Compare

How Public Sector Bodies Choose Investigation Software

The evaluation criteria, security requirements, and procurement pathways Australian regulatory bodies use to select case management and investigation platforms

Public sector regulatory bodies choose investigation case-management software by evaluating four things in sequence: fit for investigation work (purpose-built workflows, evidence integrity, and immutable audit trails), security and data sovereignty (alignment to the ASD Essential Eight and Information Security Manual, with data held in Australia), procurement compliance (value-for-money through recognised pathways such as panels and the relevant digital marketplace), and accessibility (WCAG 2.1 AA). The non-negotiables are usually data sovereignty, audit-trail integrity, and demonstrable security alignment - a platform that fails any of these is typically eliminated before commercial evaluation begins.

How do public sector regulatory bodies choose investigation software?

Public sector regulatory bodies follow a structured selection process that differs from private-sector software buying in two ways: the security and sovereignty bar is higher, and the procurement process must demonstrate value-for-money through a defensible, competitive pathway. In practice, agencies evaluate candidates in four layers - investigation fit, security and sovereignty, procurement compliance, and accessibility - and eliminate any platform that fails a non-negotiable before reaching commercial comparison.

The decision is rarely made by one person. Senior investigators (in the Australian Public Service, typically EL1/EL2) are the operational evaluators who assess whether the platform fits real investigation workflows. Directors and budget holders (SES Band 1) authorise the spend and need to see policy alignment, risk reduction, and value-for-money. ICT and security branches assess the security posture. A platform has to satisfy all three audiences.

What are the non-negotiable requirements for government investigation software?

These requirements typically eliminate candidates if unmet, regardless of price or features:

  • Australian data sovereignty - investigation data hosted within Australian jurisdiction, not replicated overseas where it could be subject to foreign access.
  • Immutable, tamper-evident audit trails - so investigation records can withstand scrutiny by oversight bodies, tribunals, and courts.
  • Investigation-grade evidence management - chain-of-custody controls and integrity verification, not basic file attachment.
  • Security framework alignment - demonstrable alignment to the Australian Signals Directorate Essential Eight and the Information Security Manual (ISM).
  • Role-based, compartmentalised access - granular access control for sensitive and covert matters.
  • Accessibility - WCAG 2.1 Level AA, a mandatory requirement for government digital services.

What security and data-sovereignty standards apply?

Australian agencies assess investigation software against the Commonwealth security frameworks: the Essential Eight Maturity Model (mitigation strategies the ASD recommends as a baseline), the Information Security Manual (ISM) (the controls framework for protecting systems and data), and the Protective Security Policy Framework (PSPF) at the policy level. Many agencies handling sensitive information also require, or prefer, solutions assessed under the Infosec Registered Assessors Program (IRAP).

Data sovereignty is assessed separately and is frequently decisive: agencies need assurance that investigation data, often relating to individuals and sensitive matters, is hosted within Australia and does not leave the jurisdiction.

What procurement pathways do Australian agencies use?

Agencies must demonstrate a competitive, value-for-money process. Common pathways include whole-of-government and agency panels, approved supplier arrangements, and the Commonwealth digital marketplace administered by the Digital Transformation Agency (DTA). State and territory governments operate their own equivalent panels and marketplaces. The pathway shapes the evaluation: panel arrangements often pre-clear security and commercial terms, shortening the agency’s own assessment.

A step-by-step evaluation process for public sector buyers

  1. Define requirements - investigation types, case volumes, statutory obligations, integration needs, classification level, and team structure.
  2. Set non-negotiables - data sovereignty, audit-trail integrity, security alignment, accessibility. Eliminate candidates that fail.
  3. Assess investigation fit - have senior investigators evaluate the platform against real case scenarios, not a generic demo.
  4. Assess security posture - ICT/security branch reviews Essential Eight and ISM alignment, hosting, and assurance evidence.
  5. Select a compliant procurement pathway - panel, marketplace, or approved arrangement that satisfies value-for-money requirements.
  6. Evaluate total cost of ownership - licensing, implementation, training, integration, and ongoing administration, in AUD.
  7. Check references and plan implementation - references from comparable Australian bodies and a phased rollout plan.

How SentinelOps maps to public sector selection criteria

SentinelOps is an Australian, investigator-built investigation case-management platform designed for the requirements above. It is purpose-built for investigation work - structured case workflows, chain-of-custody evidence management, and immutable, tamper-evident audit trails - and is designed to align with the ASD Essential Eight and the ISM, with deployment models that maintain Australian data sovereignty and an accessibility-first interface targeting WCAG 2.1 AA. Because the platform was built by an investigator (founder Lewis Smith, with a background in special operations and state policing), its workflows reflect how investigations are actually run rather than a generic case tool adapted after the fact.

See SentinelOps for government investigations, how to choose investigation software in Australia, and audit trails for government information access.

Frequently Asked Questions

How do public sector regulatory bodies choose investigation software?

Public sector bodies evaluate investigation software in four layers - investigation fit, security and data sovereignty, procurement compliance, and accessibility - and eliminate any candidate that fails a non-negotiable such as Australian data hosting, audit-trail integrity, or security-framework alignment before commercial comparison. The decision typically involves senior investigators, ICT/security, and a budget-holding director.

What are the must-have requirements for government investigation software?

The usual non-negotiables are Australian data sovereignty, immutable and tamper-evident audit trails, investigation-grade evidence management with chain of custody, alignment to the ASD Essential Eight and the Information Security Manual, granular role-based access, and WCAG 2.1 AA accessibility.

What security standards apply to government investigation software in Australia?

Agencies assess against the Essential Eight Maturity Model, the Information Security Manual (ISM), and the Protective Security Policy Framework (PSPF), and many require or prefer solutions assessed under the Infosec Registered Assessors Program (IRAP). Australian data sovereignty is assessed separately and is often decisive.

Which procurement pathways can agencies use to buy investigation software?

Agencies commonly use whole-of-government or agency panels, approved supplier arrangements, and the Commonwealth digital marketplace administered by the Digital Transformation Agency, with states and territories operating equivalent panels and marketplaces. The pathway chosen helps demonstrate the required value-for-money and competitive process.

Who makes the decision to buy investigation software in a government agency?

It is typically a shared decision: senior investigators (EL1/EL2 in the APS) assess operational fit, ICT and security branches assess the security posture, and a director or budget holder (often SES Band 1) authorises the spend against policy alignment and value-for-money.

Does investigation data have to be hosted in Australia?

For most agencies handling sensitive investigation information, Australian data sovereignty is a non-negotiable requirement, meaning data is hosted within Australian jurisdiction and not replicated overseas. SentinelOps supports deployment models that maintain Australian data sovereignty.

Your Next Investigation Deserves Better

See how SentinelOps transforms investigation management in a 30-minute investigator-led walkthrough. No sales pitch. Just the platform, your questions, and straight answers.

Currently serving Australian enterprise, government, and regulated industry organisations.