← Back to Case Studies

Health SaaS — Zero Cyber Maturity to Integrated ISMS in 10 Weeks

A fast-growing Australian health SaaS provider went from zero cyber maturity to Essential Eight ML2, ISO 27701 privacy, and ISO 42001 AI governance — integrated into a single management system — in 10 weeks, unlocking enterprise health contracts.

Sector: Healthcare Services: Essential Eight, ISO 27701, ISO 42001, Integrated Management System, DPIA, ROPA, AI Governance Tags: Essential Eight, ISO 27701, ISO 42001, Healthcare, SaaS, Privacy, AI Governance, ISMS
10 weeksZero to integrated ISMS across 3 frameworks
Essential Eight ML2Achieved and evidenced
ISO 27701 + 42001Delivered simultaneously
Enterprise contractsHealth system procurement unlocked

At a Glance

SectorHealthcare Technology (SaaS, clinical AI)
Starting pointZero formal security programme — no policies, no controls documentation, no privacy framework, AI systems in production with no governance
Timeline10 weeks to integrated management system across all three frameworks
FrameworksEssential Eight (ML2), ISO 27701:2019, ISO 42001:2023
EnvironmentMicrosoft 365 (SharePoint, Intune, Defender, Entra ID, Purview)

The Challenge

The organisation had built a genuinely strong clinical product — but security, privacy, and AI governance had not kept pace with growth. As the business moved toward enterprise health system contracts, three procurement requirements landed almost simultaneously:

  1. Essential Eight ML2 — required by the health system’s IT security policy for all software vendors handling clinical data
  2. ISO 27701 (Privacy) — required to demonstrate compliance with the Australian Privacy Act, My Health Records Act, and the health system’s own privacy obligations
  3. AI governance evidence — required following the health system’s own ISO 42001 implementation, which had created supply chain obligations for AI-enabled vendors

The compounding challenge: a health system procuring a clinical AI platform wasn’t going to accept three separate documentation packs — they needed to see an integrated, coherent governance posture.

The starting point was stark:


Our Approach

The only viable path to the 10-week objective was integration from the start — building a single management system where the shared infrastructure (scope, risk, evidence, governance) served all three frameworks simultaneously.

1. Integrated scope and governance (weeks 1–2)

Defined a single management system scope covering cyber security, privacy, and AI governance. Established the policy hierarchy, leadership roles, and operating cadences that would underpin all three frameworks — with a shared risk register and evidence repository.

2. Essential Eight uplift (weeks 2–6)

Assessed current maturity against ASD’s ML2 criteria across all eight controls. Implemented in sequence using the existing Microsoft 365 environment:

Evidence packs assembled against ASD ML2 criteria for each control milestone.

3. ISO 27701 privacy framework (weeks 3–7)

Built the Privacy Information Management System on top of the ISMS foundation:

4. ISO 42001 AI governance (weeks 4–8)

Implemented an AI Management System covering the clinical AI systems in production:

The AIMS was integrated with the ISMS and PIMS — shared risk register, shared evidence infrastructure, single management review.

5. Integration and audit readiness (weeks 8–10)

Consolidated the three management systems into a single audit-ready structure. Conducted an integrated internal audit. Prepared the evidence pack for the health system’s vendor assessment — structured to answer all three sets of requirements from a single document set.


Results

All three frameworks delivered in 10 weeks — Essential Eight ML2, ISO 27701, and ISO 42001 — in an integrated management system that answered the procurement team’s requirements without multiple rounds of back-and-forth.

The enterprise health system contract proceeded to execution. Additional outcomes:


Key Deliverables


The Bottom Line

Enterprise health system procurement doesn’t wait for vendors to mature their governance programmes sequentially. When three framework requirements arrive simultaneously, the only viable response is an integrated programme that builds the shared infrastructure once and lets each framework draw from it.

10 weeks. From zero. No existing tools replaced, no team disruption beyond what was necessary — and three enterprise framework requirements answered with a single, coherent governance posture.

Need a similar outcome?

We help government, health, and technology organisations achieve certification faster with automated evidence and expert delivery.

Book a free 30-min call
📞 Microsoft Teams