Skip to main content
Westlink Intranet

Command Palette

Search for a command to run...

?
OFFICIAL
Back to Compliance

JOSCAR-AU 2026

JOSCAR-AU 2026 Questionnaire — Submitted Answers and Evidence Mapping for Westlink Logistics

Requirements
173
Last reviewed
26/05/2026
Next review
14/04/2027
Source
Hellios Questionnaire Version 2.0, published 18 November 2025, submitted 14 April 2026, renewal 16 April 2026

Reconciliation notes

JOSCAR-AU 2026 compliance library is a curated build because the source is a Hellios portal PDF export of Westlink's live questionnaire responses, not a clause-numbered standard. Question numbering matches the Hellios portal exactly (e.g. 2.11.12). Submitted answers are as at the 14 April 2026 portal export — subject to change on portal update. Hellios ID 30005491; Questionnaire Version 2.0 (published 18/11/2025); renewal due 16 April 2026. Scope filter: substantive assurance questions only — pure metadata (addresses, contact blocks, employee counts, revenue, product sub-details, sub-contractor detail blocks) and insurance-cover-amount detail fields are excluded; top-level 'does your organisation hold X?' insurance questions are included. Total requirements: 173. Per-section counts: Stage 1 / Corporate Responsibility=2; Stage 1 / Declarations=8; Stage 1 / Diversity=6; Stage 1 / Financial & Legal=7; Stage 1 / Policy Compliance=14; Stage 1 / Products & Services=7; Stage 1 / Standard Insurances=1; Stage 2 / Anti-Bribery & Corruption=7; Stage 2 / Business Continuity=1; Stage 2 / Counterfeit Products/Materiel=5; Stage 2 / Data Privacy & Protection=10; Stage 2 / Environment=15; Stage 2 / Financial & Legal=3; Stage 2 / Health & Safety=9; Stage 2 / Human Resources=5; Stage 2 / IT & Physical Security=22; Stage 2 / Insurances=5; Stage 2 / Licences=2; Stage 2 / Modern Slavery=17; Stage 2 / Product Safety=7; Stage 2 / Quality=6; Stage 2 / Supply Chain=14. Coverage breakdown (recomputed 11/06/2026): Full=76, Partial=58, Gap=22, Not Applicable=17. Gap severities: {'Low': 26, 'Medium': 40, 'High': 14, 'Critical': 0}. Five open IsCompliant actions remain from the JOSCAR gap-analysis (Critical rows): 2.7.12 Labour Standards policy; 2.8.26 order/requirement monitoring; 2.10.2.6 supplier financial stability; 2.10.4 Supplier Code of Conduct; and (resolved) 2.11.6 User Access Management via TEC-POL-002. Legacy WLK-GBL-* document references in JOSCAR_1.csv evidence notes have been translated to current WMS refs (drop 'WLK-GBL-' prefix and '-GBL' segment). Where legacy docs have not yet been migrated to the new WMS (e.g. SCM-PRO-001, SCM-FRM-001/002, HRS-STD-001, HRS-GDL-003, HRS-PRO-003, COM-STD-002), rows are Partial with gap notes pointing to the migration gap.

