JOSCAR-AU 2026
JOSCAR-AU 2026 Questionnaire — Submitted Answers and Evidence Mapping for Westlink Logistics
- Requirements
- 173
- Last reviewed
- 26/05/2026
- Next review
- 14/04/2027
- Source
- Hellios Questionnaire Version 2.0, published 18 November 2025, submitted 14 April 2026, renewal 16 April 2026
Reconciliation notes
JOSCAR-AU 2026 compliance library is a curated build because the source is a Hellios portal PDF export of Westlink's live questionnaire responses, not a clause-numbered standard. Question numbering matches the Hellios portal exactly (e.g. 2.11.12). Submitted answers are as at the 14 April 2026 portal export — subject to change on portal update. Hellios ID 30005491; Questionnaire Version 2.0 (published 18/11/2025); renewal due 16 April 2026. Scope filter: substantive assurance questions only — pure metadata (addresses, contact blocks, employee counts, revenue, product sub-details, sub-contractor detail blocks) and insurance-cover-amount detail fields are excluded; top-level 'does your organisation hold X?' insurance questions are included. Total requirements: 173. Per-section counts: Stage 1 / Corporate Responsibility=2; Stage 1 / Declarations=8; Stage 1 / Diversity=6; Stage 1 / Financial & Legal=7; Stage 1 / Policy Compliance=14; Stage 1 / Products & Services=7; Stage 1 / Standard Insurances=1; Stage 2 / Anti-Bribery & Corruption=7; Stage 2 / Business Continuity=1; Stage 2 / Counterfeit Products/Materiel=5; Stage 2 / Data Privacy & Protection=10; Stage 2 / Environment=15; Stage 2 / Financial & Legal=3; Stage 2 / Health & Safety=9; Stage 2 / Human Resources=5; Stage 2 / IT & Physical Security=22; Stage 2 / Insurances=5; Stage 2 / Licences=2; Stage 2 / Modern Slavery=17; Stage 2 / Product Safety=7; Stage 2 / Quality=6; Stage 2 / Supply Chain=14. Coverage breakdown (recomputed 11/06/2026): Full=76, Partial=58, Gap=22, Not Applicable=17. Gap severities: {'Low': 26, 'Medium': 40, 'High': 14, 'Critical': 0}. Five open IsCompliant actions remain from the JOSCAR gap-analysis (Critical rows): 2.7.12 Labour Standards policy; 2.8.26 order/requirement monitoring; 2.10.2.6 supplier financial stability; 2.10.4 Supplier Code of Conduct; and (resolved) 2.11.6 User Access Management via TEC-POL-002. Legacy WLK-GBL-* document references in JOSCAR_1.csv evidence notes have been translated to current WMS refs (drop 'WLK-GBL-' prefix and '-GBL' segment). Where legacy docs have not yet been migrated to the new WMS (e.g. SCM-PRO-001, SCM-FRM-001/002, HRS-STD-001, HRS-GDL-003, HRS-PRO-003, COM-STD-002), rows are Partial with gap notes pointing to the migration gap.
Requirements
Showing 173 of 173 requirements
| ID | Clause | Requirement | Applicability | Coverage | Evidence | Gap |
|---|---|---|---|---|---|---|
| JOSCAR-Q1.3.1 | Q1.3.1 | Does your organisation have a legal Australian Company Number (ACN)? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q1.3.2 | Q1.3.2 | Does your organisation have a legal Australian Business Number (ABN)? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q1.3.6 | Q1.3.6 | Does your organisation have a Commercial and Government Entity (CAGE) Code or NATO Commercial and Government Entity (NCAGE) Code? Submitted: Yes | Applicable | Partial | — | Low NCAGE code is held (Z0QJ3) but not recorded in any controlled WMS document. Consider adding to Organisation Identity section of QHSE-MAN-001 §1 or a Defence Industry Registration Register. |
| JOSCAR-Q1.3.13 | Q1.3.13 | Is your organisation wholly or partially owned by a foreign person or entity? Submitted: No | Applicable | Full |
| |
| JOSCAR-Q1.3.14 | Q1.3.14 | Does your organisation hold a valid Workers Compensation insurance policy? Submitted: Yes | Applicable | Partial | — | Low Certificate of Currency held outside the WMS corpus (operational insurance register). Not a WMS-controlled document — evidence lives in finance records. |
| JOSCAR-Q1.3.16 | Q1.3.16 | Does your organisation hold a valid Public Liability insurance policy? Submitted: Yes | Applicable | Partial | — | Low Certificate of Currency held outside the WMS corpus (finance records). Not a WMS-controlled document. |
| JOSCAR-Q1.3.17 | Q1.3.17 | Does your organisation hold a valid Products Liability insurance policy? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q1.4.3 | Q1.4.3 | Are any of your organisation's products (goods or services) subject to ITAR, EAR, Australian Military or Dual-Use or any other import/export legislation required by any country? Submitted: No | Applicable | Full |
| |
| JOSCAR-Q1.4.7 | Q1.4.7 | Will your organisation or any subcontractor store, transfer, process, handle or have access to any sensitive, confidential or personal data shared by your customers physically or electronically in the day-to-day operations of your organisation? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q1.4.8 | Q1.4.8 | Does your organisation rely upon any subcontractors or sub-tier suppliers that are categorised as critical or key for the products or services supplied? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q1.4.9 | Q1.4.9 | Does your organisation hold any recognised management system certified by a third party e.g. ISO 9001, ISO 27001? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q1.4.10 | Q1.4.10 | Is it anticipated that your organisation will have direct access or an external connection to your customers' systems, networks or applications? Submitted: No | Applicable | Full |
| |
| JOSCAR-Q1.4.11 | Q1.4.11 | Has your organisation been accredited to any of the following IT security standards? Submitted: No | Applicable | Gap | — | Medium No ISO 27001 / IRAP / SOC2 accreditation. DISP membership submitted but not yet granted (per 2.11.15). Tracked via DISP project. |
| JOSCAR-Q1.4.12 | Q1.4.12 | Will your organisation or any subcontractor be collecting and/or processing personal information relating to your client's customers or employees on your client's behalf? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q1.5.5 | Q1.5.5 | What percentage of the work undertaken by your organisation is undertaken in Australia, utilising a Australian workforce? Submitted: 100% | Applicable | Partial |
| Medium Scope notes Australian operations but the percentage of work performed by the Australian workforce is not stated as the question requires. (Body also references Singapore operations — now deregistered — which should be refreshed.) |
| JOSCAR-Q1.5.7 | Q1.5.7 | Is any individual within your organisation a current or former Australian Department of Defence employee? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q1.6.1 | Q1.6.1 | Has your organisation or any of its directors been declared bankrupt or insolvent in the past 3 years? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q1.6.2 | Q1.6.2 | Has your organisation been convicted of money laundering practices in the past 3 years? Submitted: No | Applicable | Partial |
| Medium The body contains an anti-bribery / anti-corruption prohibition but no money-laundering-specific basis; the policy supports a clean-conduct posture but the money-laundering-conviction declaration the question asks about is not addressed. |
| JOSCAR-Q1.6.3 | Q1.6.3 | Has your organisation been convicted of bribery or corrupt practices in the past 3 years? Submitted: No | Applicable | Full |
| |
| JOSCAR-Q1.6.4 | Q1.6.4 | Has your organisation had any reportable Health & Safety accidents, incidents or fatalities in the past 3 years? Submitted: No | Applicable | Partial |
| High Declaration of zero reportable incidents over 3 years is being reviewed — see project_safety_reporting_review (PARKED 14/04/2026): 0 LTIs over 15 years not credible, near-miss reporting pathway broken, ISO 45001 cl 9.1/9.3 gaps. Declaration currently supportable on a strict 'reportable to regulator' reading but the underlying reporting system has integrity issues to remediate. |
| JOSCAR-Q1.6.5 | Q1.6.5 | Has your organisation or any of its directors been the subject of any criminal or civil court action in respect of your organisation's business activities in the past 7 years? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q1.6.6 | Q1.6.6 | Has your organisation ever been found to have entered into formal or informal anti-competitive arrangements? Submitted: No | Applicable | Full |
| |
| JOSCAR-Q1.6.7 | Q1.6.7 | Has your organisation been investigated or convicted by a competent authority for any activities relating to Human Rights including slavery, servitude, forced and compulsory labour and human trafficking in the past 5 years? Submitted: No | Applicable | Full |
| |
