(Aligned to ISO 31000 and tailored for NDIS, Aged Care, and Employment Services)
This Integrated Risk Management Framework sets out how risks are identified, assessed, managed, monitored, and reviewed to protect people, ensure quality services, and meet legal and funding obligations.
The framework supports:
Safe, rights-based, and person-centred services
Compliance with NDIS, Aged Care, and Employment Services requirements
Continuous improvement and accountable decision-making
This framework applies to:
All workers, contractors, volunteers, and leaders
All service delivery settings (online, in-home, community, workplace)
All funded and non-funded programs
Strategic, operational, financial, clinical, safeguarding, and reputational risks
This framework aligns with:
NDIS Act 2013
NDIS Practice Standards
NDIS Code of Conduct
NDIS Incident Management and Reportable Incidents Rules
Aged Care Act 1997 and reforms
Aged Care Quality Standards
Serious Incident Response Scheme (SIRS)
Charter of Aged Care Rights
Fair Work Act 2009
Disability Employment Services / Inclusive Employment Australia Guidelines
Work Health and Safety (WHS) laws
Anti-Discrimination and Equal Opportunity laws
Privacy Act 1988
Work Health and Safety legislation
Child Safe Standards (where applicable)
This framework follows ISO 31000 by ensuring risk management is:
Integrated into all organisational activities
Structured and comprehensive
Customised to services and client needs
Inclusive of workers, clients, and stakeholders
Dynamic and responsive to change
Based on best available information
Focused on continual improvement
Set risk appetite and tolerance
Approve this framework and oversee high and extreme risks
Ensure compliance with regulatory obligations
Implement risk systems and controls
Ensure serious incidents are escalated and reported
Review risk trends and corrective actions
Identify and manage risks in daily operations
Maintain risk registers
Ensure staff training and supervision
Follow policies and safe work practices
Report hazards, near misses, and incidents immediately
Uphold client rights and safety
Client safety and safeguarding
Clinical and personal care
Serious incidents and restrictive practices
Workforce health, safety, and conduct
Financial, fraud, and funding compliance
Information security and privacy
Service delivery and continuity
Workforce capability and culture
Legal and regulatory compliance
Reputation and stakeholder trust
Risks are identified through:
Incident, near-miss, and complaint reporting
Client feedback and advocacy input
Staff consultation and supervision
Audits, accreditation, and quality reviews
Change management and service planning
Each risk is assessed using likelihood and consequence ratings.
Rating
Description
1
Rare – may occur only in exceptional circumstances
2
Unlikely – could occur at some time
3
Possible – might occur at some time
4
Likely – will probably occur
5
Almost Certain – expected to occur frequently
Rating
Description
1
Insignificant – no injury, minimal disruption
2
Minor – short-term impact, no lasting harm
3
Moderate – medical treatment, service disruption
4
Major – serious injury, regulatory breach
5
Severe – death, abuse, systemic failure
Likelihood \ Consequence
1
2
3
4
5
5 Almost Certain
Medium
High
High
Extreme
Extreme
4 Likely
Medium
Medium
High
Extreme
Extreme
3 Possible
Low
Medium
High
High
Extreme
2 Unlikely
Low
Low
Medium
High
High
1 Rare
Low
Low
Medium
Medium
High
Controls must follow the hierarchy:
Eliminate
Reduce
Substitute
Administrative controls
Personal protective measures
Risk acceptance is only permitted within approved tolerance levels.
All risks must be recorded in the Risk Register.
Risk ID
Risk Description
Category
Cause
Impact
Likelihood
Consequence
Risk Rating
Controls
Residual Risk
Actions Required
Responsible
Review Date
Any incident involving:
Death
Serious injury or abuse
Neglect or exploitation
Restrictive practices
Sexual misconduct
Criminal behaviour
Must be:
Reported immediately to management
Recorded in incident systems
Reported to regulators within mandatory timeframes (NDIS / Aged Care SIRS)
Linked to the Risk Register as Extreme Risk
Root cause analysis and corrective action plans are mandatory.
Risks reviewed at least quarterly
High and Extreme risks reviewed monthly
Controls tested for effectiveness
Trends analysed and reported to leadership
Mandatory risk and incident training at induction
Annual refresher training
Targeted training for high-risk roles
This framework is reviewed annually or following:
A serious incident
Regulatory changes
Service expansion or system failure
Risk Register
Incident Management & SIRS Policy
Safeguarding Policy
WHS Policy
Complaints Management Policy
Business Continuity Plan
Framework Owner: Executive / Board
Review Cycle: Annual
Version: 2.0