Risk Register
Summary Report
Board of Directors | July 2026
This report presents a structured summary of the SDVC Risk Register for board review at the July 2026 meeting. It focuses on High and Medium risks requiring active board attention. A notable change since May 2026: the risk relating to loss of long-term senior staff has escalated from Medium to High, with likelihood now recorded as Near-certain (5). The board should also note two risks flagged as Review due and one where the review deadline has passed. The New Risks to be Evaluated section confirms no new risks are awaiting evaluation at this time.
CV funding model change — significant loss of CV funding due to DRCDG changes
26/02 — Added Jan 2026
Tricia Nolan
5 — Near-certain
4 — High
Loss of funding with significant staffing implications. Reduced capacity to deliver CV programme in South Dublin.
Reserve funding in place.
Board Chairs to engage with DRCDG to lobby on funding model. Revert to TDs on loss of deprivation index.
30 November 2026
Risk of losing New Communities funding in 2027
25/04 — Added Aug 2025
Tricia Nolan
4 — Likely
4 — High
Loss of €60k funding contributing to salaries of 2 staff. Potential redundancies and loss of services to our largest client cohort.
Significant surplus in place to cover scenarios such as this.
Identify alternative funding sources. Campaign ministers to retain funding. Drive executive group to deliver funding report to DRCDG.
Lack of clarity about Community Volunteers funding model in 2027
F17 — Added Jan 2025
Tricia Nolan
4 — Likely
5 — Catastrophic
Loss of funding and significant difficulties delivering the Community Volunteers programme in 2027.
Annual budget process includes forward review of all funding streams. CEO maintains regular communication with DRCDG. Board updated at each monthly meeting. Finance, Audit and Risk subcommittee reviews forward funding pipeline regularly.
Engage with DRCDG to secure 2025 budget. Explore charging model for Community Volunteers.
31 July 2026
Budget does not facilitate strategic objectives
F5 — Updated May 2026
Tricia Nolan
4 — Likely
4 — High
Unable to contribute positively to the Dublin Volunteering Strategy. Loss of trust and reputation with wider Dublin Volunteer Centres.
Annual budget prepared by CEO and bookkeeper and formally approved by the board. Finance, Audit and Risk subcommittee reviews financial performance against budget quarterly.
Review workplan with Dublin Managers to ensure it is realistic.
We will lose long-term senior staff members
25/05 — Added Sep 2025
Tricia Nolan
5 — Near-certain (increased from 4)
4 — High
Loss of experience and relationships on the ground. Reduction or degradation in important services.
Annual staff appraisals conducted. Competitive salary benchmarking carried out. Employee Assistance Programme available to all staff. Flexible working arrangements offered where possible.
Identify staff to upskill across all roles to ensure there is always an alternate. Create succession planning process and procedures. Document work of senior staff.
31 October 2027
iVOL data processing agreement does not adequately protect SDVC
O51
Tricia Nolan
3 — Possible
5 — Catastrophic
Loss of data and non-compliance with GDPR.
Existing data processing agreement in place.
Engage with Volunteer Ireland to agree a new, more robust data processing agreement.
Another organisation fills the niche of SDVC
O43
Tricia Nolan
3 — Possible
5 — Catastrophic
SDVC risks losing its market position, relevance and funding. Over time this could become an existential challenge if SDVC cannot differentiate its value in the volunteering ecosystem.
Established relationships with funders, partner organisations and community stakeholders maintained. Position as designated volunteer centre for South Dublin recognised in funder agreements.
Clearly articulate SDVC’s unique value proposition to funders and partners. Stay closely connected to needs of volunteers and VIOs. Build deep, long-term relationships with funders based on demonstrated impact.
Garda Vetting disclosure sent to incorrect organisation with convictions
O4
Tricia Nolan
3 — Possible
3 — Moderate
Serious data breach exposing SDVC to GDPR enforcement action and significant fines. Sensitive personal data compromised. Reputational damage and loss of trust in the vetting service.
