Skip to content
Please be aware the content below has been generated by an AI model from a source PDF.

Audit and Risk Committee meeting - Paper 1 annex 1: Strategic risk register - 14 November 2025

Risk OldThemeRisk cat­egoryRisk descrip­tionMitigation/​controls in placeCur­rent impactCur­rent like­li­hood scoreRisk TrendCom­mentPlanned actionsDue dateRisk own­erDate last risk updated
1 A1AllResources — financialPub­lic sec­tor fin­ances con­strain capa­city to alloc­ate suf­fi­cient resources to deliv­er cor­por­ate plan.Pre­vent­at­ive: Ongo­ing liais­on with Scot­tish Gov­ern­ment through our spon­sor­ship team and the Peat­land Action Team, high­light­ing achieve­ments of CNPA. Pre­vent­at­ive: Cor­por­ate plan pri­or­it­ised around anti­cip­ated Scot­tish Gov­ern­ment budget alloc­a­tions, tak­ing on Board expect­a­tion of fund­ing con­straints. Remedi­al: Focus resource on diver­si­fic­a­tion of income streams to altern­at­ive, non-pub­lic income gen­er­a­tion. Remedi­al: Con­tinu­ing to sup­port deliv­ery bod­ies” such as Cairngorms Nature, Cairngorms Trust in secur­ing inward investment.5315Alloc­a­tions for 202526 fin­an­cial year provide a good set­tle­ment suf­fi­cient to cov­er planned deliv­ery against cor­por­ate plan object­ives. Mit­ig­a­tion actions have sup­por­ted pos­it­ive risk man­age­ment. Risk Decreas­ing decreas­ing while recog­nisi­ing alloc­a­tions remain sub­ject to approv­al of Scot­tish budget, with resid­ual risk around in year adjustments.Award of £1.19 mil­lion from NRF con­firms suc­cess of mit­ig­a­tion approaches.Pre­vent­at­ive: Ongo­ing liais­on with Scot­tish Gov­ern­ment through our spon­sor­ship team and the Peat­land Action Team, high­light­ing achieve­ments of CNPA. Remedi­al: scen­ario plan­ning on for­ward budget mod­el­ling to pre­pare options for future resource alloc­a­tions with­in final alloc­a­tions, based on fund­ing para­met­ers sug­ges­ted by spon­sor­ship team.OpenDav­id Cameron20/01/2025
2AllResources — financialRisk of C2030 match fund­ing not being secured — cur­rent match fund­ing in bid not fully com­mit­ted and/​or for one year only in many areas.Pre­vent­at­ive: Ongo­ing liais­on with Scot­tish Gov­ern­ment through our spon­sor­ship team and the Peat­land Action Team, high­light­ing achieve­ments of CNPA and import­ance of Peat­land Res­tor­a­tion fund­ing to inward invest­ment by NLHF. Remedi­al: Dis­cus­sions with Trans­port Scot­land on fund­ing for act­ive travel design work.428Fund­ing for 2025 – 26 Peat­land Res­tor­a­tion has been secured at £4.33m. This provides a suit­able level of match fund­ing for the C2030 pro­gramme, in line with the programme’s 5‑year budget. Peat­land res­tor­a­tion deliv­ery pro­file is healthy, with expect­a­tion that suf­fi­cient will be spent with­in the year to meet required con­tri­bu­tion to C2030 deliv­ery. Fund­ing for Act­ive Com­munit­ies pro­jects now in place (Trans­port Scot­land). Con­tract­or for RIBA stages 3 and 4 design work now appoin­ted. Trans­port Scot­land fund­ing awar­ded must be used by 31 March 2026, the short time-frame put­ting pres­sure on deliv­ery. Con­tinu­ation of the pro­jects past design stage 3 will require an addi­tion­al award of fund­ing for 202627.Pre­vent­at­ive: focus over 2025 on match fund­ing pos­i­tion and con­sequent impacts to ensure C2030 pro­gramme plans and fin­an­cing of them fully aligned by end of year. Pre­vent­at­ive: high pro­file and ongo­ing focus for SMT in enga­ging in influ­en­cing to secure the match fund­ing needed from part­ners; pro­ject man­agers aware of rel­ev­ant pro­ject match fund­ing pos­i­tion and tasked with seek­ing addi­tion­al match fund­ing where appro­pri­ate. Pre­vant­at­ive: con­sid­er­a­tion of new, wider match fund­ing opportunities.OpenDav­id Cameron02/09/2025
