
CEO | Audit Express
Kevin Ekendahl is CEO of Audit Express and a specialist in tertiary education compliance, audit, and quality assurance. With over a decade of experience, he supports vocational and higher education providers to navigate regulatory requirements, strengthen quality systems, and turn compliance challenges into practical improvement opportunities.
This practical workshop will support PTEs and other tertiary education providers to build or strengthen an effective risk management system using ISO 31000 principles. As providers respond to policy reform, changing learner needs, workforce demands, regional delivery pressures, AI, international education growth, and quality assurance expectations, risk management provides a practical structure for making better decisions and turning policy intent into operational practice. The Tertiary Education Strategy 2025–2030 and the Private Training Establishment Rules 2026 will be used as sector context, showing why effective risk management matters for learner achievement, access and participation, workforce relevance, collaboration, safe delivery, student support, staffing, assessment, moderation, records, and quality management. The workshop will focus on practical application. Participants will be introduced to a simple risk management system structure, including risk categories, a risk register, risk ratings, controls, treatment actions, monitoring indicators, reporting, and review cycles. Working with realistic PTE scenarios such as regional delivery, assessment risk, learner support, staffing, AI, international education, or programme change, participants will identify risks, assess which risks matter most, develop practical controls, and consider what evidence would show whether those controls are working.
AI influences how learners’ study, how staff work, and how PTEs design, deliver, assess, and support learning. AI creates opportunities for efficiency, innovation, and learner support; however, it also introduces risks around privacy, data security, assessment integrity, learner authenticity, staff capability, academic judgement and recordkeeping. This session will explore how PTEs can use ISO 31000 risk management principles to manage AI risks and develop practical AI policies and controls. Rather than focusing on whether AI should be accepted or banned, the session will support providers to take a structured, risk-based approach to understanding AI use, setting clear expectations, and implementing safeguards across teaching, learning, assessment, administration, and quality assurance. Using ISO 31000 as a practical framework, the session will step through the process of understanding the AI context, identifying risks, assessing and prioritising risks, deciding on treatment actions, monitoring effectiveness, and communicating expectations clearly to staff and learners. The session will discuss what a practical AI policy may need to cover e.g. acceptable and unacceptable use, learner and staff responsibilities, AI use in assessment, disclosure requirements, privacy and confidential information, human oversight, academic integrity, use of AI detection tools, recordkeeping, staff training, and policy review. Practical examples will show how AI risks can arise in different areas