DTAF058979 · Attachment 2 Commercial-in-confidence

Attachment 2 to KPMG's response · DTAF058979

DFSV Capability Model,Scenarios and Requirements

South Australia has multiple fragmented systems that hold information relevant to Domestic, Family and Sexual Violence (DFSV). Information is distributed across agencies, limiting the ability to establish a consolidated view of victim-survivors, risk and service interactions.

This attachment sets out KPMG's initial view of the capabilities, requirements and use cases that a future records management and information sharing capability may need to address to build the integrated and responsive system envisaged by the Royal Commission into DFSV. It supports our Part D response and draws on the Royal Commission's final report, publicly available sources and KPMG's experience delivering information sharing and human services transformation initiatives.

It sets out the current systems landscape, a capability model of 23 capabilities across five layers, the solution concepts that connect them, five scenarios that test the model in practice, and the initial requirements that follow from each capability. The content is intended as a starting point for discussion and validation through the feasibility study. We look forward to the opportunity to discuss it with you.

Ben Wallace

Ben Wallace

Human and Social Services

bwallace@kpmg.com.au +61 8 8236 3432
Harry Cooper

Harry Cooper

Technology Advisory

harrycooper@kpmg.com.au +61 8 8236 7317

Prepared for
Department of Treasury and Finance
Invitation reference
DTAF058979
Date
5 August 2026
Status
Initial hypothesis and discussion paper

Explore the analysis

How to use this attachment

Initial hypotheses to inform validation through the feasibility study

This attachment presents KPMG's initial view of the capabilities, requirements and scenarios relevant to the scope outlined in the Invitation. It has been developed at a capability level only and deliberately avoids assumptions regarding solution architecture, implementation approach or technology selection. The content is intended to demonstrate how our assets, tools and insights can be used to accelerate towards an initial view that we can test with you.

A starting point

Findings and assumptions requiring validation

The capabilities, requirements and scenarios set out an informed opening hypothesis.

Through Phases 1 and 2, we would test them with you and the core project team, interagency working groups, technical and functional subject matter experts across lead agencies, and sector representatives.

Stakeholder engagement would validate, refine or challenge these findings and assumptions, informing subsequent requirements development and ensuring we centre our work on the voices and lived experiences of victim-survivors.

What it is built from

Public evidence, KPMG experience, insights and methodologies

The analysis draws on the Royal Commission's final report, the South Australian Government's response, published legislation and policy, and KPMG's Connected Human and Social Services methods.

Traceability to source material has been maintained throughout to support transparency and validation. Where we have extended a source, this is marked as a hypothesis for validation.

See the full source list

AI-assisted analysis

Accelerating analysis through AI-assisted methods

KPMG used AI-assisted tools to accelerate the review and structuring of a large volume of public material.

All analysis, conclusions and professional judgement remain subject to human review and validation.

This approach demonstrates how requirements development can be accelerated early in the study while preserving time for stakeholder consultation and validation.

Key

Two markers appear against claims throughout this attachment:

  • AlignedTraceable to a cited Royal Commission recommendation, government response, or item of legislation or policy.
  • KPMG hypothesis for validationA reasoned KPMG position extending a source, offered for testing and validation through the feasibility study.

Current systems landscape

A fragmented information landscape

Information about victim-survivors and perpetrators of DFSV is distributed across multiple systems, agencies and service providers. The systems shown below represent the primary platforms identified through our review and past experience supporting SA Government. Collectively they support risk assessment, case management, service delivery, statutory functions and information sharing activities across the DFSV service system. The relationships illustrated are limited to those supported by publicly available evidence and will be validated during Phase 1.

