All templates

Practice Risk Management Policy and Risk Register Template for Australian General Practices

The governance risk system RACGP 6th edition criterion F1.G names: documented processes for identifying, assessing and responding to strategic, operational and service-related risks, a five-by-five rating matrix with practice-sized consequence scales, escalation thresholds and a risk appetite statement, and the reporting cycle to practice leadership. Ships with a fillable risk register carrying three worked entries, the rating matrix as a quick reference, and a one-page leadership risk report. States the three-way boundary against the clinical risk register (CG7) and the WHS hazard register, and answers the 5th edition indicators C3.1C and C3.2D the criterion expands from, so it is assessable now.

RACGP 6th EditionCriterion F1.G19 pagesWord formatIncluded in every plan

Built from: RACGP Standards for general practices (6th edition) · RACGP Standards for general practices (5th edition) · AS ISO 31000:2018

30% off first month

All 79 templates included with ClinicComply

Subscribe to download the Practice Risk Management Policy and Risk Register and every other RACGP, NDIS, Privacy Act and WHS template, kept up to date for you.

Solo plan from
$79/month$99
Billed annually, AUD, GST inclusive
Use code SEP30 for 30% off your first month
  • All 79 templates
  • 30-day free trial
  • No credit card

What's in this template?

This template is a governance risk policy for an Australian general practice, bundled with the three things that make it usable: the risk register itself, the five-by-five rating matrix, and a one-page report format for practice leadership. It is written against criterion F1.G of the RACGP Standards for general practices (6th edition), published 26 August 2026. The RACGP's official mapping document classifies F1.G as "Expanded" from 5th edition indicators C3.1C and C3.2D, so this document is assessable now, under the edition practices are accredited against today.

The document is a Word file with fifteen numbered sections and three appendices, set in Calibri, with placeholders highlighted and grey italic guidance notes to delete before publishing. A cover block, a "How to use this policy" box and a version table precede section 1.

  1. Purpose: the criterion, the 5th edition indicators it expands, and why the business risk system matters.
  2. Scope: the three risk categories (strategic, operational, service-related) with examples, and what is out of scope because another document owns it.
  3. How this relates to the clinical and WHS risk documents: the three-way boundary table, the "who bears the harm" test, and how the Policy and Document Control Procedure and Business Continuity Plan sit alongside.
  4. Roles and accountability: the risk management lead, practice leadership, the practice manager, risk owners, team members and independent doctors.
  5. The risk management process: a seven-step table (identify, assess, respond, implement, monitor, review, report), the nine sources risks come from, and how to describe a risk as event, cause and effect.
  6. Risk categories and worked examples: 18 worked examples across three tables, including the RACGP's own two.
  7. Assessing risk: a five-point likelihood scale, a five-point consequence scale with financial, service and standing columns, and four rating bands.
  8. Risk appetite and escalation thresholds: a placeholder-driven escalation rating and timeframe, and an appetite statement the practice rewrites.
  9. Responding to risk: the four responses (avoid, reduce, transfer, accept), and how actions get an owner, a due date and a status.
  10. Maintaining the risk register: where it lives, the review interval, nine out-of-cycle review triggers, and how the register feeds the strategic and operational plans.
  11. Reporting to practice leadership: cadence, the standing agenda item, the one-page report format, and the minutes as the evidence.
  12. Training, awareness and raising a risk: induction briefing, annual refresher, how any team member raises a risk, and the lead's own education recorded in the training register.
  13. Roles and responsibilities: a table.
  14. Related documents: the documents this policy points to.
  15. Approval and review: annual review (inside the two-year F1.D maximum), review triggers, and a signature block.

Appendix A is the risk register. A landscape table with columns for ID, date raised, category, risk, existing controls, likelihood, consequence, rating, response and additional actions, owner, due, review date and status. Three worked entries ship filled in (a principal retiring at short notice; loss of internet on a single connection; the after-hours deputising contract ending without renewal), followed by blank rows.

Appendix B is the rating matrix. The five-by-five likelihood and consequence matrix, colour-banded, with the action each band requires.

Appendix C is the leadership report. A one-page report covering High and Extreme risks with rating, owner, action status and decision requested; changes since the last report; overdue actions; and leadership decisions recorded in the minutes.

Editable placeholder fields

The document ships with these placeholders to replace: Practice name{{practice_name}}, ABN{{abn}}, Practice address{{practice_address}}, Risk lead{{risk_lead}}, Practice principal name{{practice_principal_name}}, Practice manager{{practice_manager}}, Governance meeting name{{governance_meeting_name}}, Register location{{register_location}}, Register review frequency{{register_review_frequency}}, Leadership report frequency{{leadership_report_frequency}}, Escalation rating{{escalation_rating}}, Escalation timeframe{{escalation_timeframe}}, the five consequence-scale financial descriptors C1 financial{{c1_financial}} to C5 financial{{c5_financial}}, Approved by{{approved_by}}, Effective date{{effective_date}}, Next review date{{next_review_date}}, and the sign-off dates.

