Skip to content

Compliance

An RTO's Guide to the 2025 Standards for RTOs and Their IT Obligations in 2026

ASQA's 2025 Standards for RTOs replaced the 2015 Standards on 1 July 2025. What the audit teams now expect of your IT systems, your records and your retention.

12 min read
Jump to section
  1. 01 What the 2025 Standards changed for your IT
  2. 02 Records you have to keep, and for how long
  3. 03 Which parts of the Standards touch your IT
  4. 04 Systems most RTOs run, and where they fall down
  5. 05 When the 2025 Standards started, and what applies now
  6. 06 Software worth shortlisting under the 2025 Standards
  7. 07 Annual cost of running compliantly
  8. 08 What the CEO and the compliance officer need to be sure of
  9. 09 How we work with RTO clients, and where we stop
  10. 10 Primary sources

This is an IT operator’s view of the systems Australian registered training organisations (RTOs) use under the 2025 Standards for RTOs. It isn’t legal advice, a compliance opinion from the Australian Skills Quality Authority (ASQA), or a vocational education and training (VET) regulatory ruling. Whether any particular control satisfies your obligations is your compliance officer’s, your VET consultant’s, or ASQA’s call. We set up the systems. They sign off on whether it clears the bar.

The 2025 Standards have been in force since July last year, and the audit cycle is now well underway. The RTOs we work with are starting to see what ASQA asks for in practice. The gap between what the Standards say and what the audit team wants to see is wider on the IT side than most expected. Information management, recordkeeping and the systems behind quality assurance are all getting closer scrutiny than they did under the 2015 framework.

The shift is not radical, but it is real. The 2025 Standards expect an RTO to show, on demand, that the right person had access to the right record at the right time. They also expect you to show that training and assessment evidence has not been altered. Most RTOs we onboard built their systems for the 2015 audits, where evidence was a folder you handed over. In 2026 it is closer to a query you have to answer.

What the 2025 Standards changed for your IT

The 2025 Standards reorganised the obligations into a smaller set of principles-based outcomes, with practice guides explaining what compliance looks like. Three of the changes matter most for IT. Information-management expectations are tighter. Recordkeeping requirements are clearer, and assessment records must be retained for a minimum of two years. The third is a stronger emphasis on evidence integrity, which means proof that a record has not been changed since it was made.

The Standards do not name a technology. They are technology-neutral by design. ASQA does not tell you to use Microsoft 365, or any particular student management system (SMS), or any particular learning management system (LMS). It tells you the outcome it expects instead. You have to produce student records and assessment evidence on demand. The records have to be accurate and complete. They have to have been created in a controlled environment and kept for the required period. The outcomes are the obligation; the technology is the means.

Hitting those outcomes is hard without four things:

  • Sign-in and access, properly configured.
  • An SMS that logs who changed what, and when.
  • Backups you have tested by restoring from them.
  • Retention rules you have actually run, not just written.

Most RTOs have parts of this in place. The 2025 audit cycle is exposing where the parts do not connect.

Records you have to keep, and for how long

Assessment records are the evidence behind a qualification or a statement of attainment. They must be retained for a minimum of two years from the date of the assessment, and longer for some funded programs. Student records are the Unique Student Identifier (USI), the enrolment, the training plan and the results. They follow a longer retention period. It is set by the AVETMISS reporting framework, the national standard for VET data, and by the Higher Education Standards Framework. Trainer and assessor records cover qualifications, credentials and currency evidence. They must be retained while the trainer is active, and for a defined period after they leave.

For most RTOs, the retention obligations stack. One student record may be subject to a two-year minimum from one rule, and a five-year minimum under a state funding agreement. An active dispute adds an indefinite retention obligation on top. The system holding those records has to honour the longest rule that applies to each one. That is why retention labelling at the document level earns its cost, rather than blanket folder-level rules.

Practical example. A funded student completes a Diploma in November 2024. The two-year minimum says the assessment evidence can be deleted in November 2026. The state funding contract says retain for five years from completion: November 2029. The student lodges a dispute about an assessment outcome in January 2026. The dispute resolution doesn’t conclude until April 2027. The dispute now sets how long that record has to be kept, not the original calendar minimum. It is retained until the dispute is closed, plus whatever post-resolution window applies. An RTO using a flat retention rule deletes the record at the wrong time. An RTO using event-driven retention does not.

