JSM GOVERNANCE AND AUDIT READINESS

7 governance gaps putting your service desk at audit risk

CPS 230, the Essential Eight, and APRA's AI governance expectations have all moved in the last twelve months. These are the seven configuration gaps we find most often when we review a Jira Service Management environment against them, and none of them require new software to fix.

Gold

ATLASSIAN GOLD PARTNER

Government

APPROVED PANEL SUPPLIER

Since 2012

JSM SPECIALIST, BASED IN SYDNEY

WHY THIS MATTER NOW

Three frameworks moved in the last twelve months

The amended CPS 230 and its practice guide CPG 230 commenced on 1 July 2026. The Australian Prudential Regulation Authority (APRA) wrote to every regulated entity on 30 April 2026 calling for a step change in AI risk management. Consultation on the next generation of the Essential Eight, run by the Australian Signals Directorate (ASD), closed on 12 July 2026. Three frameworks, one service desk holding the evidence for all of them.

OCPS 230

APRA regulated entities

Banks, insurers, and superannuation trustees, plus their material service providers through mandated contract clauses.

ESSENTIAL EIGHT

Government agencies

Federal and state agencies working to Essential Eight maturity targets set by the Australian Signals Directorate.

SOCI ACT

Critical infrastructure operators

Energy, water, health, transport, and communications operators under the Security of Critical Infrastructure Act.

SOCI ACT

Any organisation using AI

Board level scrutiny of AI in the service desk now applies wherever Atlassian Intelligence or Rovo is switched on.

QUICK SUMMARY

The 7 gaps at a glance

Jump to any gap below, or read the full detail in order.

THE 7 GAPS

The 7 governance gaps we find most often in Jira Service Management

Ordered by how often they appear during a review. Every one of them is findable, and fixable, before an auditor or assessor finds it first.

AI GOVERNANCE

Is Atlassian Intelligence switched on with nobody accountable for it?

Atlassian Intelligence and Rovo features are enabled by default on most paid plans. Many service desks are running them with no inventory of what is enabled, no policy on what data they can touch, and no named owner.

The fix in JSM: an org wide agent inventory in Rovo Studio, with AI enabled or disabled per product and named ownership for every agent.

Relevant if: your organisation uses Atlassian Intelligence or Rovo in any capacity, regardless of sector.

CPS 230

ESSENTIAL EIGHT

Could your organisation prove what happened in an incident six months ago?

The organisation audit log is rarely streamed anywhere for long term retention. Native retention windows are finite, so evidence that must survive a full audit cycle often expires before anyone needs it.

The fix in JSM: Atlassian Guard streaming the organisation and automation audit logs to a security monitoring platform for retention that matches your audit cycle

Relevant if: you are subject to CPS 230, Essential Eight assessment, or any external audit with a retrospective evidence requirement.

CPS 230

When did anyone last check your auto approval rules still make sense?

Automation rules that auto approve standard changes are frequently left untouched since the day they were built, with no documented review cycle to confirm they still reflect an acceptable level of risk.

The fix in JSM: a scheduled, evidenced review cycle for every auto approval rule, owned by a named person.

Relevant if: you run change advisory board workflows or auto approval rules for standard changes.

CPS 230

Do you have a current register of every vendor a regulator would call material?

CPS 230 requires a register of material service providers with mandated contract clauses and visibility into fourth party dependencies. Many organisations either never built one, or built it once and let it go stale.

The fix in JSM: an Assets schema for material service providers, with contract clauses, review dates, and fourth party links kept current by scheduled automation.

Relevant if: you are an APRA regulated entity, or a vendor under contract to one.

CPS 230

Would you know the moment a service breached its risk tolerance?

Most service desks configure service level agreements (SLAs) around customer experience targets. The tolerance levels set for critical operations under CPS 230 rarely make it into that same configuration, so a genuine tolerance breach can happen without anyone noticing.

The fix in JSM: SLAs mapped directly to CPS 230 tolerance levels, with breach alerts and reporting per critical operation.

Relevant if: you have identified critical operations under CPS 230 and set tolerance levels for them.

ESSENTIAL EIGHT

Can you prove privileged access was validated before it was granted?

Privileged access is often granted through general request types with no dedicated validation step, which fails the Essential Eight on process evidence even where the technical access control itself is sound.

The fix in JSM: a dedicated request type for privileged access, with a justification field, an approval trail, and recurring recertification.