Requirements

Showing 173 of 173 requirements

IDClauseRequirementApplicabilityCoverageEvidenceGap
JOSCAR-Q1.3.1Q1.3.1Does your organisation have a legal Australian Company Number (ACN)?
Submitted: Yes
ApplicableFull
  • QHSE-MAN-001 §1Manual §1 Purpose identifies Westlink Logistics Pty Ltd (ABN 25 058 919 305, ACN 058 919 305) as the legal entity.
JOSCAR-Q1.3.2Q1.3.2Does your organisation have a legal Australian Business Number (ABN)?
Submitted: Yes
ApplicableFull
JOSCAR-Q1.3.6Q1.3.6Does your organisation have a Commercial and Government Entity (CAGE) Code or NATO Commercial and Government Entity (NCAGE) Code?
Submitted: Yes
ApplicablePartialLow
NCAGE code is held (Z0QJ3) but not recorded in any controlled WMS document. Consider adding to Organisation Identity section of QHSE-MAN-001 §1 or a Defence Industry Registration Register.
JOSCAR-Q1.3.13Q1.3.13Is your organisation wholly or partially owned by a foreign person or entity?
Submitted: No
ApplicableFull
  • QHSE-MAN-001 §1Manual §1 identifies Westlink as an Australian incorporated entity. Ownership held by Australian directors.
JOSCAR-Q1.3.14Q1.3.14Does your organisation hold a valid Workers Compensation insurance policy?
Submitted: Yes
ApplicablePartialLow
Certificate of Currency held outside the WMS corpus (operational insurance register). Not a WMS-controlled document — evidence lives in finance records.
JOSCAR-Q1.3.16Q1.3.16Does your organisation hold a valid Public Liability insurance policy?
Submitted: Yes
ApplicablePartialLow
Certificate of Currency held outside the WMS corpus (finance records). Not a WMS-controlled document.
JOSCAR-Q1.3.17Q1.3.17Does your organisation hold a valid Products Liability insurance policy?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q1.4.3Q1.4.3Are any of your organisation's products (goods or services) subject to ITAR, EAR, Australian Military or Dual-Use or any other import/export legislation required by any country?
Submitted: No
ApplicableFull
  • OPS-PRO-001OPS-PRO-001 operationalises DSGL classification, Defence Trade Controls permits and dual-use export/import controls at consignment level (ITAR/EAR/export legislation).
JOSCAR-Q1.4.7Q1.4.7Will your organisation or any subcontractor store, transfer, process, handle or have access to any sensitive, confidential or personal data shared by your customers physically or electronically in the day-to-day operations of your organisation?
Submitted: Yes
ApplicableFull
  • TEC-POL-001Information Security Policy governs handling of confidential and personal data.
  • GOV-POL-015Privacy Policy governs personal information handling.
JOSCAR-Q1.4.8Q1.4.8Does your organisation rely upon any subcontractors or sub-tier suppliers that are categorised as critical or key for the products or services supplied?
Submitted: Yes
ApplicableFull
  • QHSE-PRO-002Supplier and Subcontractor Management Procedure §6.10 records critical-supplier dependencies and sub-tier visibility for critical engagements.
JOSCAR-Q1.4.9Q1.4.9Does your organisation hold any recognised management system certified by a third party e.g. ISO 9001, ISO 27001?
Submitted: Yes
ApplicableFull
  • QHSE-MAN-001Integrated Management System Manual scopes ISO 9001, ISO 14001 and ISO 45001 certification.
JOSCAR-Q1.4.10Q1.4.10Is it anticipated that your organisation will have direct access or an external connection to your customers' systems, networks or applications?
Submitted: No
ApplicableFull
  • TEC-POL-001Information Security Policy defines the Westlink tenancy boundary; no customer system integration is in scope.
JOSCAR-Q1.4.11Q1.4.11Has your organisation been accredited to any of the following IT security standards?
Submitted: No
ApplicableGapMedium
No ISO 27001 / IRAP / SOC2 accreditation. DISP membership submitted but not yet granted (per 2.11.15). Tracked via DISP project.
JOSCAR-Q1.4.12Q1.4.12Will your organisation or any subcontractor be collecting and/or processing personal information relating to your client's customers or employees on your client's behalf?
Submitted: Yes
ApplicableFull
  • GOV-POL-015Privacy Policy applies to personal information collected or processed on behalf of clients, per Australian Privacy Principles.
JOSCAR-Q1.5.5Q1.5.5What percentage of the work undertaken by your organisation is undertaken in Australia, utilising a Australian workforce?
Submitted: 100%
ApplicablePartial
  • QHSE-MAN-001 §1Manual §1 scopes Australian operations; workforce is 100% Australia-resident.
Medium
Scope notes Australian operations but the percentage of work performed by the Australian workforce is not stated as the question requires. (Body also references Singapore operations — now deregistered — which should be refreshed.)
JOSCAR-Q1.5.7Q1.5.7Is any individual within your organisation a current or former Australian Department of Defence employee?
Submitted: No
ApplicableFull
JOSCAR-Q1.6.1Q1.6.1Has your organisation or any of its directors been declared bankrupt or insolvent in the past 3 years?
Submitted: No
ApplicableFull
JOSCAR-Q1.6.2Q1.6.2Has your organisation been convicted of money laundering practices in the past 3 years?
Submitted: No
ApplicablePartial
  • GOV-POL-012Anti-Bribery and Corruption Policy sets the prohibitions that support this declaration.
Medium
The body contains an anti-bribery / anti-corruption prohibition but no money-laundering-specific basis; the policy supports a clean-conduct posture but the money-laundering-conviction declaration the question asks about is not addressed.
JOSCAR-Q1.6.3Q1.6.3Has your organisation been convicted of bribery or corrupt practices in the past 3 years?
Submitted: No
ApplicableFull
JOSCAR-Q1.6.4Q1.6.4Has your organisation had any reportable Health & Safety accidents, incidents or fatalities in the past 3 years?
Submitted: No
ApplicablePartial
  • QHSE-PRO-001Hazard and Incident Reporting and Investigation Procedure covers reporting of WHS incidents.
High
Declaration of zero reportable incidents over 3 years is being reviewed — see project_safety_reporting_review (PARKED 14/04/2026): 0 LTIs over 15 years not credible, near-miss reporting pathway broken, ISO 45001 cl 9.1/9.3 gaps. Declaration currently supportable on a strict 'reportable to regulator' reading but the underlying reporting system has integrity issues to remediate.
JOSCAR-Q1.6.5Q1.6.5Has your organisation or any of its directors been the subject of any criminal or civil court action in respect of your organisation's business activities in the past 7 years?
Submitted: No
ApplicableFull
JOSCAR-Q1.6.6Q1.6.6Has your organisation ever been found to have entered into formal or informal anti-competitive arrangements?
Submitted: No
ApplicableFull
  • HR-STD-001Code of Conduct prohibits anti-competitive conduct; this attestation is backed by the Code's competition and anti-trust provisions.
JOSCAR-Q1.6.7Q1.6.7Has your organisation been investigated or convicted by a competent authority for any activities relating to Human Rights including slavery, servitude, forced and compulsory labour and human trafficking in the past 5 years?
Submitted: No
ApplicableFull
  • GOV-POL-013Modern Slavery Policy — prohibits forced labour, human trafficking, modern slavery.
JOSCAR-Q1.6.8Q1.6.8Is your organisation precluded from tendering for Australian Government funded work?
Submitted: No
ApplicableFull
JOSCAR-Q1.7.1Q1.7.1Is your organisation Aboriginal or Torres Strait Islanders majority owned?
Submitted: No
ApplicableFull
JOSCAR-Q1.7.3Q1.7.3Is your organisation majority veteran owned?
Submitted: No
ApplicableFull
JOSCAR-Q1.7.4Q1.7.4Is your organisation registered under the Government Veteran Employment Commitment Organisation?
Submitted: No
ApplicableFull
JOSCAR-Q1.7.5Q1.7.5Is your organisation majority female owned?
Submitted: No
ApplicableFull
JOSCAR-Q1.7.6Q1.7.6Is your organisation majority disability owned?
Submitted: No
ApplicableFull
JOSCAR-Q1.7.7Q1.7.7Is your organisation certified with BuyAbility?
Submitted: No
ApplicableFull
JOSCAR-Q1.8.5Q1.8.5Does your organisation ensure that contractors and subcontractors have valid workers compensation and/or registrations for statutory workers compensation?
Submitted: Yes
ApplicableFull
  • QHSE-PRO-002Supplier and Subcontractor Management Procedure §6.3 requires workers compensation Certificate of Currency validation at on-boarding and renewal.
JOSCAR-Q1.9.1Q1.9.1Please confirm that you have read, understood and will comply with Saab's Supplier Code of Conduct.
Submitted: Submitted
ApplicablePartial
  • GOV-POL-019Westlink Code of Conduct aligns with prime-contractor supplier codes; compliance with the Saab code is carried via this attestation rather than a mapped WMS document.
Low
Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.
JOSCAR-Q1.9.2Q1.9.2Please confirm that you have read, understood and will comply with BAE Systems' Supplier Code of Conduct.
Submitted: Submitted
ApplicablePartialLow
Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.
JOSCAR-Q1.9.3Q1.9.3Please confirm that you have read, understood and will comply with the Babcock Australasia Code of Business Conduct.
Submitted: Submitted
ApplicablePartialLow
Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.
JOSCAR-Q1.9.4Q1.9.4Please confirm that you have read, understood and will comply with the RTX Supplier Code of Conduct.
Submitted: Submitted
ApplicablePartialLow
Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.
JOSCAR-Q1.9.5Q1.9.5Please confirm that you have read, understood and will comply with the Boeing Defence Australia Supplier Code of Conduct.
Submitted: Submitted
ApplicablePartialLow
Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.
JOSCAR-Q1.9.6Q1.9.6Acknowledgement of General Privacy Notice for the Joint Supply Chain Accreditation Register and certification that data subjects consented to provision of their personal information.
Submitted: Submitted
Not ApplicableNot Applicable
JOSCAR-Q1.9.7Q1.9.7Warranty that information provided in the Register is current, complete and accurate; consent for Raytheon Australia to seek financial reports and references.
Submitted: Submitted
ApplicableFull
JOSCAR-Q1.9.8Q1.9.8Acknowledgement that information supports Raytheon Australia supply chain due diligence and consent to information sharing with related bodies and advisers.
Submitted: Submitted
Not ApplicableNot Applicable
JOSCAR-Q1.9.9Q1.9.9Representation and warranty of familiarity with Australian/FCPA/UK Bribery anti-corruption laws and Modern Slavery Act 2018 (Cth); certification of human-rights policies and supplier compliance.
Submitted: Submitted
ApplicableFull
  • GOV-POL-012Anti-Bribery and Corruption Policy.
  • GOV-POL-013Modern Slavery Policy.
  • GOV-POL-019Code of Conduct addresses harassment-free and lawful working conditions.
JOSCAR-Q1.9.10Q1.9.10Certification of a process to detect and mitigate potential conflicts of interest, including former ADF/APS/Commonwealth Service Provider employment.
Submitted: Submitted
ApplicablePartial
  • GOV-POL-019Code of Conduct addresses conflicts of interest at a policy level.
Medium
Conflict of interest disclosure process (including ADF/APS/CSP former employment) is implicit in the Code of Conduct but no standalone COI procedure or declaration register exists in the WMS.
JOSCAR-Q1.9.11Q1.9.11Certification of policies/procedures addressing the creation, maintenance and retention of accurate business records including those related to quality.
Submitted: Submitted
ApplicableFull
  • GOV-POL-001Quality Policy.
  • QHSE-MAN-001Integrated Management System Manual — records management in documented information controls.
JOSCAR-Q1.9.12Q1.9.12Certification that supplier/officers are not listed on any excluded/denied party list and have no recent fraud/corruption/money laundering convictions.
Submitted: Submitted
ApplicableFull
JOSCAR-Q1.9.13Q1.9.13Acknowledgement that completion of the Register does not guarantee future tenders/quotes/supply.
Submitted: Submitted
ApplicableFull
JOSCAR-Q1.9.14Q1.9.14Confirmation of compliance with Northrop Grumman Australia's Standards of Business Conduct for suppliers.
Submitted: Submitted
ApplicablePartialLow
Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.
JOSCAR-Q2.2.2Q2.2.2Does your organisation have a documented Employee Code of Conduct?
Submitted: Yes
ApplicableFull
  • HR-STD-001Code of Conduct applies to all personnel and agents (the consolidated employee Code of Conduct).
JOSCAR-Q2.2.3Q2.2.3Does your organisation have a documented process to verify the competency of individual employees (e.g. competency/training matrix)?
Submitted: Yes
ApplicableFull
  • QHSE-MAN-001Integrated Management System Manual references competency/training obligations.
