Treasury Regulations coverage that connects risk to audit by design
Every obligation tracked on a cycle with a named owner, the fraud prevention plan operating inside the register, and the audit plan reconciled to risk automatically.
Compliance at a glance
What the Treasury Regulations require
Risk assessments on a defensible cycle
Scheduled reviews, emerging risk capture and version history showing how the picture changed, so regular means demonstrably regular.
Fraud prevention inside the register
Fraud risks sit alongside operational and financial risk with the same scoring, owners and control evidence. The plan is auditable because it is operating, not filed.
Audit plan traced to risk
Every engagement linked to the register entry that justifies it, with a coverage view showing which top risks are unaudited and why.
Committee papers from live data
Audit committee packs generated from the register and findings data, with the risk to audit reconciliation included as a standing report.
Treasury Regulations compliance, covered by default
The Treasury Regulations turn the PFMA's broad duties into working requirements, from risk assessments and fraud prevention plans to audit plans and committee papers. Dimeri delivers each one as a working system rather than a document to maintain.
Risk management obligations mapped
Risk assessment cycles, the risk management strategy, the fraud prevention plan and the link to internal audit. Each is held as a tracked obligation with its own review date and owner.
Fraud prevention plan
Fraud risks live in the main register with their own controls and evidence, so the plan is auditable and operating rather than a standalone document filed once a year.
Risk-to-audit reconciliation
The view the rules imply, every significant risk on one axis and every planned engagement on the other, produced automatically from the register and the audit plan.
Audit committee packs
Committee papers drawn from live register and findings data, with the reconciliation between the risk register and the audit plan included as a standing report.
Cycle enforcement
Assessment reviews, control tests, strategy refreshes and committee dates run as recurring obligations with reminders and escalation, so regular means regular.
The obligations Dimeri tracks
Dimeri holds the Treasury Regulations as operational obligations on a cycle rather than as documents on a shelf, because that is how they are tested.
Regular risk assessment
A risk assessment conducted regularly to identify emerging risks, not a single annual exercise that goes stale by the second quarter.
- Assessment cycle with scheduled reviews and reminders
- Emerging risk capture between formal cycles
- Inherent and residual scoring with a documented basis
- Version history showing how the picture changed
Risk management strategy and fraud prevention plan
A risk management strategy that includes a fraud prevention plan, communicated to all officials so they understand what it asks of them.
- Strategy and fraud prevention plan held against their review dates
- Fraud risks recorded with their specific preventive controls
- Distribution and acknowledgement records for officials
- Approval trail through the risk committee and accounting officer
Risk strategy directing internal audit
The link most institutions cannot evidence: the risk management strategy used to direct internal audit effort and priority.
- Audit plan line items traced to register entries
- Coverage view showing which top risks are unaudited
- Rationale recorded where a high risk is deliberately not audited
- Reconciliation produced for the audit committee
Internal audit function and plans
An internal audit function working to a rolling three year strategic plan based on key areas of risk, with an annual plan for the first year.
- Rolling three year plan held against the risk assessment
- Annual plan with engagement status and resourcing
- Findings tracked to closure with owners and due dates
- Follow up on previously agreed management actions
Audit committee oversight
An audit committee that receives and evaluates the work, with papers it can rely on rather than reconstruct.
- Committee calendar with standing agenda items
- Packs generated from live register and findings data
- Matters arising tracked between meetings
- Annual committee report inputs assembled through the year
Public entity equivalents
Public entities carry equivalent risk management and internal audit duties, applied through the accounting authority rather than an accounting officer.
- Entity obligation set with the correct statutory wording
- Board and committee reporting lines reflected in the workflow
- Group view across entities for a parent department
- Consolidated risk reporting to the executive authority
Getting Treasury Regulations coverage in place
4 steps from where you are today to a Treasury Regulations position your auditor can rely on.
Book a demoThe internal audit and risk management duties arrive broken into their component parts, pre-mapped to the matching PFMA and PSRMF requirements so you are not maintaining three registers.
How Dimeri covers Treasury Regulations
The audit plan reconciliation
Dimeri produces the view the regulations call for: every significant risk on one axis, every planned audit engagement on the other, and the uncovered cells visible. This is usually the fastest thing to fix and the hardest to produce from spreadsheets.
Fraud risk held with everything else
The fraud prevention plan stops being a standalone document. Fraud risks live in the same register as operational and financial risk, with the same scoring, the same owners and the same control evidence, which is what makes the plan auditable.
Cycles that run themselves
Regular means on a schedule. Assessment reviews, control tests, strategy refreshes and committee dates run as recurring obligations with reminders and escalation, so a missed cycle surfaces while it can still be fixed.
Treasury Regulations questions
Which Treasury Regulations matter most for risk and assurance?
The internal audit and risk management provisions do most of the work. One set covers internal audit, including the rolling three year strategic plan based on key areas of risk and the annual plan. The other covers risk management, including regular risk assessment and a risk management strategy incorporating a fraud prevention plan. Public entities carry equivalent duties.
Do the Treasury Regulations require a fraud prevention plan?
Yes. The risk management provisions call for the strategy to include a fraud prevention plan. In Dimeri the plan is not a standalone file: the fraud risks it addresses sit in the main register with their own controls and evidence, so the plan can be shown to be operating rather than simply to exist.
What does it mean that the risk strategy must direct internal audit?
The regulations call for the risk management strategy to be used to direct internal audit effort and priority. In practice an auditor will ask you to show which risks drove which engagements. Dimeri maintains that link directly, so the reconciliation between the risk register and the audit plan is a report rather than a project.
How often is regularly?
The regulations say regularly rather than naming a frequency, which leaves it to the institution to set a defensible cycle and then keep to it. Most institutions run a full annual assessment with quarterly reviews and continuous capture of emerging risks. Dimeri enforces whichever cycle you set and shows when it slips.
Is this a substitute for legal advice?
No. This page describes how Dimeri structures Treasury Regulations obligations for tracking and evidence. It is not legal advice, and your legal advisers should confirm the current text and which provisions apply to your institution.
Ready to Transform Your GRC?
Join governance, risk, and compliance teams using AI to work smarter.