About
A small firm built for work that has to hold up
Calm delivery under scrutiny.
Aratu Consulting is a boutique, practitioner-led technology consultancy in Australia. We work on cloud, data, AI and delivery assurance for organisations whose programs face audit committees, gateway reviews, regulators and public reporting. Every engagement runs with a few experienced practitioners, which means the person who scopes your work is the person who does it. That constraint is the reason the model works, and it is also the reason we cannot take everything.
The name
Where the name comes from
Aratu comes from Tupi, an Indigenous Brazilian language, and is associated with calm or still water. It is pronounced ah-rah-TOO. We chose it because turbulence is what actually sinks large programs: scope moves, the business case ages out of date, assurance evidence gets reconstructed after the fact, and the delivery partner rotates its people through the account. Calm is not a mood we are selling. It is the state a program is in when the decisions are recorded, the risks have owners, and the evidence already exists when someone asks for it.
What we believe
Four positions we are willing to defend
These are not values statements. Each one has a cost, and each one rules something out.
The leverage model transfers risk to the client
The standard consulting pyramid sells senior judgement and delivers junior execution, then bills the client for the learning curve. This is a structural feature of that model, not a failing of the people inside it. We run the opposite arrangement: fewer people, all experienced, no bench to keep utilised. You pay more per hour and considerably less in total, and you lose the ability to scale a team to forty people in a fortnight.
Assurance evidence written afterwards is not evidence
Most program documentation is produced under deadline pressure, weeks after the decisions it describes. It reads as a reconstruction because it is one, and experienced reviewers can tell. We build decision records, risk registers and benefit traceability while the work is happening, with a named delegate against each decision. The trade is that it takes visible effort during delivery rather than invisible effort before a gateway review.
Naming the failure mode is more useful than naming the method
A method is easy to describe and tells you almost nothing about whether a firm has done the work. What tells you is whether they can name precisely what goes wrong: the migration that moved the workload and left the controls behind, the AI pilot that cannot answer a privacy question, the tender that is technically compliant and unreadable. We lead every conversation with the failure mode and then get calm about it. If we cannot describe how your program is likely to fail, we are not the right firm for it.
You should govern AI on yourself before recommending it to anyone
We use AI in our own delivery every day — drafting, code assistance, document analysis, test generation and research synthesis — and a named human remains accountable for every deliverable that leaves here. We maintain our own tool inventory, client-data handling rules and defined human review points, informed by ISO 42001, the NIST AI Risk Management Framework and Australian Government AI policy. We do not claim proprietary models and we will not quote a productivity figure we have not measured. Where the work is building rather than assuring, it happens under Greenix Digital.
The model
A few experienced practitioners, firm-wide
The individual who runs your scoping call writes the proposal, leads the engagement and signs the final report. Their name appears in the engagement letter rather than a role title, and it does not change part-way through unless we tell you why in writing and you agree. There is nobody junior to substitute in, because with a few contributors there is nobody to substitute at all. This is the whole mechanism, and it is verifiable rather than promised.
Capacity is capped deliberately. We hold a small number of concurrent engagements and we do not sell beyond that line, so a start date is sometimes several weeks out and occasionally we decline work we would like to do. When that happens we say so at the scoping call rather than at contract signature. If your program needs staff augmentation at volume, a prime or a panel provider is the correct answer and we will say that early.
What the model means in practice
- Named accountability. One individual named in the proposal, at kick-off and on the final report. Substitution only with written notice and your agreement.
- Capped concurrency. A fixed small number of live engagements at any time. Honest start dates, given before you invest effort in a procurement.
- No bench. Nobody is waiting to be utilised, so nothing is scoped to keep people busy.
- Narrow breadth. We work in cloud, data, AI and delivery assurance. Outside that, we refer.
- Australian hours. Business hours in Australian time zones. No follow-the-sun coverage and no overnight roster.
Boundaries
What we don't do
A firm that will do anything is telling you nothing. These are the constraints we hold to, and they are the fastest way to work out whether we fit.
- We do not staff large programs. If you need twenty or forty people, we are the wrong shape. We work alongside primes and panel providers rather than presenting as one.
- We do not provide legal advice, procurement probity advice or investment advice. We work to those boundaries and refer you to the appropriate adviser when a question crosses them.
- We do not guarantee tender or grant outcomes. We support bid quality, structure and compliance. We have no influence over evaluation and no role in the buyer's decision.
- We do not write claims you cannot evidence. Anything submitted in your name remains your responsibility for truth and accuracy, and we will not draft around a fact that is not there.
- We do not take work where a conflict of interest exists. Where one arises mid-engagement, we disclose it and withdraw if that is the right call.
- We do not sell licences, resell platforms or take vendor commissions. Our recommendations carry no margin for us.
- We do not run offshore delivery or overnight support. There is no follow-the-sun model behind us.
- We do not put a junior on your program to protect our margin. There are no juniors.
Risk and assurance
We build the assurance trail while the work happens
The common failure is not that a program lacks governance. It is that the governance artefacts and the delivery reality drift apart, so the business case describes one thing while the build delivers another, and nobody reconciles the two until a review forces it. By then the reconstruction is expensive and the audit trail has gaps that cannot honestly be filled. We work the other way around: the record is written as the decision is made, by the person accountable for it.
