The baseline is already in every CCP plan. Multi-factor authentication, application control, vulnerability management, tested backups and offboarding discipline cover the core of what a financial-services questionnaire asks about. Where a specific regime applies, we add the extra controls for your engagement. AUSTRAC enrolment, ASIC market-participant obligations and an APRA-regulated parent are the three we see most.
Compliance is an overlay, not a plan tier. The Managed IT + Compliance plan exists for practices that need the overlay running continuously, with evidence generation and reporting as an ongoing service. Simpler obligations can run on the baseline plan, with overlays added where a regulator or a client makes them necessary.
Some of it stays with you. Regulatory interpretation, formal compliance sign-off, and the work a Responsible Manager owns under your licence or registration. We bring the IT and compliance capability most practices cannot resource internally, alongside the people who own the regulatory substance.