Quick Answer:

Audit-ready risk management means you can produce evidence, not just documents. Regulators and auditors look for seven things: a documented assessment process, a current risk register with named owners, controls mapped to risks, policies staff have actually acknowledged, training records with dates, an incident framework that feeds back into the register, and third-party risk documentation. What fails audit-ready risk management is rarely the absence of a policy. It is the inability to show that a control was operating on the date it mattered.

The scale is not abstract. Australian workplaces recorded 146,700 serious workers’ compensation claims in 2023-24, and the Fair Work Ombudsman recovered more than $358 million in unpaid wages for over 249,000 workers in 2024-25. Behind most of those numbers sits an organisation that had policies.

Most organisations that struggle in a regulator audit are not negligent. They have compliance policies, a risk register and a training programme.

What they cannot do, under time pressure, is show that any of it was operating on the day something went wrong.

That gap between having documentation and having evidence is what audit-ready risk management closes.

This guide sets out what regulators look for, what causes findings, how to build a framework that holds up, and how to prepare before anyone asks.

Sentrient builds workplace compliance software for Australian and New Zealand organisations, including a risk management system that timestamps the evidence an audit asks for.

What Does Audit-Ready Risk Management Really Mean?

Beyond having policies on paper

Audit-ready risk management starts here. Compliance policies are statements of intent. Audit readiness is the ability to show that the intent was carried out, by whom, and when.

A well-written policy nobody has read is not a control, and auditors treat it as one of the weaker forms of evidence precisely because it is so easy to produce.

Demonstrable governance and oversight

Governance has to leave a documentation trail. Meeting minutes where risk assessment was discussed, decisions recorded with the reasoning, escalations that went somewhere.

Regulators read governance documentation for evidence of active oversight. If risk only appears in board papers as a static appendix, that is visible, and it reads as oversight in name rather than in practice.

Clear risk ownership and accountability

Every significant risk needs a named risk owner with the authority to act.

Ownership recorded as a department or a committee is the single most common finding, because when an auditor asks who decided something, there is no one to ask.

Continuous monitoring versus static controls

Continuous monitoring matters because a control assessed once and never revisited is an assumption.

Regulation 38 of the model WHS Regulations requires control measures to be reviewed when they stop working, before a workplace change likely to create a new risk, when a new hazard is identified, or when a health and safety representative requests it.

Those are events, not dates, and an audit will ask how you detect them.

Who Actually Audits You In Australia

“Regulator” covers a wide range of bodies with different powers and different interests. Knowing which apply to you determines what audit-ready risk management has to prove.

Who What they look at What they will ask for
WHS regulator (SafeWork NSW, WorkSafe Victoria and equivalents) Whether risk was eliminated or minimised so far as is reasonably practicable Risk assessments, the hierarchy of control applied in order, training records, consultation evidence
Fair Work Ombudsman Employment obligations, record keeping, pay slips Employment records, policy acknowledgements, complaint handling evidence
Sector regulators (NDIS Commission, ACQSC and similar) Compliance with sector quality standards Incident records, worker screening, training completions, continuous improvement evidence
Internal audit or the board Whether the framework operates as described Control test results, register change history, reporting trail
Insurers and clients Whether risk is actively managed Register, governance records, incident trends, remediation evidence

The five ask overlapping questions in different language, which is the practical argument for one evidence base rather than a separate pack per audience.

An organisation maintaining five parallel sets of records is not more audit-ready, it is more likely to have them disagree.

Note that an insurer or a major client asking these questions is not a regulator, and has no enforcement power. They can decline to renew, which in commercial terms is often the sharper consequence.

The 7 Components Regulators Expect To See

These are the components of audit-ready risk management that an auditor will ask for, and what each has to demonstrate.

Component What it must show Common finding
1. Documented risk assessment process A repeatable method, consistently applied Method exists but is applied differently by each team
2. Current risk register Live entries, named owners, review dates Last substantive update was before the previous audit
3. Control mapping Each risk linked to specific controls, and each control tested Controls listed as text, never verified
4. Policies and procedures Current versions, acknowledged by staff, with dates Policy current, acknowledgements missing or undated
5. Training and awareness Completion records tied to individuals and roles Training delivered, completion not evidenced
6. Incident management framework Reports, investigations, actions closed, and feedback into the register Incidents logged but never connected to the risk they relate to
7. Third-party risk documentation Assessment of suppliers, and evidence of ongoing review Assessed at onboarding, never revisited

Components 4, 5 and 6 are where most Australian organisations lose ground, and all three are records problems rather than practice problems.

The work is usually being done. The dated proof is not being kept.

The 7 Components Of Audit-Ready Risk Management In Practice

The table above says what each component must show. This is what good looks like for each, and where audit-ready risk management usually breaks down in an Australian organisation of 50 to 500 staff.

