Search all 478 artefacts by title, document ID or content.
Register | Family 5, Client Assessment & Fit
The single reference for what actually gates an Australian deal. It exists because the most expensive mistake available in Australia is treating a soft expectation as a hard gate, buying a certification that nobody asked, or treating a hard gate as a soft one and discovering it in week three.
REG-AU-002 | Version 1.0.0 | Last Modified On 01 August 2026
The single reference for what actually gates an Australian deal. It exists because the most expensive mistake available in Australia is treating a soft expectation as a hard gate, buying a certification that nobody asked for, or treating a hard gate as a soft one and discovering it in week three.
| Class | Meaning |
|---|---|
| HARD | The deal cannot lawfully or practically close or go live without it |
| SOFT | Strongly expected. Absence must be actively defended and costs days |
| COND | Hard only if a stated condition is met. The condition is a qualification question |
| N/A | Does not apply to a private hospital deal. Stated plainly rather than left silent: silence reads as a gap, whereas naming the instrument and explaining why it does not apply reads as literacy |
The organising fact. There is no Australian licence, registration, certification or approval a foreign
software vendor must hold to sell hospital software to an Australian private hospital. There are five
government conformance programmes, and each gates connecting to a national system, not selling.
DIS-AU-029 Section 2 is the status table.
| # | Requirement | Class | Enforced by | Elapsed | Cost | Artefact |
|---|---|---|---|---|---|---|
| 1 | Australian Privacy Principle 1.3 privacy policy | HARD | Information Commissioner | 2 days | Nil | POL-AU-053 |
| 2 | APP-mapped data processing agreement | HARD commercially | Contract | 3 days | Nil | DPA-AU-001 |
| 3 | Notifiable data breach commitment with named timeframes | HARD commercially | Contract, Privacy Act Part IIIC | 2 days | Nil | DPA-AU-001 Section 4, NTC-AU-009 |
| 4 | Election under section 6EA of the Privacy Act | SOFT | Information Commissioner | 2 days | Nil | Section 3 |
| 5 | State health records supplement | COND: hospital in NSW, VIC or ACT | State regulators | 3 days | Nil | DPA-AU-001 Schedule AU-B |
| 6 | Automated decision-making disclosure | HARD from 10 December 2026 | Information Commissioner | 3 days | Nil | POL-AU-053 Section 8, DPA-AU-001 Section 10.3 |
| 7 | Children's Online Privacy Code | N/A, health services excluded | Information Commissioner | Not applicable | Not applicable | Section 5 |
| 8 | Entry in the Australian Register of Therapeutic Goods | N/A while within exclusions 14G, 14M, 14N, 14O, 14I | Therapeutic Goods Administration | Not applicable | None | DIS-AU-028 |
| 9 | Published therapeutic goods exclusion analysis | SOFT, but decisive with clinical governance | Pensieve, self | 3 days | Nil | DIS-AU-028 |
| 10 | Modern Slavery Statement | SOFT: voluntary, threshold not met | Attorney-General's Department register | 2 days | Nil | STM-AU-031 |
| 11 | Foreign company registration | COND: only if carrying on business in Australia | Corporate regulator | 2 to 4 weeks | Lodgement plus agent [ESTIMATE] |
REG-AU-001 Section 2 |
| 12 | Ransomware no-payment position | SOFT | Cyber Security Act 2024 context | 1 day | Nil | DPA-AU-001 Section 4.6, MSA-AU-001 AU-12.4 |
| 13 | Critical infrastructure flow-down supplement | COND: hospital operates a general intensive care unit | Contract, Cyber and Infrastructure Security Centre | 3 days | Nil | MSA-AU-001 AU-12, Schedule AU-3 |
| 14 | Unfair contract terms compliant standard form | HARD where the customer is a small business | Competition and consumer regulator | 5 days | Nil | MSA-AU-001 AU-3, Schedule AU-2 |
| 15 | Consumer law consistent limitation ladder | HARD below the consumer threshold | Australian Consumer Law | Bundled with 14 | Nil | MSA-AU-001 AU-2, AU-7 |
Items 14 and 15 are the largest legal drafting delta between the India master and the Australian variant. Reliance on an unfair term in a standard-form small business contract is a penalisable contravention, not merely an unenforceable clause. An Indian-form agreement presented unchanged to an Australian day hospital is not simply unattractive.
