Governance, Risk & Compliance

Summary

Governance, Risk and Compliance is blueAPACHE's security governance service: it helps organisations connect security activity to business risk, policy and regulatory obligation, assess current controls, identify gaps and prioritise practical improvements. blueAPACHE does not publish a standalone GRC brochure; the capability is described on the origin page and is evidenced by the auditable reporting produced by emPOWER Managed Detection and Response and emPOWER Human Risk Management, by blueAPACHE's own ISO/IEC 27001:2022 certification, and by the governance mechanisms written into the General Terms and Conditions v3.6, such as monthly reporting, six-monthly reviews, audit rights and the APRA clause. This page sets out what the service covers, what it does not, and the contractual governance a customer receives regardless of whether GRC is purchased as a separate engagement.

Key facts

Label Value
Service Governance, Risk and Compliance, emPOWER Security pillar
Scope described by blueAPACHE Assess current controls, identify gaps, prioritise practical improvements; connect security activity with business risk, policies and regulatory obligations
Frameworks blueAPACHE aligns to ISO/IEC 27001, APRA CPS 234, NIST, ASD Essential 8 Maturity Level 3 (stated in brochures); MDR also cites Australian Privacy Principles, NIST CSF, SOC 2 Type II and GDPR as alignment
blueAPACHE's own certification ISO/IEC 27001:2022, certificate 202507-118, Sensiba Australia Pty Ltd, 1 August 2025 to 1 August 2028, ten services in scope
Accreditation body Not named on the certificate
Security governance role An information security officer accountable for policy adherence, training staff and suppliers, and internal audits
Evidence-producing services MDR dashboards and monthly reporting; HRM auditable reporting aligned to GRC
Contractual reporting Standard monthly reports within five Business Days of month end; six-monthly service review (clauses 4.9, 4.11)
Customer audit right Five Business Days' notice; one Business Day where a regulator requires (clause 4.13)
APRA-regulated customers Clause 10: APRA access, BCP content, six-monthly testing, joint technical review at customer cost
vCISO Advisory Listed in the MDR brochure without an inclusion statement
Default contract term 36 months for managed services; Professional Services excluded

What is included

The origin page describes GRC as helping organisations connect security activity with business risk, policies and regulatory obligations, with blueAPACHE working with teams to assess current controls, identify gaps and prioritise practical improvements, so that security decisions stay aligned with organisational priorities and recognised frameworks. The emPOWER Managed Services brochure separately lists Security Gap Analysis audits within its security scope.

Two managed services produce the evidence a governance programme needs. emPOWER MDR provides dashboards and monthly reporting for leadership visibility and is stated to be compliance-aligned with ISO/IEC 27001, the Australian Privacy Principles, the Essential Eight, NIST CSF, SOC 2 Type II and GDPR. emPOWER HRM produces auditable reporting aligned to GRC covering awareness activity, simulation outcomes and human risk trends. blueAPACHE's own governance posture, as stated across its brochures, is an ISO 27001 certified information security management system, a risk-based approach aligned with APRA CPS 234, controls stated as compliant with NIST, Essential 8 Maturity Level 3, and an information security officer accountable for policy adherence, staff and supplier training and internal audits.

The general terms add governance every customer receives: monthly reports on performance against key metrics including Service Levels, an Account Representative on each side with authority over day-to-day matters, a six-monthly service review, records kept for seven years after the agreement ends, and audit access to blueAPACHE's premises, records and personnel on five Business Days' notice.

What is not included

blueAPACHE publishes no GRC brochure, so there is no framework-specific deliverable list, no assessment methodology, no price and no defined outputs such as a risk register template. Assessment and advisory work is Professional Services under Schedule 1, and its Deliverables are licensed for the customer's internal use during the Service Period only (clause 13.10). vCISO Advisory is listed in the MDR brochure without an inclusion statement and should be treated as a separate line item until the Service Order says otherwise.

