Transcription for Australian Government: IRAP, the ISM, and What Buyers Actually Ask
If you're evaluating us for government work, you'll have a familiar list of questions about where data goes and who assessed the controls. This is our attempt to answer all of them up front — including the ones where the answer is simply no. Nobody enjoys discovering that in week three.
First, the vocabulary — because these terms get muddled
The ISM is the Australian Government Information Security Manual, published by the Australian Signals Directorate. It is the control framework Commonwealth entities work to.
IRAP is the Infosec Registered Assessors Program. IRAP assessors are endorsed by ASD to evaluate a system's implementation of ISM controls and produce a report. IRAP is an assessment, not a certification — the assessor documents the security posture and residual risks, and the government entity's own authorising officer decides whether to accept that risk for their use.
This distinction matters and is widely misunderstood. Vendors describing themselves as 'IRAP certified' are using language that does not exist. The accurate phrasing is that a system has been IRAP assessed to a particular classification level, on a particular date, against a particular scope.
ISO 27001 is a different thing entirely, and the two get conflated constantly. ISO 27001 is an international standard for an information security management system, certified by an accredited certification body. IRAP is an Australian assessment of a system against the ISM, performed by an ASD-endorsed assessor. Neither is a prerequisite for the other: you can hold ISO 27001 without ever having an IRAP assessment, and you can be IRAP assessed without ISO 27001. An IRAP assessment does not confer ISO 27001, and ISO 27001 does not shorten the list of ISM controls an assessor will look at.
The two do overlap in evidence — an organisation running a mature ISMS will usually have much of the documentation an IRAP assessor asks for already written. That is a practical convenience, not a formal relationship, and it is worth being precise about when a tender asks for one and a vendor offers the other.
Classification levels run from OFFICIAL through OFFICIAL: Sensitive to PROTECTED and above. Most day-to-day government business is OFFICIAL or OFFICIAL: Sensitive. PROTECTED and above carry substantially heavier requirements.
Where we stand
Australian Transcription has not undergone an IRAP assessment, is not listed on any ASD or Digital Transformation Agency register of assessed services, and has no IRAP assessment planned. If IRAP is your requirement, that is the answer and the rest of this section will not change it.
Separately, and unrelatedly: we do not currently hold ISO 27001 or SOC 2. ISO 27001 is something we are actively working towards, but it is not close enough that you should plan around it — treat it as absent until we say otherwise on this page. To be explicit, because these two get bundled together: that ISO work is not a step towards IRAP and will not produce an IRAP assessment.
We'd rather lead with that than have you find out later. If your requirement is an IRAP-assessed service at PROTECTED, we're not a candidate, and you should shortlist providers who are — no hard feelings.
What we can offer is a short, checkable set of facts about how the service actually works. In our experience that's usually what the question underneath the tender language is really getting at.
| Question | Answer |
|---|---|
| Where is audio processed? | AWS ap-southeast-2 (Sydney), exclusively |
| Is data transferred offshore? | No |
| Does a human listen to audio? | No — fully automated |
| Is audio retained? | Source audio deleted after processing |
| Is data used to train models? | No |
| IRAP assessed? (ASD / ISM) | No, and none planned |
| ISO 27001 / SOC 2? (separate scheme, not an IRAP path) | No — ISO 27001 in progress, no date |
| Underlying infrastructure | AWS, which holds its own assessments |
Do not inherit assurance you do not have
AWS regions hold their own certifications and IRAP assessments, and vendors sometimes imply that running on AWS confers that status. It does not. The cloud provider's assessment covers the cloud provider's responsibilities. Everything the vendor builds on top is out of that scope and remains unassessed unless the vendor has been assessed separately.
What you're usually really asking
Procurement language is often inherited from a template written for a different kind of system. It is worth working out which underlying concern applies, because the honest answer to the concern is sometimes stronger than the answer to the literal question.
'Is the service hosted onshore?' This is usually the real question, and it is the one where we have an unambiguous answer. Processing happens in Sydney and audio is not transferred overseas. There is no configuration that changes this, which means there is no misconfiguration risk — a meaningful difference from hyperscaler services where region is a per-call setting.
'Who has access to the data?' No human listens to submitted audio at any point. For transcription specifically this removes an entire category of concern that applies to human transcription services, where individuals hear the recording.
'How long is data retained?' Source audio is deleted after the transcript is produced. Transcripts remain available in the account until deleted.
'Is our data used to improve your models?' No. This is an increasingly common question and a reasonable one, given how many AI services reserve training rights in their terms.