| JOSCAR-Q1.6.8 | Q1.6.8 | Is your organisation precluded from tendering for Australian Government funded work? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q1.7.1 | Q1.7.1 | Is your organisation Aboriginal or Torres Strait Islanders majority owned? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q1.7.3 | Q1.7.3 | Is your organisation majority veteran owned? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q1.7.4 | Q1.7.4 | Is your organisation registered under the Government Veteran Employment Commitment Organisation? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q1.7.5 | Q1.7.5 | Is your organisation majority female owned? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q1.7.6 | Q1.7.6 | Is your organisation majority disability owned? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q1.7.7 | Q1.7.7 | Is your organisation certified with BuyAbility? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q1.8.5 | Q1.8.5 | Does your organisation ensure that contractors and subcontractors have valid workers compensation and/or registrations for statutory workers compensation? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q1.9.1 | Q1.9.1 | Please confirm that you have read, understood and will comply with Saab's Supplier Code of Conduct. Submitted: Submitted | Applicable | Partial |
| Low Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
| JOSCAR-Q1.9.2 | Q1.9.2 | Please confirm that you have read, understood and will comply with BAE Systems' Supplier Code of Conduct. Submitted: Submitted | Applicable | Partial |
| Low Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
| JOSCAR-Q1.9.3 | Q1.9.3 | Please confirm that you have read, understood and will comply with the Babcock Australasia Code of Business Conduct. Submitted: Submitted | Applicable | Partial |
| Low Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
| JOSCAR-Q1.9.4 | Q1.9.4 | Please confirm that you have read, understood and will comply with the RTX Supplier Code of Conduct. Submitted: Submitted | Applicable | Partial |
| Low Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
| JOSCAR-Q1.9.5 | Q1.9.5 | Please confirm that you have read, understood and will comply with the Boeing Defence Australia Supplier Code of Conduct. Submitted: Submitted | Applicable | Partial |
| Low Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
| JOSCAR-Q1.9.6 | Q1.9.6 | Acknowledgement of General Privacy Notice for the Joint Supply Chain Accreditation Register and certification that data subjects consented to provision of their personal information. Submitted: Submitted | Not Applicable | Not Applicable | — | |
| JOSCAR-Q1.9.7 | Q1.9.7 | Warranty that information provided in the Register is current, complete and accurate; consent for Raytheon Australia to seek financial reports and references. Submitted: Submitted | Applicable | Full | — | |
| JOSCAR-Q1.9.8 | Q1.9.8 | Acknowledgement that information supports Raytheon Australia supply chain due diligence and consent to information sharing with related bodies and advisers. Submitted: Submitted | Not Applicable | Not Applicable | — | |
| JOSCAR-Q1.9.9 | Q1.9.9 | Representation and warranty of familiarity with Australian/FCPA/UK Bribery anti-corruption laws and Modern Slavery Act 2018 (Cth); certification of human-rights policies and supplier compliance. Submitted: Submitted | Applicable | Full |
| |
| JOSCAR-Q1.9.10 | Q1.9.10 | Certification of a process to detect and mitigate potential conflicts of interest, including former ADF/APS/Commonwealth Service Provider employment. Submitted: Submitted | Applicable | Partial |
| Medium Conflict of interest disclosure process (including ADF/APS/CSP former employment) is implicit in the Code of Conduct but no standalone COI procedure or declaration register exists in the WMS. |
| JOSCAR-Q1.9.11 | Q1.9.11 | Certification of policies/procedures addressing the creation, maintenance and retention of accurate business records including those related to quality. Submitted: Submitted | Applicable | Full |
| |
| JOSCAR-Q1.9.12 | Q1.9.12 | Certification that supplier/officers are not listed on any excluded/denied party list and have no recent fraud/corruption/money laundering convictions. Submitted: Submitted | Applicable | Full | — | |
| JOSCAR-Q1.9.13 | Q1.9.13 | Acknowledgement that completion of the Register does not guarantee future tenders/quotes/supply. Submitted: Submitted | Applicable | Full | — | |
| JOSCAR-Q1.9.14 | Q1.9.14 | Confirmation of compliance with Northrop Grumman Australia's Standards of Business Conduct for suppliers. Submitted: Submitted | Applicable | Partial |
| Low Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
| JOSCAR-Q2.2.2 | Q2.2.2 | Does your organisation have a documented Employee Code of Conduct? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.2.3 | Q2.2.3 | Does your organisation have a documented process to verify the competency of individual employees (e.g. competency/training matrix)? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.2.4 | Q2.2.4 | Does your organisation have an induction programme? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.2.5 | Q2.2.5 | Does your organisation use an enterprise agreement approved by Fair Work Australia? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.2.6 | Q2.2.6 | Does your organisation undertake Employee Screening in accordance with National Standards (AS 4811)? Submitted: No | Applicable | Full |
| |
| JOSCAR-Q2.3.4 | Q2.3.4 | Does your organisation comply with applicable competition and anti-trust regulations? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.3.5 | Q2.3.5 | Does your organisation have a Statement of Tax Record (STR)? Submitted: Yes | Applicable | Partial | — | Low STR held in finance records, not a WMS-controlled document. No WMS procedure describes STR maintenance. |
| JOSCAR-Q2.3.6 | Q2.3.6 | Does your organisation collect a Statement of Tax Record for each of your subcontractors? Submitted: No | Applicable | Gap | — | Low Subcontractor STR collection is not documented. Low criticality — applies only to Commonwealth contracts over a threshold; address if Westlink tenders for qualifying government work. |
| JOSCAR-Q2.4.1 | Q2.4.1 | Does your organisation hold a valid Professional Indemnity insurance policy? Submitted: No | Applicable | Gap | — | Medium Professional Indemnity insurance not currently held. Review whether defence industry prime-contractor tenders require PI — if so, procure cover. |
| JOSCAR-Q2.4.2 | Q2.4.2 | Does your organisation hold a valid Care, Custody and Control insurance policy? Submitted: No | Applicable | Gap | — | Medium Care, Custody and Control cover not held. Material risk given warehousing service line — freight forwarding/warehousing typically relies on CCC or Transit Liability cover for client goods. Confirm cover approach with broker. |
| JOSCAR-Q2.4.3 | Q2.4.3 | Does your organisation hold a valid Cyber Liability insurance policy? Submitted: No | Applicable | Gap | — | High Cyber Liability insurance not held. With customer data handling (1.4.7=Yes, 1.4.12=Yes) and DISP membership in progress, Cyber Liability cover is a material exposure. Recommend procuring. |
| JOSCAR-Q2.4.7 | Q2.4.7 | Does your organisation hold a valid Compulsory Third Party (CTP) Motor Vehicle insurance policy? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.4.8 | Q2.4.8 | Does your organisation hold a valid Transit Liability insurance policy? Submitted: No | Applicable | Gap | — | High Transit Liability cover not held. Material given freight service line and customer cargo exposure. Review with broker as a priority. |
| JOSCAR-Q2.5.1 | Q2.5.1 | Does your organisation have an anti-bribery policy or process? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.5.2.1 | Q2.5.2.1 | Does your anti-bribery process include regular assessments to identify and mitigate risks, including reputational risks to your customers? Submitted: Yes | Applicable | Partial |
| Medium Policy references risk approach but no anti-bribery risk register / periodic assessment record exists in the WMS. Historical observation per gap-analysis (Q16) — no anti-bribery risk assessment in the risk register. |
| JOSCAR-Q2.5.2.2 | Q2.5.2.2 | Does your anti-bribery process include regular communication and training for all employees on this process including upon induction? Submitted: Yes | Applicable | Partial |
| Medium Anti-bribery training was added to onboarding per gap-analysis completed action (19/09/2025). Training delivery evidence is operational (CRM training records) rather than in a controlled WMS document. |
| JOSCAR-Q2.5.2.3 | Q2.5.2.3 | Does your anti-bribery process include regular review of this process and monitoring of compliance? Submitted: Yes | Applicable | Partial |
| Medium No documented review schedule or monitoring artefact for anti-bribery compliance in the WMS. Operational review occurs through management review but without a standing anti-bribery agenda item. |