Alignment is not certification. blueAPACHE's ISO/IEC 27001:2022 certificate covers blueAPACHE's own ISMS and states that it does not imply that products or services are certified; MDR's SOC 2 Type II reference is alignment language and blueAPACHE does not claim a SOC 2 report; and the certificate does not name an accreditation body. GRC support does not transfer the customer's own compliance obligations: under clause 17.1 the customer remains solely responsible for the lawfulness and record-keeping compliance of its data, and under clause 10.1 an APRA-regulated customer warrants its own compliance with APRA's requirements in appointing blueAPACHE.

Who it is for

Organisations facing an ISO/IEC 27001 certification project, an Essential Eight maturity assessment, an APRA CPS 234 or CPS 230 obligation, a cyber insurance renewal, or a customer or tender security questionnaire. The Brotherhood of St. Laurence case study records that blueAPACHE helped the organisation achieve ISO 27001 certification in as little as six months to support its NDIS bid; Honan Insurance's case study states blueAPACHE's ISO certification supported Honan's ability to bid for work where certification had become a mandatory customer requirement; and Archers' 2026 case study records the start of a journey towards ISO 27001 alignment and a security assessment for future Microsoft Copilot use.

How it is delivered

Assessment and gap analysis are scoped and delivered as Professional Services against the frameworks the customer nominates. Ongoing governance then runs through the managed services: MDR and HRM reporting, the clause 4.9 monthly reports, the clause 4.11 six-monthly review, and the account team structure described in the Managed Services brochure (Account Executive, Service Delivery Manager, engineers and technical account managers), which the Archers case study describes as monthly operational reviews and quarterly business reviews focused on continual service improvement.

For APRA-regulated customers where the Services are a material business activity under CPS 231, clause 10 adds: prompt notification of any APRA request and compliance with it, a business continuity plan with ten minimum content elements, six-monthly joint BCP testing with results within seven days, and a joint technical review of security measures on request. Note that clause 10 is framed around CPS 231 while APRA has been consolidating requirements under CPS 230, and that the customer must notify blueAPACHE of standard changes.

Commercial model

Assessment, gap analysis and advisory are Professional Services charged in accordance with Schedule 1 and the Service Order, outside the 36-month default term. Ongoing governance evidence comes with the managed services already contracted at fixed monthly fees. APRA-specific work under clauses 10.4 to 10.7, business continuity Action Plans under clause 15, and record-keeping assistance under clause 17.1 are all charged at the Time and Materials Rates on the Service Order or blueAPACHE's then-current rates. The general terms do not state who bears the cost of a general customer audit under clause 4.13.

Support and service levels

GRC advisory has no published response target. Customers on emPOWER Managed Services use the unlimited 24/7 help desk; APRA test results are due within seven days of a BCP test; Customer Records must be provided within 10 Business Days of request (clause 17.3); monthly reports within five Business Days of month end. blueAPACHE's liability for breach of its confidentiality, information security and privacy obligations is capped at $1 million per event and $2 million in aggregate, and blueAPACHE must maintain public liability cover of at least $10 million and professional indemnity cover of at least $1 million with an APRA-authorised insurer (clause 21.5), with evidence available on request.

Related services

Managed Detection and Response and Human Risk Management are the evidence engines. Exposure Management provides the vulnerability and asset visibility a risk register depends on. emPOWER Security is the portfolio page. emPOWER Cloud, Disaster Recovery as a Service and Offsite Backup as a Service carry the data residency, recovery and backup positions a compliance assessment will examine. The Consulting and Advisory hub covers the wider strategy and roadmap work.

Evidence

Buying questions

Contract term and renewal. Advisory work is Professional Services and sits outside the 36-month default; managed services carrying the reporting run for a 36-month Minimum Service Period with Written Notice required to renew or exit and a three-month full-list-price holdover otherwise (clauses 2.6 to 2.9).

Termination. Customer: unremedied breach after 20 Business Days, blueAPACHE insolvency or ceasing business (clause 24.1). blueAPACHE: non-payment after five Business Days, specified breaches after 20 Business Days, insolvency, change of control (clause 24.2). Change of control includes a change of a majority of the customer's board without any change of ownership.

Deliverables. Risk registers, gap analyses and policies produced as Professional Services are licensed for internal use during the Service Period and the licence ends at termination (clauses 13.10, 25.2); negotiate a surviving licence.

