Free Resources

Practical compliance resources for Australian organisations

Guides, interactive readiness checklists, and insights — built around what auditors actually look for, not what makes compliance seem harder than it is. Everything here is free.

Interactive checklists

Answer questions, see your score, download a prioritised PDF roadmap. Takes 12–15 minutes. Gives you an honest baseline and the most important gaps to close first.

§
Deep-dive guides

Practitioner-level guides on specific topics — what auditors look for, how to build it, what good looks like. Written for CISOs, compliance owners, and technical leads.

Insights & articles

Practical articles on compliance strategy, enterprise sales, and implementation — written for teams that need to make compliance decisions, not just read about them.

Show
Framework

Deep-dive guides

Practitioner-level guides on specific compliance topics. Each one covers the standard, what auditors actually check, how to implement it, and what good evidence looks like.

ISO 42001 Reports — Audit-Ready AI Governance Reporting
Featured ISO 42001 · Reporting 8 min read

ISO 42001 Reports — Audit-Ready AI Governance Reporting

The six reports an AI management system actually needs — internal audit report, management review, AI risk & impact assessment summary, Statement of Applicability, board report, and auditor evidence pack.

Read guide →
What a Good AI System Inventory Looks Like (ISO 42001)
ISO 42001 · AI Governance 7 min read

What a Good AI System Inventory Looks Like (ISO 42001)

The single most common reason an AIMS falls over at the first audit. What to track, the fields that work, and how to find AI you didn't know was already running.

Read guide →
The ISO 42001 Policy Pack — What You Actually Need
ISO 42001 · Policy 6 min read

The ISO 42001 Policy Pack — What You Actually Need

A small, coherent set of policies an auditor can trace from statement to evidence — not twenty documents nobody's read since they were written.

Read guide →
ISO 42001 vs NIST AI RMF vs EU AI Act — How the AI Governance Frameworks Map Together
ISO 42001 · AI Governance 10 min read

ISO 42001 vs NIST AI RMF vs EU AI Act — How the AI Governance Frameworks Map Together

A regulation, a risk methodology and a certifiable management system — how they map onto each other clause by clause, and why ISO 42001 is built to sit at the centre.

Read guide →
UK Cyber Essentials Readiness — Automated Inside Your Microsoft 365 Tenant
Cyber Essentials · UK Service overview

UK Cyber Essentials Readiness — Automated Inside Your Microsoft 365 Tenant

Four of five Cyber Essentials control themes are evidenced from the same Microsoft 365 checks we already run for Essential Eight and ISO 27001. We prepare you; submission goes through an IASME-licensed body of your choice.

Read guide →
Privacy Act 2024 Reforms Readiness — What Changed and What to Check
Privacy Act · Data Breach 8 min read

Privacy Act 2024 Reforms Readiness — What Changed and What to Check

Mandatory breach notification tightened, automated decision-making now needs formal governance, and penalties went up. A practical readiness checklist — standalone from ISO 27701 certification.

Read guide →
Ransomware Payment Reporting Readiness — Cyber Security Act Obligations
Cyber Security Act · Essential Eight 7 min read

Ransomware Payment Reporting Readiness — Cyber Security Act Obligations

If you pay a ransom, you now have to report it. A practical guide to the decision authority, reporting process, and how it pairs with an Essential Eight uplift.

Read guide →
AI Vendor Risk Assessment — Faster Than Full ISO 42001
AI Governance · ISO 42001 Service overview

AI Vendor Risk Assessment — Faster Than Full ISO 42001

A scoped engagement for procurement-driven AI security questionnaires — a defensible answer in weeks, with a clear upgrade path to full ISO 42001 certification later.

Read guide →
The Essential Eight Explained — Australia's Complete Cyber Security Guide
Essential Eight · ASD 20 min read

The Essential Eight Explained — Australia's Complete Cyber Security Guide

What the Essential Eight is, the maturity model (ML1/ML2/ML3), all eight controls in detail, who needs it, how to achieve ML2, and what evidence auditors expect. Updated June 2026.

Read guide →
IS18 Compliance for Queensland Government ICT Suppliers — Complete Guide
IS18 · Queensland Government 18 min read

IS18 Compliance for Queensland Government ICT Suppliers — Complete Guide

What IS18 requires, how it maps to Essential Eight and ISO 27001, what an IS18 Compliance Statement must contain, and how to achieve compliance in 4–12 weeks. Essential reading for any QLD Government ICT supplier.

Read guide →
ASD Essentials Series: What Replaces the Essential Eight?
Essential Eight · ASD · Transition 10 min read

ASD Essentials Series: What Replaces the Essential Eight?

ASD is retiring the Essential Eight and replacing it with the Essentials series — a broader framework covering enterprise IT, OT, cloud and agentic AI. Understand what's changing, when, and what to do now.

Read guide →
The RFFR SoA Control Library — Every ISM Control, and What Automates
RFFR · ISM · DEWR Reference

The RFFR SoA Control Library — Every ISM Control, and What Automates

Browse the complete Right Fit For Risk Statement of Applicability: all 989 ISM (June 2026) controls plus the 7 program-deed obligations, filterable by guideline, with Essential Eight maturity and Microsoft 365 automation coverage marked on every control.

Read guide →
Inside a Statement of Applicability (SoA)
ISO 27001 · ISO 27701 · ISO 42001 12 min read

Inside a Statement of Applicability (SoA)

What auditors expect, how risk links to Annex A, and how to build an integrated SoA across ISO 27001, ISO 27701, and ISO 42001 in Microsoft 365.

Read guide →
What a Good ROPA Looks Like — and Common Mistakes
ISO 27701 · Privacy Act 10 min read

What a Good ROPA Looks Like — and Common Mistakes

The anatomy of a useful Record of Processing Activities with worked examples, common gaps that trigger regulatory enquiries, and a SharePoint-based implementation guide.

Read guide →
AI Governance Readiness — ISO 42001 Explained
ISO 42001 · AI Governance 10 min read

AI Governance Readiness — ISO 42001 Explained

Model inventory, AI risk and impact assessments, human oversight, and monitoring — a practical guide to building an AI Management System inside Microsoft 365.

Read guide →
Automating Compliance in Microsoft 365, Azure & AWS
Microsoft 365 · Azure · AWS 8 min read

Automating Compliance in Microsoft 365, Azure & AWS

How to turn evidence collection, access reviews, and security posture into continuous assurance using tools you already own — no third-party GRC platform required.

Read guide →
How to Build a Risk Register in SharePoint
ISO 27001 · ISO 27701 · ISO 42001 14 min read

How to Build a Risk Register in SharePoint

Full column schema, conditional formatting JSON, Power Automate flows, and views — one SharePoint List covering ISO 27001, ISO 27701, and ISO 42001. No third-party GRC platform required.

Read guide →

Insights & articles

Practical articles on compliance strategy, enterprise sales, and implementation guidance for Australian organisations.

View all articles →

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on Privacy Act changes, Essential Eight revisions, ISO 27001 news, and real implementation tips — once a month, no spam.

No spam. Unsubscribe any time. We never share your email.

Not sure which resource to start with?

A free 30-minute call will tell you which framework applies to your situation, what your most important gaps are, and what the fastest path to audit-ready looks like. No obligation.

Microsoft Teams