With ESAF Now Confirmed, It’s Time To Prepare For Your Category
Earlier this month, we shared our thoughts on the upcoming changes to the External Systems Assurance Framework (ESAF) and what they could mean for funded employment, skills and disability providers. Since then, the Department of Employment and Workplace Relations (DEWR) has formally released the updated framework and confirmed it will take effect from 1 October 2026. ESAF is the framework sitting behind Right Fit For Risk (RFFR) accreditation, which is tied to your funding contract. DEWR has also advised that providers will be contacted regarding their assurance category and any steps needed to support the transition.
The updated ESAF introduces a number of important changes, including revised assurance categories, updated control expectations and changes to accreditation documentation. Those changes are important, and many providers will spend the coming weeks working through what they mean for their organisation.
At Diamond IT, however, we often find that successful outcomes are influenced just as much by organisational readiness as they are by understanding the technical requirements themselves.
As providers prepare for conversations with DEWR regarding their assurance category and transition requirements, now is a good opportunity to step back and consider how your organisation is positioned to respond.
The organisations that succeed rarely have all the answers
When significant changes are announced, it is natural to want immediate answers.
- What category will we be assigned?
- What documentation will we need?
- What does this mean for our next accreditation cycle?
They are all reasonable questions. However, the organisations that successfully navigate periods of change are rarely the ones with every answer on day one. More often, they are the organisations that understand their current position, know who is responsible for key activities and can respond confidently as new information becomes available.
With DEWR expected to engage providers regarding assurance categories and transition arrangements over the coming weeks, there is an opportunity to focus on the foundations that support long-term success.
“Frameworks change. Requirements change. Technology changes. The organisations that consistently succeed are the ones with strong foundations, clear accountability and a practical approach to managing change.” – Gavin Hall, Business Technology Consulting Team Lead, Diamond IT
Compliance is rarely the real challenge
In our experience, organisations rarely struggle because they are unaware of a requirement.
More often, challenges arise because responsibility is unclear, documentation has evolved over time, suppliers have changed, or important knowledge sits with only one or two people.
Technology is certainly part of the picture, but the most successful organisations are usually those with strong governance, clear ownership and an understanding of how people, processes and technology work together.
That is why many compliance activities become less about frameworks and more about organisational maturity.
Five questions worth asking right now
Rather than focusing solely on the framework itself, we suggest five questions every provider should be asking.
1. Who owns RFFR within your organisation?
RFFR is the accreditation ESAF sits behind, and it is tied to your funding contract rather than your IT policy. Many providers assume accreditation sits with IT. In reality, successful accreditation often relies on contributions from leadership, operations, governance, quality, risk, compliance and technology teams.
Having someone clearly accountable helps reduce confusion and ensures decisions can be made efficiently when requirements, timelines and responsibilities become clearer.
2. If a key person left tomorrow, would you know where everything is?
This question can reveal more than most organisations expect. Could you quickly locate:
- Policies and procedures
- Risk registers
- Previous accreditation artefacts
- Technology documentation
- Supplier information
- Evidence supporting current controls
Understanding where critical information lives can significantly reduce pressure when requests, audits or deadlines arise.
3. What has changed since your last accreditation?
Many organisations have undergone significant change in recent years. Perhaps you have:
- Adopted new cloud services
- Engaged a new managed service provider
- Implemented new business systems
- Expanded services
- Introduced AI-enabled tools
- Changed key suppliers
Now is a good opportunity to make sure your documentation, responsibilities and understanding of your environment remain aligned to the way your organisation operates today.
4. Are your suppliers ready for the conversation?
Most providers rely on external partners in some way. Whether that is a managed services provider (MSP), software vendor, cloud provider or specialist consultant, those relationships form part of your operating environment.
Ensuring you understand who is responsible for what, and what information or assurances may be needed from suppliers, can make future conversations much easier.
5. Are technology, governance and risk working together?
One of the challenges with compliance and accreditation activities is that they rarely sit neatly within a single team. Technology plays an important role, but so do governance, risk management, documentation, leadership and operational practices.
The strongest outcomes often occur when organisations bring these perspectives together rather than treating accreditation as solely an IT exercise or solely a compliance exercise.
This is where many organisations benefit from an advisory approach that connects business objectives, governance requirements and technology outcomes.
We recommend you use this time wisely
One thing we do know is that more information will continue to become available. DEWR has advised that providers will receive information regarding their assurance category and transition requirements.
For some organisations, that may feel like a waiting period. We would encourage a different perspective. Think of it as a preparation period.
Now is an excellent opportunity to:
- Clarify ownership and accountability
- Review existing documentation
- Understand your current position
- Engage key stakeholders
- Review supplier relationships
- Identify potential risks and gaps
These activities remain valuable regardless of what assurance category ultimately applies to your organisation.
How Diamond IT can help you succeed through change
Every organisation will approach the ESAF transition from a different starting point.
Some providers may feel confident in their current position and simply want reassurance that they are heading in the right direction. Others may be working through questions around governance, accountability, documentation, risk management or organisational readiness.
At Diamond IT, we help organisations navigate change by combining business, technology and governance expertise. Whether you need an independent perspective on your current readiness, support understanding your obligations or practical guidance on planning the next steps, our focus remains the same.
If you would like to talk this through, please get in touch with our team on 1300 307 907, send an email to enquiries@diamondit.com.au or fill out the form below.

