Skip to content

Risk Management Policy

This policy establishes guidelines for identifying, assessing, and managing information security risks at Code Town, Inc. (D/B/A “Shorebird”).

This policy outlines our approach to identifying, assessing, and managing risks related to information security.

The following policy statements outline our approach to risk management, covering all aspects from risk identification to treatment and monitoring.

Risk Tolerance defines the acceptable variation in performance relative to the company’s risk appetite. Shorebird sets thresholds based on the severity of risk impact:

  • High residual risks (e.g., regulatory non-compliance, major financial loss): These risks are treated with the highest priority, with immediate corrective actions or controls to reduce exposure.
  • Medium residual risks (e.g., operational disruptions): These are actively managed with contingency plans in place.
  • Low residual risks (e.g., minor process inefficiencies): These may be tolerated but must still be monitored to prevent escalation.

Risks exceeding the organization’s defined tolerance levels will be escalated to senior management for review and action.

Shorebird adopts a structured risk management framework to proactively identify, evaluate, and address risks. The framework includes:

  • Risk identification: Identifying risks that could affect company objectives or operations.
  • Risk assessment: Evaluating the likelihood and potential impact of identified risks using qualitative or quantitative methods.
  • Risk treatment: Applying appropriate measures to mitigate, transfer, accept, or avoid risks.
  • Risk monitoring and reporting: Continuously tracking risk levels and control effectiveness, with regular reporting to senior management.

This risk management process aligns with the company’s overall business strategy and will be reviewed periodically.

Employees and managers assess risks regularly and log them in a risk register. Each risk is evaluated based on:

  • Likelihood: Probability of occurrence.
  • Impact: Potential severity (e.g., financial loss, reputational damage, regulatory penalties).

Risks are rated as high, medium, or low, based on the likelihood and impact combined. See Appendix A for the likelihood and impact scales, the risk matrix, the scoring formula, and the residual risk acceptance criteria.

Once risks are identified and assessed, appropriate strategies are applied to manage them according to the risk tolerance. Treatment options include:

Treatment Description
Mitigation Implementing controls to reduce the risk’s likelihood or impact
Avoidance Modifying business activities or processes to eliminate the risk entirely
Transfer Shifting the risk to a third party (e.g., insurance, outsourcing)
Acceptance Recognizing the risk and choosing to accept it if the potential impact is within acceptable tolerance levels

Each identified risk must have a risk owner and a documented treatment plan, including deadlines, responsible parties, and required resources.

Risk monitoring occurs continuously, with reviews of control effectiveness on annual basis.

Any significant changes to risks are updated in the risk register and communicated to senior management.

Compliance with this policy is mandatory for all employees, contractors, and third parties with access to Shorebird’s data.

In rare cases, business needs, local laws, or regulations may require exceptions. Management will approve any exceptions and define alternative solutions.

Non-compliance may lead to disciplinary action, including termination, as per Shorebird’s policies.

This policy will be reviewed annually or when significant changes occur to maintain its continuing suitability, adequacy, and effectiveness.

Reviews must consider changes in the regulatory landscape.

Shorebird scores each risk using a qualitative 3×3 model:

Risk Score = Likelihood × Impact

Score Rating Description
3 Very likely Expected to occur frequently if not actively managed
2 Likely Could occur occasionally under normal circumstances
1 Unlikely Rare or exceptional circumstances needed for occurrence
Score Rating Description
3 Major Significant impact on strategic objectives, financial stability, or reputation
2 Moderate Noticeable operational, financial, or reputational effects
1 Minor Minimal impact; easily managed with routine processes
Likelihood ↓ / Impact → 1 (Minor) 2 (Moderate) 3 (Major)
3 (Very likely) 3 (Medium) 6 (High) 9 (High)
2 (Likely) 2 (Low) 4 (Medium) 6 (High)
1 (Unlikely) 1 (Low) 2 (Low) 3 (Medium)
Risk Score Rating
6–9 High
3–5 Medium
1–2 Low

Residual risk is the risk remaining after existing controls have been applied, calculated as:

Residual Risk Score = Likelihood (after controls) × Impact (after controls)

Residual risks are evaluated against Shorebird’s defined risk tolerance to determine whether additional treatment is required:

  • Low residual risk (score 1–2): Acceptable. May be accepted by the assigned Risk Owner, subject to ongoing monitoring.
  • Medium residual risk (score 3–5): May be accepted where justified, documented in the risk register, and approved by the relevant Department Head or Senior Management. Additional treatment should be considered where practical and cost-effective.
  • High residual risk (score 6–9): Exceeds Shorebird’s normal acceptance threshold and must be treated with priority through mitigation, avoidance, or transfer. Acceptance is permitted only in exceptional circumstances with documented business justification and formal approval from Senior Management.

All accepted residual risks must be recorded in the risk register, including the reason for acceptance, the approval authority, the assigned risk owner, and the review date.