Skip to content
Guidance to IndependenceGuidance to Independence
Policy

Governance & Risk Management Policy

Version 1.0 · Last updated: 30 July 2026· Reviewed annually

Home / Governance & Risk Management

1. Purpose

GTI actively works to identify, address, and monitor potential risks to promote a safe environment for participants, staff, and visitors, and to maintain viable business operations. This policy supports effective, risk-aware decision-making guided by GTI's mission and vision, and formalises our commitment to consistent, systematic risk management across the organisation.

2. Scope

Risk management is built into all areas of GTI's operations, including service delivery and corporate governance. It is the responsibility of every staff member and every area of the organisation — but it is the CEO's responsibility to carry out risk management analysis for the organisation and take appropriate action.

3. When GTI May Be At Risk

GTI recognises the organisation may be at risk when:

  • A well-functioning governance structure is not in place
  • Management plans, policies, and processes are inadequate
  • Staff roles and responsibilities are unclear
  • Participants are not required to sign consent forms or waivers
  • Staff practices do not meet participant or health standards
  • Participant input into governance and practices is not actioned
  • Equipment and facilities are not safe for their intended use
  • Child-safe standards are not met
  • A comprehensive risk management plan has not been implemented
  • Finances are managed inappropriately, risking financial sustainability
  • Insurance is inadequate or inappropriate
  • Operations are not evaluated regularly

4. Definition of Risk

Risk is the possibility of something occurring that will impact GTI's objectives — involving constraints, failures, obstacles, or losses that may arise in future. Risk is measured by consequence, and by whether the impact would be positive or negative.

5. Risk Identification

GTI identifies risk through:

  • Analysing hazard data
  • Conducting risk assessments (participant, environmental, and equipment)
  • Reviewing health orders and current practice requirements
  • Reviewing incident and accident information
  • Seeking feedback and complaints from staff, participants, families, and visitors
  • Ongoing review of all policies and procedures
  • Input from staff meetings and from participants directly
  • Strategic and operational planning sessions
  • Risk reviews against NDIS and Child Safe standards
  • Financial, internal, and external audits

6. Risk Planning

GTI maintains a Risk Management Plan Register, addressing three categories of risk:

  • Risks to GTI — loss of funding, inability to deliver funded outcomes within budget, embezzlement, lack of suitably qualified staff, reputational damage, changes in compliance requirements, and data loss from natural disasters
  • Risks to staff — staffing shortages, extended illness, WHS-related injury, training/compliance changes, natural disasters and infection
  • Risks to participants — environmental hazards, natural disasters, falls, transport, burns, choking, complex health needs, staff working in a participant's home, service interruptions, and exit/transition planning

Each register entry records: the risk detail, date identified, risk rating and consequence, required actions to eliminate/mitigate/control the risk, and review dates.

The CEO reviews the Risk Management Plan Register every 2 months (or more frequently if required, e.g. following WHS reviews, audits, or continuous improvement findings).

7. Risk Matrix

GTI rates risk by combining Likelihood (Rare, Unlikely, Possible, Likely, Highly Likely) against Consequence (Insignificant, Minor, Moderate, Major, Extreme) to produce an overall rating from Low through to Extreme. Higher-rated risks receive higher priority for action.

Consequences for participants range from “less than first-aid injury” (Insignificant) up to “avoidable death… systemic faults allowing widespread abuse or neglect of a participant” (Extreme).

8. Managing Risk — Controls

GTI manages identified risks through:

  • A Strategic Plan and a Risk Management Plan
  • Emergency and Disaster Management plans for participants
  • Participant risk assessments within individual support plans, reviewed regularly
  • Thorough staff orientation, education and training
  • New processes identified during risk assessments
  • Strict adherence to policies, procedures, and work instructions by all staff
  • Position descriptions and staff supervision/reviews
  • Ongoing capital maintenance and appropriate equipment budgets
  • Maintenance of all current registrations and insurances

9. Improvement Committee

GTI's Improvement Committee is made up of workforce representatives and functions to identify risks by reviewing incident, complaint, feedback, and audit data. The committee meets every quarter.

Separately, all risks are also reviewed independently by the CEO. Ongoing risks are added to the Risk Management Plan Register and Continuous Improvement Plan Register, and it is the CEO's responsibility to ensure required actions are completed within the nominated timeframes.

10. Hazard Identification and Reporting

Where a hazard or potential hazard is identified:

  1. The staff member completes a Hazard Report Form in detail
  2. The form is provided to the CEO on the same working day
  3. The CEO reviews, analyses, identifies the risk level, and creates a plan of action

Where a hazard is assessed as High or Extreme:

  1. The staff member must contact GTI and inform the CEO immediately, or as soon as it is safe to do so
  2. The CEO takes steps to address High or Extreme hazards immediately

All Hazard Report Forms are provided to the Improvement Committee for review.

11. Monitoring and Reporting

Risk management processes are audited regularly as part of GTI's audit program. Management reviews the risk, incident, complaints/feedback, and continuous improvement registers to build organisational knowledge of risk and reduce it for staff, participants, and the organisation.

GTI reviews its risk management systems through:

  • Feedback from participants, families, networks, and staff
  • Risk assessment of participants at intake, and at least annually
  • Annual practice and strategy review of each participant
  • Management meetings covering: incident management, complaint register review, governance, HR, information systems, WHS, emergency/disaster management (including infection control), financial management, and safe environments for children, young people and adults

12. Roles and Responsibilities

  • CEO (Subrath Regmi): overall responsibility for risk management analysis; reviews the Risk Management Plan Register every 2 months; independently reviews all risks; responds immediately to High/Extreme hazards; ensures actions are completed within timeframes
  • All staff: responsible for identifying and reporting hazards and risks; completing Hazard Report Forms; adhering to policies and procedures
  • Improvement Committee (workforce representatives): meets quarterly to review risk-related data

13. Related Documents

  • Emergency Plan / Emergency Plan – Waste / Contingency Emergency and Disaster Plan
  • Complaints & Feedback Policy and Procedure
  • Complaint and Feedback Form / Anonymous Complaint and Feedback Form
  • Continuous Improvement Policy and Procedure
  • Quality Audit Schedule / Internal Audit Schedule
  • Hazard Report Form
  • Risk Assessment Form / Risk Indemnity Form / Risk Management Plan Register
  • Continuous Improvement Plan Register
  • Personal Emergency Preparation Plan
  • Position Descriptions
  • Staff Training Record / Staff Training Plan / Training Register

14. Legislative References

  • NDIS Practice Standards and Quality Indicators 2021
  • Privacy Act 1988 (Cth)
  • Work Health and Safety Act 2011 (Cth)
  • Disability Services Act 1986 (Cth)

15. Contact Us

Guidance to Independence

General enquiries: info@guidancetoindependence.com.au · 0421 007 153

Website: www.guidancetoindependence.com.au