Purpose
Provide one integrated governance process for ethical leadership, enterprise risk management and controlled outsourcing decisions.
Policies Implemented
- POL-ESG-001 Governance Ethics and ESG Manual
- POL-RMF-001 Risk Management Framework Manual
- POL-OUT-001 Outsourcing Risk Management Manual
Trigger
The process starts when governance decisions, ethical or ESG matters, enterprise risks, outsourcing proposals, provider changes, incidents, assurance findings or scheduled reviews require assessment and action.
High-Level Flow
Identify governance or risk matter -> assess impact and ownership -> determine required approval and safeguards -> execute the applicable procedure -> monitor risk and obligations -> escalate exceptions -> report and assure -> retain evidence and improve.
Inputs
- Governance obligations, risk appetite and delegated authorities.
- Risk events, assessments, issues, incidents and assurance findings.
- Outsourcing proposals, due diligence, contracts, performance and exit information.
- Ethics, conflicts, ESG and stakeholder information.
Outputs
- Approved governance, risk and outsourcing decisions.
- Current risk, issue and outsourcing records.
- Assigned actions, safeguards, monitoring and escalation.
- Management, Board and regulatory reporting evidence.
Roles
- The Board and Managing Director set governance expectations and approve matters within their authority.
- Compliance coordinates regulatory alignment, risk challenge, outsourcing oversight and BCMS traceability.
- Business owners assess, own and treat risks and provider dependencies.
- Operations and Technology implement approved safeguards and provide evidence.
- Independent assurance tests governance, risk and outsourcing effectiveness.
Operating Model
This is a primary BCMS process. It links directly to policies, requirements, procedures, controls and systems. It does not contain or depend on subordinate PRC objects. Detailed operating steps remain in the linked PROC objects.
Relationships
- Architecture decision: ADR-003 Flatten Compliance Process Architecture
- Governance policy: POL-ESG-001 Governance Ethics and ESG Manual
- Risk policy: POL-RMF-001 Risk Management Framework Manual
- Outsourcing policy: POL-OUT-001 Outsourcing Risk Management Manual
Assurance
- Design status: implemented through approved governance, risk and outsourcing policies.
- Operating status: inherited from the linked procedures and controls.
- Evidence status: defined in the linked controls and systems.
- Overall status: implemented primary process; operating effectiveness is assessed through the linked assurance objects.
History
- 2026-07-26: Created as one of the five active processes in the flattened BCMS process architecture.