Bulletin Board - Document Comments

Bulletin Board - Review and Comment

Step 1 of 4: Comment on Document

How to make a comment?

1. Use this Comment Icon to open a comment box for your chosen Section, Part, Heading or clause.

2. Type your feedback into the comments box and then click "save comment" button located in the lower-right of the comment box.

3. Do not open more than one comment box at the same time.

4. When you have finished making comments proceed to the next stage by clicking on the "Continue to Step 2" button at the very bottom of this page.

Important Information

During the comment process you are connected to a database.  The session that connects you to the database may time-out due to inactivity.  The following tips will help you to avoid losing your comments or corrupting your entries:

  1. Do not jump between web pages/applications while logging comments.
  2. Do not log comments for more than one document at a time. Complete and submit comments from one document before commenting on another.
  3. Do not leave your submission part way through the comment process. If you are part way through and need to take a break, submit your current set of comments. The system will email you a copy of your comments, so you will be able to identify where you were up to so you can add to them later.
  4. Do not exit the process until you have completed all three stages.

Business Resilience Procedure

Section 1 - Summary

(1) This Procedure sets out the operational requirements for implementing Victoria University’s (VU’s) business resilience arrangements, including Business Impact Assessments, Business Continuity Plans, activation, escalation, exercising, review and continuous improvement.

(2) This Procedure supports the Business Resilience Policy and should be read in conjunction with the Business Resilience Program, Critical Incident Management Procedure, Emergency Management Procedure (pending) and Student Crisis Response Procedure.

Top of Page

Section 2 - Scope

(3) This Procedure applies to: 

  1. all University operations, activities and services; 
  2. all staff, contractors, consultants, office holders and volunteers engaged by the University; 
  3. all University-controlled entities and wholly owned subsidiaries; and 
  4. all University campuses, locations and operations, including onshore, offshore, transnational education, joint venture and related-party arrangements, where applicable. 
Top of Page

Section 3 - Policy/Regulation

(4) Business Resilience Policy

Top of Page

Section 4 - Procedures

Part A -  Summary of Roles and Responsibilities

Roles Responsibilities
Council and relevant Sub-Committees (Audit & Risk Committee)  Provides oversight of organisational resilience through governance, risk and assurance processes. 
Vice-Chancellor  Accountable for the University's overall business resilience capability and may authorise University-wide activation of business continuity arrangements.
Vice-Chancellor’s Group/ Leadership Cabinet 
Ensures business resilience arrangements are established, maintained and resourced within their portfolios.
Approves business continuity plans. 
Allocates appropriate resources during disruptions.
Supports recovery activities. 
Office of the Chief Risk Officer 
Oversees implementation of this Procedure. 
Maintains the University's business resilience framework. 
Coordinates University-wide business resilience activities. 
Reports on business resilience capability. 
Business Resilience Manager 
Supports business units in developing and maintaining plans.
Coordinates Business Impact Assessments. 
Facilitates training and exercises. 
Monitors compliance with this Procedure. 
Coordinates periodic reviews. 
College/Research Centre/Department Lead or equivalent
Identify critical business functions. 
Complete Business Impact Assessments. 
Maintain Business Continuity Plans. 
Ensure staff understand their responsibilities.
Participate in exercises and reviews. 
Staff 
Comply with business resilience arrangements. 
Participate in training and exercises where required. 
Report disruptions and incidents promptly. 
Support recovery activities as directed. 

Part B - Business Impact Assessments

(5) Business units must complete and maintain Business Impact Assessments (BIAs) for the functions they perform in accordance with the Business Resilience Policy. 

(6) Business Unit Managers are responsible for ensuring BIA’s are completed, reviewed and maintained for their area of responsibility.   

(7) BIA’s identify critical functions, activities and services, dependencies, vulnerabilities, impacts that may arise if those functions are disrupted, and recovery priorities and timeframes. 

