Compliance‑native, by construction.

BackPro is designed to align with the standards Australian regulators publish. Controls testable. Evidence packaged. Audit trail captured for you. None of this happens at the end of the quarter, all of it happens as you work.

Aligned withAPRA·ASIC·AUSTRAC·OAIC·AASB

Six standards. One framework.

The standards Australian regulators care about most. BackPro is designed to align with each, and the controls map across the lot, so an obligation answered once is an obligation answered for every standard it touches.

APRAIn force 1 Jul 2025
CPS 230
Operational Risk Management

APRA's prudential standard for managing operational risk. Sets requirements for critical operations, third‑party arrangements, and business continuity.

  • Critical operations register
  • Notifiable operational risk events (§ 36)
  • Third‑party risk assessment
  • Business continuity planning
  • Operational risk control testing
See CPS 230 in depth
APRAIn force since 2019
CPS 234
Information Security

APRA's prudential standard requiring information security capability commensurate with the size and extent of threats to information assets.

  • Information asset register
  • Information security capability
  • Implementation of controls
  • Incident detection and response
  • Notification and internal audit
See CPS 234 in depth
AASBEffective 1 Jan 2025
AASB S1 & S2
Sustainability and Climate Disclosures

Australian sustainability‑related financial disclosure standards. Aligns Australian reporting with IFRS S1 and S2 climate disclosure rules.

  • Sustainability‑related financial risks
  • Climate‑related risks and opportunities
  • Scope 1, 2 & 3 emissions tracking
  • Transition plan documentation
  • Governance and strategy disclosures
See AASB S1 & S2 in depth
AUSTRAC
AML/CTF
AML and Counter‑Terrorism Financing

AUSTRAC's anti‑money laundering and counter‑terrorism financing regime. Customer due diligence, ongoing monitoring, and reporting obligations.

  • Customer due diligence (CDD / ECDD)
  • Ongoing customer monitoring
  • Suspicious matter reporting (SMR)
  • Sanctions screening
  • International funds transfer instructions
See AML/CTF in depth
OAIC
APP 11
Security of Personal Information

Australian Privacy Principle 11 under the Privacy Act 1988, the security obligation for personal information held by an APP entity.

  • Personal information inventory
  • Reasonable security steps
  • Privacy impact assessments
  • Notifiable Data Breach scheme (Pt IIIC)
  • Access and rectification rights
See APP 11 in depth
ASICIn effect since Oct 2021
RG 271
Internal Dispute Resolution

ASIC's Regulatory Guide 271 setting standards for internal dispute resolution by financial firms.

  • Complaint registration
  • Acknowledgement timeframes
  • Response and resolution
  • Final response (RG 271 standard)
  • IDR data reporting
See RG 271 in depth

Where your data lives.

BackPro runs inside your Microsoft 365 tenancy. Open‑weight models, retrieval index, and audit log all sit on infrastructure you control. Data sources are read on demand; outputs land in your storage. Nothing crosses the boundary: by design, not by promise.

The diagram on the right is the deployment topology for a typical BackPro install. Your specific architecture is finalised in a forty‑five‑minute technical review.

⊟ Your tenancyVPC · region of your choice
Data sources you control
SharePoint · M365 Graph · OneDrive · Xero · XPLAN · Worksorted · MYOB · …

Read on demand, scoped to identities you nominate.

BackPro runtime
Open‑weight models · Retrieval index · Audit log · Identity SSO

Runs on your compute. Weights pinned. Audit log WORM‑eligible.

Audit‑ready outputs
Evidence pack · Audit trail · Regulator report · Board pack draft

Hashed, signed, timestamped. Stored in your storage account.

⊘ No egress. Nothing crosses this boundary.
Typical deployment topology. Your tenancy, your data, your audit log. Specific deployment diagram is provided as part of the technical review.