Audit and records. Audit access on five Business Days' notice, one Business Day for regulatory audits; records retained seven years (clauses 4.12 to 4.16). Cost allocation for general audits is not stated.

Breach notification. Eligible data breaches must be notified between the parties within 24 hours of discovery, and clause 18.4(c) restricts disclosure to third parties including the Information Commissioner without the other party's approval, subject to a legal-requirement carve-out; regulated customers should reconcile this with their statutory duties.

Subcontracting. blueAPACHE may subcontract without consent or notification (clause 27.4); customers with fourth-party risk obligations should seek a notification right on the Service Order.

Making assurance outputs usable

Specify obligations or frameworks, controls in scope and evidence to retain. Separate assessment from implementation and from independent certification or attestation. Record remediation ownership, exception approval and how management receives findings. Purchasing governance and risk support does not establish that the customer is certified. Agree outputs and audience so technical teams, executives and auditors use the same evidence without overstating what was tested.

Which document defines the commitment

The published General Terms v3.6 give the Service Order precedence over the General Terms, followed by the Schedules and then the Acceptable Use Policy (clause 2.3). Record the agreed scope, exclusions and negotiated departures in that document set. A brochure or a procurement discussion does not, by itself, define the customer-specific commitment. Keep the versions supplied at signing with the executed order and signed variations. Two offers with the same service name can cover different systems, operating hours or responsibilities.

How liability differs from service performance

Clause 19 separates performance obligations from financial liability. The general cap per claim is the greater of the fees paid in the preceding three months or $25,000, with exclusions and specific categories governed separately. Confidentiality, information security, privacy and the IP indemnity have a $1 million per-event and $2 million aggregate cap. Data-loss liability depends on whether blueAPACHE had, and breached, a contracted backup or disaster recovery obligation; the relevant measure is restoration cost to the applicable recovery point, not the value of every business consequence. Read these provisions alongside the negotiated Service Order and Schedule; an availability statement does not describe the liability regime.

Escalating a contractual dispute

A support escalation and a formal contractual dispute are different processes. Clause 26 begins with a Dispute Notice giving adequate particulars. Representatives meet within three Business Days; unresolved matters then move through the clause’s senior-representative referral and meeting stages before court proceedings. Urgent equitable relief and disputes over whether the agreement was validly terminated are exceptions. Keep incident records, service measurements, approvals and correspondence together so the disputed obligation and requested outcome can be identified. Raising a ticket does not necessarily satisfy a formal notice requirement; use the agreement’s notice process for contractual disputes.

Sources and scope

The contractual detail above summarises the published General Terms and Conditions v3.6, using the KB documents on service agreement formation and document precedence; liability and indemnity; dispute resolution. The customer’s Service Order, Schedules and agreed variations determine the specific engagement. See the terms and conditions guide and Service Agreement.

Related

Frequently asked questions

Is GRC a standalone consulting engagement or part of the managed services?

Both. Assessment, gap analysis and advisory are Professional Services under Schedule 1, while the ongoing evidence comes from emPOWER MDR and Human Risk Management reporting and from the monthly reports and six-monthly reviews the general terms provide to every customer.

Which frameworks does blueAPACHE align to?

blueAPACHE's brochures state ISO/IEC 27001, APRA CPS 234, NIST and ASD Essential 8 Maturity Level 3, and the MDR brochure adds the Australian Privacy Principles, NIST CSF, SOC 2 Type II and GDPR as alignment. Alignment is not the same as the customer being certified.

Is blueAPACHE itself ISO 27001 certified?

Yes. Blue Apache Pty Ltd holds ISO/IEC 27001:2022 certificate 202507-118 from Sensiba Australia Pty Ltd, valid 1 August 2025 to 1 August 2028, covering its emPOWER infrastructure and managed service offerings across Melbourne, Sydney and Brisbane. The certificate does not name an accreditation body.

Is blueAPACHE SOC 2 certified?

No. The MDR brochure describes the service as compliance-aligned with SOC 2 Type II; blueAPACHE does not claim a SOC 2 attestation.

