Use Third Party IT

Many Employment and Skills Service Providers engage Third Party IT Vendors in the delivery of services to the department. The department accredits eligible Third-Party Employment and Skills (TPES) Systems to help Providers manage risks associated with third party systems.

On this page:

The department may accredit a TPES System where:

  • The Vendor’s solution stores, processes or manages information used by Employment or Skills Service Providers to deliver Australian Government programs.
  • The Vendor enters, or seeks to enter, into a Deed with the department for the provision of those services.

Background

Consistent with the RFFR approach, the department works with Vendors to accredit TPES Systems before those Vendors sign a Deed with the department.

The department signs Deeds with Vendors where it is reasonably expected that:

  • The TPES System stores program participant data or related records, and the Vendor manages the system and retains access, such as a database administrator role.
  • A Provider has a Deed with a government department that requires the Provider to use only TPES Systems accredited by the department.

Accredited TPES systems

Accreditation applies to the system

The department accredits TPES Systems, not Vendors. Accreditation does not represent a recommendation of one system over another. Providers remain responsible for due diligence and their own business and risk decisions.

TPES Systems are accredited for specific functionality, with authorisation boundaries based on the solution architecture at the time of assessment. Changes with security implications may require reassessment by the department.

Each accreditation letter explains the assessed scope and shared responsibilities. Select a report below to review the relevant accreditation details.

TPIT VendorsTPES systemsAccreditation StatusLetters
Verner Mackay GroupaXcelerateRFFR AccreditedaXcelerate Accreditation Letter
Leading DirectionsBuddyNoteRFFR AccreditedBuddyNote Accreditation Letter
ReadyTechEsherHouse CortexRFFR AccreditedEsherHouse Cortex Accreditation Letter
ReadyTechJob ReadyRFFR AccreditedJob Ready Accreditation Letter
ReadyTechReady ApprenticeRFFR AccreditedReady Apprentice Accreditation Letter
ReadyTechReady RecruitRFFR AccreditedReady Recruit Accreditation Letter

For Providers – Using an accredited TPES system

Any Provider choosing to use a system or cloud service supplied by a third party is responsible for ensuring the system or service is secure before using it to process, store or communicate data relating to government programs.

RFFR accreditation signifies that a TPES System has met the department’s requirements for protecting information within the assessed scope. It does not guarantee that the system is fit for a Provider’s intended use or business processes. It also does not assess legal, financial or insurance risks associated with use of the system.

Before using a TPES system

  • Complete a risk assessment that considers the relevant TPES System accreditation letter.
  • Understand the scope and authorisation boundaries of the TPES System accreditation.
  • Implement the controls and system configuration requirements identified as customer responsibilities.
  • Identify risks associated with any unaccredited functionality and implement appropriate treatments.

For Vendors – Seeking RFFR Accreditation for a TPES system

TPES Systems that handle information or data relating to programs delivered by the department must obtain and maintain accreditation before use by Providers.

Vendors unsure whether a system requires accreditation should email SecurityComplianceSupport@dewr.gov.au and provide:

Information to include

  • An outline of the system and services offered.
  • How the system will help Providers deliver programs and the proposed functionality.
  • A high level overview of system design and access, including architecture, data centre locations, authentication and administrative staff locations.
  • How the system interoperates with department systems, such as bulk data transfers or real time APIs.
  • The scope of existing IT security certifications or accreditations.
  • The Providers considering use of the system.

Vendors seeking RFFR Accreditation should review the material on the RFFR website. The Third Party IT Vendor Deed Guidelines form part of the Deed and explain the Vendor’s continuing obligations.

Download the Third-Party IT Vendor Deed Guidelines