Risk Register — Year 1 populated
The Risk Register is the single document by which the Board demonstrates that it has considered, rated, controlled, and assigned ownership of every material risk facing Life Without Debt Ltd — as required by the Directors' duty of care and diligence under Corporations Act 2001 (Cth) s.180(1) and ACNC Governance Standard 5. This version contains the Y1 populated set of risks identified pre-lodgement; it will be re-baselined at the first Audit & Risk Committee meeting and refreshed each quarter thereafter.
Each risk has a unique ID (e.g. R-DAT-01) formed as R-CATEGORY-NN. The ID persists across register versions so a risk can be tracked over time even as its rating changes. Each risk is scored on a 5×5 likelihood × consequence matrix (see §2 for the matrix). The inherent rating is the risk before controls; the residual rating is the risk with current controls operating as designed. Where residual is above the Board's risk appetite, a treatment plan is required.
§1 · Scope, purpose, governance
1.1 Purpose. To provide the Board with a comprehensive, dynamically-maintained view of the risks that could prevent Life Without Debt Ltd from achieving its charitable purpose, and to record the controls, ownership, and treatment plans that manage each risk to a level the Board is willing to accept.
1.2 Authority. Corporations Act 2001 (Cth) s.180(1) (duty of care and diligence); ACNC Governance Standard 5 (duties of Responsible Persons); Board Charter §6.1 (Audit & Risk Committee); Compliance Calendar Y1–Y3 Part E (quarterly review cadence).
1.3 Ownership and cadence.
- Ultimate owner: Board of Directors.
- Operational owner: Audit & Risk Committee (reviewing quarterly).
- Register maintainer: Secretary, with input from CEO and BLO Lead.
- Individual risk owners: Named on each row.
- Cadence: Quarterly review by Audit & Risk Committee; annual full refresh at Q4 Board meeting; out-of-cycle refresh triggered by any incident, notifiable data breach, or material change in operations.
§2 · Rating methodology — 5×5 likelihood × consequence
2.1 Likelihood scale (over 12 months):
| Level | Descriptor | Indicative probability |
|---|---|---|
| 1 | Rare | <5% (may occur only in exceptional circumstances) |
| 2 | Unlikely | 5–25% |
| 3 | Possible | 25–50% |
| 4 | Likely | 50–80% |
| 5 | Almost certain | >80% |
2.2 Consequence scale:
| Level | Descriptor | Financial (indicative) | Beneficiary / mission | Regulatory / reputational |
|---|---|---|---|---|
| 1 | Insignificant | <$5k | No beneficiary impact | Internal only |
| 2 | Minor | $5k–$25k | Isolated beneficiary inconvenience | Complaint · minor media |
| 3 | Moderate | $25k–$100k | Beneficiary services degraded for weeks | Regulator inquiry · sector media |
| 4 | Major | $100k–$500k | Beneficiary harm; multiple cases affected | Regulator action · mainstream media |
| 5 | Catastrophic | >$500k | Charity unable to deliver purpose; individual serious harm | ACNC deregistration · civil penalty · front-page media |
2.3 Rating matrix (likelihood × consequence):
| C1 Insig | C2 Minor | C3 Mod | C4 Major | C5 Catas | |
|---|---|---|---|---|---|
| L5 Almost certain | Med | High | High | Extreme | Extreme |
| L4 Likely | Low | Med | High | High | Extreme |
| L3 Possible | Low | Med | Med | High | Extreme |
| L2 Unlikely | Low | Low | Med | Med | High |
| L1 Rare | Low | Low | Low | Med | Med |
2.4 Board risk appetite. The Board's default appetite is Low for regulatory, safeguarding, and data-privacy risks; Medium for operational and financial risks in the ordinary course; Low for reputational risks that could affect beneficiary trust. Residuals above appetite require an approved treatment plan and quarterly reporting until back within appetite.
§3 · Risk categories
Risks are grouped into seven categories to make the register navigable and to align ownership with the sub-committee structure.