How to read the connections

  • Established link A working information flow, evidenced in a public source.
  • Manual or delayed Information does move, but through a process the Commission found slow or manual.
  • Evidenced gap A public source confirms the connection does not exist today. This is an evidenced absence, distinct from one we have not been able to confirm.
  • Not yet established No public source found either way. Phase 1 may identify undocumented arrangements here.
Local spreadsheets, registers and shared inboxes The Commission found these can take weeks or even months to produce. — With Courage, Ch.2, p.158–159BEBOLD draws de-identified data from child protection. — With Courage, Ch.2, p.105BEBOLD draws de-identified data from SA Health. — With Courage, Ch.2, p.105The Commission found BEBOLD is missing key datasets, particularly from SAPOL. — With Courage, Ch.2, p.105, p.107The Commission found BEBOLD is missing key datasets, particularly from CAA. — With Courage, Ch.2, p.105, p.107Not yet establishedNot yet establishedNot yet establishedNot yet establishedNot yet establishedNot yet establishedNot yet establishedNot yet establishedMandatory notifications are made through eCARL into child protection.Not yet established Information is distributed across multiple systemsEach system captures different aspects of a person's interaction with servicesVictim-survivorsChildren and young peoplePerpetrators of DFSV ISDs — weeks to monthsDe-identified dataNo SAPOL dataNo courts dataNotifications SAPOLMulti-AgencyProtection ServicesystemsSAPOLDomestic ViolenceDisclosure SchemeportalAGDJustice TechnologyServicesCAACAA planned onlineplatform forprotected personsSectorProvider CRM andcase managementsystemsSectorDomestic ViolenceSerial OffenderDatabaseSectorWomen's SafetyServices SA — DFSVCrisis Support LineDHSChild and FamilySupport SystemDHSHomelessness2HomeDHSFamily SafetyFramework PortalBetterStartBEBOLDSA HealthSunrise EMRSA HealthYarrow PlaceDCPeCARLDCPC3MS DCP — PROCUREMENT LIVEKidSafe Connect(child protection case management)Not yet awarded — no data flows today

Also in view

  • Legal Services Commission — Statutory authorities, including the Legal Services Commission, may need to be included as project needs are confirmed during Phase 1.

In addition to the identified enterprise platforms, local information stores such as spreadsheets, standalone registers and shared mailboxes are likely to contribute to operational information management. The extent of reliance on these artefacts will be assessed during Phase 1.

System by system

Published evidence exists for most, but not all, systems in scope

Ten of the sixteen systems identified in this attachment have a published assessment, audit or Royal Commission finding on the public record. Six do not. Where no published assessment has been identified, this is noted as a current evidence gap to be tested during Phase 1. For each system, this section summarises its role, documented current-state issues, relevance to the feasibility study and known governance arrangements.

DHS Family Safety Framework Portal The digital platform supporting the Family Safety Framework and Family Safety Meetings, South Australia's established high-risk multi-agency coordination mechanism.
Publicly available starting point to dive deeper and validate
  • The Commission found the decentralised model means some Family Safety Meetings are not operating anywhere near as well as others, with irregular meetings and member agencies not sending representatives.With Courage, p.156
  • SAPOL's triage role has made police the gatekeeper of what reaches a Family Safety Meeting, and the Commission heard it can require sustained advocacy to get a referral accepted.With Courage, p.156
  • Administrative funding ceased and was not replaced. The Commission concluded the Framework has become almost entirely reliant on the capacity and goodwill of time-poor workers.With Courage, p.156
  • The Domestic Violence Risk Assessment dates from 2007 and was last revised in 2014 — the Commission described it as apparently the oldest common risk assessment tool in use in Australia, never independently evaluated since implementation.With Courage, pp.135-136
  • No published evaluation of the Portal itself was located in the public material reviewed for this attachment. The digital asset closest in function to what Recommendation 47 contemplates has not, on the public record, been independently assessed.Public-source search, July 2026
  • MAPS does not have access to the Family Safety Framework Portal, and relies on each partner agency's internal processes to flag matters. A worker coordinating a high-risk case may therefore need visibility of two mechanisms that neither share a system nor a single view.With Courage, pp.157–158; Flinders SWIRLS review 2024
Key considerations for the feasibility study

The Family Safety Framework is the established multi-agency process for coordinating responses to people at high risk. Any future information sharing capability will need to align with the Framework's referral, risk assessment and meeting processes, while also testing whether those processes should be digitised, integrated or changed. The Framework and MAPS also overlap substantially: both coordinate high-risk cases across the same agencies, and the Flinders review found the two mechanisms work in parallel and not in unison. MAPS does not have access to the Portal. A worker supporting a high-risk case may need visibility of both, so whether the two should be consolidated, or connected through a single coordinated view, is a core question for the study.

Governance

DHS Office for Women is both administrator and policy holder; DHS is custodian of the Portal. SAPOL chairs each of the 17 Family Safety Meetings and triages referrals. Cross-system oversight sits with the Domestic and Family Violence Multi Agency Responses Governance Group, which covers both this and MAPS. Information sharing operates under the SA Information Sharing Guidelines — Cabinet policy, and not legislation. All Portal information is classified OFFICIAL: Sensitive — Personal Privacy, and meeting reports are saved to the DHS records system, Objective.