1. Documented risk assessment process

A written method covering how risks are identified, who rates them, the scale used, and when ratings are revisited.

The risk assessment failure is rarely absence. It is inconsistency: two teams using the same 5×5 matrix with different definitions of likely, producing ratings that cannot be compared.

Agree the frequency bands once and write them down.

2. Current risk register

Live entries with inherent and residual ratings, a named owner, a review date and a change history.

An auditor will look at the modification dates before they look at the content, because a register with all entries updated in the same fortnight tells its own story.

3. Control mapping and internal controls

Each risk linked to specific named controls, each control attributed to someone, and evidence that it has been tested.

This is where the most findings land. Listing “staff trained” as a control without a completion record is an assertion, not a control.

4. Policies and procedures

Current policy versions, with acknowledgement records showing who accepted which compliance policies and when.

The OAIC found human error caused 37% of notifiable data breaches between January and June 2025, up from 29%, which is a useful reminder that records failures are usually process failures.

Version control matters more than people expect: acknowledging v3 does not evidence compliance with v5, and an auditor checking one policy against its acknowledgement dates will find that quickly.

5. Training and awareness programs

Completion records tied to named individuals, with dates, mapped to roles.

Legally endorsed content matters for high-risk topics such as bullying, sexual harassment and manual handling, because generic material may not evidence due diligence to the standard expected.

6. Incident management and reporting framework

Reports captured, investigations documented, corrective actions closed with evidence, and the result fed back into the register.

The connection back to the register is the part almost always missing, and it is what allows a risk to remain rated as well controlled while events keep occurring against it.

7. Third-party risk management documentation

Assessment of suppliers and contractors at onboarding, and evidence of ongoing review.

Under WHS law you cannot contract out of your primary duty of care, and where duties overlap the law requires duty holders to consult, cooperate and coordinate.

“We use a licensed contractor” is not an answer to a question about supervision.

What Regulators Actually Review During An Audit

Governance records

Board and committee minutes, risk reports, escalation records and decision logs.

A regulator or auditor is looking for whether risk information reached the people accountable for it, and what they did with it.

A well-formatted report that produced no decision is evidence of process, not of governance.

Evidence of control effectiveness

Not whether controls exist, but whether the controls work. Test results, verification records, sampling, dated checks.

This is the single largest documentation gap in most organisations, because control effectiveness is the column left blank in almost every risk register, and testing evidence is what fills it.

Data integrity and reporting accuracy

Whether the numbers reconcile. If the register says twelve high risks and the board pack says nine, both documents become unreliable, and the regulator or auditor will start checking your other documentation more carefully. Version control problems do more damage than the discrepancy itself.

Audit trail and change management records

Who changed what, when, and with whose approval. A risk register with no change history cannot demonstrate that the documentation was maintained rather than reconstructed, and reconstructing a register before an audit is both obvious and damaging.

How To Actually Test A Control

Every section above points at control testing, and almost no risk management documentation explains how to do it.

This is the gap that produces more audit findings than any other, so it is worth setting out properly.

Testing a control means gathering evidence that it operated as designed, over a period, for the population it covers.

It is not the same as confirming the control exists, and a regulator or auditor reviewing your documentation will make that distinction immediately.

The four testing methods

Method What you do Evidence it produces Best for
Enquiry Ask the people who operate the control how it works Interview notes. Weakest form on its own Understanding the process before testing it
Observation Watch the control being performed Dated observation record Physical controls, inductions, site checks
Inspection Examine documentation or system records Sampled records with dates and names Policy acknowledgements, training completions, approvals
Re-performance Independently perform the control yourself Your result compared against the recorded one Calculations, access reviews, register accuracy

Enquiry alone is not testing, and describing a conversation as evidence of control effectiveness is a finding waiting to happen.

Regulators expect inspection or re-performance for anything material, and an internal compliance review should apply the same standard.

How much to sample

You do not need to test every instance. For a control operating monthly, testing two or three periods across the year usually supports a conclusion.

For a daily control, a sample of 15 to 25 records is a common starting point, and for anything low-volume the honest answer is to test all of it.

Record the population size, the sample size, how the sample was chosen, and the result including any exceptions.

An exception found and documented is far stronger evidence of a working framework than a clean result with no method recorded.

What testing evidence should contain

  • The control being tested, and the risk it is mapped to in the risk register
  • The period covered and the date of the testing
  • Who performed the testing, and confirmation they do not operate the control themselves
  • The method used, from the four above
  • Population, sample size and selection basis
  • The result, including exceptions and what was done about them

The most common testing failure

Self-assessment. The person who operates the control also confirms it is working, usually in a spreadsheet with a tick. Regulators and internal audit both treat that as unverified, because independence is what makes testing evidence rather than assertion.

At 50 to 500 staff you rarely need an internal audit function. You need the reviewer to be someone other than the operator, which is a governance decision rather than a resourcing one.

