Regulations on Risk Management
at the National Aerospace University
«Kharkiv Aviation Institute»
QMS KhAI-NMV-P/007:2019
Date of Enactment: April 20, 2019
Revision No. 2
1. Purpose and Scope of Application
1.1 These Regulations establish the rules and procedures for planning, organizing, and managing risks at the National Aerospace University «Kharkiv Aviation Institute» (hereinafter referred to as the University), and also define the procedure for detecting, identifying, analyzing, and evaluating risks, conducting measures to eliminate them and their root causes in order to prevent their recurrence, as well as documenting their results.
1.2 These Regulations have been developed in accordance with the requirements of Clause 6.1 of ISO 9001 and DSTU ISO 9001, and Clause 6.1 of the Regulations «On the Quality Management System» QMS KhAI-NMV-P/013.
1.3 The requirements of these Regulations apply to the activities of the University management, heads of structural units, and other officials, and are mandatory for application in all structural units falling within the scope of the University's quality management system when determining, evaluating, and managing process risks.
2. Normative References
These Regulations contain references to the following normative documents:
1) QMS KhAI-NMV-P/013:2019 Regulations «On the Quality Management System»;
2) QMS KhAI-NMV-P/011:2019 Regulations «Planning and Conducting Internal Audits»;
3) QMS KhAI-NMV-RI/001:2019 Instruction «Management Review»;
4) QMS KhAI-NMV-RE002:2019 Instruction «Nonconformity and Corrective Actions»;
5) DSTU ISO 9000:2015 Quality management systems. Fundamentals and vocabulary (ISO 9000:2015, IDT);
6) DSTU ISO 9001:2015 Quality management systems. Requirements (ISO 9001:2015, IDT);
7) DSTU IEC/ISO 31010:2013 Risk management. Risk assessment techniques (IEC/ISO 31010:2009, IDT);
8) QMS KhAI-NMV-F.UR/001 Risk Passport;
9) QMS KhAI-NMV-F.UR/002 Planned vs. Actual Risk Elimination Measures;
10) QMS KhAI-NMV-F.UR/003 Risk Analysis Report in a Structural Unit / Process;
11) QMS KhAI-NMV-F.UR/004 Consolidated Risk Analysis Report at the University.
3. Terms and Definitions
The following terms and definitions are used in these Regulations:
3.1 data - facts about an object;
3.2 information - meaningful data;
3.3 documented procedure - an internal normative (organizational) document containing a prescribed way to perform a process (work);
3.4 process - a set of interrelated or interacting activities that transforms inputs into outputs;
3.5 risk - a probable event that may ultimately affect the achievement of the University's strategic and operational objectives;
3.6 risk management - processes related to risk identification, analysis, and decision-making, which include maximizing positive consequences and minimizing negative consequences of the occurrence of risk events;
3.7 risk management (management) - coordinated activities to direct and control an organization with regard to risk;
3.8 risk owner - the head of a unit whose strategic or operational objectives are directly affected by this risk. The risk owner is responsible for identifying, evaluating, and monitoring risk management;
3.9 risk management system - a set of processes, methods, and information systems aimed at achieving the goals and objectives of risk management;
3.10 risk passport - a document containing all available information about a risk.
4. Abbreviations
The following abbreviations are used in these Regulations:
QMS - quality management system;
EMD - Educational and Methodological Department;
RM - risk management.
5. Description of the Procedure
5.1 Process Inputs and Outputs
The inputs of the process are internal information from components of the QMS process monitoring system regarding the activities of the University and/or a structural unit/process, and the external environment.
The outputs of the process are the risk passport of the University and/or a structural unit/process, the plan-report of risk elimination measures, documented information on the results of the implementation of these measures for the University and/or a structural unit/process, and the consolidated risk analysis report at the University.
5.2 Responsibilities and Authorities
5.2.1 The University personnel responsible for fulfilling the requirements of these Regulations is the University's Chief Quality Manager.
5.2.2 The Lead Auditor is responsible for evaluating the satisfaction of risk management process participants with the actual conditions and results of its implementation.
5.2.3 Heads and employees of structural units are responsible for the timely identification of probable risks and the implementation of actions to avoid risk, eliminate the source of risk, or change the conditions for its occurrence.
5.2.4 Heads and employees of structural units are responsible for timely reporting on the implementation of the requirements of these Regulations toсил the Lead Auditor.
5.3 General Provisions
5.3.1 The risk management process is implemented to identify, analyze, evaluate, and eliminate risks and their root causes in order to prevent their recurrence.
5.3.2 The main objectives of the process are to guarantee the achievement of strategic goals and support the effectiveness of the University's QMS.