Which parts of the Standards touch your IT

Most of them, indirectly. The Standards covering information management, recordkeeping, governance and student support all assume an IT environment that works the way the principles describe. The clearest direct obligations are in the information management and recordkeeping standards. Governance and student support depend on IT too, in ways an audit will find.

The mapping we have found most useful with RTO clients is roughly this.

  • Information management and recordkeeping, plus the practice guide on Information: sign-in and access controls, retention labels, audit logging, backup and recovery testing, document-management discipline.
  • Governance, the standards covering how the RTO is run: change-management evidence and an incident-response process. Also vendor management for outsourced systems: the LMS, the SMS, proctoring and third-party assessors.
  • Student support and engagement, covering student information, training delivery and student welfare: the student-facing systems and the records they generate. That means the LMS, the student portal and the assessment portal.
  • Quality of training and assessment: the integrity of the assessment evidence, which means timestamps, version control and tamper-resistance. Also the link between trainer credentials and the units they assessed, and traceable moderation and validation records.

The 2015 Standards touched on most of this. They did not insist on evidence to the depth the 2025 Standards do. The shift is from “we have a policy” to “we can show the policy was followed”.

Systems most RTOs run, and where they fall down

A typical mid-size RTO runs a student management system, a learning management system, Microsoft 365 and an accounting system. Then there are point tools for credentialling, assessor management and proctoring. The SMS is usually aXcelerate, VETtrak, JobReady, Wisenet, RTOmanager or something similar. The LMS is usually Moodle, Canvas or Cloud Assess. The weak points cluster in three places.

First, the joins between systems. Where the SMS, LMS and Microsoft 365 have grown up separately over years, the connections between them are improvised. Spreadsheet exports, manual re-keying, and a handful of fragile automated feeds. Under the 2025 Standards, ASQA increasingly asks for a single answer to questions like “show me every record relating to this student”. An RTO with three disconnected systems can usually assemble that answer over a few hours. The 2025 audit cycle expects it inside the meeting.

Second, the access controls on the LMS and SMS. The default settings on the major SMS platforms tend to be relaxed, in favour of usability. Trainers often have access to records they no longer need. Ex-staff sometimes still have access months after they have gone.

Third, backup and recovery for the SMS and LMS. Most RTOs we onboard rely on the vendor’s backup schedule without ever having tested a restore. ASQA does not require a tested restore in so many words. But a recovery that fails during an audit period would expose the RTO to the loss-of-records part of the recordkeeping obligations.

USI checks and AVETMISS reporting have to agree

USI handling and AVETMISS reporting are where IT and compliance overlap, and they catch RTOs out. A USI has to be verified before a qualification is issued, and the evidence of that check has to be retained. AVETMISS submissions have to reconcile to the underlying student records. If the USI verification logs are in the SMS and the AVETMISS reporting comes out of a separate spreadsheet, you have a reconciliation problem. It is waiting for the next ASQA audit. The fix is integration discipline, not new software.

When the 2025 Standards started, and what applies now

The 2025 Standards commenced on 1 July 2025. The 2015 Standards continue to apply to compliance behaviour from before that date. ASQA has been clear that audits conducted from late 2025 onwards apply the 2025 Standards to current operations.

RTOs that did the work before commencement are now running the system they built. Those that decided to adjust as audits surfaced gaps are finding out now. The 2026 Annual Declaration on Compliance is where most RTOs are checking their operating position against the 2025 Standards in detail.

What the 2026 Annual Declaration asks you to sign

The 2026 Annual Declaration is an attestation to ASQA that the RTO has continued to comply with the Standards across the reporting period. Under the 2025 Standards, the wording has tightened. Providers are confirming their ongoing compliance with a more outcomes-focused framework. ASQA has indicated it will continue to use Annual Declarations as a trigger for audit-cycle activity where the responses suggest material compliance risk.

If the IT environment has not been re-checked against the 2025 Standards, the Declaration is where unattested gaps become attested gaps. Better to find and fix them before the Declaration than to sign an attestation that does not survive a follow-up audit.

Software worth shortlisting under the 2025 Standards

Three patterns are working for mid-size Australian RTOs under the 2025 Standards.

  • A well-integrated SMS with strong audit logging and a clear retention story. Some Australian SMS vendors have invested heavily in this since the new Standards came in. Others have not.
  • Microsoft 365 as the backbone, with proper identity controls, retention labels, conditional access and data loss prevention on the document store. Conditional access is the rule set that decides who can sign in, from where, and on what device. Wire that into the SMS and LMS rather than running it beside them.
  • A settled position on backup and recovery, including tested restores against both the SMS and the LMS at least annually.