Capabilities this system supports across the sector
DHS Homelessness2Home The client management system used across specialist homelessness services, including DFSV crisis case recording.
Publicly available starting point to dive deeper and validate
  • The Auditor-General found the existing client management system does not meet data requirements, and recommended a business case be developed to redevelop it.SA Auditor-General, Report 8 of 2024 — Managing homelessness services, 29 July 2024, s.5.3.2
  • The system does not accurately track performance against some service contract KPIs, including completion of client risk assessments.SA Auditor-General, Report 8 of 2024 — Managing homelessness services, 29 July 2024, s.5.3.2
  • Service providers told the Auditor-General there is no capacity to transfer data between H2H and other systems, and that reporting is not self-service and does not provide live reporting.SA Auditor-General, Report 8 of 2024 — Managing homelessness services, 29 July 2024, s.5.3.2
  • The complexity of the system reduces the time frontline staff have to work with clients, and the cost of using it in labour hours across the sector is not returned to those stakeholders as useful data or insight.SA Auditor-General, Report 8 of 2024 — Managing homelessness services, 29 July 2024, s.5.3.2
Key considerations for the feasibility study

The Royal Commission identified H2H's DFSV crisis-recording function for replacement. The feasibility study will need to consider migration of existing records and sequencing with DHS's separate Homelessness System Review. This should be treated as an early dependency, and not a downstream implementation issue.

Governance

DHS-led since 1 July 2024, with use mandated through funding agreements.

Capabilities this system supports across the sector
DHS Child and Family Support System The tiered early-intervention system for families at risk of entering the child protection system, centred on Intensive Family Services.
Publicly available starting point to dive deeper and validate
  • 74 per cent of referrals to Intensive Family Services in 2022–23 reported current or past DFSV concerns at the point of referral. Across CFSS as a whole the SA Government reports 54 per cent for the same year. The denominators differ and no source reconciles them.With Courage, p.304; SA Government Submission 351, pp.83–84
  • NGOs and Aboriginal Community Controlled Organisations, including specialist DFSV providers, do not have access to the child protection case management system, so they cannot share relevant information or seek information to support their work.SA Government Submission 351, p.107
  • No published Auditor-General or Ombudsman performance audit specific to CFSS was located in the public material reviewed for this attachment.Public-source search, August 2026
Key considerations for the feasibility study

CFSS is directly relevant to this scope because a significant proportion of families receiving Intensive Family Services are affected by DFSV. Its Learning System may also provide a relevant DHS-led reference point for data linkage, subject to validation during Phase 1.

Governance

DHS-led, delivered with DCP, NGOs and Aboriginal Community Controlled Organisations.

Capabilities this system supports across the sector
DCP KidSafe Connect The planned replacement for South Australia's child protection case management system, referred to as KidSafe Connect. Procurement has not yet been awarded and the system is not yet operational.

Procurement has not been awarded. No data flows through this system today.

Publicly available starting point to dive deeper and validate

No published assessment located in the public material reviewed for this attachment. Establishing the current-state position is early Phase 1 work.

Key considerations for the feasibility study

The live procurement creates an opportunity to define integration, data sharing and access requirements before implementation decisions are finalised. Child protection records are among the most sensitive information in scope, so the feasibility study should treat conditions for access and disclosure as a governance issue before confirming technical integration options.

Governance

DCP-led. Child protection information sharing will need to be tested against the Children and Young People (Safety) Act 2017 and DCP governance settings.

Capabilities this system supports across the sector
SAPOL Multi-Agency Protection Service systems The co-located multi-agency service that assesses and shares information on high-risk cases, including through Information Summary Documents.
Publicly available starting point to dive deeper and validate
  • Information Summary Documents can take weeks or even months to produce, so the core output is often not available until well after the frontline crisis response has concluded.With Courage, p.158
  • The Commission found the delay often makes the MAPS response redundant, because information has already been shared and risk managed through local responses and the Family Safety Meeting.With Courage, p.158
  • Some partner agencies do not contribute to all Information Summary Documents because of workload and staffing constraints.With Courage, p.158
  • Resourcing constraints mean MAPS can no longer respond to every high-risk incident as originally envisaged, and relies on an internal triage process.With Courage, p.158
  • Aboriginal people are overrepresented across the DFSV service system. At MAPS, Aboriginal people are represented in around 40 per cent of Mapped incidents — the subset of referrals MAPS selects for Mapping through its triage process — and the Royal Commission noted that no Aboriginal Community Controlled Organisation or specialist Aboriginal worker sits within it.With Courage, p.158 (MAPS); p.75 (overrepresentation)
  • MAPS does not have access to the Family Safety Framework Portal, and relies on each partner agency's internal processes to flag matters. The Flinders review found the two mechanisms work in parallel, and not in unison.With Courage, pp.157-158; Flinders SWIRLS review 2024
  • The Flinders review found little evidence to support the perceived link between MAPS outputs and improvements to the safety of women and children.Flinders SWIRLS review 2024, quoted at With Courage, p.158
Key considerations for the feasibility study

