Governance, Risk and Compliance
How do you strengthen critical infrastructure compliance without creating a separate framework that is difficult to maintain?
As part of its ongoing governance and assurance program, Magentus reviewed how its established management systems supported its obligations under the Security of Critical Infrastructure Act 2018 (SOCI Act). Working with Integris Group Services, Magentus strengthened and embedded applicable SOCI requirements into existing governance, security and risk management practices, while building the internal capability required to maintain and evolve the framework over time.
The Opportunity: Aligning Existing Systems with SOCI Obligations
Magentus provides health technology and infrastructure that supports critical clinical services across the healthcare sector, including pathology through its
The organisation already maintained robust practices across information security management, cyber security, quality, business continuity and risk management, supported by certifications including ISO 27001 and ISO 9001. These systems provided a strong foundation for regulatory compliance and operational resilience..
Following a review of its obligations, Magentus identified opportunities to further strengthen its existing framework to support applicable requirements across relevant areas of the business. The objective was not to create a separate compliance framework, but to build on established systems and ways of working in a sustainable and maintainable way.
The Challenge: Embedding Compliance Management into Existing Ways of Working
Magentus sought a practical approach that would assess existing systems, identify targeted uplift opportunities, and strengthen its management system to support applicable SOCI obligations. The organisation also wanted to ensure that responsibility for ongoing compliance remained embedded in the business..
Magentus wanted a sustainable approach that:
- Built on existing governance, security and quality management systems,
- Supported alignment across relevant SOCI risk domains, including cyber, personnel, supply chain and physical security,
- Strengthened internal ownership and capability, and
- Established a framework that could be maintained and continually improved over time
The Solution: A Collaborative SOCI Compliance Uplift
Integris and Magentus established a collaborative project team, allocating responsibilities according to internal capability, subject-matter expertise and existing system ownership.
✔ Assessing current state and requirements:
Integris applied its adaptable SOCI requirements assessment framework to review Magentus’ existing management system against applicable obligations. The Magentus Quality Team coordinated access to stakeholders, evidence and existing controls.
The assessment identified areas of strength, opportunities requiring targeted uplift and broader opportunities for continual improvement.
✔ Developing a practical implementation plan:
Findings were documented in a report that formed the basis of an agreed implementation plan. Actions were prioritised according to regulatory need, system maturity and organisational ownership, ensuring effort was focused where it would deliver the greatest value.
✔ Embedding SOCI into existing management systems:
Rather than developing a standalone compliance framework, Integris worked with Magentus to enhance existing policies, controls, governance processes and documentation. This approach enabled SOCI requirements to be integrated into established ways of working rather than managed as a separate compliance process. The Magentus Quality Team also assumed responsibility for ongoing SOCI obligations, including relevant reporting and escalation processes.
This approach enabled Magentus to leverage established practices across information security, cyber security, quality, business continuity and risk while addressing the additional requirements needed for SOCI compliance. The collaborative delivery model enabled Magentus to make efficient use of both internal capability and external expertise, while building practical knowledge of the uplifted framework within its own team.
✔ Supporting ongoing improvement:
Throughout the engagement, additional opportunities for improvement were identified through ongoing review and continual improvement activities.
These were separated from the core SOCI implementation scope and incorporated into Magentus’ broader continual improvement program, supporting the organisation’s commitment to ongoing governance maturity.
Benefits: Stronger Alignment, Greater Ownership and Sustainable Compliance
The engagement delivered several outcomes for Magentus:
- Stronger alignment between existing management systems and applicable SOCI obligations,
- Greater integration of compliance requirements into established governance and operational processes
- Reduced duplication by building on established controls, documentation and governance structures,
- More efficient use of internal and external expertise through clear ownership and collaboration, and
- Increased internal knowledge, capability and confidence to maintain the framework over time.
Importantly, the work further strengthened the governance, resilience and assurance practices that support Magentus’ role in delivering technology solutions to critical areas of healthcare
Building Sustainable Compliance Management Capability
This engagement demonstrates the value of integrating regulatory obligations into established management systems rather than treating compliance as a standalone activity.
By combining targeted external expertise with strong internal ownership, Magentus strengthened its regulatory position while preserving simplicity, avoiding unnecessary complexity and building the capability required to sustain and continually improve its approach over time.
Learn more about our approach to Compliance Management and Strategic and Operational Consulting here.
Integris Group Services is a Valuable Partner in Building Sustainable SOCI Compliance Capability
“Integris Group Services worked closely with our team to understand the strong systems and controls already in place, then identify the targeted enhancements needed to support our SOCI obligations.
By embedding those changes into our existing management systems, we have strengthened our regulatory position without introducing unnecessary complexity. Just as importantly, we have built the internal knowledge and ownership needed to maintain and continually improve the framework.”
Reference:
[i] https://www.magentus.com