Relevant if: you are being assessed against Essential Eight Maturity Level 1 or higher.

AI GOVERNANCE

CPS 230

Is any automation rule making a consequential decision that nobody owns?

Automation rules can end up routing, approving, or escalating consequential decisions with no owner and no scheduled review, which is exactly the lifecycle accountability gap regulators are now asking boards to close.

The fix in JSM: an ownership and review register covering every automation rule that makes a consequential decision, including rules that have nothing to do with AI.

Relevant if: you run Jira automation for approvals, routing, or escalation of any kind.

TAKE IT WITH YOU

Download the governance briefing deck

All seven gaps, the full CPS 230 and Essential Eight mapping, and the AI governance controls, in one deck you can bring to your next risk or audit committee conversation.

CLOSE THE GAPS

A JSM audit readiness assessment, shaped to your framework

One fixed core review, plus modules selected for the frameworks that actually apply to your organisation. Nobody pays for a CPS 230 review if they have no APRA exposure.

CORE ASSESSMENT, ALWAYS INCLUDED

The baseline every client gets

A structured review of your workflow and approval configuration, audit trail setup, Assets schema, and automation rule inventory, backed by interviews with your service desk lead and your security or compliance lead.

Workflow and approval configuration review
Assets schema and configuration item coverage
Gap report rated by audit exposure

Audit trail and Atlassian Guard configuration review
Automation rule inventory, ownership, and review history
Prioritised remediation roadmap

MODULE

CPS 230 & operational risk

Critical operations, tolerance levels, the 72 hour notification workflow, and the material service provider register.

MODULE

Essential Eight process evidence

Privileged access validation, patch and vulnerability SLA timers, and control ruleset review evidence.

MODULE

AI governance

AI enablement, agent inventory, audit logging, and data residency, mapped against APRA's four minimum expectations.

MODULE

Critical infrastructure and SOCI

Critical asset mapping, incident and risk management program evidence, and supply chain visibility.

A simple path from booking to remediation roadmap

Empty gray arrow pointing to the right on a white background.
A long empty gray arrow pointing to the right.
A black and white ruler with a right arrow

1

Scoping call

Confirm which modules apply and agree access requirements and the interview list.

2

Discovery and review

Environment access, configuration review, and structured interviews against the core and selected modules.

3

Gap analysis

Every finding rated by audit exposure: high, medium, or low.

4

Report and readout

The gap report and remediation roadmap, walked through with your team before it is left with you.

WHY SYSTEMOLOGY

Depth beats breadth in service management

Other partners spread across the Atlassian suite. Jira Service Management is the whole of our practice. Every consultant, every engagement, and every methodology is built around it. We assess and remediate governance controls inside real ITSM workflows, with the change control and approval discipline enterprise and government environments require.

Our team is based in Sydney with no offshore delivery. The engineers who scope your assessment are the same engineers who deliver the remediation work.

On governance, our service management background is the difference. We bring compliance context, audit thinking, and approval design a generalist security consultancy typically lacks.

What sets the work apart

  • A review scoped to your actual environment and configuration, run against your real risk.

  • Delivered directly by engineers, with no account managers and no offshore handoff.

  • Findings sequenced by the exposure they actually carry.

  • A roadmap you can act on the moment the assessment ends.

COMMON QUESTIONS

Before you book

Does CPS 230 apply to us if we are not a bank?

CPS 230 is issued by the Australian Prudential Regulation Authority and applies directly to banks, insurers, and superannuation trustees. It also reaches vendors and service providers under contract to those entities, since CPS 230 requires mandated audit and security clauses to be pushed down into supplier contracts.


What is Essential Eight Maturity Level 2?

Maturity Level 2 is the second of four levels in the Essential Eight maturity model run by the Australian Signals Directorate. It introduces recurring, timestamped process requirements, such as scheduled revalidation of privileged access and a 48 hour patching window for critical vulnerabilities on internet facing assets.


Do we need to buy new software to close these gaps?

No. Most of the control surface CPS 230 and the Essential Eight expect already exists inside Jira Service Management. The gap is almost always configuration discipline and process evidence.


How is this different from a security audit?

A security audit typically tests technical controls such as firewalls, patching, and access management directly. This assessment is scoped to your Jira Service Management configuration specifically: the approval workflows, audit trails, and AI controls that produce the process evidence an auditor or assessor will ask for.


GET STARTED

Book an assessment

Tell us which frameworks apply to you and we will scope the right modules.