JOSCAR-Q2.2.4Q2.2.4Does your organisation have an induction programme?
Submitted: Yes
ApplicableFull
  • QHSE-MAN-001Integrated Management System Manual references induction obligations.
JOSCAR-Q2.2.5Q2.2.5Does your organisation use an enterprise agreement approved by Fair Work Australia?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.2.6Q2.2.6Does your organisation undertake Employee Screening in accordance with National Standards (AS 4811)?
Submitted: No
ApplicableFull
  • HR-PRO-001Workforce Screening Procedure (AS 4811-2022) — identity verification (100-point formula), integrity and credentials screening, screening tiers, records management, right of review. Migrated from WLK-GBL-HRS-POL-001 (consolidates the DISP-originated DEF-POL-002, removed from SP 11/06/2026); live in the WMS library 09/06/2026. Closes this question.
JOSCAR-Q2.3.4Q2.3.4Does your organisation comply with applicable competition and anti-trust regulations?
Submitted: Yes
ApplicableFull
  • HR-STD-001Code of Conduct — competition and anti-trust compliance ("No anti-competitive behaviour" plus follow-the-law competition and consumer-law obligations).
JOSCAR-Q2.3.5Q2.3.5Does your organisation have a Statement of Tax Record (STR)?
Submitted: Yes
ApplicablePartialLow
STR held in finance records, not a WMS-controlled document. No WMS procedure describes STR maintenance.
JOSCAR-Q2.3.6Q2.3.6Does your organisation collect a Statement of Tax Record for each of your subcontractors?
Submitted: No
ApplicableGapLow
Subcontractor STR collection is not documented. Low criticality — applies only to Commonwealth contracts over a threshold; address if Westlink tenders for qualifying government work.
JOSCAR-Q2.4.1Q2.4.1Does your organisation hold a valid Professional Indemnity insurance policy?
Submitted: No
ApplicableGapMedium
Professional Indemnity insurance not currently held. Review whether defence industry prime-contractor tenders require PI — if so, procure cover.
JOSCAR-Q2.4.2Q2.4.2Does your organisation hold a valid Care, Custody and Control insurance policy?
Submitted: No
ApplicableGapMedium
Care, Custody and Control cover not held. Material risk given warehousing service line — freight forwarding/warehousing typically relies on CCC or Transit Liability cover for client goods. Confirm cover approach with broker.
JOSCAR-Q2.4.3Q2.4.3Does your organisation hold a valid Cyber Liability insurance policy?
Submitted: No
ApplicableGapHigh
Cyber Liability insurance not held. With customer data handling (1.4.7=Yes, 1.4.12=Yes) and DISP membership in progress, Cyber Liability cover is a material exposure. Recommend procuring.
JOSCAR-Q2.4.7Q2.4.7Does your organisation hold a valid Compulsory Third Party (CTP) Motor Vehicle insurance policy?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.4.8Q2.4.8Does your organisation hold a valid Transit Liability insurance policy?
Submitted: No
ApplicableGapHigh
Transit Liability cover not held. Material given freight service line and customer cargo exposure. Review with broker as a priority.
JOSCAR-Q2.5.1Q2.5.1Does your organisation have an anti-bribery policy or process?
Submitted: Yes
ApplicableFull
  • GOV-POL-012Anti-Bribery and Corruption Policy.
  • GOV-POL-019Code of Conduct reinforces anti-bribery expectations.
JOSCAR-Q2.5.2.1Q2.5.2.1Does your anti-bribery process include regular assessments to identify and mitigate risks, including reputational risks to your customers?
Submitted: Yes
ApplicablePartial
  • GOV-POL-012Anti-Bribery and Corruption Policy references risk-based approach.
Medium
Policy references risk approach but no anti-bribery risk register / periodic assessment record exists in the WMS. Historical observation per gap-analysis (Q16) — no anti-bribery risk assessment in the risk register.
JOSCAR-Q2.5.2.2Q2.5.2.2Does your anti-bribery process include regular communication and training for all employees on this process including upon induction?
Submitted: Yes
ApplicablePartialMedium
Anti-bribery training was added to onboarding per gap-analysis completed action (19/09/2025). Training delivery evidence is operational (CRM training records) rather than in a controlled WMS document.
JOSCAR-Q2.5.2.3Q2.5.2.3Does your anti-bribery process include regular review of this process and monitoring of compliance?
Submitted: Yes
ApplicablePartialMedium
No documented review schedule or monitoring artefact for anti-bribery compliance in the WMS. Operational review occurs through management review but without a standing anti-bribery agenda item.
JOSCAR-Q2.5.2.4Q2.5.2.4Does your anti-bribery process include controls to prevent corruption, conflicts of interest and unethical behaviour?
Submitted: Yes
ApplicableFull
  • GOV-POL-012Anti-Bribery and Corruption Policy.
  • GOV-POL-019Code of Conduct addresses conflicts of interest and unethical behaviour.
JOSCAR-Q2.5.2.5Q2.5.2.5Evidence of senior management commitment to Anti-Bribery legislation?
Submitted: Yes
ApplicableFull
  • GOV-POL-012Anti-Bribery and Corruption Policy — signed by CEO.
JOSCAR-Q2.5.2.6Q2.5.2.6Guidance relating to the appropriate acceptance and offering of gifts and hospitality?
Submitted: Yes
ApplicableFull
  • GOV-POL-019Code of Conduct addresses gifts and hospitality.
  • GOV-POL-012Anti-Bribery and Corruption Policy references gifts and hospitality controls.
JOSCAR-Q2.6.2Q2.6.2Does your organisation have a documented Health & Safety policy?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.6.2.2Q2.6.2.2Has your organisation's Health & Safety policy been endorsed and signed by senior management?
Submitted: Yes
ApplicableFull
  • GOV-POL-002Health and Safety Policy is signed by the CEO.
JOSCAR-Q2.6.9Q2.6.9Does your organisation have a Drug & Alcohol policy?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.6.10Q2.6.10Does your organisation have a Chain of Responsibility policy?
Submitted: Yes
ApplicableFull
  • QHSE-MAN-001Integrated Management System Manual references HVNL obligations.
JOSCAR-Q2.6.11Q2.6.11Does your organisation have a hazard and risk management process?
Submitted: Yes
ApplicableFull
  • QHSE-PRO-001Hazard and Incident Reporting and Investigation Procedure.
  • QHSE-MAN-001Integrated Management System Manual — risk management process.
JOSCAR-Q2.6.12Q2.6.12Does your organisation have Crisis Management and Emergency response plans?
Submitted: Yes
ApplicableFull
  • QHSE-PLN-002Crisis Management Plan — enterprise crisis command, scenario playbooks, communications and regulatory notifications, and exercising regime.
  • QHSE-MAN-001Integrated Management System Manual references emergency preparedness obligations.
JOSCAR-Q2.6.13Q2.6.13Does your organisation use hazardous substances?
Submitted: No
ApplicableGapMedium
P1.2 relevance adjudication (2026-06-19, CF): flipped N/A->Applicable. 'Use of hazardous substances' is a WHS/GHS workplace question, not a DG-freight question — onsite/warehouse operations (including biosecurity fumigation handling) engage common hazardous chemicals binding Westlink's own WHS duty; sibling Q2.6.15 is already Applicable on identical own-personnel logic. The submitted JOSCAR answer 'No' understated this — flag for JOSCAR answer-integrity refresh. Existing WHS hazard management (QHSE-PRO-001, QHSE-PRO-007, QHSE-MAN-001) references hazardous substances but no dedicated SDS/chemical-management control is wired; coverage + evidence to be assessed in P2 (likely Partial).
JOSCAR-Q2.6.14Q2.6.14Does your organisation import plant, equipment or goods from overseas containing asbestos?
Submitted: No
ApplicableFull
JOSCAR-Q2.6.15Q2.6.15Does your organisation require personnel to hold a High Risk Work Licence (HRWL)?
Submitted: No
ApplicableFull
  • QHSE-PRO-002Supplier and Subcontractor Management Procedure §6.4 requires HRWL verification for subcontractors performing high-risk work.
JOSCAR-Q2.7.3Q2.7.3Does your organisation have a documented Environmental Policy?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.7.3.1Q2.7.3.1Has your organisation formally communicated your environmental policy to your employees?
Submitted: Yes
ApplicableFull
  • GOV-POL-004Environmental Policy published on WMS intranet; included in induction per QHSE-MAN-001.
JOSCAR-Q2.7.3.3Q2.7.3.3Has your organisation's Environmental policy been endorsed and signed by senior management?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.7.6Q2.7.6Is your company working towards achieving net zero (scope 1, 2 and 3), in accordance with top level management set objectives & targets?
Submitted: No
ApplicableGapMedium
No net-zero commitment or Scope 1/2/3 target has been adopted. Historical observation (Q36 per gap-analysis). Emerging defence-industry prime requirement — consider scoping in 2026 environmental objectives review.
JOSCAR-Q2.7.7Q2.7.7Please select which categories of greenhouse gas emissions your organisation publicly reports on.
Submitted: None
ApplicableGapLow
Westlink is below NGER reporting thresholds and does not voluntarily publish GHG data. Address alongside any net-zero commitment decision.
JOSCAR-Q2.7.11Q2.7.11Does your organisation have a documented Corporate & Social Responsibility (CSR) or ESG policy?
Submitted: No
ApplicableGapMedium
No standalone CSR / ESG policy. Historical observation (Q37 per gap-analysis). Elements covered in Modern Slavery, Environment, Privacy and Code of Conduct but not consolidated.
JOSCAR-Q2.7.12Q2.7.12Does your organisation have a policy that documents your approach to Labour Standards & Human Rights?
Submitted: No
ApplicableFull
  • GOV-POL-013 §Labour Standards and Human RightsGOV-POL-013 rev 4 (renamed Modern Slavery, Labour Standards and Human Rights Policy) — §Labour Standards and Human Rights documents Westlink's approach (Fair Work Act 2009 (Cth), UN Guiding Principles): fair and lawful conditions, safe work, non-discrimination, freedom of association, supply-chain expectations and grievance/remediation.
JOSCAR-Q2.7.13Q2.7.13Does your organisation have a policy documenting its approach to Diversity & Inclusion?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.7.13.1Q2.7.13.1Does your organisation measure how you are performing on Diversity & Inclusion?
Submitted: No
ApplicableGapLow
No D&I performance metrics tracked. Historical observation (Q40). Low priority given 12-person workforce; address via annual D&I objective-setting if scaled.
JOSCAR-Q2.7.13.2Q2.7.13.2Does your organisation have a documented process in place to handle reports of discrimination?
Submitted: Yes
ApplicablePartial
  • GOV-POL-018Whistleblower Policy provides a reporting channel.
Medium
Grievance Resolution Procedure (legacy HRS-PRO-003) has not been migrated to the new WMS corpus. Current reporting channels rely on the Code of Conduct and Whistleblower Policy.
JOSCAR-Q2.7.13.3Q2.7.13.3Does your organisation have a process and measures in place to integrate disabled persons into your workforce?
Submitted: No
ApplicableGap
  • GOV-POL-010Diversity and Inclusion Policy covers inclusive employment principles but no active disability integration measures.
Low
Historical observation (Q42). Policy-level commitment only; no operational measures.
JOSCAR-Q2.7.19Q2.7.19Does your organisation have a Reconciliation Action Plan (or similar) that provides an organisation commitment to Indigenous employment targets?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.7.21Q2.7.21Does your organisation identify, support, or partner with Indigenous enterprises or participate in social impact initiatives?
Submitted: Yes
Not ApplicableNot Applicable
JOSCAR-Q2.7.24Q2.7.24Does your organisation have a strategy to engage with and procure from Small to Medium Enterprises (SMEs)?
Submitted: Yes
ApplicablePartialLow
Procurement approach is SME-friendly operationally; no documented SME engagement strategy exists in the WMS.
JOSCAR-Q2.7.16Q2.7.16Does your organisation ensure that the National Minimum Wage is paid to all employees in the jurisdictions in which it operates?
Submitted: Yes
ApplicableFull
  • GOV-POL-013Modern Slavery Policy — fair wages commitment.
JOSCAR-Q2.8.5Q2.8.5Does your organisation have a documented Quality policy?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.8.5.2Q2.8.5.2Has your organisation's Quality policy been endorsed and signed by senior management?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.8.25Q2.8.25Does your organisation have processes and associated documentation relating to obsolescence management?
Submitted: No
ApplicableGapMedium
No documented obsolescence-management process. A prior IsCompliant remediation (19/09/2025) is not reflected in the Manual text.
JOSCAR-Q2.8.26Q2.8.26Does your organisation monitor an originating order or customer requirements throughout all stages of work?
