RFFR Compliance,
Done Properly.
Risk Ninja is the only GRC platform engineered from the ground up for the Department of Employment and Workplace Relations (DEWR) Right Fit For Risk programme — with direct sync to your Statement of Applicability spreadsheet.
RFFR Isn't Just Another Framework
Right Fit For Risk weaves together the Essential Eight, the ACSC Information Security Manual and ISO 27001 — then layers in DEWR's specific obligations and a Statement of Applicability spreadsheet that has to stay perfectly in step with your evidence. Generic GRC tooling treats those as three separate jobs. Risk Ninja treats them as one.
Built for DEWR Assessors
Designed against the actual RFFR assessment rubric — not retrofitted from a generic ISO 27001 product.
Native SoA Sync
Two-way sync between the platform and the DEWR Statement of Applicability spreadsheet — formatting and formulas preserved.
Three Frameworks, One View
Essential Eight, ISM and ISO 27001 surfaced as a single RFFR meta-framework. Update once, comply everywhere.
Defensible at Assessment Time
Evidence-backed compliance enforcement means assessors see the artefact, not just the tick.
The RFFR Meta-Framework
Every Essential Eight maturity level, every ISM control and every ISO 27001 Annex A control rolls up into a single RFFR posture — with the DEWR obligations tracked alongside.
One Workspace, Every RFFR Requirement
Risk Ninja's RFFR meta-framework page groups all of your in-scope frameworks into one assessor-ready workspace. Cross-framework mapping means a control implemented for ISM is automatically credited against Essential Eight and ISO 27001 where the mapping exists — you don't pay the implementation cost three times.
- ACSC Essential Eight with full maturity-level (ML1 / ML2 / ML3) tracking and target ML selection
- ACSC Information Security Manual — June 2026 control set loaded, with ISM classification scope so you are measured only against controls for the classifications you actually handle
- ISO 27001:2022 Annex A with implementation-status vocabulary
- E8 ↔ ISM compliance sync with daily reconciliation and weakest-sibling conflict resolution
- Seven DEWR RFFR obligations tracked with named Person Responsible per obligation
RFFR Meta-Framework
Sync Straight to the DEWR Spreadsheet
The Statement of Applicability stops being a shadow copy you have to maintain by hand. Risk Ninja exports directly into the official DEWR spreadsheet, preserving formatting, formulas, tabs and structure — so what your team sees in the platform is exactly what the assessor sees in the workbook.
Preview Before You Commit
A four-step modal walks the operator through every row that will be written, every unmatched control identifier, and every cell that will change — before a single byte goes near the file.
Description, Status, Notes, Owner
Risk Ninja writes the four fields that matter on each control row, matched on Control Identifier — no copy-paste, no broken references, no lost formatting.
One-Click Transfers
Per-widget Transfer buttons on the RFFR page push current ISM, E8 and ISO 27001 status to the SoA spreadsheet in seconds — ready for the next DEWR submission.
Audit-Trailed
Every transfer is logged with who, what, when. When DEWR asks how a control moved from Partial to Compliant, the answer is one click away.
AI That Reads Like Your CISO Wrote It
Risk Ninja's AI features are tuned for Australian cyber regulation, written in Australian English, and instructed not to hallucinate. They accelerate the work your team is already doing — they don't replace the judgement that DEWR is going to test.
Executive Risk Narrative
An AI-drafted, five-section, board-grade report for your CEO and executive leadership. Edit, approve, lock and download as a branded PDF — with the data snapshot frozen for future defensibility.
Hattori AI Chat
A streaming assistant that knows your risks, findings, controls, treatment plans and frameworks — ready to answer assessor-style questions while you draft your SoA.
What Next Gap Analysis
AI-driven maturity gap analysis and remediation roadmap for E8, ISM and ISO 27001 — the three frameworks that decide your RFFR outcome.
Suggest Owners & Controls
AI nominates likely control owners and suggests treatment controls when you draft a new risk — with a guardrail so BCP/DR never gets confused with Backups.
