Is IRAP Certification a Must-Have for Enterprise AI in Australia?

0
minutes read
Is IRAP Certification a Must-Have for Enterprise AI in Australia?

Is IRAP Certification a Must-Have for Enterprise AI in Australia?

IRAP is a must-have when your AI platform handles Australian Government data at OFFICIAL: Sensitive or PROTECTED, or when you supply or host government workloads, where it is effectively a procurement prerequisite under the Protective Security Policy Framework. Outside those cases, it works as a credible security benchmark rather than a hard requirement.

IRAP stands for the Infosec Registered Assessors Program, run by the Australian Signals Directorate (ASD) through its Australian Cyber Security Centre. ASD-endorsed assessors independently evaluate whether a system meets the security controls in the Information Security Manual (ISM).

For organizations handling sensitive or government data, that independent assessment is how you show your security posture to agencies, regulators, and procurement teams before they trust you with classified or personal information. It answers a practical question: has someone qualified checked this system against a recognized national standard?

What Is IRAP and How Does It Apply to Enterprise AI?

IRAP is the Australian Government's program for independent security assessment, and for enterprise AI it applies to the AI platform itself, including its configuration, application layer, identity handling, and data flows. A cloud provider's IRAP-assessed infrastructure does not automatically cover the AI service running on top of it. That service is a separate scope, and it needs its own assessment.

The program is administered by ASD through the Australian Cyber Security Centre. ASD-endorsed assessors, who hold a minimum NV1 security clearance, evaluate a system against the controls in the ISM. Assessments are scoped to a classification level, typically OFFICIAL, OFFICIAL: Sensitive, or PROTECTED, with PROTECTED the level most sensitive government workloads expect across defense, health, law enforcement, and public sector environments.

One point matters for how you talk about it: IRAP produces an assessment report, not a pass-or-fail certificate. Assessors do not accredit or certify systems on ASD's behalf, so "IRAP-assessed" is more accurate than "IRAP-certified." Agencies and regulated organizations then read that report as part of their own security authorization process. The ISM itself is a living document that ASD updates several times a year, and recent releases have expanded coverage relevant to AI governance and data protection, so any assessment should be dated to the ISM version it was tested against.

For AI specifically, an assessment examines how the platform stores data, where it runs inference, and how it enforces access across people, processes, and technology. Access control is a core ISM concern, and it maps closely to how a well-governed AI platform should behave. Glean Search, for example, enforces permission-aware results at the search layer, returning answers based only on what each user is already authorized to see.

Who Actually Needs IRAP-Assessed AI in Australia?

Four groups need IRAP-assessed AI in Australia: government agencies, the vendors that supply them, APRA-regulated financial institutions, and critical infrastructure operators. Everyone else can treat the standard as a benchmark rather than a rule.

Australian Government agencies sit at the center. When they procure cloud-hosted or AI-powered services for sensitive workloads, the Protective Security Policy Framework makes an IRAP-assessed system a procurement prerequisite, not a nice-to-have.

Vendors that want to sell AI platforms to Commonwealth, state, or territory agencies inherit the same requirement. They need an assessment report at the classification level the buying agency expects. The obligation follows the data and the buyer, not the vendor's size, so a small provider can be pulled into scope by a single government contract.

APRA-regulated organizations in banking, insurance, and superannuation have a related driver. CPS 234 and CPS 230 hold them accountable for the security and operational risk of third parties that manage their information assets, and an AI vendor counts as one of those third parties. An IRAP report gives their risk teams independent evidence to work from.

Critical infrastructure operators covered by the Security of Critical Infrastructure Act face regulator scrutiny over their security posture. Choosing AI platforms with ISM-tested controls lowers the effort of proving that posture during a review.

Private-sector enterprises with no government data and no regulated-sector obligations rarely need a formal assessment. Their baseline is usually the Privacy Act and the Australian Privacy Principles, though the ISM control set still makes a useful yardstick for measuring a vendor's security maturity.

How IRAP Assessment Differs from Other Cloud Compliance Frameworks

FrameworkJurisdictionWhat It CoversSatisfies Australian Government Procurement?
IRAPAustraliaISM controls at OFFICIAL, OFFICIAL: Sensitive, or PROTECTED classification levelsYes
SOC 2 Type IIInternationalSecurity, availability, processing integrity, confidentiality, privacy for cloud servicesNo
ISO 27001InternationalInformation security management system to a repeatable standardNo
FedRAMPUnited StatesCloud services for US federal use; High tier shares conceptual ground with IRAP PROTECTEDNo
Privacy Act 1988AustraliaCollection, use, and disclosure of personal informationNo (different lane — stacks with IRAP, does not replace it)

IRAP measures a system against Australia's Information Security Manual and, for cloud and government workloads, the Protective Security Policy Framework. SOC 2, ISO 27001, and FedRAMP are either jurisdiction-neutral or built for the United States, so none of them speaks to Australian data sovereignty on its own.

