Risk oversight and management
Risk management is central to the Listed Entity’s ability to deliver its legislative purpose, support the Courts and Tribunal, and respond effectively to emerging uncertainty, policy and legislative change, and operational demands. The Risk Management Framework and Plan, developed in accordance with the Commonwealth Risk Management Policy 2014 and AS/NZS ISO 31000:2018, provides a structured and systematic approach to identifying, assessing, treating, monitoring, and reviewing risks across the Listed Entity.
The framework supports effective risk management through sound planning, decision-making, stakeholder engagement, and efficient resource use. It also promotes risk awareness, incident reporting, ownership of issues, and the sharing of risk information and lessons across the Listed Entity and relevant Australian Government communities of practice. The framework is implemented through strategies, policies, processes and resources that provide ongoing clarity and guidance that allows the Listed Entity to promptly identify and manage risk.
Current risk management priorities are grouped across human resources, compliance and statutory obligations, financial sustainability, information technology systems, cyber security, service delivery, physical security, project delivery and climate change.
Risk oversight and assurance are provided through established governance arrangements. The Corporate Strategy and Operations Committee oversees implementation of the Risk Management Plan and advises on the framework, risk appetite, enterprise-wide risk register, and treatment strategies. The internal audit function and the Audit and Risk Committee provide independent assurance, including on the effectiveness of the Risk Management Framework, compliance with finance law, internal controls, risk reporting, and business continuity and IT disaster recovery arrangements.
Key strategic risks and how these are managed are outlined in the table below:
| Key risk areas | How key risks are managed |
|---|---|
Human resourcesFailure to safeguard employees from workplace risk and the inability to adequately resource programs and retain staff |
|
Compliance and statutoryFailure to comply with legislative obligations |
|
FinancialFailure to maintain sufficient funding levels resulting in a potential impact on financial sustainability |
|
IT systemsFailure of IT systems resulting in potential impact on program delivery and court operations |
|
Cyber securityFailure to safeguard against cyber intrusion, data breach and information security |
|
Service deliveryInability to deliver core services and programs |
|
Physical securityFailure to safeguard against protective security failures |
|
Project deliveryInability to deliver capital projects |
|
Climate changeFailure to manage climate change impacts on court |
|