AI Vendor Response Review
AI reads a supplier's questionnaire answers and proposes flags, a rating and candidate findings, so supplier assurance keeps pace with the rest of your RFFR work. Advisory only — you accept, edit or dismiss every suggestion.
Transparent AI Credits
AI use is metered against a daily organisation-wide allowance, with the balance shown on the Overview and an AI Usage Report broken down by feature and by user. Nothing about how AI was used is hidden.
Define What Matters — Then Defend It
Your participant data, your DEWR portal access, your case-management systems — that's what RFFR is actually about protecting. Risk Ninja gives you a place to define those crown jewels and a structured lifecycle for keeping them safe.
Scoped Risk Registers
Organise risk registers around your crown jewels. Each register carries its own risks, treatment plans, owners and approvals — with a complete audit trail of who changed what and when.
Many-to-Many Treatment Plans
A single mitigation can defend several crown jewels at once. Risk Ninja models treatment plans the way your team actually works — one plan, many linked risks.
Evidence-Gated Compliance
You can't mark a control Compliant or Implemented on an auditable framework without a non-expired evidence artefact. Bypasses are recorded with a warning that the audit will fail.
Cross-Framework Impact Assessment
Change a control status in one framework and see immediately which other frameworks — and which crown-jewel registers — are affected. No more silent compliance regressions.
My Work: One Ranked Queue
Overdue items, assignments, approvals and risk acceptance decisions — findings, evidence renewals, treatment plans, vendor follow-ups — in one ranked queue that says why each matters, so nothing slips before assessment day.
Daily Compliance Snapshots
Compliance posture for every framework is snapshotted daily, with trend charts so you can show DEWR a defensible trajectory — not just a single-point-in-time score.
Suppliers, Dependencies and Live Checks
RFFR posture depends on more than your own control statuses. Risk Ninja assesses the providers you rely on, maps how findings, controls and risks connect, and automatically checks your Microsoft 365 tenant against Essential Eight and ISM controls.
Third Party Risk Management
Tier the providers your services depend on, send security questionnaires by secure link, and turn gaps into findings linked to the risks they feed. Supplier findings are held apart from your own compliance figures, so they never distort your posture.
Relationship Map
When a pen test breaks a control, see every risk that relied on it. Trace findings, controls, risks, treatment plans and suppliers on one canvas — and show exactly why a remediation was prioritised.
Automated Microsoft 365 Checks
Microsoft Control Assurance, a read-only connector, checks your Microsoft 365 tenant daily — MFA coverage, administrator account hygiene and more — against Essential Eight and ISM controls. It corroborates or contradicts your assessment; it never changes it.
Why Heads of IT Choose Risk Ninja for RFFR
If you're carrying RFFR for your employment services organisation, you're juggling DEWR timelines, internal audit, executive reporting and a delivery roadmap that's already full. Here's what changes when RFFR runs on Risk Ninja.
You Stop Maintaining the SoA by Hand
The spreadsheet stays canonical for DEWR. The work happens in the platform. The two stay in sync.
You Walk Into Assessment Audit-Ready
Evidence on every Compliant control, version-locked executive narrative, daily compliance snapshots, every change captured in the audit log.
AI Drafts, You Decide
No AI feature writes to a register, sets a rating or creates a finding on its own. Every suggestion is yours to accept, edit or dismiss — and every credit is metered and reported.
Your Team Shares the Load
Named Person Responsible per RFFR obligation, per-control owners, role-based visibility, and My Work making sure nobody's plate is invisible.
Need a Framework We Don't Have Yet?
Risk Ninja already ships with 30+ frameworks — but if your organisation needs a standard or framework we haven't built yet, we'll add it on request. Sector regulations, internal control catalogues, customer-specific control sets — ask us and we'll get it into the platform for you.
Request a FrameworkWalk Into Your Next RFFR Assessment With Confidence
Book a tailored RFFR demo. We'll show you the meta-framework, the SoA sync, the executive narrative and the Relationship Map — with your DEWR timeline in mind.