The Commission has identified and manages actual, potential or perceived risks within the below profile categories: • Key strategic and foundational enterprise risks: uncertainties that exist or threaten delivery of the Commission’s strategic purpose – such as ensuring the Commission’s governance arrangements are effective, working within a constrained funding environment, maintaining our reputation as a strong independent NHRI, ensuring strong relationships with key stakeholders and partners, and our ability to respond quickly and effectively to a changing political landscape. • Current and topical risks: risks that relate to current and emerging issues – such as ensuring the successful delivery of purpose funded initiatives, responding quickly and effectively to a cyber security incident, and ensuring an engaged and highperforming workforce in a context where the Commission’s work and workload can impact staff health and wellbeing. • Compliance and systems risks: risks associated with core compliance obligations and systems – such as ensuring staff adhere to internal and legislative compliance requirements, ensuring the Commission manages information effectively and complies with its records management requirements and ensuring the Commission has in place effective physical and information security arrangements to protect its assets and information. • Particular Risks: such as fraud, Protective Security, child safety and wellbeing, and work health and safety. • Regulatory Risk – risks associated with the Commission’s new regulatory function - such as grooming and regulatory capture, jurisdictional challenges, conflicting legislation and regulation, political, public, media or stakeholder perception or resistance. Through our implementation of the Enterprise Risk Assessment conducted by our internal auditors in 2023, the Commission will continue to improve our risk maturity through enterprise risk identification, preventative and mitigating controls, and a plan of action to improve these controls. 20 Australian Human Rights Commission Examples of preventative and mitigating controls include: • Strategic and foundational enterprise risks regarding governance controls include our governance framework, transparency of actions and decisions through well-recorded minutes and action items, the Commission’s induction process and training which will be reviewed this planning period. • Financial management and sustainability risk controls include clearly documented budget processes, budget planning, forecasting and reporting with additional training provided to budget managers to improve processes. Advocacy, engagement and programs are effective and delivered as planned with controls including our Corporate Planning process and quarterly reporting processes, with future actions planned to improve coordination and streamlining of work. 7.4 Cooperation and partnerships The Commission positions partnerships as one of its core values and cooperation with government, corporate sector, peak bodies, academia, philanthropic, NGOs, civil society and international organisations is a core part of our work. These partnerships support our legislative mandates and our strategic priorities across the Commission. Our partnerships with government departments and agencies include the Attorney-General’s Department, National Indigenous Australians Agency, Department of Defence, Australian Federal Police, Department of Social Services, Department of Education, and Department of Infrastructure, Transport, Regional Development, Communication and the Arts. Our partnerships with other sectors in Australia include a broad range of NGOs and community organisations, education peak bodies and universities, legal services and the corporate sector. Our partnerships internationally include GANHRI, the Asia-Pacific Forum, the Office of the High Commissioner for Human Rights, Department of Foreign Affairs and Trade funded bilateral ASEAN partnerships in our region and engagement with other NHRIs.

Select target paragraph3