Selected engagements
Each entry describes the design problem and the decision taken. Nothing here describes a client's internal risk position
Kairos helps financial-services organisations align governance, operating model, workflow, data, reporting and platform design—creating enterprise GRC solutions that are practical, defensible and sustainable over time.
We work in the critical space between strategy and implementation, where regulatory expectations, governance decisions, platform architecture and delivery realities must come together coherently.

TRUMPET
GUITAR
DRUM
Extending an out-of-the-box capability to support the business
MARSH McLENNAN AUSTRALIA · MARCH 2024 TO PRESENT
ServiceNow IRM introduced end to end for a regulated entity operating under licence conditions. The out-of-the-box RG 78 breach reporting capability fell well short of what was needed, so it was extended to run alongside the standard model rather than replacing it.
CPS 230 across four strategic platforms
SUNCORP GROUP · MARCH 2021 TO PRESENT
CPS 230 spanned four systems, each strategic in its own right. Rather than consolidating them, the design integrated those systems with the GRC platform and kept the integration deliberately light: enough to support reporting across the domains later, without coupling them.
Value chain risk management under an enforceable undertaking
WESTPAC BANKING CORPORATION · FEBRUARY 2021 TO SEPTEMBER 2023
Senior solution architect across APRA enforceable undertaking remediation, covering controls, value chain risk, obligations, breach reporting and risk data governance. Recognised as a 2021 Risk Awards winner by the Chief Risk Officer for the value chain work.
Adapting an out-of-the-box model to a firm's own methodology
KPMG AUSTRALIA · MARCH TO JULY 2025
A four-domain operational resilience solution on IBM OpenPages, carrying the firm's own methodology without disturbing the existing operational risk and IT governance solutions. Delivered with a single custom helper, everything else through configuration.
Extending an out-of-the-box capability to support the business
MARSH McLENNAN AUSTRALIA · MARCH 2024 TO PRESENT
ServiceNow IRM introduced end to end for a regulated entity operating under licence conditions. The out-of-the-box RG 78 breach reporting capability fell well short of what was needed, so it was extended to run alongside the standard model rather than replacing it.
Adapting an out-of-the-box model to a firm's own methodology
KPMG AUSTRALIA · MARCH TO JULY 2025
A four-domain operational resilience solution on IBM OpenPages, carrying the firm's own methodology without disturbing the existing operational risk and IT governance solutions. Delivered with a single custom helper, everything else through configuration.
CPS 230 across four strategic platforms
SUNCORP GROUP · MARCH 2021 TO PRESENT
CPS 230 spanned four systems, each strategic in its own right. Rather than consolidating them, the design integrated those systems with the GRC platform and kept the integration deliberately light: enough to support reporting across the domains later, without coupling them.
Value chain risk management under an enforceable undertaking
WESTPAC BANKING CORPORATION · FEBRUARY 2021 TO SEPTEMBER 2023
Senior solution architect across APRA enforceable undertaking remediation, covering controls, value chain risk, obligations, breach reporting and risk data governance. Recognised as a 2021 Risk Awards winner by the Chief Risk Officer for the value chain work.