How often to test

Test the controls attached to your highest-rated risk assessments quarterly, and work through the rest across a rolling annual programme.

Also test after any change to how the control operates, and after any incident where the control should have prevented the outcome and did not.

That last trigger is the one most often missed, and it is exactly the case a regulator will ask about.

Two or three controls tested properly each quarter beats forty reviewed on paper.

Documentation of a review that consisted of reading the control description is not testing, and it will not survive scrutiny.

What Regulators Do Not Want To See

What they see Why it counts against you What to do instead
Generic templates with no customisation Risks that do not match your operations show the assessment was never done Rewrite entries in the language of your own work
Policies staff do not follow Gap between the document and practice suggests the document is decorative Acknowledge, train, and spot-check that it happens
Outdated risk assessments A date years old signals the framework is dormant Review on regulation 38 triggers as well as a cycle
No evidence of testing or monitoring Controls are assumed to work rather than known to Test two or three properly each quarter and record it
Reactive rather than proactive management Entries created after incidents show the register follows events rather than anticipating them Add risks from near misses and change, not only from incidents

There is a pattern in that column. Every one of them is visible from your documentation alone, without a regulator needing to interview anybody. That is worth knowing, because it means these findings are avoidable before anyone arrives.

Building Audit-Ready Risk Management That Stands Up To Scrutiny

Align with recognised frameworks

ISO 31000, adopted in Australia as AS ISO 31000, gives the principles.

Alignment is not certification and should not be described as such, but referencing a recognised compliance framework shows the risk management framework was designed rather than improvised. The enterprise risk management framework guide covers the structure.

Embed risk into daily operations

Audit-ready risk management cannot be assembled in a fortnight. Risk management that only appears at audit time is visible to a regulator as such.

Where risk assessment features in project approvals, budget decisions and change processes, the documentation trail generates itself as a by-product of ordinary work, which is the only sustainable way to stay audit-ready.

Establish measurable key risk indicators

Key risk indicators give early warning and, just as usefully, give a regulator or auditor something quantitative to look at as part of ongoing monitoring.

A KRI with a threshold, a trend and a documented response is stronger evidence than any narrative.

Periodic independent reviews

Independent review is part of audit-ready risk management. Someone who did not build the framework should test it at least annually.

It does not require an internal audit function at 50 to 500 staff. It requires that the reviewer is not the person being reviewed, which is a governance point rather than a resourcing one.

Where this sits against maturity

Audit readiness and risk management maturity are related but not the same. Maturity describes how embedded risk management is across five levels. Audit readiness describes whether you can evidence it right now.

Most organisations at maturity level 3 have audit-ready risk management in place. Level 2 organisations often are not, because the register is updated for the audit rather than maintained through the year, and that shows in the change history. For the full five-level model and how to move up, see the maturity guide.

How To Prepare For A Regulatory Audit, Step By Step

Step 1: Conduct a mock audit

Ask someone internal to request documentation as a regulator or auditor would, with the same time pressure.

Most gaps surface in the first hour, and the exercise is more useful than any checklist because it tests retrieval rather than existence.

Step 2: Review and update risk assessments

Work through the risk register and re-rate each risk assessment against what has actually happened since.

Any risk assessment nobody can explain should be re-identified properly rather than carried forward, because an entry you cannot justify is worse than one that is missing.

Step 3: Test controls before regulators do

Pick the controls attached to your highest-rated risks and complete proper control testing on them, using the methods set out above.

If a control cannot be tested, that itself is a finding worth recording, and recording it is better than being asked about it.

Step 4: Train leadership and staff

People a regulator may interview should know where risk management documentation lives and who owns what.

Coaching answers is the wrong approach and auditors recognise it. Making sure the answers exist is the right one.

Step 5: Organise documentation in advance

Retrieval time is itself evidence of how your compliance documentation is maintained.

An organisation that produces a worker’s full training and compliance policy documentation in minutes reads differently from one that takes three days, even where the underlying records are identical.

The Evidence Test

There is one question that predicts audit-ready risk management better than any checklist. Pick a worker and an incident, real or hypothetical, and ask:

The question

What training had this person completed before this incident, when did they complete it, and which version of the relevant policy had they acknowledged at that date?

If that takes minutes, you are audit-ready. If it takes days, you are not, regardless of how comprehensive the policy library is.

It works as a test because it cuts across every component at once.

It needs a current register, a control mapped to the risk, a training record tied to an individual with a date, policy version control, and an incident record connected to the risk it relates to. Any weak link shows up immediately.

Answer time What it means What an auditor concludes
Under 5 minutes Records are connected and current Systems are being maintained through the year
An hour or two Records exist but are in separate places Workable, but reconstruction risk under pressure
Days Records are fragmented or incomplete The framework may not have been operating as described
Cannot answer No link between training, policy and incident Findings likely across several components

Run it on three different workers before an audit rather than one. Consistency is what an auditor is actually testing, and a single good example proves less than three ordinary ones.

