Board Assurance Framework and Corporate Risk Register Report

Similar documents
To be an active partner, always ready to improve by working with others

REPORT 2015/149 INTERNAL AUDIT DIVISION

Birmingham Community Healthcare NHS Foundation Trust. 2017/17 Data Security and Protection Requirements March 2018

Policy. Business Resilience MB2010.P.119

Information backup - diagnostic review Abertawe Bro Morgannwg University Health Board. Issued: September 2013 Document reference: 495A2013

NHS WALES INFORMATICS SERVICE DATA QUALITY ASSURANCE NATIONAL STATISTICS

Audit and Compliance Committee - Agenda

The ehealth Annual Report aims to highlight the activities within the teams that make up the ehealth Department.

Ventilation Policy Type: Policy Register No: Status: Public. Developed in response to: Contributes to CQC Outcome number: Outcome 8 and 10

ISO STANDARD IMPLEMENTATION AND TECHNOLOGY CONSOLIDATION

Reviewed by ADM(RS) in accordance with the Access to Information Act. Information UNCLASSIFIED.

IT Progress Report. Presented by: Owen Brady Director of Information Technology. Board. 19 th March 2015

Aneurin Bevan Health Board

SCHEME OF DELEGATION (Based on the model produced to the National Governors Association)

Use Of Mobile Communication Devices Within Healthcare Premises Policy

Public Safety Canada. Audit of the Business Continuity Planning Program

Bicycle Access & Parking Plan Project List Review

Procedure re-written. (i.e. All staff with responsibility for the creation, use and management of organisational responsibility)

SUBJECT: PRESTO operating agreement renewal update. Committee of the Whole. Transit Department. Recommendation: Purpose: Page 1 of Report TR-01-17

Manufacturing Skills Australia Training Package Continuous Improvement Plan Release 2, January 2015

FRIENDS AND FAMILY TEST IN GENERAL PRACTICE

INFORMATION SECURITY AND RISK POLICY

New Zealand Customs Service: Managing Trade Assurance capability risks

FRIENDS AND FAMILY TEST IN GENERAL PRACTICE

AUDIT OF ICT STRATEGY IMPLEMENTATION

Policy on the Provision of Mobile Phones

How we do ehealth in NHS Scotland

Academic Program Review at Illinois State University PROGRAM REVIEW OVERVIEW

TxDOT Internal Audit Materials and Testing Audit Department-wide Report

ALBEMARLE COUNTY SERVICE AUTHORITY

HSCIC Audit of Data Sharing Activities:

Data Encryption Policy

Chapter 35 ehealth Saskatchewan Sharing Patient Data 1.0 MAIN POINTS

Management s Response to the Auditor General s Review of Management and Oversight of the Integrated Business Management System (IBMS)

Wye Valley NHS Trust. Data protection audit report. Executive summary June 2017

SALISBURY NHS FOUNDATION TRUST. TITLE - Information Strategy Annual Review

Director, Major Projects and Resilience. To: Planning and Performance Committee 6 November 2014

REPORT 2015/010 INTERNAL AUDIT DIVISION

Short Guide to using the Report Template (Version 3)

ERO Enterprise Strategic Planning Redesign

BENEFITS of MEMBERSHIP FOR YOUR INSTITUTION

Working Together to Create Sustainable Success. APICS Board of Directors Meeting Update April 2012

Audit Report. Mineral Products Qualifications Council (MPQC) 31 March 2014

CHAIR AND MEMBERS CIVIC WORKS COMMITTEE MEETING ON NOVEMBER 29, 2016

SAMPLE REPORT. Business Continuity Gap Analysis Report. Prepared for XYZ Business by CSC Business Continuity Services Date: xx/xx/xxxx

Process Definition: Security Services

Provider Monitoring Report. City and Guilds

The Smart Campaign: Introducing Certification

GMSS Information Governance & Cyber Security Incident Reporting Procedure. February 2017

Ministry of Government and Consumer Services. ServiceOntario. Figure 1: Summary Status of Actions Recommended in June 2016 Committee Report

CERTIFIED IN THE GOVERNANCE OF ENTERPRISE IT CGEIT AFFIRM YOUR STRATEGIC VALUE AND CAREER SUCCESS

DAC EVALUATION INVENTORY AS A POTENTIAL KNOWLEDGE BUILDING TOOL. Submitted by Canada

Current status and next steps. Haileyesus Getahun Coordinator IACG Secretariat World Health Organization

Dated 3 rd of November 2017 MEMORANDUM OF UNDERSTANDING SIERRA LEONE NATIONAL ehealth COORDINATION HUB

Service Improvement Review of Guarding:

REPORT ON TELECOMMUNICATIONS SERVICE QUALITY WINDSTREAM FLORIDA, INC.

