Managing risk is central to how PM&C supports effective operations of government. The department’s approach recognises that risk is inherent in a complex and fast-paced operating environment but that it must be managed in a way that balances informed decision making with maintaining public trust and confidence.
Our approach is underpinned by a framework that supports the identification, assessment and management of risk across all areas of the department. PM&C’s Risk Management Policy and Framework complies with the Commonwealth Risk Management Policy, which supports the Secretary in meeting their obligations under section 16 of the Public Governance, Performance and Accountability Act 2013. This approach promotes clear accountability, open discussion and regular review, ensuring risks are considered as part of day-to-day business and strategic decision-making. It balances the need to enable innovation and responsiveness with protecting PM&C’s integrity, reputation and ability to deliver outcomes.
Strengthening capability and culture remains a priority. PM&C will continue to build its risk management capability and culture by clarifying risk appetite and tolerance, improving reporting, and embedding consistent practices across the department. This includes supporting staff to confidently identify and manage risk, strengthening leadership capability, and reinforcing a culture that is confident and accountable in managing uncertainty.
Adapting to a changing environment is critical as risks become more complex, interconnected and unpredictable. PM&C will continue enhancing its ability to identify emerging risks and opportunities, ensuring its risk settings remain aligned to its operating context. This includes integrating risk considerations more effectively into policy development, coordination and delivery, and supporting the government to respond to evolving challenges in a timely and coordinated way.
Strategic and enterprise risks provide a structured focus for managing the most significant risks to the department’s objectives. These risks are regularly reviewed through governance processes, with clear ownership and accountability. PM&C will continue to strengthen how these risks are monitored and managed, ensuring mitigation strategies remain effective and responsive to changing conditions. These are outlined in more detail in table 1.
Table 1: PM&C’s strategic and enterprise risks and management strategies
| Risk statements | Management strategies |
|---|---|
| Risk 1 We are not influential and fail to lead, collaborate, and anticipate policy direction | This risk is managed through proactive stakeholder engagement and strong coordination. Efforts focus on maintaining influential relationships with ministers, agencies, and key stakeholders, providing leadership across the APS, and supporting the delivery of government priorities through timely advice and coordinated responses to emerging issues. Ongoing stakeholder feedback helps strengthen our effectiveness and identify opportunities for improvement. If realised, impacts are mitigated through policy realignment, targeted communication, and strengthened partnerships to minimise strategic and reputational impacts. |
| Risk 2 We are not able to effectively support government operations | This risk is managed through strong planning, governance, coordination, and stakeholder engagement. Efforts focus on maintaining operational readiness, supporting critical government functions, and delivering timely, high-quality support through established processes. Ongoing feedback and continuous improvement help ensure support remains effective and responsive to government needs. If realised, impacts are mitigated through prioritisation, surge responses, and targeted stakeholder engagement to minimise disruption to government operations. |
| Risk 3 We fail to maintain a strong integrity culture | This risk is managed through clear expectations, strong governance, ethical leadership, and comprehensive integrity frameworks. Efforts focus on promoting ethical behaviour, accountability, integrity awareness, and the effective management of integrity concerns through education, advice, and reporting mechanisms. If realised, impacts are mitigated through timely investigation, strengthened controls, targeted communication and training, and corrective action to minimise compliance, reputational, and trust impacts. |
| Risk 4 We do not have the capability or capacity to deliver and meet emerging priorities | This risk is managed through workforce planning, capability development, and flexible resource allocation. Efforts focus on building a skilled, adaptable, diverse and responsive workforce. Ongoing oversight supports the early identification of capability and capacity risks, enabling resources to be effectively deployed to meet current and emerging priorities. If realised, impacts are mitigated through reprioritisation, targeted capability interventions, and collaboration to minimise delivery delays and capability gaps. |
| Risk 5 We do not have effective, efficient and fit for purpose ICT systems and services | This risk is managed through strategic ICT planning, service management, technology modernisation, and targeted investment. Efforts focus on maintaining reliable, secure, and fit-for-purpose systems, strengthening workforce capability, and aligning ICT services with business needs. If realised, impacts are mitigated through continuity arrangements, system redundancy, incident response, and recovery measures to minimise operational disruption and maintain critical services. |
| Risk 6 We fail to secure our personnel and physical assets | This risk is managed through protective security controls, governance, and security awareness. Efforts focus on safeguarding personnel, facilities, and assets through robust security frameworks, compliance with government security requirements, ongoing risk assessment, and staff training. If realised, impacts are mitigated through incident response, recovery activities, and timely risk treatment to minimise harm, operational disruption, and reputational impacts. |
| Risk 7 We fail to protect our digital ecosystem from compromise | This risk is managed through cyber security controls, governance, and ongoing investment in secure and resilient ICT infrastructure. Efforts focus on monitoring and managing cyber security risks, strengthening resilience, promoting security awareness, and maintaining compliance with relevant security requirements. If realised, impacts are mitigated through incident response, containment, recovery activities, and collaboration across government to minimise data loss, system disruption, and operational impacts. |
| Risk 8 We fail to adopt, appropriately engage with and/or manage emerging/new technologies for PM&C | This risk is managed through strategic technology governance, architecture assurance, and informed decision-making. Efforts focus on monitoring emerging technologies, assessing opportunities and risks, building workforce capability, and supporting secure and responsible adoption aligned with departmental objectives. If realised, impacts are mitigated through enhanced oversight, targeted interventions, and implementation adjustments to minimise inefficiencies, risks, and missed opportunities. |
| Risk 9 We fail to provide a safe workplace that manages psychosocial or physical hazards to support the wellbeing of our people | This risk is managed through active leadership, staff consultation and proactive management of physical and psychosocial risks. Efforts focus on fostering a safe, healthy, respectful, and inclusive workplace through a comprehensive work health and safety management system including risk assessments, safety inspections, hazard reporting, wellbeing initiatives as well as diversity and inclusion programs. If realised, impacts are mitigated through early intervention, accessible support services such as the Employee Assistance Program, workplace adjustments, and corrective action to minimise harm, workforce disruption, and cultural impacts. |