Risk-aware does not mean alarmist. We name the failure mode plainly, put an owner and a review date against it, and then get on with the work. Our practice is informed by the PGPA Act 2013, the Commonwealth Procurement Rules, the ICT Investment Approval Process and Assurance Framework and, for regulated businesses, APRA CPS 230 and CPS 234. We align to those frameworks. We do not claim assessment or certification against any of them.
What that produces
- Decision records with a named delegate, the options considered and the date.
- A risk register with owners, review dates and a visible history of what changed.
- Benefit traceability from business case commitment to delivered capability.
- Gateway-ready evidence packs assembled from live artefacts, not rewritten for the review.
- Control mapping that shows which obligation each control answers and who owns it.
- An exit plan, written at the start, that a successor could actually use.
How we engage
How we work with government and with primes
With agencies
We are fluent in the accountability language an agency runs on: delegate, business case, gateway review, probity, benefits realisation, audit committee. We can be engaged directly for advisory and assurance work at a scale that suits a small firm, and through the arrangements an agency already uses where that is simpler for you. We state our position on panels, arrangements and marketplace listings plainly, including where we hold nothing, and we confirm it in writing before you invest effort in a procurement. The same applies to security clearances and assessments: we tell you what we hold and what we do not. If a requirement needs something we do not hold, we tell you at the scoping call and not after you have shortlisted us.
With primes and delivery partners
On larger programs we work as a subcontracted specialist inside someone else's contract, usually on assurance, architecture or delivery leadership where the prime needs senior depth in one area rather than headcount. We do not compete for the whole scope and we do not use a subcontract position to position ourselves for it later. The prime holds the client relationship and we say so in writing. Where our involvement needs to be visible to the end client for probity reasons, we expect that disclosure to happen.
People
Who you will actually be working with
A boutique firm's credibility rests on named individuals rather than on a logo. You will know who is doing your work before you sign anything, and that name does not change part-way through unless we tell you why in writing and you agree.
The practitioner who runs your scoping call is named in the engagement letter, writes the proposal, leads the delivery and signs the final report. Their background, the frameworks they actually work to, their certifications and the issuing bodies, and their clearance status — stated explicitly, including when the answer is none held — are set out in the proposal for your engagement. We put that detail in front of the people who will rely on it rather than on a public page, and we will provide it on request before a scoping call if you would rather see it first.
We do not claim credentials we cannot evidence. Every certification, clearance and panel reference we state is one we can produce a document for, and where a metric concerns a client's program it is published only with that client's permission.
Network
Who we work with
A small firm's network is a set of individual relationships, not an alliance program, and we would rather describe it accurately than dress it up. Where an engagement needs capability we do not hold, we bring in a named specialist we have worked with before, we tell you who they are and what they are accountable for, and they are contracted transparently. We do not sub-let work to an unnamed party and we do not present other people's capability as our own.
Greenix Digital is the brand under which we build: applied AI engineering, prototypes, agent workflows, evaluation harnesses and production systems. One small, experienced team, two fronts. Aratu answers whether a program will hold up. Greenix answers whether a thing can be built. Joint work is proposed under both names, with one accountable individual per part and one contracting entity.
Current relationships
- independent security assessment —
- data engineering delivery —
- —
- Greenix Digital — AI product and applied AI engineering. → greenixdigital.com
Commitments
What we hold ourselves to
Four commitments, written at the level we can actually meet today rather than the level that would read well.
Accessibility
Everything we produce for public-facing use is built to meet WCAG 2.2 Level AA, and this site is built to the same standard. Where an agency's own requirement is higher, we work to theirs. Accessibility is treated as a delivery requirement with an owner and a test, not as a remediation task after launch.
Privacy and data handling
We handle client information under the Australian Privacy Principles and the Privacy Act 1988, and we hold client data only as long as an engagement requires it. Our internal rules define what may be placed into an AI tool, what may not, and which review point a human owns before anything leaves here. Where an engagement involves data sharing under the DATA Scheme or a security classification under the Protective Security Policy Framework, we work to the agency's controls and say plainly what we are not accredited to do.
Indigenous procurement
We work within the Indigenous Procurement Policy and its requirements as they apply to the arrangements we work under, and we support clients in meeting their own obligations under it. We make no claim to Indigenous ownership or supplier status. Our name comes from an Indigenous Brazilian language and carries no connection to Aboriginal or Torres Strait Islander peoples, and we would rather state that directly than let it be assumed.
Environmental and social
We are a small firm with no premises footprint of consequence and no supply chain to speak of, so a claim of environmental leadership from us would be noise. What we do commit to is designing for efficient resource use in the cloud work we deliver, because oversized environments cost money and carbon in the same proportion. We do not hold a carbon or sustainability certification and we will not imply one.
Start with a scoping call
A scoping call is a conversation about what is likely to go wrong in your program and whether we are the right firm to help with it. You will get an honest read on fit, a realistic start date given our capacity, and a clear answer if the work sits outside what we do. There is no obligation attached and no proposal produced unless you ask for one.
A short first conversation, then a clear recommendation.
Tell us what the program is, where it is, and what has to hold up. If we are not the right firm, we will say so and point you to who is.