← Back to blog

Charity governance risk management: an ACNC-aligned board guide

August 5, 2026
Charity governance risk management: an ACNC-aligned board guide

Three actions your board must take at this meeting to meet ACNC obligations on risk: first, formally set or reconfirm your risk appetite statement; second, confirm a current risk policy is in place and approved; third, verify that a living risk register exists and is scheduled for quarterly board review. These are not aspirational practices. ACNC Governance Standard 5 requires responsible people to act with reasonable care and diligence, manage financial affairs responsibly, and not allow the charity to operate while insolvent. A risk register reviewed infrequently and not actively used does not meet that standard.

Immediate board actions:

  1. Resolve to set or reconfirm the organisation's risk appetite statement.
  2. Confirm the risk policy is current, approved, and accessible to all responsible people.
  3. Schedule quarterly risk register reviews as a standing board agenda item.
  4. Download the ACNC Governance Toolkit and assign a director to review the safeguarding and cyber templates before the next meeting.

Why risk governance is the board's core compliance duty

Governance Standard 5 is not a soft expectation. It places legal duties on every responsible person: act with care and diligence, act honestly and in the best interests of the charity, disclose conflicts of interest, and protect the charity's financial position. Non-compliance can trigger ACNC enforcement actions including formal warnings, directions to change governance practices, or revocation of registration, which puts funding and tax concessions at risk.

The international standard AS ISO 31000 provides the underlying risk management framework most ACNC-aligned charities reference. It positions risk management as an integrated, iterative process rather than a one-off document. For Australian charities, aligning with AS ISO 31000 alongside the ACNC Governance Standards gives boards a defensible, auditable approach that satisfies both compliance and sustainability expectations. The Governance Institute of Australia's risk management guide reinforces this: risk oversight begins with the board and must be integrated with governance and strategy, not delegated entirely to management.

What does an effective charity governance and risk-management framework look like?

Close-up of hands exchanging governance documents on table

The structural elements boards should expect, and who is accountable for each:

ComponentBoardCEO/EDRisk OwnerAssurance
Risk appetite statementSets and approves annuallyCommunicates to staffOperates within itInternal audit confirms
Risk policyApprovesImplementsFollowsExternal review periodically
Risk registerReviews quarterlyMaintains and updatesOwns assigned risksTested by internal/external audit
Incident response plansReceives reportsActivates and leadsExecutesTested at least annually
Assurance mapRequests and reviewsPreparesContributes evidenceLinks risks to controls
Escalation processDefines thresholdsTriggers escalationReports promptlyBoard confirms receipt

A governance-focused assurance map links each risk to its controls and assurance sources, helping boards identify where internal checks suffice and where external assurance is warranted. "What good looks like" at board level is a quarterly dashboard focused on high and extreme risks, clear ownership for every risk, and evidence that treatment plans are progressing, not just listed.

How do you build an ACNC-aligned risk register the board can rely on?

The risk register is the board's primary oversight tool, not a management spreadsheet. Best practice is a formal register reviewed at least quarterly, documenting likelihood and impact, ownership, and mitigation plans. Here is the sequence to build or refresh one:

  1. Establish context — Define the organisation's purpose, operating environment, key stakeholders, and applicable standards (ACNC Governance Standards, NDIS Practice Standards, Aged Care Quality Standards (Strengthened), or National Principles for Child Safe Organisations as relevant).

Minimum register fields: Risk ID, description, category, likelihood score, impact score, residual risk score, current controls, treatment actions, risk owner, due date, and status. A practical guide to community services risk registers covers these fields in detail.

What are the ACNC's four priority risk areas for charities?

Infographic showing ACNC's four priority charity risk areas

The ACNC Governance Toolkit identifies four areas where charities face the greatest governance exposure.

Financial abuse. Misuse of charity funds, whether by staff, volunteers, or third parties. Controls boards must require: segregation of duties, dual-authorisation for payments above a threshold, regular financial reporting to the board, and an annual independent financial review.

Cyber security. Data breaches and system compromise affecting client records and operations. The ACNC Toolkit directs charities to the Australian Signals Directorate's Essential Eight framework for technical controls. Boards should require evidence that the Essential Eight are implemented at an appropriate maturity level, and that incident response plans are tested, not just documented.

Working with partners. Subcontracting, auspicing, and funding-pass-through arrangements create shared risk. Boards must see executed partner agreements that include safeguarding obligations, and management should report on partner compliance at least annually.

Safeguarding vulnerable people. Organisations working with children, people with disability, or older Australians carry heightened duty. Boards must confirm that safeguarding policies align with the National Principles for Child Safe Organisations or equivalent, that staff training records are current, and that any incident is reported to the board promptly.

What should boards actually do in meetings to oversee risk?

Make risk a standing agenda item, but keep it focused. The board's job is to scrutinise high and extreme risks and test management's assurance, not to review every operational issue. AICD's NFP Governance Principles recommend that board reporting on risk be concise, material, and timely so directors can make informed decisions.

Questions directors should ask when reviewing the risk report:

  • Has the residual risk score changed since last quarter, and why?
  • Are treatment actions on track, and who is accountable for overdue items?
  • Have any new high or extreme risks emerged since the last report?
  • What assurance does management have that controls are actually working?
  • Have any incidents occurred that should trigger a register update?

Reporting cadence: quarterly risk dashboard to the board (high/extreme risks only), monthly CEO update for operational hotspots, and an annual framework review that includes a full register refresh and risk appetite reconfirmation.