SOC 2 Type II reports on security, availability, processing integrity, confidentiality, and privacy for a cloud service. It gives buyers useful assurance, but it says nothing about ISM control coverage or where Australian data is processed.

ISO 27001 certifies that an organization runs an information security management system to a repeatable standard. The certificate does not map to the government classification levels an Australian agency works in, so it cannot answer a procurement question about PROTECTED data.

FedRAMP is the closest overseas analog, since it authorizes cloud services for US federal use. FedRAMP High and IRAP PROTECTED share conceptual ground, yet they belong to separate regimes, and one never substitutes for the other when Australian Government data is involved.

The Privacy Act 1988 sits in a different lane again. It governs how personal information is collected, used, and disclosed, while an IRAP assessment tests system-level security. The two stack together, and one does not discharge the other. Worth noting for architects: the ISM's risk-management approach draws on NIST SP 800-37 Rev. 2, and the ISM itself is guidance rather than legislation or a pass-fail certificate.

What IRAP Assessment Evaluates in an AI Platform

An IRAP assessment of an AI platform looks at three things: the security controls behind the system, where data is stored and processed, and how the platform stays current after the assessor signs off. Each area carries specific expectations for AI workloads.

Security Controls Across People, Processes, and Technology

Assessors test the security controls that surround an AI platform, spanning people, processes, and technology. Typical areas include patching, centralized logging, approved cryptography, network segregation, access control, cross-domain security, physical data-center security, and information security risk management.

AI workloads add their own questions. Assessors want to see how the platform governs model behavior, enforces data classification, and stops sensitive information from surfacing in an AI response to someone who should not see it.

Permission-aware architecture carries a lot of weight here. A platform that returns cited answers based only on what the requesting user is authorized to access speaks directly to the ISM's access control requirements, because the model never reaches data the user could not open themselves.

Data Residency and Sovereign Processing

Data residency is a central line of questioning, and for AI the sharper question is where inference runs, not just where records sit. Some platforms host storage in Australia but route model processing offshore when demand spikes, which breaks the sovereignty assumption buyers rely on.

Region-locked deployment, keeping both storage and compute inside Australian data-center regions, is a control assessors examine closely. Buyers should ask for evidence, not a marketing statement.

Contractual zero-day data retention with the underlying model providers is a further control. It shows that prompts and responses containing sensitive data are not kept outside the assessed boundary.

Continuous Monitoring and Reassessment

An IRAP assessment captures a single point in time, so currency matters as much as the original result. Under PSPF requirement 0109, an agency should rely only on an assessment carried out in the previous 24 months against the ISM current at that time, and reassess sooner after a material change such as a new architecture or a poorly handled incident.

No annual cycle applies, and no printed expiry date exists. Platforms with built-in audit logging, real-time access monitoring, and automated reporting cut the operational effort of holding that posture steady between formal assessments.

The Real Consequences of Deploying AI Without Adequate Security Assessment

Deploying AI without an adequate security assessment exposes an organization to procurement failure, regulatory enforcement, and slower breach response. The costs land hardest on agencies and regulated firms.

A government agency generally cannot stand up an OFFICIAL: Sensitive or PROTECTED system without both a current IRAP assessment and, for hosting, certification under the DTA Hosting Certification Framework. Missing either one blocks the deployment outright and can trigger audit findings on systems already in production.

For APRA-regulated entities, an AI vendor that cannot show ISM-tested security controls creates exposure under CPS 234, the prudential information security standard in force since July 1, 2019. The standard requires systematic control testing and prompt notification to APRA of material security incidents, and it reaches the third parties that handle an entity's information assets.

Breach response gets harder too. The Notifiable Data Breaches scheme, part of the Privacy Act 1988 and in force since February 22, 2018, requires covered organizations to assess and report eligible breaches likely to cause serious harm. An AI platform with weak access controls and thin audit trails slows that assessment when the clock is already running.

Reputational and operational costs compound the legal ones. Organizations holding citizen records, patient data, or financial information face public scrutiny after an incident, and platforms with undocumented controls accrue technical debt that grows more expensive to fix as AI use spreads across the business.

Key Benefits of IRAP-Assessed AI for Enterprise Buyers

IRAP-assessed AI gives enterprise buyers documented proof of security, faster procurement, and cleaner mapping across the regulations they answer to. The value is concrete, not reputational alone.

An assessment report hands security teams and procurement boards independent evidence that a platform meets government-grade controls. That evidence shortens evaluation cycles, because reviewers work from a tested report instead of a vendor questionnaire.

