Purpose of this checklist
This checklist is designed to help RTO governing persons, CEOs and compliance teams test whether governance and regulatory-risk systems are operating effectively.
The 2025 Standards place a strong emphasis on quality outcomes, leadership, accountability, risk management and systematic monitoring. ASQA's supporting guidance identifies risks such as weak governance structures, insufficient use of data and failure to evaluate operational functions.
The checklist should not be completed as a one-off declaration. Providers should use it as part of a scheduled assurance cycle and retain evidence supporting each response.
1. Governance structure and accountability
Confirm that:
- The provider has a current governance structure appropriate to its size, scope and operating complexity.
- Governing-person, CEO, senior-management and operational responsibilities are clearly defined.
- Delegations of authority are documented and current.
- Compliance responsibility is not assigned solely to one compliance officer without executive oversight.
- Governing persons understand that accountability remains with the registered provider when services are outsourced.
- Decision-making authority for training, assessment, certification, marketing, finance and student support is clear.
- Conflicts of interest and related-party relationships are declared, reviewed and managed.
- Changes to ownership, control, governing persons or senior management are identified and reported where required.
Suggested evidence
- governance charter;
- organisational chart;
- position descriptions;
- delegations register;
- governing-person declarations;
- conflict-of-interest register;
- board and management meeting records.
2. Governing-person suitability and capability
Confirm that:
- Required suitability and fit-and-proper-person checks are current.
- Governing persons understand the VET regulatory environment.
- Governing persons receive induction on provider obligations.
- Governance capability is reviewed when the provider expands scope, locations or delivery models.
- Governing persons understand the provider's principal student, delivery, financial and compliance risks.
- Relevant professional development is maintained.
Suggested evidence
- suitability declarations;
- identity and background checks;
- governance induction;
- professional-development records;
- board skills matrix;
- meeting attendance.
3. Regulatory obligations and compliance oversight
Confirm that:
- The provider maintains a current register of regulatory obligations.
- Changes to legislation, Standards, funding rules and CRICOS obligations are monitored.
- Relevant changes are communicated to affected staff.
- A compliance calendar identifies recurring reporting and renewal dates.
- Compliance performance is reported to governing persons.
- Regulatory correspondence is centrally controlled and escalated.
- Previous regulator findings and conditions are monitored.
- The provider can demonstrate ongoing self-assurance rather than reliance on pre-audit preparation.
Suggested evidence
- obligations register;
- compliance calendar;
- regulatory update records;
- board compliance reports;
- ASQA correspondence register;
- internal-assurance schedule.
4. Risk management
Confirm that:
- A current risk-management framework is in place.
- Risks are assessed using defined likelihood and consequence criteria.
- Student-outcome and regulatory risks are included, not only commercial risks.
- Risk owners and treatment actions are assigned.
- High and emerging risks are reported to governing persons.
- Risk treatments are reviewed for effectiveness.
- The risk register reflects actual operations.
- Financial, workforce, third-party, cyber, data, premises and continuity risks are considered.
- Significant incidents trigger risk reassessment.
Suggested evidence
- risk-management framework;
- risk register;
- treatment plans;
- risk reports;
- incident reviews;
- business-continuity plan.
5. Financial and operational sustainability
Confirm that:
- Governing persons receive current financial reports.
- Cash flow and financial forecasts are based on reasonable assumptions.
- Student-enrolment forecasts are compared with staffing and resource capacity.
- Related-party transactions are transparent.
- Prepaid student fees are protected as required.
- Refund liabilities are understood.
- The provider has continuity arrangements for disruption or closure.
- Growth decisions consider quality and compliance capacity.
- Financial risks are escalated before they affect students.
Suggested evidence
- financial statements;
- budgets and forecasts;
- cash-flow reports;
- management accounts;
- enrolment forecasts;
- prepaid-fee controls;
- continuity and closure plans.
6. Training quality and sufficiency
Confirm that:
- Each training product has a current and approved TAS.
- Delivery duration and structure are appropriate for the student cohort.
- Timetables align with the TAS.
- Actual delivery is periodically reconciled with the planned strategy.
- Practical training, workplace learning and simulation are adequately provided.
- Online or blended delivery includes meaningful engagement and support.
- Changes to delivery are approved and documented.
- Cancelled or missed sessions are replaced.
- Student support is integrated into delivery.
- Facilities and resources remain sufficient for current enrolment levels.
Suggested evidence
- TAS documents;
- timetables;
- trainer schedules;
- attendance records;
- LMS activity;
- practical-session records;
- resource registers;
- delivery-review reports.
