Context
The Office of the Information and Privacy Commissioner (OIPC) operates in an environment of evolving threats, technologies, and legal obligations affecting information and information systems. Risk to Information Assets is inherent in the OIPC’s operations and cannot be eliminated, only managed. Sound risk management supports the OIPC’s ability to fulfill its mandate and to meet its legal obligations, including the obligation to make reasonable security arrangements to protect Business Information or Statutory Information, and maintain the confidentiality of records in its control.
Purpose
This policy establishes the OIPC’s approach to identifying, assessing, treating, and accepting risk to Information Assets, and to ensure that such risk is factored into decisions about new, changed, ongoing, and decommissioned practices and systems.
Application
This policy applies to all employees of the OIPC.
References
ATIA, POPA, POPR, IM/IT Policy Framework, Information Governance Policy, Risk Assessment Directive, Information Security Directive, Electronic Transmission of Information Directive, Information Security Classification Directive, Information Training and Awareness Directive, Breach and IT Security Incident Management Directive
NIST Cybersecurity Framework, including standards, guidelines, and best practices
Policy Statements
- The OIPC identifies and assesses risk to Information Assets whenever it:
- Implements a new information system or a new practice that involves OIPC Information;
- significantly changes an existing practice, process, or information system;
- decommissions or retires a practice, process, or information system; or
- conducts a periodic reassessment of an existing practice, process, or information system, on a cycle and scope determined by the Chief Information Officer.
- Where a risk assessment is warranted and OIPC Business Information is involved, a Privacy Impact Assessment is required. Where the primary concern is threats to OIPC IT Resources, a Threat Risk Assessment is required. Where both privacy and security considerations, or other considerations, are engaged, the Chief Information Officer determines which instrument or combination of instruments applies.
- Before a decision is made on a proposed change, initiative, or investment, the IM/IT Governance Committee must be informed of the identified risks, the proposed treatments, and any residual risk that would remain following treatment, so that risk is weighed alongside other operational considerations.
- All risks to Information Assets, whether identified through a Privacy Impact Assessment, a Threat Risk Assessment, or otherwise in the course of operations, must be logged in the IM/IT Risk Register, along with their status, mitigation measures, and, where applicable, formal acceptance of residual risk.
- Whenever a PIA or TRA identifies mitigation measures to reduce risk to OIPC Information Assets, the Chief Information Officer is responsible to assess whether changes to an OIPC IM/IT policy instrument are necessary, and take appropriate steps to effect such changes.
- Where residual risk exists, its acceptance requires sign-off by the Information and Privacy Commissioner.
Roles and Responsibilities
Information and Privacy Commissioner
Approves the acceptance of residual risk.
Chief Information Officer
Maintains the IM/IT Risk Register, including its structure, quality, and accessibility.
Acts as backup for logging identified risks in the IM/IT Risk Register in the absence of the Director, IM/IT.
Determines the applicable risk assessment instrument or instruments for a new initiative or information system.
Approves the acceptance of residual risk that falls below the threshold established in the Risk Assessment Directive.
Monitors whether changes to an OIPC IM/IT policy instrument are necessary and initiates changes as needed.
Determines the cycle and scope of periodic risk reassessment.
Director, IM/IT
Logs identified risks in the IM/IT Risk Register, including those identified outside a formal risk assessment instrument.
Brings identified risks, proposed mitigation measures, and residual risk forward to the IM/IT Governance Committee.
Supports the work to assess risk relevant to the Information Asset or initiative under consideration.
Ensures risk assessment instruments and risk mitigation measures follow industry best practices as outlined in the NIST CSF.
Supervisors
Ensure that risk assessments are initiated for new, significantly changed, retired, or periodically reassessed practices and information systems within their areas of responsibility.
Reporting suspected or confirmed risks to Information Assets to the Director, IM/IT for logging in the IM/IT Risk Register.
Monitoring and review period
This policy will be reviewed by the IM/IT Governance Committee within one year of its implementation, and every two years thereafter, or as otherwise required.
Approval
This policy was approved by the IM/IT Governance Committee on September 21, 2026 and is in effect.