Submitted: Yes
ApplicableFull
  • GOV-PRO-001Business Process Overview (Rev 2, live interactive flowchart) maps requirement monitoring from tender/order through award, project execution under a unique Westlink Project Number, to Project Closeout — i.e. order-to-delivery traceability.
  • QHSE-TPL-014 §§13PQMP §13 — client files and deliverables carry the Project Document Number; traceability established and controlled to satisfy contract/client requirements.
JOSCAR-Q2.8.27Q2.8.27Does your organisation issue original Certificates of Conformance for applicable deliverables?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.8.28Q2.8.28Does your organisation have a process to promptly inform customers of any anticipated delays in delivery?
Submitted: Yes
ApplicableGapMedium
No delivery-delay notification process documented.
JOSCAR-Q2.9.1Q2.9.1Does your organisation have policies and/or processes and associated support documentation that addresses product safety requirements and related statutory obligations?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.9.5Q2.9.5Does your organisation sub-contract design work?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.9.6Q2.9.6Does your organisation have a policy to ensure customers are notified of the presence of hazardous materials in the products you supply or generated as a result of the service you provide?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.9.10Q2.9.10Does your organisation proactively and in a timely manner communicate security vulnerabilities to customers for delivered goods?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.9.11Q2.9.11Does your organisation perform testing of your goods to ensure that vulnerabilities are identified and actively remediated?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.9.12Q2.9.12Does your organisation have protective measures in place to prevent your goods from sabotage or tampering during manufacturing and through final delivery?
Submitted: No
ApplicablePartial
  • OPS-PRO-001OPS-PRO-001 + GOV-POL-023 air-cargo security (security declarations, eligibility gate, pre-uplift checkpoint, false-description criminal control) provide supply-chain physical security.
Medium
Anti-sabotage/tamper coverage is partial: Westlink is asset-light with no manufacturing leg, so physical-security controls apply at the air-cargo handling layer (OPS-PRO-001 / GOV-POL-023) rather than to production.
JOSCAR-Q2.9.13Q2.9.13Are security risks inherent in your organisation's systems and processes (e.g. design, manufacturing, test, sustainment) identified and mitigated or managed on an ongoing basis?
Submitted: No
ApplicablePartial
  • TEC-POL-001Information Security Policy — ICT security risk management.
  • QHSE-MAN-001Integrated Management System Manual references risk management.
  • TEC-PRO-001 §ResponsibilitiesTEC-PRO-001 §Responsibilities defines MSP (Becloudsmart) cyber response duties including evidence preservation and Tier-2 support.
Medium
A general ISO 31000 risk-based approach is described and information security is flagged as an internal issue with DISP/ISM references, but security risks across systems and processes are not substantively identified and mitigated as a managed process in the body.
JOSCAR-Q2.10.1Q2.10.1Does your organisation have a documented supplier/subcontractor assessment procedure?
Submitted: Yes
ApplicableFull
  • QHSE-PRO-002Supplier and Subcontractor Management Procedure documents the full pre-qualification and assessment workflow.
  • GOV-PRO-003Supplier Prequalification — Major: live documented assessment procedure (questionnaire, QHSE/technical/financial assessment, approval with conditions, periodic review).
  • GOV-PRO-005Supplier Prequalification — Minor: live documented proportionate assessment procedure for minor works.
JOSCAR-Q2.10.2.1Q2.10.2.1Does your supplier/subcontractor assessment procedure include controls to manage anti-bribery and corruption risk?
Submitted: Yes
ApplicablePartial
  • GOV-POL-012Anti-Bribery and Corruption Policy applies to suppliers via flow-down.
Medium
Supplier anti-bribery flow-down is policy-level only; supplier assessment procedure to give effect to this is pending (see 2.10.1).
JOSCAR-Q2.10.2.2Q2.10.2.2Does your supplier/subcontractor assessment procedure include controls to identify and mitigate the risk of Modern Slavery and Human Trafficking?
Submitted: Yes
ApplicablePartial
  • GOV-POL-013Modern Slavery Policy applies to suppliers via Purchase Order T&C (legacy COM-STD-002 §17 / §30) per IsCompliant completed action 12/06/2025.
Medium
Modern Slavery supplier flow-down is in place via purchase-order terms (legacy reference); prequalification questionnaires (legacy SCM-FRM-001/002) not yet migrated. Historical observation Q5.
JOSCAR-Q2.10.2.3Q2.10.2.3Does your supplier/subcontractor assessment procedure include controls to manage environmental risk?
Submitted: Yes
ApplicableGapMedium
Environmental risk flow-down is implied via policy; supplier assessment procedure pending migration.
JOSCAR-Q2.10.2.4Q2.10.2.4Does your supplier/subcontractor assessment procedure include controls to collect and validate certificates of currency from critical suppliers?
Submitted: Yes
ApplicableFull
  • QHSE-PRO-002Supplier and Subcontractor Management Procedure §6.3 requires collection and validation of Certificates of Currency.
JOSCAR-Q2.10.2.5Q2.10.2.5Does your supplier/subcontractor assessment procedure include a process to audit critical suppliers?
Submitted: Yes
ApplicableFull
  • QHSE-PRO-002Supplier and Subcontractor Management Procedure §6.8 establishes the audit programme for critical suppliers.
JOSCAR-Q2.10.2.6Q2.10.2.6Does your supplier/subcontractor assessment procedure include controls to monitor the financial stability of critical suppliers?
Submitted: Yes
ApplicableFull
  • QHSE-PRO-002Supplier and Subcontractor Management Procedure §6.2.2 financial standing evaluation (last two years of financial statements or independent credit reference for material engagements) and §6.7 ongoing monitoring (material events including insolvency).
JOSCAR-Q2.10.2.7Q2.10.2.7Does your supplier/subcontractor assessment procedure include an induction process for suppliers entering your site?
Submitted: Yes
ApplicableFull
  • QHSE-PRO-002Supplier and Subcontractor Management Procedure §6.6 documents the contractor site-induction process.
JOSCAR-Q2.10.3Q2.10.3Does your organisation have a process for ensuring that on-site welfare provision meets legal requirements and the needs and expectations of its workforce?
Submitted: No
ApplicableGapLow
On-site welfare-provision adequacy against legal requirements not articulated in a WHS procedure.
JOSCAR-Q2.10.4Q2.10.4Does your organisation have a documented Code of Conduct for suppliers?
Submitted: Yes
ApplicableFull
  • QHSE-PRO-002Supplier and Subcontractor Management Procedure §6.9 is the Supplier Code of Conduct.
JOSCAR-Q2.10.5Q2.10.5Please select which tiers of your supply chain your organisation collects information on.
Submitted: Tier 1
ApplicablePartialLow
Tier 1 only — consistent with 12-person service-provider scale. No sub-tier supply chain visibility documented.
JOSCAR-Q2.10.6Q2.10.6Does your organisation measure your suppliers' compliance and performance in line with your Health & Safety requirements?
Submitted: Yes
ApplicableFull
  • QHSE-PRO-002Supplier and Subcontractor Management Procedure §6.7 documents KPI-based supplier performance measurement and re-evaluation.
JOSCAR-Q2.10.7Q2.10.7Does your organisation have a list of approved or preferred suppliers including critical subcontractors?
Submitted: Yes
ApplicablePartialLow
Preferred supplier list is maintained in CRM / operational systems; not a controlled WMS document.
JOSCAR-Q2.10.8Q2.10.8Does your organisation have defined acceptance criteria for approved or preferred suppliers including critical subcontractors?
Submitted: Yes
ApplicableFull
  • QHSE-PRO-002Supplier and Subcontractor Management Procedure §6.2.3 defines acceptance criteria for approved suppliers.
JOSCAR-Q2.11.1Q2.11.1Does your organisation have a documented Information Security Policy?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.11.1.1Q2.11.1.1Does your organisation have a process in place for communicating Cyber Security alerts/breaches to your customers?
Submitted: Yes — Within 24 hours
ApplicableGapHigh
Policy commitment present; implementing Cyber Incident Response Plan (which would document the 24-hour customer notification pathway) is a Critical gap per the E8 ML2 library. External to WMS — Becloudsmart handles detection/escalation.
JOSCAR-Q2.11.1.2Q2.11.1.2Has your organisation or system undergone an IRAP assessment against the Australian Government's Information Security Manual (ISM)?
Submitted: No
ApplicableGapMedium
No IRAP assessment completed. Q68 flagged in gap-analysis — 2024 Defence Cyber Assessment was 'Embedded' but this is not an IRAP. Review whether IRAP is required for DISP Entry Level (generally not) or for specific defence-industry contracts.
JOSCAR-Q2.11.2Q2.11.2Is your organisation compliant with the cyber security framework set out in the Australian Government's Information Security Manual (ISM)?
Submitted: Yes
ApplicablePartial
  • TEC-POL-001Information Security Policy aligns with ISM.
High
Submitted 'Yes' is aspirational — E8 ML2 library shows substantial gaps against ISM controls (incident response plan, central logging, phishing-resistant MFA). Treat as partial pending the DISP uplift programme completing.
JOSCAR-Q2.11.5Q2.11.5Does your organisation have an in-house documented Information Security management system?
Submitted: Yes
ApplicablePartialHigh
An ISMS document suite has been initiated via TEC-POL-001/002. A full ISO 27001-style ISMS (scope statement, SoA, risk treatment plan, internal audit, management review) is not yet in place.
JOSCAR-Q2.11.5.2Q2.11.5.2Does your Information Security management system include a process to classify the types of information your organisation holds?
Submitted: Yes
ApplicablePartial
  • TEC-POL-001Information Security Policy references classification.
Medium
Classification scheme referenced in TEC-POL-001 but an information classification standard/matrix is not separately published. OFFICIAL / OFFICIAL:Sensitive handling is operational.
JOSCAR-Q2.11.5.3Q2.11.5.3Does your Information Security management system include a process to identify, risk assess and record critical assets at least annually?
Submitted: Yes
ApplicableGapHigh
Historical observation Q72. No annual critical-asset identification cycle is evidenced. InfoSec Risk Assessment Register was stale (last updated Aug 2022) before the 19/09/2025 completed IsCompliant remediation — verify currency.
JOSCAR-Q2.11.5.4Q2.11.5.4Does your Information Security management system include accountabilities and responsibilities based on clearly defined roles for cyber security?
Submitted: Yes
ApplicableFull
  • TEC-POL-001Information Security Policy defines cyber security roles.
  • TEC-PRO-001 §ResponsibilitiesTEC-PRO-001 §Responsibilities assigns the Security Officer (QHSE Manager) the cyber incident response coordination role.
JOSCAR-Q2.11.6Q2.11.6Does your organisation have a documented User Access Management Policy to control access to confidential information provided by, or produced for, your customers?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.11.7Q2.11.7Does your organisation have a process to identify, assess and record information security risks at least annually?
Submitted: Yes
ApplicablePartial
  • TEC-POL-001Information Security Policy commits to annual risk assessment.
High
Historical observation Q75 — InfoSec Risk Assessment Register stale (Aug 2022). Reported last-assessed 14/06/2024 in portal. IsCompliant action 19/09/2025 marked complete — verify register reflects genuinely annual cadence going forward.
JOSCAR-Q2.11.8Q2.11.8Does your organisation have a System Security Patching policy?
Submitted: No
ApplicablePartial
  • TEC-POL-001Information Security Policy references patch management at policy level but no dedicated Patching Policy / Procedure exists.
Medium
Patch-management commitment exists at policy level (TEC-POL-001 — critical/high patches within 48 hours); no dedicated System Security Patching policy/procedure. Residual — dedicated patching procedure + E8 ML2 patching-cadence implementation (Becloudsmart uplift).
JOSCAR-Q2.11.9Q2.11.9Does your organisation have a documented system/network security monitoring policy?
Submitted: Yes
ApplicableGapHigh
Monitoring is delivered operationally via Becloudsmart-managed Defender/Sentinel. No dedicated monitoring policy or procedure exists in the controlled WMS corpus.
