Risk is the effect of uncertainty on objectives, recognising both downside threats and upside opportunities across financial and non-financial considerations. Three distinctions govern how we apply it.
Inherent and residual risk are not the same.
Inherent risk exists before controls; residual risk is what remains after they operate. Boards are often shown one and told it is the other. We report both, and we say which controls close the gap.
Risk is managed to an appetite, not driven to zero.
A business that takes no risk creates no value. The discipline is to define how much risk the organisation will accept in pursuit of its objectives, then hold the line. This is why our promise is Managed Risk, not Minimised Risk.
Risk without measurement is opinion.
A risk that has not been rated, assigned an owner and given a review date is not being managed. It is being noted.
The L&A position:Â risk is not the thing that stops a strategy. Understood properly, it is the thing that shapes it.
THE L&A RISK UNIVERSE
Six Domains, Thirty Risk Types
The domains are deliberately comprehensive: the failures that damage organisations most are usually the ones that fell between two functions, each assuming the other was watching.
01 Financial & Reporting Risk
Liquidity and working capital; capital structure and covenants; material misstatement; impairment, provisioning and valuation; interest rate, currency and counterparty exposure.
How L&A addresses it:Â audit and assurance; financial statement preparation and review; cash flow forecasting; financial modelling; independent valuation.
02 Tax & Regulatory Risk
Entity structuring and CGT; GST, FBT, payroll tax and withholding; transfer pricing and cross-border; ATO review and dispute; licence and lodgement obligations.
How L&A addresses it:Â tax advisory and structuring; restructuring and rollover planning; ATO engagement and dispute support; cross-border compliance.
03 Commercial & Strategic Risk
Market and demand shift; customer, supplier and revenue concentration; pricing, margin and contract terms; growth, M&A and integration failure; reputation and stakeholder confidence.
How L&A addresses it:Â strategy and business advisory; Virtual CEO & CFO services; corporate finance; due diligence; commercial risk assessment.
04 Operational, Project & Delivery Risk
Scope, schedule and cost overrun; procurement and contractor performance; supply chain and business continuity; benefits realisation; key-person dependency and succession.
How L&A addresses it:Â infrastructure, property and program advisory; PMO establishment; capital works governance; delivery assurance; succession planning.
05 Governance, Compliance & Conduct Risk
Corporations Act and director duties; fraud, corruption and financial crime; delegations, conflicts and related parties; employment, WHS and modern slavery; board and committee effectiveness.
How L&A addresses it:Â internal audit; governance framework design; probity and procurement advisory; forensic accounting and investigations; Audit and Risk Committee support.
06 Technology, Data & Sustainability Risk
Cyber and information security; IT general controls and access management; data integrity, privacy and AI governance; system implementation and change control; climate, environmental and ESG compliance.
How L&A addresses it:Â IT general controls reviews; ERP and transformation controls assurance; data analytics; ICT governance maturity assessment; environmental provisioning review.
HOW WE MANAGE RISK
The L&A Lifecycle
01 Establish Context & Appetite
We begin with objectives, not risks. What is the organisation trying to achieve, in what environment, and how much risk is it genuinely prepared to accept? Without a stated appetite, every subsequent rating is arbitrary.
02 Identify
Structured identification across all six domains — facilitated workshops, document and contract review, control walkthroughs, and data analytics across full transaction populations where data quality and system access permit. We test what is missing from the register as rigorously as what is on it.
03 Analyse & Evaluate
Each risk rated for likelihood and consequence on a consistent scale, expressed as both inherent and residual exposure, and evaluated against the stated appetite. Consequence is assessed across financial, operational, compliance and reputational dimensions — not financial alone.
04 Treat & Mitigate
Four responses, applied deliberately: Terminate (exit the activity where exposure cannot be brought within appetite), Treat (design, implement and test controls), Transfer (insure, contract or share with a party better placed to carry it), Tolerate (accept the residual exposure consciously, documented, with an owner).
05 Monitor, Report & Assure
Ownership assigned, review cadence set, and reporting delivered to the board, audit and risk committee or executive at a level they can act on. Independent assurance confirms controls are operating as designed — not merely that they exist on paper.
The Three Lines
First line — management and operational teams
Own and manage risk day to day. L&A supports through framework design, control implementation, and capability uplift.
Second line — risk, compliance and finance functions
Oversee, challenge and monitor. L&A supports through framework development, risk register facilitation, and Audit and Risk Committee reporting.
Third line — internal audit
Provides independent assurance. L&A operates here through co-sourced and outsourced internal audit, controls testing, and assurance mapping.
Independence matters here. Where L&A provides external audit, we do not also design or operate first-line controls for the same entity. Where we act in a co-sourced internal audit or Chief Audit Executive capacity, that role is documented and separated. Independence requirements under APES 110 are applied at engagement acceptance.
Risk by Engagement Type
Preparing for audit or facing regulator scrutiny
DOMAINS 01 & 05
Audit and assurance; controls review; remediation roadmap.
Restructuring or planning succession
DOMAINS 02, 03 & 04
Tax structuring; succession planning; valuation.
Acquiring, divesting or raising capital
DOMAINS 01, 02 & 03
Due diligence; valuation; transaction structuring.
Delivering a capital works or development program
DOMAINS 04 & 05
PMO establishment; capital works governance; delivery assurance.
Implementing a new ERP or finance system
DOMAINS 06 & 01
Controls mapping; go-live readiness; post-implementation assurance.
Facing suspected fraud or a dispute
DOMAINS 05 & 01
Forensic investigation; asset tracing; expert evidence.
Managing an SMSF or family wealth structure
DOMAINS 02 & 05
SMSF audit and compliance; asset protection; estate planning.
Sitting on a board or audit and risk committee
ALL SIX DOMAINS
Enterprise risk framework; risk appetite statement; ARC reporting.