The filed record
Status Update on the City-wide Risk Governance Model
The Public Gallery wrote no story on this item. What follows is the city’s own record of what happened to it, as filed: nothing on this page is summarised or scored by us.
The decision
2023-12-13 · Toronto City Council · adopted
As filed
City Council on December 13, 14, and 15, 2023, adopted the following: 1. City Council request the City Manager, in co-ordination with the Chief Technology Officer, the Chief Information Security Officer, the Executive Director, Toronto Emergency Management, and the Director, Internal Audit, to report to the Audit Committee in the third quarter of 2024 with an update on the implementation and maturation of Enterprise Risk Management.
Show the rest of As filed, 237 more characters as filed
2. City Council request the City Manager, in co-ordination with Director, Internal Audit to work with division heads to expand the inclusion of risk management considerations into reports provided to Committees and Council as applicable.
On the agenda
As the city filed it
This report outlines the governance model, processes, and activities that will contribute to overall Enterprise Risk Management within the City. Enterprise Risk Management (ERM) is a structured, consistent, and continuous process that supports the achievement of the organization's objectives by identifying, assessing, responding to, and reporting on the full spectrum of risk, holistically across the organization. It also manages the combined impact of those risks as an interrelated risk portfolio.
Show the rest of As the city filed it, 701 more characters as filed
The report provides an overview of the proposed City-wide Risk Governance Model. The governance model outlines roles and responsibilities within the Enterprise Risk Management process with respect to oversight of risks throughout the organization, including risks pertaining to business continuity, cyber major incident, and technology disaster recovery. While divisions across the City including Technology Services, the Office of the Chief Information Security Officer and Toronto Emergency Management have employed their own processes to manage and govern their respective risks, Enterprise Risk Management takes a holistic approach to risk management looking at risks from a City-wide perspective.
Staff recommended
The Chief Technology Officer, the Chief Information Security Officer, the Executive Director, Toronto Emergency Management, and the Acting Director, Internal Audit recommends that: 1. Audit Committee receive this report for information.
Considered
2023-12-01 · Audit Committee · amended
Decision as filed
The Audit Committee recommends that: 1. City Council request the City Manager, in co-ordination with the Chief Technology Officer, the Chief Information Security Officer, the Executive Director, Toronto Emergency Management, and the Director, Internal Audit, to report to the Audit Committee in the third quarter of 2024 with an update on the implementation and maturation of Enterprise Risk Management. 2. City Council request
Show the rest of Decision as filed, 213 more characters as filed
the City Manager, in co-ordination with Director, Internal Audit to work with division heads to expand the inclusion of risk management considerations into reports provided to Committees and Council as applicable.
2023-12-13 · Toronto City Council · adopted
On the record
More from this meeting
- Auditor General’s Office 2024 Work Plan and Budget HighlightsFiled record
- Audit of the Toronto Transit Commission’s Streetcar Overhead Assets: Strengthening the Maintenance and Repair Program to Minimize Asset Failures and Service DelaysFiled record
- Toronto Transit Commission Cybersecurity Audit - Phase Two: Overall Network Security and Cybersecurity Assessment of Select Critical SystemsFiled record
- Audit of the Enterprise Work Management Solution (EWMS): Lessons Learned for Future Large Information Technology ProjectsFiled record
- Update to Winter Maintenance Program Follow-Up: Change in Contract TermsFiled record
- Status Update on the Information Technology Disaster Recovery ProgramFiled record