PHIG Policy Framework v1.2 · Policy 38 · Adopted 1 September 2026 · References: ASF Policy 34; EU MGA Art. 13 (implementation) and risk assessment practice; 2 CFR 200.303; ISO 31000 (reference)
1. Purpose and scope
To identify, assess and manage the risks to PHIG’s mission, people, funds, data and reputation, and to keep essential services running through disruption. Applies to the Board, the Director, staff, consultants, volunteers, experts, partners and suppliers of PHIG and all platforms of its network.
2. Policy
- A risk register is maintained covering strategic, financial, operational, compliance, security, reputational, IT and project risks, each rated by likelihood and impact with an owner and mitigation.
- The Board reviews the register at least twice a year; new grants and programmes add their risks at the planning stage.
- Business continuity plan: critical functions (websites and feeds, journal publishing, courses, finance, communications), recovery objectives, backups and alternative hosting, key-person dependencies and deputies, contact lists; tested annually.
- Insurance reviewed annually (liability, travel, assets).
- Key-person risk: the Chair’s functions have a designated deputy and documented procedures (see the handover documentation of the network).
3. Procedures
- Risk register template; continuity plan; annual test and Board report.
Responsibilities
Board; Director.
Review
Every two years and when donor rules change.
Part of the PHIG Policy Framework. Breaches and concerns may be reported under the Whistleblowing Procedure to info@accreditation.ge (subject “Confidential — integrity”).