Risk Management: A Practical Guide for RTOs
Article 6 – Newbery Consulting – 2025 Standards Article Series
1. Introduction Residual risk
When risk management was re-introduced into the standards (Outcome Standard 4.3), I was both pleased and also a little concerned about the sector’s ability to comply with this standard. The new standards require RTOs to identify and manage risks throughout their operations. This includes risks to VET students, staff and the organisation. So, basically everything and everyone. I have been involved in risk management in one way or another for most of my working life and particularly in the last 30 years at a relatively complex level. When I speak to people about risk management, it’s very clear to me that they have a very basic understanding and many people just haven’t had the opportunity to engage in risk management in a systems context. I don’t see this as a disadvantage. I just think that we need to recognise that some people have a better understanding than others and we need to try and bring everyone along.
Risk management is one of those things that has an element of black art. It seems to have this mystique of something that is complex and only really used by senior managers or larger organisations. This thinking is something that we need to change. There is also a human element. Some people are natural systems thinkers. They see connections and processes instinctively. Others are more intuitive or creative. They thrive in the relational parts of the job. Asking them to map out likelihood, consequence, and control measures feels like asking them to speak a second language. That does not mean they cannot do it. It simply means the process needs explanation in a calm, practical way.
The good news is that risk management is not as complicated as it first appears. At its heart, it is a structured conversation. It helps you think ahead, prepare, and make better decisions and it gives you a way to break a large compliance obligation into manageable parts. It allows you to measure the strengths of your current arrangements and see where improvements are needed. When we approach it this way, risk management stops feeling like a burden. It becomes a normal part of how we run an RTO. I guess that is the purpose of this article. I want to try and explain the process of how risk management can fit into your governance arrangements and how you can use it really effectively as a management tool and as a way to get everyone involved in understanding and implementing compliance arrangements.
Some of our clients know that I volunteer as the Chairperson of a not for profit organisation in the northwest of NSW. This service supports people who need a hand up, and I care deeply about the work. I mention this because I have seen first-hand how using risk management to think clearly about compliance and operating arrangements has changed the way that organisation works. It helped us achieve ASES accreditation a few years ago and, more importantly, it brought the whole team into the process. I see this same effect in some of our clients. I believe strongly that the risk management requirement in the Outcome Standards is not just another compliance obligation. It is an opportunity for every RTO to understand its systems more clearly and involve its people in a meaningful way. In many ways, undertaking a risk assessment is very aligned to undertaking a compliance self-assessment. It examines your arrangements from a slightly different perspective but, it is something that you can do in a day and the outcomes can be very valuable in establishing a baseline risk management plan. Follow along with me in this article and I will explain the basic concept of risk management. When I explain this verbally, the client often has a bit of a light bulb moment, so I am hoping that I can do it justice in this article.
I have provided the following diagram which is an extract from our policy and procedure on risk management so that you can refer to this as we work our way through the steps in risk assessment.

2. Understanding what compliance risk actually means
I think the first things to make clear is that when we refer to “risk”, we are not referring to the risk of injury or hazard risk. If we wanted to have a discussion about risk to injury then we would talk about hazard risk management or hazard control. This is probably one of the most widely misunderstood aspects. I couldn’t tell you the number of times that I get into a conversation about the client’s risk management arrangements and they start talking about their safety arrangements. Yes, we can apply the same process of risk management to hazard control but in the context of this article, I are predominantly focused on the management of the risks relating to your compliance and obligations as an RTO. Yes, ASQA would say that standard 4.3 includes risks to VET students, staff and the organisation. That’s what is says but here and now, I think it is enough to focus on the risk to the organisation. Trust me, that is enough and once you have the concept clear, you can apply it to anything.
Compliance risk refers to the possibility that an organisation’s systems or practices will fail in meeting a compliance requirement. Such failure affects students, staff, or the organisation. This could be a gap in training, a student support issue, poor record keeping, or a system drifting away from legal expectations such your obligations under the Privacy Act.
Broadening the view helps. RTOs must consider obligations under privacy, work health and safety, anti-discrimination, and consumer protection laws. They also consider specific VET sector legislation. Each area brings consequences if something goes wrong. For example, a privacy breach affects more than audit outcomes. It affects trust, reputation, and student confidence. Failing WHS obligations can affect the health and safety of personnel and exposes leaders to legal action. These issues are not separate from compliance. They are part of the same picture.
