While my Department maintains a risk register, the Department is not in position to provide the Deputy with the requested information as described within the scope of the Deputy's question. The eRisk system used by my Department does not maintain a historical record in the manner requested. Instead, when the Risk Register report is generated for specific requirements, it reflects the information recorded in the system in its current form at that point in time.
Risk Registers are central to modern effective management in organisations and are integral to the day-to-day management and good governance of the Department. Achieving this requires the creation of an environment where officers can identify risks secure in the knowledge that this is a positive contribution to improving the Department’s functions rather than potentially exposing weaknesses or endangering critical systems or infrastructure.
The release of the Department’s Risk Register could reasonably be expected to result in underreporting of risk and undermine the effectiveness of registers and thus the management function of the Department. The release of these records may impact on the prevention, detection and investigation of offences or the effectiveness of lawful methods, systems, plans or procedures.