Skip to main content
Update Required: We noticed you are using an older version of Internet Explorer. To ensure full functionality of this site, please contact your system administrator to upgrade to the newest version of Internet Explorer or try accessing the site in Chrome.
HIROC
  • Home
  • Services
    • Risk Management
      Learn how our risk management solutions help you increase safety
    • Insurance
      Learn about our coverage offerings and how the HIROC advantage can work for you
    • Claims
      Learn about the claims process and the support HIROC provides
  • Resources
  • News & Events
    • Annual Conference
      Learn how the HIROC Annual Conference brings Subscribers, partners, and healthcare professionals together to drive patient safety forward
    • News
      News from HIROC and our subscribers about what’s trending in healthcare
    • Podcasts
      Podcasts from HIROC about healthcare
      • Healthcare Change Makers Podcast
      • Share Scale Repeat Podcast
    • Webinars and Events
      View our schedule of upcoming webinars and access the archives
  • About Us
    • Board of Directors
      Learn about our Board – made up of HIROC subscribers – and access the current list of Directors
    • Leadership Team
      A message from HIROC's CEO, Catherine Gaulton
    • Careers
      Want to join a team of innovators and leaders? Check out our current opportunities
    • Our Story, Our Art of Safety Strategy
      How HIROC and its Subscribers are working to create the safest healthcare system
    • Risk Management Residency Program (RMRP)
      Learn about the RMRP
    • Safety Grants Program
      Learn about the HIROC Foundation and the Safety Grants Program
  • Contact Us
Log in Register
HIROC
Log in Register
  1. Home
  2. Resources
  3. Integrated Risk Management

Related Resources

Risk Watch (October '25)

Download PDF

Members Only

Webinars

Documentation: Answers to Frequently Asked Questions

Care

Risk Case Studies

Patient/Client Falls

Download PDF

Integrated Risk Management

Category
Risk Management Operations
Topic
IRM and Risk Register
Type
Risk Notes
  • Download PDF
  • LinkedIn

Overview of Issue

Failures in the financial and healthcare sectors have underscored the importance of anticipating and managing serious organizational risks. An integrated risk management (IRM) approach is required to identify, assess, prioritize, and manage key organizational risks.

Refer to related Risk Notes for details:

  • Risk – Concepts and Misconceptions, Risk Assessment, Risk Management and IRM/ERM.

Key Points

  • IRM is a critical leadership function in healthcare.
  • There are common pitfalls in IRM implementation.
  • A simplified approach may be the most effective, supported by HIROC tools, resources and peer knowledge.

 

Things to Consider

 

Definition of IRM

  • The Treasury Board of Canada Secretariat defines IRM as “a continuous, proactive, systematic approach to identifying, assessing, understanding, acting on, and communicating risk from an organization-wide, aggregate perspective” (TBSC, 2010).
  • IRM aligns with Accreditation Canada standards and is used frequently in the public sector.
  • The terms integrated risk management (IRM) and enterprise risk management (ERM) are seen as synonymous.

Rationale for IRM

  • Healthcare is complex, and many organizations manage risks independently as a patchwork of risk management activities within horizontal or vertical silos. The result is that one type of risk may receive attention and resources while another more important risk goes undetected or unacknowledged.
  • The consequences of ineffective management of risks range from organizational underperformance to catastrophic failures that could threaten the continued existence of the organization (Caldwell, 2012).
  • Effective IRM provides a framework for understanding and prioritizing very different types of risks from across an organization, for creating a concise summary of the most significant risks, and for identifying whether further work is required to bring these risks to acceptable levels.

Simplified, Effective Approach

  • There is no universal approach to IRM that will guarantee success and, generally speaking, organizations need to adapt processes to match their particular circumstances (Mikes, 2014).
  • Those that have led IRM implementation efforts in healthcare organizations have consistent advice – keep it simple. The figure to the right depicts the basic components of an simplified and effect approach to IRM including:
    • Focus on risks to key organizational and/or strategic objectives; start with a few;
IRM
  •  
    • Ensure effective coordination (e.g. Risk Manager);
    • Ensure board and senior leadership oversight / ownership;
    • Identify risks (what can go wrong?) related to key objectives (note: these are largely known; see HIROC taxonomy);
    • Assess impacts (how bad?) and likelihoods (how often?) of identified risks;
    • Manage risks (is there a need for action?) (see HIROC Risk Profiles for peer knowledge on mitigating risks).
  • Record and report risks (see HIROC Risk Register application).

Common Pitfalls

  • Many IRM efforts stall due to:
    • The absence of senior leadership ownership and support;
    • Lack of resources or expertise to carry out key coordinating functions;
    • Cognitive/group biases that result in over or under appreciating the importance of a particular risk due to lack of awareness or understanding, or deference to others;
    • A focus on identifying all risks which can overwhelm resources and mask the truly “vital few” which require senior leadership attention.
  • Commercial IRM (ERM) models are sometimes “tone deaf” to the realities of healthcare and may lead to approaches that result in lost time and resources with little realized benefit including:
    • Seeing strategic risks as distinct from operational risks – this is not the case in healthcare (see Risk – Concepts and Misconceptions Risk Note);
    • Focusing on “upside” risks (i.e. opportunities) versus “downside” risks (i.e. potential failures such as patient harm) (see Risk – Concepts and Misconceptions Risk Note); - Focusing on development of overall risk “appetite” or “tolerance” statements (see Risk – Concepts and Misconceptions Risk Note);
    • Assessing “inherent” risk (before controls/ mitigation strategies in place) versus a focus on “residual” risk (risk as it is now) (see Risk Assessment Risk Note).

References

• HIROC. (2014). IRM Risk Register website.

• HIROC. (2017). Taxonomy of healthcare organizational risks.

• Treasury Board Secretariat (TBS). (2012). Integrated risk management implementation guide. Government of Canada.

• Caldwell, J. (2012). A framework for board oversight of enterprise risk. Chartered Accountants of Canada

. • Mikes A, Kaplan R. (2014). Towards a contingency theory of enterprise risk management. Harvard Business School Working Paper.

• NHS - National Patient Safety Agency. (2007). Healthcare risks assessment made easy

Date last reviewed: March 2017
This is a resource for quality assurance and risk management purposes only, and is not intended to provide or replace legal or medical advice or reflect standards of care and/or standards of practice of a regulatory body. The information contained in this resource was deemed accurate at the time of publication, however, practices may change without notice.

Related Resources

Risk Watch (October '25)

Download PDF

Members Only

Webinars

Documentation: Answers to Frequently Asked Questions

Care

Risk Case Studies

Patient/Client Falls

Download PDF

Partnering to create the safest healthcare system

HIROC is not just a not-for-profit, we are a reciprocal. This means we are governed by our Subscribers – a group of over 800 diverse healthcare organizations across Canada. Together we share learnings and find ways to adapt to the changing nature of the industry.
Learn More
HIROC staff members
HIROC
Join our newsletter to stay up to date with the latest news.
By subscribing you agree with our Privacy Policy and provide consent to receive updates from HIROC.

About Us

  • Careers
  • Contact Us
  • Our Story, Our Art of Safety Strategy
  • Risk Management Residency Program (RMRP)
  • Safety Grants Program

Quicklinks

  • Claims
  • Insurance
  • Risk Management

Important information

  • Privacy Policy
  • Cookie Policy
  • Terms and Conditions
  • AODA

©2026 HIROC All rights reserved.

  • Linkedin
  • Instagram
  • Youtube