Adopting a Risk-Based Approach: A Guide for Public Procurement Professionals

April 13, 2023

As public entities continue to deliver essential public services against an evolving landscape, procurement professionals play a critical role to ensuring the ethical and effective expenditure of public funds in order for public entities to meet the evolving needs of its communities. Through their work, procurement professional are critical in providing value and managing risks.

With the uptake of risk management by public entities and procurement professionals, it has further enabled their ability to deliver on their mandate while creating additional value through the effective management of risks associated with the purchase of specific goods and services. The benefits include:

  1. Focus on portfolio of risks;
  2. Insight into correlation of risks across the organization; and
  3. Adoption of a blend of controls to manage risks.

While traditional focus has been placed on managing risks through the use of risk transfer (e.g. insurance) techniques, there exists a knowledge and practice gap as there has been limited information made available to procurement professionals that provides guidance on the application of a risk-based approach that allows for the holistic management of risks through a blend of risk controls (e.g. prevention, mitigation, transfer).

A Risk Based Approach to Procurement

To support public entities and procurement professionals in adopting a risk-based approach to their work, the following outlines a structured approach that can be applied by procurements professionals. Specifically, the framework will enable procurement professionals to:

  1. Identify the risks to the public entity or third-parties; 
  2. Assess the risks using a standardized methodology; and
  3. Determine the risk controls, including insurance types, appropriate to the risk.

Through a risk-based approach, the key components that warrant focus are in the areas of: risk Identification, risk assessment, and risk control

Risk Identification

A risk-based approach starts with identifying potential, actual, or emerging risks. To achieve this, the following steps can be taken to identify the risks facing the organization:

  1. Stakeholder Engagement: Engage stakeholders to get feedback on potential, actual, or emerging risks. This can include using: surveys, interviews, and brainstorming;
  2. Case Scenarios: Engage in a discussion that centers on the best and worst case scenarios associated with the identified risks; and
  3. Identify Risks: Document the full list of risks identified by stakeholders and facilitate dialogue to gain a better understanding of risk it poses.

As part of this step, consider the risks that apply to the following areas within the organization: 

OPBA RiskIdentification April2023

Risk Assessment

Once the list of risks has been identified and compiled, the next steps it to assess the degree of impact and uncertainty it poses. To achieve this, the following steps can help to assess the risks:

  1. Establish Standardized Tool: Develop a standardized assessment tool that can be used by stakeholders to rate the risks;
  2. Evaluate the Risks: Support the stakeholders as they complete the evaluation of the risks against the following criteria:  likelihood, impact and velocity of risks.
  3. Validate the Rankings: Facilitate a discussion with the stakeholders to review the list of risks and discuss the risk scores; adjustments should be made as required; and
  4. Rank the Risks: Based on the adjusted and final risk ratings, the risks should be ranked accordingly to inform risk control initiatives.

Risk Control

Once the risks have been ranked, the next step is to implement the appropriate blend of risk controls to achieve the desired effect. In support of this, the following steps can be taken:

  1. Control in Layers: Implement a blend of different controls to treat the risks in varying manners; this can include a mix of controls aimed to prevent, mitigate, or transfer the risks.  
  2. Implement Broadly: Apply a broad lens when applying risk controls; consider implementing  controls across the enterprise and at different levels of the organization; and
  3. Balance the Controls: Implement a balanced approach to risk controls; don’t rely too heavily on a single type of control (e.g insurance); in an ideal scenario, there should be a mix of risk controls within the organization. 

OPBA RiskControl April2023

Powered by MediaEdge Publishing and Blogging Services
© Copyright 2026