RFFR — Right Fit For Risk

The information security accreditation required of providers delivering employment and workforce services funded by DEWR.

Department of Employment and Workplace Relations (DEWR).

What it is

Right Fit For Risk is the information security accreditation approach applied by the Department of Employment and Workplace Relations to organisations delivering DEWR-funded services. It exists because those providers handle substantial volumes of sensitive personal information about programme participants, and the Department needs assurance proportionate to that risk.

RFFR is not an ISO standard and not a certification scheme in the ISO sense. It is a contractual accreditation obligation: the requirements sit in your funding agreement, and the consequence of failing them is contractual rather than regulatory.

Its substance draws heavily on established frameworks. Providers are expected to operate an information security management system aligned to ISO/IEC 27001 concepts, and to implement the Essential Eight as the technical baseline. Requirements are scaled to the provider's size and the risk profile of the services delivered, so a small provider is not held to the same programme as a national one.

The scope that matters is the environment used to deliver the funded services and handle participant data — not necessarily the whole organisation. That distinction is the single biggest determinant of cost.

Who it's for

Employment services providers

Organisations delivering DEWR-funded employment, workforce and participant services. For these providers RFFR is a condition of funding.

Disability employment and related programme providers

Where DEWR funding and participant data handling bring the obligation with them.

Subcontractors and IT suppliers to those providers

Where obligations flow down through the head provider's agreement, which is increasingly common as providers push assurance requirements to their own supply chain.

What triggers the work

Almost always a funding agreement obligation with a date attached, or a re-accreditation cycle approaching.

Why implement it

  • It is a condition of funding. Non-compliance is a contractual matter with your DEWR funding at stake, which makes it more consequential than most voluntary frameworks.
  • It protects genuinely sensitive data. Participant information in this sector is among the more sensitive personal information held by any Australian provider, and the controls exist for good reason.
  • The work is reusable. Because RFFR leans on ISO 27001 concepts and the Essential Eight, the same system supports ISO certification later if commercial need arises.
  • Scope discipline saves money. Providers who scope to the funded-services environment rather than the whole organisation spend materially less, and the requirement does not ask for more.

How implementation works

Scope determination first, because it is the largest cost driver.

1. Establish scope and the accreditation pathway

Identify the environment used to deliver the funded services and handle participant data. This is rarely the whole organisation, and over-scoping is the most common way to make the programme more expensive than it needed to be.

2. Gap assessment

Against the requirements set out in your funding agreement, including current Essential Eight maturity.

3. Build the management system

Scoped ISMS drawing on ISO 27001 structure — risk assessment, Statement of Applicability, policy set, access control, incident response — tailored to the participant data environment.

4. Technical remediation

Essential Eight uplift and the controls that protect participant data specifically.

5. Assessment and attestation

Depending on your tier and pathway, this involves self-assessment, external assessment, or both, with attestation to DEWR.

6. Maintain

RFFR carries recurring obligations. Accreditation is a cycle, not a single event.

How Soveriq helps

Soveriq scopes the RFFR environment carefully, because over-scoping is where providers waste the most money on this framework. Where ISO 27001 is already held, we map it across rather than rebuilding; where it is not, we build the scoped management system directly rather than certifying an entire organisation you did not need to certify.

On internal review. Where Soveriq has built your management system, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.

What we will not do. Soveriq does not grant accreditation, does not speak for DEWR, and does not promise an assessment outcome.

What the engagement looks like

  • Module 01 — Gap analysis against the requirements in your funding agreement, including current Essential Eight maturity.
  • Module 02 — Build. ISMS scoped to the DEWR-related environment, plus the technical remediation.
  • Module 03 — Internal review ahead of assessment, subject to the impartiality position above.
  • Module 04 — Representation during assessment.
  • Module 05 — Continuous compliance, including annual re-attestation and sustained maturity.

Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day. Assessor fees, where an external assessor is required, are separate.

Common questions

Is RFFR the same as ISO 27001?

No, but the overlap is substantial. RFFR draws on ISO 27001 concepts and the Essential Eight, so an existing ISO 27001 management system does a large share of the work. It is not a substitute — RFFR has its own accreditation process and its own scope expectations.

Do we need to certify to ISO 27001 first?

No. RFFR does not require an ISO certificate. Where you already hold one it materially reduces effort; where you do not, the RFFR-scoped ISMS is built directly.

What scope applies?

The environment used to deliver the DEWR-funded services and handle the associated participant data — not necessarily your whole organisation. Getting this boundary right is the main cost lever, and over-scoping is common.

What happens if we do not comply?

RFFR obligations sit in the funding agreement, so non-compliance is a contractual matter with your funding at stake. That makes it more consequential than most voluntary frameworks.

Someone has asked you to prove it.

Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.

Book to Scope