Start with the obligation

Compliance by regulation

Most buyers do not start with a service name — they start with the standard a customer, insurer or board has asked them to meet. Each obligation below is broken into what it actually demands and the work that answers it.

ACSC Essential Eight

Australian Signals Directorate / ACSC

Who it applies to. Commonwealth entities under the PSPF, and any Australian business asked to demonstrate a baseline maturity level by a customer, insurer or board.

Eight mitigation strategies, each scored from Maturity Level 0 to 3. Progress is measured per strategy, not as an average — so the honest question is which strategy is holding the target level back.

ISO/IEC 42001

International standard for AI management systems

Who it applies to. Organisations deploying or building AI who need governance that stands up to customer and regulator scrutiny.

The AI equivalent of 27001: defined AI scope, impact assessment, lifecycle controls and evidence that human oversight is real.

APRA CPS 234 and CPS 230

Australian Prudential Regulation Authority

Who it applies to. APRA-regulated entities and the service providers they rely on.

Information security capability commensurate with the threat, clear accountability, and tested controls — plus operational resilience obligations under CPS 230.

Dealing with a live incident right now?

Suspected breach, ransomware note, business email compromise or a notifiable data breach clock already running — say so and your enquiry is triaged ahead of the queue.

Not sure which obligation actually binds you?

Thirty minutes with a senior advisor is usually enough to separate the contractual requirement from the nice-to-have, and to sequence the work.

Book a review