Certification & privacy law
A customer asked for your SOC 2 report. Now what?
Separate from the AI work, and usually driven by someone else's deadline — a tender, an enterprise customer, a regulator. We assess where you stand, do the work to close the gaps, and manage the auditor.
10 December 2026. New Australian Privacy Principle 1.7 commences. If a computer program uses personal information to make — or substantially help make — a decision that significantly affects someone, your privacy policy has to say so. It is a disclosure duty, not a ban. Most companies will find they are in scope and have nothing written.
What this meansThe deadline nobody has budgeted for
You do not need AI to be caught by APP 1.7.
The rule says “computer program”, not AI. A system that declines an application, ranks job applicants, decides who gets a payment plan, flags a transaction as fraud, or sets a roster that affects pay — if personal information goes in and a decision that significantly affects someone comes out, you have to disclose it. It also covers decisions your suppliers make for you, which is where most companies get caught short.
- Find every system in scope, including bought onesYour own software, your SaaS platforms, and anything a supplier runs for you. Procurement contracts rarely say. Someone has to ask.
- Decide what counts, and write down whyThe judgement calls sit around “substantially and directly related” and “significantly affect”. Getting them right matters less than having a documented reason for each.
- Draft the privacy policy wordingThe kinds of personal information used, the kinds of decisions made by the program alone, and the kinds it substantially helps make. In plain English, because that is the point of the rule.
- Leave a register behindA forward-looking duty, not a one-off. Every new tool changes the answer, so it needs somewhere to live and someone who updates it.
We are not lawyers and this is not legal advice. We do the inventory, the technical scoping and the draft; your counsel signs it off. Where you don't have counsel, we'll introduce a privacy lawyer and tell you who they are before they start.
Standards we work to
The same controls carry most of the way into the next standard.
Most companies end up needing more than one. Assessed together, the overlap does the work.
SOC 2 Type 1 & Type 2
What North American and enterprise buyers ask for by name. Scoping, control design, and evidence that survives the observation window.
ISO/IEC 27001:2022
What international and European customers recognise. Full build: scope, risk method, Statement of Applicability, internal audit and management review.
ISO/IEC 42001
The first certifiable AI management standard, adopted here as AS ISO/IEC 42001. Turns “we're careful with AI” into something a board can be shown. Certifications are still rare and auditors scarce, which is why being early is worth something in a tender.
Essential Eight
Still what insurers, tenders and assessors measure against. We assess against the current maturity model and build uplift that carries forward rather than becoming work you redo.
APRA CPS 234 & CPS 230
If you supply banks, insurers or super funds, these reach you through your contracts. Information security capability, incident notification, and operational risk for material service providers.
Privacy Act & NZ Privacy Act 2020
APP 1.7 disclosure, the Notifiable Data Breaches scheme, and the statutory tort of serious invasion of privacy live since June 2025. Plus NIST AI RMF and the EU AI Act if you sell into Europe.
How the work runs
Assess, fix, certify, sustain. Take one phase or all four.
Assess
Control-by-control gap assessment, prioritised roadmap, policy gap list, evidence guide, and a costed path to certification.
3–4 weeks · fixed fee
Remediate
Policies written to how you actually work, controls implemented, tooling configured, evidence trail started. Hands on the console.
Fixed-price sprint, quoted from the assessment
Certify
Auditor selection and briefing, evidence assembly, managing the request list through fieldwork, translating findings before they become surprises.
Through the audit cycle · monthly retainer
Sustain
Certification is annual. Access reviews, register upkeep, internal audit and surveillance prep, so year two isn't another scramble.
From AUD 900/month
Set expectations early
SOC 2 Type 2 takes about a year. Most people are told six weeks.
- Weeks 1–4 · Readiness assessmentWhere you find out what you are actually working with.
- Months 2–5 · RemediationPolicies written, controls implemented, and — the part teams underestimate — controls operated long enough to leave a trail.
- Month 5 · Auditor selection and Type 1A point-in-time report you can put in front of a customer while the clock runs on Type 2.
- Months 5–11 · Observation windowThree to six months in which your controls must demonstrably operate. It cannot be shortened, bought or backdated. The step nobody mentions.
- Months 11–12 · Fieldwork and reportThe auditor tests your evidence and issues the report your customer asked for.
If a deal depends on a date, you need this map before you promise one — usually the difference between a Type 1 that holds the customer and a commitment you can't meet.
The option most teams try first
Doing it in-house doesn't save money. It moves the cost onto your engineers.
Engineering time
A first certification absorbs a third to a half of a senior engineer for four to six months, plus a manager. That's a feature you didn't ship, at your most expensive internal rate.
Learning on the clock
The first attempt is also the training run. Scoping errors surface during fieldwork, which is the most expensive possible moment to find them.
Key-person risk
The knowledge ends up in one person's head. When they take leave — or another job — the evidence trail and the auditor relationship go with them.
It comes back every year
ISO 27001 brings annual surveillance audits and recertification every three years; SOC 2 needs a fresh report each year. Access reviews and register upkeep run indefinitely.
Before you ask
Common questions.
We already bought a compliance platform. Do we still need you?
Vanta, Drata and Sprinto watch controls you've already built. They don't decide what those controls should be, write policies that match your business, or configure the systems so the checks go green for real reasons. Most teams who stall sit at 60% with no idea which of the remaining 40% is an afternoon and which is three months. That gap is the job.
Can you work with the auditor we've already chosen?
Yes — the normal arrangement. We're not auditors and don't issue reports, so there's no independence question. We sit on your side and manage the relationship, the request list and the findings. If you haven't picked one, we'll shortlist firms that suit your size rather than price for enterprise.
Can you do an IRAP assessment?
No. IRAP assessments must be performed by an ASD-endorsed assessor and we don't hold that endorsement — anyone telling you otherwise is worth a second look. We can get you ready for one and help you close what the assessor finds.
What does the whole thing cost, end to end?
For 20 to 100 people on a modern cloud stack, budget AUD 50,000 to 90,000 across a first SOC 2 Type 2 or ISO 27001 cycle — including auditor fees and tooling, not just ours. The APP 1.7 work is far smaller at AUD 2,500. You get a specific number before you commit.