Understanding compliance risk also means recognising how connected obligations are. A weakness in one area often affects another. Poor assessment systems affect training quality. Weak supervision affects student safety. Communication gaps create record keeping problems. Each element affects the next. This is why risk management matters. It allows you to map connections and see how one issue affects overall operation stability. Most importantly, compliance risk is not about fear. It is about clarity. When you understand your obligations broadly and practically, you see where real exposure lies. You make informed decisions about what to strengthen and why. That is the purpose of risk management. It allows you to understand your environment, not to fear it.
3. Planning your risk assessment
Before getting into the risk assessment itself, it is worth spending some time planning the activity. Good preparation makes an enormous difference as it allows the people participating to focus on the risks and contribute their experience, rather than spending half the day trying to work out what the organisation currently does.
Start by identifying someone to coordinate and facilitate the activity. This person does not need to be a risk management expert, but they should understand the organisation and be comfortable guiding a group discussion. Before the session, they should identify the compliance obligations or operational areas to be considered and do some basic analysis of the arrangements already in place. For example, if assessment validation is going to be considered, the facilitator should understand the relevant requirements and identify the organisation’s current validation arrangements. This might include the assessment validation policy and procedure, validation plan, tools and templates, schedules and records of previous validation activities. The facilitator is not doing the risk assessment in advance. They are simply making sure the group has the information it will need to make informed decisions.
You will also need a suitable risk assessment tool to record the discussion, ratings and agreed controls. There is no shortage of risk assessment templates available, and the basic format is reasonably consistent. The important thing is to have the documentation ready before the session rather than designing it as you go. I recommend involving a reasonable cross-section of the organisation. A group of around three to ten people generally works well. Different people see different things, and this is one of the strengths of conducting risk assessment as a group activity. Some participants will contribute more than others, but everyone will hear the discussion and develop a better understanding of the organisation’s compliance arrangements. This helps spread compliance knowledge rather than concentrating it with one manager or compliance person.
Give participants some information beforehand so they understand what they are coming to do. This article might even be useful pre-reading. Depending on the scope, set aside a full day, organise a suitable room, and have a whiteboard available to work through ideas. I also find it useful to have the risk assessment document displayed on a screen, with someone recording the group’s decisions on a laptop as you work through them. These days you could also consider recording the activity using AI and producing A transcript and an analysis later on.
Good preparation makes the assessment itself much easier. The facilitator does not need to arrive with all the answers, but they should understand the obligations, know the organisation’s current arrangements and have everything ready so the group can concentrate on the real task: critically assessing whether those arrangements are good enough.
4. Start small. Focus on one obligation or one operational area
A common risk management mistake is trying to assess too much at once. Standards are broad and legislation is detailed. An RTO’s daily operation involves many moving parts. If you face the whole system, the process quickly overwhelms you. An example of trying to assess too much is trying to assess the risks associated the entire Quality Area 1 (Training and assessment) from the outcome standards. There are just too many moving parts to this. The way is to start small. Risk management works best when focusing on one obligation or one operation part at a time. You choose a single requirement and check your current arrangements. This sets a clear discussion boundary. It keeps people focused and produces better results because the group can delve deeper without drifting.
Explaining this in an example helps. One outcome standard obligation is that trainers must maintain current training and assessment skills (Standard 3.2). This includes ongoing professional development. You could take that single obligation and undertake a risk assessment for it. You would review what the requirement seeks, consider how your organisation manages it today, and think about consequences if not done well. This allows you to ask and answer the questions at the right level. Starting with one area also helps those less comfortable with structured thinking. It gives them a clear starting point. They do not need to map the entire organisation mentally. They only need to review the specific requirement, understand weather the current arrangements are supporting compliance (or not), and share their experience.
This approach has another benefit. Working through individual obligations builds a deeper understanding of your systems. You begin to see patterns. You notice where processes are solid and where they rely too much on individual habits. You also start to see common risk trends which in-turn helps you assess the risks with greater consistency and identify improvements (risk treatments). Risk management does not need to be large or complicated. Breaking the process into small, focused pieces makes the work more accessible. It also becomes more accurate, as people can concentrate on important details.
So, the key take away here is break the standards down into smaller components for the risk assessment. As an example, don’t try and undertake a risk assessment on the entire Quality Area 1 of the outcome standards, instead break this into 8 separate standards which allows you to properly focus on the requirements of each standard.