| # | Requirement | Class | Issued by | Elapsed | Sell without it? |
|---|---|---|---|---|---|
| 16 | Services Australia Notice of Integration: Medicare, ECLIPSE, immunisation register | COND (HARD) if Pensieve must lodge claims | Services Australia | 3 to 9 months [ESTIMATE] |
Yes, if the hospital keeps its existing claiming path |
| 17 | My Health Record conformance and Notice of Connection | COND: HARD if Pensieve is the My Health Record system | Digital Health Agency | 6 to 12 months [ESTIMATE] |
Yes, on the same condition |
| 18 | Connecting Systems Security Conformance Profile | COND, prerequisite to 17 | Digital Health Agency | Bundled with 17 | Yes |
| 19 | Healthcare Identifiers Service conformance | COND: only if Pensieve stores individual identifiers | Services Australia and the Agency | Bundled with 17 | Yes: publish the non-collection boundary instead |
| 20 | Electronic prescribing conformance | COND: community or discharge prescribing only | Digital Health Agency | 6 to 12 months [ESTIMATE] |
Yes for inpatient-only scope |
| 21 | Secure messaging conformance | SOFT | Digital Health Agency | 3 to 6 months [ESTIMATE] |
Yes |
| 22 | NASH PKI certificate | HARD for the hospital, not for Pensieve | Services Australia, to the hospital | Days | Yes: it is the hospital's credential |
| 23 | AU Core FHIR conformance self-declaration | SOFT, appreciating quickly | HL7 Australia, self-assessed | 2 to 4 weeks | Yes |
| 24 | My Health Record pathology and imaging upload capability | COND: HARD where the hospital authors its own reports | Health department and the Agency | With 17 | No, for that hospital segment |
Items 16, 17, 20 and 24 are the entire difference between a fourteen-day Australian deal and a nine-month
one. DIS-AU-029 Section 3 defines the two tracks and the two qualification questions that decide which one a
prospect is.
| # | Requirement | Class | Issued by | Elapsed | Cost | Position |
|---|---|---|---|---|---|---|
| 25 | Self-assessed Essential Eight maturity statement | SOFT: the standard Australian ask | Pensieve, self | 3 days | Nil | Section 4 |
| 26 | Independent Essential Eight assessment at Maturity Level 2 | SOFT | Aligned assessor | 2 to 4 weeks | from A$8,500 | Buy only when a real Australian pipeline exists |
| 27 | ISO/IEC 27001:2022 | SOFT for independents; HARD for group panel entry | Accredited certification body | 90 to 120 days | Per the certifications research | Not held |
| 28 | SOC 2 Type I / Type II | SOFT | Licensed audit firm | +45 / +180 days | Per the certifications research | Not held |
| 29 | Cloud Security Alliance self-assessment | SOFT | Self, public registry | 7 to 14 days | Nil | It is free; there is no reason not to |
| 30 | Independent penetration test attestation | SOFT | Any reputable tester | 2 to 4 weeks | Per the certifications research | REP-GL-001 |
| 31 | Information Security Registered Assessors Program assessment | N/A for private hospitals | Endorsed assessor | 6 to 16 weeks | A$30k to A$300k+ | Do not buy: Section 5 |
| 32 | Hosting Certification Framework | N/A, provider-level and government-only | Home Affairs | Not applicable | Not applicable | Section 5 |
| 33 | Software bill of materials | SOFT, rising | Pensieve, self | 3 days | Nil | DIS-GL-019 |
| 34 | Source code escrow | SOFT | Escrow agent | 2 to 5 days | Per the certifications research | ADD-GL-011 |
| # | Requirement | Class | Elapsed | Cost | Artefact |
|---|---|---|---|---|---|
| 35 | Australian Business Number as a non-resident | HARD for cash | up to 28 days [ESTIMATE] |
Nil | REG-AU-001 Section 3 |
| 36 | Statement by a Supplier where no ABN is quoted | HARD for cash | 1 day | Nil | FIN-AU-024 |
| 37 | GST registration | N/A for business-to-business supplies to registered hospitals | Not applicable | Not applicable | REG-AU-001 Section 4 |
| 38 | Tax Residency Certificate | HARD to access treaty relief | 2 to 6 weeks | Nominal | REG-AU-001 Section 6.1 |
| 39 | Royalty-versus-services characterisation advice | HARD commercially: worth 15% of every invoice | 1 to 2 weeks | ~A$3,000 [ESTIMATE] |
REG-AU-001 Section 5.6 |
| 40 | Withholding gross-up clause | HARD commercially | 1 day | Nil | MSA-AU-001 AU-5.6 |
