SOCI Act: Risk management program attestation - key considerations checklist
By 28 September 2025, boards of many Australian Critical Infrastructure entities must attest to the effectiveness of their risk management practices under the SOCI Act. This brochure introduces a practical checklist to help organisations assess readiness, strengthen governance and prepare confidently for their upcoming attestation.
© 123RF
Boards of Critical Infrastructure entities are required to attest annually to the effectiveness of their risk management practices, including how risks were identified, managed and responded to over the past year, and how these practices will support the organisation going forward.
Preparation should begin early and include a review of critical asset operations, changes to the risk environment, and the design and operating effectiveness of the Critical Infrastructure Risk Management Program (CIRMP). Early board engagement is essential to build understanding of the attestation process, improve organisational resilience and compliance outcomes, and support directors in fulfilling their professional duties.
This brochure provides access to a practical checklist designed to help organisations assess their attestation readiness and define next steps. It is supported by expert guidance covering Risk Management Program rules and Enhanced Cybersecurity Obligations, with tailored approaches spanning penetration testing, business continuity planning and risk management alignment to support efficient compliance.