The choice of SMS is the decision that matters most. An SMS that does not log changes at the field level cannot demonstrate “who changed what when” to ASQA’s satisfaction. An SMS with weak role-based access cannot limit each person to the records their job needs, which is what the Standards expect. RTOs due an SMS refresh should be evaluating against the 2025 Standards, not the 2015-era criteria most procurement processes still use.

Off-the-shelf versus custom build

There is no case for a custom-built SMS or LMS in an Australian RTO of the size we typically work with. The off-the-shelf market is mature, the vendors compete on features, and the cost of getting custom development wrong in a regulated environment is high. The decision is between off-the-shelf options, not between off-the-shelf and bespoke.

What is realistic is integration work: wiring the off-the-shelf SMS, LMS and Microsoft 365 together so the 2025 Standards can be operated against. That is where most of the real effort goes.

Microsoft 365 licensing for RTOs

If the RTO’s recordkeeping evidence relies on Microsoft 365 for retention labelling, audit logging and access control, and most RTOs do, the licence tier matters. Business Premium covers the basic retention and access-control features. E3 with the E5 Security add-on, or full E5, adds advanced auditing, eDiscovery and conditional-access features that audits increasingly look for. eDiscovery is the ability to search and export records for a legal or regulatory request. RTOs on Business Standard will struggle to produce the evidence the 2025 Standards imply.

The licence step-up is a real cost line. Take an RTO of 50 staff plus contracted trainers. The yearly difference between Business Premium and E3 plus E5 Security, across all named users, is meaningful. It should be modelled in the IT budget before the next audit cycle, not after.

Annual cost of running compliantly

For a 30-to-100-seat Australian RTO, running compliantly with the 2025 Standards typically costs 20,000 to 60,000 Australian dollars a year on the IT side. That covers software licensing, integration support, and backup-and-recovery discipline. A one-off catch-up project can be a multiple of that. It usually happens in the year an RTO faces a deferred SMS replacement, an integration project, or a major access-control rebuild.

What you pay depends most on the state of the existing environment. A recent SMS, a clean Microsoft 365 setup and a retention policy that is documented and actually run puts you at the lower end. An end-of-life SMS, Microsoft 365 with no retention labels and an undocumented backup schedule puts you at the higher end. That RTO usually needs a one-off catch-up project before the annual cost settles.

What the CEO and the compliance officer need to be sure of

The IT environment is now part of the compliance environment, in a way it was not under the 2015 Standards. The CEO needs to be confident that the IT systems will not produce a finding in the next audit. The compliance officer needs to be confident that the IT vendor, internal or external, understands the 2025 Standards well enough to turn them into configuration.

That confidence comes down to two things. First, a walk-through of the IT environment against the 2025 Standards before the next ASQA contact, with the gaps written down and the fixes scheduled. Second, a standing operational discipline. Monthly access reviews, quarterly retention-policy checks, annual backup-restore testing, and a documented change-management process for SMS, LMS or Microsoft 365 changes that affect compliance evidence.

How we work with RTO clients, and where we stop

We do not interpret the Standards. We set up the IT systems an RTO needs to operate compliantly against them, and we keep those systems audit-ready.

For an RTO client, the work usually breaks into three streams.

  • Microsoft 365: identity, retention labels, conditional access, audit logging, and the licence uplift where the current tier cannot produce what an audit asks for.
  • SMS and LMS: configuration, integration, access-control review, and the recovery testing that turns a vendor backup into something you can prove works.
  • Evidence: making sure every claim the RTO makes in its compliance documentation can be backed by audit-grade evidence from the IT environment.

Interpreting the Standards stays with the RTO’s compliance officer and its VET consultant. So does the design of the compliance framework, and the call on whether a particular control satisfies a particular Standard. Our boundary is explicit. We handle the machinery. They handle the interpretation.

RTOs that did the catch-up work in late 2025 are now in a steady operational rhythm. RTOs that deferred it are increasingly hitting it in the lead-up to the 2026 Annual Declaration. The window to fix things without outside pressure is shorter than it was a year ago.

Primary sources

Tags complianceasqartostandards-for-rtosvet-sector
Share LinkedIn Email
See if we're a fit