| JOSCAR-Q2.5.2.4 | Q2.5.2.4 | Does your anti-bribery process include controls to prevent corruption, conflicts of interest and unethical behaviour? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.5.2.5 | Q2.5.2.5 | Evidence of senior management commitment to Anti-Bribery legislation? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.5.2.6 | Q2.5.2.6 | Guidance relating to the appropriate acceptance and offering of gifts and hospitality? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.6.2 | Q2.6.2 | Does your organisation have a documented Health & Safety policy? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.6.2.2 | Q2.6.2.2 | Has your organisation's Health & Safety policy been endorsed and signed by senior management? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.6.9 | Q2.6.9 | Does your organisation have a Drug & Alcohol policy? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.6.10 | Q2.6.10 | Does your organisation have a Chain of Responsibility policy? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.6.11 | Q2.6.11 | Does your organisation have a hazard and risk management process? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.6.12 | Q2.6.12 | Does your organisation have Crisis Management and Emergency response plans? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.6.13 | Q2.6.13 | Does your organisation use hazardous substances? Submitted: No | Applicable | Gap | — | Medium P1.2 relevance adjudication (2026-06-19, CF): flipped N/A->Applicable. 'Use of hazardous substances' is a WHS/GHS workplace question, not a DG-freight question — onsite/warehouse operations (including biosecurity fumigation handling) engage common hazardous chemicals binding Westlink's own WHS duty; sibling Q2.6.15 is already Applicable on identical own-personnel logic. The submitted JOSCAR answer 'No' understated this — flag for JOSCAR answer-integrity refresh. Existing WHS hazard management (QHSE-PRO-001, QHSE-PRO-007, QHSE-MAN-001) references hazardous substances but no dedicated SDS/chemical-management control is wired; coverage + evidence to be assessed in P2 (likely Partial). |
| JOSCAR-Q2.6.14 | Q2.6.14 | Does your organisation import plant, equipment or goods from overseas containing asbestos? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q2.6.15 | Q2.6.15 | Does your organisation require personnel to hold a High Risk Work Licence (HRWL)? Submitted: No | Applicable | Full |
| |
| JOSCAR-Q2.7.3 | Q2.7.3 | Does your organisation have a documented Environmental Policy? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.7.3.1 | Q2.7.3.1 | Has your organisation formally communicated your environmental policy to your employees? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.7.3.3 | Q2.7.3.3 | Has your organisation's Environmental policy been endorsed and signed by senior management? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.7.6 | Q2.7.6 | Is your company working towards achieving net zero (scope 1, 2 and 3), in accordance with top level management set objectives & targets? Submitted: No | Applicable | Gap | — | Medium No net-zero commitment or Scope 1/2/3 target has been adopted. Historical observation (Q36 per gap-analysis). Emerging defence-industry prime requirement — consider scoping in 2026 environmental objectives review. |
| JOSCAR-Q2.7.7 | Q2.7.7 | Please select which categories of greenhouse gas emissions your organisation publicly reports on. Submitted: None | Applicable | Gap | — | Low Westlink is below NGER reporting thresholds and does not voluntarily publish GHG data. Address alongside any net-zero commitment decision. |
| JOSCAR-Q2.7.11 | Q2.7.11 | Does your organisation have a documented Corporate & Social Responsibility (CSR) or ESG policy? Submitted: No | Applicable | Gap | — | Medium No standalone CSR / ESG policy. Historical observation (Q37 per gap-analysis). Elements covered in Modern Slavery, Environment, Privacy and Code of Conduct but not consolidated. |
| JOSCAR-Q2.7.12 | Q2.7.12 | Does your organisation have a policy that documents your approach to Labour Standards & Human Rights? Submitted: No | Applicable | Full |
| |
| JOSCAR-Q2.7.13 | Q2.7.13 | Does your organisation have a policy documenting its approach to Diversity & Inclusion? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.7.13.1 | Q2.7.13.1 | Does your organisation measure how you are performing on Diversity & Inclusion? Submitted: No | Applicable | Gap | — | Low No D&I performance metrics tracked. Historical observation (Q40). Low priority given 12-person workforce; address via annual D&I objective-setting if scaled. |
| JOSCAR-Q2.7.13.2 | Q2.7.13.2 | Does your organisation have a documented process in place to handle reports of discrimination? Submitted: Yes | Applicable | Partial |
| Medium Grievance Resolution Procedure (legacy HRS-PRO-003) has not been migrated to the new WMS corpus. Current reporting channels rely on the Code of Conduct and Whistleblower Policy. |
| JOSCAR-Q2.7.13.3 | Q2.7.13.3 | Does your organisation have a process and measures in place to integrate disabled persons into your workforce? Submitted: No | Applicable | Gap |
| Low Historical observation (Q42). Policy-level commitment only; no operational measures. |
| JOSCAR-Q2.7.19 | Q2.7.19 | Does your organisation have a Reconciliation Action Plan (or similar) that provides an organisation commitment to Indigenous employment targets? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.7.21 | Q2.7.21 | Does your organisation identify, support, or partner with Indigenous enterprises or participate in social impact initiatives? Submitted: Yes | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.7.24 | Q2.7.24 | Does your organisation have a strategy to engage with and procure from Small to Medium Enterprises (SMEs)? Submitted: Yes | Applicable | Partial | — | Low Procurement approach is SME-friendly operationally; no documented SME engagement strategy exists in the WMS. |
| JOSCAR-Q2.7.16 | Q2.7.16 | Does your organisation ensure that the National Minimum Wage is paid to all employees in the jurisdictions in which it operates? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.8.5 | Q2.8.5 | Does your organisation have a documented Quality policy? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.8.5.2 | Q2.8.5.2 | Has your organisation's Quality policy been endorsed and signed by senior management? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.8.25 | Q2.8.25 | Does your organisation have processes and associated documentation relating to obsolescence management? Submitted: No | Applicable | Gap | — | Medium No documented obsolescence-management process. A prior IsCompliant remediation (19/09/2025) is not reflected in the Manual text. |
| JOSCAR-Q2.8.26 | Q2.8.26 | Does your organisation monitor an originating order or customer requirements throughout all stages of work? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.8.27 | Q2.8.27 | Does your organisation issue original Certificates of Conformance for applicable deliverables? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.8.28 | Q2.8.28 | Does your organisation have a process to promptly inform customers of any anticipated delays in delivery? Submitted: Yes | Applicable | Gap | — | Medium No delivery-delay notification process documented. |
| JOSCAR-Q2.9.1 | Q2.9.1 | Does your organisation have policies and/or processes and associated support documentation that addresses product safety requirements and related statutory obligations? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.9.5 | Q2.9.5 | Does your organisation sub-contract design work? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.9.6 | Q2.9.6 | Does your organisation have a policy to ensure customers are notified of the presence of hazardous materials in the products you supply or generated as a result of the service you provide? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.9.10 | Q2.9.10 | Does your organisation proactively and in a timely manner communicate security vulnerabilities to customers for delivered goods? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.9.11 | Q2.9.11 | Does your organisation perform testing of your goods to ensure that vulnerabilities are identified and actively remediated? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.9.12 | Q2.9.12 | Does your organisation have protective measures in place to prevent your goods from sabotage or tampering during manufacturing and through final delivery? Submitted: No | Applicable | Partial |
| Medium Anti-sabotage/tamper coverage is partial: Westlink is asset-light with no manufacturing leg, so physical-security controls apply at the air-cargo handling layer (OPS-PRO-001 / GOV-POL-023) rather than to production. |
| JOSCAR-Q2.9.13 | Q2.9.13 | Are security risks inherent in your organisation's systems and processes (e.g. design, manufacturing, test, sustainment) identified and mitigated or managed on an ongoing basis? Submitted: No | Applicable | Partial |