| 41 | Insurance certificates of currency with Australian territorial confirmation | SOFT to HARD, depending on the buyer | 5 to 15 days | ~A$4,000 to 12,000/yr [ESTIMATE] |
REG-AU-001 Section 7 |
| 42 | Australian counsel opinion on the regulatory position | SOFT | 1 to 2 weeks | A$2,000 to 5,000 [ESTIMATE] |
Section 7 |
| 43 | Data residency statement, per deployment model | HARD commercially | 2 days | Nil in fees | DIS-AU-008 |
| 44 | Accreditation evidence map for the health service standards | SOFT, high differentiation | 5 days | Nil | DIS-AU-028 Section 7 |
| 45 | Stamp duty, notarisation, apostille | N/A | Not applicable | Nil | Australia has none |
3.1 Pensieve is inside the Act on any sensible reading. Section 5B gives the Act extraterritorial operation where an organisation has an Australian link, and since the 2022 amendment carrying on business in Australia is sufficient: the information need not be collected or held in Australia. The Commissioner has demonstrated willingness to assert the link against a foreign entity with no Australian establishment.
3.2 Pensieve does not rely on the small business exemption, and says so in writing, at
POL-AU-053 Section 2.2. It is the worst available sentence to say to a hospital privacy officer.
3.3 The election under section 6EA. An entity that would otherwise be outside the Act may elect in writing to the Commissioner to be treated as an organisation, becoming bound by the Australian Privacy Principles and subject to the Commissioner, and is entered on a public opt-in register.
| Item | Value |
|---|---|
| Cost | Nil |
| Elapsed | Days |
| Status | Pensieve au s6ea election status |
| Effect | Converts "you are an offshore company, the Act does not reach you" into "we are bound and the Commissioner can act against us" |
This is the cheapest credibility purchase available to Pensieve in Australia, and it costs nothing.
Very few entities have
made the election, which is precisely why making it is a signal rather than a formality. It belongs in
the pre-first-contact readiness set, and CHK-AU-001 places it there.
3.4 Penalty exposure that should change behaviour today. The 2024 amendments restructured the civil
penalty regime into three tiers, and a failure to maintain a compliant APP 1.3 privacy policy is now
directly penalisable by infringement notice. An out-of-date Australian privacy policy is therefore a
measurable financial exposure, and the staleness monitoring on POL-AU-053 has a direct financial
justification in Australia that it does not have elsewhere.
4.1 The Essential Eight is the Australian commercial ask. It scores eight mitigation strategies at maturity levels zero to three and can be self-assessed or independently assessed. Maturity Level 2 is the commercial expectation. Maturity Level 3 is a government-grade posture, and asking a company of Pensieve's size for it is a category error a good chief information officer will not make.
4.2 Pensieve's position. Pensieve publishes a self-assessed maturity statement, per control, at the honest current level, with each gap named and dated.
| Control | Current self-assessed level | Target | Target date |
|---|---|---|---|
| Application control | Pensieve e8 application control |
ML2 | Pensieve e8 application control target date |
| Patch applications | Pensieve e8 patch applications |
ML2 | Pensieve e8 patch applications target date |
| Configure office macro settings | Pensieve e8 macro settings |
ML2 | Pensieve e8 macro settings target date |
| User application hardening | Pensieve e8 app hardening |
ML2 | Pensieve e8 app hardening target date |
| Restrict administrative privileges | Pensieve e8 admin privileges |
ML2 | Pensieve e8 admin privileges target date |
| Patch operating systems | Pensieve e8 patch os |
ML2 | Pensieve e8 patch os target date |
| Multi-factor authentication | Pensieve e8 mfa |
ML2 | Pensieve e8 mfa target date |
| Regular backups | Pensieve e8 backups |
ML2 | Pensieve e8 backups target date |
A vendor that publishes Maturity Level 1 on two controls and states when Level 2 lands is more credible than one claiming Level 2 with no evidence. The assessment is self-assessed and is labelled as such every time it is cited.
