Risk Management Policy
How risks to the business, and to the hotels that depend on our software, are identified, owned and reviewed.
Awaiting legal review. The structure below is agreed. The clauses under each heading are to be drafted and approved by counsel before this page is published.
Purpose and scope
What this policy governs, and the categories of risk it covers.
Governance and ownership
Who owns risk at board and department level, and how ownership is recorded.
Risk identification
How risks enter the register, including from incidents, audits and customer escalations.
Assessment and scoring
The likelihood and impact scale used, and how tolerance is defined.
Treatment and mitigation
Accept, reduce, transfer or avoid, and who signs off each choice.
Operational and service risk
Risks to availability and support of live properties, where the impact lands on a hotel rather than on us.
Information security risk
The interface with the Information Security Policy and its own risk process.
Business continuity
Continuity planning, dependencies, and the scenarios tested.
Monitoring and review
Review cadence, reporting to management, and how closure is evidenced.
Escalating a risk
Risks that need attention outside the review cycle should be escalated to [email protected], or directly to the department head where time matters.