KindPath Collective Inc

Risk Management Policy

Version 1.0 | Effective: 29 August 2026 | Review: 29 August 2027 | Owner: Director

1. Purpose

To identify, assess and manage risks to participants, workers, and the organisation before they become incidents.

2. Legislative and standards basis

  • NDIS Practice Standards, Module 2: Governance and Operational Management — Risk management.
  • Work Health and Safety Act 2011 (NSW).

3. Policy statement

Risk management at KindPath covers four linked areas: participant safety risk, worker safety risk (including psychosocial risk), organisational/financial risk, and service continuity risk. Risk is assessed honestly, including risks created by KindPath’s current small size and pre-registration status — pretending a risk doesn’t exist because addressing it is inconvenient is itself a governance failure.

4. Procedure

  1. Identify. Risks are identified from four sources: routine review, incidents/near-misses (Incident Management Policy), complaints (Feedback and Complaints Management Policy), and direct staff/participant input.
  2. Assess. Each risk is rated for likelihood (rare/unlikely/possible/likely/almost certain) and consequence (negligible/minor/moderate/major/catastrophic), producing a risk rating used to prioritise action.
  3. Treat. For each material risk, the Risk Register (Module 6) records the treatment: eliminate, reduce, transfer (e.g. insurance), or accept (with sign-off and reasoning — “accept” is not a default for anything rated moderate or above).
  4. Monitor. The Risk Register is reviewed at minimum quarterly while KindPath is at its current scale, and immediately after any serious incident.

5. Current standing risks (illustrative — full detail in the Risk Register)

  • Insurance gap: public liability and professional indemnity not yet confirmed in place while direct support is being delivered. Rated high consequence; treatment: confirm cover before further support delivery, or explicitly document acceptance of the gap with reasoning and a closing date.
  • Worker screening gap: NDIS Worker Screening Checks / WWCC not yet systematised for everyone delivering support, including family-member workers. Rated high; treatment: implement per the Human Resource Management Policy.
  • Family-member worker boundary risk: where a worker is also a family member of the Director, professional boundaries can blur in ways a stranger-worker relationship would not. Rated moderate-to-high depending on the specific support; treatment: explicit role-scoping documents, supervision, and the boundary-setting procedures in the Sexual Harassment and Bullying Prevention Policy and Independence and Informed Choice Policy.
  • Single point of failure: KindPath’s current support delivery relies heavily on very few people (including the Director personally). Rated moderate; treatment: Continuity of Supports Policy.

6. Roles and responsibilities

  • Director: owns the Risk Register, ensures quarterly review happens, escalates and treats high/extreme risks without delay.
  • Workers: raise emerging risks as they see them, not just after something goes wrong.

7. Related documents

Risk Register (Module 6) · WHS Policy and Procedures · Continuity of Supports Policy · Incident Management Policy

8. Review

Quarterly for the register; annually for this policy.