5.3.3 Tasks of the risk management process:
- identification and evaluation of risks affecting the achievement of the University's strategic goals;
- ensuring measures to minimize the probability and negative impact of risks on the University's goals;
- strategic planning of the University's activities taking risks into account;
- timely notification of the Lead Auditor and interested parties about the presence of potential risks;
- monitoring of risk control measures;
- identification, evaluation, and management of risks associated with the University's processes;
- providing information on risks during managerial decision-making;
- formation of a plan of measures for risk elimination;
- coordination, provision, and evaluation of the effectiveness of timely response to risks;
- generation of proposals for improving the processes of the University's QMS.
5.3.4 The process owners are the University Chief Quality Manager and the Lead Auditor.
5.3.5 Participants in the process are the heads of structural units/processes and employees of structural units.
5.3.6 Information, material, financial, and human resources are used to implement the process.
5.3.7 Feedback mechanism - evaluation of the satisfaction of participants in this process with the actual conditions of its implementation.
5.3.8 An example of a list of probable risks that may arise in QMS processes and the University's activities is given in Table 1.
Table 1
| Process Name | Risk Name | Risk Factors |
| Management Processes | ||
| 1. PLANNING | Financial Risk | Unforeseen inflation, tax increases. Incorrect planning and allocation of budget funds (inefficient expenditure of finances), insufficient qualification of employees engaged in planning at the University, etc. |
| Legal Risk | Changes in the legislation of Ukraine and its imperfection, etc. | |
| 2. ORGANIZATION OF THE QUALITY MANAGEMENT SYSTEM | Failure to implement planned measures for the organization of the quality management system | Lack of financial resources at the University for training QMS employees, insufficient qualification of internal auditors and University staff. |
| 3. MONITORING, ANALYSIS, AND IMPROVEMENT | Deterioration of quality system performance indicators | Incorrect timing for planning and conducting internal audits. Lack of funding for training internal auditors and quality officers in the audited units, incorrect selection of main goals and objectives when planning improvements, lack of employee qualifications for monitoring and analysis, low performance discipline, etc. |
| Core Processes (University Activities) | ||
| 1. ADMISSIONS | Failure to meet targets for student admissions to the University | Decreased demand from applicants, insufficient advertising of studies at the University, inefficient organization of pre-university activities and career guidance work among applicants. |
| 2. DESIGN AND DEVELOPMENT OF EDUCATIONAL PROGRAMS | Untimely design and development of educational programs | Insufficient qualification level of project team members at the University, lack of necessary methodological support for the development of educational programs, negligent attitude of University employees towards their duties, inefficient use of human potential in University units, low performance discipline of University employees, etc. |
| 3. IMPLEMENTATION OF EDUCATIONAL PROGRAMS | Insufficient (low) quality of educational services | Insufficiently high initial level of applicants. Shortcomings in working curricula, inability to provide necessary funding for educational activities, low performance discipline of University employees, inadequate material and technical base for the implementation of educational programs, insufficient flexibility in program management preventing prompt response to changes in the external environment, inability to provide students with modern literature and access to information resources. |
|
| Non-fulfillment of the teacher's individual plan-report. Imperfect educational and methodological support of educational programs, non-fulfillment of the educational process by participants of the educational process, nonconformities based on the results of current checks and audits. Insufficient number of highly qualified teachers, etc. | |
| Insufficient level of modern theoretical and practical training of employees | Teachers missing meetings, seminars, and councils. Unadjusted process of industrial internship for teachers, personal characteristics of employees, personnel illness, etc. | |
| 4. EDUCATIONAL AND EXTRACURRICULAR WORK | Decreased student participation activity in extracurricular activities | Low level of student motivation to participate in extracurricular work, etc. |
| 5. SCIENTIFIC RESEARCH AND DEVELOPMENT | Insufficient information support for the scientific and educational process | Lack of access to information sources. Absence of process inputs, their nonconformity or untimely receipt, inconsistency of actions of various executors, etc. |
| Failure to ensure the effectiveness of research activities | Low quality of pedagogical personnel training. Low activity of scientific and scientific-pedagogical staff in publishing the results of scientific research, low student activity in research work, etc. | |
| Nonconformities in the laboratory base | Lack of appropriate methodological support. Lack of necessary tools and equipment or their moral aging, lack of appropriately qualified employees. Unsatisfactory condition of laboratories, violation of safety rules and internal regulations, etc. | |
| Support Processes | ||
| 1. PERSONNEL MANAGEMENT | Shortage of qualified pedagogical staff | Low level of foreign language proficiency by University employees, inability of University employees to work with office equipment and computers, insufficient number of highly qualified teachers, etc. |
| Insufficient practical experience of employees | Lack of funding for employee training. Lack of opportunities for advanced training in certain specialties, etc. | |
| 2. INFRASTRUCTURE MANAGEMENT (EDUCATIONAL ENVIRONMENT) | Risks of financial and economic activity | Incorrect development of the University's financial strategy, lack of necessary resources, low performance discipline of University employees, etc. |
| Disruption of the Educational and Scientific Center of Information Technologies | Lack of funding, lack of Internet access, lack of power supply, low performance discipline of University employees, etc. | |
| 3. LIBRARY AND INFORMATION SERVICES | Nonconformity of the University's library collection with modern requirements | Untimely updating of textbooks and study guides. Difficulty of access to textbooks and study guides or their shortage, nonconformity of educational and methodological support of the educational process with educational standards, etc. |
| 4. CONTROL OF CUSTOMER PROPERTY | Risk of loss of property | Inappropriate storage conditions, low performance discipline of University employees, etc. |
| 5. DOCUMENT CONTROL | Nonconformity of documented information formatting | Low performance discipline of University employees, lack of funding for employee training, lack of qualified employees, inability of University employees to work with office equipment, etc. |
5.3.9 Stages of Risk Management
The risk management process includes the following stages:
- identification and evaluation of risks;
- planning necessary measures to eliminate risks / prevent risks;
- implementation of measures to eliminate risks / prevent risks;
- analysis of the results and effectiveness of measures taken to eliminate/prevent risks.