3AllResources — staffingThere are per­ceived gaps in our skill set with respect to: pro­cure­ment pro­cesses, recruit­ment of tech­nic­al staff, abil­ity to under­take neces­sary due dili­gence on out­put from con­sult­ants and con­tract­ors. — Risks that pro­cure­ment and wider skill set capa­cit­ies are insuf­fi­cient to meet the evolving needs of the organ­isa­tion. — Lack of expert­ise and exper­i­ence in man­aging con­struc­tion pro­jects may com­prom­ise the effect­ive­ness and effi­ciency of planned deliv­ery. — Fin­an­cial risks asso­ci­ated with the let­ting of con­tracts where part­ner­ship fund­ing is likely to be depend­ent on the achieve­ment of sat­is­fact­ory standards.Pre­vent­at­ive: Recruit­ment of Pro­cure­ment Officer Pre­vent­at­ive: Sup­port secured from Scot­land Excel (and from Cent­ral Gov­ern­ment Pro­cure­ment Shared Ser­vices (CGPSS) if required). Pre­vent­at­ive: Con­sider deliv­ery through part­ners with con­struc­tion pro­ject deliv­ery exper­i­ence where appro­pri­ate to deliv­ery object­ives. Remedi­al: use of leg­al sup­port or oth­er out­sourced sup­port where required Pre­vent­at­ive: licen­cing arrange­ments con­trib­ute to more effect­ive con­trol framework.339Recruit­ment to new Pro­cure­ment Officer post achieved. Pro­gramme of improve­ment in pro­cure­ment pro­cesses, pro­ced­ures and con­trols under­way, includ­ing estab­lish­ment of new Pro­cure­ment Strategy. Con­struc­tion pro­jects of the size anti­cip­ated with­in the C2030 pro­gramme are new to the organ­isa­tion. We need to improve our know­ledge of Con­struc­tion Design Man­age­ment Reg­u­la­tions (CDM) and con­tracts (NEC4). We lack exper­i­ence in pro­du­cing briefs and review­ing tenders of this size and type. Improve­ments in our skill set will also bene­fit: peat­land res­tor­a­tion, river res­tor­a­tion, con­struc­tion of paths, act­ive travel projects.Pre­vent­at­ive: addi­tion­al sup­port from LL&TNPA reques­ted Pre­vent­at­ive: Options for train­ing of wider staff group under invest­ig­a­tion — sup­por­ted by Scot­land Excel. Remedi­al: pro­cure­ment action plan developed from intern­al audit recom­mend­a­tions; reviewed monthly by Chair/​Vice Chair of ARC. Tar­get date for com­ple­tion of key improve­ments 31.03.26 (exten­ded from 31/12/24). SG budget con­trols delayed train­ing until the first half of 202526.Cau­tiousDav­id Cameron12/05/2025
4 A24Nature & conservatStra­tegic deliveryThe Authority’s range of powers com­bined with stra­tegic part­ner­ships is insuf­fi­cient to deliv­er out­comes on wild­life crime.Tracker/​satel­lite mon­it­or­ing deployed for some rap­tors. Remedi­al: NPPP devel­op­ment pro­cesses used to explore part­ner­ship atti­tudes, engage­ment and powers.4416Action on wild­life crime depends on the devel­op­ment, deliv­ery and design of stra­tegic part­ner­ships. Fin­an­cial con­straints with­in the pub­lic and third sec­tors is likely to reduce the level of resource avail­able to tackle this issue.Remedi­al: Development/​strength­en­ing of stra­tegic partnerships.OpenAndy Ford20/01/2025
