Enterprise management

Direction and guidance on the frameworks, procedures and standards designed to ensure compliance with department objectives in relation to enterprise risk management, legislative compliance, business continuity, enterprise data governance, evaluation, and fraud and corruption control.

Audience

All staff including temporary and casual staff, contractors and volunteers.

Version Date Description of changes Approved by

V04.0.1

28/11/2025

Clarified information and improved readability. Updated policy owner and references.

Executive Director, Chief Risk Office Transition Support and Chief Audit Executive

V04.0.0

26/07/2024

Under the 2023 Policy and procedure review program, this policy is consolidated with the Evaluation, Enterprise Data, Business Continuity Management, Legislative Compliance and the Fraud and corruption control policies. Policy name changed from Enterprise risk management, converted into new template and improved readability.

Chief Risk Officer

Document history

2022 Oct 17 - updated the policy statement and the Enterprise Risk Management Framework to more closely align to ISO31000:2018 Risk Management Guidelines.

2021 May 07 - updated policy in line with international standard ISO31000:2018 and NSW Treasury TPP-20-08 Internal Audit and Risk Management Policy for the General Government Sector. Updated to clarify the risk hierarchy and reporting cadence.

Removed implementation document: Enterprise Risk Management Procedures, which was replaced by: Enterprise Risk Management Framework.

2019 Aug - made typographical changes and updated contact details to policy statement.

2019 Jun - updated reference to the new Strategy and Delivery division and deputy secretary as well as to the revised risk standard ISO31000 (no significant changes).

2017 Jun update:

  • improved clarification of roles and responsibilities and included requirement to use the risk matrix to ensure consistency in risk ratings across the department
  • simplified and shortened procedures, and simplified risk matrix.

Previous title: Enterprise Risk Management in the Department of Education and Communities.

Superseded documents

Enterprise Risk Management Procedures - 7/5/21

Risk Management Policy, 91/090 (S.062), 24/4/91

  1. Policy statement
    1. Effective risk management supports the achievement of objectives by identifying and managing risks. All employees must manage risk in their roles and in accordance with the enterprise risk management framework and relevant policies and procedures.
    2. The department is responsible for applying and implementing key legislation. The responsible officer of the relevant business unit has primary responsibility for legislative compliance.
    3. The department must build organisational resilience and enhance continuity of critical business services at an acceptable level by being able to anticipate, prepare for, respond to, recover from and adapt to disruptions.
    4. Data and information the department collects or acquires must be stored and effectively managed.
    5. Department programs, projects, strategies, policies and initiatives must be evaluated for their effectiveness in improving education outcomes for students and supporting the effective, efficient, appropriate and transparent use of public resources.
    6. The department must apply risk management principles and develop, implement and maintain an effective fraud and corruption control system, incorporating prevention, early detection and effective responses to fraud and corruption events in ways that achieve optimal outcomes for the department.
  2. Context
    1. The following procedures support this policy:
      • Enterprise data standards
      • Enterprise risk management framework
      • Evaluation
      • Fraud and corruption control procedures and framework
      • Legislative compliance
      • Resilience and business continuity management.
    2. The relevant legislation, standards and guidelines include:
  3. Policy contact
    1. Enterprise risk management
      Executive Director, Chief Risk Office Transition Support
      Chiefriskoffice@det.nsw.edu.au

      Legislative compliance
      Manager, Compliance and Privacy, Legal Services
      LegislativeCompliance@det.nsw.edu.au

      Resilience and business continuity management
      Director, Controls Monitoring Advisory
      Chiefriskoffice@det.nsw.edu.au

      Enterprise data
      Manager Data Governance,
      Centre for Education Statistics and Evaluation
      CESEPolicy@det.nsw.edu.au

      Evaluation
      Director, Evaluation and Effectiveness, Centre for Education Statistics and Evaluation
      info@cese.nsw.gov.au

      Fraud and corruption control
      Director, Controls Monitoring Advisory
      Chiefriskoffice@det.nsw.edu.au
  4. Monitoring the policy
    1. The Executive Director, Chief Risk Office Transition Support and Chief Audit Executive monitors the implementation of this policy, regularly reviews its contents to ensure relevance and accuracy, and updates it as needed.


Return to top of page Back to top