Some thoughts on best practice risk management

Risk management is simple.

It just takes 12 easy steps to achieve effective risk management in your organisation.

Truly.

So what is the simple 12 point method to best practice risk management.

But before we get to that, why is it important to be best practice risk management?  The primary reason is it provides management with the full understanding of the risks of the business and therefore should allow the business to make even more informed and balanced decisions.  You know when you have a great risk management framework when everyone in your business is talking risk and making considered decisions based on the risks.

Essentially a good risk management framework has the following key aspects:

  • A well understood view of the risks of the business;
  • A process of ongoing update of the risks but also some form of periodic review;
  • An analysis of other organisations events and incorporating them in your risk assessment process;
  • Reporting includes risks, events and key risk indicators (KRIs);
  • A process of root cause analysis such as using 5 Whys and Six Sigma techniques;
  • All business events cover who, what when and how;
  • Any actions that are required after an event are effectively managed;
  • Committees have an effective charter and accountability, and understand the risk appetite;
  • Committee actions are effectively managed;
  • Members of the committee attend all meetings; and
  • Risk owners present all papers.

Using these 12 key points and ensuring that the individuals in the organisation understand that the most important person in risk management is them, should provide your business with a great risk management framework.

Cheers,

More from the Reading Room

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

APRA and ASIC put frontier AI, cyber and resilience on the board agenda

APRA and ASIC’s September 2026 superannuation roundtable summary shows why AI, cyber and supplier disruption should be tested as one compound event. Businesses need rehearsed authority to contain harm, operate through disruption and approve recovery.

APRA’s ING action is a blunt reminder: liquidity breaches are not just an internal issue

APRA’s 3 September 2026 action against ING Australia showed how a reported liquidity ratio near 160 per cent could conceal a materially lower position. Every business should govern critical metrics as controlled products with reproducible calculations, named ownership and escalation for uncertainty.