---
title: "Plans and procedure declarations for relying parties applying to participate in the AGDIS"
source: "https://www.digitalidsystem.gov.au/sites/default/files/2025-03/Plans%20and%20procedure%20declaration%20for%20relying%20parties%20applying%20to%20participate%20in%20the%20AGDIS_Mar%202025.pdf"
collection: "digital-id-accreditation"
guidance_commit: "db3111cd9d11643ac08b34b4d75b0d0d983ca388"
---

Plans and procedures declaration for relying
parties applying to participate in the AGDIS
I                                        of,

declare that my organisation has the following:

•   effective written procedures to notify the System Administrator as soon as
    practicable of:

       o any proposed change to my organisation's information technology system
         that interacts with the Australian Government Digital ID System, where the
         change will, or could reasonably be expected to, have a material effect on
         the operation of the Australian Government Digital ID System;

       o any planned or unplanned outage or downtime affecting my organisation’s
         information technology system, where the outage or downtime will, or
         could reasonably be expected to, have a material effect on the operation of
         the Australian Government Digital ID System.

•   A written cyber security plan approved by my organisation’s governing body,
                                          , that addresses:
       o the management of any risks identified by the risk assessment of a cyber
         security incident occurring in connection with a service that my
         organisation intends to provide, or provide access to, within the Australian
         Government Digital ID System, which was conducted by my organisation
         on                   ;

       o the prevention, identification, investigation and management of cyber
         security incidents, including incidents notified to my organisation by the
         System Administrator, if my organisation is approved to participate in the
         Australian Government Digital ID System; and

       o regular reviews of the written cyber security plan by my organisation at
         least once per year.

•   A written digital ID fraud management plan approved by my organisation’s
    governing body,                                   , that addresses
       o the management of any risks identified by the risk assessment of a digital
         ID fraud incident occurring in connection with a service that my
         organisation intends to provide, or provide access to, within the Australian
         Government Digital ID System, which was conducted by my organisation
         on                   ;
       o the prevention, identification, investigation and management of digital ID
         fraud incidents, including incidents notified to my organisation by the
         System Administrator, if my organisation is approved to participate in the
         Australian Government Digital ID System; and

       o regular reviews of the written digital ID fraud management plan by my
         organisation at least once per year.

•   A written disaster recovery and business continuity plan approved by my
    organisation’s governing body,                                   , that addresses:
           o disaster recovery procedures for critical functions of my organisation’s
             information technology system within the Australian Government
             Digital ID System; and

           o regular reviews of this plan by my organisation at least once per year.

I declare I am authorised by my organisation to make the declarations contained in
this application.
