Built to
The standards behind governance, risk, audit and legal
ISO 31000 and COSO for risk, audit and risk committee rules, ISO 37301 compliance, the IIA Global Internal Audit Standards, ISO 22301 continuity, AS 8001 fraud and corruption control, the Legal Services Directions and court rules, information access law, public interest and records.
| Standard | Source | Requirement | Where it shows up here |
|---|---|---|---|
| Risk management | ISO 31000:2018; COSO ERM (2017); Commonwealth Risk Management Policy (2023) under PGPA Act s 16; NSW Risk Management and Internal Audit Guidelines for local government (2022) | A register with owners, controls and treatments; an appetite set by the governing body; movement escalated; the register reviewed on a cycle. | Risk register with inherent and residual ratings; appetite by category set by the audit and risk committee; live signals from every service move likelihood and escalate beyond appetite (GL-GA-01, 02). |
| Audit and risk committee | Local Government Act s 428A and Regulation (audit, risk and improvement committees); PGPA Rule s 17; Department of Finance guidance | An independent committee that sets appetite, accepts audit findings and oversees control, compliance and risk. | RISK_ACCEPTANCE, APPETITE_SETTING and FINDING_ACCEPTANCE are delegated to the committee and checked in code. |
| Compliance management | ISO 37301:2021; AS ISO 37301; statutory obligations under the Acts each service administers | An obligations register with owners and due dates, evidence of compliance, and reporting of breaches. | Every obligation carries its source, owner and due date; live evidence rules read the owning service; overdue obligations surface to the owner (GL-GA-03). |
| Internal audit | IIA Global Internal Audit Standards (2024); IPPF; Institute of Internal Auditors independence and evidence requirements | Engagements with objectives, criteria, sufficient and reliable evidence, workpapers, findings with management responses, and follow-up. | Workpapers cite the platform record they tested, with population, sample and exceptions; findings carry condition, criteria, cause and recommendation; management responses before acceptance; closure with evidence (GL-GA-04, 05). |
| Business continuity | ISO 22301:2019; ISO 22313 guidance; Essential Eight backup requirements | Plans with recovery time and point objectives, tested at least annually; incidents reviewed and closed with lessons. | Plans with RTO and RPO tested against the live platform; incidents assessed against the RTO and closed only by the accountable executive with lessons (GL-GA-08). |
| Fraud and corruption control | AS 8001:2021; ICAC and IBAC guidance; Commonwealth Fraud and Corruption Control Framework (2024) | Conflicts and gifts registers, segregation of duties, controls tested. | Conflicts and gifts on one register with MG-02 and MG-14; audit tests of delegations, conflicts declared before scoring and voting (GL-GA-09). |
| Legal services and litigation | Legal Services Directions 2017 (model litigant obligation); court rules (28-day defence; subpoena return dates); Limitation Acts; Civil Liability Acts | Positions and settlements decided by an accountable lawyer within delegation; deadlines met; the department acts as a model litigant. | Every matter carries its deadline rule; the file is assembled from the services; general counsel decides the position and settlements within a monetary limit (GL-GA-06, 07). |
| Information access reviews | GIPA Act (NSW) s 83 (internal review within 20 working days); FOI Act (Cth) s 54C (30 days) | Reviews decided in the period by a different officer. | FOI_REVIEW matters carry the 20-working-day clock; the position holds for general counsel. |
| Public interest and accountability | Public Interest Disclosures Acts; Ombudsman good administration guidance; public sector codes of ethics | Findings, risks and obligations reported to the governing body and, where appropriate, the public. | Public accountability page shows the appetite statement, findings accepted and closed, obligations met, and continuity tests. |
| Records and evidence | ISO 15489; Evidence Acts (business records); court discovery rules | Records that can be produced and relied on: who did what, when, on what basis. | The tamper-evident evidence chain and every agent run and human decision are cited in workpapers and exportable for discovery. |