Accountability

How the department watches itself

The risk appetite the audit and risk committee has set, the audit findings it has accepted and how they are being closed, the obligations we are held to and whether we met them, and whether our continuity plans have been tested. Legal matters are counted, not named.

Risk appetite

CategoryStatementTolerated
COMPLIANCEWe have very low appetite for breaching a statutory obligation.medium
FINANCIALWe accept low financial risk; no loss beyond budget tolerance without the council's knowledge.medium
OPERATIONALWe accept low risk to service standards; a breach of a statutory standard is not tolerated for more than a quarter.medium
REPUTATIONWe accept moderate reputational risk when acting lawfully and transparently.high
SAFETYWe have no appetite for avoidable harm to people; a safety risk rated high is escalated at once.medium
STRATEGICWe accept moderate risk in pursuing the community strategic plan's outcomes.high
TECHNOLOGYWe accept moderate technology risk in change, and low risk to the evidence chain and data.medium

Audit findings accepted by the committee

RefFindingSeverityResponseStatus
AF-2026-01Final payments before acquittal acceptanceGrants round RIF-26: probity and acquittalMEDIUMAgreed. Payments agent to check acquittal status before preparing a final payment.OPEN
AF-2026-02Assessor declarations not datedGrants round RIF-26: probity and acquittalLOWDone in the application form.CLOSED

Obligations

ObligationSourceDueStatus
Public interest disclosure policy reviewedPublic Interest Disclosures Act09/09/2026DUE
Publish an AI transparency statementPolicy for the responsible use of AI in government (DTA, 2024)11/09/2026DUE
Risk register reviewed every quarterRisk Management and Internal Audit Guidelines (2022)24/09/2026DUE
Council minutes confirmed after every meetingModel Code of Meeting Practice28/09/2026DUE
Members' disclosure returns lodgedModel Code of Conduct: annual returns of interests30/09/2026DUE
Statutory notices published by their due datesLocal Government Act; EP&A Regulation; emergency legislation14/10/2026DUE
Personal information redacted before submissions are publishedPrivacy Act APP 6; PPIP Act14/10/2026DUE
Overpayment notices carry the 28-day response periodData-matching program guidelines; Robodebt Royal Commission recommendations14/10/2026DUE
Internal reviews decided by a different officerAdministrative law; agency review policy14/10/2026DUE
Business continuity plans tested annuallyISO 22301; Essential Eight backup requirements24/10/2026DUE
Publish the annual reportLocal Government Act s 428 (within five months of year end)31/10/2026DUE
Payment times report lodgedPayment Times Reporting Act03/11/2026DUE
Keep the delegations register current and enforcedLocal Government Act s 377; instrument DI-2026-0113/11/2026DUE
Internal audit plan deliveredIIA Standards; committee charter02/04/2027DUE

Continuity and legal

3 of 4 continuity plans passed their last test. 6 legal matters open. The department acts as a model litigant.