Recommendation 20(b) requires the future solution to have regard to the MAPS information sharing product. Information Summary Documents provide a useful current-state reference for the type of information a future capability may need to aggregate, automate or make available earlier. The planned consolidation of MAPS resourcing into Integrated Response Teams also means the feasibility study must design for an operating model that will evolve through to 2030–31. Whether outcome measurement should be specified in the target system, given the Flinders finding, is a question we would put to the working groups.

Governance

SAPOL-led, funded from within participating agency budgets. Oversight via the Domestic and Family Violence Multi Agency Responses Governance Group. Information sharing relies on the SA Information Sharing Guidelines. South Australia remains the only jurisdiction without a Privacy Act, and the Commission urged that the current information-sharing settings be protected if that changes.

Capabilities this system supports across the sector
AGD Justice Technology Services The shared technology service within the Attorney-General's Department, supporting infrastructure, applications and network services across the justice portfolio, including AGD, SAPOL, courts, corrections and child protection.
Publicly available starting point to dive deeper and validate
  • Limited public assessment material was identified for Justice Technology Services. Phase 1 will confirm current integration patterns, custodianship and constraints directly with AGD and court stakeholders.Public-source search, August 2026
Key considerations for the feasibility study

The ECMS specification is one publicly documented example of cross-agency API requirements in the justice sector. Phase 1 will confirm whether that pattern remains current, reusable and relevant to any DFSV information sharing capability that needs to connect with justice agencies.

Governance

AGD provides the shared technology service, but court data is subject to separate custodianship and judicial independence considerations. The feasibility study should not assume executive government control over all data hosted through JTS.

Capabilities this system supports across the sector
CAA CAA planned online platform for protected persons The Courts Administration Authority's online services for people subject to intervention orders, and the court case data behind them.
Publicly available starting point to dive deeper and validate
  • Existing victim information mechanisms do not provide victim-survivors with information about court outcomes other than bail or sentence, or changes to intervention orders. Victim-survivors remain reliant on police or CAA staff to receive this information.With Courage, pp.554–555
  • Reliance on police is problematic given the number of matters listed in Family Violence Court lists and the time available to police prosecutors to contact every victim-survivor after each hearing.With Courage, p.555
  • Victim-survivors are generally informed when an intervention order is served on the perpetrator, but the Commission found instances where that notification is overlooked, which can leave a protected person exposed to further danger.Uniting Communities SA submission, quoted in With Courage, p.639
  • The CAA's own submission states its court data needs further investment before it is usable for larger-scale analytical work, and that affidavit data has only been matched to case files since 29 August 2022.Courts Administration Authority, Submission 382, p.34
  • The CAA has stated it has limited ability for further court investment in DFSV outside its core functions. Any CAA-side integration work is a funding dependency as well as a technical one.Courts Administration Authority, Submission 382, p.9
  • The Coroners Court still has no electronic case management system and depends on paper files.Courts Administration Authority, Submission 382, pp.88–89
Key considerations for the feasibility study

The Recommendation 118 platform and this feasibility study both depend on court information, but they are being progressed through different commissioning pathways. The study should therefore map the data, timing and governance dependencies with the CAA, while making clear that delivery of the platform itself is outside this scope.

Governance

The Courts Administration Act 1993 (SA) establishes the CAA as independent of the executive arm of government. Decisions on court data are made through the State Courts Administration Council, and not by ministerial direction. The CAA's budget is fixed and AGD-approved, and it has stated it has limited ability for further court investment in DFSV. Any information sharing arrangement involving court data is therefore a governance and funding dependency as well as a technical one.

Capabilities this system supports across the sector
Sector Provider CRM and case management systems The client and case management systems used by DFSV specialist services. No single sector-wide platform exists beyond H2H.
Publicly available starting point to dive deeper and validate
  • No single sector-wide client system exists beyond H2H, and reporting obligations to multiple funders drive fragmented collection.Good Government Advisory, State of the Sector 2025, cited in With Courage
Key considerations for the feasibility study

Provider systems are shaped by multiple funding and reporting obligations. Any future capability that expects sector contribution will need to account for this operating context, including existing cross-sector linkage initiatives such as Thriving Families and BEBOLD.