JOSCAR-Q2.11.10Q2.11.10Does your organisation formally review the physical security environment and risks whenever there is a significant change but no less frequently than annually?
Submitted: Yes
ApplicableGapHigh
Historical observation Q78 — physical security reviews not documented. No controlled record of physical security review cycle exists. DISP Entry Level physical security obligations not evidenced in the WMS.
JOSCAR-Q2.11.11Q2.11.11Does your organisation have regular mandatory security training for all employees and contractors?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.11.12Q2.11.12Does your organisation have a documented Security Incident Management policy?
Submitted: Yes
ApplicableFull
  • TEC-POL-001Information Security Policy requires reporting of security incidents to the Security Officer.
  • TEC-PRO-001 §PurposeTEC-PRO-001 §Purpose operationalises TEC-POL-001 information security commitments.
JOSCAR-Q2.11.13Q2.11.13Has your organisation completed the Cyber For Defence Industry (CFDI) questionnaire?
Submitted: Yes
ApplicableGapLow
CFDI questionnaire completion not stated or evidenced.
JOSCAR-Q2.11.15Q2.11.15Has your organisation applied for Defence Industry Security Programme (DISP) membership?
Submitted: Submitted
Not ApplicableNot Applicable
JOSCAR-Q2.11.16Q2.11.16Has your organisation been the subject of any external security investigation?
Submitted: No
ApplicableFull
JOSCAR-Q2.11.17Q2.11.17Has your organisation notified any customers, legislators, or regulators of any information, IT or cyber security incidents within the last three years?
Submitted: No
ApplicableFull
JOSCAR-Q2.11.18Q2.11.18Has your organisation had a cyber security breach in the last three years?
Submitted: No
ApplicableFull
JOSCAR-Q2.11.19Q2.11.19Does your organisation deploy Multi Factor Authentication (MFA) across all systems?
Submitted: Yes
ApplicablePartial
  • TEC-POL-002User Access Management Policy addresses MFA.
High
MFA is deployed across M365 tenancy. Phishing-resistant MFA (E8 ML2 requirement) is not yet in place — Critical gap per E8 ML2 library. Portal answer 'Yes' correct for baseline MFA but does not reflect ML2 phishing-resistant standard.
JOSCAR-Q2.11.20Q2.11.20Does your organisation take regular backups on systems containing customer data?
Submitted: No
ApplicablePartial
  • TEC-POL-001Information Security Policy references backup at policy level.
Medium
Backup commitment exists at policy level (TEC-POL-001) and M365 native retention/restore is in place for email/SharePoint/OneDrive. Residual — no dedicated backup policy, retention schedule, or immutability control documented in the WMS; E8 ML2 Regular Backups implementation (Becloudsmart uplift).
JOSCAR-Q2.12.1Q2.12.1Does your organisation have a documented Data Privacy & Protection policy?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.12.1.1Q2.12.1.1Does your organisation's Data Privacy & Protection policy apply to personal data collected or processed on the client's behalf, or collected from the client?
Submitted: Yes
ApplicableFull
  • GOV-POL-015Privacy Policy scope covers personal information collected from or on behalf of clients.
JOSCAR-Q2.12.2.1Q2.12.2.1Does your Data Privacy & Protection policy define what personal data is collected?
Submitted: Yes
ApplicableFull
  • GOV-POL-015Privacy Policy defines categories of personal information collected.
JOSCAR-Q2.12.2.2Q2.12.2.2Does your Data Privacy & Protection policy define when the individual's permission is sought?
Submitted: Yes
ApplicablePartialMedium
Commitment 1 references collection notice / APP 5 and reasonable expectation; consent is implied but the policy never states when permission is sought.
JOSCAR-Q2.12.2.3Q2.12.2.3Does your Data Privacy & Protection policy address protection of personal data against accidental or deliberate misuse, damage or destruction?
Submitted: Yes
ApplicableFull
  • GOV-POL-015Privacy Policy addresses safeguards.
  • TEC-POL-001Information Security Policy provides the technical controls that give effect to the safeguard commitment.
JOSCAR-Q2.12.2.4Q2.12.2.4Does your Data Privacy & Protection policy address transferring of personal data to other jurisdictions only in compliance with relevant local data privacy laws and with approval from the customer?
Submitted: No
ApplicableGapMedium
Cross-border transfer clauses not present in Privacy Policy. Low likelihood of cross-border transfer in day-to-day operations (see 2.12.5 = No), but Privacy Policy should still cover the obligation for completeness.
JOSCAR-Q2.12.2.5Q2.12.2.5Regular training for all employees on this process including upon induction?
Submitted: Yes
ApplicableGapMedium
Privacy training delivery is operational; evidenced via training records in CRM rather than a controlled WMS training procedure.
JOSCAR-Q2.12.3Q2.12.3Does your organisation ensure that all personal data is kept up to date?
Submitted: Yes
ApplicablePartial
  • GOV-POL-015Privacy Policy addresses data accuracy and update obligations (APP 10).
Medium
Commitment 4 commits to correcting inaccurate or out-of-date information on request (APP 13), but there is no proactive mechanism to keep personal information up to date; the control is reactive only.
JOSCAR-Q2.12.4Q2.12.4Does your organisation have a documented and implemented data retention schedule in place which covers your client's personal data?
Submitted: Yes
ApplicablePartial
  • GOV-POL-015Privacy Policy references retention but no separate retention schedule document is in WMS.
Medium
IsCompliant action (31/07/2025, completed 23/09/2025) marked done but a standalone data retention schedule document cannot be located in the current WMS corpus. Verify and publish.
JOSCAR-Q2.12.5Q2.12.5Does your organisation transfer or process personal data belonging to your clients outside Australia?
Submitted: No
ApplicableGapHigh
No policy element addresses APP 8 / overseas-disclosure commitment. Westlink does not restrict processing to Australia; prior TEC-POL-001 and GOV-POL-015 evidence notes were factually incorrect (S144 D3c). Policy gap: GOV-POL-015 needs an APP 8 overseas-disclosure commitment in a future revision (cf. PRV-APP8-01 framework Critical gap).
JOSCAR-Q2.13.1Q2.13.1Does your organisation hold any of the listed regulated licences (or any other not listed)?
Submitted: None of the above / No
Not ApplicableNot Applicable
JOSCAR-Q2.13.4Q2.13.4Is your organisation registered with the Australian Skills Quality Authority as a Registered Training Organisation?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.14.1Q2.14.1Does your organisation operate to the principles of any of the following counterfeit-prevention standards (e.g. AS6174, SAE AS5553)?
Submitted: None of the above
Not ApplicableNot Applicable
JOSCAR-Q2.14.2Q2.14.2Does your organisation have a documented Counterfeit Products/Materiel policy, plan, or process?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.14.6Q2.14.6Do your organisation's processes include suitable disposal methods of component/material packaging?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.14.7Q2.14.7Do your suppliers' processes include suitable disposal methods of component/material packaging with identification and traceability?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.14.8Q2.14.8When buying items of high concern, do your organisation's processes ensure returned goods are not purchased without a formal risk agreement with the customer?
Submitted: No
Not ApplicableNot Applicable
JOSCAR-Q2.15.1Q2.15.1Does your organisation have a documented Business Continuity Plan?
Submitted: No
ApplicableFull
  • QHSE-PLN-001Business Continuity Plan — recovery objectives (MAO/RTO/RPO), scenario playbooks, roles, communications and testing/maintenance regime. Rebuilt and renumbered from legacy WLK-GBL-QHSE-PLN-002; closes this question.
JOSCAR-Q2.20.1Q2.20.1Is your organisation required to report under the Modern Slavery Act 2018 (Cth)?
Submitted: No
ApplicableFull
JOSCAR-Q2.20.2.1Q2.20.2.1Addressed/incorporated modern slavery, forced labour, and human trafficking guidelines into your organisation's policies?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.20.2.2Q2.20.2.2Included modern slavery, forced labour, and human trafficking guidelines for your supply chain into your standard terms and conditions with suppliers?
Submitted: Yes
ApplicablePartial
  • GOV-POL-013Modern Slavery Policy — flow-down principle.
Medium
Modern slavery flow-down is in purchase order T&C (legacy COM-STD reference). Current equivalent T&C document exists but mapping to the new WMS corpus reference is pending.
JOSCAR-Q2.20.2.3Q2.20.2.3Conducting regular risk assessments of your suppliers against criteria that includes modern slavery, forced labour, and human trafficking?
Submitted: Yes
ApplicablePartial
  • GOV-POL-013Modern Slavery Policy requires supplier risk assessment.
Medium
Historical observation Q5 — supplier risk assessments do not always include modern slavery criteria. Remediation via pending supplier assessment procedure migration.
JOSCAR-Q2.20.2.4Q2.20.2.4Training your employees on the prevention of modern slavery, forced labour, and human trafficking, including upon induction?
Submitted: Yes
ApplicablePartial
  • GOV-POL-013Modern Slavery Policy references training.
Medium
Training is operational; no standalone training record for modern slavery exists in controlled WMS.
JOSCAR-Q2.20.3Q2.20.3Does your organisation have a person or team responsible for overseeing modern slavery risks arising from the goods or services that you deliver?
Submitted: Yes
ApplicableFull
  • GOV-POL-013Modern Slavery Policy assigns oversight responsibility.
JOSCAR-Q2.20.4Q2.20.4Is your organisation aware of low-skilled migrant workers working in your organisation's supply chains?
Submitted: No
ApplicableFull
JOSCAR-Q2.20.5Q2.20.5Does your organisation retain any original employee documentation (passports, identity papers) or any part of their salary?
Submitted: No
ApplicableGapMedium
No WMS document states the prohibition on retaining passports or withholding salary (a forced-labour / modern-slavery indicator).
JOSCAR-Q2.20.6Q2.20.6Does your organisation have controls in place to ensure that workers are paid lawfully and fairly, and that no improper wage deductions or financial penalties are imposed?
Submitted: Yes
ApplicablePartialMedium
The Labour section commits to minimum wages, NES and lawful engagement, supporting lawful and fair pay, but there is no explicit control against improper wage deductions or financial penalties at the level the question requires.
JOSCAR-Q2.20.7Q2.20.7Does your organisation have a documented statement to capture freedom of association to a union?
Submitted: No
ApplicableGapLow
No explicit freedom-of-association statement. Implicit coverage via Fair Work Act compliance and Code of Conduct. Low priority — could be addressed in Code of Conduct update.
JOSCAR-Q2.20.8Q2.20.8Does your organisation have an anonymous whistleblowers hotline, email, or web link (URL) available on your public company website for confidential use?
Submitted: No
ApplicablePartial
  • GOV-POL-018Whistleblower Policy establishes internal reporting channels.
Medium
Whistleblower Policy exists but no public-facing anonymous channel is published on westlinklogistics.com. Remediation: publish whistleblower URL/email on website.
JOSCAR-Q2.20.9Q2.20.9Does your organisation have a public complaints system available and easily accessible to the public?
Submitted: No
ApplicableGapLow
No public-facing complaints system published. General 'contact us' channel exists. Address alongside 2.20.8 website whistleblower publication.
JOSCAR-Q2.20.10Q2.20.10Does your organisation have any employees under the age of 18?
Submitted: No
ApplicableFull
JOSCAR-Q2.20.11Q2.20.11Does your organisation ensure that employment contracts are provided to employees in a language that they can understand?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.20.12Q2.20.12Do your organisation's employment contracts clearly state key terms of employment, such as wage rates and expected working hours?
Submitted: Yes
ApplicableFull
JOSCAR-Q2.20.14Q2.20.14Does your organisation procure raw materials, inputs to manufacture, service related inputs, constructed materials/parts/components from sources outside of Australia, New Zealand, Europe, Canada or the USA?
Submitted: No
ApplicableFull
JOSCAR-Q2.20.15Q2.20.15Has your organisation identified any instances of forced labour, modern slavery or human trafficking in your organisation or your supply chain in the last three years?
Submitted: No
Not ApplicableNot Applicable
Source document

