Fraud and Risk Management
National Office
Risk Assurance & Fraud
[redacted — s22(1)(a)(ii)]
Page 160 of 292
Session Outline
-
What is Risk/Risk Management?
-
Why is it important?
-
The Agency’s approach to Risk Management
-
What is your role?
-
Fraud in the Commonwealth
-
The Agency’s approach to Fraud Control
-
What is your role?
What is Risk?
“Risk is the effect of uncertainty on objectives”
AS/NZS ISO31000:2009
Page 162 of 292
Risk Management
Risk Management is the process of identifying, analysing and evaluating risks with a view to ensuring the effective management of potential opportunities while reducing or avoiding adverse effects.
Page 163 of 292
Why is it important?
- To minimise the negative impact of risks upon achievement of objectives; and
- To maximise the Agency’s ability to realise potential opportunities
Prevention is better than the cure.
Risk management is a proactive attempt to identify potential risks and incidents before they happen in order to develop prevention and response strategies.
Requirements:
- CAC Act/PGPA Act;
- NDIS— Risk Management Rules
- APRA CPS 220 (Board policy)
• Risk is part of the way we do business in the Agency, not another thing to do
Risk Management: Benefits
- Increase the likelihood of the Agency achieving strategic and business objectives;
- Encourage a high standard of accountability at all levels of the organisation;
- Support more effective decision making through better understanding of risk exposures;
- Create an environment that enables the Agency to deliver timely services and meet performance objectives in an efficient and cost effective manner;
- Safeguard the Agency’s assets — human, property and reputation; and
- Meet compliance and governance requirements.
Agency Approach - Components
- Risk Management Framework
- Risk Management Strategy
- Risk Management Manual
- Tools and templates
- Intranet site
- Risk Management Champions (per Division & Trial Site)
Risk champions
| Division | Risk CHAMPION |
|---|---|
| GOVERNANCE Division | $22(1)(a)(ii) - irrelevant material |
| OPERATIONS Division | |
| CORPORATE SERVICES | |
| SCHEME ACTUARY | |
| MARKETS Division | |
| SCHEME DESIGN Division | |
| TECHNOLOGY AUTHORITY | |
| CONTRACTS, PROCUREMENT & PROPERTY |
| TRIAL SITE / SITE | Risk CHAMPION | | ACT | $22(1)(a)(ii) - irrelevant material | | NSW | | WA | | NT | | SA | | VIC | | TAS | | NEPEAN BLUE MOUNTAINS (PENRITH) | [redacted — s22(1)(a)(ii)]
Page 168 of 292
Risk Management Framework
- Systematic approach to risk identification & management
- Consistent risk assessment criteria
- Accurate and concise risk information, for decisions
- Cost effective and efficient risk treatment strategies
- Ensure risk exposure remains within acceptable level
- Includes the culture, processes and structures that are directed towards realising potential opportunities while managing adverse effects
Risk Management Strategy
- Covers:
- Risk Governance
- Processes to identify, mitigate and control risks
- Monitoring and reporting risks
- Risk communication and risk culture
- Roles and Responsibilities
- Review process
Governance Arrangements
[Image not converted to Markdown – “Governance Arrangement Diagram” – check the source PDF page for the actual content]
COAG Disability Reform Council
NDIA Board
Sustainability Committee
Scheme Actuary
Chief Risk Officer
Audit and Risk Committee
Chief Executive Officer
Executive Management Team
NDIA staff
Commonwealth Minister (CAC/PGPA Act)
External Auditor (ANAO)
Internal Audit/Independent Review
Independent Advisors (e.g. APRA, Review Actuary)
Assurance, Audit and Risk Committee
Page 171 of 292
Risk Management Processes
Communicate and consult
| Risk context | Risk identification | Risk analysis | Risk evaluation | Risk treatment |
|---|---|---|---|---|
| Objectives | What can happen? | Review controls | Evaluate risks | Further mitigation activities |
| Stakeholders | How can it happen? | Assess consequence | Rank risks | Risk escalation, monitoring and assurance |
| Assessment criteria | Assess likelihood | Risk acceptance (yes/no) | ||
| Define key risk elements | Determine ‘current’ risk level | Determine ‘target’ risk level |
Monitor and review
Monitoring & Reporting
- Three levels of monitoring
- Strategic risks
- Operational risks
- Project risks
Integrated Risk Management
[Image of a flowchart depicting integrated risk management processes]
NDIA Board
-
Corporate Plan & Strategic Plan
-
Divisional Business Plans
-
Branch/Site Business Plans
- Business as usual
- Significant projects
Individual 100 day plans
Page 174 of 292
Reporting & Monitoring
Strategic Risks
- Strategic Risk Treatment Actions Report (quarterly)
- Risks to the delivery of strategic plans or achievement of corporate goals
Operational Risks
- Operational Risk Treatment Actions Report (monthly)
- Risks to the delivery of day to day operations or services
- Specialist risk assessments (e.g fraud, WHS)
Project Risks
- Project Risk Treatment Actions Report (fortnightly)
- Risks to the delivery of individual projects
CRO reviews and prepares summary report for CEO, Board, Strategic Risk Committee, Audit Fraud Risk and Compliance Committee, and/or Audit and Risk Committee as appropriate
Page 175 of 292
Strategic Risks
- People with disability are in control and have choices, based on the UN Convention on the Rights of Persons with Disabilities
-
The Agency fails to build the capacity of people with disability to exercise choice and control
-
The Agency fails to promote the independence and social and economic participation of people with disability
-
The Agency fails to establish mechanisms which effectively measure social and economic outcomes and exercise of choice and control
Page 176 of 292
Strategic Risks (2)
The National Disability Insurance Scheme (NDIS) is financially sustainable and governed using insurance principles
- The Agency fails to meet support package needs within available funding envelopes
- The Agency fails to deliver operational capability within available funding envelopes
- The Agency fails to identify and mobilise IT resources to meet the needs of actuarial and management reporting
- The scope and scale of participation exceeds Scheme design — more people with permanent and significant disabilities
- The scope and scale of supports exceed Scheme design — cost of reasonable and necessary supports
- A reduction occurs in the level of family and community supports and in personal responsibility
- The Agency fails to invest in a lifetime approach, including early intervention
Strategic Risks (3)
The community has ownership, confidence and pride in the National Disability Insurance Scheme and the National Disability Insurance Agency
- Stakeholders perceive that the Scheme has failed to meet the needs of people with disability and/or is too costly
- Sufficient competent providers fail to emerge to meet the new and expanded demand for services
- Sufficient qualified provider staff fail to emerge to meet the new and expanded demand for services
- The Agency fails to meet its reporting obligations to Governments and the Commonwealth Parliament
- The Agency fails to establish an organisational culture and management systems that foster accountability and continuous learning
- The Agency fails to attract and retain sufficient talented leaders and staff to meet the challenges of start-up and/or full scheme rollout