Risk programs have many goals, but essentially they should be designed to:
- ensure risks that could result in significant harm to business objectives are identified and assessed;
- determine appropriate responses to assessed significant risks based on the level of risk and the risk tolerances established by the Board;
- ensure Senior Management and the Board are aware of the risk assessment process, significant residual risks and related mitigation action plans, as well as instances when the business exceeds a risk tolerance
- promote risk awareness and risk management practices.