Service
Governance, Risk and Compliance Software
Governance, risk and compliance, in a system rather than a spreadsheet.
Security obligations fail quietly. A licence lapses, a control is never reviewed, an evidence pack is assembled from scratch the week before an audit because nothing was kept as it happened.
The platform holds the risk register, the controls and the evidence behind them, with review dates and expiries tracked rather than remembered. When a regulator, a customer or an auditor asks what you have, the answer is already assembled.
Built from how Empire runs its own compliance, and the compliance of the clients it holds a security officer role for.
Common questions
What does the platform actually hold?
The risk register, the controls that treat those risks, and the evidence behind each control, with review dates and expiries tracked rather than remembered. Licences, insurances, certifications and clearances sit alongside the obligations they satisfy.
How is this different from a spreadsheet?
A spreadsheet records what someone believed on the day they last opened it. It does not tell you a certificate expires in three weeks, it does not keep the evidence attached to the control, and it cannot produce an evidence pack without someone rebuilding it by hand. Those three differences are the entire product.
Does it help with DISP or SOCI obligations?
Yes, those are the obligations it was built around. A DISP annual review and a CIRMP annual report both ask you to demonstrate that a program stayed current across a year, which is a question you can only answer well if the evidence was captured as it happened rather than assembled afterwards.
Can we use it without the consulting engagement?
Yes. Organisations that already have a security officer use the platform on its own. Where you do not, it is usually taken with the CSO as a Service engagement, and the platform is what that engagement reports from.
Where is the data held?
Speak to Empire about your specific data residency and classification requirements before committing. Where an obligation constrains where information may be held or who may access it, that constraint shapes the deployment rather than being worked around afterwards.
Check this against the source
Everything on this page describes a regulated activity. These are the bodies that set the rules, so you can read them rather than take Empire’s word for it.
- Security of Critical Infrastructure Act 2018 Federal Register of Legislation
- Cyber and Infrastructure Security Centre Australian Government
- Privacy Act 1988 Federal Register of Legislation
- The Australian Privacy Principles Office of the Australian Information Commissioner
How the evidence stays current
Security obligations fail quietly: a licence lapses, a control is never reviewed, an evidence pack is built from scratch the week before an audit because nothing was kept as it happened.
-
Risk register
The risks, held in one place rather than in a spreadsheet that records what someone believed on the day they last opened it.
-
Controls
The controls that treat those risks, attached to the risks rather than tracked separately from them.
-
Evidence as it happens
The evidence behind each control, captured when it is produced. This is the difference that makes an annual review answerable.
-
Expiries tracked
Review dates and expiries tracked rather than remembered. Licences, insurances, certifications and clearances sit alongside the obligations they satisfy.
-
Pack already assembled
When a regulator, a customer or an auditor asks what you have, the answer already exists instead of being rebuilt by hand.
Insights
Empire Executive Protection Pty Ltd · ABN 30 622 627 034 · trading as Empire Protection
