Industries / Australian government
Technology delivery that holds up when someone independent looks at it
For Commonwealth and state entities delivering programs where the failure is public and the audit is real.
You are accountable for something that has to work, on funding that arrives in cycles, with a workforce you cannot grow. The delivery capability sits outside your entity, and the assurance obligation stays inside it. We provide senior delivery leadership, cloud and data modernisation, AI enablement and independent assurance, with a few experienced practitioners and no handover to juniors. The person who scopes your work is the person who does it.
The environment
The record is the deliverable
Commonwealth entities operate under the Public Governance, Performance and Accountability Act 2013 (PGPA Act), which makes an accountable authority personally responsible for the proper use of public resources. Procurement runs under the Commonwealth Procurement Rules (CPRs), where value for money is a judgement you have to be able to explain, not a price you can point at. Above that sit the Australian National Audit Office (ANAO), parliamentary committees, your own audit and risk committee, and gateway reviews at the points where money is committed. None of those bodies were in the room when the decision was made. They read what was written down.
That is the real constraint on a government technology program. Not the technology. The requirement to produce, months or years later, a defensible account of what was decided, by whom, under what delegation, on what information. Programs that treat this as a reporting overhead end up reconstructing the record under time pressure, and the gaps in it become the finding. Programs that treat it as part of delivery have the answer before the question is asked.
We work the second way. Aratu takes its name from Tupi, an Indigenous Brazilian language, where it is associated with still water. The relevance is narrow and we will only claim it once: programs fail when they become turbulent, and a settled program is one where the record keeps pace with the work.
What you are working against
Seven pressures we plan around rather than pretend away
Item 1 — Appropriation cycles set the clock Funding is approved in cycles and often in tranches, which means a program can be fully staffed in March and unfunded in July. Delivery plans that assume continuous funding create a cliff. We plan work in tranches that produce a defensible stopping point, so that if the next tranche does not arrive you have a usable capability and a clean handover rather than a half-migrated platform.
Item 2 — ANAO scrutiny is retrospective and detailed Performance audits examine what was recorded at the time, not what you remember. The common finding is not incompetence, it is an absent or inconsistent audit trail: decisions without a named delegate, benefits claimed in a business case that were never traced to a delivered capability, risks accepted without evidence of who accepted them. We write those artefacts as the work proceeds, in the form an auditor recognises.
Item 3 — Machinery-of-government changes move the ground Functions transfer between entities. Programs are split, merged or reassigned with limited notice, and the receiving entity inherits a system it did not design and a contract it did not write. We keep the target architecture, the data classification and the decision record documented to a standard that survives transfer, and we write exit and transition provisions into the design rather than after it.
Item 4 — Legacy systems carry undocumented obligations The system you want to replace enforces a statutory rule that exists nowhere else in writing. It also holds records with retention obligations under the Archives Act 1983. Modernisation that treats the old system as a technical artefact rather than a legal one produces a new platform that quietly stops meeting an obligation. We look for those obligations before the migration design is settled.
Item 5 — Workforce caps push capability outside the entity Average staffing level limits mean you cannot hire the delivery capability you need, so it is contracted. That is a structural fact rather than a failure. The problem it creates is dependency: the knowledge leaves when the contract ends. We work with an explicit handover obligation from the first week, and we write the documentation your people will actually use.
Item 6 — The shift from contractors to outcome-based engagement Entities are moving away from time-and-materials augmentation towards defined outcomes and deliverables, partly in response to sustained criticism of consulting expenditure. Outcome-based engagement only works if the outcome is specified precisely enough to be accepted or rejected. We will help you write that specification even where it constrains us, because an unclear deliverable is a dispute waiting for a change of sponsor.
Item 7 — Do more with less, without dropping the assurance Efficiency expectations arrive without a matching reduction in obligations. The tempting response is to defer the assurance work, because it is the part with no visible user. That is the wrong economy. Assurance is cheapest when it is concurrent and most expensive when it is reconstructed. We use AI in our own delivery — document analysis, drafting, code assistance, test generation — which is how a small firm carries this volume of artefact work at a sensible price. A named person reviews and signs everything.
Service lines, in a government context
What we do, and what it looks like in an entity
Program and Delivery Leadership
Failure mode: The business case no longer matches the delivery. Scope shifted twice, the benefits in the second-pass case were never traced to anything that got built, and the steering committee has been receiving a status report that is green until the month it is red.