When an unassessed service is still a reasonable choice
Not all government work needs an assessed platform, and treating IRAP as a universal gate tends to push agencies into either overpaying or quietly using consumer tools that are considerably worse.
The question worth asking is what the audio actually contains. A public consultation session, a media interview, a webinar or an internal training recording is generally OFFICIAL and unremarkable. A recorded interview in an integrity investigation is a different matter entirely — same organisation, very different call.
Local government, state entities, universities, and government-adjacent bodies frequently operate under lighter requirements than Commonwealth agencies handling PROTECTED material, and often the binding constraint is a data sovereignty policy rather than an ISM control set.
The comparison that matters
The realistic alternative to an onshore unassessed service is rarely an IRAP-assessed one. It is usually a staff member using a free consumer app that stores recordings offshore indefinitely and reserves training rights. Assessed against that baseline, onshore processing with no retention and no training use is a substantial improvement.
Questions worth asking us, or anyone else
- In which specific region is audio processed, and can that be changed by configuration?
- Is any component — storage, queueing, model inference, logging — outside Australia?
- Does any person have access to submitted audio or transcripts?
- What is retained, for how long, and how is deletion verified?
- Are customer recordings used for training or evaluation?
- What assessments exist, at what classification, on what date, over what scope?
- Where does the vendor's responsibility end and the cloud provider's begin?
Those last two are the useful ones. They separate vendors who understand their own security posture from vendors reciting marketing copy — and anyone who can't tell you the scope and date of their assessment probably doesn't have one.
If you do need an assessed service
Then go and get one, genuinely. Look for providers holding a current assessment at the classification you need, ask to see the report rather than a logo, check the scope actually covers the service you'll use, and confirm the date — an assessment from a few years ago against an older ISM revision is weaker assurance than it looks.
We'd honestly rather point you there than win a tender we shouldn't.
Frequently asked questions
Is Australian Transcription IRAP assessed?
No, and we have none planned. If your requirement is an IRAP-assessed service at PROTECTED or above, you should shortlist providers who hold current assessments at that level. Separately — and these are unrelated schemes — we do not currently hold ISO 27001 or SOC 2. ISO 27001 is in progress with no committed date, so treat it as absent when evaluating us.
Is ISO 27001 a prerequisite for IRAP, or does it count instead?
Neither. They are separate schemes with no formal relationship. ISO 27001 is an international standard for an information security management system, certified by an accredited certification body. IRAP is an Australian assessment of a system against the Information Security Manual, performed by an ASD-endorsed assessor. You can hold either without the other, an IRAP assessment does not confer ISO 27001, and ISO 27001 does not reduce the ISM controls an assessor examines. They do overlap in evidence — a mature ISMS usually has much of the documentation an assessor asks for — but that is convenience, not substitution.
What is the difference between IRAP assessed and IRAP certified?
There is no such thing as IRAP certification. IRAP assessors endorsed by the Australian Signals Directorate evaluate a system against Information Security Manual controls and produce a report documenting the security posture and residual risks. The government entity's own authorising officer then decides whether to accept that risk. Vendors claiming to be 'IRAP certified' are using language that does not exist.
Does running on AWS mean a service inherits AWS's IRAP assessment?
No. The cloud provider's assessment covers the cloud provider's responsibilities under the shared responsibility model. Anything a vendor builds on top is outside that scope and remains unassessed unless the vendor has been assessed separately. Treat any implication otherwise as a warning sign.
Can government agencies use a transcription service that is not IRAP assessed?
It depends on the classification of the material and the agency's own risk framework, and it is a decision for the agency rather than the vendor. A recorded public consultation and a recorded integrity investigation sit very differently even within the same organisation. Many state, local government and university buyers are bound by a data sovereignty policy rather than an ISM control set.
Where is government audio processed if we use your service?
Exclusively on AWS infrastructure in ap-southeast-2 (Sydney). There is no configuration that routes processing elsewhere, so unlike hyperscaler services where region is a per-call setting, there is no misconfiguration path that sends audio offshore. Source audio is deleted after transcription and is never used for training.
What should we ask a transcription vendor in a security review?
Which specific region processes audio and whether configuration can change it; whether any component including storage, queueing and logging sits offshore; whether any person can access recordings; what is retained and for how long; whether recordings are used for training; and the scope, classification and date of any assessment. Vendors who cannot answer the last one usually do not have one.
Straight answers to residency questions
90 minutes free, no credit card required. Processed in AWS Sydney, deleted after transcription, never used for training.