Skip to content
Please be aware the content below has been generated by an AI model from a source PDF.

241025ARCtteePaper3Annex1StrategicRiskRegister

Audit and Risk Com­mit­tee Paper 6 Annex 1

27 Septem­ber 2024

Risk ref­er­enceThemeRisk cat­egoryRisk descrip­tionMitigation/​con­trols in placeCur­rent impactCur­rent like­li­hoodRisk scoreTrendCom­mentPlanned actionsDue dateRisk appet­iteTar­get impactTar­get like­li­hoodTar­get risk scoreRisk own­erDate last updated
1AllResources — financialPub­lic sec­tor fin­ances con­strain capa­city to alloc­ate suf­fi­cient resources to deliv­er cor­por­ate plan.Pre­vent­at­ive: Ongo­ing liais­on with Scot­tish Gov­ern­ment through our spon­sor­ship team and the Peat­land Action Team, high­light­ing achieve­ments of CNPA. Pre­vent­at­ive: Cor­por­ate plan pri­or­it­ised around anti­cip­ated Scot­tish Gov­ern­ment budget alloc­a­tions, tak­ing on Board expect­a­tion of fund­ing con­straints. Remedi­al: Focus resource on diver­si­fic­a­tion of income streams to altern­at­ive, non-pub­lic income gen­er­a­tion. Remedi­al: Con­tinu­ing to sup­port deliv­ery bod­ies” such as Cairngorms Nature, Cairngorms Trust in secur­ing inward investment.5420Stat­icRisk escal­a­tion reflects Scot­tish Government’s con­tin­ued and heightened con­cerns on for­ward sta­bil­ity of cur­rent fin­an­cial alloc­a­tions; risk of in-year adjust­ments, and risk over future year fund­ing levels. Des­pite a good set­tle­ment for 2024 – 25, the risk of in-year adjust­ments remains a con­cern. All mit­ig­at­ing actions in place and operational.Pre­vent­at­ive: Ongo­ing liais­on with Scot­tish Gov­ern­ment through our spon­sor­ship team and the Peat­land Action Team, high­light­ing achieve­ments of CNPA. Remedi­al: scen­ario plan­ning on for­ward budget mod­el­ling to pre­pare options for future resource alloc­a­tions with­in final alloc­a­tions, based on fund­ing para­met­ers sug­ges­ted by spon­sor­ship team.Ongo­ingOpen4312Dav­id Cameron21/10/2024
2AllResources — financialRisk of C2030 match fund­ing not being secured — cur­rent match fund­ing in bid not fully com­mit­ted and/​or for one year only in many areas.Pre­vent­at­ive: Ongo­ing liais­on with Scot­tish Gov­ern­ment through our spon­sor­ship team and the Peat­land Action Team, high­light­ing achieve­ments of CNPA and import­ance of Peat­land Res­tor­a­tion fund­ing to inward invest­ment by NLHF. Remedi­al: Dis­cus­sions with Trans­port Scot­land on fund­ing for act­ive travel design work.5420Escal­at­ingFund­ing for 2024 – 25 Peat­land Res­tor­a­tion has been secured at £3.5m. This provides a suit­able level of match fund­ing for the C2030 pro­gramme, in line with the programme’s 5‑year budget. Act­ive Trans­port fund­ing changes and impacts have impacted expec­ted match fund­ing in 202425 and are being escal­ated to Trans­port Scot­land and our spon­sor team.Pre­vent­at­ive: stra­tegic dis­cus­sions pro­gress­ing on approach by Trans­port Scot­land to Act­ive Trans­port / Act­ive Com­munit­ies fund­ing Pre­vent­at­ive: high pro­file and ongo­ing focus for SMT in enga­ging in influ­en­cing to secure the match fund­ing needed from part­ners; pro­ject man­agers aware of rel­ev­ant pro­ject match fund­ing pos­i­tion and tasked with seek­ing addi­tion­al match fund­ing where appro­pri­ate. Pre­vant­at­ive: con­sid­er­a­tion of new, wider match fund­ing opportunities.Ongo­ingOpen428Dav­id Cameron18/09/2024