Governance

Provider-owned, and distributed across providers and funders. That makes standardisation and participation a design issue, and not a simple onboarding task.

Capabilities this system supports across the sector
DCP C3MS DCP's current child protection case management system, which is expected to be replaced by the new system.
Publicly available starting point to dive deeper and validate
  • NGOs and Aboriginal Community Controlled Organisations, including specialist DFSV service providers, do not have access to the current child protection case management system, so they cannot share relevant information or seek information to support their work.SA Government submission to the Royal Commission, p.107
Key considerations for the feasibility study

C3MS holds current child protection case information and is a source for de-identified data used by BEBOLD. Any near-term information sharing arrangements will need to work with C3MS while also planning for transition to the new child protection system.

Governance

DCP-led, under the Children and Young People (Safety) Act 2017. Transition planning will require alignment with DCP's replacement system roadmap.

Capabilities this system supports across the sector
DCP eCARL The online child abuse report line through which mandatory notifiers make child protection reports.
Publicly available starting point to dive deeper and validate

No published assessment located in the public material reviewed for this attachment. Establishing the current-state position is early Phase 1 work.

Key considerations for the feasibility study

eCARL is a key entry point for child protection notifications made by mandated notifiers across health, education, police and the DFSV sector. Phase 2 will test whether, and under what authority, information from notifications can contribute to a broader DFSV risk view.

Governance

DCP-led, under the mandatory notification provisions of the Children and Young People (Safety) Act 2017.

Capabilities this system supports across the sector
Sector Domestic Violence Serial Offender Database The database collating information on people who perpetrate domestic violence against multiple victim-survivors and pose an elevated risk of serious injury or death.
Publicly available starting point to dive deeper and validate
  • The information held is based on alleged events, which sets the evidentiary standard any replacement capability would have to handle explicitly.SA Government Submission 351, pp.83–84
  • Access is restricted to DFV Safety Alliance caseworkers, so the check is unavailable to other agencies and providers who encounter the same people.SA Government Submission 351, pp.83–84
Key considerations for the feasibility study

The Royal Commission identified this function for replacement alongside H2H crisis records. The function, and not the database itself, will need to be carried forward. This creates requirements for linking a perpetrator across records, and for risk linkage, evidentiary status, and access controls at least as strict as those used today.

Governance

Funded by the SA Government and delivered by Women's Safety Services SA on behalf of DFV Safety Alliance members. Access is restricted to Alliance caseworkers.

Capabilities this system supports across the sector
SAPOL Domestic Violence Disclosure Scheme portal The scheme through which a person with genuine safety concerns can apply to find out whether someone has a history of violence. South Australia is currently the only Australian jurisdiction operating such a scheme.
Publicly available starting point to dive deeper and validate
  • The independent review found very high client satisfaction — 99 per cent in South Australia against 64 per cent in England and Wales — and described the scheme as unique globally in its victim-centred approach, specialist support for every case, coordinated partnership and systematic monitoring.Independent Review, December 2024, quoted in With Courage, pp.347–348
  • Demand has risen more than 200 per cent in six years, with SAPOL receiving no dedicated budget for the scheme since 2018.With Courage, pp.337, 340 — public hearing evidence, 4 March 2025
  • Processing times for a disclosure have extended from an average of 14 days to 21, which SAPOL attributed to the growth of the scheme and police demand without additional investment.With Courage, p.340 — public hearing evidence, 4 March 2025
  • Compiling a disclosure is a manual process — scanning, emailing and manual written assessment of documents — described in evidence as very manual when overlaid on a modern technology environment.With Courage, pp.342–343
  • LGBTQIA+, CALD and disability applicants are under-represented, and regional and remote delivery is constrained by a thinner specialist workforce.With Courage, p.344
Key considerations for the feasibility study

The Disclosure Scheme provides a near-term test case for aggregating relevant police information to support multi-agency responses. If the portal moves to a central DFSV website, the feasibility study should identify the related custodianship, integration and operating model implications.

Governance

SAPOL-led, currently hosted on SAPOL's website.

Capabilities this system supports across the sector
SA Health Sunrise EMR SA Health's electronic medical record, supporting clinical information relevant to responses for victim-survivors of sexual violence.
Publicly available starting point to dive deeper and validate

No published assessment located in the public material reviewed for this attachment. Establishing the current-state position is early Phase 1 work.