5. Identify the real risks of non-compliance
After identifying the obligation to assess, the next step is to consider risks if it is not met. In other words, what are the negative consequences if you do not comply with that standard? This is where the process becomes real. You move past the requirements wording to what could happen if your organisation’s systems falter. The goal is not to create long lists of hypothetical problems. The goal is to understand practical consequences from weak systems or inconsistent practice. Start by asking: if we did not meet this obligation, what would be the impact? The answer usually unfolds in layers. There is the immediate impact on students. There is the operational impact on staff. There is the compliance impact during an audit. There is the reputational impact in the market. These are the logical outcomes of a system drifting away from Standard expectations.
Consider the earlier example of trainer professional development. If trainers do not keep skills current, the risk affects students directly. Student’s may not receive needed training depth or quality. Assessment practices may lag sector expectations. New techniques and technologies may not be used. Over time, this creates wider consequences. The organisation could be found non-compliant during a performance assessment and the RTO’s reputation may suffer if the market becomes aware or the regulator shares the information with a funding authority. The student’s individual learning experience may also decline. These are all valid risks from one obligation not managed well or having insufficient arrangements.
Avoid generic statements at this stage. The most useful risks are specific to your organisation and the specific requirement. Consider your delivery modes, cohort size, staff capability, delivery locations, administrative habits, etc. Consider any past issues, even minor ones. Small problems often show how a risk could reappear. Avoid just copying and pasting the same risks from standard to standard.
This step to identify the real risks of non-compliance helps the group see the bigger picture. It changes the conversation from “we need to comply” to “here is what happens if we do not.” That change in thinking is powerful. It encourages better decisions because everyone understands the real impact of non-compliance. Understanding these risks sets you up to consider what arrangements you already have in place to comply with these requirements.
6. Take stock of your current controls
After understanding non-compliance risks, the next step is to review your current controls. This is an important part of the process that many organisations overlook. People often jump from identifying risks to proposing new strategies. Avoid that. Every RTO has existing controls, even if not formally documented. Policies, templates, checklists, training habits, supervisor oversight, staff reminders, and routines all serve as controls. They are not always perfect, but they help reduce a risk event’s likelihood or consequence. Your task is to list controls and understand their practical operation. It’s important here to acknowledge that some of these existing controls may not necessarily be implemented.
It’s quite common for an organisation to maybe have a management meeting policy but when I ask for evidence of the management meetings they undertake, the organisation is not able to provide any. This is a good example of where the organisation has a strategy but they have not implemented the strategy into practice. In this instance, I still want you to identify what arrangements you have got in place but, make a note that they are not being consistently applied.
Going back to the trainer professional development example, you could identify several existing controls. You may have a policy outlining the requirement. You may keep a professional development register for trainers. You may send periodic reminders or expect trainers to submit evidence at set times during the year. These controls may not be perfect, but they form the base for your risk assessment. Clarity about current controls matters because your risk rating must reflect your real operating context. You are not assessing the risk of an organisation doing nothing. You are assessing your organisation’s risk with its current systems. This produces a more accurate likelihood and consequence rating. It also guides future decisions, as you see which controls are working and which controls need improvement.
7. Assess likelihood and consequence using recognised risk tools
After understanding risks and current controls, the next step is to assess risk likelihood and consequence. This is where the process becomes structured. You move from general discussion to a clearer, objective judgment. The goal is not a perfect score. The goal is to reach a shared, evidence-based view of the organisation’s exposure. Most risk management standards use simple tools to guide this process part. They include a likelihood scale, a consequence scale, and a risk matrix. These tools help anchor your thinking in common criteria, not personal opinion. They also help the group reach agreement because everyone works from the same reference point.
A likelihood scale asks how probable the risk is, given your current controls. It usually ranges from rare to almost certain. The important point is to assess likelihood based on what happens in your organisation, not on fear or assumption. If a risk has occurred several times, the likelihood is higher. If it has almost never occurred, the likelihood is lower. Historical patterns matter.
A consequence scale asks what would happen if the risk occurred. This does not exaggerate worst-case scenarios. It involves thinking realistically about operational, compliance, and reputational impact. Consequence scales usually range from insignificant to catastrophic. They help you consider effects on students, staff, audit outcomes, service continuity, financial stability, and reputation. Again, the task is to keep thinking practical.
After agreeing on likelihood and consequence, you combine them using a risk matrix. Most matrices (example below) follow the same format. Likelihood runs down one side. Consequence runs across the top. Where they meet gives you a risk rating. The result is usually low, moderate, high, or extreme. This is your initial risk rating. The following risk evaluation matrix is an extract from our policy and procedure on risk management:
This rating measures your current arrangements’ strength. It tells you if existing controls are enough or if you need to strengthen them. A low rating usually shows the risk is managed reasonably well. A moderate rating usually means that additional control should be considered as a part of your continuous improvement. A high or extreme rating shows current controls are not sufficient to prevent or limit the risk’s impact.