4.3 The transition nobody has noticed yet. The issuing authority has announced that the Essential Eight will be retired and replaced by a new "Essentials" series, with retirement beginning in 2027 and completing around 2028. The first chapter is the direct evolution of the Essential Eight, and the authority has said existing investment will not be made redundant. Pensieve tracks the transition and will re-baseline against the replacement when it is published. Almost no competing vendor will raise this, and currency is one of the substitutes Pensieve is selling in place of certification.
4.4 The sequencing argument. The security baseline the Digital Health Agency applies to systems connecting to My Health Record is aligned to the Essential Eight. The uplift Pensieve should do anyway for commercial procurement is the same work that would later underpin Agency security conformance. Do it once, use it twice. It is the only place in the Australian programme where a free early action buys down a later expensive one.
4.5 The standing evidence set. Supplied by link, not by questionnaire cycle.
| Evidence | Artefact |
|---|---|
| Security control set | ADD-GL-001 |
| Essential Eight self-assessment | Section 4.2 |
| Penetration test attestation | REP-GL-001 |
| Software bill of materials | DIS-GL-019 |
| Sub-processors and locations | DIS-GL-009 |
| Access and support model | DIS-AU-033 |
| Residency | DIS-AU-008 |
| Encryption, access control, logging | DIS-GL-011, DIS-GL-012, DIS-GL-013 |
| Backup, recovery and continuity | DIS-GL-014 |
| Standard questionnaire answers | QRE-GL-008 |
Silence reads as a gap. Naming the instrument and explaining why it does not apply reads as literacy.
| Not pursued | Why |
|---|---|
| Information Security Registered Assessors Program assessment | It is a government instrument, assessing against the government information security manual at a security classification. Australian private hospital groups do not require it; they run commercial third-party risk management and ask for ISO 27001 and SOC 2. Relevant only if a State health department or public hospital network deal appears, and then only after qualification. The permitted sentence is: the program applies to Australian government systems; Pensieve sells to private hospitals and therefore holds no assessment |
| Hosting Certification Framework certification | Certifies data centre and hosting providers for Australian Government customers. Pensieve's hosting provider holds the highest level; Pensieve does not hold it and does not imply that it does. Registration was paused in late 2025 pending reforms [UNVERIFIED: confirm whether the pause has lifted before relying on this in a long-cycle document.] Irrelevant to a private hospital deal |
| Register of Therapeutic Goods technical file, ISO 13485, IEC 62304 | Buying them concedes device status. DIS-AU-028 Section 8 and Section 10 |
| Children's Online Privacy Code assessment | The Code applies to designated online services and expressly excludes health services. Not applicable. POL-AU-053 Section 16 |
| GST registration pack | Not required for business-to-business supplies to GST-registered hospitals. REG-AU-001 Section 4 |
| Digital Health Agency conformance evidence pack | Track B only. Do not pre-build for a product decision that has not been made. DIS-AU-029 Section 3 |
| # | Item | Owner | Why it matters | Status |
|---|---|---|---|---|
| 1 | Service-by-service residency review: which services in the Pensieve stack are not regionalised to Australia | Engineering | The residency statement must be defensible line by line under questioning | Open: DIS-AU-008 Section 4 |
| 2 | Proactive inappropriate-access detection: pattern-based alerting on unusual record access by the hospital's own workforce | Engineering | Answers the statutory tort exposure directly, and Australian buyers recognise it instantly | Open: DPA-AU-001 Section 10.2 |
| 3 | Automated decision register as a product feature, generating the hospital's own disclosure text | Engineering | Hard deadline 10 December 2026 | Open: DPA-AU-001 Section 10.3 |
| 4 | AU Core FHIR profile conformance and published CapabilityStatement | Engineering | The cheapest credibility purchase in an Australian technical conversation | Pensieve au au core status (DIS-AU-029 Section 7) |