Pro Tip: Require a one-page "risk spotlight" in every board pack that names the single highest-residual risk, its current treatment status, and the next action. It takes management ten minutes to prepare and gives directors an immediate focus point.

For guidance on when to bring in external compliance support, see why boards need external compliance advice.

How do you embed risk awareness across staff, volunteers, and partners?

Risk culture is what happens when no one is watching the register. Organisations that fail to embed risk into daily operations react to crises rather than preventing them. Three practical steps to change that:

Boards must see partner contracts and evidence of partner adherence to safeguarding policies, not just a signed agreement filed away.

What templates and tools should you use right now?

The ACNC Governance Toolkit is the first stop. It includes downloadable templates for safeguarding risk assessment, cyber security review, and a basic risk register. For most small to medium charities, a well-structured spreadsheet with the minimum fields listed above is sufficient, provided it is reviewed quarterly and version-controlled.

Move from a spreadsheet to specialised risk software when: the organisation manages more than 15 active third-party relationships, an external audit requires a more auditable trail, or the board needs automated escalation and reporting across multiple programmes. Tools such as Protecht, RiskWare, or LogicGate are used in the Australian sector, though the ACNC does not mandate any specific platform.

A project portfolio dashboard approach can help boards visualise risk status across programmes without requiring expensive software.

How one medium human services charity closed its top three risks

A community services organisation with an approved risk register had not reviewed it for an extended period. Several high-risk issues remained unaddressed, including safeguarding policy deficiencies, cyber security vulnerabilities, and partner agreements missing safeguarding clauses.

The board resolved to treat the register as a standing agenda item and assigned a director as risk champion. Within 90 days, management had updated the safeguarding policy to align with the National Principles for Child Safe Organisations, completed an Essential Eight gap assessment with an external IT provider, and renegotiated the partner agreement to include explicit safeguarding obligations. The board moved from three open high risks to zero, and the CEO began reporting a monthly one-page risk spotlight.

What the board asked management to report next: evidence of staff safeguarding training completion rates, results of the first tested incident response exercise, and a partner compliance confirmation from each active subcontractor. This kind of structured gap analysis is exactly the work The Planning and Practice Hub supports with boards across the human services sector.

Key takeaways

Effective charity governance risk management requires a living risk register reviewed quarterly, a board-set risk appetite, and clear ownership of every high risk, all aligned to ACNC Governance Standard 5.

PointDetails
Set risk appetite firstThe board must formally set risk appetite before management can operate within it.
Living register, quarterly reviewA register approved once a year and filed away does not meet ACNC Standard 5 expectations.
Four ACNC priority areasFinancial abuse, cyber security, working with partners, and safeguarding require specific controls and board-level assurance.
Embed risk into operationsIncident reporting pathways and partner onboarding checklists make risk management a daily practice, not a board artefact.
The Planning and Practice HubSupports boards with risk-register builds, governance gap analyses, and board advisory across Australian human services.

The register is not the governance

Most boards I work with have a risk register. The gap is almost never the document. It is the cadence, the ownership, and the board's willingness to ask hard questions when treatment actions are overdue. A register that sits in a folder between AGMs is a compliance liability, not a governance asset.

The shift that makes the most difference is deceptively simple: treat the risk spotlight as a non-negotiable part of every board pack, and hold management to account for the one action that will move the highest residual risk down a rating. That single discipline, applied consistently, changes the board's relationship with risk from reactive to genuinely proactive.

What I see less often, and what the Governance Institute's guidance supports, is boards using an assurance map to know which risks have genuine external assurance behind them and which are relying entirely on management's word. That is the next maturity step for most Australian charity boards.

How The Planning and Practice Hub supports boards with risk and governance

Boards that want to move from a compliance checkbox to genuine risk oversight often need a structured starting point. The Planning and Practice Hub works with boards and executives across Australian human services to build ACNC-aligned risk registers, facilitate risk appetite workshops, and provide ongoing board advisory on governance and compliance.

The Planning and Practice Hub

Engagement options include fixed-price register builds, facilitated board workshops, and retainer-based advisory for organisations that need ongoing support across ACNC, NDIS, aged care, or child safe frameworks. If your board wants a governance gap analysis or a risk-register build scoped to your organisation's size and complexity, contact The Planning and Practice Hub through the human services consulting page to discuss your requirements.

FAQ

What is charity governance risk management?

Charity governance risk management is the board-level process of identifying, assessing, and overseeing risks that could prevent a charity from achieving its purposes or meeting its legal obligations, including those under ACNC Governance Standard 5.

What does ACNC Governance Standard 5 require of boards?

Governance Standard 5 requires responsible people to act with reasonable care and diligence, manage financial affairs responsibly, disclose conflicts of interest, and not allow the charity to operate while insolvent.

How often should a charity review its risk register?

Best practice is quarterly board review of high and extreme risks, with a full register and framework review conducted annually.

What are the four ACNC priority risk areas for charities?

The ACNC Governance Toolkit identifies financial abuse, cyber security, working with partners, and safeguarding vulnerable people as the four areas requiring specific board-level controls and assurance.

When should a charity board seek external governance advice?

When the board lacks internal expertise to assess a high or extreme risk, when an ACNC compliance concern arises, or when the organisation is undergoing significant change, external advice from a specialist such as The Planning and Practice Hub is appropriate.