JSM GOVERNANCE AND AUDIT READINESS
7 governance gaps putting your service desk at audit risk
CPS 230, the Essential Eight, and APRA's AI governance expectations have all moved in the last twelve months. These are the seven configuration gaps we find most often when we review a Jira Service Management environment against them, and none of them require new software to fix.
Gold
ATLASSIAN GOLD PARTNER
Government
APPROVED PANEL SUPPLIER
Since 2012
JSM SPECIALIST, BASED IN SYDNEY
WHY THIS MATTER NOW
Three frameworks moved in the last twelve months
The amended CPS 230 and its practice guide CPG 230 commenced on 1 July 2026. The Australian Prudential Regulation Authority (APRA) wrote to every regulated entity on 30 April 2026 calling for a step change in AI risk management. Consultation on the next generation of the Essential Eight, run by the Australian Signals Directorate (ASD), closed on 12 July 2026. Three frameworks, one service desk holding the evidence for all of them.
OCPS 230
APRA regulated entities
Banks, insurers, and superannuation trustees, plus their material service providers through mandated contract clauses.
ESSENTIAL EIGHT
Government agencies
Federal and state agencies working to Essential Eight maturity targets set by the Australian Signals Directorate.
SOCI ACT
Critical infrastructure operators
Energy, water, health, transport, and communications operators under the Security of Critical Infrastructure Act.
SOCI ACT
Any organisation using AI
Board level scrutiny of AI in the service desk now applies wherever Atlassian Intelligence or Rovo is switched on.
QUICK SUMMARY
The 7 gaps at a glance
Jump to any gap below, or read the full detail in order.
THE 7 GAPS
The 7 governance gaps we find most often in Jira Service Management
Ordered by how often they appear during a review. Every one of them is findable, and fixable, before an auditor or assessor finds it first.
AI GOVERNANCE
Is Atlassian Intelligence switched on with nobody accountable for it?
Atlassian Intelligence and Rovo features are enabled by default on most paid plans. Many service desks are running them with no inventory of what is enabled, no policy on what data they can touch, and no named owner.
The fix in JSM: an org wide agent inventory in Rovo Studio, with AI enabled or disabled per product and named ownership for every agent.
Relevant if: your organisation uses Atlassian Intelligence or Rovo in any capacity, regardless of sector.
CPS 230
ESSENTIAL EIGHT
Could your organisation prove what happened in an incident six months ago?
The organisation audit log is rarely streamed anywhere for long term retention. Native retention windows are finite, so evidence that must survive a full audit cycle often expires before anyone needs it.
The fix in JSM: Atlassian Guard streaming the organisation and automation audit logs to a security monitoring platform for retention that matches your audit cycle
Relevant if: you are subject to CPS 230, Essential Eight assessment, or any external audit with a retrospective evidence requirement.
CPS 230
When did anyone last check your auto approval rules still make sense?
Automation rules that auto approve standard changes are frequently left untouched since the day they were built, with no documented review cycle to confirm they still reflect an acceptable level of risk.
The fix in JSM: a scheduled, evidenced review cycle for every auto approval rule, owned by a named person.
Relevant if: you run change advisory board workflows or auto approval rules for standard changes.
CPS 230
Do you have a current register of every vendor a regulator would call material?
CPS 230 requires a register of material service providers with mandated contract clauses and visibility into fourth party dependencies. Many organisations either never built one, or built it once and let it go stale.
The fix in JSM: an Assets schema for material service providers, with contract clauses, review dates, and fourth party links kept current by scheduled automation.
Relevant if: you are an APRA regulated entity, or a vendor under contract to one.
CPS 230
Would you know the moment a service breached its risk tolerance?
Most service desks configure service level agreements (SLAs) around customer experience targets. The tolerance levels set for critical operations under CPS 230 rarely make it into that same configuration, so a genuine tolerance breach can happen without anyone noticing.
The fix in JSM: SLAs mapped directly to CPS 230 tolerance levels, with breach alerts and reporting per critical operation.
Relevant if: you have identified critical operations under CPS 230 and set tolerance levels for them.
ESSENTIAL EIGHT
Can you prove privileged access was validated before it was granted?
Privileged access is often granted through general request types with no dedicated validation step, which fails the Essential Eight on process evidence even where the technical access control itself is sound.
The fix in JSM: a dedicated request type for privileged access, with a justification field, an approval trail, and recurring recertification.