Key considerations for the feasibility study

SA Health is a key service provider for victim-survivors of sexual violence, including through Yarrow Place and related services. This makes health information relevant to the sexual violence component of scope, subject to separate clinical information governance and consent settings.

Governance

SA Health, under its own clinical information governance and the Health Care Act 2008 (SA). Clinical records carry confidentiality obligations distinct from those applying to human services records, so health integration may require a different approval, consent and access pathway.

Capabilities this system supports across the sector
BetterStart BEBOLD BetterStart's linked-data platform, named by the Commission as a candidate for the Recommendation 3 dashboard.
Publicly available starting point to dive deeper and validate

No published assessment located in the public material reviewed for this attachment. Establishing the current-state position is early Phase 1 work.

Key considerations for the feasibility study

BEBOLD is a relevant existing linked-data platform and is identified by the Royal Commission as a candidate for the Recommendation 3 dashboard. Its current dataset coverage and gaps should inform the feasibility study's assessment of linked-data options and dependencies.

Governance

BetterStart, drawing de-identified data under agreement with the contributing agencies.

Capabilities this system supports across the sector
Sector Women's Safety Services SA — DFSV Crisis Support Line The statewide crisis support line for DFSV, and the first point of contact with the service system for many victim-survivors.
Publicly available starting point to dive deeper and validate

No published assessment located in the public material reviewed for this attachment. Establishing the current-state position is early Phase 1 work.

Key considerations for the feasibility study

The crisis support line is where a victim-survivor's first account is most often given, so what is recorded at that point determines how much has to be repeated later. No records management system supporting the line was identified in the public material reviewed, and KPMG's understanding of the service system is that contact records are not held in a dedicated records management capability. If that holds, the line is a requirements gap rather than a system to integrate with, and it will be validated with the service and DHS Office for Women during Phase 1.

Governance

Delivered by Women's Safety Services SA. The public material reviewed does not confirm where contact records are held, who is the custodian of them, or what retention arrangements apply. This will be validated during Phase 1, because it determines whether first-contact information can be carried forward into a shared record at all.

Capabilities this system supports across the sector
SA Health Yarrow Place SA Health's statewide service for people who have experienced rape or sexual assault, providing medical care, counselling and forensic examination.
Publicly available starting point to dive deeper and validate

No published assessment located in the public material reviewed for this attachment. Establishing the current-state position is early Phase 1 work.

Key considerations for the feasibility study

Yarrow Place holds some of the most sensitive records in scope, and it sits under clinical rather than human services information governance. This creates a consent and authority question that differs from the rest of the landscape: forensic and counselling records cannot be treated as ordinary case information. The applicable governance, and whether any sharing pathway to the DFSV service system exists today, will be validated with SA Health during Phase 1.

Governance

SA Health, under its own clinical information governance and the Health Care Act 2008 (SA). The public material reviewed does not confirm what records platform the service uses or how its records relate to Sunrise EMR. This will be validated with SA Health during Phase 1.

Capabilities this system supports across the sector

The capability model

The capability model identifies 23 capabilities to test through the feasibility study

The model identifies 23 capabilities across five layers that a future DFSV records management and information sharing solution would need to provide. No capability is marked as already available. Whether a requirement is already met by an asset held or planned by SAPOL, the Attorney-General's Department, DCP's KidSafe Connect procurement or a sector provider is an assessment the feasibility study would make, and asserting it now would prejudge both the requirement and the sourcing decision.

Once the model is agreed with the Department, Phase 1 will establish the current-state position and Phase 2 will refine and test these requirements and the solution concepts beneath them, assessing for each capability which current or planned assets could deliver it or be integrated with it. The model is expressed at a capability level, independent of any product, platform or vendor.

People the system serves Victim-survivorsChildren and young peoplePerpetrators of DFSV
Value streamsIntake and triageRisk assessmentResponse planningIntervention and deliveryMonitor and recoveryExit and transition

Digital Channels

Service & Case Management

Information Exchange

Data & Records

Governance & Enabling

Cross-cutting capabilities that apply across each stage of the response.

Central government and regulators

Key

A capability the future DFSV solution requiresLinks to a Royal Commission recommendation — shown as R followed by its number

Capability detail is provided on selection

Questions to test with people with lived experience

The questions against each capability are primarily directed to workers, technical owners and agency staff. Improvements to records and information sharing would also affect victim-survivors directly, and would build the foundation for DFSV services that are more integrated and responsive, and in which a victim-survivor needs to tell their story only once. These questions should therefore be explored with lived-experience advisory members through an engagement approach that is designed, supported and trauma-informed.