5.4 Sequence of Execution
5.4.1 Identification and Evaluation of Risks
5.4.1.1 Risk identification is carried out no later than June 1 of the current year in all structural units of the University by discussing potential problems in their activities at meetings/conferences. The head of a structural unit/process may initiate an unscheduled meeting/conference regarding risk identification in the event of changes in the structure, regulatory framework, or activities of the unit/process.
5.4.1.2 When identifying risks, functions, the regulatory framework, performance results, process results, customer satisfaction (complaints and claims), results of internal and external audits, and prior experience performing similar activities/processes within the unit are taken into account.
5.4.1.3 During risk identification, the following information is determined:
- risk name;
- risk description;
- risk causes;
- head of the unit/process;
- name of the unit/process.
The results of risk identification are entered into the risk passport of the structural unit/process, which is formatted according to form QMS KhAI-NMV-F.UR/001 (Appendix A).
5.4.1.4 The head of the structural unit/process evaluates the identified risks no later than June 10 of the current year by determining the level of probability of occurrence and possible consequences for each of them. In the event of changes in the structure, regulatory framework, or activities of the unit/process, the head of the structural unit/process additionally evaluates the risk.
5.4.1.5 The level of probability of risk occurrence is determined in accordance with Table 2, and the level of significance of potential consequences of risk occurrence is determined in accordance with Table 3.
Table 2 - Gradation of Risk Probability Levels
| Risk Probability Level | Qualitative Indicator of Risk Probability | Quantitative Indicator of Risk Probability, % | Interpretation |
| 1 | very low | 0-20 | The event is most likely to occur no more than once every 5 years |
| 2 | low | 21-40 | The event is most likely to occur once every 4 years |
| 3 | medium | 41-60 | The event is most likely to occur once every 3 years |
| 4 | high | 61-80 | The event is most likely to occur within the next two years |
| 5 | very high | 81-100 | The event is most likely to occur within the coming year |
Table 3 - Gradation of Significance Levels of Potential Consequences of Risk Occurrence
| Level | Interpretation |
| 1 (low) | The consequences have a negligible or minimal impact on the quality of educational activities and/or the safety of life and health of participants in the educational process. |
| 2 (medium) | The consequences have an impact on the quality of educational activities and/or the safety of life and health of participants in the educational process and do not require significant expenditures. |
| 3 (high) | The consequences have a significant impact on the quality of educational activities and/or the safety of life and health of participants in the educational process. |
5.4.1.6 The results of risk evaluation are entered into the risk passport of the structural unit/process, which is formatted according to form QMS KhAI-NMV-F.UR/001 (Appendix A).
5.4.1.7 The risk passport of the structural unit/process is signed by the head.
5.4.1.8 A copy of the approved risk passport of the structural unit/process is submitted to the Lead Auditor.
5.4.2 Planning Necessary Measures to Eliminate Risks
5.4.2.1 The head of the structural unit/process, no later than June 15 of the current year, based on the approved risk passport, guided by prior experience, the regulatory framework, and the results of previous internal and external audits, must define measures for elimination, potential completion timelines, and responsible persons for implementation for any risks where the product of the probability level and the significance level is greater than or equal to 6. If necessary, elimination measures are also defined for other risks.
5.4.2.2 The list of risk elimination measures, completion timelines, and responsible persons for implementation are entered into the planned vs. actual risk elimination form in accordance with form QMS KhAI-NMV-F.UR/002 (Appendix B).
