IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
STAT builds compliance setup in under a month with Orca

STAT builds compliance setup in under a month with Orca

Wed, 23rd Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

STAT built a governance, risk and compliance environment in under a month using Orca Opti, covering ISO 27001, NIST CSF and SOC 2.

The Australian health technology platform completed the setup across four sessions over three weeks as it moved into enterprise partnerships and faced more detailed due diligence from prospective partners.

STAT operates a digital platform that connects AHPRA-registered healthcare practitioners with healthcare organisations for learning, market research and networking. Its model depends on compliant engagement between practitioners and organisations, making information security and operational controls central to its commercial offering.

As the business shifted from development to active partnership discussions, it needed a more formal compliance structure. Larger partners wanted evidence that practitioner data was being handled responsibly and that recognised frameworks for information security, cyber risk management and operational controls were in place.

Three frameworks

The work involved connecting STAT's Google Workspace directory, selecting the frameworks and using Orca Opti's onboarding tools to create an initial environment. That environment included policies, procedures, controls and a baseline risk register tailored to STAT's position as a health technology business that works with practitioners rather than handling patient records directly.

By the third session, Co-Founder and Chief Executive Officer Chris Risby had returned to the platform independently and uploaded material about the company's structure, roles and operations into a knowledge pack. He then used Ask Opti, the platform's assistant, to add company-specific detail to policies and procedures.

"All of our policies look good. They've taken our context and put in our business structure. They know who our team is. They know what we do in our roles. That was really intuitive," said Chris Risby, Co-Founder and Chief Executive Officer, STAT.

Risby also used the system to assign control ownership across the founding team based on technical responsibilities, covering 139 controls.

"Instead of manually changing 139 of them, I was like, let's start with this. And sure enough, it just did it," he said.

Audit preparation

During the fourth session, the team created a custom ISO 27001 auditor workspace inside Orca Opti to run an internal pre-audit, review policies and procedures, and identify gaps before any formal certification review.

Risby said the process gave the company a structured set of findings and an improvement plan. The environment now includes configured ISO 27001, NIST CSF and SOC 2 frameworks, published policies and procedures, assigned controls, a baseline risk assessment and a risk register covering commercial and regulatory issues.

The risk register covers areas including revenue, regulation, information security and key person risk. STAT said 12 baseline risks were assessed with ratings, owners and review schedules.

"I'm starting to feel a little more familiar and comfortable with the system. I can just go and get my fingers into it again and see what it can do for us," Risby said.

Commercial pressure

For early-stage companies selling into regulated sectors, compliance reviews can become a procurement bottleneck. STAT said the new structure has reduced the burden of partner questionnaires.

"Government, enterprise medtech and pharma partners already expect this level of compliance. Since we built this out with ORCA, questionnaires that used to run 50 questions deep are down to single digits. We've got the evidence to point to," Risby said.

That reduction matters because STAT's business model relies on trust between practitioners and organisations. The platform says it enables compliant, paid engagements and CPD-eligible reflection through its AI reflection tool, CLARA, while giving organisations verified access to practitioner insight.

Orca Opti describes itself as a governed AI and compliance platform for regulated Australian organisations. Its system operates within Microsoft 365 on Australian infrastructure.

Founder and Managing Director Kat Giudes said STAT's approach showed how smaller teams are trying to meet standards long associated with larger organisations and bigger compliance budgets.

"STAT's product runs on trust, so compliance was never going to be an afterthought. Watching a founder stand up ISO 27001, NIST CSF and SOC 2 in under a month, then answer partner due diligence in single digits, is exactly what we built Opti Core for," said Kat Giudes, Founder and Managing Director, Orca Opti.

Risby said the system may also allow STAT to replace some standalone software subscriptions with a more centralised setup as the business grows.

"There's lots of subscriptions I'll probably be able to get rid of and bundle into ORCA," he said.

STAT said its compliance framework is intended to support growth in professional development partnerships and enterprise healthcare engagements. It added that the work has turned compliance from an internal requirement into a commercial tool for closing deals.

"This is pretty valuable. Just gives me some peace knowing that this ball's rolling," Risby said.