- STR — Strategic · risks to LWD's ability to achieve its charitable purpose
- REG — Regulatory & legal · risks arising from statutory obligations (ACNC, ASIC, ATO, DGR, ACL, Fair Work, Privacy)
- FIN — Financial · risks to solvency, reserves, funding, and financial integrity
- OPS — Operational · risks to day-to-day operations (people, systems, third parties)
- DAT — Data & privacy · risks to the confidentiality, integrity, and availability of beneficiary and donor information
- SFG — Safeguarding & beneficiary · risks of harm to beneficiaries, families, and staff
- REP — Reputational · risks to trust with beneficiaries, donors, regulators, and the public
§4 · Risk register — Year 1 populated
Strategic (STR)
| ID | Risk | Cause / event | L | C | Inherent | Controls | Residual | Owner |
|---|---|---|---|---|---|---|---|---|
| R-STR-01 | ACNC registration refused or delayed | PBI subtype eligibility not accepted; charitable purposes drafting challenged | 2 | 4 | Solicitor pre-review; ACNC Portal-Ready doc; PBI CIS 29 Sep 2025 aligned; Public Benefit Memo | Secretary + solicitor | ||
| R-STR-02 | DGR endorsement refused | Gift-fund structure or activities challenged as inconsistent with item 4.1.1 | 2 | 4 | Constitution cl.26–29 gift-fund provisions; DGR-purpose activities documented; DGR Application Package | Treasurer + solicitor | ||
| R-STR-03 | Insufficient founding capital to demonstrate viability | Y1 founding-donor round misses target | 3 | 4 | Three-tier ask ($25k/$100k/$500k+); founding-donor deck & one-pager; case-studies bank; reserves policy target | CEO + Chair | ||
| R-STR-04 | Mission drift into activities inconsistent with charitable purpose | Pressure to expand into general debt-advocacy for non-terminally-ill population | 2 | 3 | Constitution cl.4 (purposes); Board Charter §5.1; Direct Relief Policy eligibility gate | Board |
Regulatory & legal (REG)
| ID | Risk | Cause / event | L | C | Inherent | Controls | Residual | Owner |
|---|---|---|---|---|---|---|---|---|
| R-REG-01 | ACL trigger crossed unknowingly in Y1 | Volume of on-behalf-of hardship engagement with credit providers crosses NCCP s.29 threshold | 2 | 4 | Quarterly volume & scope assessment by CEO + solicitor; ACL Application Package pre-drafted; RG 203 test applied | CEO + solicitor | ||
| R-REG-02 | Corporations Act director duty breach | Undisclosed material personal interest; related-party transaction outside Ch 2E | 2 | 5 | Register of Interests pre-filled + maintained; Conflicts Policy + Related-Party Policy; Chair's script at first meeting; DAS §5.6 | Secretary | ||
| R-REG-03 | ACNC Governance Standard breach | Standard 5 duty; Standard 3 (Australian laws); Standard 6 (external conduct) | 2 | 4 | Compliance Plan; Compliance Calendar; policy suite; annual Board effectiveness review | Secretary | ||
| R-REG-04 | State fundraising authority breach | Active fundraising in a state without authority | 3 | 3 | NSW/Vic/Qld authorities lodged Y1 Q2; solicitor tracks reciprocal recognition; fundraising channels tagged per state | Secretary + solicitor | ||
| R-REG-05 | Late lodgement of AIS / AFR / ASIC review | Deadline missed | 2 | 3 | Compliance Calendar Y1–Y3 (this document's companion); Secretary's diary; A&R Committee quarterly review | Secretary |
Financial (FIN)
| ID | Risk | Cause / event | L | C | Inherent | Controls | Residual | Owner |
|---|---|---|---|---|---|---|---|---|
| R-FIN-01 | Insolvent trading | Board incurs debt when there are reasonable grounds to suspect the company cannot pay | 1 | 5 | Corporations Act s.588G briefing at first meeting; Treasurer monthly cash-flow reporting; Reserves Policy; DAS §5.3 dollar-band thresholds; monthly board dashboard | Treasurer / CoSai | ||
| R-FIN-02 | Reserves fall below policy floor | Cost overrun; direct-relief demand spike; slow donation cycle | 3 | 3 | Reserves Policy floor (6 months operating); quarterly reserves report; direct-relief caps DAS §5.4; Board approval required for >$5k relief | Treasurer | ||
| R-FIN-03 | Fraud or misappropriation | Internal or external actor diverts funds | 1 | 5 | Two-signatory bank rule (DAS §5.7); segregation of duties; external audit/review from Y1 close; fidelity insurance; whistleblower policy | Treasurer + Chair | ||
| R-FIN-04 | DGR gift-fund misuse | Receipted funds used for non-DGR-purpose activity | 2 | 4 | Gift fund ring-fenced in accounting system; annual gift-fund audit trail; Constitution cl.26–29 restrictions; auditor sign-off | Treasurer |