3AllResources — staffingThere are per­ceived gaps in our skill set with respect to: pro­cure­ment pro­cesses, recruit­ment of tech­nic­al staff, abil­ity to under­take neces­sary due dili­gence on out­put from con­sult­ants and con­tract­ors. — Risks that pro­cure­ment and wider skill set capa­cit­ies are insuf­fi­cient to meet the evolving needs of the organ­isa­tion. — Lack of expert­ise and exper­i­ence in man­aging con­struc­tion pro­jects may com­prom­ise the effect­ive­ness and effi­ciency of planned deliv­ery. — Fin­an­cial risks asso­ci­ated with the let­ting of con­tracts where part­ner­ship fund­ing is likely to be depend­ent on the achieve­ment of sat­is­fact­ory standards.Pre­vent­at­ive: Recruit­ment of Pro­cure­ment Officer Pre­vent­at­ive: Sup­port secured from Scot­land Excel (and from Cent­ral Gov­ern­ment Pro­cure­ment Shared Ser­vices (CGPSS) if required).5315Stat­icRecruit­ment to new Pro­cure­ment Officer post achieved. Pro­gramme of improve­ment in pro­cure­ment pro­cesses, pro­ced­ures and con­trols under­way, includ­ing estab­lish­ment of new Pro­cure­ment Strategy. Con­struc­tion pro­jects of the size anti­cip­ated with­in the C2030 pro­gramme are new to the organ­isa­tion. We need to improve our know­ledge of Con­struc­tion Design Man­age­ment Reg­u­la­tions (CDM) and con­tracts (NEC4). We lack exper­i­ence in pro­du­cing briefs and review­ing tenders of this size and type. Improve­ments in our skill set will also bene­fit: peat­land res­tor­a­tion, river res­tor­a­tion, con­struc­tion of paths, act­ive travel projects.Pre­vent­at­ive: addi­tion­al sup­port from LL&TNPA reques­ted Pre­vent­at­ive: Options for train­ing of wider staff group under invest­ig­a­tion — sup­por­ted by Scot­land Excel. Rem­di­al: pro­cure­ment action plan developed from intern­al audit recom­mend­a­tions; reviewed monthly by Chair / Vice Chair of ARC. Tar­get date for com­ple­tion of key improve­ments 31.03.25 (exten­ded from 31/12/24). SG budget con­trols may delay train­ing until the first quarter of 202526.31/12/2024Cau­tious414Dav­id Cameron18/09/2024
4Nature & conservationStra­tegic deliveryThe Authority’s range of powers com­bined with stra­tegic part­ner­ships is insuf­fi­cient to deliv­er out­comes on wild­life crime.Pre­vent­at­ive: licen­cing arrange­ments con­trib­ute to more effect­ive con­trol frame­work. Tracker/​satel­lite mon­it­or­ing deployed for some rap­tors. Remedi­al: NPPP devel­op­ment pro­cesses used to explore part­ner­ship atti­tudes, engage­ment and powers.4416Stat­icAction on wild­life crime depends on the devel­op­ment, deliv­ery and design of stra­tegic part­ner­ships. Fin­an­cial con­straints with­in the pub­lic and third sec­tors is likely to reduce the level of resource avail­able to tackle this issue.Remedi­al: Development/​strength­en­ing of stra­tegic partnerships.Ongo­ingOpen4312Andy Ford30/01/2024