JOSCAR-AU 2026 Questionnaire — Submitted Answers and Evidence Mapping for Westlink Logistics

173 normative shall-statements extracted from JOSCAR-AU 2026 (source: ~/projects/wms/sources/joscar/Westlink Logistics Pty Ltd-14-April-2026-questionnaire.pdf). The frontmatter requirements array is the source of truth — this body is rendered by scripts/render_compliance.py.

Coverage summary

CoverageCount
✅ Full83
🟡 Partial40
🟠 Ref-only0
🔴 Gap28
— N/A22

Gap severity distribution

SeverityCount
🔴 Critical0
🟠 High12
🟡 Medium35
🟢 Low21

Requirements

Clause Q1

IDCoverageEvidenceGapNotes
JOSCAR-Q1.3.1✅ FullQHSE-MAN-001 §‘1’
JOSCAR-Q1.3.2✅ FullQHSE-MAN-001 §‘1’
JOSCAR-Q1.3.6🟡 Partial🟢 LowNCAGE code is held (Z0QJ3) but not recorded in any controlled WMS document. Consider adding to Organisation Identity section of QHSE-MAN-001 §1 or a Defence Industry Registration Register.
JOSCAR-Q1.3.13✅ FullQHSE-MAN-001 §‘1’
JOSCAR-Q1.3.14🟡 Partial🟢 LowCertificate of Currency held outside the WMS corpus (operational insurance register). Not a WMS-controlled document — evidence lives in finance records.
JOSCAR-Q1.3.16🟡 Partial🟢 LowCertificate of Currency held outside the WMS corpus (finance records). Not a WMS-controlled document.
JOSCAR-Q1.3.17— N/AN/A — Westlink is a service provider (logistics, freight, warehousing, customs brokerage) — does not manufacture or supply physical products requiring Products Liability cover.
JOSCAR-Q1.4.3✅ FullOPS-PRO-001
JOSCAR-Q1.4.7✅ FullTEC-POL-001
GOV-POL-015
JOSCAR-Q1.4.8✅ FullQHSE-PRO-002
JOSCAR-Q1.4.9✅ FullQHSE-MAN-001
JOSCAR-Q1.4.10✅ FullTEC-POL-001
JOSCAR-Q1.4.11🔴 Gap🟡 MediumNo ISO 27001 / IRAP / SOC2 accreditation. DISP membership submitted but not yet granted (per 2.11.15). Tracked via DISP project.
JOSCAR-Q1.4.12✅ FullGOV-POL-015
JOSCAR-Q1.5.5🟡 PartialQHSE-MAN-001 §‘1’🟡 MediumScope notes Australian operations but the percentage of work performed by the Australian workforce is not stated as the question requires. (Body also references Singapore operations — now deregistered — which should be refreshed.)
JOSCAR-Q1.5.7✅ Full
JOSCAR-Q1.6.1✅ Full
JOSCAR-Q1.6.2🟡 PartialGOV-POL-012🟡 MediumThe body contains an anti-bribery / anti-corruption prohibition but no money-laundering-specific basis; the policy supports a clean-conduct posture but the money-laundering-conviction declaration the question asks about is not addressed.
JOSCAR-Q1.6.3✅ FullGOV-POL-012
GOV-POL-019
JOSCAR-Q1.6.4🟡 PartialQHSE-PRO-001🟠 HighDeclaration of zero reportable incidents over 3 years is being reviewed — see project_safety_reporting_review (PARKED 14/04/2026): 0 LTIs over 15 years not credible, near-miss reporting pathway broken, ISO 45001 cl 9.1/9.3 gaps. Declaration currently supportable on a strict ‘reportable to regulator’ reading but the underlying reporting system has integrity issues to remediate.
JOSCAR-Q1.6.5✅ Full
JOSCAR-Q1.6.6✅ FullHR-STD-001
JOSCAR-Q1.6.7✅ FullGOV-POL-013
JOSCAR-Q1.6.8✅ Full
JOSCAR-Q1.7.1✅ Full
JOSCAR-Q1.7.3✅ Full
JOSCAR-Q1.7.4✅ Full
JOSCAR-Q1.7.5✅ Full
JOSCAR-Q1.7.6✅ Full
JOSCAR-Q1.7.7✅ Full
JOSCAR-Q1.8.5✅ FullQHSE-PRO-002
JOSCAR-Q1.9.1🟡 PartialGOV-POL-019🟢 LowSubmitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.
JOSCAR-Q1.9.2🟡 PartialGOV-POL-019🟢 LowSubmitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.
JOSCAR-Q1.9.3🟡 PartialGOV-POL-019🟢 LowSubmitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.
JOSCAR-Q1.9.4🟡 PartialGOV-POL-019🟢 LowSubmitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.
JOSCAR-Q1.9.5🟡 PartialGOV-POL-019🟢 LowSubmitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.
JOSCAR-Q1.9.6— N/AN/A — JOSCAR registration attestation — acknowledgement of the JOSCAR General Privacy Notice and certification of data-subject consent; answered at JOSCAR registration, not a WMS-library policy obligation.
JOSCAR-Q1.9.7✅ Full
JOSCAR-Q1.9.8— N/AN/A — JOSCAR registration attestation — consent to share information with Raytheon for due diligence; answered at registration, not a WMS-library obligation.
JOSCAR-Q1.9.9✅ FullGOV-POL-012
GOV-POL-013
GOV-POL-019
JOSCAR-Q1.9.10🟡 PartialGOV-POL-019🟡 MediumConflict of interest disclosure process (including ADF/APS/CSP former employment) is implicit in the Code of Conduct but no standalone COI procedure or declaration register exists in the WMS.
JOSCAR-Q1.9.11✅ FullGOV-POL-001
QHSE-MAN-001
JOSCAR-Q1.9.12✅ Full
JOSCAR-Q1.9.13✅ Full
JOSCAR-Q1.9.14🟡 PartialGOV-POL-019🟢 LowSubmitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given.

