Frequently Asked Questions

On this page:

RFFR Changes

Why are changes being introduced?

The Department of Employment and Workplace Relations (the department) is updating the External Systems Assurance Framework (ESAF) and the Right Fit for Risk (RFFR) accreditation requirements. These changes will make sure the accreditation requirements align with government security policies and that the department’s approach follows whole-of-government security guidance, as well as relevant laws and regulations.

What are the changes?

A summary of changes can be found on the Updated ESAF and Transitions page.

When will these changes be implemented?

The updates to the ESAF will take effect from 1 October 2026.

The department will work with each Provider to transition to the revised requirements over the coming 12 months.

What won't change?

Your accreditation (including current accreditation status and timeframes) remains valid.

Providers are still expected to:

  • Protect participant and departmental information.
  • Meet Deed obligations.
  • Report privacy and cyber incidents.
  • Manage risks associated with subcontractors and third parties.
  • Maintain appropriate security controls.

What is the PSP and PSP-Annex?

The Provider Security Plan (PSP) replaces the Scope document.

The PSP-Annex (PSP-A) replaces the Statement of Applicability (SoA).

These documents have been refined and updated to reflect how your organisation manages information security risks and protects data.

Are there Control Changes?

Yes. RFFR Core controls (Core Expectations) within your current Statement of Applicability (SoA) have been updated and are included within the PSP-A. These are applicable to all Providers.

How is my categorisation determined?

Each assurance category is based on a Provider’s exposure to security risks, the data they hold and their organisational profile. This approach is in line with contemporary security risk considerations, particularly in the context of supply chain risk exposure.

My RFFR submission is due within the next 9 months. What documentation should I complete?

You may continue to use the existing documentation for your submission.

If you have not started your submission yet you can use the new PSP-A.

Will the department be updating the PSP-A following Information Security Manual (ISM) quarterly updates?

The department will complete an analysis of the ISM updates each quarter and determine whether any changes need to be made to the PSP-A. Any changes will be published on the department’s website.

General RFFR FAQ

Can I discuss my upcoming RFFR submission with an assessor?

Yes. An RFFR Cyber Security Assessor is happy to engage with a Provider or their representative on their upcoming submission. The Assessors will provide guidance through the RFFR Accreditation process and help provide relevant resources.

What changes in circumstances should I advise the department about that might affect my RFFR accreditation?

If the change alters the risk profile of your organisation, the department will reassess the accreditation status. This includes, but is not limited to, when your organisation:

  • enters or terminates a Deed/Agreement with the department
  • changes its legal or organisational arrangements, including to its:
    • legal entity details (such as changes to its legal entity or business name(s)),
    • organisational or corporate structure (including subsidiaries or group member organisations), or
    • key Personnel or governance roles (such as Chief Executive Officer, Chief Information Security Officer or equivalent positions).
  • changes how it handles information, or the volume or sensitivity of information it handles,
  • changes its subcontracting arrangements (from one Subcontractor to another, or introduces a new Subcontractor),
  • changes its IT systems, infrastructure or online services,
  • changes its Third-Party IT Vendors who are supporting its IT environments, and/or
  • implements the use of AI technology in the delivery of Services.

You must notify the department within 5 business days of a change in circumstance by completing a Change of Circumstances Form.

How can I find out more information about my individual circumstances?

Please reach out to SecurityComplianceSupport@dewr.gov.au and an RFFR team member will can assist with your enquiry and provide information relating to your individual circumstances.

Artificial Intelligence (AI)

Can I use Artificial Intelligence (AI)?

We recognise the potential of AI capabilities to enhance service delivery and support better outcomes for individuals and communities. The department is taking a proactive yet cautious approach to ensure AI is used safely, securely, and ethically. To ensure safe and responsible use of AI, the department has developed a suite of resources and processes for third-party organisations seeking to use AI in the delivery of contracted services.

AI use must be explicitly approved under the Third-Party AI Assessment Framework. Following approval, it will be embedded within the Right Fit for Risk (RFFR) accreditation and maintenance lifecycle.

Before using AI, your organisation must:

  • Review the Third-Party AI Assessment Framework for eligibility, obligations, and the application process.
  • If suitable, submit a formal application using the Third-Party AI Assessment Application Form.
  • Ensure any AI used for other business purposes is isolated and inaccessible from the department’s service delivery systems and data. If isolation cannot be guaranteed, AI must not be used until approved by the department.

For further information, please visit Artificial Intelligence at DEWR.