This process part works best when the group takes its time. You do not need long discussions, but you do need clarity. Each person brings their experience. You consider past events, system consistency, and the organisation’s vulnerability if something goes wrong. The goal is consensus. Everyone should feel the rating reflects the organisation’s reality, not a hopeful or pessimistic view. Considering likelihood and consequence in this structured way makes the risk rating a reliable guide. It gives a clear picture of current exposure and sets direction for the next process step which is deciding if the risk rating is acceptable.
8. Decide whether the initial risk rating is acceptable
After getting an initial risk rating, you decide if it is acceptable. This is a straightforward step, but it is one of the most important steps in the process. It forces you to decide if current arrangements are sufficient or if you need to act and implement additional controls. Most organisations adopt a simple rule. A low rating is usually acceptable. A moderate rating may require a strengthening or stronger implementation of existing arrangements. A high or extreme rating requires new controls as a higher priority. This approach keeps the organisation honest. It prevents people from assuming a weak system is “good enough.” It also protects leaders from overlooking risks that could cause major disruption if not addressed.
Understanding why high and extreme risks are unacceptable helps the group stay focused. A high rating shows the likelihood or consequence is more serious than it should be. An extreme rating shows the risk could cause major harm to students, staff, or the organisation. These ratings are a signal. They show current controls are not sufficient to prevent or contain the problem if it occurs. This decision point also clarifies the group’s judgment. If people feel uncertain, the rating itself guides the conversation. A moderate rating means you have reasonable controls, but strengthening them still holds value. A low rating means the risk is stable and current arrangement are working well. No system is perfect, but a low or moderate rating gives confidence that the organisation stands on solid ground.
Make this decision without emotion and try to get to consensus. The rating does not assess performance. It is not a criticism of staff. It simply measures exposure. If the rating is moderate to extreme, the organisation needs stronger controls. That does not mean anyone has done something wrong. It means the system needs reinforcement. When the group accepts this logic, the process becomes much easier. You do not get stuck debating the past. You focus on what needs to change. The rating gives clear direction and prevents the conversation from drifting into general statements. It keeps the team grounded and ready for the next step in the process.
9. Identify smart and efficient additional controls
If the initial risk rating is moderate to extreme, the organisation needs stronger controls. This is where you decide what to add, adjust, or tighten. Think carefully and choose controls that are effective, practical, and realistic for your operation. You do not need to build new systems from scratch. You need to strengthen the parts that matter. When identifying additional controls, start by considering what influences likelihood and consequence. These are two different ideas. A likelihood control reduces the chance of the problem occurring. A consequence control reduces the impact if it occurs. Both are useful, but they serve different purposes. Keeping this distinction clear helps you make smarter decisions.
Likelihood controls are usually proactive. They strengthen a process’s inputs. They improve consistency and prevent drift. Examples include clearer procedures, better templates, stronger supervision, staff training, updated learning materials, quality checkpoints, or small adjustments to task sequencing. Often, clearer expectations reduce likelihood alone. Confusion and inconsistency are common sources of compliance risk. A big part of this is considering whether the existing controls have been fully implemented or not and this may be the first place to start.
Consequence controls are usually reactive. They do not stop a problem, but they limit damage. These controls include backup arrangements, continuity plans, escalation procedures, critical incident training, and clear communication paths. They help the organisation recover faster if something goes wrong. They are useful, but they do not replace the need for robust preventative controls.
Using our trainer professional development example, if the initial risk rating is too high, the group could identify new controls. These include mandatory professional development sessions, scheduled reminders, updated policy requirements, scheduled trainer record review, or a better record keeping process. None of these controls are heavy or intrusive. They are small adjustments that improve consistency and reduce exposure. The most effective controls are often simple. A reminder built into an annual calendar. A checklist added to an existing workflow. A clearer template. A scheduled training session. A change in when evidence is collected. These small steps reduce risk more than large, complex changes that take time to embed. The goal is not to create more work but is to make existing work more reliable.
