Enterprise Risk Management

The Risk Management Council (RMC) facilitates Enterprise Risk Management (ERM) at the University. Comprised of representatives from Internal Audit, Compliance and leaders from the Academic Division and Health System, the RMC serves a critical role between elevating enterprise-level risks to senior leaders and identifying and cultivating risk management activities at the department level.

The RMC works with the University's ERM Risk Management Networks (RMN) to connect major operating areas of each division and to establish a conduit for identifying and gathering key risk data.

Read the University of Virginia Enterprise Risk Management Charter here.


  • Key Risk Management - Identify and mitigate Academic Division and Health System enterprise level risks that could jeopardize or enable the University’s ability to meet its overarching strategic and operational objectives
  • Mitigation Confidence - Inform executive management and BOV leadership of the level of confidence related to mitigation of key risks at the University
  • Risk Communications - Facilitate risk management discussions and activities at University-wide and department levels
  • Higher Education Networks - Represent UVA in various networks of higher education ERM interactions.