Board Activities and Meetings
Minutes | Meeting of the Risk Committee of the Board (BRC) | 27 August 2024
BRC Attendees: Maarten Botterman, Becky Burr, Chris Chapman, James Galvin (Chair), and Patricio Poblete
BRC Member Apology: Harald Alvestrand and Wes Hardaker
ICANN organization Attendees: Xavier Calvez (SVP, Planning & Chief Financial Officer), Franco Carrasco (Board Operations Manager), Irina Douzadjian (Risk Management and Internal Audit Sr. Director), and Elizabeth Le (Deputy General Counsel), and Amy Stathos (Deputy General Counsel).
The following is a summary of discussions, actions taken and actions identified:
- Introduction and Opening Remarks – The Chair opened the meeting, discussed the workplan for the year, and introduced the agenda.
- BRC Action Items Log – The Committee reviewed the BRC Action Items Log. The Committee noted, as it had at the last meeting, that the Risk Appetite Statement updates have been discussed over the last couple of BRC meetings and a proposed draft version was included as part of the BRC report to the Board. With respect to the BRC charter update, the ICANN org will distributing proposed changes to the charter via email for the Committee's consideration. As it relates to the critical path for the New gTLD Program: Next Round (Next Round) action item, ICANN org reported that the risk analysis is underway. ICANN org anticipates on providing the Committee with an update of this work at its next meeting in October. The items on the Action Items Log relating to the governance overview of the risk management and the Internal Audit Function will be addressed at this meeting.
- Action: ICANN org to provide the Committee with an update of the risk analysis of the Next Round to develop critical path at the next meeting in October.
- Governance Overview for Risk Management and Internal Audit – The Committee received an updated overview of the governance structure of the Committee's oversight responsibilities of risk management and the Internal Audit Function.
- Assessment Plan – Risk Management Function – ICANN org presented a high-level overview of an assessment plan for the Risk Management Function which will be undertaken in ten phases. The proposed timeline is to capture and integrate the seven components of the maturity model, as needed and applicable. While the assessment has started and is expected to last until October 2025, the BRC will be briefed if and when matters come up that deserve the Committee's attention
- Implementation Plan – Internal Audit Function – ICANN org presented the Committee with the proposed implementation plan for the Internal Audit Function. The structure of the implementation plan is similar to the assessment plan and has a six phase approach. ICANN org noted that the final phase is project governance and oversight, and is an ongoing phase throughout the entire implementation plan. The Committee discussed the Internal Audit Charter, which is different from the BRC Charter. It was noted that best practices recommends for an Internal Audit Function to have a charter. The charter will cover the roles and responsibilities of the Internal Audit Function, which will include the Board level responsibilities in its oversight of the Internal Audit Function.
- AOB – The Committee discussed the Microsoft Exchange Outage that occurred on 19 July 2024 and the impact analysis of the incident. The Committee asked ICANN org to prepare a report on how the org handles third-party dependencies as a general risk category.
- Action: ICANN org to prepare a report on how the org handles third-party dependencies as a general risk category.
Published on 17 October 2024