5.4.2.3 The planned vs. actual risk elimination form is signed by the head of the structural unit/process and communicated to subordinates at a meeting/conference.
5.4.2.4 Amendments to the planned vs. actual risk elimination form are issued as an annex to the plan, and the head of the structural unit/process communicates this plan to subordinates at a meeting/conference.
5.4.3 Implementation of Risk Elimination Measures
5.4.3.1 In accordance with the planned vs. actual risk elimination form, designated responsible persons carry out the planned measures within established deadlines.
5.4.3.2 The head of the structural unit/process monitors the execution of the risk elimination plan-report on a monthly basis.
5.4.3.3 During an internal audit in a structural unit, members of the audit team verify the execution of the planned vs. actual risk elimination form. The verification results are recorded in the corresponding section of the form and, if necessary, in the internal audit report.
5.4.4 Analysis of Resulting Effectiveness and Efficiency of Risk Elimination Measures
5.4.4.1 The analysis of the performance and effectiveness of taken risk elimination measures is carried out no later than June 1 of the current year in all structural units of the University by discussing the results obtained from the implementation of planned actions at meetings/conferences.
5.4.4.2 The results of хлопсци the analysis are documented in a report in accordance with form QMS KhAI-NMV-F.UR/003 (Appendix C), which is signed by the head of the unit/process.
5.4.4.3 Proposals for improving the unit's activities and processes are developed based on the report and registered in the meeting/conference protocol.
5.4.4.4 A copy of the report is provided to the Lead Auditor by June 10 of the current year.
5.4.4.5 Based on the copies of risk analysis reports provided by the structural units, the Lead Auditor compiles a consolidated report in accordance with form QMS KhAI-NMV-F.UR/003 (Appendix D).
5.4.4.6 The consolidated report is endorsed by the Chief Quality Manager and submitted to the Rector of the University for approval.
5.4.4.7 The approved consolidated report is added to the input data for management review of the quality management system.
6. Measurement and Monitoring
Risk monitoring consists of controlling the risk level. This is achieved by regularly updating (every six months) information on risks, risk management measures, and the implementation status of measures previously developed during the risk identification and evaluation stage.
Verification of the execution of risk elimination actions across all units/processes is performed by internal audits.
Control over the fulfillment of these regulations' requirements is exercised during internal and external QMS audits and management reviews of the quality management system.
Evaluation criteria:
- the ratio of the number of planned risk elimination measures to the number of implemented risk elimination measures in the reporting period for each unit/process;
- the ratio of the planned labor hours allocated for risk elimination measures to the actual labor hours spent for each risk during the reporting period for each unit/process;
- the ratio of the number of persons scheduled to participate in risk elimination measures to the number of persons who actually participated in risk elimination measures for each risk during the reporting period for each unit/process.
- the number of risks that reoccurred after implementing risk elimination measures during the reporting period for each unit/process.
7. Records (Protocols)
7.1 Risk Passport
7.1.1 Identification
Each risk passport is assigned an identification number consisting of the name (abbreviation) of the unit/process and the academic year for which it was developed.
7.1.2 Retention
The approved risk passport is retained by the head of the structural unit/process for three years.
7.2 Planned vs. Actual Risk Elimination Form
7.2.1 Identification
Each planned vs. actual risk elimination form is assigned an identification number consisting of the name (abbreviation) of the unit/process, a sequential number, and the academic year for which it was developed.
7.2.2 Retention
The planned vs. actual risk elimination form is retained by the head of the structural unit/process for three years.
7.3 Risk Analysis Report
7.3.1 Identification
Each risk analysis report is assigned an identification number consisting of the name (abbreviation) of the unit/process, a sequential number, and the academic year for which it was prepared.
7.3.2 Retention
The risk analysis report is retained by the head of the structural unit/process for three years.
7.4 Consolidated Risk Analysis Report
7.4.1 Identification
Each consolidated risk analysis report is assigned an identification number consisting of a sequential number and the academic year for which it was prepared.
7.4.2 Retention
The consolidated risk analysis report is retained in the educational and methodological department for five years.
Upon expiration of the retention period, the consolidated risk analysis report is transferred according to an inventory list to the University Archive, where it is kept for five years.
8. Final Provisions
8.1 These Regulations are signed by the Chief Quality Manager, approved by the Rector of the University, and enacted by their order.
8.2 Control over the implementation of these Regulations is exercised by the Chief Quality Manager of the University.
8.3 Amendments and additions to these Regulations are reviewed and endorsed in accordance with the established adoption procedure.
Appendix A
Risk Passport Form
Appendix B
Planned vs. Actual Risk Elimination Measures Form
Appendix C
Risk Analysis Report Form
Appendix D
Form of the Consolidated Risk Analysis Report in Structural Units of the University




