Risk
RISK POLICY – Version 1.0
Purpose
To manage and mitigate risks associated with This Is Islay in fulfilling its charitable
aims and purposes, safeguarding the charities assets, ensuring financial stability and
protecting any staff and volunteers.
Scope
This policy applies to all This Is Islay activities and forms part of the This Is Islay Risk
Management Framework. It also applies to all those individuals involved, including
Trustees, employees and volunteers. In particular, it recognises the core duties of
Trustees in terms of Section 66 of The Charities and Trustee Investment (Scotland)
Act 2005.
Risk Management Framework
Being a small charity, our Framework is not extensive but is fit for purpose in listing
risk management processes, being clear about who is responsible for instigating and
managing these and ensuring that our Board regularly reviews and manages our
Risk Register and actions.
The process
1. Identification of type of risks faced
2. Analysis and evaluation of risks
3. Prioritisation in relation to likelihood and impact
4. Means of tackling and mitigating risk
5. Monitoring and review
The people
The Board of Trustees is responsible for the risk policy, for receiving risk reports,
reviewing the reports and approving actions. The Risk Register is used to ensure
effective and active management.
The Chair of the Board is responsible for ensuring that risk management is
incorporated in our day-to-day activities. They will ensure that all Trustees,
volunteers and any staff are collectively involved in improving the risk management
policy.
The Risk Register
We have a formal Risk Register which encompasses the following categories:
• Governance
• Financial
• Operational
• Compliance and regulations
• Reputation
Risks identified will be added to the register immediately. The register will be
reviewed at each management meeting and risks that are no longer considered
relevant will be removed.
The risk reports for each area of responsibility will be prepared by an identified Lead
for each risk. These will include details of the risk treatment plans. They will be
reviewed by the Board at each management meeting.
Where a risk is identified that is deemed to be of a critical nature a special
management meeting will be convened.
Risk Register Standard Example
This policy is reviewed annually.
7. Supporting quotations and evidence to support funding details
| Risk Area | Description | Likelyhood (1-5 | Impact (1-5 | Total Score (L x I | Mitigation Actions/ Controls | Owner | Review Date |
| Version Control | Change/Update | Author / Owner | Date |
| 1.0 | Initial Version | J MacLellan | 02/03/2026 |