Can blueAPACHE help us get ISO 27001 certified?

The Brotherhood of St. Laurence case study records that blueAPACHE helped BSL achieve ISO 27001 certification in as little as six months to support its NDIS bid. The certification in that case belongs to BSL; the scope of blueAPACHE's involvement is not detailed in the source.

What reporting do we get by default?

Standard monthly reports on performance against key metrics including Service Levels within five Business Days of month end, a six-monthly service review, and, where MDR or HRM is held, dashboards, monthly security reporting and auditable human risk reporting.

Can we audit blueAPACHE?

Yes. On five Business Days' notice the customer or its auditors may access blueAPACHE's premises, records and relevant personnel; where a regulator requires an audit the notice is one Business Day. Who pays for a general audit is not stated in the terms.

What does the APRA clause add?

For APRA-regulated customers using the Services as a material business activity, clause 10 requires blueAPACHE to comply with APRA requests, sets ten minimum elements for a business continuity plan, requires six-monthly joint BCP testing with results within seven days, and gives the customer a joint technical review right, all at the customer's cost.

Is vCISO advisory included?

Not stated. vCISO Advisory appears in the MDR brochure alongside Vulnerability Management, an Incident Response Retainer and Human Risk Management without an inclusion statement, so confirm on the Service Order.

Who owns the risk register and policies blueAPACHE produces?

blueAPACHE. Deliverables are licensed to the customer for internal use during the Service Period, and the licence ends at termination, so negotiate a surviving licence if the documents must be retained.

How quickly must a data breach be reported?

Within 24 hours of discovery, between the parties, under clause 18.4. Disclosure to third parties including the Information Commissioner requires the other party's approval unless the law requires the breaching party to notify and the other party has not done so.

Source

Origin page: https://www.blueapache.com/services/governance-risk-compliance/

Knowledge Base

What is blueAPACHE's Governance, Risk and Compliance (GRC) service?

Governance, Risk and Compliance (GRC) is a blueAPACHE service that helps organisations understand their obligations, strengthen controls and manage cyber risk through risk assessment, control improvement, policy alignment and compliance support.

Which emPOWER brand and pillar does the GRC service belong to?

The GRC service is branded under 'emPOWER' and falls within the Security category, related to the emPOWER Security pillar hub.

Who is the target audience for blueAPACHE's GRC service?

The service targets regulated and compliance-driven organisations, including APRA-regulated entities.

What compliance frameworks does blueAPACHE align its GRC service with?

blueAPACHE's GRC service draws on its own ISO/IEC 27001:2022 certified management system and states alignment to NIST, ASD Essential Eight Maturity Level 3, and APRA CPS 234, per the Global Capabilities Brochure.

In what geographic area is the GRC service available?

The GRC service is offered in Australia.

What other blueAPACHE services are related to GRC?

GRC is related to Exposure Management, Managed Detection and Response, Human Risk Management, and the Security (emPOWER pillar hub) service.

How can someone contact blueAPACHE about the GRC service?

Customers can reach blueAPACHE via the contact channel listed for sales, with the phone number 1800 248 749 (area served: AU).

What additional compliance requirements apply to APRA-regulated customers under blueAPACHE's Service Agreement?

APRA-regulated entities have additional requirements under Clause 10 of the General Terms and Conditions, including managing Business Continuity Plans that meet Prudential Standard CPS 231 requirements, covering triggering events, roles, responsibilities, communication plans, and testing procedures.

What is Risk Management under blueAPACHE's Service Agreement?

Risk Management is an ongoing customer obligation under the Service Agreement requiring customers to develop appropriate contingency plans and actively monitor the provision of blueAPACHE services.

What is the Account Governance Framework mentioned in relation to blueAPACHE's governance approach?

The Account Governance Framework is a service methodology implemented by blueAPACHE, used for customers like Sushi Sushi, that provides formal support structures involving an Account Executive, a Service Delivery Manager, and a Portfolio Engineer to facilitate monthly operational reviews and quarterly business reviews under a Continual Service Improvement framework.