| 5 | Per-tenant, per-record-class retention schedule with an age-based rule | Engineering | Required by State health records law; cheap early, expensive to retrofit | Open: DPA-AU-001 Schedule AU-B.3 |
| 6 | Patient access request workflow with response-time tracking | Engineering | State law confers a direct patient right of access with its own clock | Open: DPA-AU-001 Section 7.1 |
| 7 | Records transfer export that survives the hospital closing or being sold | Engineering | A statutory event in State health records law | Open: DPA-AU-001 Schedule AU-B.3 |
| 8 | Verify ECLIPSE conformance effort with a vendor that has completed it | Engineering | The 3 to 9 month figure is an estimate with no primary source | Open: DIS-AU-029 Section 13 |
| 9 | Confirm the therapeutic goods exclusion item numbers against the current Determination text | Legal | A wrong item number in a clinical governance artefact is a credibility event | Open: DIS-AU-028 Section 2 |
| 10 | Confirm the State cross-border transfer principles for New South Wales and Victoria | Legal | Determines whether onshore hosting is legal or only commercial in those States | Open: DIS-AU-008 Section 1 |
| 11 | Confirm the Australian Capital Territory health records scope and principle set | Legal | Determines whether Schedule AU-B attaches for an ACT deal | Open: DPA-AU-001 Schedule AU-B.1 |
| 12 | Re-check Privacy Act tranche 2 status before the review date | Legal | Would remove the small business exemption and add a direct right of action | Open |
| # | Decision | Blocks | Cost of deciding | Cost of not deciding |
|---|---|---|---|---|
| 1 | Is the Australian fee a service fee or a licence fee? | The first Australian Order Form | ~A$3,000 [ESTIMATE] and 1 to 2 weeks |
15% of Australian revenue, every year (REG-AU-001 Section 5.6) |
| 2 | Is Track A the Australian product, and will it be said out loud in the first call? | Every Australian qualification conversation | Nil. A written, dated decision | The fourteen-day target does not survive contact with Australia: DIS-AU-029 Section 3 |
| 3 | Is a clinical-determination feature on the twenty-four month roadmap? | Every Australian clinical governance conversation | Nil. A written, dated, signed decision | If yes and undecided, a retrofit after a regulatory query instead of a separately regulated product line, see DIS-AU-028 Section 10 |
| 4 | Will Pensieve stand up an Australian DM-2 estate? |
Whether DM-2 is sellable in Australia at all |
Infrastructure cost | DM-2 cannot be quoted to a residency-sensitive Australian buyer (DIS-AU-008 Section 3) |
| 5 | Will Pensieve commit to an Australian-resident support tier? | Any My Health Record connectivity, ever | Hiring and identity architecture, measured in months | My Health Record remains permanently out of scope (DIS-AU-033 Section 6) |
| 6 | Australian counsel opinion on the Corporations Act position | Nothing today; buy it before deal two | A$2,000 to 5,000 [ESTIMATE] |
Registration exposure, and the loss of a saleable artefact (REG-AU-001 Section 2.4) |
| 7 | Australian counsel opinion on the therapeutic goods exclusion position | Nothing today. Strengthens DIS-AU-028 from a self-analysis to an advised position |
[ESTIMATE] comparable to item 6 |
The clinical governance answer remains self-asserted. See DIS-AU-028 Section 12 |
| Document | For |
|---|---|
CHK-AU-001 |
The sequenced checklist that operationalises this table |
REG-AU-001 |
Entity, tax and the fee-characterisation decision |
DIS-AU-008, DIS-AU-028, DIS-AU-029, DIS-AU-033 |
The four Australian disclosures |
DPA-AU-001, MSA-AU-001, POL-AU-053, STM-AU-031 |
The Australian legal and policy set |
01-research/international/01-australia.md |
The research this table is derived from, with sources |
| Version | Date | Author | Summary |
|---|---|---|---|
| 1.0.0 | 01 August 2026 |
Founder | First issue. Forty-five gating items across four categories with class, issuer, elapsed, cost and artefact; the Privacy Act and section 6EA position; the Essential Eight self-assessment and the replacement-series transition; the frameworks deliberately not pursued and why; and the open engineering items and founder decisions with what each one blocks. |