Risk Management

Our primary risk management principles

The Risk Management Committee (CRM), which oversees risk management at our School, carries out wide-scale assessments involving various school units to identify and measure the risks to which our School is exposed. Major risks are those whose level, as defined by the CEPF Directive, falls within a zone requiring immediate action to deal with the risk. Our primary principles when it comes to managing these risks are as follows:

  • Protecting and promoting our School’s core missions and reputation by instilling a culture that encourages being aware of and addressing risks;
  • Upholding our School’s shared values of integrity, innovation, creativity, excellence and open-mindedness;
  • Encouraging staff and students to think about and discuss important decisions, so that they can better understand all possible options and potential consequences;
  • Fostering an open dialogue, especially about uncertain situations, the environment and different ways we can reach our School’s objectives.

Governance

While the overall responsibility for risk management is in the hands of the President, the Vice President Finance is responsible for its implementation. The Risk Management Committee, chaired by the Vice President Finance , advises the President and the EPFL Management on matters relating to risk management, risk financing and insurance. It also determines and supervises the procedure for identifying, evaluating, handling and monitoring risk. 

 

Risk Management Committee (CRM)

Risk management is overseen by the CRM, which conducts a comprehensive assessment of risk identification and evaluation across the School’s various units. It relies on close collaboration with the GRC and all School units to ensure a proactive, coordinated, and effective approach to risk management.

Mission

The Risk Management Committee (CRM) is the body responsible for steering and coordinating risk management at EPFL. It operates under the responsibility of the Presidency and the School’s Management.

Its mission includes:

  • implementing the institutional risk management framework;
  • periodically assess exposure to risks and claims;
  • propose and monitor appropriate mitigation measures;
  • ensure the existence and development of an effective internal control system (ICS);
  • advise the Management on issues related to risks and insurance.

Operating Procedures and Meeting Frequency

The CRM meets as often as necessary, with a minimum of four meetings per year.

The sessions are confidential and minutes are taken. The committee’s secretariat is provided by the GRC department.

Role of the GRC

Within the Vice-Presidency for Finances, the Risk Management and Compliance (GRC) department plays a central role in the framework:

  • it coordinates the School’s overall risk management process;
  • it supports units in identifying and assessing risks;
  • it prepares analyses, reports, and materials for the CRM;
  • it monitors risks and mitigation measures;
  • it manages the insurance portfolio and claims processing.

The GRC thus serves as the operational point of contact for any risk-related issues.

Reporting of a Significant Risk (Outside the Annual Process)

In addition to the annual risk review process, any significant risk must be reported immediately upon identification.

In accordance with Article 11 of LEX 1.4.3:

  • all employees must first inform their supervisors of any situation or threat likely to affect EPFL;
  • when the situation warrants it, the information is forwarded to the CRM;
  • the CRM Chair shall immediately inform the Executive Board in the event of an incident or significant risk requiring a decision.

This mechanism ensures early detection and proactive management of major risks, independent of the annual cycle.

In practice:

  • the report is made through the chain of command and/or by contacting the CRM Chair and/or the GRC;
  • the GRC assesses the situation and coordinates, if necessary, its escalation to the CRM;
  • critical cases may lead to immediate notification of Management and, where appropriate, external authorities.

This mechanism complements the annual risk management process and specific procedures such as crisis management or the whistleblowing procedure.