Risk Management

A complete guide to understanding and implementing
Risk Management within the PSET sector.

Risk Management is a core governance function for SETAs, TVET Colleges, Universities, and public institutions. This pillar provides a structured, practical, and PFMA‑aligned overview of risk identification, assessment, mitigation, monitoring, and reporting across the skills development environment.

What this pillar covers

Risk Management includes the full lifecycle of identifying, assessing, mitigating, and monitoring risks that impact institutional performance, compliance, and service delivery.

This pillar covers:

  • Risk management frameworks

  • PFMA‑aligned internal controls

  • Risk identification and categorisation

  • Risk assessment and scoring

  • Mitigation strategies and action plans

  • Combined assurance

  • Monitoring and reporting

  • Fraud prevention and ethics

  • Auditor‑General expectations

  • Linking risk to DG, PFMA, M&E, and APP processes

 

Why Risk Management matters

Risk Management ensures that institutions proactively identify threats, implement controls, and maintain compliance with PFMA, Treasury Regulations, and AG audit expectations.

Compliance

Risk Management supports PFMA internal control requirements and AG audit readiness.

Governance

Effective risk processes strengthen oversight, accountability, and ethical conduct.

Performance

Risk mitigation improves programme delivery, DG administration, QCTO processes, and institutional stability.

Professional Competence

Membership with recognised Professional bodies such as IRMSA or IIA strengthens institutional risk capability, supports AG audit readiness, and ensures practitioners follow industry‑aligned ethical standards.

Key Components

  • Enterprise Risk Management Framework (ERMF) — The overarching framework that defines how risks are identified, assessed, mitigated, monitored, and reported across the institution.
  • Risk Management Framework — The structure, principles, and processes guiding risk management.

  • Risk Identification — Identifying strategic, operational, financial, compliance, and project risks.

  • Risk Assessment — Scoring risks based on likelihood, impact, and control effectiveness.

  • Mitigation Strategies — Developing action plans to reduce risk exposure.

  • Internal Controls — PFMA‑aligned controls that prevent errors, fraud, and irregularities.

  • Combined Assurance — Coordinating assurance between Risk, Internal Audit, Compliance, and EXCO.

  • Monitoring & Reporting — Tracking risk trends, control effectiveness, and mitigation progress.

  • Fraud Prevention — Identifying fraud risks and implementing preventative controls.

  • Audit Readiness — Ensuring risk processes support AG audit requirements.

chatgpt image aug 11, 2026, 11 36 05 pm

Risk Management Guides and Articles

Risk Identification & Assessment Guide

This guide explains how risks are identified, classified, and assessed within PFMA‑aligned environments.

Risk Mitigation & Control Guide

Explains how institutions design and implement mitigation strategies that reduce risk exposure and strengthen internal controls.

ERMF Guide

Provides a clear, sector‑aligned explanation of the Enterprise Risk Management Framework — what it is, why it exists, how it is structured, and how it functions within a public institution or SETA.

Frequently Asked Questions (FAQ)

  1. Does professional body membership matter for Risk Management and AG audit readiness? Yes. Membership with bodies such as IRMSA (risk practitioners) or IIA (internal auditors) ensures practitioners follow recognised standards, maintain competence, and apply best‑practice methodologies aligned to AG expectations.
  2. What is the purpose of Risk Management? To identify, assess, and mitigate risks that impact institutional performance and compliance.
  3. Who is responsible for Risk Management? Management, Risk Practitioners, Internal Audit, Compliance, and EXCO.
  4. What documents are required for Risk Management? Risk registers, mitigation plans, internal control frameworks, combined assurance plans, and monitoring reports.
  5. How does Risk Management link to PFMA? PFMA requires internal controls and risk processes to prevent irregular expenditure and ensure accountability.
  6. What are the reporting requirements? Quarterly risk reports, combined assurance updates, mitigation progress reports, and AG audit submissions.

Related Pillars

  • PFMA Compliance

  • DG Administration

  • Monitoring & Evaluation

  • QCTO Accreditation

  • Skills Planning

  • APP Alignment

Need Support?

Connect with us if you need additional information, guidance or support with strengthening risk management capabilities including risk registers, designing internal controls,  implementing PFMA‑aligned risk management frameworks, and alignment with IRMSA standards and AG requirements.