| Medium A general ISO 31000 risk-based approach is described and information security is flagged as an internal issue with DISP/ISM references, but security risks across systems and processes are not substantively identified and mitigated as a managed process in the body. |
| JOSCAR-Q2.10.1 | Q2.10.1 | Does your organisation have a documented supplier/subcontractor assessment procedure? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.10.2.1 | Q2.10.2.1 | Does your supplier/subcontractor assessment procedure include controls to manage anti-bribery and corruption risk? Submitted: Yes | Applicable | Partial |
| Medium Supplier anti-bribery flow-down is policy-level only; supplier assessment procedure to give effect to this is pending (see 2.10.1). |
| JOSCAR-Q2.10.2.2 | Q2.10.2.2 | Does your supplier/subcontractor assessment procedure include controls to identify and mitigate the risk of Modern Slavery and Human Trafficking? Submitted: Yes | Applicable | Partial |
| Medium Modern Slavery supplier flow-down is in place via purchase-order terms (legacy reference); prequalification questionnaires (legacy SCM-FRM-001/002) not yet migrated. Historical observation Q5. |
| JOSCAR-Q2.10.2.3 | Q2.10.2.3 | Does your supplier/subcontractor assessment procedure include controls to manage environmental risk? Submitted: Yes | Applicable | Gap | — | Medium Environmental risk flow-down is implied via policy; supplier assessment procedure pending migration. |
| JOSCAR-Q2.10.2.4 | Q2.10.2.4 | Does your supplier/subcontractor assessment procedure include controls to collect and validate certificates of currency from critical suppliers? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.10.2.5 | Q2.10.2.5 | Does your supplier/subcontractor assessment procedure include a process to audit critical suppliers? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.10.2.6 | Q2.10.2.6 | Does your supplier/subcontractor assessment procedure include controls to monitor the financial stability of critical suppliers? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.10.2.7 | Q2.10.2.7 | Does your supplier/subcontractor assessment procedure include an induction process for suppliers entering your site? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.10.3 | Q2.10.3 | Does your organisation have a process for ensuring that on-site welfare provision meets legal requirements and the needs and expectations of its workforce? Submitted: No | Applicable | Gap | — | Low On-site welfare-provision adequacy against legal requirements not articulated in a WHS procedure. |
| JOSCAR-Q2.10.4 | Q2.10.4 | Does your organisation have a documented Code of Conduct for suppliers? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.10.5 | Q2.10.5 | Please select which tiers of your supply chain your organisation collects information on. Submitted: Tier 1 | Applicable | Partial | — | Low Tier 1 only — consistent with 12-person service-provider scale. No sub-tier supply chain visibility documented. |
| JOSCAR-Q2.10.6 | Q2.10.6 | Does your organisation measure your suppliers' compliance and performance in line with your Health & Safety requirements? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.10.7 | Q2.10.7 | Does your organisation have a list of approved or preferred suppliers including critical subcontractors? Submitted: Yes | Applicable | Partial | — | Low Preferred supplier list is maintained in CRM / operational systems; not a controlled WMS document. |
| JOSCAR-Q2.10.8 | Q2.10.8 | Does your organisation have defined acceptance criteria for approved or preferred suppliers including critical subcontractors? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.11.1 | Q2.11.1 | Does your organisation have a documented Information Security Policy? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.11.1.1 | Q2.11.1.1 | Does your organisation have a process in place for communicating Cyber Security alerts/breaches to your customers? Submitted: Yes — Within 24 hours | Applicable | Gap | — | High Policy commitment present; implementing Cyber Incident Response Plan (which would document the 24-hour customer notification pathway) is a Critical gap per the E8 ML2 library. External to WMS — Becloudsmart handles detection/escalation. |
| JOSCAR-Q2.11.1.2 | Q2.11.1.2 | Has your organisation or system undergone an IRAP assessment against the Australian Government's Information Security Manual (ISM)? Submitted: No | Applicable | Gap | — | Medium No IRAP assessment completed. Q68 flagged in gap-analysis — 2024 Defence Cyber Assessment was 'Embedded' but this is not an IRAP. Review whether IRAP is required for DISP Entry Level (generally not) or for specific defence-industry contracts. |
| JOSCAR-Q2.11.2 | Q2.11.2 | Is your organisation compliant with the cyber security framework set out in the Australian Government's Information Security Manual (ISM)? Submitted: Yes | Applicable | Partial |
| High Submitted 'Yes' is aspirational — E8 ML2 library shows substantial gaps against ISM controls (incident response plan, central logging, phishing-resistant MFA). Treat as partial pending the DISP uplift programme completing. |
| JOSCAR-Q2.11.5 | Q2.11.5 | Does your organisation have an in-house documented Information Security management system? Submitted: Yes | Applicable | Partial |
| High An ISMS document suite has been initiated via TEC-POL-001/002. A full ISO 27001-style ISMS (scope statement, SoA, risk treatment plan, internal audit, management review) is not yet in place. |
| JOSCAR-Q2.11.5.2 | Q2.11.5.2 | Does your Information Security management system include a process to classify the types of information your organisation holds? Submitted: Yes | Applicable | Partial |
| Medium Classification scheme referenced in TEC-POL-001 but an information classification standard/matrix is not separately published. OFFICIAL / OFFICIAL:Sensitive handling is operational. |
| JOSCAR-Q2.11.5.3 | Q2.11.5.3 | Does your Information Security management system include a process to identify, risk assess and record critical assets at least annually? Submitted: Yes | Applicable | Gap | — | High Historical observation Q72. No annual critical-asset identification cycle is evidenced. InfoSec Risk Assessment Register was stale (last updated Aug 2022) before the 19/09/2025 completed IsCompliant remediation — verify currency. |
| JOSCAR-Q2.11.5.4 | Q2.11.5.4 | Does your Information Security management system include accountabilities and responsibilities based on clearly defined roles for cyber security? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.11.6 | Q2.11.6 | Does your organisation have a documented User Access Management Policy to control access to confidential information provided by, or produced for, your customers? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.11.7 | Q2.11.7 | Does your organisation have a process to identify, assess and record information security risks at least annually? Submitted: Yes | Applicable | Partial |
| High Historical observation Q75 — InfoSec Risk Assessment Register stale (Aug 2022). Reported last-assessed 14/06/2024 in portal. IsCompliant action 19/09/2025 marked complete — verify register reflects genuinely annual cadence going forward. |
| JOSCAR-Q2.11.8 | Q2.11.8 | Does your organisation have a System Security Patching policy? Submitted: No | Applicable | Partial |
| Medium Patch-management commitment exists at policy level (TEC-POL-001 — critical/high patches within 48 hours); no dedicated System Security Patching policy/procedure. Residual — dedicated patching procedure + E8 ML2 patching-cadence implementation (Becloudsmart uplift). |
| JOSCAR-Q2.11.9 | Q2.11.9 | Does your organisation have a documented system/network security monitoring policy? Submitted: Yes | Applicable | Gap | — | High Monitoring is delivered operationally via Becloudsmart-managed Defender/Sentinel. No dedicated monitoring policy or procedure exists in the controlled WMS corpus. |
| JOSCAR-Q2.11.10 | Q2.11.10 | Does your organisation formally review the physical security environment and risks whenever there is a significant change but no less frequently than annually? Submitted: Yes | Applicable | Gap | — | High Historical observation Q78 — physical security reviews not documented. No controlled record of physical security review cycle exists. DISP Entry Level physical security obligations not evidenced in the WMS. |
| JOSCAR-Q2.11.11 | Q2.11.11 | Does your organisation have regular mandatory security training for all employees and contractors? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.11.12 | Q2.11.12 | Does your organisation have a documented Security Incident Management policy? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.11.13 | Q2.11.13 | Has your organisation completed the Cyber For Defence Industry (CFDI) questionnaire? Submitted: Yes | Applicable | Gap | — | Low CFDI questionnaire completion not stated or evidenced. |
