Compliance Framework
Western Sydney University’s compliance framework sets out the relationship between the strategic and operational components of its Compliance Management Program, its governing benchmarks, and its approach to compliance risk management. This Framework also covers The College.
The University’s compliance framework is based on three main benchmarks:
- International Standard of ISO 19600;
- University’s objectives as outlined in its Securing Success plan; and
- Good governance principles, including Audit and Risk Committee endorsement and oversight of the Compliance Program, supported by regular reporting on significant compliance matters and annual assurance reporting on the Program, Privacy and GIPA.
Three Lines of Responsibility
The Framework operates on a three lines of responsibility model.
Its effectiveness is dependent on clearly defined roles and accountabilities across the University, ensuring that compliance obligations are appropriately owned, implemented, and overseen.
Compliance Policy
The Compliance Policy establishes the University’s overarching principles and commitment to compliance. It is aligned with ISO 19600, endorsed by the ARC, and reflects the University’s values.
It operates alongside key conduct frameworks, including the University’s Code of Conduct.
Compliance Strategic Priorities
The Compliance Strategic Priorities set the three-year direction of the Compliance Program Unit.
They focus on maturing the Compliance Management Program across all 12 components of a mature compliance model, with the objective of achieving Level 5 – Embedded maturity.
- Download the 2023-2026 Strategic Priorities(current)
- Download the 2019-2022 Strategic Priorities
- Download the 2015-2018 Strategic Priorities
Compliance Planning
The CPU adopts a risk-based approach to compliance planning. Targeted compliance plans may be developed for particular areas where warranted by regulatory risk, significant change or identified compliance priorities. These may include key legislative obligations, planned control activities, risk mitigation initiatives and measures of success.
As part of the Framework, the CPU acts as a central consultative and assurance function, supporting both academic and professional units.
Policy, contractual, and governance responsibilities
Compliance with operational policies, including those that give effect to legislative requirements (e.g. workplace surveillance, external employment, national security), is owned and managed by the relevant accountable business areas. Contractual compliance is similarly owned and managed by the business areas responsible for the relevant contracts, with legal advice provided by the Office of General Counsel where required. The CPU owns the overarching Compliance Policy and provides advisory support where these matters intersect with the broader regulatory compliance framework.
Procedures, guidance, and tools
The CPU partners with business units to develop:
- procedures and guidelines
- reporting and monitoring tools
- infographics, process maps, and flowcharts to support practical implementation
Training and capability
The CPU consults on Enterprise mandatory compliance training, including associated monitoring and reporting where required.
It also provides advisory support for targeted or specialised training to ensure:
- alignment with compliance obligations
- consistency with enterprise training frameworks
- effective capability uplift across the University