Risk oversight and management

Risk management is central to the Listed Entity’s ability to deliver its legislative purpose, support the Courts and Tribunal, and respond effectively to emerging uncertainty, policy and legislative change, and operational demands. The Risk Management Framework and Plan, developed in accordance with the Commonwealth Risk Management Policy 2014 and AS/NZS ISO 31000:2018, provides a structured and systematic approach to identifying, assessing, treating, monitoring, and reviewing risks across the Listed Entity.

The framework supports effective risk management through sound planning, decision-making, stakeholder engagement, and efficient resource use. It also promotes risk awareness, incident reporting, ownership of issues, and the sharing of risk information and lessons across the Listed Entity and relevant Australian Government communities of practice. The framework is implemented through strategies, policies, processes and resources that provide ongoing clarity and guidance that allows the Listed Entity to promptly identify and manage risk.

Current risk management priorities are grouped across human resources, compliance and statutory obligations, financial sustainability, information technology systems, cyber security, service delivery, physical security, project delivery and climate change.

Risk oversight and assurance are provided through established governance arrangements. The Corporate Strategy and Operations Committee oversees implementation of the Risk Management Plan and advises on the framework, risk appetite, enterprise-wide risk register, and treatment strategies. The internal audit function and the Audit and Risk Committee provide independent assurance, including on the effectiveness of the Risk Management Framework, compliance with finance law, internal controls, risk reporting, and business continuity and IT disaster recovery arrangements.

Key strategic risks and how these are managed are outlined in the table below:

Key risk areas How key risks are managed

Human resources

Failure to safeguard employees from workplace risk and the inability to adequately resource programs and retain staff

  • Relevant policies and procedures
  • Qualified staff to manage psychosocial risks and WHS consultative committees
  • Regular communications and consultation with staff
  • Upskill staff and redeploy existing workforce capability where appropriate
  • Periodic review of issues arising
  • Monitoring turnover rates at all levels
  • Enhanced recruitment capability to target skilled/experienced staff.

Compliance and statutory

Failure to comply with legislative obligations

  • Executive meetings and Corporate  Strategy and Operations Committee oversight
  • Financial framework including policies, procedures and systems
  • Self-assessment  of compliance performance and identification of improvement opportunities
  • Staff training  programs and awareness  campaigns.

Financial

Failure to maintain sufficient funding levels resulting in a potential impact on financial sustainability

  • Robust budgeting and disciplined financial management practices
  • Ongoing communication and consultation with key stakeholders particularly Minister, Attorney-General’s Department & Department of  Finance and key government agencies
  • Oversight through the Capital Investment Committee and Corporate Strategy and Operations Committee
  • Financial sustainability modelling
  • Re-evaluation and reprioritisation of services/functions in line with funding availability.

IT systems

Failure of IT systems resulting in potential impact on program delivery and court operations

  • Digital Court Program underway to align case management systems across the Courts and Tribunal
  • Ongoing modernisation remediation plan to replace obsolete legacy IT infrastructure and systems
  • Continuous monitoring, management and preventative maintenance of digital estate
  • IT Disaster Recovery Plan and annual disaster recovery testing.

Cyber security

Failure to safeguard against cyber intrusion, data breach and information security

  • Cyber and Information Security Risk Management, including identification and reporting
  • Entity wide security framework, policies procedures and plans including Business Continuity Plan, IT Disaster Recovery Plan
  • Security governance and compliance protocols including incident detection
  • Cyber & Information Security Frameworks (e.g. PSPF, ISM, NIST, ISO 27001)
  • Secure AI environment supported by AI Policy.

Service delivery

Inability to deliver core services and programs

  • Clearly defined service standards
  • Fit for purpose governance and assurance framework
  • Executive oversight of core services and programs
  • Strengthening of contract management and associated risk assessments
  • Increased resilience measures regarding contract breach/failure.

Physical security

Failure to safeguard against protective security failures

  • Dedicated security resources including contracted security services (guards)
  • Entity wide security framework, policy, plan and procedures
  • Implement the Commonwealth Protective Security Policy Framework requirements
  • Fit-for-purpose facilities including layered security zones with access and security control
  • Entity wide security procedures and reporting

Project delivery

Inability to deliver capital projects

  • Capital project and expenditure oversight by Capital Investment Committee and Property Works Sub-Committee
  • IT governance oversight by relevant project governance arrangements
  • Project delivery support through the Strategic Programs Office
  • Budget management
  • Key personnel appointments
  • Project management.

Climate change

Failure to manage climate change impacts on court

  • Preventative maintenance and asset management programs
  • Infrastructure resilience (backup power, filtration and flood mitigation measures)
  • Weather monitoring and reactive operational responses
  • Site-specific operational playbooks (heat, flood, cyclone, smoke events)
  • Hybrid/remote hearing

Was this page useful?

What did you like about it?

If you would like the Court to contact you about your website feedback enter your email address in the box below. If you need help with a Court matter, visit the Contact Us pages or go to Live Chat.

How can we make it better?

If you would like the Court to contact you about your website feedback enter your email address in the box below. If you need help with a Court matter, visit the Contact Us pages or go to Live Chat.

* This online submission is protected by captcha