KNOWLEDGE BASE
REGISTER
Governance Risk Register
Document No:
REG-001
Version:
1.0
Approved by:
Management
Effective Date:
30/06/2026
Review Date:
30/06/2027
Purpose
The Governance Risk Register is used to identify, assess and monitor organisational risks that may affect Bodyfocus Wellness Centre, its employees, patients, services, operations or compliance.
The register supports proactive risk management by documenting identified risks, existing controls and ongoing review activities. It forms part of the organisation's governance framework and assists management to monitor significant organisational risks over time.
Management is responsible for maintaining the Governance Risk Register. The register is stored within the organisation's governance records and is reviewed periodically and whenever significant organisational changes or new risks are identified.
When is this register used?
A new entry may be created whenever a significant organisational risk is identified through activities such as:
Incident investigations
Complaints or feedback
Workplace inspections
Audits or reviews
Legislative or regulatory changes
Management review
Staff feedback
Service delivery activities
Not every issue requires a Risk Register entry. Day-to-day operational matters should generally be managed through the appropriate incident, hazard or complaints process unless they present an ongoing organisational risk.
Register Fields
Risk Category
Select the category that best describes the primary risk.
Category | Description |
Clinical | Risks affecting patient safety, wellbeing or clinical outcomes. |
Workplace Health & Safety | Risks affecting employees, contractors, students, patients or visitors. |
Information & Biosecurity | Privacy, confidentiality, information security or technology risks. |
Workforce | Recruitment, staffing, competency, professional conduct or workforce capability. |
Compliance & Regulatory | Legislative, contractual, professional or NDIS compliance risks. |
Financial | Risks affecting the financial sustainability or operation of the organisation. |
Business Continuity | Risks that may interrupt normal service delivery or organisational operations. |
Reputation | Risks that may adversely affect public confidence or stakeholder relationships. |
These categories are taken directly from the Governance Risk Management Policy.
Likelihood
Estimate how likely the risk is to occur.
Rare
Unlikely
Possible
Likely
Almost Certain
Consequence
Estimate the potential impact if the risk occurred.
Insignificant
Minor
Moderate
Major
Severe
Existing Controls
Record any measures already in place to reduce the likelihood or impact of the risk.
Examples include:
policies and procedures
staff training
supervision
engineering controls
technology controls
business continuity arrangements
These examples are consistent with the Governance Risk Management Policy.
Responsible Person
The person responsible for monitoring the risk and coordinating any required actions.
Status
Status | Description |
Open | Risk has been identified and is being actively monitored. |
Under Review | Risk is currently being assessed or additional controls are being implemented. |
Closed | The risk has been addressed or is no longer considered to require active monitoring. |
Review Date
The date the risk should next be reviewed to ensure controls remain appropriate and effective.
Responsibility
Management is responsible for maintaining the Governance Risk Register and reviewing organisational risks. Employees are encouraged to identify and report risks that may require inclusion in the register. These responsibilities are outlined in the Governance Risk Management Policy.