7. Assessment and qualification integrity
Confirm that:
- Assessment tools meet training-product requirements.
- Assessment instructions and benchmarks are clear.
- Practical skills are directly and sufficiently observed.
- Authenticity and identity controls are appropriate.
- Assessor decisions are supported by retained evidence.
- Reassessment is controlled and documented.
- RPL decisions are based on adequate evidence.
- Validation is risk-based and results in improvement.
- Certification is not issued before all requirements are completed.
- Completed student files are periodically sampled.
Suggested evidence
- assessment tools;
- mapping documents;
- completed assessments;
- observation records;
- assessor feedback;
- validation records;
- RPL files;
- certification controls;
- file-sampling reports.
8. Workforce capacity and capability
Confirm that:
- Trainers and assessors meet credential requirements.
- Vocational competency is verified.
- Industry currency is current and relevant.
- Trainer and assessor professional development is planned and recorded.
- Workforce capacity is sufficient for enrolment levels and delivery schedules.
- Contractor arrangements are documented and monitored.
- Trainer workload is realistic.
- Supervision arrangements are effective where used.
- Staff understand relevant policies and operational procedures.
Suggested evidence
- trainer matrix;
- verified qualifications;
- CVs;
- industry-currency evidence;
- professional-development plans;
- contracts;
- workload and timetable records.
9. Student entry, support and progression
Confirm that:
- Entry requirements are clear and consistently applied.
- Pre-enrolment information is accurate.
- Course suitability and support needs are assessed.
- LLND or English-language requirements are appropriately considered.
- Reasonable adjustment is available and documented.
- Students at risk are identified and supported.
- Progression and participation are monitored.
- Complaints and appeals are accessible.
- Student feedback informs improvement.
Suggested evidence
- pre-enrolment reviews;
- LLND assessments;
- support plans;
- progression reports;
- intervention records;
- complaints and appeals;
- survey analysis.
10. Agents, third parties and complex arrangements
Confirm that:
- Due diligence is completed before engagement.
- Written agreements clearly define responsibilities.
- Marketing and recruitment activity is monitored.
- The provider has access to relevant records.
- Third-party performance is reviewed.
- Complaints and student outcomes are included in monitoring.
- Non-compliance is escalated and corrected.
- Arrangements can be terminated where necessary.
- The provider remains in effective control of delivery and assessment.
- Public information clearly identifies services delivered by another party.
Suggested evidence
- due-diligence checks;
- agreements;
- monitoring schedules;
- agent reports;
- performance reviews;
- meeting records;
- corrective actions;
- termination records.
11. Complaints, incidents and emerging risks
Confirm that:
- Complaints and appeals are recorded centrally.
- Trends and recurring causes are analysed.
- Serious matters are escalated to governing persons.
- Critical incidents are reviewed.
- Student-safety and wellbeing risks are addressed.
- Whistleblower or staff concerns can be raised safely.
- Incident findings inform policy and operational changes.
- Corrective actions are verified for effectiveness.
Suggested evidence
- complaints register;
- incident register;
- investigation records;
- trend reports;
- board reports;
- corrective-action records.
12. Continuous improvement and assurance
Confirm that:
- The provider has a planned assurance program.
- All significant operational functions are periodically reviewed.
- Internal audits use representative evidence samples.
- Findings identify cause, risk and affected operations.
- Actions have owners and due dates.
- Closure requires implementation evidence.
- Effectiveness is checked after implementation.
- Student, trainer, employer and stakeholder feedback is considered.
- Governing persons receive assurance reports.
- Improvement records show what changed and why.
Suggested evidence
- internal-audit schedule;
- audit reports;
- continuous-improvement register;
- action plans;
- closure evidence;
- effectiveness reviews;
- governance reports.
Suggested assurance rating
Providers may rate each section as:
- Effective: The system is implemented and supported by current evidence.
- Partially effective: The system exists but implementation or evidence is inconsistent.
- Not effective: The requirement is not adequately addressed.
- Not applicable: The area does not apply, with reasons documented.
A provider should prioritise matters that may affect:
- student safety;
- qualification integrity;
- training sufficiency;
- financial sustainability;
- regulatory reporting;
- third-party control; or
- continuity of student services.
E-Skills support
E-Skills Australia can conduct an independent governance and regulatory-risk review and provide:
- evidence-based findings;
- prioritised risk ratings;
- practical rectification actions;
- governance reporting recommendations; and
- follow-up assurance.