Operational (OPS)
| ID | Risk | Cause / event | L | C | Inherent | Controls | Residual | Owner |
|---|---|---|---|---|---|---|---|---|
| R-OPS-01 | Key-person dependency | CEO (Laurence) or CFO (CoSai/Carla) incapacitated | 3 | 4 | Documented processes; Board Charter delegation; N&R Committee succession watchlist; independent Chair; sub-committee structure spreads knowledge | Chair + N&R Chair | ||
| R-OPS-02 | BLO capacity — beneficiary demand outstrips available casework hours | Founding phase; single BLO; case complexity varies | 4 | 3 | Intake triage per Beneficiary Intake Pack; complexity scoring; warm-referral pathway; quarterly capacity review by Beneficiary Services Committee | CEO + Beneficiary Services Chair | ||
| R-OPS-03 | Third-party service provider failure | Case management system outage; bank outage; email provider outage | 2 | 3 | Australian-hosted providers with SLA; encrypted backups to second region; documented manual fallback for hardship notices; annual restore test | Secretary + IT provider | ||
| R-OPS-04 | Insurance gap — D&O, PL, PI, cyber, fidelity | Cover not in place at incident date | 2 | 4 | All lines bound at Y1 Q1; annual renewal cycle at Y1 Q4 / Y2 Q1; broker review at renewal; Board sights certificates of currency each year | Secretary |
Data & privacy (DAT)
| ID | Risk | Cause / event | L | C | Inherent | Controls | Residual | Owner |
|---|---|---|---|---|---|---|---|---|
| R-DAT-01 | Notifiable data breach affecting beneficiary health information | Phishing; misdirected email; unauthorised access to case management system | 2 | 5 | Privacy Policy §6 access controls; MFA on all systems; role-based case-file access; encrypted at rest & in transit; NDB response plan; staff training | Secretary | ||
| R-DAT-02 | Improper disclosure to a debt collector | BLO shares more than minimum necessary; diagnosis specifics leaked | 3 | 3 | Privacy Policy §5.2 minimum-disclosure rule for collectors; BLO scripts; supervisory review of first 20 collector communications per BLO | CEO + Secretary | ||
| R-DAT-03 | SIS Reg 6.01A medical certificate leak | Highly sensitive certificate leaves the restricted sub-folder inappropriately | 2 | 5 | Privacy Policy §7.1 additional access log; disclosure limited to super trustee only; separate sub-folder; quarterly access-log review by A&R | Secretary + BLO Lead | ||
| R-DAT-04 | Retention over-hold | Records kept beyond schedule; re-identification of "destroyed" case | 3 | 3 | Privacy Policy §11 retention schedule; Records Destruction Register; annual purge job; A&R Committee review | Secretary |
Safeguarding & beneficiary (SFG)
| ID | Risk | Cause / event | L | C | Inherent | Controls | Residual | Owner |
|---|---|---|---|---|---|---|---|---|
| R-SFG-01 | Beneficiary self-harm or acute mental-health crisis identified during intake | Vulnerable population; combined terminal diagnosis + hardship + harassment | 3 | 5 | Intake Pack Step 6 duty-of-care escalation; BLO trained crisis referral (Lifeline, 1800RESPECT); CEO same-day notification; Privacy Policy §4.2 APP 6.2(c) serious-threat exception | CEO + BLO Lead | ||
| R-SFG-02 | Elder abuse / financial abuse of a beneficiary detected | Family member misappropriating beneficiary funds; coerced consent | 3 | 4 | BLO trained detection; Elder Abuse Helpline referral; Consent D third-party protocol; direct-relief payments to beneficiary account only (not third-party) | CEO + Beneficiary Services Chair | ||
| R-SFG-03 | Family violence disclosed during intake | Beneficiary in a coercive household; financial-abuse debts | 2 | 4 | Intake Pack Step 6 escalation; safe-contact method flagged in case file; 1800RESPECT referral; case-file access hardening | BLO Lead | ||
| R-SFG-04 | BLO vicarious trauma / burnout | Repeated exposure to terminally-ill, distressed beneficiaries | 4 | 3 | External clinical supervision monthly; peer debrief cadence; annual EAP; case-complexity throttling by Beneficiary Services Committee; leave policy | CEO |
Reputational (REP)
| ID | Risk | Cause / event | L | C | Inherent | Controls | Residual | Owner |
|---|---|---|---|---|---|---|---|---|
| R-REP-01 | Public perception of "picking winners" | Case selection appears arbitrary or opaque | 3 | 3 | Direct Relief Policy published; eligibility criteria transparent; annual anonymised outcomes report; Beneficiary Services Committee reviews sample | CEO + Chair | ||