Relevant if: you are being assessed against Essential Eight Maturity Level 1 or higher.
AI GOVERNANCE
CPS 230
Is any automation rule making a consequential decision that nobody owns?
Automation rules can end up routing, approving, or escalating consequential decisions with no owner and no scheduled review, which is exactly the lifecycle accountability gap regulators are now asking boards to close.
The fix in JSM: an ownership and review register covering every automation rule that makes a consequential decision, including rules that have nothing to do with AI.
Relevant if: you run Jira automation for approvals, routing, or escalation of any kind.
TAKE IT WITH YOU
Download the governance briefing deck
All seven gaps, the full CPS 230 and Essential Eight mapping, and the AI governance controls, in one deck you can bring to your next risk or audit committee conversation.
CLOSE THE GAPS
A JSM audit readiness assessment, shaped to your framework
One fixed core review, plus modules selected for the frameworks that actually apply to your organisation. Nobody pays for a CPS 230 review if they have no APRA exposure.
CORE ASSESSMENT, ALWAYS INCLUDED
The baseline every client gets
A structured review of your workflow and approval configuration, audit trail setup, Assets schema, and automation rule inventory, backed by interviews with your service desk lead and your security or compliance lead.
☑ Workflow and approval configuration review
☑ Assets schema and configuration item coverage
☑ Gap report rated by audit exposure
☑ Audit trail and Atlassian Guard configuration review
☑ Automation rule inventory, ownership, and review history
☑ Prioritised remediation roadmap
MODULE
CPS 230 & operational risk
Critical operations, tolerance levels, the 72 hour notification workflow, and the material service provider register.
MODULE
Essential Eight process evidence
Privileged access validation, patch and vulnerability SLA timers, and control ruleset review evidence.
MODULE
AI governance
AI enablement, agent inventory, audit logging, and data residency, mapped against APRA's four minimum expectations.
MODULE
Critical infrastructure and SOCI
Critical asset mapping, incident and risk management program evidence, and supply chain visibility.
A simple path from booking to remediation roadmap
1
Scoping call
Confirm which modules apply and agree access requirements and the interview list.
2
Discovery and review
Environment access, configuration review, and structured interviews against the core and selected modules.
3
Gap analysis
Every finding rated by audit exposure: high, medium, or low.
4
Report and readout
The gap report and remediation roadmap, walked through with your team before it is left with you.
WHY SYSTEMOLOGY
Depth beats breadth in service management
Other partners spread across the Atlassian suite. Jira Service Management is the whole of our practice. Every consultant, every engagement, and every methodology is built around it. We assess and remediate governance controls inside real ITSM workflows, with the change control and approval discipline enterprise and government environments require.
Our team is based in Sydney with no offshore delivery. The engineers who scope your assessment are the same engineers who deliver the remediation work.
On governance, our service management background is the difference. We bring compliance context, audit thinking, and approval design a generalist security consultancy typically lacks.
What sets the work apart
A review scoped to your actual environment and configuration, run against your real risk.
Delivered directly by engineers, with no account managers and no offshore handoff.
Findings sequenced by the exposure they actually carry.
A roadmap you can act on the moment the assessment ends.
COMMON QUESTIONS
Before you book
Does CPS 230 apply to us if we are not a bank?
CPS 230 is issued by the Australian Prudential Regulation Authority and applies directly to banks, insurers, and superannuation trustees. It also reaches vendors and service providers under contract to those entities, since CPS 230 requires mandated audit and security clauses to be pushed down into supplier contracts.
What is Essential Eight Maturity Level 2?
Maturity Level 2 is the second of four levels in the Essential Eight maturity model run by the Australian Signals Directorate. It introduces recurring, timestamped process requirements, such as scheduled revalidation of privileged access and a 48 hour patching window for critical vulnerabilities on internet facing assets.
Do we need to buy new software to close these gaps?
No. Most of the control surface CPS 230 and the Essential Eight expect already exists inside Jira Service Management. The gap is almost always configuration discipline and process evidence.
How is this different from a security audit?
A security audit typically tests technical controls such as firewalls, patching, and access management directly. This assessment is scoped to your Jira Service Management configuration specifically: the approval workflows, audit trails, and AI controls that produce the process evidence an auditor or assessor will ask for.
GET STARTED
Book an assessment
Tell us which frameworks apply to you and we will scope the right modules.