Feature Article Topic: Start With the Risk, Not the Dashboard 

There is a temptation when implementing a new compliance platform to begin with its functionality. 

  • What can it automate? 
  • What reports can it produce? 
  • What workflows can we build? 
  • What spreadsheets can we get rid of? 

Those are reasonable questions. 

They just shouldn’t be the first ones. 

The starting point should be much more fundamental: What compliance risks are we trying to control? 

Technology is most useful when it strengthens an already considered approach to risk, governance and assurance. 

Without that foundation, there is a danger that an RTO simply takes its existing compliance activity and digitises it. 

  • The old spreadsheet becomes a dashboard. 
  • The manual reminder becomes an automated email. 
  • The action register becomes a workflow. 

But the underlying question remains unanswered: Was the original process effective? 

Don’t automate a process simply because it exists 

Compliance environments accumulate processes over time. 

Some exist because they are genuinely important controls. 

Others exist because somebody created a spreadsheet five years ago and everyone has continued updating it ever since. 

Before transferring those activities into a new system, the Compliance Manager has an opportunity to challenge them. 

Ask: 

  • What risk does this activity control? 
  • What obligation does it support? 
  • What evidence does it provide? 
  • Who uses the information? 
  • What decision does it enable? 
  • What happens if we stop doing it? 

If those questions cannot be answered, the organisation may be automating activity rather than strengthening assurance. 

Map risks to controls before building workflows 

A useful compliance platform should help the organisation understand the relationship between: 

obligation → risk → control → evidence → assurance. 

Take assessment validation as an example. 

The purpose of monitoring validation is not simply to prove that a validation event occurred by a due date. 

The underlying concern is whether assessment practices continue to produce valid and defensible competency decisions. 

A dashboard therefore needs to do more than display whether validation is complete. 

A mature system might also help identify: 

  • recurring validation findings; 
  • training products with repeated assessment weaknesses; 
  • overdue rectification; 
  • whether corrective actions were implemented; 
  • whether similar issues exist elsewhere; and 
  • whether previous rectification has prevented recurrence. 

That moves the organisation from recording compliance activity to using information for assurance. 

The Compliance Manager’s role 

This is where the Compliance Manager adds significant value. 

Technology vendors understand their platforms. 

Compliance Managers must understand the organisation. 

They know where processes break down, where evidence is unreliable, where ownership is unclear and where apparently minor issues may indicate something more systemic. 

That knowledge should shape how the technology is configured. 

The question is not: How do we make our current compliance processes fit this platform? 

It is: 

How can this platform help us strengthen the way we identify, control and understand risk? 

That is a very different implementation conversation. 

Technology should support the compliance framework. 

The compliance framework should never be designed around the technology. 

Other feature articles: 

From Compliance Activity to Risk Control 

Closing The Assurance Loop – What Happens After You Find A Problem? 

Evidence Is Not Assurance and Why Having the Documents Is No Longer Enough 

Can You Trust Your Own Compliance Data? 

References:  

VET Quality Framework   

National Vocational Education and Training Regulator (Outcome Standards for Registered Training Organisations) Instrument 2025   

AQSQ Practice Guide Assessment 

Leadership and Accountability Practice Guide 

Risk Management Practice Guide 

Continuous Improvement Practice Guide