5AllSys­tems developmentSup­port­ing speed of organ­isa­tion­al change pre­vents required devel­op­ment and embed­ding of effect­ive sup­port sys­tems. The speed / scale of oper­a­tion­al demand for sup­port from cor­por­ate sys­tems is such that we are always fire-fight­ing and giv­ing the best advice and sup­port we can. How­ever, that ongo­ing fire-fight­ing and imme­di­ate advice pre­vents us hav­ing suf­fi­cient time to design, devel­op and imple­ment new sys­tems to bet­ter suit the new organisation.Remedi­al: recruit­ment of addi­tion­al staff to cor­por­ate func­tion dur­ing 2223 and 2324. Remedi­al: pro­ject man­age­ment train­ing provided Remedi­al: devel­op­ment of improved systems/​ways of work­ing through bet­ter use of M365 applic­a­tions Remedi­al: Imple­ment new fin­ance sys­tem to sup­port wider digit­isa­tion of sys­tems and effect­ive fin­an­cial report­ing. Pre­vent­at­ive: design and imple­ment pro­ject ini­ti­ation con­trols sup­port­ing more man­aged timelines and fuller, earli­er con­sid­er­a­tion of pro­ject plans.326Ini­tial mit­ig­a­tion actions now in place and embed­ding, includ­ing Decreas­ing pro­ject ini­ti­ation con­trols. Fur­ther rein­force­ment of oper­a­tion of con­trols to be under­taken. Remedi­al: apply resource to devel­op­ment of improved systems/​ways of work­ing — new fin­ance sys­tem due to be installed by 31/03/25; new pro­ject ini­ti­ation con­trol under devel­op­ment Remedi­al: provide train­ing — pro­cure­ment and in wider assess­ment of pro­ject impacts at ini­ti­ation stage. Remedi­al: final­isa­tion and roll-out of pro­ject ini­ti­ation guid­ance, includ­ing assess­ment of any new leg­al implic­a­tions arising from pro­ject deliv­ery intentions.OpenDav­id Cameron17/10/2025
9 A13/A18AllTech­nic­alCNPA IT ser­vices are not suf­fi­ciently robust/​secure/​or well enough spe­cified to sup­port effect­ive and effi­cient ser­vice deliv­ery. Increas­ing demand for know­ledge around Microsoft 365 and cyber secur­ity is out­strip­ping the team’s know­ledge/skill-set. Increas­ing ICT depend­ency for effect­ive and effi­cient oper­a­tions is not adequately backed up by ICT sys­tems sup­port. Use of Al increases risk of cyber secur­ity threats such as spear-phishing.Pre­vent­at­ive: Daily review of Scot­tish Cyber Coordin­a­tion Centre threat sum­mar­ies, with fol­low up action taken (eg patch­ing) as appro­pri­ate. Preventative/​remedi­al: Col­lab­or­a­tion with LL&TNPA provides sup­port. Pre­vent­at­ive: Trans­ition to Share­point com­plete; R‑drive now a read-only repos­it­ory, redu­cing risk of threats from out­side the organ­isa­tion. Pre­vent­at­ive: imple­ment Cyber Secur­ity Plus controls5210Intern­al audit report on IT Strategy sets out key actions in this area of risk man­age­ment around IT Strategy devel­op­ment, pro­ject man­age­ment and cost­ing of IT action plans to be imple­men­ted. Move­ment into Microsoft 365 deploy­ment and cloud based sys­tems con­tin­ues. Cyber Secur­ity Plus accred­it­a­tion now in place and sys­tems oper­at­ing to those stand­ards. Con­sid­er­a­tion giv­en to effect­ive­ness of shared ser­vices with LL&TNPA.Devel­op­ment of the IT oper­a­tion­al risk register has iden­ti­fied poten­tial for struc­tur­al improve­ment. These con­sid­er­a­tions to be developed fur­ther (poten­tial for extern­al con­sultancy to devel­op our IT strategy organ­isa­tion­al devel­op­ment, tech­nic­al improve­ments and upskilling). Cyber essen­tials accred­it­a­tion achieved: audit towards essen­tials plus accred­it­a­tion under­way (11÷09÷24). A review of IT staff role descrip­tions now com­pleted; renewed focus on IT action plans will flow from that. Work on the inform­a­tion man­age­ment plan will pro­duce great­er resi­li­ence of data and access to key inform­a­tion when complete.Cau­tiousDav­id Cameron20/01/2025
