Risk Management Policy

How risks to the business, and to the hotels that depend on our software, are identified, owned and reviewed.

Awaiting legal review. The structure below is agreed. The clauses under each heading are to be drafted and approved by counsel before this page is published.

Owner: Compliance Version: Draft Applies to: All departments
01

Purpose and scope

What this policy governs, and the categories of risk it covers.

02

Governance and ownership

Who owns risk at board and department level, and how ownership is recorded.

03

Risk identification

How risks enter the register, including from incidents, audits and customer escalations.

04

Assessment and scoring

The likelihood and impact scale used, and how tolerance is defined.

05

Treatment and mitigation

Accept, reduce, transfer or avoid, and who signs off each choice.

06

Operational and service risk

Risks to availability and support of live properties, where the impact lands on a hotel rather than on us.

07

Information security risk

The interface with the Information Security Policy and its own risk process.

08

Business continuity

Continuity planning, dependencies, and the scenarios tested.

09

Monitoring and review

Review cadence, reporting to management, and how closure is evidenced.

Escalating a risk

Risks that need attention outside the review cycle should be escalated to [email protected], or directly to the department head where time matters.