Risk Management: The Glue of Your Compliance System
Most RTOs have a risk register providing a static snapshot of risks they’ve reacted to. Far fewer have a risk management system that tells a cohesive story of how risks are continuously and actively managed. Under the Standards for RTOs 2025, only the second approach is enough to satisfy ASQA.
Done well, risk management is what turns compliance from a list of things you tick off into something integrated and responsive. It connects your training delivery, your validation, your feedback and your continuous improvement into one system rather than a set of unrelated tasks. Done poorly, it is a spreadsheet showing sporadic singular actions taken hodge-podge over the years.
In addition to being a requirement under the 2025 Standards, proactive risk management is simply good RTO business. It is far better to identify and manage your own risks than to have them identified for you, and the management of them directed, by the regulator.
Risk and the 2025 Standards
Risk appears explicitly in several places in the 2025 Standards, and each needs to be dealt with explicitly by your system:
Outcome Standard 1.5 — risks to training outcomes
Outcome Standard 1.8 — facilities and equipment being fit for purpose
Outcome Standard 4.3 — the general risk management standard, explicitly requiring risks to financial position, performance and cash flow, conflicts of interest, and learners under 18 to be identified and managed.
Whose job is it?
A recurring theme of the 2025 Standards is that compliance is everybody’s job, not just the compliance officer’s. This goes for risk identification and management. Every RTO staff member has a role to play.
The compliance team may be accountable for many risks, but identifying them needs the whole organisation. A practical approach is a regular whole-team workshop where staff work through risks and controls together.
Assessing risk: two RTO-specific tips
Most readers will be familiar with the terms ‘likelihood’ and ‘consequence’ when it comes to risk management. There are a couple of RTO-specific things to note about them:
First, assess likelihood against the controls you currently have, not the controls you wish you had. A weak control means a higher likelihood, and being honest about that will give you better results.
Second, assessconsequence from multiple perspectives. Physical danger is only one perspective. Depending on the risk, the meaningful consequence may be financial, regulatory, contractual, or a data breach. The scale and type of consequences will differ depending on where consequences are being viewed from.
Controls, and proving they work
For each risk: do you have a control, is it fit for purpose, is it documented in enough detail, and can you evidence that it is actually being implemented?
That last point is where most RTOs come unstuck. As the saying goes, it’s not what you know it’s what you can prove. You may be managing a risk well, but without a trail to point to, you cannot demonstrate it to ASQA.
The most effective control is usually a documented process with proof it was followed. Other controls include investing in staff capability, collecting the right data to warn you when a risk is materialising, and making the risk register a standing agenda item at every management meeting.
What ASQA is looking for
ASQA increasingly asks not for specific documents but something broader: show us everything you believe demonstrates compliance with Outcome Standard 4.3.
Which means you need to be able to tell a story. Here is how this risk was identified, here is how we evaluated it, here is the control we put in place, and here is the follow-up that confirmed the control was working.
Two related issues when it comes to satisfying ASQA are a policy that over promises and sporadic or incomplete records. Your policy might commit your RTO to monthly risk meetings, and the records show one meeting in the past year. Your procedure and your practice must match Likewise, you might have a register with all the right fields containing two risks identified three years ago and no evidence of management or review since. Even if you HAVE managed and reviewed the risks, you need to be able to show it.
Want more info?
This article skims the surface. The full recording, Risk Management for RTOs, presented by VETNexus compliance consultant Jack Murray, works through detail including the complete risk management process end to end, worked consequence scales across multiple perspectives, exactly what belongs in a sufficiently detailed risk register, the supporting evidence that should sit beneath each entry, and a walkthrough of the new generation of RTO compliance management platforms that link your risk, validation and continuous improvement registers in one place and export audit-ready evidence at the click of a button.
Purchase the recording, or unlock this session and our full library with the VETNexus PD Passport — unlimited access to every webinar, live and recorded, with certificates of attendance that count toward your professional development requirements.
Registered Training Organisations (RTOs) are increasingly relying on AI-generated quizzes uploaded to a Learning Management System (LMS) – a quick AI prompt, a neatly generated quiz, and up it goes, job done. Except…it isn’t.
While AI-generated assessments can be comprehensive and substantively sound, simply uploading them to an LMS without thoughtful adaptation often results in poorly designed, generally non-compliant assessment tools.