10 A22AllTech­nic­alBusi­ness Con­tinu­ity Plans (BCP) are inad­equate to deal with sig­ni­fic­ant impacts to nor­mal work­ing arrange­ments and res­ult in ser­vice failure.Pre­vent­at­ive: Devel­op­ment of hybrid work­ing meth­ods and cloud com­put­ing approaches have improved the organisation’s resi­li­ence. Remedi­al: devel­op updated busi­ness con­tinu­ity plan and embed its provisions5420Work on BCP assisted in roll out of ini­tial and ongo­ing responses to Coronavir­us pan­dem­ic. Now that hybrid work­ing arrange­ments are embed­ded, there is a need to recon­sider BCP.Pre­vent­at­ive: pro­posed con­sultancy to devel­op new BCPCau­tiousDav­id Cameron20/01/2025
11AllRepu­ta­tionRepu­ta­tion­al dam­age may res­ult from: — Unreal­ist­ic expect­a­tions of what the Park Author­ity and its part­ners can achieve in the face of the sig­ni­fic­ant risks presen­ted by cli­mate change, spe­cies extinc­tion, flood man­age­ment and fire; and/​or — Dis­agree­ment between the Park Author­ity and stake­hold­er groups with­in the Park. — Dis­in­form­a­tion cir­cu­lated about the Park Authority’s actionsPre­vent­at­ive: Exist­ing stra­tegic part­ner­ships and stake­hold­er rela­tion­ships help to cre­ate a wider under­stand­ing of the factors that are with­in, and those that are out­side the con­trol of the Park Author­ity and its part­ners. Pre­vent­at­ive: com­mu­nic­a­tions strategy devel­op­ment and imple­ment­a­tion to ensure Park Authority’s mes­sages and inform­a­tion are widely received and under­stood by appro­pri­ate audiences4312Scor­ing reviewed fol­low­ing over­view of NPPP deliv­ery to be sub­mit­ted to board in Septem­ber, with like­li­hood decreased from 4 to 3. Stake­hold­er rela­tion­ship data­base now designed and under developmentPre­vent­at­ive: Man­age­ment of expect­a­tions through: — Tar­geted com­mu­nic­a­tions — Fur­ther devel­op­ment of stake­hold­er rela­tion­ships. Clear pos­i­tion­ing on the Park Authority’s role / level of involve­ment in sig­ni­fic­ant issuesOpenGrant Moir17/10/2025
13AllStra­tegic deliveryThe Park Author­ity does not adequately respond or adpat to changes in fund­ing or policy envir­on­ment at Scot­tish Gov­ern­ment policy levels; from extern­al fund­ing sources; or in evol­u­tion of private fin­ance investment.Pre­vent­at­ive: alloc­ate seni­or time to engage­ment with Scot­tish Gov­ern­ment in policy dis­cus­sion and devel­op­ment, identi­fy­ing and respond­ing to risk implic­a­tions. Pre­vent­at­ive: pro­act­ively identi­fy oppor­tun­it­ies for private invest­ment and struc­tures to sup­port their invest­ment to com­ple­ment and sup­port NPPP and cor­por­ate objectives.4312Pos­it­ive rela­tion­ships developed at seni­or levels on engage­ment with the Park Author­ity and our fin­an­cial require­ments. Work pro­gress­ing on devel­op­ment of a private fin­ance frame­work. Need iden­ti­fied to begin plan­ning for end of C2030 fin­an­cing peri­od and replace­ment of NLHF fund­ing with­in the Park Authority’s resource mix. Seni­or staff are fully engaged at a lead­er­ship level in Pub­lic Ser­vice Reform and wider policy evolution- Ongo­ing assess­ment of oper­a­tion­al risk man­age­ment and mit­ig­a­tion in our com­mu­nic­a­tions. — Devel­op­ment of stake­hold­er rela­tion­ship data­base Development/​strengthening of stra­tegic partnerships.OpenDav­id Cameron17/10/2025
