Compliance help, by industry.
Compliance pressure on a firm your size rarely comes from one regulator. The obligations overlap, and your IT environment is where they either hold or quietly fail. Pick your industry for what that means in practice.
Industries · by sector
Each sector, and the rules that hit it.
Each page covers one industry: what compliance asks of a firm of 20 to 250 staff, and which dated regulations we are tracking for it. A law firm and an aged care provider have almost nothing in common here. Start with yours.
Law firms
- AUSTRAC Tranche 2 AML/CTF · in force since 1 July 2026
Finance, advisers, accountants
- AUSTRAC Tranche 2 AML/CTF · in force since 1 July 2026
Construction and engineering
We are not tracking a dated regulation for construction and engineering right now. Compliance here is ongoing work inside a managed IT engagement.
Open the construction and engineering pageMining services and technology
We are not tracking a dated regulation for mining services and technology right now. Compliance here is ongoing work inside a managed IT engagement.
Open the mining services and technology pageRTOs and training organisations
- 2025 Standards for RTOs · in force since 1 July 2025
Health and aged care
- Aged Care Act 2024 · in force since 1 November 2025
Not-for-profits
We are not tracking a dated regulation for not-for-profits right now. Compliance here is ongoing work inside a managed IT engagement.
Open the not-for-profits pageThe baseline · every sector
Compliance work that is the same in every sector.
You get the same core work whatever your sector. Identity that holds, retention that survives a vendor switch, and audit logging that produces evidence on demand. Backup that has been restored from at least once. Every control is documented against the obligation it satisfies, so the evidence is there before anyone asks.
Some sectors need more than that. AUSTRAC's anti-money-laundering programme covers legal and finance firms. Aged care has the Aged Care Act's information management standard. Registered training organisations are audited against the 2025 Standards. Where one of those applies to you, the extra work goes on top.
Plenty of it is cross-cutting, though. Privacy Act breach notification, cyber-insurance questionnaires, and the security questionnaires your own clients send you all draw on the same control environment. One set of evidence covers most of what all three ask for, without a separate build for each.
We do not interpret regulations and we do not write your compliance documentation. That call belongs to your compliance officer, your lawyer, or your sector consultant. We own the IT environment that has to back the call up when somebody asks for evidence.
Next step · start with the evidence
Score yourself against the Essential Eight.
The self-assessment takes about ten minutes. It scores you against the eight security controls the Australian Cyber Security Centre recommends. You get a PDF report the same day, ready for your compliance officer, your insurer or your board. It is not sector-specific, but those controls support almost every compliance obligation we see.