  1. When you have moved to a new service, what did you most want them to already know before you arrived?
  2. What would you want to decide for yourself about what is shared?
  3. If information about you moved between services, what would you want to be told?
  4. What would make you trust that a system holding your information was keeping you safer?

KPMG would work with the Department and sector representatives to design and support this engagement before any questions are put to people with lived experience.

Solution concepts

Nine concepts connect the capabilities to the scenarios

The capability model sets out what the future solution would need to do. These nine solution concepts describe how those capabilities would have to work together to deliver it. Each concept draws on several capabilities at once, which is why a capability-by-capability assessment alone would not surface the main feasibility risks. The scenarios that follow show each concept in practice.

C1

Identity resolution without a shared identifier

Recognising that records in different agencies describe the same person, where no common client number exists and some identifying details are deliberately changed for safety.

What it takes
  • Configurable attribute-based matching that tolerates missing and inconsistent fields
  • Worker adjudication of partial matches, with the decision fed back to improve later attempts
  • Match reasoning held as a system service, invisible to workers who may not see the underlying attributes
  • False positive and false negative analysis over time
Where the difficulty sits

A false match could place one person's information in front of a worker making a safety decision about someone else. Accuracy thresholds and tolerances should therefore be deliberately set and tested, recognising that false positives and false negatives carry different safety implications.

Capabilities it draws on
Demonstrated in scenarios
C2

One aggregated view, assembled on demand

Presenting a single coordinated picture of what is known about a person across agencies, at the moment a worker needs it, so that a victim-survivor is not required to tell their story over and over.

What it takes
  • Query-time aggregation across participating agency systems
  • Provenance on every item, showing which agency holds it and when it was last updated
  • A single coordinated case view in place of parallel processes
  • Graceful degradation where one source is unavailable, with the gap shown plainly
Where the difficulty sits

The central design question is whether the view is assembled at query time from source systems or held in a central store. This should be an early supplier test question because it affects latency, currency, custodianship and cost.

Capabilities it draws on
Demonstrated in scenarios
C3

Legal basis attached to each shared item

Every shared item carrying the consent or legal authority it moved under, so a worker can see what they are reading, and an auditor can see why it was disclosed.

What it takes
  • Consent, withdrawal and statutory basis recorded against the person and the purpose
  • The high-risk pathway distinguished from routine consented sharing
  • Withdrawal propagating to sharing decisions still in flight
  • A sharing transaction blocked where no valid basis exists, unless an explicit recorded override applies
Where the difficulty sits

Consent is often implemented as a static form field. South Australia's threshold-based sharing model requires consent and legal authority to travel with the information and constrain how it moves, which is what EC3 asks suppliers to evidence from their data model.

Capabilities it draws on
Demonstrated in scenarios
C4

Role, purpose and time-bound access

Visibility set by what a worker is doing and for whom, with the ability to bring another worker in for a specific reason, for a defined period.

What it takes
  • Access profiles that differ per agency and per program
  • Deliberate extension of case visibility to close a feedback loop
  • Time-limited or automatically reviewed access, including at case exit
  • Anomalous access detection and periodic recertification
Where the difficulty sits

Agency-level access is unlikely to be sufficient in this domain. Safe address information, for example, may require tighter visibility than general case information.

Capabilities it draws on
Demonstrated in scenarios
C5

Aboriginal data sovereignty in the access model

Aboriginal Community Controlled Organisations holding a defined role in the sharing model, with control over access to and onward use of data about their own communities.

What it takes
  • ACCO participation as a resourced, defined role in the operating model
  • Community-level control over access and secondary use, distinct from participant-level access
  • Governance roles and decision rights held as configuration
  • Alignment with national Aboriginal data governance frameworks already in force
Where the difficulty sits

This concept may not be met by standard product configuration. It requires a governance model expressed through access, control and onward-use rules in the system.

Capabilities it draws on
Demonstrated in scenarios
C6

Event notifications in place of manual checking

A system notifying a subscribing agency or service provider when a relevant event has changed, without that agency or provider needing to check manually.

What it takes
  • Publish and subscribe notification for new risk flags, referrals and disclosure outcomes
  • Interface versioning without a synchronised release across every connected system
  • Monitoring and alerting per connection, so a broken feed is visible
  • A repeatable connection pattern published so an agency can self-assess effort
Where the difficulty sits

Participating systems differ widely in what they can consume. Some could subscribe today, some would need to be polled, and a few may need an intermediary. The design has to tolerate all three at once.

