Right Fit for Risk
If you deliver services under a departmental contract, your security accreditation is not optional and neither is the deadline. I help providers get there and stay there.
Right Fit for Risk is the Department of Employment and Workplace Relations approach to accrediting the information security of contracted providers and the systems that connect to its environment. It sits inside the External Systems Assurance Framework, which is built on the whole-of-government Protective Security Policy Framework.
Whether you’re a category 1 provider needing a full ISO 27001 certification, or a smaller provider requiring a self-audited ISMS, the requirements are clear, but getting there isn’t just a case of ticking boxes.
In practice it means building an information security management system consistent with ISO 27001, then extending it with controls from the Australian Government Information Security Manual relevant to OFFICIAL information, plus the department’s own core expectations.
The requirement is not the hard part. The hard part is that RFFR asks a mid-sized provider to build and evidence a full ISMS, against milestone deadlines, usually without a dedicated security team.
What
this looks like when it works: a mid-sized disability employment provider, no
dedicated security team. Initial accreditation, three annual recertifications,
and the RFFR evidence behind a successful Inclusive Employment Australia bid
when the DES contracts ended. Built with their people and still run by their
people.
Your subcontractors are in scope. The department seeks assurance that providers and their subcontractors have implemented an appropriate standard of security. If you deliver any part of your service through another organisation, their security posture is your accreditation problem. This is routinely discovered late.
ISO 27001:2013 is dead. Certificates issued against the 2013 version stopped being valid on 31 October 2025. If you are working from documentation written before the transition, some of it is out of date.
Too wide and you drown in evidence. Too narrow and it gets rejected. This decision determines how hard the rest will be.
The artefacts assessors actually ask for, built as you go rather than assembled in a panic.
“Right fit” is in the name for a reason. You are required to demonstrate that your controls suit your risk.
What you need from the organisations delivering on your behalf, and how to evidence it without souring the relationship.
Preparing AI use cases for submission, and the governance that keeps them approved.
Maintenance is continuous. What I build is meant to be run by your people.
Accreditation applies to two groups:
You are in scope if any of the following apply:
If you want to use AI in service delivery, that now has to be assessed and approved separately, and then maintained inside your accreditation.
Tell me what you're facing. You'll get a straight answer on whether this is the right piece of work, and what it would involve.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
ZOHO is a comprehensive suite of cloud-based applications for business management, collaboration, and productivity.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
GoDaddy's visitor traffic tracking, added automatically to sites hosted with GoDaddy and to sites built with GoDaddy Website Builder. It records page views, clicks, and page timing, and sends them to GoDaddy to measure traffic and site performance.
Service URL: www.godaddy.com (opens in a new window)
You can find more information in our Privacy Policy and .