Skip to main content
Green Ports Toolkit
Global · Case study

Port of Melbourne, Enterprise Risk Management Framework

Melbourne, Australia2022 to present

The Port of Melbourne operates a comprehensive enterprise risk management framework integrated into its governance structure (Port of Melbourne, 2024b). The port maintains a corporate risk register, including climate related risks, that is reviewed regularly throughout the year (Port of Melbourne, 2024b). The port's risk management approach aligns with the Port Management Act 1995 (amended 2003), which requires managers of Victorian local and commercial ports to prepare Safety and Environment Management Plans that are audited by approved auditors.

In May 2022, Port of Melbourne's Safety and Environment Management Plan was externally audited by an auditor approved by the Minister for Ports, who found it had been prepared as required by the Port Management Act 1995 and that the port was complying with it (Port of Melbourne, 2022).

The port applies a structured risk assessment process that rates each risk by likelihood and by consequences including financial impact, regulation and compliance, community and reputation, environment and safety, and business interruption (Port of Melbourne, 2025). Corporate risks are reported to the Board annually and to the Audit and Risk Management Committee twice a year (Port of Melbourne, 2024b).

Port of Melbourne's ERM framework manages climate related risks and opportunities, and the port's climate disclosures are guided by the Australian Sustainability Reporting Standards (ASRS) and its reporting is aligned with the Global Reporting Initiative (GRI) standards (Port of Melbourne, 2024b; Port of Melbourne, 2025).

Business continuity planning and safety protocols are in place to support port operations during and after adverse weather events (Port of Melbourne, 2025).

Transferability

DMC port authorities can rate every risk on one likelihood and consequence scale that covers financial, compliance, community, environment, safety and business interruption impacts. Keeping climate risks in the same corporate register, rather than a separate list, lets the board compare them with other risks. A set reporting rhythm, such as twice a year to an audit and risk committee and once a year to the board, keeps oversight regular. Where national law requires port safety and environment management plans, independent audit of those plans gives external assurance that the plan is being followed.

Sources

All information used for this case study was based on publicly available resources.