The same report supports more than one obligation. ISM controls map closely to CPS 234 and the ASD Essential Eight maturity model, so a single assessment can feed evidence into several frameworks a regulated buyer already tracks.

A good report also settles shared-responsibility questions. It states which controls the provider satisfies and which stay with the customer, such as identity configuration, data classification, and application-layer settings, which removes a common source of gaps during onboarding.

For vendors, an assessment at PROTECTED level clears objections early in government and regulated-sector deals, so bids reach the shortlist faster. And because assessed platforms carry documented incident response protocols, escalation paths, and notification timelines, buyers inherit a response posture that lines up with OAIC and APRA expectations from day one.

How to Evaluate Whether Your AI Platform Needs IRAP Assessment

Deciding whether your AI platform needs IRAP assessment comes down to three steps: map your obligations, question your vendor precisely, and fit the result into a wider governance program.

Map Your Data Classification and Regulatory Obligations

Start by classifying the data your AI workloads touch. If they involve Australian Government data at OFFICIAL: Sensitive or PROTECTED, IRAP assessment is a hard requirement under the PSPF, and the decision is effectively made for you.

Next, check which regulator you answer to. APRA, ASIC, the TGA, and critical infrastructure rules each expect security assurance from vendors, and several point back to ISM-grade controls. Add the Privacy Act's automated decision-making transparency duties, which start on December 10, 2026 and require APP entities to disclose in their privacy policy the kinds of personal information and decisions involved when a program substantially assists decisions that affect someone's rights.

If you handle only commercial data with no government or regulated-sector exposure, SOC 2 Type II, ISO 27001, and Privacy Act compliance form a practical baseline.

Ask the Right Questions During Vendor Assessment

Request the vendor's IRAP assessment report and read three details: the classification level, the exact scope of services assessed, and the date. An assessment against an old ISM version may not reflect the controls current today.

Ask where inference runs, not just where data rests, and request a data flow diagram that traces a user query through to the AI response. Confirm that the platform respects your existing permissions and answers only from what the requesting user can access.

Check for zero-day retention commitments with upstream model providers, and ask how the vendor keeps controls current between formal assessments.

Build IRAP into Your Broader AI Governance Framework

Treat an IRAP assessment as one layer of defense in depth within a broader AI security effort, not the whole program. It validates platform security, yet you still own data classification, identity management, and the policies that govern how staff use AI.

Pair the assessed platform with a governance program that keeps an AI register, runs risk assessments, and maps controls to a recognized framework such as ISO 42001 or the NIST AI Risk Management Framework. Back that with continuous monitoring, including audit logs, access reviews, and model behavior checks, so the posture the assessor validated holds up over time.

Frequently Asked Questions

What is IRAP certification and why is it important for AI?

IRAP is a security assessment, not a certification. ASD-endorsed assessors test a system against Information Security Manual controls at a set classification level. For AI, the assessment confirms that data handling, access enforcement, and processing location meet Australian Government security standards before agencies trust the platform with sensitive information.

How does IRAP assessment compare to SOC 2 or ISO 27001?

SOC 2 and ISO 27001 are international assurance frameworks that many vendors hold as baseline security proof. IRAP is Australia-specific, measuring systems against the ISM and government classification levels. The frameworks stack rather than substitute. Only IRAP directly satisfies Commonwealth procurement requirements for sensitive government data.

Can an AI platform inherit IRAP assessment from its cloud infrastructure provider?

Only partly. A hyperscale cloud provider's IRAP assessment covers its infrastructure layer, not the AI service running above it. The vendor's application, identity configuration, data handling, and model governance sit above the infrastructure line and need their own assessment at the classification level buyers require.

What happens if an AI vendor loses IRAP alignment between assessments?

An IRAP assessment reflects a single point in time, and the ISM changes several times a year. If a vendor stops maintaining controls or skips reassessment against newer ISM versions, agencies may need to re-evaluate the platform. Regulated buyers should write 24-month reassessment commitments into vendor contracts.

Is IRAP required for private-sector AI deployments in Australia?

Not directly. IRAP is built for government use, so most commercial buyers face Privacy Act and Australian Privacy Principles obligations instead. APRA-regulated firms, critical infrastructure operators, and government subcontractors increasingly reference IRAP-assessed controls in vendor due diligence, which makes the assessment a market differentiator well beyond formal Commonwealth procurement.

For regulated Australian workloads, IRAP assessment isn't a box to tick after deployment, and it should shape how you evaluate an AI platform from day one. We build security and governance into how we connect, understand, and act on your organization's knowledge, so you can adopt AI without loosening the controls your compliance teams rely on. Request a demo to explore how Glean and AI can transform your workplace.

Recent posts

Work AI that works.

Get a demo
CTA BG