The Commonwealth Risk Committee (CRC) met on 27 August 2026 via Microsoft Teams and discussed the following matters:
Commonwealth legal risk management framework
The CRC received a briefing from the Attorney-General’s Department on the current arrangements for the management of legal risk across the Commonwealth. This included outlining the role of the Significant Legal Issues Committee which is to ensure the approach to significant legal issues is appropriate and consistent across the Commonwealth and the purpose of Legal risk Committee to foster legal capability across the Commonwealth.
Members agreed that existing mechanisms provide appropriate support and oversight for accountable authorities and that additional reporting to the CRC or COO Committee is not required. The Committee supported receiving an annual update from the Office of Legal Services Coordination on emerging legal risks and the Commonwealth’s overall legal risk posture.
Services Australia Legal Compliance and Remediation Program
The CRC heard from Services Australia on its enterprise-wide Legal Compliance and Remediation Program. The program was established in April 2025 to provide an enterprise-wide view of systemic legal compliance issues, a single source of truth for the Chief Executive Officer and a consistent approach to remediation prioritisation.
Members discussed the importance of executive sponsorship, strong governance, early escalation of issues and effective remediation pathways. The Committee noted that while the model is resource-intensive, its underlying principles may be adapted by other entities according to their size, risk profile and operating context.
Australian National Audit Office observations on risk management maturity
The CRC received a presentation from the Australian National Audit Office (ANAO) on risk management maturity across the Commonwealth. Members discussed the importance of demonstrating how risk management informs decision-making, strengthens controls and supports delivery outcomes, rather than focusing solely on compliance processes and risk documentation.
Recurring weaknesses identified by the ANAO includes risk not being embedded in decisions, controls being assumed effective without testing, late escalation of emerging risks, and weak links between risk, performance, stewardship and delivery.
Five characteristics observed of mature risk management practice are active use of risk appetite, treatment of controls as strategic assets, leadership discussion of risk in delivery and performance terms, active management of shared risks, and integration of risk information into performance reporting.
The Committee supported ongoing engagement with the ANAO on emerging observations and better‑practice examples.
Shared risk framework update
The CRC considered progress on the shared risk framework and noted feedback from the COO Committee. Members agreed to support continued work on workforce wellbeing risks for inclusion in the shared risk register. The Committee also agreed to further development of a broader whole-of-government shared risk model and guidance to share with entities across the Commonwealth as an example of better practice.
Chief Risk Officers Network update
The CRC noted an update on upcoming Chief Risk Officers Network activities, including a presentation on adaptive risk management and discussion of a new Resource Management Guide on internal controls being developed by Finance.
Next Meeting
Thursday 15 October 2026.
Lead agency contact
CRC Secretariat
Department to Finance
Risk and Insurance Branch
1800 651 540 (Option 4)