Tap any paragraph to write a margin note. Your notes collect in the Desk below the text and file under cases with @. The side-by-side margin rail opens on a larger screen.

Code · CFR · Title 16 — Commercial Practices · Part 1 — General Procedures · § 1.154

§ 1.154. Enterprise risk management.

522 words·~2 min read·/us/cfr/t16/s§ 1.154·

A research copy — for the controlling text, always check the official state or federal source. Not legal advice.

(a)Guiding principles. The Authority must effectively manage risk to prevent conflicts of interest, waste, fraud, embezzlement, and abuse. To manage risk, the Authority must align the enterprise risk-management process to the goals and objectives noted in the Authority's strategic plan. The Authority must assess risks, select risk responses, monitor whether responses are successful, and communicate and report on risks, consistent with § 1.153. The Authority must ensure that all internal controls have appropriate separation of duties (e.g., requester, approver, recorder). In addition, the Authority must develop corrective action plans no later than 90 days after receiving a notice of finding from its auditors or other internal assessments. The Board of Directors (or one of the Authority's standing committees) must review and evaluate identified risks and proposed corrective action plans. The Authority must review regularly its corrective actions identified from all audits and internal assessments and should develop criteria by which to prioritize its response activities. The Authority must ensure that its risk management activities encompass:
(1)Compliance with applicable laws, rules, and regulations;
(2)The avoidance of conflicts of interest, or the appearance thereof, in all aspects of the Authority's operations, including investigation and enforcement, vendor selection, personnel assignments and responsibilities, and actions by the Board of Directors or management; and
(3)Handling funds received and expended by the Authority, including revenue/expense policies, fundraising practices, contracting policies, travel policies, and real and personal property agreements and expenses.
(b)Data security and privacy. The Authority must ensure the privacy and security of data, including all reasonable measures to protect the confidentiality of any sensitive health information (SHI), personally identifiable Information (PII), and sensitive PII
(SPII)stored in its systems, including those operated by the anti-doping and medication control program, the Horseracing Integrity and Welfare Unit, and the Authority's third-party contractors. The Authority must ensure a complete annual evaluation of the status of its overall information technology security program and practices, as audited by a qualified, independent, third-party auditor. The Authority must also ensure that it has policies, programs, and practices in place to protect SHI, PII, and SPII. The Authority must send a copy of the annual evaluation to Commission staff.
(c)Vendor selection. Procurement actions estimated at over \$10,000 must be accompanied by documented market research (e.g., comparing the prices and other terms offered by the selected vendor against the prices and other terms offered by at least two other vendors) to ensure lowest cost or best value for goods or services to be provided. The Authority should also develop policies and procedures covering procurement activities.
(d)Notice. The Authority must provide advance notice to Commission staff of all significant Authority-planned events (e.g., press conferences, media events, summits, etc.) via a calendar, a list, email, or some other reasonable means. The Authority must also summarize key aspects of all such events on its website within a reasonable timeframe. The Authority must also give Commission staff prompt notice after it has been alerted to significant, adverse events in the horseracing industry (e.g., adverse safety or medical events that might reasonably lead to sanctions, track closures, etc.). \[89 FR 66550, Aug. 16, 2024\]
★   the supreme law of the land   ★
Don't Tread on Me
E Pluribus Unum — out of many, one

"If you don't know your rights, you don't have any."

Marginalia · a citizen's law index
A research desk, not legal advice. Always read the cited source before relying on a summary.
Questions or an issue? support@self-law.org
disclaimerMarginalia is a research index, not a law firm. Nothing on this site is legal, tax, or financial advice and no attorney–client relationship is formed by using it. Statutes, regulations, and case law change; summaries, search results, AI output, and member posts may be incomplete, out of date, or wrong. Any interpretation drawn from material on this site should be validated by a licensed attorney in your jurisdiction before you act on it.