The group should review the work process itself. Consider the inputs, outputs, supervision, documentation, timings, staff awareness and quality checks. Most improvements fit within this structure. Focusing on these areas makes additional controls targeted and practical. Good controls give people confidence. They make the system more robust without overwhelming staff. They reduce exposure and help the organisation operate with more stability. That is the purpose of this step. To choose improvements that are smart, achievable, and align with how your organisation already works. Sometimes you might identify that your existing arrangements are just not suitable and you need to overhaul these significantly and that’s fine as well.
10. Reassess and determine the residual risk
After identifying additional controls to implement, the next step is to reassess the risk. This process part often gets overlooked, but it is essential. You need to understand how new controls will change the organisation’s exposure. You might recall at the beginning of this article I made the statement that risk assessment “allows you to measure the strengths of your current arrangements”. This is the point when you might adjust your measurement. The goal is to move from the initial rating (if it was unacceptable) to a more acceptable position, based on practical changes that strengthen your system.
You reassess the risk using the same likelihood and consequence thinking. This keeps the process consistent. You consider new controls and ask how they influence the risk’s chance of occurring and its impact. This is not a guess. It is a measured view of how the improved system will operate. Applying this thinking usually shifts the rating. It may drop from high to moderate, or from moderate to low. The result of this second assessment is called the residual risk. This is the risk level remaining once all agreed controls are in place. The organisation must decide if the residual risk is acceptable. In most cases, a low rating is acceptable. If the reassessed rating remains moderate to extreme, the group needs to revisit controls and identify further improvements. The system must be strengthened until the residual risk sits at a level the organisation can manage confidently.
View the residual risk as a baseline, not an end point. It reflects your arrangements’ strength once improvements are implemented. It gives a clear picture of your position and what to expect. It also helps explain your decisions. If someone asks why a control was added or adjusted, the residual risk shows the reasoning. If someone asks you to explain your current arrangements in support of a specific requirement in the standards, you can go to the risk register and identify that your current residual risk for that requirement is assessed at “low” or “moderate” and then explain the current controls that you have identified for this particular requirement. That’s the good thing about this process. It gives you a measure of your compliance and it gives you a register of what strategies you have implemented across the organisation to control this particular risk. This part of the process also reinforces accountability. Once the group agrees the residual risk is acceptable, the organisation has a clear plan for next steps. Controls must be implemented, monitored, and reviewed. That discipline turns a risk assessment from discussion into real practice improvement.
11. Integrate the new controls into normal business
Identifying new controls is not the end. The real value comes from integrating controls into how the organisation actually works. This step turns ideas into action and makes sure improvements agreed during risk assessment are not lost after the meeting. Good controls only matter if implemented, understood, and maintained over time.
First, record decisions clearly. Each new control needs a brief description, a responsible person, and a timeframe. This does not need to be complex. A simple entry in your continuous improvement system is suitable. Someone must own the task, and the organisation must track progress. This creates accountability and helps the executive officer monitor system improvement.
Next, build new controls into existing workflows. This keeps the process practical. For example, if you add a quality checkpoint, position it at a natural workflow point instead of creating a separate step. If you update a policy, make sure it aligns with how staff already complete tasks. If you add a reminder or schedule, embed it into your existing governance calendar or communication cycle. Good controls reinforce the system, they do not add unnecessary weight. Communication is also important. Staff need to understand what is changing, its importance, and how it affects their role. A short explanation is usually enough. People respond well when they know changes are based on clear reasoning and linked to compliance, quality, or student experience. When staff see controls make their work more consistent and predictable, they use them more.
Monitoring new controls is a normal part of business. This does not require extra meetings. Most organisations already have rhythms (existing management meetings) for reviewing progress, checking documentation, or discussing quality issues. New controls should appear in those existing discussions. Over time, you can confirm if changes produce the expected effect. If not, you adjust them. That is the continuous improvement cycle working as intended. Integrating new controls into normal business completes the risk assessment cycle. It makes sure the process leads to genuine organisational strengthening. It is a way to create steady, reliable systems that support students, staff, and overall service quality. The important takeaway here is to manage this through your continuous improvement process so that you have a way of tracking and monitoring its implementation.
12. Use the residual risk as a baseline for governance
Once the residual risk is confirmed, it gives the organisation a clear, measurable view of its compliance position. It shows the current arrangements which are supporting compliance with the relevant standard. The residual risk together with the agreed controls acts as a reference point for later use. If the risk stays low over time, it suggests the controls are working. If the risk increases the following year, it suggests something has changed and the risk needs improved controls. This is a practical way to maintain oversight without over-complicating the process. It is difficult to make progress if you do not know from where you started. Being able to identify a current residual risk and controls tells you the current start point.