What we do: We take delivery leadership or independent assurance on a program and run it so that the evidence exists continuously. That means decision records naming the delegate and the authority relied on, a risk register with owners and review dates that are actually met, benefit traceability from the business case through to delivered capability, and a status view that separates schedule confidence from scope confidence. We prepare gateway-ready evidence packs before the gateway is scheduled, not in the fortnight before it. Where we are assuring rather than leading, we report to the audit and risk committee or the sponsor directly, and we will put a finding in writing that the program manager disagrees with.
What you trade away: We cannot also be your delivery partner on the same program if we are providing independent assurance of it. Pick one.
IT Program and Delivery Leadership
Platform, Cloud and Cybersecurity
Failure mode: The migration moved the workload and left the controls behind. The application runs in the new environment, the Information Security Manual (ISM) control mapping still describes the old one, and nobody can say which of the Essential Eight mitigation strategies the new platform actually implements. Alongside it sits security documentation written for accreditation and never touched since — a system security plan describing a system that has changed, and residual risks accepted by someone who is no longer the delegate.
What we do: We design landing zones with the control mapping built in, aligned to the ISM, the Protective Security Policy Framework and the Essential Eight maturity level your entity has committed to. We document the target architecture, the data classification, the residency position and the exit path before migration begins, because an exit plan written after go-live is a negotiating position rather than a plan. On the assurance side we prepare entities for assessment: security plans that match the running configuration, obligations traced to an owner, maturity assessed honestly rather than aspirationally, and residual risk written so a delegate can make an informed acceptance. We are not an assessor and we certify nothing — an assessor engaged by you does that, and we work alongside them.
What you trade away: We will not run a lift-and-shift on a schedule that does not allow the control mapping to be completed. Readiness work also surfaces controls that were assumed to be in place; the finding arrives from us rather than from an assessor, which is cheaper, but it is still a finding.
Platform, Cloud and Cybersecurity
AI Adoption and Enablement
Failure mode: The AI pilot cannot answer a privacy question. It works, people like it, and nobody can state which personal information it processed, under what authority, with what human oversight, or what happens to the output if it is wrong.
What we do: We start with the authority and the classification, not the model. That means establishing the legal basis for the data use under the Privacy Act 1988 and the Australian Privacy Principles (APPs), and where data is shared between Commonwealth entities, working within the Data Availability and Transparency Act 2022 (the DATA Scheme) rather than around it. We build data lineage and stewardship that names a person for each dataset. For AI, we set up evaluation, human review points and an accountability record informed by ISO/IEC 42001 and the NIST AI Risk Management Framework, and aligned to Australian Government policy on the responsible use of AI. Where the work moves from advice into building applied AI systems, it is delivered under Greenix Digital, with one accountable person named for each part.
What you trade away: We will not deploy a model into a process that affects a person's entitlement without a documented human decision point. If that makes the automation less efficient, that is the correct outcome.
Tender and Grant Advisory
Failure mode: The submission is compliant and unreadable. Every requirement is addressed somewhere, the evaluator cannot find the answer inside the word limit, and the response describes capability rather than demonstrating it against the evaluation criteria.
What we do: For entities, we help with the buy side: writing statements of requirement that can actually be evaluated, structuring evaluation criteria that discriminate between responses, and reviewing draft approach-to-market documents for internal consistency before they go to AusTender or BuyICT. For suppliers responding to government, we improve bid quality, structure and compliance. We support quality and structure only. We do not guarantee outcomes, we have no influence over evaluation and no role in the buyer's decision, and you remain responsible for the truth and accuracy of everything submitted in your name. Probity matters, and we will decline or withdraw where a conflict of interest arises. We do not provide legal advice, procurement probity advice or investment advice.
What you trade away: We will not write a claim we cannot see evidence for, including in the sections you would prefer to keep vague.
The obligation set
What we work within
These are the frameworks that shape the work. We use them where they apply, and we date-hedge anything that changes, because policy and framework versions move faster than website copy.
Group 1 — Spending, procurement and investment The PGPA Act 2013 governs the use and management of public resources and defines who may commit it. The Commonwealth Procurement Rules govern how you go to market and what value for money means in practice. The ICT Investment Approval Process and Assurance Framework, including two-pass business cases and gateway reviews, governs how larger investments are approved and reviewed. AusTender and BuyICT, including the Digital Marketplace, are where most of this becomes visible. The Indigenous Procurement Policy applies to procurement planning and we support entities in meeting it accurately rather than nominally.
