risk, and how do we know it works?
- Who owns management action and who provides oversight?
- What indicator requires immediate escalation?
- How would essential services continue if this person, facility, system, vendor, or district contact were unavailable?
Optional AI practice
Use AI as a thinking partner—not a records system.
Protect sensitive information. Do not upload personally identifiable student information, protected student records, confidential personnel information, unredacted contracts, credentials, or sensitive financial information to an AI system without explicit authorization. Follow FERPA, IDEA, district policy, employment-confidentiality duties, contractual restrictions, records rules, and approved data-security procedures.
Week 11 in one sentencePractical risk management connects uncertainty to objectives, controls, owners, triggers, and governance. Resilience focuses on continuing essential services when prevention is not enough.