Capability through digital infrastructure and investment Information and communications technology (ICT) has a crucial role in supporting the organisation’s communication, collaboration and accountability – both internally and externally. Investing in this aspect of our capability has been challenging, given our long-standing fiscal constraints and as a small Commonwealth agency. This planning period, we will develop a roadmap for the implementation of internal audit and other recommendations, which will include improving our ICT infrastructure and enhancing our cyber security and process automation. We will finalise the decommissioning of remaining legacy ICT infrastructure, which will complete the process of transitioning to Microsoft 365 cloud-based systems. We continue to implement the Commission website roadmap, including upgrades on content and style of the existing website, as we also scope and plan for a new website. 7.3 Risk oversight systems and key risk management We adopt a positive risk management culture that promotes an open and proactive approach to managing risk. We achieve this through our governance, risk and compliance mechanisms, such as our Internal Audit function, our Audit and Risk Committee and our Governance Framework subcommittees – Partnerships and Projects, Budget, Strategic Issues and Engagement and Organisational Development and Culture. Our existing risk management framework provides a mechanism for proactively identifying and mitigating risks across the organisation, and for monitoring the operating environment. It includes a risk appetite statement, that identifies the Commission’s attitude towards risk and establishes the amount of risk that we are willing to accept in the work we undertake. The Commission will continue to embed the enterprise-wide risk assessment conducted by our internal auditors in 2023 into our regular systems of risk planning and mitigation practices. This includes streamlining our risk identification process and templates, updating our risk profiles and strengthening planning processes. As part of this risk planning process, we have completed a comprehensive risk assessment of our new regulatory powers at the Commission, including a robust risk identification and mitigation process. The risk management framework is tailored to meet the Commission’s needs. Our positive risk culture encourages the practice of risk identification and the appropriate mitigation of actual, potential, or perceived risks. By identifying, monitoring and reviewing these risks the Commission ensures new risks are identified and existing risks remain appropriately managed. Corporate Plan 2024-2025 19

Select target paragraph3