← All work

An Australian financial services licensee · 2026

Compliance manual and coverage map

The obvious fix is to write a second manual covering technology. That is the wrong move, and it creates a worse problem than the thin section it replaces.

01

What you have

Conduct
IT, cyber, privacy

Conduct obligations covered properly. The technology layer is a paragraph.

02

The obvious fix

Manual
Second manual

contradiction

A second manual. Written separately, it contradicts the first inside a year.

03

What I do

Conduct
13 policies

A companion, reconciled through a coverage map. Nothing duplicated, nothing uncovered.

Two documents written separately will disagree within a year, and an auditor finding an inconsistency in your control framework is a worse conversation than a thin section was. The coverage map is what stops that.

How to tell whether you have this

Read what your compliance manual says about IT, cyber and privacy. Then ask who implemented it, and where the record of that is.

In most licensed firms that section was written to satisfy an obligation and has never been tested against the estate. The manual is not wrong. It was simply never written to be checked.

Why it happens

Your manual was written by people whose expertise is licensing obligation rather than infrastructure, and it reflects that honestly. The conduct sections are usually detailed and correct. The technology paragraph is a paragraph.

The trap in fixing it

The obvious move is to commission a second manual covering the technology layer. That is the wrong move.

Two documents written by different people at different times will disagree within a year. When they disagree, an auditor has found an inconsistency in your control framework, which is a considerably more awkward conversation than a thin section was. Whichever document is more convenient then gets quoted, and at that point the framework has stopped meaning anything.

How I would approach it

  1. Write a companion rather than a replacement, deliberately not duplicating the conduct sections that already work.
  2. Reconcile the two through a coverage map, so any obligation traces to whichever document carries it and nothing is covered twice or not at all.
  3. Build the register on your own model. If you already use a 5x5 likelihood and consequence scale with control ratings, the register should use it too, so it reads as a continuation of your framework rather than an import from somewhere else.
  4. Wire the standard into the delivery workflow, so architecture and configuration decisions stay traceable to what they cite instead of being reconciled annually.

What you end up with

One framework rather than two competing ones, a technology layer covered at the same depth as the conduct layer, and a register your own people already know how to read.

Framing throughout is alignment with ISO 27001 and 27701 and the ASD Essential Eight. That distinction matters to anyone who knows the standards, and the engagement operated under a constraint that forbids asserting compliance.

What it looked like in practice

delivered

Figures from the engagement described above, not a projection of what your estate would produce. Yours will look different.

RefFoundNowWhat the figure refers to
0113policies added across the IT, cyber and privacy layer
0218sheets in the risk and control register

Is this yours?

If any of the above sounds like your estate, say so and I will tell you what checking would involve. Most of these start as a short look rather than a project.

Not sure it is this one? The rest of the work covers monitoring, identity, deployment, cost, AI use and compliance documentation.

Related work

All work