| JOSCAR-Q2.11.15 | Q2.11.15 | Has your organisation applied for Defence Industry Security Programme (DISP) membership? Submitted: Submitted | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.11.16 | Q2.11.16 | Has your organisation been the subject of any external security investigation? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q2.11.17 | Q2.11.17 | Has your organisation notified any customers, legislators, or regulators of any information, IT or cyber security incidents within the last three years? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q2.11.18 | Q2.11.18 | Has your organisation had a cyber security breach in the last three years? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q2.11.19 | Q2.11.19 | Does your organisation deploy Multi Factor Authentication (MFA) across all systems? Submitted: Yes | Applicable | Partial |
| High MFA is deployed across M365 tenancy. Phishing-resistant MFA (E8 ML2 requirement) is not yet in place — Critical gap per E8 ML2 library. Portal answer 'Yes' correct for baseline MFA but does not reflect ML2 phishing-resistant standard. |
| JOSCAR-Q2.11.20 | Q2.11.20 | Does your organisation take regular backups on systems containing customer data? Submitted: No | Applicable | Partial |
| Medium Backup commitment exists at policy level (TEC-POL-001) and M365 native retention/restore is in place for email/SharePoint/OneDrive. Residual — no dedicated backup policy, retention schedule, or immutability control documented in the WMS; E8 ML2 Regular Backups implementation (Becloudsmart uplift). |
| JOSCAR-Q2.12.1 | Q2.12.1 | Does your organisation have a documented Data Privacy & Protection policy? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.12.1.1 | Q2.12.1.1 | Does your organisation's Data Privacy & Protection policy apply to personal data collected or processed on the client's behalf, or collected from the client? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.12.2.1 | Q2.12.2.1 | Does your Data Privacy & Protection policy define what personal data is collected? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.12.2.2 | Q2.12.2.2 | Does your Data Privacy & Protection policy define when the individual's permission is sought? Submitted: Yes | Applicable | Partial |
| Medium Commitment 1 references collection notice / APP 5 and reasonable expectation; consent is implied but the policy never states when permission is sought. |
| JOSCAR-Q2.12.2.3 | Q2.12.2.3 | Does your Data Privacy & Protection policy address protection of personal data against accidental or deliberate misuse, damage or destruction? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.12.2.4 | Q2.12.2.4 | Does your Data Privacy & Protection policy address transferring of personal data to other jurisdictions only in compliance with relevant local data privacy laws and with approval from the customer? Submitted: No | Applicable | Gap | — | Medium Cross-border transfer clauses not present in Privacy Policy. Low likelihood of cross-border transfer in day-to-day operations (see 2.12.5 = No), but Privacy Policy should still cover the obligation for completeness. |
| JOSCAR-Q2.12.2.5 | Q2.12.2.5 | Regular training for all employees on this process including upon induction? Submitted: Yes | Applicable | Gap | — | Medium Privacy training delivery is operational; evidenced via training records in CRM rather than a controlled WMS training procedure. |
| JOSCAR-Q2.12.3 | Q2.12.3 | Does your organisation ensure that all personal data is kept up to date? Submitted: Yes | Applicable | Partial |
| Medium Commitment 4 commits to correcting inaccurate or out-of-date information on request (APP 13), but there is no proactive mechanism to keep personal information up to date; the control is reactive only. |
| JOSCAR-Q2.12.4 | Q2.12.4 | Does your organisation have a documented and implemented data retention schedule in place which covers your client's personal data? Submitted: Yes | Applicable | Partial |
| Medium IsCompliant action (31/07/2025, completed 23/09/2025) marked done but a standalone data retention schedule document cannot be located in the current WMS corpus. Verify and publish. |
| JOSCAR-Q2.12.5 | Q2.12.5 | Does your organisation transfer or process personal data belonging to your clients outside Australia? Submitted: No | Applicable | Gap | — | High No policy element addresses APP 8 / overseas-disclosure commitment. Westlink does not restrict processing to Australia; prior TEC-POL-001 and GOV-POL-015 evidence notes were factually incorrect (S144 D3c). Policy gap: GOV-POL-015 needs an APP 8 overseas-disclosure commitment in a future revision (cf. PRV-APP8-01 framework Critical gap). |
| JOSCAR-Q2.13.1 | Q2.13.1 | Does your organisation hold any of the listed regulated licences (or any other not listed)? Submitted: None of the above / No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.13.4 | Q2.13.4 | Is your organisation registered with the Australian Skills Quality Authority as a Registered Training Organisation? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.14.1 | Q2.14.1 | Does your organisation operate to the principles of any of the following counterfeit-prevention standards (e.g. AS6174, SAE AS5553)? Submitted: None of the above | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.14.2 | Q2.14.2 | Does your organisation have a documented Counterfeit Products/Materiel policy, plan, or process? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.14.6 | Q2.14.6 | Do your organisation's processes include suitable disposal methods of component/material packaging? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.14.7 | Q2.14.7 | Do your suppliers' processes include suitable disposal methods of component/material packaging with identification and traceability? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.14.8 | Q2.14.8 | When buying items of high concern, do your organisation's processes ensure returned goods are not purchased without a formal risk agreement with the customer? Submitted: No | Not Applicable | Not Applicable | — | |
| JOSCAR-Q2.15.1 | Q2.15.1 | Does your organisation have a documented Business Continuity Plan? Submitted: No | Applicable | Full |
| |
| JOSCAR-Q2.20.1 | Q2.20.1 | Is your organisation required to report under the Modern Slavery Act 2018 (Cth)? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q2.20.2.1 | Q2.20.2.1 | Addressed/incorporated modern slavery, forced labour, and human trafficking guidelines into your organisation's policies? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.20.2.2 | Q2.20.2.2 | Included modern slavery, forced labour, and human trafficking guidelines for your supply chain into your standard terms and conditions with suppliers? Submitted: Yes | Applicable | Partial |
| Medium Modern slavery flow-down is in purchase order T&C (legacy COM-STD reference). Current equivalent T&C document exists but mapping to the new WMS corpus reference is pending. |
| JOSCAR-Q2.20.2.3 | Q2.20.2.3 | Conducting regular risk assessments of your suppliers against criteria that includes modern slavery, forced labour, and human trafficking? Submitted: Yes | Applicable | Partial |
| Medium Historical observation Q5 — supplier risk assessments do not always include modern slavery criteria. Remediation via pending supplier assessment procedure migration. |
| JOSCAR-Q2.20.2.4 | Q2.20.2.4 | Training your employees on the prevention of modern slavery, forced labour, and human trafficking, including upon induction? Submitted: Yes | Applicable | Partial |
| Medium Training is operational; no standalone training record for modern slavery exists in controlled WMS. |
| JOSCAR-Q2.20.3 | Q2.20.3 | Does your organisation have a person or team responsible for overseeing modern slavery risks arising from the goods or services that you deliver? Submitted: Yes | Applicable | Full |
| |
| JOSCAR-Q2.20.4 | Q2.20.4 | Is your organisation aware of low-skilled migrant workers working in your organisation's supply chains? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q2.20.5 | Q2.20.5 | Does your organisation retain any original employee documentation (passports, identity papers) or any part of their salary? Submitted: No | Applicable | Gap | — | Medium No WMS document states the prohibition on retaining passports or withholding salary (a forced-labour / modern-slavery indicator). |
| JOSCAR-Q2.20.6 | Q2.20.6 | Does your organisation have controls in place to ensure that workers are paid lawfully and fairly, and that no improper wage deductions or financial penalties are imposed? Submitted: Yes | Applicable | Partial |
