Compliance‑native, by construction.
BackPro is designed to align with the standards Australian regulators publish. Controls testable. Evidence packaged. Audit trail captured for you. None of this happens at the end of the quarter, all of it happens as you work.
Six standards. One framework.
The standards Australian regulators care about most. BackPro is designed to align with each, and the controls map across the lot, so an obligation answered once is an obligation answered for every standard it touches.
APRA's prudential standard for managing operational risk. Sets requirements for critical operations, third‑party arrangements, and business continuity.
- Critical operations register
- Notifiable operational risk events (§ 36)
- Third‑party risk assessment
- Business continuity planning
- Operational risk control testing
APRA's prudential standard requiring information security capability commensurate with the size and extent of threats to information assets.
- Information asset register
- Information security capability
- Implementation of controls
- Incident detection and response
- Notification and internal audit
Australian sustainability‑related financial disclosure standards. Aligns Australian reporting with IFRS S1 and S2 climate disclosure rules.
- Sustainability‑related financial risks
- Climate‑related risks and opportunities
- Scope 1, 2 & 3 emissions tracking
- Transition plan documentation
- Governance and strategy disclosures
AUSTRAC's anti‑money laundering and counter‑terrorism financing regime. Customer due diligence, ongoing monitoring, and reporting obligations.
- Customer due diligence (CDD / ECDD)
- Ongoing customer monitoring
- Suspicious matter reporting (SMR)
- Sanctions screening
- International funds transfer instructions
Australian Privacy Principle 11 under the Privacy Act 1988, the security obligation for personal information held by an APP entity.
- Personal information inventory
- Reasonable security steps
- Privacy impact assessments
- Notifiable Data Breach scheme (Pt IIIC)
- Access and rectification rights
ASIC's Regulatory Guide 271 setting standards for internal dispute resolution by financial firms.
- Complaint registration
- Acknowledgement timeframes
- Response and resolution
- Final response (RG 271 standard)
- IDR data reporting
Where your data lives.
BackPro runs inside your Microsoft 365 tenancy. Open‑weight models, retrieval index, and audit log all sit on infrastructure you control. Data sources are read on demand; outputs land in your storage. Nothing crosses the boundary: by design, not by promise.
The diagram on the right is the deployment topology for a typical BackPro install. Your specific architecture is finalised in a forty‑five‑minute technical review.
Read on demand, scoped to identities you nominate.
Runs on your compute. Weights pinned. Audit log WORM‑eligible.
Hashed, signed, timestamped. Stored in your storage account.