U.S. flag

An official website of the United States government

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock () or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Identification of TVA’s Enterprise Risks

Report Information

Date Issued
Report Number
2022-17381
Report Type
Inspection / Evaluation
Description
Enterprise Risk Management (ERM) provides an enterprise-wide, strategically aligned portfolio view of organizational challenges that provides improved insight about how to more effectively prioritize and manage risks. The Tennessee Valley Authority (TVA) Board of Directors established a formalized ERM program in 1999 to (1) develop a standard framework and (2) promote risk management awareness and techniques to manage risks throughout the company. Due to the importance of TVA identifying and assessing risks, we evaluated (1) the process used by TVA business units (BU) to identify risks and (2) how BU risks were used to comprise TVA's enterprise risk levels. We determined the processes used by TVA were generally effective for identifying strategic business unit (SBU)/BU risks and assessing those risks to determine enterprise level risks. However, we identified some opportunities for improvement related to documentation of the ERM process and defining and documenting TVA’s risk appetite. Additionally, we could not determine if the risks in the 2022 Enterprise Level Risk Portfolio adequately addressed the rolling blackouts that occurred on December 23 and 24, 2022.
Joint Report
Yes
Participating OIG
Tennessee Valley Authority OIG
Agency Wide
Yes (agency-wide)
Questioned Costs
$0
Funds for Better Use
$0

Recommendations

We recommend the Director, Enterprise Risk and Assurance, revise Tennessee Valley Authority’s Standard Programs and Processes-13.017, Enterprise Risk Management to fully document the process used to identify and assess risks.

We recommend the Director, Enterprise Risk and Assurance, formally define and document Tennessee Valley Authority’s risk appetite to comply with TVA-SPP-13.017, Enterprise Risk Management.

We recommend the Director, Enterprise Risk and Assurance, evaluate whether Tennessee Valley Authority’s inability to meet demand is adequately covered in the Enterprise Level Risk Portfolio.