Clause Q2

IDCoverageEvidenceGapNotes
JOSCAR-Q2.2.2✅ FullHR-STD-001
JOSCAR-Q2.2.3✅ FullQHSE-MAN-001
JOSCAR-Q2.2.4✅ FullQHSE-MAN-001
JOSCAR-Q2.2.5— N/AN/A — Westlink does not operate under an enterprise agreement; National Employment Standards and relevant Modern Awards apply.
JOSCAR-Q2.2.6✅ FullHR-PRO-001
JOSCAR-Q2.3.4✅ FullHR-STD-001
JOSCAR-Q2.3.5🟡 Partial🟢 LowSTR held in finance records, not a WMS-controlled document. No WMS procedure describes STR maintenance.
JOSCAR-Q2.3.6🔴 Gap🟢 LowSubcontractor STR collection is not documented. Low criticality — applies only to Commonwealth contracts over a threshold; address if Westlink tenders for qualifying government work.
JOSCAR-Q2.4.1🔴 Gap🟡 MediumProfessional Indemnity insurance not currently held. Review whether defence industry prime-contractor tenders require PI — if so, procure cover.
JOSCAR-Q2.4.2🔴 Gap🟡 MediumCare, Custody and Control cover not held. Material risk given warehousing service line — freight forwarding/warehousing typically relies on CCC or Transit Liability cover for client goods. Confirm cover approach with broker.
JOSCAR-Q2.4.3🔴 Gap🟠 HighCyber Liability insurance not held. With customer data handling (1.4.7=Yes, 1.4.12=Yes) and DISP membership in progress, Cyber Liability cover is a material exposure. Recommend procuring.
JOSCAR-Q2.4.7— N/AN/A — Westlink does not operate its own motor vehicle fleet — road freight is subcontracted. CTP is carried by subcontracted carriers.
JOSCAR-Q2.4.8🔴 Gap🟠 HighTransit Liability cover not held. Material given freight service line and customer cargo exposure. Review with broker as a priority.
JOSCAR-Q2.5.1✅ FullGOV-POL-012
GOV-POL-019
JOSCAR-Q2.5.2.1🟡 PartialGOV-POL-012🟡 MediumPolicy references risk approach but no anti-bribery risk register / periodic assessment record exists in the WMS. Historical observation per gap-analysis (Q16) — no anti-bribery risk assessment in the risk register.
JOSCAR-Q2.5.2.2🟡 PartialGOV-POL-012🟡 MediumAnti-bribery training was added to onboarding per gap-analysis completed action (19/09/2025). Training delivery evidence is operational (CRM training records) rather than in a controlled WMS document.
JOSCAR-Q2.5.2.3🟡 PartialGOV-POL-012🟡 MediumNo documented review schedule or monitoring artefact for anti-bribery compliance in the WMS. Operational review occurs through management review but without a standing anti-bribery agenda item.
JOSCAR-Q2.5.2.4✅ FullGOV-POL-012
GOV-POL-019
JOSCAR-Q2.5.2.5✅ FullGOV-POL-012
JOSCAR-Q2.5.2.6✅ FullGOV-POL-019
GOV-POL-012
JOSCAR-Q2.6.2✅ FullGOV-POL-002
JOSCAR-Q2.6.2.2✅ FullGOV-POL-002
JOSCAR-Q2.6.9✅ FullGOV-POL-003
JOSCAR-Q2.6.10✅ FullQHSE-MAN-001
JOSCAR-Q2.6.11✅ FullQHSE-PRO-001
QHSE-MAN-001
JOSCAR-Q2.6.12✅ FullQHSE-PLN-002
QHSE-MAN-001
JOSCAR-Q2.6.13🔴 Gap🟡 MediumP1.2 relevance adjudication (2026-06-19, CF): flipped N/A->Applicable. ‘Use of hazardous substances’ is a WHS/GHS workplace question, not a DG-freight question — onsite/warehouse operations (including biosecurity fumigation handling) engage common hazardous chemicals binding Westlink’s own WHS duty; sibling Q2.6.15 is already Applicable on identical own-personnel logic. The submitted JOSCAR answer ‘No’ understated this — flag for JOSCAR answer-integrity refresh. Existing WHS hazard management (QHSE-PRO-001, QHSE-PRO-007, QHSE-MAN-001) references hazardous substances but no dedicated SDS/chemical-management control is wired; coverage + evidence to be assessed in P2 (likely Partial).
JOSCAR-Q2.6.14✅ Full
JOSCAR-Q2.6.15✅ FullQHSE-PRO-002
JOSCAR-Q2.7.3✅ FullGOV-POL-004
JOSCAR-Q2.7.3.1✅ FullGOV-POL-004
JOSCAR-Q2.7.3.3✅ FullGOV-POL-004
JOSCAR-Q2.7.6🔴 Gap🟡 MediumNo net-zero commitment or Scope 1/2/3 target has been adopted. Historical observation (Q36 per gap-analysis). Emerging defence-industry prime requirement — consider scoping in 2026 environmental objectives review.
JOSCAR-Q2.7.7🔴 Gap🟢 LowWestlink is below NGER reporting thresholds and does not voluntarily publish GHG data. Address alongside any net-zero commitment decision.
JOSCAR-Q2.7.11🔴 Gap🟡 MediumNo standalone CSR / ESG policy. Historical observation (Q37 per gap-analysis). Elements covered in Modern Slavery, Environment, Privacy and Code of Conduct but not consolidated.
JOSCAR-Q2.7.12✅ Full[GOV-POL-013 §‘Labour Standards and Human Rights’](/wms/GOV-POL-013#s’Labour Standards and Human Rights’)
JOSCAR-Q2.7.13✅ FullGOV-POL-010
JOSCAR-Q2.7.13.1🔴 Gap🟢 LowNo D&I performance metrics tracked. Historical observation (Q40). Low priority given 12-person workforce; address via annual D&I objective-setting if scaled.
JOSCAR-Q2.7.13.2🟡 PartialGOV-POL-018🟡 MediumGrievance Resolution Procedure (legacy HRS-PRO-003) has not been migrated to the new WMS corpus. Current reporting channels rely on the Code of Conduct and Whistleblower Policy.
JOSCAR-Q2.7.13.3🔴 GapGOV-POL-010🟢 LowHistorical observation (Q42). Policy-level commitment only; no operational measures.
JOSCAR-Q2.7.19— N/AN/A — Indigenous employment targets were deliberately removed at GOV-POL-008 rev3; out of scope for a 13-employee organisation.
JOSCAR-Q2.7.21— N/AN/A — Support for / partnering with Indigenous enterprises was removed at GOV-POL-008 rev3; out of scope for a 13-employee organisation.
JOSCAR-Q2.7.24🟡 Partial🟢 LowProcurement approach is SME-friendly operationally; no documented SME engagement strategy exists in the WMS.
JOSCAR-Q2.7.16✅ FullGOV-POL-013
JOSCAR-Q2.8.5✅ FullGOV-POL-001
JOSCAR-Q2.8.5.2✅ FullGOV-POL-001
JOSCAR-Q2.8.25🔴 Gap🟡 MediumNo documented obsolescence-management process. A prior IsCompliant remediation (19/09/2025) is not reflected in the Manual text.
JOSCAR-Q2.8.26✅ FullGOV-PRO-001
QHSE-TPL-014 §§13
JOSCAR-Q2.8.27— N/AN/A — Westlink is a service provider (logistics, freight, warehousing, customs brokerage). CoCs apply to product manufacturers; not applicable to service delivery.
JOSCAR-Q2.8.28🔴 Gap🟡 MediumNo delivery-delay notification process documented.
JOSCAR-Q2.9.1— N/AN/A — Westlink is a service provider — product safety obligations sit with manufacturers and suppliers whose goods Westlink transports. Logistics-specific safety is covered under WHS (GOV-POL-002) and dangerous-goods transport requirements handled by licensed subcontractors.
JOSCAR-Q2.9.5— N/AN/A — No design activity in scope of services.
JOSCAR-Q2.9.6— N/AN/A — Westlink does not supply products. Hazardous materials in transported freight are managed via DG declarations from consignors under the ADG Code, not via Westlink policy.
JOSCAR-Q2.9.10— N/AN/A — Not applicable to a logistics service provider — no delivered goods whose vulnerabilities would be communicated.
JOSCAR-Q2.9.11— N/AN/A — Service provider — no goods manufactured or tested.
JOSCAR-Q2.9.12🟡 PartialOPS-PRO-001🟡 MediumAnti-sabotage/tamper coverage is partial: Westlink is asset-light with no manufacturing leg, so physical-security controls apply at the air-cargo handling layer (OPS-PRO-001 / GOV-POL-023) rather than to production.
JOSCAR-Q2.9.13🟡 PartialTEC-POL-001
QHSE-MAN-001
TEC-PRO-001 §‘Responsibilities’
🟡 MediumA general ISO 31000 risk-based approach is described and information security is flagged as an internal issue with DISP/ISM references, but security risks across systems and processes are not substantively identified and mitigated as a managed process in the body.
JOSCAR-Q2.10.1✅ FullQHSE-PRO-002
GOV-PRO-003
GOV-PRO-005
JOSCAR-Q2.10.2.1🟡 PartialGOV-POL-012🟡 MediumSupplier anti-bribery flow-down is policy-level only; supplier assessment procedure to give effect to this is pending (see 2.10.1).
JOSCAR-Q2.10.2.2🟡 PartialGOV-POL-013🟡 MediumModern Slavery supplier flow-down is in place via purchase-order terms (legacy reference); prequalification questionnaires (legacy SCM-FRM-001/002) not yet migrated. Historical observation Q5.
JOSCAR-Q2.10.2.3🔴 Gap🟡 MediumEnvironmental risk flow-down is implied via policy; supplier assessment procedure pending migration.
JOSCAR-Q2.10.2.4✅ FullQHSE-PRO-002
JOSCAR-Q2.10.2.5✅ FullQHSE-PRO-002
JOSCAR-Q2.10.2.6✅ FullQHSE-PRO-002
JOSCAR-Q2.10.2.7✅ FullQHSE-PRO-002
JOSCAR-Q2.10.3🔴 Gap🟢 LowOn-site welfare-provision adequacy against legal requirements not articulated in a WHS procedure.
JOSCAR-Q2.10.4✅ FullQHSE-PRO-002
JOSCAR-Q2.10.5🟡 Partial🟢 LowTier 1 only — consistent with 12-person service-provider scale. No sub-tier supply chain visibility documented.
JOSCAR-Q2.10.6✅ FullQHSE-PRO-002
JOSCAR-Q2.10.7🟡 Partial🟢 LowPreferred supplier list is maintained in CRM / operational systems; not a controlled WMS document.