5AllResources — staffingIncreas­ingly com­pet­it­ive and restric­ted recruit­ment cli­mate pre­vents staff with the required exper­i­ence and skill sets being secured. Plan­ning and oth­er spe­cial­ist staff (IT, pro­cure­ment, fin­ance) require­ments impacted by nation­al labour/​skills short­ages and/​or salary struc­tures not suf­fi­ciently com­pet­it­ive to attract or retain key staff.Pre­vent­at­ive: focus on train­ing and devel­op­ment and intern­al suc­ces­sion plan­ning, in turn bring­ing recruit­ment into less experienced/​less highly skilled mar­kets and devel­op­ing pipeline of qual­i­fied staff Pre­vent­at­ive: con­sid­er­a­tion giv­en to job design, cre­at­ing roles with more seni­or­ity (high­er grades), and flex­ib­il­ity of offer regard­ing part-time/ job share.339Decreas­ingEvid­ence of redu­cing num­ber of applic­ants and can­did­ate lists for vacan­cies ongo­ing, while trend in unsuc­cess­ful recruit­ment exer­cises has been acted on with no recent unsuc­cess­ful recruit­ment. Suc­cess­ful recent recruit­ment in dif­fi­cult sec­tors includ­ing pro­cure­ment and planning.Pre­vent­at­ive: Review our salary struc­tures and bench­mark these against organ­isa­tions with whom we might com­pete for staff, par­tic­u­larly in the loc­al area. Use this evid­ence to inform future pay structure/​awards. Remedi­al: con­tin­gency plan­ning for example around out-sourcing of aspects of deliv­ery eg estab­lish call-off frame­work for con­sult plan­ning services.31/03/2025Open236Dav­id Cameron21/10/2024
6AllSys­tems developmentSup­port­ing speed of organ­isa­tion­al change pre­vents required devel­op­ment and embed­ding of effect­ive sup­port sys­tems. The speed / scale of oper­a­tion­al demand for sup­port from cor­por­ate sys­tems is such that we are always fire-fight­ing and giv­ing the best advice and sup­port we can. How­ever, that ongo­ing fire-fight­ing and imme­di­ate advice pre­vents us hav­ing suf­fi­cient time to design, devel­op and imple­ment new sys­tems to bet­ter suit the new organisation.Remedi­al: recruit­ment of addi­tion­al staff to cor­por­ate func­tion dur­ing 2223 and 2324. Remedi­al: pro­ject man­age­ment train­ing provided Remedi­al: devel­op­ment of improved systems/​ways of work­ing through bet­ter use of M365 applic­a­tions Remedi­al: Imple­ment new fin­ance sys­tem to sup­port wider digit­isa­tion of sys­tems and effect­ive fin­an­cial reporting4416Escal­at­ingAssess­ment of the impact of new/​addi­tion­al activ­it­ies on cor­por­ate sys­tems and resources should be part of the ini­tial con­sid­er­a­tions of these activ­it­ies. Staff recruit­met has been sec­cess­fully com­pleted. Key work on improv­ing organ­isa­tion­al intern­al con­trol sys­tems and digit­isa­tion of sys­tems is pro­gress­ing well. New fin­ance sys­tem imple­ment­a­tion is underway.Remedi­al: apply resource to devel­op­ment of improved systems/​ways of work­ing — new fin­ance sys­tem due to be installed by 31/12/24; new pro­ject ini­ti­ation con­trol under devel­op­ment Remedi­al: provide train­ing — pro­cure­ment and in wider assess­ment of pro­ject impacts at ini­ti­ation stage31/12/2024Open326Dav­id Cameron21/10/2024
7AllResources — staffingScot­tish Gov­ern­ment Main Group award 202325 cre­ates sig­ni­fic­ant fin­an­cial pres­sure on the Park Authority’s resource budget for 202425, with the poten­tial to affect pos­it­ive rela­tion­ships with the Uni­on, staff mor­ale and motiv­a­tion, recruit­ment and retention.Pre­vent­at­ive: devel­op­ment of pay mod­els to identi­fy the poten­tial cost to the Park Author­ity of fol­low­ing the Main Group pos­i­tion & con­sider the impact of poten­tial pay strategies on the devel­op­ing budget pos­i­tion for 202425; con­sider pay award dates and staged awards as tools to meet expect­a­tions while main­tain­ing afford­ab­il­ity Pre­vent­at­ive: Staff and fin­an­cial resources con­sidered dur­ing budget devel­op­ment pro­cess for 2425.339Man­agedPay mod­els developed are being accom­mod­ated with­in the budget, based on indic­at­ive Grant-in-Aid fund­ing for 202425.Open339Dav­id Cameron25/07/2024
