Right Fit for Risk

RFFR accreditation, without the guesswork

If you deliver services under a departmental contract, your security accreditation is not optional and neither is the deadline. I help providers get there and stay there.

Book a conversation

The requirement is clear. The path is not.

Right Fit for Risk is the Department of Employment and Workplace Relations approach to accrediting the information security of contracted providers and the systems that connect to its environment. It sits inside the External Systems Assurance Framework, which is built on the whole-of-government Protective Security Policy Framework.

Whetherr you’re a category 1 provider needing a full ISO27001 certification, or a smaller provider requiring a self audited ISMS system, the requirements are clear, but getting there isn’t just a case of ticking boxes.

In practice it means building an information security management system consistent with ISO 27001, then extending it with controls from the Australian Government Information Security Manual relevant to OFFICIAL information, plus the department’s own core expectations.

The requirement is not the hard part. The hard part is that RFFR asks a mid-sized provider to build and evidence a full ISMS, against milestone deadlines, usually without a dedicated security team.

Two things that catch providers out

Your subcontractors are in scope. The department seeks assurance that providers and their subcontractors have implemented an appropriate standard of security. If you deliver any part of your service through another organisation, their security posture is your accreditation problem. This is routinely discovered late.

ISO 27001:2013 is dead. Certificates issued against the 2013 version stopped being valid on 31 October 2025. If you are working from documentation written before the transition, some of it is out of date.

What you get

A scope that will survive assessment

Too wide and you drown in evidence. Too narrow and it gets rejected. This decision determines how hard the rest will be.

Milestone-ready evidence

The artefacts assessors actually ask for, built as you go rather than assembled in a panic.

Controls proportionate to your risk

“Right fit” is in the name for a reason. You are required to demonstrate that your controls suit your risk.

Subcontractor assurance

What you need from the organisations delivering on your behalf, and how to evidence it without souring the relationship.

AI assessment support

Preparing AI use cases for submission, and the governance that keeps them approved.

A system that survives me leaving

Maintenance is continuous. What I build is meant to be run by your people.

Do I actually need RFFR?

Accreditation applies to two groups: 

  1. service providers contracted to deliver departmental programs and their subcontractors, and 
  2. Third Party Employment and Skills systems that interface with the department or store program data.

You are in scope if any of the following apply:

  • Does your Deed reference security accreditation or an ISMS?
  • Do you handle participant or jobseeker data?
  • Does a system you operate exchange data with departmental systems?
  • Has the department asked you for a self-assessment report?
  • Do you deliver any part of your service through a subcontractor?

If you use AI, then there's an extra step in your RFFR cycle

The RFFR accreditation lifecycle as a continuous loop, with AI use entering at the accreditation stage

Related resource

If you want to use AI in service delivery, that now has to be assessed and approved separately, and then maintained inside your accreditation.

Click here for information on RFFR AI Assessment

Not sure where to start?

Tell me what you're facing. You'll get a straight answer on whether this is the right piece of work, and what it would involve.

Book a conversation