Risk management
Risk management
Risk management is essential to the effective running of Greater Manchester Pension Fund (GMPF).
Risk management aims to provide an effective way of identifying, evaluating and understanding risks so that these can be mitigated and allow GMPF to achieve its objectives.
It’s important to realise that you cannot eliminate risk, but you can take actions that can reduce any adverse impact on service delivery. Continual monitoring by officers of GMPF can help to control risks. Officers look to design and implement appropriate measures to reduce the impact of the risks identified, wherever it is cost effective to do so.
Risk management follows a reiterative cycle that involves identifying risk, analysing it, controlling it and then monitoring it. Officers continually assess risk as part of this reiterative cycle and judge the probability of events occurring against the potential impact.
As part of its risk management process, GMPF’s senior management team review the high level risk register each month, analysing the key risks on a strategic and operational level. They judge all risks in the risk register following the corporate risk management policy.
You can find GMPF's latest risk register within the last Management Panel or Local Board meeting papers.
Cyber risk is the probability of exposure or loss resulting from a cyberattack or data breach. It is the potential loss or harm related to technical infrastructure, use of technology or reputation of an organisation. As we and our partners become increasingly reliant on computers and IT networks, we become more vulnerable to cyber threats. This is one of our greatest risks.
Cybersecurity refers to the technologies, processes and practices designed to protect an organisation's intellectual property, customer data and other sensitive information from unauthorised access by cyber criminals. The frequency and severity of cybercrime is on the rise and there is a significant need to continually improve our cybersecurity risk management.
Our cyber footprint is the total extent of the digital presence of all the parties involved in running our Scheme, both internal and external.
The Pensions Regulator has produced cyber security principles for pension schemes that help guide the approach pension schemes should take.
Data risk is another high risk area due to the amount of personal data we hold.
The Pension’s Regulator expects funds to regularly review the quality of the scheme data they hold and to calculate common and scheme specific data scores. The Regulator expects us to review our scheme data at least once a year and to provide confirmation of our data scores every year in our scheme return.
The Fund will have regular interactions with the Pensions Regulator. As a minimum, the Fund must submit a scheme return to the Pensions Regulator annually and report any material breaches to The Pensions Regulator when they arise.