Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibraryRisk Management Policy
Contents & downloads
Purpose
This policy establishes Westlink Logistics’ commitment to managing risk in a systematic, structured, and proactive way. It provides the framework for identifying, assessing, treating, and monitoring risk across the organisation, aligned to ISO 31000, and integrates risk management with the quality, work health and safety, environmental, and information-security elements of the Westlink Management System (WMS).
Scope
This policy applies to all Westlink Logistics operations, personnel, contractors, and suppliers, and to all categories of risk — strategic, operational, commercial, work health and safety, environmental, security, and compliance. It covers risks and opportunities arising across heavy haulage, project logistics, and maritime services, and across the activities Westlink performs for customers, including government and defence clients.
Organisational Context
Westlink Logistics operates specialised heavy haulage, project logistics, and maritime services across Australia, primarily supporting defence, government, resources, and infrastructure sectors. This exposes the organisation to a broad and interacting risk profile — project execution and commercial risk, Chain of Responsibility and road-transport safety risk, work health and safety and environmental risk in the field, and security risk arising from Defence Industry Security Program (DISP) membership and the handling of official information.
Effective risk management is integral to contract eligibility, DISP and JOSCAR obligations, and the safety of workers, the public, and the environment. Risk is managed in an integrated way across the WMS rather than in isolation, so that risks affecting quality, safety, environment, and security are identified and treated through one consistent framework.
Policy Statement
Westlink Logistics is committed to:
-
Applying a structured risk management process aligned to ISO 31000 — establishing the context and identifying, analysing, evaluating, treating, monitoring, and communicating risk — in planning, decision-making, and day-to-day operations.
-
Integrating risk management across the WMS so that quality (ISO 9001), work health and safety (ISO 45001), environmental (ISO 14001), and security risks are managed under one consistent framework.
-
Establishing risk criteria and a risk appetite approved by executive management, and escalating risks that exceed tolerance for executive decision and treatment.
-
Maintaining corporate, operational, and project risk registers as the record of identified risks, their treatments, and their owners, and reviewing them through the management review process.
-
Assigning clear ownership and accountability for each risk and its treatment to a named role.
-
Managing security risk in accordance with Westlink’s DISP obligations and the Information Security Manual (ISM), protecting official and customer information.
-
Pursuing opportunities through the same risk-based approach, so that risk management supports — not only constrains — the achievement of objectives.
-
Continually improving the risk management framework using audit results, incident and near-miss data, and lessons learned.
Risk Management Approach
Westlink applies the ISO 31000 risk management process: establishing the context; risk identification; risk analysis (assessing likelihood and consequence); risk evaluation against the risk criteria; risk treatment (avoid, reduce, transfer, or accept); and ongoing monitoring, review, and communication. Risk is rated on a consistent likelihood-and-consequence basis so that risks across different parts of the business can be compared and prioritised, and risks assessed above the tolerances set by executive management are escalated for executive decision.
Operational and project risks are captured and tracked in the risk registers maintained under the Operations Risk Register Guideline (OPS-GDL-001). Work health and safety hazards and incidents are managed under the Hazard and Incident Reporting and Investigation Procedure (QHSE-PRO-001), and security risk is managed under Westlink’s DISP and information-security arrangements.
Responsibilities
| Role | Responsibility | Reference |
|---|---|---|
| Chief Executive Officer | Accountable for risk management across the organisation; approves the risk criteria and risk appetite and ensures resources for the framework. | ISO 31000 cl.5.2 |
| QHSE Manager | Maintains the risk management framework and registers; coordinates risk reviews and reporting into the management review. | ISO 31000 cl.5.3; ISO 9001 cl.6.1 |
| Managers and supervisors | Identify, assess, and treat risks within their area; assign and track risk treatments; escalate risks that exceed tolerance. | ISO 31000 cl.6 |
| Chief Security Officer (CSO) | Authority for DISP-related matters; accountable for security risk management and the organisation’s DISP and ISM obligations. | DISP / ISM |
| Security Officers (SO) | Implement and monitor security controls and manage day-to-day security risk, protecting official and customer information, under the direction of the CSO. | DISP / ISM |
| All employees and contractors | Identify and report risks, hazards, near misses, and opportunities, and apply risk controls in their work. | ISO 45001 cl.6.1 |
Review
This policy is reviewed annually as part of the management review cycle. It is reviewed earlier where significant changes occur to the organisation’s context, risk profile, or applicable requirements. The policy is communicated to all personnel and is available to interested parties on request.