8AllResources — staffingOur Cor­por­ate and Oper­a­tion­al Plan­ning sys­tems do not adapt to deliv­ery of major fun­ded pro­grammes along­side deliv­er­ing core’ nation­al park object­ives. This leads to work­force stretch between 3rd party fund­ing deliv­ery and core’ cor­por­ate plan activ­it­ies with increased risks of stress and reduced morale.Pre­vent­at­ive: Stra­tegic and oper­a­tion­al plans developed with extern­ally fun­ded pro­ject deliv­ery as intrins­ic ele­ments of plans to ensure deliv­ery capa­city is con­sidered fully. Preventative:Importance of staff man­age­ment and task pri­or­it­isa­tion rein­forced through lead­er­ship meet­ings. Preventative:Focus on few­er, lar­ger impact pro­jects (C2030). Remedi­al: Per­form­ance Devel­op­ment Con­ver­sa­tions (PDCs) being deployed reg­u­larly with all staff to check on staff work­loads, with 2 way flows of com­mu­nic­a­tions enabled through that pro­cess on staff work­load and capa­city. Pre­vent­at­ive: Staff and fin­an­cial resources for C2030 con­sidered along­side oper­a­tion­al plan activ­ity as part of budget devel­op­ment pro­cess for 2425.339Man­agedAddi­tion­al recruit­ment has alle­vi­ated key staff pres­sure points. Fixed term staff con­tracts reviewed through­out the year. Staff sur­vey res­ults (23÷24) pos­it­ive. Impact score of 3 reflects the risks inher­ent in the likely intens­ity of work dur­ing ini­tial stages of C2030.Likelihood of risk there­fore held stat­ic. Impact of meas­ures and risk pro­file will con­tin­ue to be closely mon­itored through staff man­age­ment processes.339Dav­id Cameron25/07/2024
9AllTech­nic­alCNPA IT ser­vices are not suf­fi­ciently robust/​secure/​or well enough spe­cified to sup­port effect­ive and effi­cient ser­vice deliv­ery. Increas­ing demand for know­ledge around Microsoft 365 and cyber secur­ity is out­strip­ping the team’s knowledge/​skill-set. Increas­ing ICT depend­ency for effect­ive and effi­cient oper­a­tions is not adequately backed up by ICT sys­tems sup­port. Use of AI increases risk of cyber secur­ity threats such as spear-phishing.Pre­vent­at­ive: Daily review of Scot­tish Cyber Coordin­a­tion Centre threat sum­mar­ies, with fol­low up action taken (eg patch­ing) as appro­pri­ate. Preventative/​remedi­al: Col­lab­or­a­tion with LL&TNPA provides sup­port. Pre­vent­at­ive: Trans­ition to Share­point com­plete; R‑drive now a read-only repos­it­ory, redu­cing risk of threats from out­side the organ­isa­tion. Pre­vent­at­ive: imple­ment Cyber Secur­ity Plus controls5315Stat­icIntern­al audit report on IT Strategy sets out key actions in this area of risk man­age­ment around IT Strategy devel­op­ment, pro­ject man­age­ment and cost­ing of IT action plans to be imple­men­ted. Move­ment into Microsoft 365 deploy­ment and cloud based sys­tems con­tin­ues. Con­sid­er­a­tion giv­en to effect­ive­ness of shared ser­vices with LL&TNPA. Devel­op­ment of the IT oper­a­tion­al risk register has iden­ti­fied poten­tial for struc­tur­al improve­ment. These con­sid­er­a­tions to be developed fur­ther (poten­tial for extern­al con­sultancy to devel­op our IT strategy organ­isa­tion­al devel­op­ment, tech­nic­al improve­ments and upskilling). Cyber essen­tials accred­it­a­tion achieved; audit towards essen­tials plus accred­it­a­tion under­way (11÷09÷24). A review of IT staff role descrip­tions now com­pleted; renewed focus on IT actions plans will flow from that. Work on the inform­a­tion man­age­ment plan will pro­duce great­er resi­li­ence of data and access to key inform­a­tion when complete.31/12/2024Cau­tious326Dav­id Cameron21/10/2024