NHS Fife. 2015/16 Audit Computer Service Review Follow Up

REPORT 2015/186 INTERNAL AUDIT DIVISION

NEWCASTLE CLINICAL TRIALS UNIT STANDARD OPERATING PROCEDURES

Post-accreditation monitoring report: British Computer Society (BCS) September 2006 QCA/06/2926

Continuing Professional Development: Professional and Regulatory Requirements

FedRAMP: Understanding Agency and Cloud Provider Responsibilities

NORTH CAROLINA NC MRITE. Nominating Category: Enterprise IT Management Initiatives

STRATEGIC PLAN

INFORMATION GOVERNANCE. Caldicott Approval Procedure

Chapter 18 SaskPower Managing the Risk of Cyber Incidents 1.0 MAIN POINTS

Audit Report. Chartered Management Institute (CMI)

Organizational Structure of the Toronto Environment Office

Ervia Risk Management. Elaine O Donoghue IPA Governance Forum Briefing 10 th November 2017

General Information Technology Controls Follow-up Review

BCI Principles & Criteria: Revision

Community Development and Recreation Committee

REPORT Bill Bradbury, Secretary of State Cathy Pollino, Director, Audits Division

Single Academy Trust Structure

CABINET PLANNING SYSTEM PROCUREMENT

NATIONAL INFRASTRUCTURE COMMISSION CORPORATE PLAN TO

Technical Advisory Board (TAB) Terms of Reference

REVIEW OF MANAGEMENT AND OVERSIGHT OF THE INTEGRATED BUSINESS MANAGEMENT SYSTEM (IBMS) January 16, 2009

How to Become a CMA (Certified Management Accountant) May 10, 2017

OCM ACADEMIC SERVICES PROJECT INITIATION DOCUMENT. Project Title: Online Coursework Management

Cancer Waiting Times. Getting Started with Beta Testing. Beta Testing period: 01 February May Copyright 2018 NHS Digital

CCS NHS Trust EPRR Core Standards Work Plan & Schedule (attached below).

Public Disclosure Copy

Working with Health IT Systems is available under a Creative Commons Attribution-NonCommercial- ShareAlike 3.0 Unported license.

0522: Governance of the use of as a valid UNC communication

ISO Certification For Laboratory Accreditation. Dr Amadou TALL Consultation

Customer Service Excellence Response Audit (QM054c) Department: Quality Assurance. Summary by: Nassir Ahad (Quality Improvement Auditor)

Haringey CCG Performance and Quality Dash Board January 2015

Accessibility and Usability Standards Procurement Checklist

Reliability & Resiliency in the US Capitol Region/Hardening the Grid One Year after Hurricane Sandy

Procedure for Handling Third Party Requests to Access Data on eportfolio

WHO-ITU National ehealth Strategy Toolkit

BOARD OF DIRECTORS (OPEN) Meeting Date: 14 th November 2018

PFE Online Application Help File

Standard Development Timeline

The Defence Nuclear Enterprise: a landscape review

Energy Step Code Implementation Strategy. March 26, 2018

* - Note: complete submissions are to be submitted at least two weeks before any deadline to ensure timely closure.

Overview of ABET Kent Hamlin Director Institute of Nuclear Power Operations Commissioner TAC of ABET

Internal Audit Follow-Up Report. Multiple Use Agreements TxDOT Office of Internal Audit

Transcription:

Trust Board Meeting in Public: Wednesday 9 th November 20 Title Board Assurance Framework and Corporate Risk Register Report Status History For discussion The full BAF and CRR was reported to the: Audit Committee in April and September 2015, February and April 20. Trust Board in November 2015 and May 20. Trust Management Executive on 9 July and 12 November 2015 and 28 January, April 20, 25 August and 26 October 20. Extracts of relevant risks from the CRR and the BAF were reported to: Quality Committee in June, October and December 2014; February 2015. CRR: June and August 2015, CRR and BAF: December 2015, February 20 and April 20 Finance & Performance Committee in June, October and December 2014; February 2015. CRR: June and August 2015, CRR and BAF: December 2015, February 20 and April 20 Updates of relevant risks from the CRR were reported to Trust Management Executive on 2 and 7 August, 24 September and 8 October 2015 Board Lead(s) Eileen Walsh, Director of Assurance Key purpose Strategy Assurance Policy Performance Board Assurance Framework and Corporate Risk Register Report Page 1 of 7