14AllResources — staffingThe Park Authority’s work­force is not adequately flex­ible to respond to chan­ging stra­tegic pri­or­it­ies or to chan­ging oper­a­tion­al scalePri­or­it­ise Pre­vent­at­ive: work­force man­age­ment strategy updated and reg­u­larly reviewed to take a 5+ year for­ward view. Pre­vent­at­ive: con­tin­ued invest­ment in train­ing and devel­op­ment for staff sup­port­ing per­form­ance in cur­rent roles and suc­ces­sion / devel­op­ment plans. Pre­vent­at­ive: estab­lish an appro­pri­ate mix of per­man­ent and fixed term staff to allow for flex­ib­il­ity in future struc­tures. Remedi­al: retain scru­tiny of all vacan­cies and iden­ti­fic­a­tion of oppor­tun­it­ies to adapt vacan­cies toward future needs.339Multi-year work­force man­age­ment and fin­an­cial fore­casts estab­lished to guide actionsFinal­ise private fin­ance frame­work Work­force man­age­ment strategy reviewed by board at busiess ses­sion, Octo­ber 2025. This will now guide asso­ci­ated policy devel­op­ment work fol­low­ing full intern­al con­sulta­tion. Mit­ig­a­tion actions pro­gress­ing to plan.31.03.26Dav­id Cameron17/10/2025
15AllSys­tems developmentNPPP deliv­ery respons­ib­il­it­ies are not suf­fi­ciently clear Sys­tems devel­op­ment across the part­ner­ship and Park Author­ity is expec­ted to address more than it is cap­able to deliver.Pre­vent­at­ive: rein­force spe­cif­ic part­ner deliv­ery respons­ib­il­it­ies through per­form­ance man­age­ment sys­tems and report­ing. Pre­vent­at­ive: rein­force NPPP deliv­ery link­ages through grant con­tract terms.3412NPPP Per­form­ance Man­age­ment dash­board now com­plete. Part­ner engage­ment and clar­ity of respons­ib­il­ity to be addressed as aspect of devel­op­ment of 27 – 32 NPPP.Con­sulta­tion on work­force man­age­ment strategy. Devel­op­ment of organ­isa­tion­al policies sup­port­ing deliv­ery of work­force man­age­ment objectives.31.12.26Gav­in Miles17/10/2025
16AllTech­nic­alEvol­u­tion of the Park Authority’s range of activ­it­ies and pro­jects res­ults in uniden­ti­fied and unmit­ig­ated expos­ure to leg­al implic­a­tions and asso­ci­ated liabilitiesPre­vent­at­ive: under­take risk ana­lys­is over­view of 202526 oper­a­tion­al plan to identi­fy any deliv­ery areas with poten­tial expos­ure; devel­op and deliv­er mit­ig­a­tion action plan339Evid­ence that prpo­ject ini­ti­ation pro­cesses is work­ing in draw­ing out poten­tial leg­al implic­a­tions of pro­ject plans.Mon­it­or effect­ive­ness of sys­tem and level of any issues arising.TBCDav­id Cameron17/10/2025
17PlaceStra­tegic deliveryUncer­tain­ties on fin­ance, pro­cure­ment, con­tract­or cap­city and part­ner­ship devel­op­ment com­bine to pre­vent achieve­ment of key Cairngorms 2030 com­munity trans­port infra­struc­ture enhancements.Pre­vent­at­ive: pres­sure on extern­al fun­ders to make decisions with­in neces­sary timetable Pre­vent­at­ive: revised pro­cure­ment approach to sim­pli­fy require­ments and min­im­ise per­ceived con­tract­or risk Pre­vent­at­ive: estab­lish over-arch­ing aaree­ments with partners4416Fund­ing for Act­ive Com­munit­ies pro­jects now in place (Trans­port Scot­land). Con­tract­or for RIBA stages 3 and 4 design work now appoin­ted. Trans­port Scot­land fund­ing awar­ded must be used by 31 March 2026, the short time-frame put­ting pres­sure on deliv­ery. Con­tinu­ation of the pro­jects past design stage 3 will require an addi­tion­al award of fund­ing for 202627.Ongo­ing con­tact with extern­al fun­ders to secure fund­ing for 202627. Devel­op­ment of memor­andum of agree­ment with key loc­al author­ity partnerGav­in Miles02/09/2025
×

We want your feedback

Thank you for visiting our new website. We'd appreciate any feedback using our quick feedback form. Your thoughts make a big difference.

Thank you!