Three registers, three kinds of risk

Most practices already hold two risk documents: a clinical risk register and a WHS hazard register. This template holds the third one, the governance register, and section 3 of the policy draws the boundary between all three so nothing is double counted and nothing falls between them.

DocumentWhose risk, and under what dutyThe question it answers
Practice Risk Management Policy and Risk Register (this template)Risk to the practice as a business and a service: its viability, its operations, its capacity to deliver what it offers. RACGP F1.G (6th edition), C3.1C and C3.2D (5th edition)Can the practice keep operating, and keep delivering its services, if this goes wrong?
Clinical Risk Management Policy and clinical risk registerRisk to patients arising from the care the practice provides. RACGP CG7.A and CG7.B (6th edition), QI3.1 (5th edition)Could a patient be harmed by how we deliver care?
WHS Hazard and Risk RegisterRisk to workers, contractors, visitors and patients as people on the premises. Work Health and Safety Act 2011 sections 17 to 19 and the Safe Work Australia risk management Code of PracticeCould someone be hurt at or by our workplace, and have we minimised that so far as is reasonably practicable?

The test the policy teaches is who bears the harm: the business, a patient through their care, or a person's body because of the workplace. One event can appear in all three registers. The template's worked example is a cyber attack: this register records the operational risk (the practice's ability to bill, roster and communicate), the clinical register records the risk of losing access to patient records during care, and the Computer and Information Security Policy holds the controls. Each document records the part it owns and cross-references the others by ID.

Two other documents sit alongside this one. The Policy and Document Control Procedure governs this policy as a document: version control, currency review at least every two years under F1.D, and the version table on page one. The Business Continuity Plan is what a realised operational risk triggers. Its scenarios should trace back to entries in this register, so the plan is exercised against risks you have actually identified rather than generic ones.

What RACGP criterion F1.G actually requires

Criterion F1.G sits in the F1 criteria set, "Defining and planning for the practice", in the Foundations of general practice standard of the 6th edition. It reads, in full:

F1.G The practice identifies and manages governance risks. The practice:

  • maintains documented processes for identifying, assessing, and responding to strategic, operational, and service-related risks
  • implements, monitors and reports risk management and mitigation actions
  • uses a risk register (or equivalent) to document and prioritise identified risks
  • regularly reviews and reports risks, including their management and mitigation, to practice leadership.

The 6th edition has criteria and sub-criteria only; it has no "indicators". The four points above are the sub-criteria, and only they bind. Guidance written as "could" is a suggestion.

The 5th edition indicators it expands

The RACGP's official mapping classifies F1.G "Governance risk management" as Expanded from two 5th edition indicators. Criterion C3.1 indicator C reads:

"C3.1 C Our practice has a business risk management system that identifies, monitors, and mitigates risks in the practice."

You must: maintain a documented risk management process; develop procedures to mitigate risks. You could: maintain a risk register; maintain a log of risks if you are a small practice; keep a record of meetings where risks have been identified and actions agreed on to manage those risks.

Criterion C3.2 indicator D reads:

"C3.2 D Our practice has at least one team member who has the primary responsibility for leading risk management systems and processes."

You must: educate the team member responsible for risk management so that they understand their role. You could: create a position description that includes the responsibility for risk management.

The mandatory elements today are "maintain a documented risk management process" and "educate the team member responsible". This template is built around both: sections 4 and 12 name the lead and record their education, and the whole document is the documented process C3.1C asks for.

The guidance draws the clinical line itself

The F1 guidance states the boundary in one sentence: "Strategic, operational and service-related risks are different to clinical risks which are addressed in CG7: Managing clinical risks and incidents." You do not have to justify keeping the governance register separate; the standard does it for you.

The F2 guidance, on Response planning, gives the reason the business register matters at all: "Just as clinical risks need to be managed, so too do risks related to running a practice. If a practice is unable to operate due to a disruption to business-as-usual or an emergency, it will not be able to provide clinical care."

The four steps in the RACGP's own table

The F1 guidance Table 1 describes four steps for managing these risks. The guidance says these actions are suggestions only, and that the size and complexity of the practice's risk framework can be proportionate to the practice. The template's seven-step process in section 5 covers all four.

Implementing. Establish risk controls or mitigation actions. The RACGP's examples: installing a secondary internet connection after identifying a single point of failure; introducing multi-factor authentication after a cyber audit.

