Western Australian compliance has a structural feature that distinguishes it from the eastern states. A large share of obligations attach not to the company but to the thing: a tenement, a licence, a Ministerial statement, a prescribed premises. They survive corporate restructures, transfers and management changes, and they accumulate over decades.
The practical consequence is that organisations here regularly discover obligations nobody currently employed knew existed. A condition imposed on a mining tenement in the 1990s. A licence requirement attaching to a site acquired in a portfolio transaction. Reporting obligations that ran continuously while the people responsible for them changed four times.
Nathan ISO Consulting implements compliance management systems under ISO 37301:2021 for Western Australian organisations, building registers that follow obligations to whatever they attach to rather than only to the entity.
Why ISO 37301 matters for Western Australian organisations
Obligation persistence is the first reason. Where duties attach to assets and approvals rather than to entities, the corporate knowledge that would normally carry them is unreliable. A register that records the instrument, the site and the condition survives the personnel changes that would otherwise lose it.
Distributed operations are the second. A WA business frequently holds obligations across multiple regimes at multiple sites administered by different regulators. Safety at a mine sits with the mines inspectorate; environment with the environmental regulator; tenement conditions with the mining department; workplace obligations at the Perth office with the general safety regulator. No single relationship covers it.
The third reason is scrutiny cycles. Resources operators, health providers and government-contracted services in this state face periodic reviews, and the question asked in each is consistent: what arrangements were meant to prevent this, and how did you know they were working. An obligations register with monitoring evidence answers that; a policy library does not.
The regimes a Western Australian register must carry
| Regime | Examples relevant to Perth | What it generates |
|---|---|---|
| Commonwealth financial regulation | Financial services and credit licensing, prudential standards, financial crime obligations | Licence conditions, reporting duties, senior accountability requirements |
| WA workplace regulation | Work Health and Safety Act 2020 with general, mines and petroleum regulations | Duties, statutory roles, inspection exposure and industrial manslaughter exposure |
| WA environmental regulation | Environmental Protection Act approvals, Ministerial conditions, licences and clearing permits | Long-lived conditions, monitoring, reporting and rehabilitation commitments |
| Resources tenure and title | Mining Act obligations, tenement conditions, closure and rehabilitation provisioning | Conditions attaching to tenure and surviving transfer |
| WA occupational licensing | Building services, trade and occupational registrations | Registration conditions, competency requirements and renewal cycles |
| State privacy and information regulation | Privacy and Responsible Information Sharing Act obligations for public entities and their providers | Information handling duties and, from January 2027, breach reporting |
| Economic regulation | Oversight of water and energy businesses | Licence conditions, reporting obligations and service standard requirements |
| Care and quality regulation | Aged care, disability and health service standards | Standards, notification duties and audit regimes on independent cycles |
Perth and regional WA coverage
| Location | Activity | Compliance driver |
|---|---|---|
| Perth CBD and West Perth | Resources head offices, financial services, legal and advisory | Tenement and approval conditions, licensee duties, professional obligations |
| Government precincts | Departments, agencies and contracted providers | Information handling, procurement and integrity obligations |
| Kwinana and Henderson | Processing, marine and defence engineering | Licence conditions, workplace duties and major hazard obligations |
| Welshpool and Canning Vale | Transport, fabrication, industrial services | Licensing, workplace duties and operator contract requirements |
| Perth growth corridors | Builders, developers, trades | Building services registration, conduct and rectification obligations |
| Pilbara operations | Iron ore, LNG, rail and port infrastructure | Mines regulations, Ministerial conditions, tenement obligations |
| Goldfields | Mining and processing operations and services | Mines regulations, closure planning, rehabilitation provisioning |
| Health and community services | Hospitals, aged care, disability providers | Sector standards, notification duties and contracted service obligations |
| South West and Mid West | Processing, ports, agriculture services | Environmental licences, workplace duties and regional regulator interaction |
Following the obligation rather than the entity
Most compliance registers are built around the company. In Western Australia that misses a category of obligation entirely, because the duty is attached to a tenement, an approval or a premises and travels with it.
A register built properly for this state records the instrument, what it attaches to, the site or tenure identifier, the condition itself, who in the business is accountable, the control and the evidence it operated. Built that way, a portfolio acquisition becomes a due diligence exercise the register can absorb rather than a discovery process that runs for two years afterwards.
Ownership creates the usual friction. Where every entry names the compliance or legal function, a regulator reads accountability as having been delegated rather than accepted. Pushing conditions out to the people managing the sites they attach to is the most valuable and least comfortable part of the work.