Executive Summary 1. This paper provides a summary of the developments to the Board Assurance Framework made during 20/17 and following the approval of the Trust s Strategic Objectives. 2. It also provides the results of the Quarter two review of the Corporate Risk Register and a summary of changes to the risk register for the Board s review and discussion. 3. The Trust Board is asked to: Note the continued development of a new Board Assurance Framework Approve the changes to the CRR, risk scores, and escalated risks. Board Assurance Framework and Corporate Risk Register Report Page 2 of 7

1. Introduction 1.1. This paper provides an opportunity for the Trust Board to review the Board Assurance Framework (BAF) and Corporate Risk Register (CRR) following the Quarter two review results as presented to the Trust Management Executive on 27 th October. 1.2. The development of the new strategic themes provided the Assurance Directorate with an opportunity to develop a new version of the Board Assurance Framework. 1.3. This paper provides the following: A summary of the development of the BAF for 20/17, Ongoing changes to risks held in the current version of the CRR, following consultations with the risk leads and approval by Trust Management Executive in October. 2. Board Assurance Framework 2.1. The existing Board Assurance Framework has been in place from April 20 until September 20, aligned to the Trust s strategic objectives in place for that time period. 2.2. Aligned to the Sustainability and Transformation Plan (STP) for Oxfordshire; there has been a review of the Trust strategy which has identified the following strategic themes: 2.3. Following the development of the strategic themes, a new set of strategic objectives were formally approved by the Trust Board on 14th September 20. These new objectives now form the basis of the new BAF. 2.4. The Trust has used the opportunity of the new objectives to launch a new approach to the presentation of the BAF going forward. As part of this research conducted to inform this new approach, the Trust considered the findings of a KPMG study in 2015, which reviewed various approaches to best practice for Board Assurance Framework and Corporate Risk Register Report Page 3 of 7

Board Assurance Frameworks. The report reviewed areas of weakness within organisations, the quality of information and sources of assurance contained within a range of Board Assurance Frameworks. 2.5. As a result, the Trust has developed a digital BAF tool that is designed to streamline resources and reflect the new strategic themes. The new BAF uses strong assurance mapping methodology, presented in a clear and visual format using the principles of mapping the existing risks on the CRR to the new themes. 2.6. The updated BAF is currently a work in progress. The aim is that it should act as a more effective tool to provide assurance to the Board on plans to deliver the Trust s new Strategic Objectives over the next 3-5 years. 2.7. The following provides a brief summary of developments to the Board Assurance Framework: Existing BAF was remapped to the new Strategic themes / strategic objectives as approved by the Board in September 20. Each theme has a page in the new BAF. Current risks were mapped to the revised BAF, albeit there are some themes that are new and demonstrate a different focus for the trust. These have fewer risks mapped to them. The Assurance Team are working with the relevant Theme Lead to review and populate each page. A new BAF template was developed to more clearly map risk, control and assurance, also to bring in a direct link to the Key Performance Indicators (KPIs) that help demonstrate that performance is on track or moving towards the strategic goals. These will be further developed through Board subcommittees and Trust Management Executive review over time. This will include a link to the operational Corporate Risk Register as part of the risk map. A feedback loop was added to capture queries in relation to gaps in control and gaps in assurance, with a cross reference between risk owners (where they are different from the overarching theme owner). 2.8. A draft outline of the proposed Board Assurance Framework has been shared with the chairs of the Board sub-committees. Their feedback is helping to shape the final framework which will be discussed in detail by the Trust Board at its next seminar meeting in late November 20. 2.9. The Assurance Directorate is working with the theme owners to continue to populate the BAF as plans and KPIs are developed. It is proposed that a revised version of the new BAF is presented to the Board in January 2017. Board Assurance Framework and Corporate Risk Register Report Page 4 of 7

