The information security accreditation required of providers delivering employment and workforce services funded by DEWR.
Right Fit For Risk is the information security accreditation approach applied by the Department of Employment and Workplace Relations to organisations delivering DEWR-funded services. It exists because those providers handle substantial volumes of sensitive personal information about programme participants, and the Department needs assurance proportionate to that risk.
RFFR is not an ISO standard and not a certification scheme in the ISO sense. It is a contractual accreditation obligation: the requirements sit in your funding agreement, and the consequence of failing them is contractual rather than regulatory.
Its substance draws heavily on established frameworks. Providers are expected to operate an information security management system aligned to ISO/IEC 27001 concepts, and to implement the Essential Eight as the technical baseline. Requirements are scaled to the provider's size and the risk profile of the services delivered, so a small provider is not held to the same programme as a national one.
The scope that matters is the environment used to deliver the funded services and handle participant data — not necessarily the whole organisation. That distinction is the single biggest determinant of cost.
Organisations delivering DEWR-funded employment, workforce and participant services. For these providers RFFR is a condition of funding.
Where DEWR funding and participant data handling bring the obligation with them.
Where obligations flow down through the head provider's agreement, which is increasingly common as providers push assurance requirements to their own supply chain.
Almost always a funding agreement obligation with a date attached, or a re-accreditation cycle approaching.
Scope determination first, because it is the largest cost driver.
Identify the environment used to deliver the funded services and handle participant data. This is rarely the whole organisation, and over-scoping is the most common way to make the programme more expensive than it needed to be.
Against the requirements set out in your funding agreement, including current Essential Eight maturity.
Scoped ISMS drawing on ISO 27001 structure — risk assessment, Statement of Applicability, policy set, access control, incident response — tailored to the participant data environment.
Essential Eight uplift and the controls that protect participant data specifically.
Depending on your tier and pathway, this involves self-assessment, external assessment, or both, with attestation to DEWR.
RFFR carries recurring obligations. Accreditation is a cycle, not a single event.
Soveriq scopes the RFFR environment carefully, because over-scoping is where providers waste the most money on this framework. Where ISO 27001 is already held, we map it across rather than rebuilding; where it is not, we build the scoped management system directly rather than certifying an entire organisation you did not need to certify.
On internal review. Where Soveriq has built your management system, we do not then assess it and present that as independent assurance. We provide readiness validation, labelled as such, with genuine independence supplied by someone independent of the build and disclosed in writing.
What we will not do. Soveriq does not grant accreditation, does not speak for DEWR, and does not promise an assessment outcome.
Engagements in this area are scoped and priced in writing after a scoping call, usually within one business day. Assessor fees, where an external assessor is required, are separate.
No, but the overlap is substantial. RFFR draws on ISO 27001 concepts and the Essential Eight, so an existing ISO 27001 management system does a large share of the work. It is not a substitute — RFFR has its own accreditation process and its own scope expectations.
No. RFFR does not require an ISO certificate. Where you already hold one it materially reduces effort; where you do not, the RFFR-scoped ISMS is built directly.
The environment used to deliver the DEWR-funded services and handle the associated participant data — not necessarily your whole organisation. Getting this boundary right is the main cost lever, and over-scoping is common.
RFFR obligations sit in the funding agreement, so non-compliance is a contractual matter with your funding at stake. That makes it more consequential than most voluntary frameworks.
Tell us the standard, the deadline and where you are starting from. You get a written scope and a fixed price within one business day.
Book to Scope