| Medium The Labour section commits to minimum wages, NES and lawful engagement, supporting lawful and fair pay, but there is no explicit control against improper wage deductions or financial penalties at the level the question requires. |
| JOSCAR-Q2.20.7 | Q2.20.7 | Does your organisation have a documented statement to capture freedom of association to a union? Submitted: No | Applicable | Gap | — | Low No explicit freedom-of-association statement. Implicit coverage via Fair Work Act compliance and Code of Conduct. Low priority — could be addressed in Code of Conduct update. |
| JOSCAR-Q2.20.8 | Q2.20.8 | Does your organisation have an anonymous whistleblowers hotline, email, or web link (URL) available on your public company website for confidential use? Submitted: No | Applicable | Partial |
| Medium Whistleblower Policy exists but no public-facing anonymous channel is published on westlinklogistics.com. Remediation: publish whistleblower URL/email on website. |
| JOSCAR-Q2.20.9 | Q2.20.9 | Does your organisation have a public complaints system available and easily accessible to the public? Submitted: No | Applicable | Gap | — | Low No public-facing complaints system published. General 'contact us' channel exists. Address alongside 2.20.8 website whistleblower publication. |
| JOSCAR-Q2.20.10 | Q2.20.10 | Does your organisation have any employees under the age of 18? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q2.20.11 | Q2.20.11 | Does your organisation ensure that employment contracts are provided to employees in a language that they can understand? Submitted: Yes | Applicable | Full | — | |
| JOSCAR-Q2.20.12 | Q2.20.12 | Do your organisation's employment contracts clearly state key terms of employment, such as wage rates and expected working hours? Submitted: Yes | Applicable | Full | — | |
| JOSCAR-Q2.20.14 | Q2.20.14 | Does your organisation procure raw materials, inputs to manufacture, service related inputs, constructed materials/parts/components from sources outside of Australia, New Zealand, Europe, Canada or the USA? Submitted: No | Applicable | Full | — | |
| JOSCAR-Q2.20.15 | Q2.20.15 | Has your organisation identified any instances of forced labour, modern slavery or human trafficking in your organisation or your supply chain in the last three years? Submitted: No | Not Applicable | Not Applicable | — |
Source document
JOSCAR-AU 2026 Questionnaire — Submitted Answers and Evidence Mapping for Westlink Logistics
173 normative shall-statements extracted from JOSCAR-AU 2026 (source: ~/projects/wms/sources/joscar/Westlink Logistics Pty Ltd-14-April-2026-questionnaire.pdf). The frontmatter requirements array is the source of truth — this body is rendered by scripts/render_compliance.py.
Coverage summary
| Coverage | Count |
|---|---|
| ✅ Full | 83 |
| 🟡 Partial | 40 |
| 🟠 Ref-only | 0 |
| 🔴 Gap | 28 |
| — N/A | 22 |
Gap severity distribution
| Severity | Count |
|---|---|
| 🔴 Critical | 0 |
| 🟠 High | 12 |
| 🟡 Medium | 35 |
| 🟢 Low | 21 |
Requirements
Clause Q1
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| JOSCAR-Q1.3.1 | ✅ Full | QHSE-MAN-001 §‘1’ | ||
| JOSCAR-Q1.3.2 | ✅ Full | QHSE-MAN-001 §‘1’ | ||
| JOSCAR-Q1.3.6 | 🟡 Partial | — | 🟢 Low | NCAGE code is held (Z0QJ3) but not recorded in any controlled WMS document. Consider adding to Organisation Identity section of QHSE-MAN-001 §1 or a Defence Industry Registration Register. |
| JOSCAR-Q1.3.13 | ✅ Full | QHSE-MAN-001 §‘1’ | ||
| JOSCAR-Q1.3.14 | 🟡 Partial | — | 🟢 Low | Certificate of Currency held outside the WMS corpus (operational insurance register). Not a WMS-controlled document — evidence lives in finance records. |
| JOSCAR-Q1.3.16 | 🟡 Partial | — | 🟢 Low | Certificate of Currency held outside the WMS corpus (finance records). Not a WMS-controlled document. |
| JOSCAR-Q1.3.17 | — N/A | — | N/A — Westlink is a service provider (logistics, freight, warehousing, customs brokerage) — does not manufacture or supply physical products requiring Products Liability cover. | |
| JOSCAR-Q1.4.3 | ✅ Full | OPS-PRO-001 | ||
| JOSCAR-Q1.4.7 | ✅ Full | TEC-POL-001 GOV-POL-015 | ||
| JOSCAR-Q1.4.8 | ✅ Full | QHSE-PRO-002 | ||
| JOSCAR-Q1.4.9 | ✅ Full | QHSE-MAN-001 | ||
| JOSCAR-Q1.4.10 | ✅ Full | TEC-POL-001 | ||
| JOSCAR-Q1.4.11 | 🔴 Gap | — | 🟡 Medium | No ISO 27001 / IRAP / SOC2 accreditation. DISP membership submitted but not yet granted (per 2.11.15). Tracked via DISP project. |
| JOSCAR-Q1.4.12 | ✅ Full | GOV-POL-015 | ||
| JOSCAR-Q1.5.5 | 🟡 Partial | QHSE-MAN-001 §‘1’ | 🟡 Medium | Scope notes Australian operations but the percentage of work performed by the Australian workforce is not stated as the question requires. (Body also references Singapore operations — now deregistered — which should be refreshed.) |
| JOSCAR-Q1.5.7 | ✅ Full | — | ||
| JOSCAR-Q1.6.1 | ✅ Full | — | ||
| JOSCAR-Q1.6.2 | 🟡 Partial | GOV-POL-012 | 🟡 Medium | The body contains an anti-bribery / anti-corruption prohibition but no money-laundering-specific basis; the policy supports a clean-conduct posture but the money-laundering-conviction declaration the question asks about is not addressed. |
| JOSCAR-Q1.6.3 | ✅ Full | GOV-POL-012 GOV-POL-019 | ||
| JOSCAR-Q1.6.4 | 🟡 Partial | QHSE-PRO-001 | 🟠 High | Declaration of zero reportable incidents over 3 years is being reviewed — see project_safety_reporting_review (PARKED 14/04/2026): 0 LTIs over 15 years not credible, near-miss reporting pathway broken, ISO 45001 cl 9.1/9.3 gaps. Declaration currently supportable on a strict ‘reportable to regulator’ reading but the underlying reporting system has integrity issues to remediate. |
| JOSCAR-Q1.6.5 | ✅ Full | — | ||
| JOSCAR-Q1.6.6 | ✅ Full | HR-STD-001 | ||
| JOSCAR-Q1.6.7 | ✅ Full | GOV-POL-013 | ||
| JOSCAR-Q1.6.8 | ✅ Full | — | ||
| JOSCAR-Q1.7.1 | ✅ Full | — | ||
| JOSCAR-Q1.7.3 | ✅ Full | — | ||
| JOSCAR-Q1.7.4 | ✅ Full | — | ||
| JOSCAR-Q1.7.5 | ✅ Full | — | ||
| JOSCAR-Q1.7.6 | ✅ Full | — | ||
| JOSCAR-Q1.7.7 | ✅ Full | — | ||
| JOSCAR-Q1.8.5 | ✅ Full | QHSE-PRO-002 | ||
| JOSCAR-Q1.9.1 | 🟡 Partial | GOV-POL-019 | 🟢 Low | Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
| JOSCAR-Q1.9.2 | 🟡 Partial | GOV-POL-019 | 🟢 Low | Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
| JOSCAR-Q1.9.3 | 🟡 Partial | GOV-POL-019 | 🟢 Low | Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
| JOSCAR-Q1.9.4 | 🟡 Partial | GOV-POL-019 | 🟢 Low | Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
| JOSCAR-Q1.9.5 | 🟡 Partial | GOV-POL-019 | 🟢 Low | Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
| JOSCAR-Q1.9.6 | — N/A | — | N/A — JOSCAR registration attestation — acknowledgement of the JOSCAR General Privacy Notice and certification of data-subject consent; answered at JOSCAR registration, not a WMS-library policy obligation. | |
| JOSCAR-Q1.9.7 | ✅ Full | — | ||
| JOSCAR-Q1.9.8 | — N/A | — | N/A — JOSCAR registration attestation — consent to share information with Raytheon for due diligence; answered at registration, not a WMS-library obligation. | |
| JOSCAR-Q1.9.9 | ✅ Full | GOV-POL-012 GOV-POL-013 GOV-POL-019 | ||
| JOSCAR-Q1.9.10 | 🟡 Partial | GOV-POL-019 | 🟡 Medium | Conflict of interest disclosure process (including ADF/APS/CSP former employment) is implicit in the Code of Conduct but no standalone COI procedure or declaration register exists in the WMS. |
| JOSCAR-Q1.9.11 | ✅ Full | GOV-POL-001 QHSE-MAN-001 | ||
| JOSCAR-Q1.9.12 | ✅ Full | — | ||
| JOSCAR-Q1.9.13 | ✅ Full | — | ||
| JOSCAR-Q1.9.14 | 🟡 Partial | GOV-POL-019 | 🟢 Low | Submitted answer is an external attestation against a third-party Code of Conduct / terms; no Westlink-controlled evidence is uploaded to the portal and none is expected — captured here for traceability of the assurance given. |
Clause Q2
| ID | Coverage | Evidence | Gap | Notes |
|---|---|---|---|---|
| JOSCAR-Q2.2.2 | ✅ Full | HR-STD-001 | ||
| JOSCAR-Q2.2.3 | ✅ Full | QHSE-MAN-001 | ||
| JOSCAR-Q2.2.4 | ✅ Full | QHSE-MAN-001 | ||
| JOSCAR-Q2.2.5 | — N/A | — | N/A — Westlink does not operate under an enterprise agreement; National Employment Standards and relevant Modern Awards apply. | |
| JOSCAR-Q2.2.6 | ✅ Full | HR-PRO-001 | ||
| JOSCAR-Q2.3.4 | ✅ Full | HR-STD-001 | ||
| JOSCAR-Q2.3.5 | 🟡 Partial | — | 🟢 Low | STR held in finance records, not a WMS-controlled document. No WMS procedure describes STR maintenance. |
| JOSCAR-Q2.3.6 | 🔴 Gap | — | 🟢 Low | Subcontractor STR collection is not documented. Low criticality — applies only to Commonwealth contracts over a threshold; address if Westlink tenders for qualifying government work. |
| JOSCAR-Q2.4.1 | 🔴 Gap | — | 🟡 Medium | Professional Indemnity insurance not currently held. Review whether defence industry prime-contractor tenders require PI — if so, procure cover. |
| JOSCAR-Q2.4.2 | 🔴 Gap | — | 🟡 Medium | Care, Custody and Control cover not held. Material risk given warehousing service line — freight forwarding/warehousing typically relies on CCC or Transit Liability cover for client goods. Confirm cover approach with broker. |