(8) Business Impact Assessments are completed within VU’s business reliance tools and processes and must consider, as relevant:  

  1. people: what human capability and capacity do we need to deliver our activities; 
  2. property: what physical infrastructure are we relying on to deliver those activities; 
  3. equipment: what pieces of equipment. machinery, technology, etc. do we need; 
  4. systems, data and information: what systems, data, communication mechanism, etc. are necessary to perform those activities; 
  5. third-parties, suppliers, service providers and partners: do we need the input, approval or actions of third parties (including internal stakeholders) to achieve our outcomes;. 
  6. Internal dependencies: what inputs or outputs from other business units are required for the process to be completed; and, 
  7. Legal, regulatory, contractual or operational obligations. 

(9) Business Impact Assessments must be reviewed: 

  1. at least annually; 
  2. following a significant organisational, operational, system, location or service delivery change; 
  3. following a significant disruption, exercise or post-incident review; or 
  4. when requested by the Office of the Chief Risk Officer. 

(10) The BIA process will identify vulnerabilities that may affect the continuity or recovery of critical functions.  The assessment will assign an overall BIA rating to each business function.  Ratings will be used to group functions into priority cohorts, which will then be used by the Critical Incident Management Team (when activated), to direct and prioritise response and recovery activities. 

(11) The Office of the Chief Risk Officer will consolidate Business Impact Assessment outcomes to produce support the Vice-Chancellor’s Group annual prioritisation of critical functions and recovery activities in accordance with the Business Resilience Program.  

Part C - Business Continuity Plans 

(12) Business Continuity Plans (BCP) must be developed and maintained following completion of the Business Impact Assessment process.  

(13) The level of detail required within a BCP will be proportionate to the criticality and risk of the function it supports. Where a function is deemed high priority through the BIA process, the business area will be required to prepare a more detailed and comprehensive BCP, and its testing regime will be more frequent. 

(14) BCPs consist of two separate components:  

  1. the response plan: articulating how VU maintains critical functions while the business is disrupted; and 
  2. the recovery plan: describing how VU gets back to business as usual (BAU) once the crisis or disruption is over. 

(15) The relevant member of the Vice-Chancellor's Group is responsible for approving BCPs within their portfolio.  

(16) BCPs must be reviewed: 

  1. at least annually; 
  2. following a significant organisational, operational, system or service delivery change; 
  3. following activation of the plan; 
  4. following exercises or post-incident reviews; 
  5. when requested by the Office of the Chief Risk Officer. 

Part D - Activation and Escalation 

(17) A Business Continuity Plan may be activated where a disruption: 

  1. significantly affects delivery of critical services; 
  2. exceeds routine operational management; 
  3. requires coordinated management across multiple business units; or 
  4. is expected to have sustained operational impacts. 

(18) Activation of a BCP may be authorised by: 

  1. the Vice-Chancellor; 
  2. the Critical Incident Management Lead (see Critical Incident Response Procedure); 
  3. a member of the Vice-Chancellor's Group; or 
  4. another authorised officer (for example a member of the Leadership Cabinet or the CEO of VU Online).  

(19) Following activation, the responsible manager shall: 

  1. assess the nature and extent of the disruption; 
  2. confirm the safety and wellbeing of people; 
  3. notify relevant stakeholders; 
  4. activate appropriate response arrangements; 
  5. establish coordination arrangements where required; 
  6. implement agreed continuity strategies; 
  7. communicate regularly with affected stakeholders; 
  8. monitor operational impacts;  
  9. maintain appropriate records; and,
  10. escalate significant issues as necessary.

(20) Where: 

  1. a disruption meets, or may meet, the criteria for a critical incident, the matter must be escalated in accordance with the Critical Incident Management Procedure.
  2. an emergency exists, the matter must be managed in accordance with the Emergency Management Response Procedure (pending). 
  3. a disruption or critical incident involves students, the Student Crisis Response Procedure must also be applied. 