3. Review of the Existing Corporate Risk Register 3.1. This quarterly review was completed with the help and support of Divisional Governance Leads and Executive Directors or nominated representatives. A full copy of the detailed register is available at the following hyperlink. a Corporate Risk Register Update v2.docx 3.2. From this review, the TME were asked to discuss two key areas. New risks for escalation on to the CRR Changes in risk scores and risks proposed for archive Changes to the CRR 3.3. This review of the CRR for 20/17 was conducted with all the risk leads. Full list of all risks on the CRR is provided as Appendix 1. New risks / risks for escalation 3.4. The following risks were accepted as new risks or for escalation to the CRR by the Divisions and Risk Leads. Escalated by CD CD MRC Risk Description Failure to implement actions following the CQC Improvement Notice which could result in the contravention of IRMER Regulations 2000. It was noted that there were issues with documentation controls with incomplete training records and monitoring compliance. Risk of lower quality care for patients as some policies and Standard Operating Policies are not updated in accordance with the Trust Policy. This may result in staff potentially following out of date policies Potentially unable to sustain Emergency Department (both JR and HGH)middle grade rota due to recruitment difficulties Changes to Risk Scores Board Assurance Framework and Corporate Risk Register Report Page 5 of 7 Risk Score 3 x 3 4 x 3 4 x 3 Table 1: Risks for inclusion onto CRR 3.5. TME accepted to risk scores as a result of the review, with one having met target. The changes are presented in table 2. The red italics in the risk descriptions summarise the reasons for change. New Risk Risk Description ID 4.1 Unsuitable outpatient accommodation in Clinical Genetics Department at the Churchill A solution has been found for the Genetics Service to relocate to the ACE building on the NOC site. Refurbishments of the area are in the process of being planned to come on line during October. It is likely that the relocation will take place towards the end of November estates works permitting. 5.1 Patients experience indicators show a decline in quality. Improved results from patient experience indicators 5.5 Inability to continue to supply stock medicines to wards and Trust dispensaries Sep- Oct- Trend Distanc e from 12 6 3 3 6 4 2 2 Plan to improve staff accommodation is in progress and the 12 2 10 space created will need to be converted to medicines storage 7.1 Insufficient provision of appropriate education and 9 6 3 3

New Risk ID Risk Description learning development opportunities Sep- Oct- Trend Distanc e from Controls in place are working to reduce the risk 8.4 Potential risk of failing to respond to the results of diagnostic tests Results show improvements and actions monitored through Clinical Governance Committee monthly 8.5 Potential risks to handover of treatment through poor communication of discharge summaries Results show improvements and actions monitored through Clinical Governance Committee monthly Impact of changes to specialist services tariff 10 8 4 4 10 8 4 4 8.7 8.14 Two year tariff proposals published along with a note from NHSI that they are not considering introducing a marginal rate for specialised services for 2017 to 2019. ** to be considered for archive** Excessive use of agency staff may pose a risk to the quality of service delivered reviewed and reduced from 3 to 2 9 6 4 4 to archive 8-2 Change to target 2 2 Table 2: Changes to risk scores 3.6. TME discussed the current situation with ED performance regarding the national standard for 4 hours. The Trust performance has dropped and following detailed discussions it was agreed that the risk score for this risk should be increased to 20, based on the fact that likelihood had increased from a score of 4 to now being a score of 5. It was agreed that a series of actions would be implemented to reestablish control and to improve the performance in a sustained manner. 4. The Trust Board is asked to: Note the continued development of a new Board Assurance Framework Approve the changes to the CRR, risk scores, and escalated risks. Eileen Walsh, Director of Assurance November 20 Report prepared by: Clare Winch Deputy Director of Assurance and Catherine Pearson Assurance Manager Board Assurance Framework and Corporate Risk Register Report Page 6 of 7

