Agency Approach
- Requirements:
- CAC Act/PGPA Act;
- NDIS — Risk Management Rules
- APRA CPS 220 (Board policy)
- Risk is part of the way we do business in the Agency, not another thing to do
Page 129 of 292
Agency Approach - Components
- Risk Management Framework
- Risk Management Strategy
- Risk Management Manual — Tools and templates
- Intranet site
- Risk Management Champions
Page 130 of 292
Risk Management Framework
- Systematic approach to risk identification & management
- Consistent risk assessment criteria
- Accurate and concise risk information, for decisions
- Cost effective and efficient risk treatment strategies
- Ensure risk exposure remains within acceptable level
- Includes the culture, processes and structures that are directed towards realising potential opportunities while managing adverse effects
Risk Management Strategy
-
Approved by CDRC
-
Covers: — Risk Governance — Processes to identify, mitigate and control risks — Monitoring and reporting risks — Risk communication and risk culture — Roles and Responsibilities — Review process
Governance Arrangements
[Image not converted to Markdown – “Governance Arrangement Diagram” – check the source PDF page for the actual content]
COAG Disability Reform Council
Sustainability Committee - NDIA Board - External Auditor (ANAO)
Scheme Actuary - Audit and Risk Committee - Internal Audit/Independent Review
Chief Executive Officer - Independent Advisors (e.g. APRA, Review Actuary)
Chief Risk Officer - Executive Management Team - Assurance, Audit and Risk Committee
NDIA staff
[redacted — s22(1)(a)(ii)]
Commonwealth Minister (CAC/PGPA Act)
Page 133 of 292
Risk Management Processes
[redacted]
Communicate and consult
Risk context - Objectives
- Stakeholders
- Assessment criteria
- Define key risk elements
Risk identification - What can happen?
- How can it happen?
Risk analysis - Review controls
- Assess consequence
- Assess likelihood
- Determine ‘current’ risk level
Risk evaluation - Evaluate risks
- Rank risks
- Risk acceptance (yes/no)
- Determine ‘target’ risk level
Risk treatment - Further mitigation activities
- Risk escalation, monitoring and assurance
Monitor and review
Page 134 of 292
Monitoring & Reporting
- Three levels of monitoring
- Strategic risks
- Operational risks
- Project risks
Integrated Risk Management
[redacted]
Strategic Plan
- Strategic Risks
- Strategic Risk Management
- Operational Risks
- Operational Risk Management
- Significant Projects
Corporate Business Plan
Divisional Business Plans
Branch/Site Business Plans
Business as usual
Significant projects
Individual Performance Agreements
Page 136 of 292
Reporting & Monitoring
Strategic Risks - Risks to the delivery of strategic plans or achievement of corporate goals
Operational Risks - Risks to the delivery of day to day operations or services, Specialist risk assessments (e.g. fraud, WHS)
Project Risks - Risks to the delivery of individual projects
CRO reviews and prepares summary report for CEO, Board, Strategic Risk Committee, Audit Fraud Risk and Compliance Committee, and/or Audit and Risk Committee as appropriate
Strategic Risks
- People with disability are in control and have choices, based on the UN Convention on the Rights of Persons with Disabilities
-
The Agency fails to build the capacity of people with disability to exercise choice and control
-
The Agency fails to promote the independence and social and economic participation of people with disability
-
The Agency fails to establish mechanisms which effectively measure social and economic outcomes and exercise of choice and control
Page 138 of 292
Strategic Risks (2)
The National Disability Insurance Scheme (NDIS) is financially sustainable and governed using insurance principles
- The Agency fails to meet support package needs within available funding envelopes
- The Agency fails to deliver operational capability within available funding envelopes
- The Agency fails to identify and mobilise IT resources to meet the needs of actuarial and management reporting
- The scope and scale of participation exceeds Scheme design — more people with permanent and significant disabilities
- The scope and scale of supports exceed Scheme design — cost of reasonable and necessary supports
- A reduction occurs in the level of family and community supports and in personal responsibility
- The Agency fails to invest in a lifetime approach, including early intervention
Strategic Risks (3)
- The community has ownership, confidence and pride in the National Disability Insurance Scheme and the National Disability Insurance Agency
-
Stakeholders perceive that the Scheme has failed to meet the needs of people with disability and/or is too costly
-
Sufficient competent providers fail to emerge to meet the new and expanded demand for services
-
Sufficient qualified provider staff fail to emerge to meet the new and expanded demand for services
-
The Agency fails to meet its reporting obligations to Governments and the Commonwealth Parliament
-
The Agency fails to establish an organisational culture and management systems that foster accountability and continuous learning
-
The Agency fails to attract and retain sufficient talented leaders and staff to meet the challenges of start-up and/or full scheme rollout
Page 140 of 292
Progress
- Strategy
- Strategic risks
- Framework
- Risk Management Manual
- Intranet site
- Risk Management Champions
- Business Planning processes
Your role
- Be familiar with the Agency’s risk management strategy and policy;
- Alert managers to the presence of risks and participate in their management; and
- Use the tools available to identify and manage risks in the workplace
- Give us feedback
Fraud Control
“Dishonestly obtaining a benefit, or causing a loss, by deception or other means”
Page 143 of 292
Fraud against the Commonwealth
Includes (but is not limited to):
- Theft
- Accounting fraud (false invoices, misappropriations etc.)