Monitoring. Track the status of actions and whether the controls are working. The RACGP's examples: a monthly review of appointment delays to check the results of a rostering change; tracking feedback from the practice team.

Reviewing. Reassess the risk and the control. The RACGP's examples: reviewing a data security process annually or after a near-miss; reassessing emergency plans after a local flood event.

Reporting. Make practice leaders aware of potential risks. The RACGP's examples: regularly review and update the risk register; report risks to practice leaders as often as needed.

Where accreditation actually stands

Practices are still accredited against the 5th edition. The Australian Commission on Safety and Quality in Health Care has not published transition arrangements under the National General Practice Accreditation Scheme, and its own page says arrangements will come "in due course". No date has been announced, and this page will not guess one. What matters here is that F1.G is not one of the new criteria with no ancestor: it expands C3.1C and C3.2D, so a surveyor asking for your "business risk management system" today is asking for exactly what this template holds.

How to customise this template

  1. Download the Word file and replace every highlighted placeholder. The grey italic guidance notes are there to explain each choice; delete them before publishing.
  2. Name the risk management lead and record their education. This is the C3.2D mandatory element: the lead must be educated for the role, and section 12 records it in the training register.
  3. Rewrite the consequence scale in the practice's own figures before rating anything. The financial descriptors in section 7 are placeholders (C1 financial{{c1_financial}} to C5 financial{{c5_financial}}); a week of lost billings means something different to a two-doctor practice than to a large one.
  4. Run the first register workshop with leadership, using the 18 worked examples in section 6 as prompts. Ten to twenty entries is normal for a first pass.
  5. Set the escalation threshold and the appetite statement. Section 8 is placeholder-driven: the escalation rating, the timeframe, and an appetite statement the practice rewrites in its own voice.
  6. Put risk on the agenda of the governance meeting as a standing item, and use Appendix C as the report format. The minutes are the evidence that reporting happened.
  7. Set the register review interval and the policy review date. The policy reviews annually, which sits inside the two-year F1.D maximum for document currency.

Frequently asked questions

Is a practice risk register required for RACGP accreditation right now?

Yes. Under 5th edition indicator C3.1C you must maintain a documented risk management process, and the guidance suggests a risk register (or a log of risks for a small practice) as the way to evidence it. A surveyor asking for your "business risk management system" is asking for this document. The 6th edition criterion F1.G makes the register explicit, but the obligation is already live.

What is RACGP criterion F1.G?

It is the 6th edition criterion requiring the practice to identify and manage governance risks: documented processes for strategic, operational and service-related risks, implemented and monitored mitigation actions, a risk register (or equivalent), and regular reporting to practice leadership. It expands 5th edition indicators C3.1C and C3.2D.

How is this different from our clinical risk register?

The clinical register records risks to patients arising from the care you provide, under CG7. This register records risks to the practice as a business and a service: its viability, its operations, its capacity to deliver. The F1 guidance draws the line itself: strategic, operational and service-related risks are different to clinical risks, which CG7 addresses.

Do we need a separate WHS risk register as well?

Yes. WHS risks to workers, contractors, visitors and patients as people on the premises sit under the Work Health and Safety Act 2011, not under F1.G. The boundary table in section 3 keeps the two apart. One event can appear in both registers: a flood at the premises is a hazard to the people in the building in the WHS register and a loss of access to the practice in this one, each entry cross-referencing the other by ID.

Who should be the risk management lead in a small practice?

In a small practice it is usually the practice manager. The 5th edition indicator C3.2D requires at least one team member with primary responsibility for leading risk management, and it requires that person to be educated for the role. Section 4 of the template names the lead, and section 12 records their education in the training register.

How many risks should the register have?

Ten to twenty entries is normal for a first pass. Section 6 gives 18 worked examples across the three categories to use as prompts in a workshop with leadership. The RACGP's own examples, a secondary internet connection and multi-factor authentication, are among them.

How often does the register have to be reviewed and reported?

The template leaves the intervals to the practice as placeholders, because the RACGP does not fix a number. You set the register review interval and the leadership report frequency when you customise the document, and section 10 lists nine out-of-cycle triggers, such as a near miss, a change in ownership or a cyber security event, that force a review regardless.

Can we use this if we are also an NDIS provider?

Yes. Section 3 notes how the NDIS Risk Management Policy sits alongside this document for practices that are also NDIS providers. The governance register holds the risks to the practice as a business; the NDIS framework carries its own risk obligations, and the two cross-reference rather than overlap.

30-day free trial, no credit card

Be the practice the assessor compliments.

Set up your frameworks this weekend. Walk into your next visit with your evidence linked and current, and nothing left to chase.

No credit card required
Australian data residency (Sydney)
Cancel anytime