Our Approach · The L&A Risk Framework

Risk, Defined. Assessed. Managed. Measured.

Every organisation carries risk. The question is not whether it exists, but whether it has been named, understood, priced and governed — or whether it is simply being carried in the dark.

WHAT WE MEAN BY RISK

Risk is the effect of uncertainty on objectives, recognising both downside threats and upside opportunities across financial and non-financial considerations. Three distinctions govern how we apply it.

Inherent and residual risk are not the same.

Inherent risk exists before controls; residual risk is what remains after they operate. Boards are often shown one and told it is the other. We report both, and we say which controls close the gap.

Risk is managed to an appetite, not driven to zero.

A business that takes no risk creates no value. The discipline is to define how much risk the organisation will accept in pursuit of its objectives, then hold the line. This is why our promise is Managed Risk, not Minimised Risk.

Risk without measurement is opinion.

A risk that has not been rated, assigned an owner and given a review date is not being managed. It is being noted.

The L&A position: risk is not the thing that stops a strategy. Understood properly, it is the thing that shapes it.

THE L&A RISK UNIVERSE

Six Domains, Thirty Risk Types

The domains are deliberately comprehensive: the failures that damage organisations most are usually the ones that fell between two functions, each assuming the other was watching.

01 Financial & Reporting Risk

Liquidity and working capital; capital structure and covenants; material misstatement; impairment, provisioning and valuation; interest rate, currency and counterparty exposure.


How L&A addresses it: audit and assurance; financial statement preparation and review; cash flow forecasting; financial modelling; independent valuation.

02 Tax & Regulatory Risk

Entity structuring and CGT; GST, FBT, payroll tax and withholding; transfer pricing and cross-border; ATO review and dispute; licence and lodgement obligations.


How L&A addresses it: tax advisory and structuring; restructuring and rollover planning; ATO engagement and dispute support; cross-border compliance.

03 Commercial & Strategic Risk

Market and demand shift; customer, supplier and revenue concentration; pricing, margin and contract terms; growth, M&A and integration failure; reputation and stakeholder confidence.


How L&A addresses it: strategy and business advisory; Virtual CEO & CFO services; corporate finance; due diligence; commercial risk assessment.

04 Operational, Project & Delivery Risk

Scope, schedule and cost overrun; procurement and contractor performance; supply chain and business continuity; benefits realisation; key-person dependency and succession.


How L&A addresses it: infrastructure, property and program advisory; PMO establishment; capital works governance; delivery assurance; succession planning.

05 Governance, Compliance & Conduct Risk

Corporations Act and director duties; fraud, corruption and financial crime; delegations, conflicts and related parties; employment, WHS and modern slavery; board and committee effectiveness.


How L&A addresses it: internal audit; governance framework design; probity and procurement advisory; forensic accounting and investigations; Audit and Risk Committee support.

06 Technology, Data & Sustainability Risk

Cyber and information security; IT general controls and access management; data integrity, privacy and AI governance; system implementation and change control; climate, environmental and ESG compliance.


How L&A addresses it: IT general controls reviews; ERP and transformation controls assurance; data analytics; ICT governance maturity assessment; environmental provisioning review.

HOW WE MANAGE RISK

The L&A Lifecycle

01 Establish Context & Appetite

We begin with objectives, not risks. What is the organisation trying to achieve, in what environment, and how much risk is it genuinely prepared to accept? Without a stated appetite, every subsequent rating is arbitrary.

02 Identify

Structured identification across all six domains — facilitated workshops, document and contract review, control walkthroughs, and data analytics across full transaction populations where data quality and system access permit. We test what is missing from the register as rigorously as what is on it.

03 Analyse & Evaluate

Each risk rated for likelihood and consequence on a consistent scale, expressed as both inherent and residual exposure, and evaluated against the stated appetite. Consequence is assessed across financial, operational, compliance and reputational dimensions — not financial alone.

04 Treat & Mitigate

Four responses, applied deliberately: Terminate (exit the activity where exposure cannot be brought within appetite), Treat (design, implement and test controls), Transfer (insure, contract or share with a party better placed to carry it), Tolerate (accept the residual exposure consciously, documented, with an owner).

05 Monitor, Report & Assure

Ownership assigned, review cadence set, and reporting delivered to the board, audit and risk committee or executive at a level they can act on. Independent assurance confirms controls are operating as designed — not merely that they exist on paper.

GOVERNANCE

The Three Lines

First line — management and operational teams

Own and manage risk day to day. L&A supports through framework design, control implementation, and capability uplift.

Second line — risk, compliance and finance functions

Oversee, challenge and monitor. L&A supports through framework development, risk register facilitation, and Audit and Risk Committee reporting.

Third line — internal audit

Provides independent assurance. L&A operates here through co-sourced and outsourced internal audit, controls testing, and assurance mapping.

Independence matters here. Where L&A provides external audit, we do not also design or operate first-line controls for the same entity. Where we act in a co-sourced internal audit or Chief Audit Executive capacity, that role is documented and separated. Independence requirements under APES 110 are applied at engagement acceptance.

WHERE TO START

Risk by Engagement Type

Preparing for audit or facing regulator scrutiny

DOMAINS 01 & 05

Audit and assurance; controls review; remediation roadmap.

Restructuring or planning succession

DOMAINS 02, 03 & 04

Tax structuring; succession planning; valuation.

Acquiring, divesting or raising capital

DOMAINS 01, 02 & 03

Due diligence; valuation; transaction structuring.

Delivering a capital works or development program

DOMAINS 04 & 05

PMO establishment; capital works governance; delivery assurance.

Implementing a new ERP or finance system

DOMAINS 06 & 01

Controls mapping; go-live readiness; post-implementation assurance.

Facing suspected fraud or a dispute

DOMAINS 05 & 01

Forensic investigation; asset tracing; expert evidence.

Managing an SMSF or family wealth structure

DOMAINS 02 & 05

SMSF audit and compliance; asset protection; estate planning.

Sitting on a board or audit and risk committee

ALL SIX DOMAINS

Enterprise risk framework; risk appetite statement; ARC reporting.

Where Does Your Risk Actually Sit?

Most organisations can name three or four of their risks with confidence. The exposure is usually in the ones nobody has been asked to own. A structured assessment across all six domains is where we start.