Is your service desk audit ready? Get the report

Three governance frameworks moved in the last twelve months, and your service desk is holding the evidence for all of them.

We built a governance briefing that maps Jira Service Management (JSM) against CPS 230, the Essential Eight, and APRA's new expectations for AI governance. The amended CPS 230 and its practice guide CPG 230 commenced 1 July 2026. The Australian Prudential Regulation Authority wrote to every regulated entity on 30 April 2026 calling for a step change in AI risk management. Consultation on the next generation of the Essential Eight closed 12 July 2026. None of that is abstract if you run a service desk for a bank, an insurer, a government agency, or a critical infrastructure operator.

The briefing sets out where most JSM environments already have the right capability sitting unused, and where the genuine gaps are.

A preview of what the briefing covers:

  • Most of the control surface regulators expect, approval workflows, audit trails, change advisory board routing, already ships with JSM. The gap is almost always configuration discipline and process evidence.

  • Atlassian Intelligence and Rovo are switched on by default on most paid plans. Very few environments have an inventory of what is enabled or who owns it, which is precisely the first thing APRA's AI letter now asks a board to evidence.

  • Service level agreements (SLAs) are usually built around customer experience. The tolerance levels CPS 230 requires for critical operations rarely make it into that same configuration, so a genuine risk breach can happen without anyone noticing.

What's inside the full deck:

  • A slide by slide mapping of CPS 230 obligations to specific JSM configuration

  • The three Essential Eight strategies that sit directly on the service desk, and why the process evidence matters more than the technical control

  • APRA's four minimum expectations for AI governance, mapped to controls already available in Rovo Studio

  • The seven governance gaps we find most often across client environments, ranked by frequency

  • Where to act first, and how an assessment sequences the work

We cover these seven gaps in more depth here as well, if you want the detail before you decide whether to book anything.

Download the full deck and bring it to your next risk or audit committee conversation, or use it to start the discussion with your CIO (chief information officer).

If you would rather have a conversation first, book a JSM audit readiness assessment and we will scope it to the frameworks that actually apply to you.

John Mustac

John Mustac co-founded Systemology in 2012 and leads its sales and marketing. Before Systemology he spent nearly two decades in technology sales and marketing leadership, across senior sales, strategic alliance and management at some of Australia's leading technology companies. He now helps Australian enterprise and government organisations adopt Jira Service Management to run their IT and service operations, and hosts Systemology's JSM showcase series for IT leaders. He writes regularly on ITSM, enterprise service management, and the shift to agentic AI through Atlassian Rovo and Claude.

https://www.linkedin.com/in/jmustac/
Next
Next

How AI agents are changing your service desk - Systemology Customer Briefing Series - July 2026