Appendix 1 Corporate Risk Register in order of Highest Rank Old New Risk ID Risk ID Risk Description Proximity Mar- (Y/E) Sep- Oct- Trend Distance f rom Movement to since y/e 15/ 3.3 6.1 Failure to deliver National A&E targets and increasing level of delay impacting on patient flow 3-12 mth 20 6 14 0 4.2 1.1 Lack of robust plans across healthcare systems / Failure to reduce activity through robust demand management plans 3-12 mth 6 10 0 2.1 6.3 Potential failure to deliver the required levels of CIP 3-12 mth 9 7 0 2.7 6.4 Risk of not hitting Trajectories to access Sustainability and Transformation Fund 3-12 mth new 9 7-3.10 4.4 Capacity of AICU/CICU does not meet demand 3 12 12 12 6 6 0 6.1 5.3 Difficulty recruiting and retaining high-quality staff in certain areas. 3 12 12 12 8 4 4 1.31 5.5 Inability to continue to supply stock medicines to wards and Trust despensaries 3-12 mth 12 2 10 new risk 2.8 6.2 Loss of funding if contractual CQUIN targets not met 3-12 mth new 12 12 4 8-12 7.8 8.1 Building issues in the Women's Centre could lead to patient safety issues 3 12 12 12 3 9 0 6.5 8.2 Potential for reduced staffing levels in maternity service 3-12 mth 9 12 12 4 8-3 1.10 8.3 CAS Alert NPSA 2011/PSA001 Part b 1.30 5.4 Implementation of the Horton contingency plan results in potential adverse outcomes now - 3 12 12 12 6 6 0 new 10 n/a TBC #VALUE! tbc 3.7 4.2 Inability to meet the Trust needs for capital investment 3-12 mth 9 9 9 6 3 3 3.9 4.3 Access to hospital site and current car parking constraints across the trust 3 9 9 9 6 3 0 3.4 6.5 Failure to deliver National Access targets 18 weeks incompletes, failure to deliver 1% or less for diagnostic waits within 6 weeks 3-12 mth 6 9 9 3 6 0 3.6 6.6 Failure to deliver National Access targets Cancer - (62 day cancer standard) 3-12 mth 9 9 9 6 3 0 2.2 6.8 Potential failure to effectively control pay and agency costs. 3-12 mth 9 9 9 9 0 7 7.12 8.6 Failure to Generate hot water and heat in retained parts of the Churchill estate 9 9 9 3 6 3 7.5 3.3 Potential failure to obtain the clinical advantages from EPR 3-12 mth 8 8 8 6 2 0 3.11 8.4 Potential risk of failing to respond to the results of diagnostic tests 3 8 10 8 4 4-10 3.12 8.5 Potential risks to handover of treatment through poor communication of discharge summaries 3 15 10 8 4 4-10 1.14 3.1 Poor clinical records management processes have a potential impact in quality and safety 3 6 6 6 4 2 3 3.2 3.2 Potential failure of accurate reporting and poor data quality due to implementation of the EPR 3-12 mth 6 6 6 4 2 0 1.29 4.1 Unsuitable outpatient accommodation in Clinical Genetics Department at the Churchill 3 15 12 6 3 3-12 1.3 5.2 Failure to meet the Trust s Quality Strategy goals. 6 6 6 4 2 0 2.4 6.7 Services display poor cost-effectiveness 3-12 mth 6 6 6 4 2 0 6.3 7.1 Insufficient provision of appropriate education and learning development opportunities 3-12 mth 6 9 6 3 3 0 1.21 8.8 Out of hours care (Care 24/7) 3-12 mth 9 6 6 3 3 3 1.24 8.9 TIE failure between EPR and CRIS poses a risk to accurate data recording and reporting 3-12 mth 6 6 6 3 3 0 1.26 8. 10 Failure to comply with NICE Quality Standard 13 End of Life Care (now a CQUIN) 3 6 6 6 3 3 6 6.2 8.11 Low levels of staff satisfaction 3-12 mth 6 6 6 3 3 2 1.17 8.12 Aspects of Medicine Management identified as needing improvement 3-12 mth 5 5 5 3 2-1 1.1 5.1 Patients experience indicators show a decline in quality. 4 6 4 2 2 0 1.9 8.13 CAS Alert NPSA 2011/PSA001 Part A 3-12 mth 4 4 4 3 1 4 1.15 8.14 Excessive use of agency staff may pose a risk to the quality of service delivered 3 4 4 4 2 2 5 n/a 8.15 Failure to implement actions arising from CQC Improvement Notice n/a 8. Risk that outdated Trust Policies may have an impact upon the quality of care n/a 8.17 Emergency Department (both JR and HGH) risk to middle grade rota as insufficient permanent team new 9 new 12 new 12 new ris k 3 new ris k 3 new ris k 2 6 new risk 9 new risk 10 new risk Link to the Full Corporate Risk Register is here Board Assurance Framework and Corporate Risk Register Report Page 7 of 7