Governance, Risk and Compliance (GRC) System – Workflow, Reporting and Survey Capabilities

Closes in 6 daysClose date: 21 August 2026

About this tender

This Tender is invited by the Issuer. Overview The Department of Social Services (the Department) is seeking information through this Request for Information (RFI) regarding Governance, Risk and Compliance (GRC) system solutions that provide workflow, reporting and survey capabilities. About The Department is responsible for the development and delivery of social policy and programs that support the economic and social wellbeing of individuals, families, and vulnerable members of the Australian community. The Department operates in a complex and highly regulated environment, requiring robust governance, risk, and compliance arrangements to support effective decision-making and accountability. To support these activities, the Department utilises digital systems across a diverse and distributed workforce and seeks to ensure that these systems continue to meet evolving organisational needs and ways of working. Work Already Done The Department currently uses a GRC platform that provides non-compliance reporting, risk assessment, custom online processes, workflow management, survey functionality, and reporting capabilities, with expanded scope to support additional users, processes, and modules. As organisational needs evolve, the Department is seeking to further understand available capabilities in the market, explore approaches that may support current and future requirements, and better understand how different solutions support configurability and user experience. Purpose This RFI is intended to identify available solutions and approaches in the market that can meet the Department's governance, risk and compliance requirements. The Department's current arrangement is due to conclude in late 2026, and this RFI is intended as market research to support planning for future service requirements and procurement activities. Scope The Department requires capability to support workflow-based processes, survey and form-based data collection, and reporting functions, incorporating: End-to-end management of non-compliance reporting, investigation, and resolution activities, including survey integration into governance and compliance processes Off the shelf and customisable digital process management supporting governance, risk and compliance Consistent and auditable workflows across a broad range of business processes (e.g. HR, security, travel, procurement, and operational processes) Risk management processes, including risk identification, assessment, and maintenance of risk registers Structured and unstructured data collection through customisable surveys functionality Reporting, analytics, and visibility of organisational activities, non-compliance and risk processes Provision of non-production environments to support testing, configuration, training and user acceptance activities The Department is interested in solutions that: Support configurable workflows that can be adapted to different business functions without significant redevelopment Facilitate the capture of information through surveys, forms, or workflow interactions, and enable that information to be incorporated into governance or compliance processes Support interaction with internal users and external stakeholders through secure and accessible interfaces, including where the platform is used to collect public responses, feedback, forms or survey submissions Maintain traceability, auditability, and data integrity across all processes Are available as established, commercially supported products that can be configured to meet organisational needs Minimise reliance on extensive bespoke development or ongoing vendor-led customisation Provide the ability to utilise pre-built processes and templates, while also supporting the configuration and development of organisation-specific workflows, forms and processes where required Users and Their Needs The solution will support a wide range of users, including: Governance, risk, and compliance teams responsible for oversight and reporting HR, security, procurement, and operational teams managing specific processes Senior executives requiring dashboard reporting and visibility of organisational risks and activities General staff initiating or participating in workflows Online processes for external users such as new starters (pre-onboarding) Internal and external users who may need to submit information or respond to forms or surveys (including anonymously) Users require: Intuitive and accessible interfaces that support efficient completion of tasks The ability to initiate, complete, and track workflows online from any location Mechanisms to capture and manage non-compliance events and risk information Tools to create and distribute surveys and forms, including externally The ability to submit information anonymously where appropriate, with appropriate controls to protect information submitted through public facing forms, surveys or feedback channels Access to registers, reports, and dashboards that support decision-making and audit requirements Audit logs and traceability for all processes within the system Contractor Requirements Security and Data Protection Solutions should support appropriate security controls aligned with recognised standards and frameworks, including: Australian data residency Compliance with Australian Privacy Principles and privacy legislation Compliance with Australian Government security frameworks and requirements, including as amended (including but not limited to ISM, PSPF), and the ability to maintain alignment with updates to those frameworks and associated cyber security guidance throughout the life of the platform IRAP Assessed to Protected VANguard Federated Authentication Service, Single Sign-On (SSO) Vendors should describe how their solution manages and protects information across different use cases and user groups, including internal DSS users and external stakeholders, and outline relevant security, privacy and access controls for public facing forms, surveys or feedback channels, including how the solution manages monitoring and protection of personal or sensitive information. Auditability and Traceability Solutions should support appropriate levels of auditability and traceability, including the ability to: Record and track user activity and system interactions Maintain records of workflow actions, decisions, and changes Support monitoring, review, and assurance activities Interoperability Solutions should be capable of integrating with other enterprise systems using standard interfaces or open standards where available. Scalability Solutions should be capable of scaling to meet organisational needs, including increasing numbers of users, expanding workflows and processes, and growing data volumes and reporting requirements. Accessibility and Usability Solutions should be accessible and usable by a diverse user base, including remote or hybrid workers, and support contemporary accessibility standards including Web Content Accessibility Guidelines (WCAG) 2.2 Level AA. Information Requested Vendors should outline how their solution currently supports the user requirements outlined above and, where functionality is not available, how it may be supported through configuration, integration, or planned future capability. Responses should include: References Relevant case study Presentation Other

How to respond to this tender

A strong tender response is clear, compliant, and backed by evidence. These steps apply to most Australian and New Zealand public tenders.

Read the requirements in full

Open the official listing and download the full tender pack. Note the response schedules, evaluation criteria, mandatory conditions, and the exact closing time and lodgement method.

Confirm you are eligible and it is worth bidding

Check licences, insurances, certifications, and any conformance requirements before you commit. A quick bid or no-bid decision saves days of wasted effort on a tender you cannot win.

Answer every criterion with evidence

Respond to each evaluation criterion directly and back your claims with concrete examples, referees, and past performance. Address the buyer’s stated need, not a generic capability statement.

Lodge early through the official portal

Submit through the source portal well before the deadline. Late or incorrectly lodged bids are almost always rejected, so leave time for uploads, portal errors, and last-minute questions.

Ready to write winning tenders?

Sign up today, what a relief.

Sign up