- Unlawful use of, or unlawfully obtaining, property, equipment, material or services
- Causing a loss, or avoiding and/or creating a liability
- Providing false or misleading information to the Commonwealth, or failing to provide it when there is an obligation to do so
- Misuse of Commonwealth assets, equipment or facilities
- Making or using false, forged or falsified documents
- Wrongfully using Commonwealth information or intellectual property
- Bribery, corruption or abuse of office
Page 144 of 292
Fraud and Error
-
Fraud is a criminal offence
-
Fraud is based on deception
-
An error is not fraud
-
If you make a mistake — Tell your supervisor about the error — Follow it up with an email — Keep a record of the email
Agency’s Approach to Fraud Control
- Fraud Control Framework & Plan
- APS Values and Code of Conduct
- Fraud Policy Statement
- Fraud Awareness Education
- Financial rules
- Governance arrangements — Prevention and detection strategies
Internal Fraud
- Involves staff
- Examples:
- Falsifying a medical certificate or statutory declaration
- Cheating on a flex sheet
- Unauthorised disclosure of information
- Claiming travel allowance you are not entitle to
- Failing to record, or incorrect recording of, leave
- Misuse of Cabcharge vouchers
- Use of the Corporate credit card for personal gain
Page 147 of 292
… and more
- Using office printers for non-work related printing
- Internet — unreasonable personal use of internet, including emails and communicator/Lync
- Failing to secure portable assets such as TVs during relocation/renovations
- Personal use of pool vehicles/fuel cards
- Stealing laptops/phones/GPS devices
False information
- Providing false information includes:
- Backdating and post signing of records
- Altering funding agreements/contracts etc. after the event
- Submitting information in reports, acquittals, returns etc. that the author knew did or did not happen, and is untrue
Page 149 of 292
Internal Fraud - Penalties
-
Internal fraud can result in criminal prosecution, and/or investigation under the APS Code of Conduct.
-
Penalties can include:
- Dismissal
- Demotion
- Loss of Commonwealth contributed superannuation
- Criminal conviction
- Imprisonment
Page 150 of 292
Corruption & Collusion
- How can it happen?
-
Internal/external collusion — if a staff member colludes with an external supplier to procure goods/services to get a personal benefit
-
“kick-backs” — payments made by service provider organisations to their employees/executive using Commonwealth funding
-
Acceptance of gifts/hospitality over specified amounts
Conflict of Interest
• A conflict of interest occurs when an employee is influenced, or may be perceived to be influenced, by personal interests when conducting his/her official duties
• If you have a conflict of interest, or are unsure, talk to your manager
External Fraud
- Fraud by participants
- Fraud by providers
External fraud — some examples
- Examples include:
- Community organisations receiving funds from the Agency and fraudulently misusing the money
- Providing false or misleading financial information/reports to the Agency
- Overcharging the Commonwealth for services
- Submitting false invoices
- Misuse of assets (including unauthorised acquisition or disposal)
- Submitting audit reports that are not independent or are inaccurate
Page 154 of 292
Things to watch out for
• Things to watch out for:
- Breeches to funding agreement/grants guidelines
- Delays in providing reports or answering communications
- Failure to submit reports required
- Lack of records for invoices and purchase orders
- Conflicts of interest in the Board/CEO
- Complaints from ex-staff or clients
- Poor internal controls and lack of policies in organisations
- High staff turnover
- Poor governance – no separation of duties, one person performing multiple roles
External fraud - penalties
- Penalties and sanctions may include:
- Criminal conviction
- Imprisonment
- Fine
- Repayment of monies
- Confiscation of assets
Page 156 of 292
Your role
- Report all incidents of suspected or potential fraud immediately to the Fraud Prevention and Detection Section or to your SES manager for potential investigation — Or see the intranet for contact details
- Report any weaknesses in Agency business controls or processes that might facilitate fraud against the Commonwealth — to the same
What not to do
- DO NOT — Attempt to investigate the fraud yourself — Alert the suspect — Mark or unnecessarily handle documents or material — keep in original condition — Discuss the matter with anyone, including colleagues, other than for appropriate reporting purposes
Page 158 of 292
National
ability Contacts
¢ Helen McKenna — (02) 6146 3464
Page 159 of 292