Group 2 — Digital delivery and accessibility The Digital Transformation Agency (DTA) sets the Digital Service Standard, which shapes how services are designed, tested with users and reported against. Accessibility is a service obligation, not a late test: we work to the Web Content Accessibility Guidelines at level AA as the baseline expectation for Australian government digital services. Accessibility findings are cheapest at design and most expensive after a public release.
Group 3 — Security, protective security and hosting The Information Security Manual gives the technical control set. The Protective Security Policy Framework sets the governance, personnel, physical and information security policy expectations for entities. The Essential Eight and its maturity model give a concrete baseline for mitigation strategies, and the honest question is which maturity level you have committed to and whether you are actually at it. The Hosting Certification Framework governs where certain systems and data may be hosted.
Group 4 — Privacy, data sharing and records The Privacy Act 1988 and the Australian Privacy Principles govern the handling of personal information, including collection, use, disclosure and the security of records. The DATA Scheme under the Data Availability and Transparency Act 2022 provides a controlled pathway for sharing public sector data between accredited parties. Records management obligations under the Archives Act 1983 apply to Commonwealth records and constrain what a migration or decommissioning may do with data. Each of these has a practical consequence for architecture, and we treat them as design inputs.
Contracting
How a firm this size can actually be engaged
Scale is the first practical objection to engaging a boutique firm, and the second is procurement mechanics. Here are the routes that work.
Route 1 — Panels and marketplace arrangements Many entities buy digital and ICT services through established panels and marketplace arrangements, including BuyICT and the Digital Marketplace. Our current arrangements are listed here:. Where we do not hold a relevant arrangement, the routes below usually apply.
Route 2 — Limited tender or direct engagement under threshold Under the Commonwealth Procurement Rules, procurement below the relevant reporting threshold can be conducted more simply, subject to the entity's own accountable authority instructions. Short advisory engagements — an assurance review, a target architecture, a business case quality review — frequently fit inside this. We will provide the documentation your delegate needs to record the value-for-money decision.
Route 3 — Subcontracting to a prime We work alongside larger delivery partners rather than presenting as one. If a prime holds the contract, we can be named for a defined scope: independent assurance, architecture, the AI governance component, or a specific deliverable. One named person is accountable for our part, and that name appears in the proposal and in the final report.
Route 4 — Short-form advisory Some of the most useful work is small: a two-week review of a program in trouble, a second opinion on a target architecture before the money is committed, a readiness check ahead of a gateway. These are fixed-scope, fixed-price and produce a written deliverable your committee can table.
Engagement mechanics
What to expect in the first ninety days and after
Cadence A weekly written status note to the sponsor, a fortnightly working session with the delivery leadership, and a monthly pack formatted for your audit and risk committee or program board. The status note is short and states schedule confidence, scope changes, open decisions awaiting a delegate and the risks whose treatment is overdue. Green status is earned, not defaulted to.
Artefacts Decision records naming the delegate and the authority relied on. A risk register with owners and review dates. A benefits traceability view linking business case commitments to delivered capability. Target architecture and data classification documentation. A gateway-ready evidence pack maintained continuously. Everything is delivered in your document management system, in your templates, not ours.
Security and clearance Our contributors' security clearance status is stated here:. Where work requires access to classified material or systems, that access is arranged through your entity under its own processes. We will work in your environment on your devices where your policy requires it. Our own information handling rules, including what may and may not be processed with AI tooling, are documented and provided at engagement start.
Handover to business as usual Handover is designed at the start, not negotiated at the end. Named recipients in your team are identified in the first fortnight, participate in the work, and take the artefacts with an agreed acceptance step. The final report names the person who did the work and includes an honest statement of what remains open. We do not build a dependency and then offer to maintain it.
Beyond the Commonwealth
State and local entities
State jurisdictions run their own procurement rules, digital standards, information security policies and record-keeping obligations, and they do not map one-to-one onto the Commonwealth set. The substance is usually similar — a delegate has to be able to justify a decision, and an auditor-general will eventually look at it — but the instruments differ and the terminology differs with them. We work to your jurisdiction's framework and say plainly when we need to confirm a detail rather than assuming the Commonwealth position applies.
Local government has a different constraint again: smaller programs, thinner internal ICT capability and a council that reads the report. Short-form advisory suits this well. A fixed-scope review that produces one document a council can consider is often more useful than a long engagement.
For the audit and risk committee
What an audit committee will want to see, and where it comes from
An audit and risk committee is not testing whether the program is popular. It is testing whether the accountable authority can rely on what it is being told. That reliance depends on artefacts that were created at the time, by someone identifiable, and have not been retrofitted. The list below is what we maintain on every engagement, and what we would expect to see if we were reviewing someone else's program.
