The risk management plan a tender actually asks for
You’ve made the shortlist. Then you reach the compliance schedule, and there it is: “Provide your risk management plan” — sometimes with “aligned to ISO 31000” or “including a HSEQ risk assessment” attached. If you don’t have one, the deadline just became a problem, because in Australian tendering a risk management plan is increasingly not a nice-to-have — it’s a pass/fail gate. Government and large-corporate buyers, and prequalification schemes such as the NSW works scheme for contracts up to A$1M, ask for documented risk management as evidence you can be trusted with the job. Here’s exactly what they’re looking for, and how to produce it in an afternoon instead of a fortnight — then keep it for the next bid.
What buyers and tenders actually ask for
Tender risk requirements usually come in one of three shapes: a general “risk management plan” or “risk assessment”; an explicit “aligned to / compliant with ISO 31000”; or a project-specific “HSEQ risk assessment” for the work being tendered. Underneath, they’re asking the same question: can you identify the things that could go wrong on this job, and show you’ve thought about how to control them? A buyer isn’t grading your prose. They’re checking that risk is something you do, not something you’re improvising for their form.
ISO 31000 alignment and HSEQ evidence
ISO 31000 is the international risk-management standard, and “aligned to ISO 31000” sounds heavier than it is. It asks that you have a consistent process — identify risks, analyse them (likelihood and consequence), evaluate them against your risk appetite, treat them, and review — and that you can show it. You don’t need certification to say you align with it; certification is a separate, bigger step. For construction works above roughly A$1M, though, formal ISO certification is often effectively expected, so read the specific tender carefully. HSEQ (health, safety, environment, quality) evidence is the same idea applied to the physical work: the safety and environmental risks of this particular job, assessed and controlled.
Internal link: “ISO 31000” → A5 (ISO 31000 for small business).
The anatomy of a tender risk management plan
A plan that satisfies most tenders contains:
- Scope and context — what work, what site, what’s in and out.
- A risk register — the identified risks, each rated (inherent and residual), with controls and owners. This is the core of it.
- Your methodology — a short statement of how you identify and rate risk. This is where “aligned to ISO 31000” is earned.
- WHS and environmental risks — specific to this job, with controls.
- Roles and review — who owns risk on the project, and how often it’s reviewed.
Notice that the register is the heart of the plan. If you already keep a live register, the tender plan is mostly assembly, not creation.
Producing it fast
The slow way is to start from a blank template and a stressful week. The fast way is to start from your business and the specific opportunity. With RiskCompass, you set up the Project/Job you’re bidding, and its risk profile is drawn from your live register rather than re-keyed — then you add the risks specific to this job. You get a rated register, plus the obligations and licences that apply, which is most of the plan, produced in an afternoon. The point isn’t to cut corners; it’s to stop rebuilding from scratch every time a buyer asks.
Reusing it for the next bid
Here’s the part most businesses miss: the plan you produce under deadline is an asset, not a throwaway. If it lives in a spreadsheet you emailed to the buyer, it’s gone by the next tender. If it lives in a register you maintain, the next bid starts at eighty per cent done. The businesses that win consistently aren’t the ones who write the best risk plan once — they’re the ones for whom the plan is just this week’s export of a register they already keep. That’s the difference between risk as tender paperwork and risk as a standing capability — and it’s the same shift that lets you assess a job’s risk before you decide to bid at all.
See the risks that apply to your business
Answer a few questions about what you do — RiskCompass suggests the risks, regulations and licences that actually apply to you.
Show me what applies →This article is general information about risk management practice in Australia. It isn’t legal, financial or compliance advice — RiskCompass’s output is advisory and is a starting point for your own judgement, not a substitute for it.