We take a balanced and risk-informed approach to decision-making to respond to change in our operating environment and support the delivery of our purpose.

Our approach to risk management is to use a robust risk analysis to make risk-informed decisions within the boundaries set by our risk appetite statement and tolerance settings. These settings define how much risk we are prepared to accept in delivering our schemes and key activities, and they are supported by our:

  • Risk Management Policy - that provides the over-arching guidance for the agency’s risk management program.  
  • Risk Management Framework - that outlines our system of risk management and oversight and is aligned to the Commonwealth Risk Management Policy and the ISO 31000: 2018 Risk Management Guidelines.

Our risk management process is systematic, repeatable, and scalable. It enables officials across the agency to make risk-informed decisions and take appropriate actions in response to events, issues or incidents. This approach helps us respond to a changing operating environment, safeguard the integrity of our schemes and identify opportunities to improve the delivery of our purpose. 

Strategic risks

We have a clear understanding of our regulatory environment, which drives strategic thinking and supports risk-informed discussions by the Regulator Board, the Audit Committee and Executive leadership committees.

Our strategic risks consider events and changes in our operating environment with a view to mitigate threats that may impact our ability to achieve our purpose. We also consider opportunities arising from change that could strengthen our delivery, capability and regulatory outcomes. Table 1 summarises our strategic risks and their relationship to the key activities that support delivery of our purpose.

Table 1

Strategic risksDescriptionLinked key activity
We do not effectively manage our programs Our programs are central to delivering Australia’s carbon abatement objectives and meeting international commitments. Their effective stewardship depends on strong regulatory administration, organisational capability, and secure, resilient enabling infrastructure. Sustained performance in these areas is critical to maintaining confidence in scheme integrity, delivery and outcomes.Key activity 2, supported by Key activity 4. 
Effective program delivery depends on sound regulatory administration, enabling services, capable people and reliable systems.
Our advice, insights and data are not of high qualityWe are the custodian of Australia’s renewable energy, emissions and abatement data. High-quality data is essential to ensuring the advice, insights and information we provide to government and stakeholders is trusted and supports policy decisions, government outcomes and progress towards emissions targets.Key activity 1, supported by Key activity 3.
High-quality advice, insights and data are central to scheme integrity, transparency and informed engagement with government and stakeholders.
We do not adaptWe operate in a dynamic environment and must respond to changes in policy, markets, funding and stakeholder expectations. This depends on flexible and resilient systems, processes and infrastructure, supported by a capable workforce and an adaptive operating model.
By adapting effectively, we are better positioned to support carbon markets, respond to emerging needs, engage stakeholders and deliver current and future programs.
Key activity 4, supported by Key activity 3.
Adapting to change relies on workforce capability, flexible processes, resilient systems and engagement approaches that respond to evolving needs.

 

We manage our strategic risks through:

  • risk owners identifying and implementing actions to address threats and respond to opportunities, including:
    • developing strategies that reduce uncertainty including by improving knowledge
    • strengthening controls to limit the likelihood or impact of the risks
    • monitoring changes in risk exposure and emerging issues
    • accepting the risk or opportunity within appetite and tolerance settings
  • regular review of strategic risks by the agency Chair, Strategic Leadership Team and the Regulator Board
  • oversight by the Regulator Board and Audit Committee.

Risk oversight and governance

The Accountable Authority (the Chair) requires all officials and contractors to consider and actively manage risk in their day-to-day duties and decision-making. However, those risks are not managed in isolation and are reported through governance committees to support oversight and escalation. Where a committee has specific responsibilities relating to risk, they are outlined in the committees’ terms of reference. Table 2 outlines the key risk responsibilities across the agency and how they support effective risk oversight and management.

Table 2

RoleResponsibility
Risk ownersAccountable for managing enterprise risks.
Control ownersResponsible for implementing strategies or actions to reduce and manage uncertainty and help determine the impact of potential changes to the agency’s objectives.
Regulator BoardMonitoring and reviewing the agency’s risk profile and advising on the management of key risks.
Audit CommitteeMonitoring and reviewing the appropriateness of the agency’s system of risk oversight.
Chief Risk AdvisorChampions our risk culture and plays a central role in creating an environment where risk thinking and engagement is incorporated into operational and strategic decisions with transparent reporting to our governance committees.