Applicable Standards and Legislation
-
ISO 31000:2018 Risk Management — Guidelines
-
ISO 9001:2015 Quality Management Systems — Requirements
-
ISO 45001:2018 Occupational Health and Safety Management Systems — Requirements
-
ISO 14001:2026 Environmental Management Systems — Requirements
-
Defence Security Principles Framework (DSPF) / Defence Industry Security Program (DISP) — security risk management
-
Information Security Manual (ISM) — security risk
-
Work Health and Safety Act 2020 (WA) — duty to manage risks so far as is reasonably practicable
Related Documents
-
GOV-POL-001 Quality Policy
-
GOV-POL-002 Work Health and Safety Policy
-
GOV-POL-004 Environmental Management Policy
-
TEC-POL-001 Information Security Policy
-
OPS-GDL-001 Operations Risk Register Guideline
-
QHSE-PRO-001 Hazard and Incident Reporting and Investigation Procedure
-
QHSE-MAN-001 Westlink Management System Manual
Compliance coverage — cited by 7 requirements across 3 frameworks
ISO 14001:2026(2)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO14001-2026-6.1.1-01 | 6.1.1 | Full | Risk Management Policy — integrates environmental risk into the enterprise ISO 31000 framework. | |
| ISO14001-2026-6.1.2-01 | 6.1.2 | Full | Risk Management Policy — environmental aspects/risk managed within the integrated WMS risk framework. |
ISO 45001:2018(2)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO45001-2018-6.1.1-01 | 6.1.1 | Full | Risk Management Policy — integrates WHS risk into the enterprise ISO 31000 framework (operationalised via QHSE-PRO-001). | |
| ISO45001-2018-6.1.2.1-01 | 6.1.2.1 | Full | Risk Management Policy — frames hazard/WHS risk identification within the enterprise risk framework. |
ISO 9001:2015(3)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO9001-2015-6.1.1-01 | 6.1.1 | Partial | High | Risk Management Policy — ISO 31000-aligned enterprise framework for determining and addressing risks and opportunities across the WMS. |
| ISO9001-2015-6.1.2-01 | 6.1.2 | Partial | High | Risk Management Policy — establishes the ISO 31000 process (identify, analyse, evaluate, treat) and integration of risk actions across the WMS. |
| ISO9001-2015-6.1.2-02 | 6.1.2 | Partial | High | Risk Management Policy — risk rated on a consistent likelihood/consequence basis with treatment evaluated against the risk criteria (proportionality). |
Declared compliance references (7)
ISO14001-2026-6.1.1-01ISO14001-2026-6.1.2-01ISO45001-2018-6.1.1-01ISO45001-2018-6.1.2.1-01ISO9001-2015-6.1.1-01ISO9001-2015-6.1.2-01ISO9001-2015-6.1.2-02
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 1 | 30/06/2026 | GOV-POL-021 | Risk Management Policy | FTM (CF) | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 1 | Initial release — establishes Westlink's enterprise risk management policy aligned to ISO 31000.• Integrates risk management across the WMS (quality, WHS, environmental, and security risk) under a single, consistent framework.• Defines the ISO 31000 risk process, risk criteria and appetite, escalation, risk registers, and risk ownership.• Backs the risk-based commitment in the Quality Policy (GOV-POL-001) and provides the framework for the operational risk register (OPS-GDL-001). |