Our delivery model in Western Australia
Scope gets drawn first, covering which legal entities, tenements, approvals, licences and categories of site fall inside it, and which regulator oversees each. Building the register then works from the instruments you actually hold, not an industry precedent, because precedents capture company-level duties and overlook everything fixed to tenure and approvals. Risk work follows to produce a priority order that will withstand challenge, then control mapping, and finally the governance, reporting and monitoring arrangements.
Compliance management draws a smaller pool of accredited assessors than quality or security does, and their grasp of particular sectors is uneven. We find ones with real exposure to resources, health or government-contracted work as your situation requires, agree commercial terms and dates, and deliver readiness via internal audit and a documented review. Both stages are attended.
Instruments are amended, conditions varied, tenements transferred and regulators restructured, none of it arriving as an internal notification. Keeping the register aligned is our work, alongside recurring audit and surveillance readiness, so it reflects the current position rather than the position at handover.
Your deliverables
Where Perth ISO 37301 projects go wrong
Who certifies you, and where we fit
We implement. An accredited body certifies.
Nathan ISO Consulting builds and implements management systems. We do not issue certificates, and no legitimate consultancy does. Your certificate comes from an independent certification body accredited by JAS-ANZ, the accreditation authority appointed jointly by the Australian and New Zealand governments. Accredited bodies operate under impartiality rules that prohibit them from certifying a system they helped build, which is precisely why the two roles are separate. Our job is to get you audit-ready, help you select the right accredited body, and stand alongside you through assessment.
Which accredited body you engage, on what terms and to what timetable, is work we take off you, matched against scope, sector and the audit approach that fits how you operate. Both assessment stages are attended by our people, and resolving whatever gets raised belongs to us rather than arriving as a list once the assessor leaves. Check one thing yourself first: that the JAS-ANZ register lists the body as accredited for your particular scope. Certificates from unaccredited providers cost little and take days, and procurement teams reject them regularly enough that the check pays for itself.
FAQ'S
No. We are an implementation consultancy. Certificates are issued by independent certification bodies accredited by JAS-ANZ. Accreditation rules prevent a body from certifying a system it helped build, so the consulting and certification roles must stay separate.
A JAS-ANZ accredited certification body of your choosing. We shortlist accredited bodies against your scope and sector, manage the quote process, and attend both audit stages with you. The certificate and the audit decision rest entirely with them.
Check the JAS-ANZ register and confirm the body is accredited for the specific standard and scope you need. Unaccredited certificates are widely available, inexpensive and routinely rejected by procurement teams, which means paying twice and starting over.
No consultancy honestly can, because the decision belongs to an independent auditor. What we can do is run your internal audit the way an external auditor would, close findings before assessment, and attend both stages so issues get resolved in the room.
Because many attach to a tenement, approval or premises rather than to the entity holding it. They transfer with the asset, which is why organisations regularly discover conditions imposed by a previous owner years earlier.
What preceded it offered advice with no certification route attached. The present standard reformulated those ideas as testable requirements. Earlier effort is not wasted, but the framework has to be reconstructed before certification comes into reach.
How wide they reach. One takes in the organisation's entire obligation set; the other examines a single risk thoroughly. Western Australian businesses trading offshore or working closely with government occasionally maintain both.
Many find it valuable. Contractors carry workplace duties under general and mines regulations, environmental conditions on client sites, licensing obligations and operator contract terms simultaneously, and the register keeps those visible in one place.
The individual doing the work or running the site the obligation is fixed to, with the compliance team maintaining the register itself. Where a single function appears against every line, a regulator concludes the operating business never took it on.
Certification discharges nothing. What shifts is how readily you can evidence compliance the moment it is requested, and that generally decides whether a review closes promptly or expands into something wider.
By treating them as a register population exercise during due diligence rather than afterwards. Conditions attaching to acquired tenements and premises are frequently the largest source of unknown obligations in Western Australian transactions.
The requirement is a function carrying genuine authority with an unimpeded line to the board, not a particular position on an org chart. Smaller Western Australian businesses regularly merge it into legal or risk, and assessors accept that where independence is real.
Usually twenty to thirty-five weeks. Assembling the register sets the pace, and businesses carrying tenements, approvals and varied site types across several regions land at the longer end. Shortening that phase delivers something that collapses at the first serious question.
Without difficulty. Shared clause architecture across security, continuity and quality standards means governance, audit and review are constructed a single time. Regulated Western Australian businesses commonly operate several certificates from one underlying system.
Send us your instruments
Your tenements, approvals, licences and the compliance schedules from major contracts define the register far more accurately than an organisational chart. Where any were acquired rather than granted, mention that too.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving