— Services

Advisory across the full data and information governance lifecycle.

Each engagement starts with a scoped assessment, not a generic framework. The services below reflect recurring needs across public and private sector clients; most engagements combine elements of more than one.

SERVICE LINE 01

Data Governance & Privacy Compliance Advisory

Privacy Act 1988 and Australian Privacy Principles compliance reviews, data governance framework design, privacy policy and collection notice review, and readiness assessment for the automated decision-making transparency obligations taking effect 10 December 2026.

Privacy management framework design and uplift

Data mapping and information asset registers

Privacy impact assessments

Notifiable Data Breaches scheme readiness and response planning

Cross-border data transfer governance

Suited to organisations preparing for OAIC scrutiny, boards seeking assurance their privacy posture is defensible, and organisations affected by small business exemption changes or AML/CTF-driven Privacy Act expansion.

Privacy Act 1988
APP 1.7–1.9
SERVICE LINE 02

AI Governance & Accountability Frameworks

Practical AI governance design aligned to the National AI Centre’s Guidance for AI Adoption and Australia’s AI Ethics Principles: risk classification, human oversight design, transparency and disclosure practices, and accountability structures across the AI lifecycle.

AI use case risk assessment and registers

AI governance policy and oversight structure design

Vendor and procurement due diligence for AI systems

Board and executive briefings on AI regulatory direction

Suited to organisations adopting AI tools who need a defensible governance position under Australia’s technology-neutral regulatory approach, and Commonwealth or state agencies managing staged mandatory AI policy requirements.

GfAA, Oct 2025
National AI Plan
SERVICE LINE 03

Records & Information Management Architecture

Information governance frameworks and records management systems aligned to ISO 15489, retention and disposal schedules, digital archiving and lifecycle governance, and document management system design, drawing on direct delivery experience on a $700M capital project.

Records and information governance framework design

Retention, disposal and lifecycle policy development

Document and records management system selection and governance

Public sector records and archives modernisation advisory

Suited to public sector bodies and large enterprises managing legacy records environments, digital transformation programs, or regulatory obligations around records retention.

ISO 15489
SERVICE LINE 04

Professional Certification & Standards Architecture

Design of professional certification and accreditation schemes aligned to ISO/IEC 17024, competency framework development, and capacity-building program design, drawing on direct experience architecting a national certification body recognised by a government data protection regulator.

Certification scheme design (ISO/IEC 17024 aligned)

Competency framework development

Governance structure design for professional bodies and standards organisations

Training and accreditation program architecture

Suited to industry associations, regulators and membership bodies seeking to establish or formalise a professional certification scheme.

ISO/IEC 17024
— Engagement Approach

How engagements work.

01

Initial briefing

A focused conversation to understand the problem and confirm fit, at no cost.

02

Scoped proposal

A defined scope, timeline and fee. No open-ended retainers without agreement.

03

Delivery

Working sessions, documented frameworks, and where relevant, board or executive presentation of findings.

04

Handover

Frameworks are built to be owned and run by your team, not to create ongoing dependency.

Not sure which service line fits?

Most problems don’t arrive pre-sorted. A short conversation is the fastest way to find out.