| R-REP-02 | Founder-related-party perception risk | Laurence Hugo's disclosed interests + BLO family interest perceived as self-dealing | 3 | 3 | Register of Interests pre-filled + public; Chair's script s.191/192 briefing; Ch 2E recusal on any related-party matter; independent-majority Board target; independent Chair | Chair + Secretary |
§5 · Risk summary — residuals by category
| Category | Risks logged | Residual: Low | Residual: Med | Residual: High | Residual: Extreme | Notes |
|---|---|---|---|---|---|---|
| Strategic (STR) | 4 | 3 | 1 | 0 | 0 | R-STR-03 (funding round) is the outlier; treated via founding-donor pack |
| Regulatory (REG) | 5 | 4 | 1 | 0 | 0 | R-REG-02 residual Medium — reduce with quarterly conflicts audit |
| Financial (FIN) | 4 | 3 | 1 | 0 | 0 | R-FIN-02 residual Medium; watch reserves ratio at each quarterly meeting |
| Operational (OPS) | 4 | 2 | 2 | 0 | 0 | R-OPS-01, R-OPS-02 both key-person / capacity; treated by N&R + committee structure |
| Data & privacy (DAT) | 4 | 2 | 2 | 0 | 0 | R-DAT-01 & R-DAT-03 highest inherent exposure; controls robust |
| Safeguarding (SFG) | 4 | 1 | 2 | 1 | 0 | R-SFG-01 residual High — Board-noted acceptable residual given population served; monitored by Beneficiary Services Committee |
| Reputational (REP) | 2 | 2 | 0 | 0 | 0 | Founder-related-party (R-REP-02) treated by transparent register + independent Chair |
| Total | 27 | 17 | 9 | 1 | 0 | All residuals within appetite except R-SFG-01, which is Board-accepted with monitoring |
R-SFG-01 (beneficiary self-harm risk) has a residual rating of High which is above the Board's default appetite for safeguarding. The Board accepts this residual because (a) LWD's population is by definition at elevated distress; (b) the controls in place (immediate crisis referral, same-day CEO notification, APP 6.2(c) exception) represent best practice; and (c) driving the residual below High would require refusing to serve the highest-need beneficiaries, which is inconsistent with LWD's purpose. The residual is reviewed at every quarterly A&R meeting and reported to the Board at every Board meeting.
§6 · Active treatment plans
Treatment plans are opened for each risk with residual above appetite, and closed when the residual is back within appetite. Y1 open plans:
| Risk ID | Treatment | Owner | Milestone | Status |
|---|---|---|---|---|
| R-STR-03 | Execute founding-donor round using one-pager + deck + case-studies bank; secure at least one Lead Founding Partner or two Founding Patrons by Y1 Q4 | CEO + Chair | Y1 Q4 pipeline review | Open |
| R-OPS-01 | Document all CEO / CFO processes in operating manual; N&R Committee to maintain succession watchlist and consider adding a second BLO in Y2 | N&R Chair | Y1 Q4 succession review | Open |
| R-OPS-02 | Quarterly capacity review; case-complexity throttling; establish warm-referral network with financial counsellors and CLCs by Y1 Q2 | Beneficiary Services Chair | Y1 Q2 network stood up; ongoing | Open |
| R-SFG-01 | Accept residual above appetite; monitor at every A&R meeting; ensure crisis referral SOP is trained annually; consider clinical-social-worker advisor arrangement in Y2 | CEO + Beneficiary Services Chair | Ongoing | Accepted (Board-noted) |
| R-SFG-04 | External clinical supervision monthly for BLOs; peer debrief cadence; annual EAP; case-complexity throttling | CEO | Y1 Q2 supervision arrangement in place | Open |
§7 · Adoption and sign-off
Resolution — adoption of Risk Register (Y1 populated):
"That the Board adopts the Risk Register (Y1 populated, Draft v1.0) as the operative risk log of Life Without Debt Ltd, appoints the Audit & Risk Committee as the standing owner of quarterly review, notes and accepts the residual rating of R-SFG-01 above default appetite for the reasons recorded at §5, and confirms that the Register will be tabled at every Board meeting alongside the Compliance Calendar and any active treatment plans."
- Board Charter §6.1 — Audit & Risk Committee terms of reference
- Compliance Calendar Y1–Y3 — quarterly review cadence embedded in Part E
- Privacy & Beneficiary Data Handling Policy — controls behind R-DAT-01..04
- Beneficiary Intake Pack — operational controls behind R-SFG-01..04
- Direct Relief Policy — controls behind R-FIN-02
- Reserves Policy — controls behind R-FIN-01, R-FIN-02
- Conflicts Policy + Related-Party Policy — controls behind R-REG-02, R-REP-02