Home / Industries / Not-for-profit & human services
MyRISK · not-for-profit and human services
Government funding comes with compliance. Your compliance team is one or two people.
Employment programs carry Right Fit for Risk. Disability, aged care and community programs carry their own quality standards, and every program brings privacy and funding-agreement obligations that change and are audited. Core holds the controls and evidence once, so the next assessment is an update, not a rebuild.
Why now
The obligations grow with every program. The team does not.
For employment services, Inclusive Employment Australia replaced the Disability Employment Services program from 1 November 2025, and providers must meet Right Fit for Risk — the ISM and ISO 27001 — before they deliver. Disability, aged care and community programs answer to their own standards, such as the NDIS Practice Standards, with audits and funding-agreement reporting of their own. A provider running several programs carries several of these at once.
None of it is a one-off. For RFFR, the ISM changes every quarter and the Statement of Applicability has to follow it. Surveillance audits come back every year — usually answered from a spreadsheet one person maintains across every site.
The work is not the frameworks. It is keeping them current with the people you have.
What usually starts the conversation
- A new government program contract with Right Fit for Risk attached
- A quarterly ISM release that changes the Statement of Applicability
- An ISO 27001 certification or surveillance audit
- A funding-agreement or program audit with an evidence request
- New sites, merged programs, or a change of managed service provider
- A privacy incident, and the question of what the controls actually were
Where it bites first
Six places the same evidence is assembled again
01
The Statement of Applicability
Every quarterly ISM release flags new and changed controls, and the SoA follows them, instead of a manual comparison in a spreadsheet.
02
ISM and ISO 27001 together
Controls assessed once against the ISM and mapped to ISO 27001, so one assessment answers both.
03
Many sites, one position
Where sites share the same technology and provider, one assessment can carry across them, with the exceptions recorded.
04
The surveillance audit
Evidence held against each control through the year, so the auditor's request is a retrieval.
05
Your managed service provider
The controls your provider runs for you, assessed and evidenced as theirs, with the questionnaire portal free for them to answer.
—
Not only cyber
Program standards, privacy and funding-agreement reporting draw on the same evidence. Load the framework you answer to, and reuse what already holds.
Human services compliance
Every program standard you answer to, as one annual package.
Right Fit for Risk (the ISM and ISO 27001) for employment programs, and whichever other standards your programs answer to — such as the NDIS Practice Standards, the Aged Care Quality Standards, state human services standards, the Privacy Act and the Essential Eight — loaded for you. Priced by your compliance team; everyone who fills in data is licence-free. Australian dollars, excluding GST.
| Package, per year | 1–2 in compliance | 3–5 in compliance | What is included |
|---|---|---|---|
| Bronze | A$19,000 | A$36,000 | The platform, with all ISM updates, and your other specific program standards loaded, as well as monthly 60-minute support calls |
| Silver | A$29,000 | A$46,000 | Bronze, plus a two-day bootcamp and monthly 60-minute management cyber risk advice |
| Gold | A$39,000 | A$56,000 | Bronze, plus fifteen days of expert compliance resource to carry out the assessments |
Every Core plan, from the Free Tier, is on Core plans and pricing. References from employment service providers are available on request.
Where to start
Three ways in, by the size of the job
A small team, one program
Start on the Free Tier with the frameworks already loaded, and move to a compliance package or a plan when the assessment is due.
Several programs or many sites
With a compliance team of three or more and someone who can approve the spend, the Opportunity Scan maps your last assessment into Core and ends with a plan and a price.
Risk, not only compliance
If the board or a funder keeps asking how risks are managed across programs, Essentials keeps a current baseline and a monthly rhythm.
For your reviewers
The boundaries, in writing
What this is not
- Not Right Fit for Risk accreditation, ISO 27001 certification or any program approval. Those decisions belong to your assessor, certifier and the funding department.
- No endorsement by any government department is claimed.
- Not legal advice on your funding agreement or your obligations under it.
- The platform holds the work; the judgement on each control stays with your team.
When is your next assessment due?
Start on the Free Tier now, and have the Statement of Applicability current before the auditor asks.