Part E - Response and Recovery 

(21) Business units must implement continuity and recovery arrangements in accordance with their approved Business Continuity Plans. 

(22) Response and recovery activities must be prioritised based on operational criticality, available resources and the nature of the disruption, in accordance with the Business Resilience Policy. 

(23) Recovery activities must commence as soon as reasonably practicable following stabilisation of the disruption. 

Part F - Training, Exercising and Review 

(24) Business continuity plans must be exercised and reviewed in accordance with the Business Resilience Policy. 

(25) Business resilience capability shall be supported through: 

  1. awareness activities; 
  2. staff training; 
  3. induction for relevant personnel; 
  4. desktop exercises; 
  5. simulation exercises; 
  6. recovery exercises; and 
  7. post-exercise reviews. 

(26) Business units responsible for critical functions must participate in training, exercising and review activities as required by the Office of the Chief Risk Officer. 

(27) Outcomes of exercises and reviews will be used to improve Business Impact Assessments, Business Continuity Plans and resilience capability. 

Part G - Monitoring and Continuous Improvement 

(28) The Office of the Chief Risk Officer will monitor implementation of business resilience arrangements across the University. 

(29) Business units must participate in monitoring, assurance, review and reporting activities relating to business resilience arrangements when required. 

(30) Following a significant disruption, activation or exercise, a structured review must be conducted to identify lessons learned and improvement actions. Improvement actions shall be monitored until completed. 

Part H - Records 

(31) Business units must maintain records relating to Business Impact Assessments, Business Continuity Plans, activations, exercises, reviews and improvement actions. 

(32) Records created under this Procedure must be managed in accordance with the University's Records Management Policy, Privacy Policy and Information Security Policy

Top of Page

Section 5 - HESF/ASQA/ESOS Alignment

(33) HESF: Standards 2.3 Wellbeing and Safety; 5.3 Monitoring, Review and Improvement; 6.1 Corporate Governance; 6.2 Corporate Monitoring and Accountability; 7.3 Information Management. 

(34) Outcome Standards for NVR Registered Training Organisations 2025: Standards 2.6 Wellbeing; 4.1 - 4.2 Leadership and Accountability, 4.3 Risk Management, 4.4 Continuous Improvement. 

(35) Compliance Standards for NVR Registered Training Organisations and FPP Requirements 2025: Standards 16 Notification of Material Changes; 17 Third Party Arrangements; 20 Compliance with Laws. 

(36) National Code of Practice for Providers of Education and Training to Overseas Students 2018: Standards 6 Overseas Student Support Services; 5 Younger Overseas Students. 

Top of Page

Section 6 - Definitions

(37) Business Impact Assessment (BIA): A structured assessment used to identify critical functions, dependencies, vulnerabilities, impacts and recovery priorities associated with a disruption.  

(38) Business Continuity: The capability of the University to continue delivery of critical functions during a disruption. 

(39) Business Continuity Plan: A documented plan that outlines how critical functions will be maintained and recovered during and following a disruptive event. 

(40) Business Resilience: The capability of the University to anticipate, prepare for, respond to and recover from disruptions while continuing to deliver its critical functions and strategic objectives. 

(41) Critical Function: A function, activity or service that is essential to the University's ongoing operations or ability to meet its obligations. 

(42) Crisis or Critical Incident: An event that has the potential to cause significant harm to people, disrupt critical University operations, impact the University's reputation, or require a coordinated response involving senior leadership and multiple functions. 

(43) Disruptive Event: Any event that adversely impacts or has the potential to adversely impact the University's people, operations, systems, facilities, services or reputation. 

(44) Emergency: An actual or imminent event that poses a risk to life, health, property, the environment or University operations and requires immediate action. 

(45) Leadership Cabinet:  Direct reports to the Vice-Chancellor’s Group members.  

(46) Recovery: Activities undertaken to restore operations and services following a disruptive event.