4.
Risk management

Amsterdam UMC uses an organisation-wide risk management system designed to ensure the timely identification, assessment and management of risks that may affect the achievement of strategic objectives, the continuity of core tasks and compliance with laws and regulations. This system is embedded within the organisation’s standard governance, planning, control and compliance processes and is supported by policy frameworks, risk analyses, monitoring, audits, incident management and periodic reporting. For risks affecting patient safety, continuity of care, data protection, research and compliance with laws and regulations, Amsterdam UMC applies a limited risk appetite and implements additional control measures. Comprehensive risk management is carried out by the ICO committee, which also takes into account other risks such as flooding and terrorism.

Within this broader framework, cybersecurity and knowledge security were two particularly relevant risk themes for Amsterdam UMC. The escalating frequency of digital threats, dependence on suppliers and digital supply chains, the geopolitical context and the importance of protecting patient data, research data, knowledge and innovation mean that these themes require particular attention.

Cyber security

Knowledge security