Staff checks in place. New Salesforce bulk download build (closed system) that automates sends to the appropriate person.
Review systems and controls. Continue to build IT solutions that automate workflows to prevent human error.
Theft or loss of sensitive/personal data
O14
Tricia Nolan
2 — Unlikely
4 — High
Serious breach of GDPR obligations, mandatory notification to the Data Protection Commission, significant regulatory fines, reputational damage and loss of trust from volunteers, staff and partner organisations.
GDPR-compliant data protection policy in place. Staff have received data protection training. Access to sensitive personal data restricted to authorised staff only.
All access to sensitive information protected by 2FA. Schedule automatic weekly backups of iVOL data.
Failure to innovate and update IT systems
O29
Tricia Nolan
4 — Likely
3 — Moderate
Outdated systems will erode service quality and relevance. Competitors may offer more effective digital solutions, making SDVC less attractive. Older unsupported systems create growing security vulnerabilities.
Organisation participates in sector networks where technology developments are shared. Microsoft 365 and cloud-based tools kept updated. Management reviews technology needs as part of annual planning.
Establish annual technology review process. Allocate a dedicated budget line for technology innovation. Designate a staff technology lead. Develop a rolling three-year technology roadmap.
Multiple platform logins with password reuse
O45
Tricia Nolan
2 — Unlikely
4 — High
Passwords compromised, unauthorised access to systems, potential loss of sensitive data or theft of funds.
Staff are aware of the importance of securing online information.
Implement password management software. Prevent password sharing and reuse.
Lack of awareness of policies and procedures
O27
Tricia Nolan
2 — Unlikely
4 — High
Actions taken without proper authority.
Policies and procedures held in a central, accessible location. New staff receive an induction as part of onboarding. Regular team meetings used to communicate policy updates.
Ensure all policies are in a single centralised location. Include policies induction for all new staff onboarding with sign-off. Conduct annual staff policies awareness review.
No new risks are awaiting evaluation this month. There are no items in the new risks queue at the time this report was generated. If the board or management identify any emerging risks during this meeting, these should be added to the register for formal evaluation and scoring at the next cycle.
| Risk Level | Count | Active | Mitigated | Materialised | Board Action |
|---|---|---|---|---|---|
| High | 5 | 4 | 1 | 1 | Discussion required for all five. Senior staff risk newly escalated from Medium. |
| Medium | 7 | 5 | 2 | 0 | All scored. Monitor ongoing. No score gaps remaining. |
| Low | ∼47 | Mixed | Mixed | 0 | Monitor. Two Low risks flagged Review due (25/04 and 25/06). |
| Negligible | ∼25 | Mixed | Mixed | 0 | No action required unless circumstances change. |
| Priority | Risk | Recommended Action |
|---|---|---|
| Immediate | CV funding model change (26/02) — materialised | Confirm status of Chair engagement with DRCDG and TD outreach. Board to agree next steps and timeline. |
| Immediate | Senior staff risk (25/05) — escalated to High | Board to review adequacy of succession planning controls. Likelihood is now Near-certain — confirm what concrete steps have been taken to document senior staff work and identify upskilling candidates. |
| Immediate | New Communities funding (25/04) — review deadline passed | Confirm updated position. Record outcome in register and set new review date. |
| This Meeting | CV funding clarity (F17) — review deadline 31 July 2026 | Update risk status. Confirm actions taken with DRCDG on 2025 budget and charging model exploration. |
| This Meeting | Donated software dependency (25/06) — review overdue | Confirm status of software audit and transition plan. Update review date in register. |
| Ongoing | Password management (O45) | Confirm whether password management software has been implemented — this action has been outstanding since at least May 2026. |
Good news: Medium risk score gaps resolved. All Medium risks now have formal likelihood and impact scores recorded. The four unscored risks flagged in the May 2026 report (O29, O43, O27, and the VI affiliation agreement) have all been updated in the register. The board no longer needs to take any action on scoring at this meeting.