| JOSCAR-Q2.4.3 | 🔴 Gap | — | 🟠 High | Cyber Liability insurance not held. With customer data handling (1.4.7=Yes, 1.4.12=Yes) and DISP membership in progress, Cyber Liability cover is a material exposure. Recommend procuring. |
| JOSCAR-Q2.4.7 | — N/A | — | N/A — Westlink does not operate its own motor vehicle fleet — road freight is subcontracted. CTP is carried by subcontracted carriers. | |
| JOSCAR-Q2.4.8 | 🔴 Gap | — | 🟠 High | Transit Liability cover not held. Material given freight service line and customer cargo exposure. Review with broker as a priority. |
| JOSCAR-Q2.5.1 | ✅ Full | GOV-POL-012 GOV-POL-019 | ||
| JOSCAR-Q2.5.2.1 | 🟡 Partial | GOV-POL-012 | 🟡 Medium | Policy references risk approach but no anti-bribery risk register / periodic assessment record exists in the WMS. Historical observation per gap-analysis (Q16) — no anti-bribery risk assessment in the risk register. |
| JOSCAR-Q2.5.2.2 | 🟡 Partial | GOV-POL-012 | 🟡 Medium | Anti-bribery training was added to onboarding per gap-analysis completed action (19/09/2025). Training delivery evidence is operational (CRM training records) rather than in a controlled WMS document. |
| JOSCAR-Q2.5.2.3 | 🟡 Partial | GOV-POL-012 | 🟡 Medium | No documented review schedule or monitoring artefact for anti-bribery compliance in the WMS. Operational review occurs through management review but without a standing anti-bribery agenda item. |
| JOSCAR-Q2.5.2.4 | ✅ Full | GOV-POL-012 GOV-POL-019 | ||
| JOSCAR-Q2.5.2.5 | ✅ Full | GOV-POL-012 | ||
| JOSCAR-Q2.5.2.6 | ✅ Full | GOV-POL-019 GOV-POL-012 | ||
| JOSCAR-Q2.6.2 | ✅ Full | GOV-POL-002 | ||
| JOSCAR-Q2.6.2.2 | ✅ Full | GOV-POL-002 | ||
| JOSCAR-Q2.6.9 | ✅ Full | GOV-POL-003 | ||
| JOSCAR-Q2.6.10 | ✅ Full | QHSE-MAN-001 | ||
| JOSCAR-Q2.6.11 | ✅ Full | QHSE-PRO-001 QHSE-MAN-001 | ||
| JOSCAR-Q2.6.12 | ✅ Full | QHSE-PLN-002 QHSE-MAN-001 | ||
| JOSCAR-Q2.6.13 | 🔴 Gap | — | 🟡 Medium | P1.2 relevance adjudication (2026-06-19, CF): flipped N/A->Applicable. ‘Use of hazardous substances’ is a WHS/GHS workplace question, not a DG-freight question — onsite/warehouse operations (including biosecurity fumigation handling) engage common hazardous chemicals binding Westlink’s own WHS duty; sibling Q2.6.15 is already Applicable on identical own-personnel logic. The submitted JOSCAR answer ‘No’ understated this — flag for JOSCAR answer-integrity refresh. Existing WHS hazard management (QHSE-PRO-001, QHSE-PRO-007, QHSE-MAN-001) references hazardous substances but no dedicated SDS/chemical-management control is wired; coverage + evidence to be assessed in P2 (likely Partial). |
| JOSCAR-Q2.6.14 | ✅ Full | — | ||
| JOSCAR-Q2.6.15 | ✅ Full | QHSE-PRO-002 | ||
| JOSCAR-Q2.7.3 | ✅ Full | GOV-POL-004 | ||
| JOSCAR-Q2.7.3.1 | ✅ Full | GOV-POL-004 | ||
| JOSCAR-Q2.7.3.3 | ✅ Full | GOV-POL-004 | ||
| JOSCAR-Q2.7.6 | 🔴 Gap | — | 🟡 Medium | No net-zero commitment or Scope 1/2/3 target has been adopted. Historical observation (Q36 per gap-analysis). Emerging defence-industry prime requirement — consider scoping in 2026 environmental objectives review. |
| JOSCAR-Q2.7.7 | 🔴 Gap | — | 🟢 Low | Westlink is below NGER reporting thresholds and does not voluntarily publish GHG data. Address alongside any net-zero commitment decision. |
| JOSCAR-Q2.7.11 | 🔴 Gap | — | 🟡 Medium | No standalone CSR / ESG policy. Historical observation (Q37 per gap-analysis). Elements covered in Modern Slavery, Environment, Privacy and Code of Conduct but not consolidated. |
| JOSCAR-Q2.7.12 | ✅ Full | [GOV-POL-013 §‘Labour Standards and Human Rights’](/wms/GOV-POL-013#s’Labour Standards and Human Rights’) | ||
| JOSCAR-Q2.7.13 | ✅ Full | GOV-POL-010 | ||
| JOSCAR-Q2.7.13.1 | 🔴 Gap | — | 🟢 Low | No D&I performance metrics tracked. Historical observation (Q40). Low priority given 12-person workforce; address via annual D&I objective-setting if scaled. |
| JOSCAR-Q2.7.13.2 | 🟡 Partial | GOV-POL-018 | 🟡 Medium | Grievance Resolution Procedure (legacy HRS-PRO-003) has not been migrated to the new WMS corpus. Current reporting channels rely on the Code of Conduct and Whistleblower Policy. |
| JOSCAR-Q2.7.13.3 | 🔴 Gap | GOV-POL-010 | 🟢 Low | Historical observation (Q42). Policy-level commitment only; no operational measures. |
| JOSCAR-Q2.7.19 | — N/A | — | N/A — Indigenous employment targets were deliberately removed at GOV-POL-008 rev3; out of scope for a 13-employee organisation. | |
| JOSCAR-Q2.7.21 | — N/A | — | N/A — Support for / partnering with Indigenous enterprises was removed at GOV-POL-008 rev3; out of scope for a 13-employee organisation. | |
| JOSCAR-Q2.7.24 | 🟡 Partial | — | 🟢 Low | Procurement approach is SME-friendly operationally; no documented SME engagement strategy exists in the WMS. |
| JOSCAR-Q2.7.16 | ✅ Full | GOV-POL-013 | ||
| JOSCAR-Q2.8.5 | ✅ Full | GOV-POL-001 | ||
| JOSCAR-Q2.8.5.2 | ✅ Full | GOV-POL-001 | ||
| JOSCAR-Q2.8.25 | 🔴 Gap | — | 🟡 Medium | No documented obsolescence-management process. A prior IsCompliant remediation (19/09/2025) is not reflected in the Manual text. |
| JOSCAR-Q2.8.26 | ✅ Full | GOV-PRO-001 QHSE-TPL-014 §§13 | ||
| JOSCAR-Q2.8.27 | — N/A | — | N/A — Westlink is a service provider (logistics, freight, warehousing, customs brokerage). CoCs apply to product manufacturers; not applicable to service delivery. | |
| JOSCAR-Q2.8.28 | 🔴 Gap | — | 🟡 Medium | No delivery-delay notification process documented. |
| JOSCAR-Q2.9.1 | — N/A | — | N/A — Westlink is a service provider — product safety obligations sit with manufacturers and suppliers whose goods Westlink transports. Logistics-specific safety is covered under WHS (GOV-POL-002) and dangerous-goods transport requirements handled by licensed subcontractors. | |
| JOSCAR-Q2.9.5 | — N/A | — | N/A — No design activity in scope of services. | |
| JOSCAR-Q2.9.6 | — N/A | — | N/A — Westlink does not supply products. Hazardous materials in transported freight are managed via DG declarations from consignors under the ADG Code, not via Westlink policy. | |
| JOSCAR-Q2.9.10 | — N/A | — | N/A — Not applicable to a logistics service provider — no delivered goods whose vulnerabilities would be communicated. | |
| JOSCAR-Q2.9.11 | — N/A | — | N/A — Service provider — no goods manufactured or tested. | |
| JOSCAR-Q2.9.12 | 🟡 Partial | OPS-PRO-001 | 🟡 Medium | Anti-sabotage/tamper coverage is partial: Westlink is asset-light with no manufacturing leg, so physical-security controls apply at the air-cargo handling layer (OPS-PRO-001 / GOV-POL-023) rather than to production. |
| JOSCAR-Q2.9.13 | 🟡 Partial | TEC-POL-001 QHSE-MAN-001 TEC-PRO-001 §‘Responsibilities’ | 🟡 Medium | A general ISO 31000 risk-based approach is described and information security is flagged as an internal issue with DISP/ISM references, but security risks across systems and processes are not substantively identified and mitigated as a managed process in the body. |
| JOSCAR-Q2.10.1 | ✅ Full | QHSE-PRO-002 GOV-PRO-003 GOV-PRO-005 | ||
| JOSCAR-Q2.10.2.1 | 🟡 Partial | GOV-POL-012 | 🟡 Medium | Supplier anti-bribery flow-down is policy-level only; supplier assessment procedure to give effect to this is pending (see 2.10.1). |
| JOSCAR-Q2.10.2.2 | 🟡 Partial | GOV-POL-013 | 🟡 Medium | Modern Slavery supplier flow-down is in place via purchase-order terms (legacy reference); prequalification questionnaires (legacy SCM-FRM-001/002) not yet migrated. Historical observation Q5. |
| JOSCAR-Q2.10.2.3 | 🔴 Gap | — | 🟡 Medium | Environmental risk flow-down is implied via policy; supplier assessment procedure pending migration. |
| JOSCAR-Q2.10.2.4 | ✅ Full | QHSE-PRO-002 | ||
| JOSCAR-Q2.10.2.5 | ✅ Full | QHSE-PRO-002 | ||
| JOSCAR-Q2.10.2.6 | ✅ Full | QHSE-PRO-002 | ||
| JOSCAR-Q2.10.2.7 | ✅ Full | QHSE-PRO-002 | ||
| JOSCAR-Q2.10.3 | 🔴 Gap | — | 🟢 Low | On-site welfare-provision adequacy against legal requirements not articulated in a WHS procedure. |
| JOSCAR-Q2.10.4 | ✅ Full | QHSE-PRO-002 | ||
| JOSCAR-Q2.10.5 | 🟡 Partial | — | 🟢 Low | Tier 1 only — consistent with 12-person service-provider scale. No sub-tier supply chain visibility documented. |
| JOSCAR-Q2.10.6 | ✅ Full | QHSE-PRO-002 | ||
| JOSCAR-Q2.10.7 | 🟡 Partial | — | 🟢 Low | Preferred supplier list is maintained in CRM / operational systems; not a controlled WMS document. |
| JOSCAR-Q2.10.8 | ✅ Full | QHSE-PRO-002 | ||
| JOSCAR-Q2.11.1 | ✅ Full | TEC-POL-001 | ||
| JOSCAR-Q2.11.1.1 | 🔴 Gap | — | 🟠 High | Policy commitment present; implementing Cyber Incident Response Plan (which would document the 24-hour customer notification pathway) is a Critical gap per the E8 ML2 library. External to WMS — Becloudsmart handles detection/escalation. |