JOSCAR-Q2.10.8✅ FullQHSE-PRO-002
JOSCAR-Q2.11.1✅ FullTEC-POL-001
JOSCAR-Q2.11.1.1🔴 Gap🟠 HighPolicy commitment present; implementing Cyber Incident Response Plan (which would document the 24-hour customer notification pathway) is a Critical gap per the E8 ML2 library. External to WMS — Becloudsmart handles detection/escalation.
JOSCAR-Q2.11.1.2🔴 Gap🟡 MediumNo IRAP assessment completed. Q68 flagged in gap-analysis — 2024 Defence Cyber Assessment was ‘Embedded’ but this is not an IRAP. Review whether IRAP is required for DISP Entry Level (generally not) or for specific defence-industry contracts.
JOSCAR-Q2.11.2🟡 PartialTEC-POL-001🟠 HighSubmitted ‘Yes’ is aspirational — E8 ML2 library shows substantial gaps against ISM controls (incident response plan, central logging, phishing-resistant MFA). Treat as partial pending the DISP uplift programme completing.
JOSCAR-Q2.11.5🟡 PartialTEC-POL-001
TEC-POL-002
🟠 HighAn ISMS document suite has been initiated via TEC-POL-001/002. A full ISO 27001-style ISMS (scope statement, SoA, risk treatment plan, internal audit, management review) is not yet in place.
JOSCAR-Q2.11.5.2🟡 PartialTEC-POL-001🟡 MediumClassification scheme referenced in TEC-POL-001 but an information classification standard/matrix is not separately published. OFFICIAL / OFFICIAL:Sensitive handling is operational.
JOSCAR-Q2.11.5.3🔴 Gap🟠 HighHistorical observation Q72. No annual critical-asset identification cycle is evidenced. InfoSec Risk Assessment Register was stale (last updated Aug 2022) before the 19/09/2025 completed IsCompliant remediation — verify currency.
JOSCAR-Q2.11.5.4✅ FullTEC-POL-001
TEC-PRO-001 §‘Responsibilities’
JOSCAR-Q2.11.6✅ FullTEC-POL-002
JOSCAR-Q2.11.7🟡 PartialTEC-POL-001🟠 HighHistorical observation Q75 — InfoSec Risk Assessment Register stale (Aug 2022). Reported last-assessed 14/06/2024 in portal. IsCompliant action 19/09/2025 marked complete — verify register reflects genuinely annual cadence going forward.
JOSCAR-Q2.11.8🟡 PartialTEC-POL-001🟡 MediumPatch-management commitment exists at policy level (TEC-POL-001 — critical/high patches within 48 hours); no dedicated System Security Patching policy/procedure. Residual — dedicated patching procedure + E8 ML2 patching-cadence implementation (Becloudsmart uplift).
JOSCAR-Q2.11.9🔴 Gap🟠 HighMonitoring is delivered operationally via Becloudsmart-managed Defender/Sentinel. No dedicated monitoring policy or procedure exists in the controlled WMS corpus.
JOSCAR-Q2.11.10🔴 Gap🟠 HighHistorical observation Q78 — physical security reviews not documented. No controlled record of physical security review cycle exists. DISP Entry Level physical security obligations not evidenced in the WMS.
JOSCAR-Q2.11.11✅ FullTEC-POL-001
[GOV-POL-016 §Policy Commitments](/wms/GOV-POL-016#sPolicy Commitments)
[TEC-PRO-002 §‘Security awareness and insider-threat training’](/wms/TEC-PRO-002#s’Security awareness and insider-threat training’)
JOSCAR-Q2.11.12✅ FullTEC-POL-001
TEC-PRO-001 §‘Purpose’
JOSCAR-Q2.11.13🔴 Gap🟢 LowCFDI questionnaire completion not stated or evidenced.
JOSCAR-Q2.11.15— N/AN/A — DISP membership statement — covered by DISP certification (cert_disp-membership.md), not a WMS-library obligation.
JOSCAR-Q2.11.16✅ Full
JOSCAR-Q2.11.17✅ Full
JOSCAR-Q2.11.18✅ Full
JOSCAR-Q2.11.19🟡 PartialTEC-POL-002🟠 HighMFA is deployed across M365 tenancy. Phishing-resistant MFA (E8 ML2 requirement) is not yet in place — Critical gap per E8 ML2 library. Portal answer ‘Yes’ correct for baseline MFA but does not reflect ML2 phishing-resistant standard.
JOSCAR-Q2.11.20🟡 PartialTEC-POL-001🟡 MediumBackup commitment exists at policy level (TEC-POL-001) and M365 native retention/restore is in place for email/SharePoint/OneDrive. Residual — no dedicated backup policy, retention schedule, or immutability control documented in the WMS; E8 ML2 Regular Backups implementation (Becloudsmart uplift).
JOSCAR-Q2.12.1✅ FullGOV-POL-015
JOSCAR-Q2.12.1.1✅ FullGOV-POL-015
JOSCAR-Q2.12.2.1✅ FullGOV-POL-015
JOSCAR-Q2.12.2.2🟡 PartialGOV-POL-015🟡 MediumCommitment 1 references collection notice / APP 5 and reasonable expectation; consent is implied but the policy never states when permission is sought.
JOSCAR-Q2.12.2.3✅ FullGOV-POL-015
TEC-POL-001
JOSCAR-Q2.12.2.4🔴 Gap🟡 MediumCross-border transfer clauses not present in Privacy Policy. Low likelihood of cross-border transfer in day-to-day operations (see 2.12.5 = No), but Privacy Policy should still cover the obligation for completeness.
JOSCAR-Q2.12.2.5🔴 Gap🟡 MediumPrivacy training delivery is operational; evidenced via training records in CRM rather than a controlled WMS training procedure.
JOSCAR-Q2.12.3🟡 PartialGOV-POL-015🟡 MediumCommitment 4 commits to correcting inaccurate or out-of-date information on request (APP 13), but there is no proactive mechanism to keep personal information up to date; the control is reactive only.
JOSCAR-Q2.12.4🟡 PartialGOV-POL-015🟡 MediumIsCompliant action (31/07/2025, completed 23/09/2025) marked done but a standalone data retention schedule document cannot be located in the current WMS corpus. Verify and publish.
JOSCAR-Q2.12.5🔴 Gap🟠 HighNo policy element addresses APP 8 / overseas-disclosure commitment. Westlink does not restrict processing to Australia; prior TEC-POL-001 and GOV-POL-015 evidence notes were factually incorrect (S144 D3c). Policy gap: GOV-POL-015 needs an APP 8 overseas-disclosure commitment in a future revision (cf. PRV-APP8-01 framework Critical gap).
JOSCAR-Q2.13.1— N/AN/A — None of the listed regulated licences apply to Westlink’s scope of services. Customs Brokerage operates under customs broker licensing held by the lodging agent — captured separately.
JOSCAR-Q2.13.4— N/AN/A — Westlink is not an RTO.
JOSCAR-Q2.14.1— N/AN/A — Counterfeit standards apply to manufacturers/distributors of electronic parts/materiel. Westlink is a logistics service provider — not applicable.
JOSCAR-Q2.14.2— N/AN/A — Service provider — no counterfeit product risk within Westlink’s own deliverables. Counterfeit risk in transported freight sits with consignors.
JOSCAR-Q2.14.6— N/AN/A — Service provider — component/material disposal is not in scope.
JOSCAR-Q2.14.7— N/AN/A — Not applicable to logistics service scope.
JOSCAR-Q2.14.8— N/AN/A — Not applicable to logistics service scope — Westlink does not buy high-concern items for resale.
JOSCAR-Q2.15.1✅ FullQHSE-PLN-001
JOSCAR-Q2.20.1✅ Full
JOSCAR-Q2.20.2.1✅ FullGOV-POL-013
JOSCAR-Q2.20.2.2🟡 PartialGOV-POL-013🟡 MediumModern slavery flow-down is in purchase order T&C (legacy COM-STD reference). Current equivalent T&C document exists but mapping to the new WMS corpus reference is pending.
JOSCAR-Q2.20.2.3🟡 PartialGOV-POL-013🟡 MediumHistorical observation Q5 — supplier risk assessments do not always include modern slavery criteria. Remediation via pending supplier assessment procedure migration.
JOSCAR-Q2.20.2.4🟡 PartialGOV-POL-013🟡 MediumTraining is operational; no standalone training record for modern slavery exists in controlled WMS.
JOSCAR-Q2.20.3✅ FullGOV-POL-013
JOSCAR-Q2.20.4✅ Full
JOSCAR-Q2.20.5🔴 Gap🟡 MediumNo WMS document states the prohibition on retaining passports or withholding salary (a forced-labour / modern-slavery indicator).
JOSCAR-Q2.20.6🟡 PartialGOV-POL-013🟡 MediumThe Labour section commits to minimum wages, NES and lawful engagement, supporting lawful and fair pay, but there is no explicit control against improper wage deductions or financial penalties at the level the question requires.
JOSCAR-Q2.20.7🔴 Gap🟢 LowNo explicit freedom-of-association statement. Implicit coverage via Fair Work Act compliance and Code of Conduct. Low priority — could be addressed in Code of Conduct update.
JOSCAR-Q2.20.8🟡 PartialGOV-POL-018🟡 MediumWhistleblower Policy exists but no public-facing anonymous channel is published on westlinklogistics.com. Remediation: publish whistleblower URL/email on website.
JOSCAR-Q2.20.9🔴 Gap🟢 LowNo public-facing complaints system published. General ‘contact us’ channel exists. Address alongside 2.20.8 website whistleblower publication.
JOSCAR-Q2.20.10✅ Full
JOSCAR-Q2.20.11✅ Full
JOSCAR-Q2.20.12✅ Full
JOSCAR-Q2.20.14✅ Full
JOSCAR-Q2.20.15— N/AN/A — The ‘no instances in 3 years’ records attestation is maintained in the DISP Security Register, not a WMS document.

Rendered from frontmatter by scripts/render_compliance.py. Source extraction: scripts/extract_iso9001_requirements.py. Evidence population: scripts/populate_iso9001_evidence.py. Validate: scripts/compliance_validate.py.