This approach also strengthens accountability. When the residual risk and the controls are documented, there is visibility over the actions required, who was responsible, and the expected outcome. If compliance issues arise, it is easier to identify the root cause. For governance, the real benefit is confidence. Leaders make decisions with a clearer understanding of their risk exposure. They allocate resources where most needed. They explain their reasoning to staff and stakeholders. They show how the organisation meets its obligations in a structured, deliberate way. This is what good governance looks like in practice.
When residual risk becomes part of regular oversight, risk management stops being a periodic activity. It becomes a natural part of how the organisation understands its compliance position and maintains effective arrangements over time. It is like tuning an engine. Over time, all engines will drift away from optimal performance. Working to a schedule, we get the engine serviced and tuned to keep it running reliably and within the parameters it was designed to operate. Your RTO’s compliance arrangements are no different. They need regular review and adjustment to ensure they remain effective and continue to support compliance over time.
13. Risk management within the broader governance ecosystem
Risk management does not stand alone. It fits within a wider governance system that keeps an RTO compliant. Good governance is never one activity. It is a set of connected practices that help an organisation stay focused, organised, and compliant. Every RTO already has a system of governance. There is an organisational structure assigning responsibilities, management meetings bringing people together to plan, report, and solve problems. There are continuous improvement processes recording issues and tracking outcomes. There are internal checks helping you confirm if systems work as intended. Each part plays a different role. Together, they provide the structure through which the organisation manages its operations and maintains compliance with its regulatory obligations.
Risk management fits naturally into this environment. It gives leaders a structured way to examine one operational part in detail and understand how it is performing. It helps you plan improvements without relying on guesswork. Risk management is not a replacement for other governance activities. It does not replace meetings, continuous improvement or the need for internal checks. Instead, it helps those activities become more informed. When you understand your risks clearly, you bring better questions to meetings, make clearer decisions about improvement priorities, and conduct more focused internal reviews.
I find it useful to think about these governance arrangements at different levels. Risk management sits at a more strategic level. It allows the organisation to step back from day-to-day activity, consider its regulatory obligations, assess the effectiveness of its current arrangements and decide where additional controls are needed. It provides management with a broader view of where the organisation is exposed and where attention should be directed.
Those decisions then flow into the more operational and tactical parts of governance. Management meetings provide a regular forum to monitor actions and make decisions. Continuous improvement processes help allocate and track the changes that need to occur. Internal quality checks can then test whether those changes have been implemented and are working as intended. A governance calendar helps make sure these activities happen when they are supposed to happen.
This is where I see risk management adding real value. It provides the strategic assessment that informs what happens at the operational level, which in turn drives action within the RTO. Rather than sitting alongside your other governance arrangements as another compliance task, risk management helps give those arrangements direction and priority.
14. Bringing everyone along
One of the mistakes we can make with risk management is assuming that everyone participating needs to understand the process in detail. They do not. The facilitator needs a good understanding of the process because they are responsible for guiding the group through each step. The other participants need to understand what is being considered, what question they are being asked and how their knowledge and experience can contribute.
This is where some simple visual aids can make a big difference. I like to display the risk assessment process on a screen or put it up on the wall so everyone can see where we are. You can also give participants a one-page handout showing the steps. When you reach likelihood and consequence, put the relevant tables in front of people. When you are determining the risk rating, display the risk matrix. People do not need to memorise any of this. They simply need to be able to follow the discussion and understand how the group is reaching its decisions.
The facilitator also has an important role in translating the process into ordinary questions. What are we required to do? What are we doing now? What could go wrong? How likely is that, given the controls we already have? What would the consequences be? Are we comfortable with that level of risk? If not, what could we do differently? These are questions that most people can engage with, regardless of whether they have any previous experience with formal risk management.
There is real value in involving a cross-section of people in these discussions. Trainers, administration staff and managers see different parts of the organisation and will often identify issues or controls that others have overlooked. They are also being given a genuine opportunity to contribute to decisions about how the organisation operates. In my experience, most people respond well to that. They want good outcomes for students and they generally have useful ideas about how the organisation can improve.
We do not need everyone in the RTO to become an expert in risk management. We need a capable facilitator, a clear process and people who are willing to contribute what they know. Done well, the risk assessment becomes a practical way of drawing that knowledge together and using it to make better decisions about how the RTO meets its obligations.
Good training,
Joe Newbery
Published: 27th August 2026
Copyright © Newbery Consulting 2026. All rights reserved.