| JOSCAR-Q2.11.1.2 | 🔴 Gap | — | 🟡 Medium | No IRAP assessment completed. Q68 flagged in gap-analysis — 2024 Defence Cyber Assessment was ‘Embedded’ but this is not an IRAP. Review whether IRAP is required for DISP Entry Level (generally not) or for specific defence-industry contracts. |
| JOSCAR-Q2.11.2 | 🟡 Partial | TEC-POL-001 | 🟠 High | Submitted ‘Yes’ is aspirational — E8 ML2 library shows substantial gaps against ISM controls (incident response plan, central logging, phishing-resistant MFA). Treat as partial pending the DISP uplift programme completing. |
| JOSCAR-Q2.11.5 | 🟡 Partial | TEC-POL-001 TEC-POL-002 | 🟠 High | An ISMS document suite has been initiated via TEC-POL-001/002. A full ISO 27001-style ISMS (scope statement, SoA, risk treatment plan, internal audit, management review) is not yet in place. |
| JOSCAR-Q2.11.5.2 | 🟡 Partial | TEC-POL-001 | 🟡 Medium | Classification scheme referenced in TEC-POL-001 but an information classification standard/matrix is not separately published. OFFICIAL / OFFICIAL:Sensitive handling is operational. |
| JOSCAR-Q2.11.5.3 | 🔴 Gap | — | 🟠 High | Historical observation Q72. No annual critical-asset identification cycle is evidenced. InfoSec Risk Assessment Register was stale (last updated Aug 2022) before the 19/09/2025 completed IsCompliant remediation — verify currency. |
| JOSCAR-Q2.11.5.4 | ✅ Full | TEC-POL-001 TEC-PRO-001 §‘Responsibilities’ | ||
| JOSCAR-Q2.11.6 | ✅ Full | TEC-POL-002 | ||
| JOSCAR-Q2.11.7 | 🟡 Partial | TEC-POL-001 | 🟠 High | Historical observation Q75 — InfoSec Risk Assessment Register stale (Aug 2022). Reported last-assessed 14/06/2024 in portal. IsCompliant action 19/09/2025 marked complete — verify register reflects genuinely annual cadence going forward. |
| JOSCAR-Q2.11.8 | 🟡 Partial | TEC-POL-001 | 🟡 Medium | Patch-management commitment exists at policy level (TEC-POL-001 — critical/high patches within 48 hours); no dedicated System Security Patching policy/procedure. Residual — dedicated patching procedure + E8 ML2 patching-cadence implementation (Becloudsmart uplift). |
| JOSCAR-Q2.11.9 | 🔴 Gap | — | 🟠 High | Monitoring is delivered operationally via Becloudsmart-managed Defender/Sentinel. No dedicated monitoring policy or procedure exists in the controlled WMS corpus. |
| JOSCAR-Q2.11.10 | 🔴 Gap | — | 🟠 High | Historical observation Q78 — physical security reviews not documented. No controlled record of physical security review cycle exists. DISP Entry Level physical security obligations not evidenced in the WMS. |
| JOSCAR-Q2.11.11 | ✅ Full | TEC-POL-001 [GOV-POL-016 §Policy Commitments](/wms/GOV-POL-016#sPolicy Commitments) [TEC-PRO-002 §‘Security awareness and insider-threat training’](/wms/TEC-PRO-002#s’Security awareness and insider-threat training’) | ||
| JOSCAR-Q2.11.12 | ✅ Full | TEC-POL-001 TEC-PRO-001 §‘Purpose’ | ||
| JOSCAR-Q2.11.13 | 🔴 Gap | — | 🟢 Low | CFDI questionnaire completion not stated or evidenced. |
| JOSCAR-Q2.11.15 | — N/A | — | N/A — DISP membership statement — covered by DISP certification (cert_disp-membership.md), not a WMS-library obligation. | |
| JOSCAR-Q2.11.16 | ✅ Full | — | ||
| JOSCAR-Q2.11.17 | ✅ Full | — | ||
| JOSCAR-Q2.11.18 | ✅ Full | — | ||
| JOSCAR-Q2.11.19 | 🟡 Partial | TEC-POL-002 | 🟠 High | MFA is deployed across M365 tenancy. Phishing-resistant MFA (E8 ML2 requirement) is not yet in place — Critical gap per E8 ML2 library. Portal answer ‘Yes’ correct for baseline MFA but does not reflect ML2 phishing-resistant standard. |
| JOSCAR-Q2.11.20 | 🟡 Partial | TEC-POL-001 | 🟡 Medium | Backup commitment exists at policy level (TEC-POL-001) and M365 native retention/restore is in place for email/SharePoint/OneDrive. Residual — no dedicated backup policy, retention schedule, or immutability control documented in the WMS; E8 ML2 Regular Backups implementation (Becloudsmart uplift). |
| JOSCAR-Q2.12.1 | ✅ Full | GOV-POL-015 | ||
| JOSCAR-Q2.12.1.1 | ✅ Full | GOV-POL-015 | ||
| JOSCAR-Q2.12.2.1 | ✅ Full | GOV-POL-015 | ||
| JOSCAR-Q2.12.2.2 | 🟡 Partial | GOV-POL-015 | 🟡 Medium | Commitment 1 references collection notice / APP 5 and reasonable expectation; consent is implied but the policy never states when permission is sought. |
| JOSCAR-Q2.12.2.3 | ✅ Full | GOV-POL-015 TEC-POL-001 | ||
| JOSCAR-Q2.12.2.4 | 🔴 Gap | — | 🟡 Medium | Cross-border transfer clauses not present in Privacy Policy. Low likelihood of cross-border transfer in day-to-day operations (see 2.12.5 = No), but Privacy Policy should still cover the obligation for completeness. |
| JOSCAR-Q2.12.2.5 | 🔴 Gap | — | 🟡 Medium | Privacy training delivery is operational; evidenced via training records in CRM rather than a controlled WMS training procedure. |
| JOSCAR-Q2.12.3 | 🟡 Partial | GOV-POL-015 | 🟡 Medium | Commitment 4 commits to correcting inaccurate or out-of-date information on request (APP 13), but there is no proactive mechanism to keep personal information up to date; the control is reactive only. |
| JOSCAR-Q2.12.4 | 🟡 Partial | GOV-POL-015 | 🟡 Medium | IsCompliant action (31/07/2025, completed 23/09/2025) marked done but a standalone data retention schedule document cannot be located in the current WMS corpus. Verify and publish. |
| JOSCAR-Q2.12.5 | 🔴 Gap | — | 🟠 High | No policy element addresses APP 8 / overseas-disclosure commitment. Westlink does not restrict processing to Australia; prior TEC-POL-001 and GOV-POL-015 evidence notes were factually incorrect (S144 D3c). Policy gap: GOV-POL-015 needs an APP 8 overseas-disclosure commitment in a future revision (cf. PRV-APP8-01 framework Critical gap). |
| JOSCAR-Q2.13.1 | — N/A | — | N/A — None of the listed regulated licences apply to Westlink’s scope of services. Customs Brokerage operates under customs broker licensing held by the lodging agent — captured separately. | |
| JOSCAR-Q2.13.4 | — N/A | — | N/A — Westlink is not an RTO. | |
| JOSCAR-Q2.14.1 | — N/A | — | N/A — Counterfeit standards apply to manufacturers/distributors of electronic parts/materiel. Westlink is a logistics service provider — not applicable. | |
| JOSCAR-Q2.14.2 | — N/A | — | N/A — Service provider — no counterfeit product risk within Westlink’s own deliverables. Counterfeit risk in transported freight sits with consignors. | |
| JOSCAR-Q2.14.6 | — N/A | — | N/A — Service provider — component/material disposal is not in scope. | |
| JOSCAR-Q2.14.7 | — N/A | — | N/A — Not applicable to logistics service scope. | |
| JOSCAR-Q2.14.8 | — N/A | — | N/A — Not applicable to logistics service scope — Westlink does not buy high-concern items for resale. | |
| JOSCAR-Q2.15.1 | ✅ Full | QHSE-PLN-001 | ||
| JOSCAR-Q2.20.1 | ✅ Full | — | ||
| JOSCAR-Q2.20.2.1 | ✅ Full | GOV-POL-013 | ||
| JOSCAR-Q2.20.2.2 | 🟡 Partial | GOV-POL-013 | 🟡 Medium | Modern slavery flow-down is in purchase order T&C (legacy COM-STD reference). Current equivalent T&C document exists but mapping to the new WMS corpus reference is pending. |
| JOSCAR-Q2.20.2.3 | 🟡 Partial | GOV-POL-013 | 🟡 Medium | Historical observation Q5 — supplier risk assessments do not always include modern slavery criteria. Remediation via pending supplier assessment procedure migration. |
| JOSCAR-Q2.20.2.4 | 🟡 Partial | GOV-POL-013 | 🟡 Medium | Training is operational; no standalone training record for modern slavery exists in controlled WMS. |
| JOSCAR-Q2.20.3 | ✅ Full | GOV-POL-013 | ||
| JOSCAR-Q2.20.4 | ✅ Full | — | ||
| JOSCAR-Q2.20.5 | 🔴 Gap | — | 🟡 Medium | No WMS document states the prohibition on retaining passports or withholding salary (a forced-labour / modern-slavery indicator). |
| JOSCAR-Q2.20.6 | 🟡 Partial | GOV-POL-013 | 🟡 Medium | The Labour section commits to minimum wages, NES and lawful engagement, supporting lawful and fair pay, but there is no explicit control against improper wage deductions or financial penalties at the level the question requires. |
| JOSCAR-Q2.20.7 | 🔴 Gap | — | 🟢 Low | No explicit freedom-of-association statement. Implicit coverage via Fair Work Act compliance and Code of Conduct. Low priority — could be addressed in Code of Conduct update. |
| JOSCAR-Q2.20.8 | 🟡 Partial | GOV-POL-018 | 🟡 Medium | Whistleblower Policy exists but no public-facing anonymous channel is published on westlinklogistics.com. Remediation: publish whistleblower URL/email on website. |
| JOSCAR-Q2.20.9 | 🔴 Gap | — | 🟢 Low | No public-facing complaints system published. General ‘contact us’ channel exists. Address alongside 2.20.8 website whistleblower publication. |
| JOSCAR-Q2.20.10 | ✅ Full | — | ||
| JOSCAR-Q2.20.11 | ✅ Full | — | ||
| JOSCAR-Q2.20.12 | ✅ Full | — | ||
| JOSCAR-Q2.20.14 | ✅ Full | — | ||
| JOSCAR-Q2.20.15 | — N/A | — | N/A — The ‘no instances in 3 years’ records attestation is maintained in the DISP Security Register, not a WMS document. |
Rendered from frontmatter by scripts/render_compliance.py. Source extraction: scripts/extract_iso9001_requirements.py. Evidence population: scripts/populate_iso9001_evidence.py. Validate: scripts/compliance_validate.py.