10AllTech­nic­alBusi­ness Con­tinu­ity Plans (BCP) are inad­equate to deal with sig­ni­fic­ant impacts to nor­mal work­ing arrange­ments and res­ult in ser­vice failure.Pre­vent­at­ive: Devel­op­ment of hybrid work­ing meth­ods and cloud com­put­ing approaches have improved the organisation’s resi­li­ence. Remedi­al: devel­op updated busi­ness con­tinu­ity plan and embed its provisions5420Stat­icWork on BCP assisted in roll out of ini­tial and ongo­ing responses to Coronavir­us pan­dem­ic. Now that hybrid work­ing arrange­ments are embed­ded, there is a need to recon­sider BCP.Pre­vent­at­ive: pro­posed con­sultancy to devel­op new BCP31/03/2025Cau­tious515Dav­id Cameron21/10/2024
11AllRepu­ta­tionRepu­ta­tion­al dam­age may res­ult from: — Unreal­ist­ic expect­a­tions of what the Park Author­ity and its part­ners can achieve in the face of the sig­ni­fic­ant risks presen­ted by cli­mate change, spe­cies extinc­tion, flood man­age­ment and fire; and/​or — Dis­agree­ment between the Park Author­ity and stake­hold­er groups with­in the Park.Pre­vent­at­ive: Exist­ing stra­tegic part­ner­ships and stake­hold­er rela­tion­ships help to cre­ate a wider under­stand­ing of the factors that are with­in, and those that are out­side the con­trol of the Park Author­ity and its partners.5315Decreas­ingScor­ing reviewed fol­low­ing over­view of NPPP deliv­ery to be sub­mit­ted to board in September,with like­li­hood decreased from 4 to 3. Stake­hold­er rela­tion­ship data­base now designed and under developmentPre­vent­at­ive: Man­age­ment of expect­a­tions through: — Tar­geted com­mu­nic­a­tions — Fur­ther devel­op­ment of stake­hold­er rela­tion­ships. — Development/​strength­en­ing of stra­tegic part­ner­ships. — Ongo­ing assess­ment of oper­a­tion­al risk man­age­ment and mit­ig­a­tion in our com­mu­nic­a­tions. — Devel­op­ment of stake­hold­er rela­tion­ship databaseOngo­ingOpen339Grant Moir21/10/2024
12AllResources — staffingScot­tish Gov­ern­ment pay remit for 2425 is lower than desired pay award. Pay expect­a­tions of staff may not be met, lead­ing to issues with pay align­ment with oth­er NDPBs and con­sequent effect on staff mor­ale and motivationPre­vent­at­ive: Devel­op­ment and sub­mis­sion of busi­ness case for pay align­ment in keep­ing with SG nation­al two-year sec­tor­al pay award.4416Decreas­ingSG remu­ner­a­tion Group turned down ini­tial busi­ness case. Amended busi­ness case sub­mit­ted and approv­al received end Aug 24. Staff con­sulta­tion under­way to end Oct. Sea­son­al staff pos­i­tion resolved satisfactorily.Remedi­al: busi­ness case sub­mit­ted to SG; attend­ance at Remu­ner­a­tion group July 2024; staff con­sulta­tions Oct 24; action on sea­son­al pay arrange­ments Oct 24.31/12/2024Open122Dav­id Cameron21/10/2024
×

We want your feedback

Thank you for visiting our new website. We'd appreciate any feedback using our quick feedback form. Your thoughts make a big difference.

Thank you!