Checklist item 1 — A decision record with named delegates Every material decision recorded with the date, the person, the authority relied on, the options considered and the information available at the time. Not minutes. A record that can be read on its own.
Checklist item 2 — A risk register that shows treatment, not just rating Risks with a named owner, a treatment, a review date and evidence that the review happened. Risks accepted rather than treated should show who accepted them and on what basis.
Checklist item 3 — Benefit traceability from business case to capability A line from each benefit claimed in the business case to the capability that delivers it and the measure that will show it. Where a benefit is no longer achievable, that should be recorded when it becomes true, not at closure.
Checklist item 4 — Control mapping that matches the running system Security and privacy controls mapped to the architecture as deployed, with the date of last verification. A control library that has drifted from the system is worse than none, because it creates false assurance.
Checklist item 5 — A change record for scope and schedule Every scope and schedule change with the approval, the impact assessment and the effect on benefits. Reviewers reconstruct this from correspondence when it does not exist, and the reconstruction is where findings come from.
Checklist item 6 — An honest closure report What was delivered, what was not, what was learned and what is still open. Written to be read by someone who was not involved.
We do not publish client metrics or case studies without written consent, and we do not claim outcomes we cannot evidence. Where a proof point belongs on this page, it will be one an entity has agreed to: and an illustrative result.
Common questions
Questions we are asked before an engagement
Q1. You are a very small firm. How do you carry a program of this size? We do not carry programs of every size, and we will tell you when yours is beyond us. What we carry is the leadership, assurance and architecture layer, while delivery capacity comes from your team, a prime or a panel supplier. Being small is what makes the practitioner-led commitment real: with a few contributors there is nobody to substitute in. We also use AI in our own delivery — document analysis, drafting, code assistance, test generation, research synthesis — which is why the artefact load is manageable. A named person reviews and is accountable for every deliverable.
Q2. Are you IRAP assessed, ISO certified or on a panel? Our current position on assessments, certifications and panel arrangements is stated here:. We describe our work as aligned to or informed by frameworks such as the ISM, ISO/IEC 27001 and ISO/IEC 42001. Alignment is not certification and we will not blur the two.
Q3. Do your people hold security clearances? Clearance status is stated here:. Where an engagement requires clearance we do not hold, we will say so before you spend time on scoping, and we will work at a scope and classification level that does not require it, or decline.
Q4. Can you provide independent assurance of a program you helped design? No. If we designed or led the delivery, we are not independent of it, and any assurance opinion we gave would be worth less to your audit committee than it cost you. We will take one role or the other on a given program and say which at the start.
Q5. What happens if the program is in trouble and the honest status is red? We report it, in writing, to the sponsor and the committee, with the evidence. If a status we cannot support is being reported in our name, we raise it once internally and then in writing to the accountable person. This has consequences for the relationship and we accept them. You are paying for a status you can rely on.
Q6. How do you handle our data when you use AI tooling? We maintain an inventory of the tools we use and rules about what may be processed in each. Client material above the agreed classification is not processed in general-purpose tools. Where your entity requires work to occur inside your environment on your devices, we work that way. The rules are provided in writing at engagement start and we will accept your rules where they are stricter than ours.
Q7. What is Greenix Digital and when does it apply? Greenix Digital is the brand under which we build, and it is where the building happens: applied AI engineering, prototypes, agent workflows, evaluation harnesses and production systems. Aratu answers whether a program will hold up. Greenix answers whether something can be built. One small, experienced team, two fronts. Joint work is proposed under both names with one accountable individual for each part and a single contracting entity.
Q8. What is the smallest useful engagement? A two-week fixed-price review. That is enough to assess a program's assurance position, review a target architecture before commitment, or test whether a business case still matches the delivery. It produces one written document your committee can table.
Q9. How quickly can you start? Capacity is capped deliberately, so start dates are real and sometimes several weeks out. We will give you an honest date on the scoping call rather than an optimistic one that turns into a delay after contracting.
Calm delivery under scrutiny
Bring us the program that has a review coming, the migration whose control position nobody can state, or the business case that no longer matches what is being built. A scoping call is thirty minutes and produces a straight answer about whether this is our work.
A short first conversation, then a clear recommendation.
Tell us what the program is, where it is, and what has to hold up. If we are not the right firm, we will say so and point you to who is.