What Happens After A Finding

Most audits produce findings, even where audit-ready risk management is strong. How an organisation responds is itself assessed, and a well-handled finding is a smaller problem than a defensive one.

Finding type What it usually means Typical expectation
Observation A weakness with no immediate breach Note it, address it in the ordinary cycle
Minor finding A control gap that has not yet caused harm Corrective action with an owner and a date, usually 30 to 90 days
Major finding A systemic gap, or a control that failed Root cause analysis, remediation plan, evidence of closure
Repeat finding The same gap raised in a previous audit Treated far more seriously. Suggests the framework is not being managed

The repeat finding is the one to avoid at almost any cost. A first finding says a gap existed. A repeat says the organisation was told and did not act, which changes how everything else in the report is read.

Three things make remediation credible: a named owner rather than a team, a date rather than “ongoing”, and evidence of closure rather than an assertion that it was done.

Those are the same three things that make a risk register credible, which is not a coincidence.

Final Thoughts

Audit-ready risk management is not about producing more documentation. Organisations that struggle usually have plenty of documentation.

It is about whether the compliance documentation connects, carries dates, and can be retrieved when a regulator asks.

The seven components of audit-ready risk management above are what gets asked for.

Control effectiveness, compliance policies and training records are where most regulator findings land, and all three are records problems rather than practice problems.

The work is usually happening. The proof is not being kept.

Sentrient’s risk management system holds the risk register, controls, monitoring, incident records, policy acknowledgements and training completions together, so the evidence assembles itself rather than being reconstructed.

Book a free demonstration and we will run the evidence test against your current setup.

Frequently Asked Questions

1. What does audit-ready mean in risk management?

It means you can produce evidence that your risk framework was operating, not just that it exists. Documents show intent. Evidence shows the control was in place on the date it mattered, with a name and a timestamp against it. Most organisations have the documents and struggle with the evidence.

2. What documents do regulators review during an audit?

Governance records such as board minutes and escalation logs, the risk register with owners and review dates, control mapping with test results, current policies with acknowledgement records, training completions tied to individuals, incident reports with closed actions, and third-party risk assessments. They also review the audit trail showing who changed what and when.

3. How often should risk assessments be updated?

At least quarterly for high and extreme risks and annually for the full register, and whenever a triggering event occurs. Regulation 38 of the model WHS Regulations sets those triggers, including a workplace change likely to create a new risk, a newly identified hazard, a control that is not working, and a request from a health and safety representative.

4. What is the difference between an internal audit and a regulatory audit?

An internal audit is commissioned by the organisation to test its own controls, and the findings are yours to act on. A regulatory audit is conducted by an external body against a legal or licensing obligation, and the findings can carry enforcement consequences. Preparing well for internal reviews is the cheapest way to be ready for the external ones.

5. How do you prove control effectiveness?

By testing the control and recording the result, rather than describing the control. That means dated verification records, sampling, spot checks or system reports showing the control operated. A control listed in a register with no test evidence is an assumption, and it is the most common gap auditors find.

6. What is a risk register?

The central record of identified risks, their ratings before and after controls, the controls in place, the named owner and the review date. For audit purposes the register also needs a change history, because a register with no version trail cannot demonstrate it was maintained rather than assembled shortly before the audit.

7. How do you prepare for a surprise audit?

You cannot prepare for a surprise audit in the week it happens, which is the point of it. What works is keeping the register current on event triggers, testing a few controls each quarter, and making sure training and policy records are retrievable. Run the evidence test above on three workers periodically and you will know where you stand.

8. What is the most common audit finding in risk management?

Ownership recorded as a department or a committee rather than a named person, followed closely by controls listed without any test evidence. Both are visible from the documents alone, without the auditor needing to interview anyone, which makes them entirely avoidable.

Sources

  • Work Health and Safety Regulations 2011, regulation 38, Review of control measures
  • Work Health and Safety Regulations 2011, regulation 36, Hierarchy of control measures
  • Safe Work Australia, Identify, assess and control hazards
  • Safe Work Australia, Key Work Health and Safety Statistics Australia 2025, October 2025
  • Fair Work Ombudsman, Annual Report 2024-25, October 2025
  • OAIC, Notifiable Data Breaches statistics, January to June 2025
  • ISO 31000 Risk Management, International Organization for Standardization
  • Work Health and Safety Act 2011 (Cth)

Read More About Risk Management

Disclaimer: This guide is general information current at the date of publication and is not legal advice. Audit and regulatory obligations differ between jurisdictions, industries and regulators, and change over time. Confirm what applies to you with the relevant regulator or a qualified adviser.