Risk Management and Business Continuity
ASF identifies its main risks, assigns an owner to each, and keeps functioning through disruption — including disruption affecting a facility accreditation cycle already in progress. Owner: ASF Secretariat, reporting to the International Standards Council.
Risk register
A register rates each risk by likelihood and impact across eight areas: financial independence and fee integrity (Financial Independence, published on Standards Development); standards development integrity (conflict of interest, panel composition); assessment integrity (Coordinator/Monitor conduct, false verification); confidentiality of facility data during an open assessment cycle; human resources (staff/Coordinator/Monitor capacity and turnover, covered operationally in ASF-POL-51); environmental (ASF’s own footprint, ASF-POL-45); reputational risk; and operations, including IT and the credential registry. Each risk has an owner, controls and actions. The register is reviewed by the Council twice a year, and whenever a new standard or accreditation track opens.
Business continuity
- Critical functions defined: the Public Standards Register, the Coordinator/Monitor credential registry, active facility assessment records, the website and training platform, and communication with the Council and facilities currently under assessment.
- Remote working possible for all ASF roles; assessment and standards data backed up (see Data Protection, IT and Cybersecurity, ASF-POL-18).
- A deputy identified for each Council and Secretariat function, so no single person’s unavailability stalls an open accreditation cycle.
- Continuity plan tested once a year, and after any disruption that affects a facility mid-cycle — with the affected facility notified directly if a published decision date is at risk.