Capabilities it draws on
Demonstrated in scenarios
C7

Audit trail suitable for review and inquiry

A durable record of who saw what, when, and under what authority, at a standard that would stand up in a coronial inquiry or a review of a death.

What it takes
  • Every disclosure decision recorded with its legal basis
  • Consent decisions auditable independently of the transactions they support
  • Access to safety-critical information separately auditable
  • Retention and disposal applied per record type under the State Records Act 1997 (SA)
Where the difficulty sits

The relevant question in a later review may be what was known, by whom and when. An audit trail designed only for routine compliance reporting may not be sufficient to answer that question.

Capabilities it draws on
Demonstrated in scenarios
C8

A statewide register that separates cohorts

One view of accommodation availability and suitability, holding accommodation for perpetrators separately from accommodation for victim-survivors.

What it takes
  • Accommodation type, location, capacity and dates of effect maintained statewide
  • Clear separation between cohorts, in both records and visibility
  • Placement matched against orders, conditions and risk factors
  • More than one concurrent location per client, with the current one clearly marked
Where the difficulty sits

The main feasibility risk is data currency. The register will only be useful if providers are resourced and incentivised to keep availability current, and if stale vacancies can be detected quickly.

Capabilities it draws on
Demonstrated in scenarios
C9

No wrong door

No wrong door means a person reaches the right service wherever they first present. A risk assessment carries through to the referral pathway its outcome implies, so finding the right service does not depend on the person, or the worker in front of them, already knowing which one it is.

What it takes
  • A common risk assessment structure that different agencies can complete and read consistently
  • Referral pathways informed by the assessment outcome, so finding the right service does not depend on the worker already knowing it
  • Assessment and pathway variations for different cohorts, including Aboriginal people, people with disability, multicultural communities and LGBTIQA+ people
  • Confirmation back to the referring worker that the referral was received and acted on
Where the difficulty sits

A referral triggered by an assessment carries an assumption that the receiving service has capacity and is the right fit. Routing on assessment outcome alone could generate referrals a service cannot accept, which would move the coordination burden rather than remove it. How much routing logic sits in the system and how much stays with practitioner judgement is a design decision that should be settled with the sector before requirements are set, because it determines whether this is one capability or several.

Capabilities it draws on
Demonstrated in scenarios

Use-case scenarios

Five scenarios test how the capabilities would need to work together

The five scenarios show how existing information could support safer and more coordinated decisions if it were available to the right person, at the right time and under the right authority. They are written from a practitioner perspective and are not based on Royal Commission testimony or any individual's account.

Three scenarios are worked step by step. Each step shows the future-state action, the current-state constraint and the capabilities it draws on.

Each pathway is a hypothesis for validation. Through Phases 1 and 2, we would test the steps with the working groups and refine them based on how practitioners confirm the current process operates.

Five illustrative scenarios to test the capability model

Each scenario exercises a different part of the capability model.

Scenariowhat a practitioner facesSolution conceptshow it would be made to workCapabilitieswhat the system must doSystems holding theinformation todaywhat exists now IdentityresolutionIdentity resolution without a shared identifierAggregated viewon demandOne aggregated view, assembled on demandLegal basis oneach itemLegal basis attached to each shared itemTime-bound accessRole, purpose and time-bound accessAboriginal datasovereigntyAboriginal data sovereignty in the access modelEventnotificationsEvent notifications in place of manual checkingAudit trailAudit trail suitable for review and inquiryStatewideregisterA statewide register that separates cohortsNo wrong doorNo wrong doorDigital ChannelsWeb portalWeb portalDigital ChannelsPractitioner workspacePractitioner workspaceCase managementClient & case managementClient & case managementCase managementIntegrated riskassessmentIntegrated risk assessmentCase managementReferrals & handoverReferrals & handoverCase managementCollaboration andcoordinationCollaboration and coordinationInformation ExchangeClient & identitymatchingClient & identity matchingInformation ExchangeInformation sharingInformation sharingInformation ExchangeConsent, authority anddisclosureConsent, authority and disclosureInformation ExchangeIntegration, APIs &eventsIntegration, APIs & eventsData & RecordsMaster data andinformation managementMaster data and information managementData & RecordsRecords lifecyclemanagementRecords lifecycle managementData & RecordsProvenance & evidentiaryintegrityProvenance & evidentiary integrityData & RecordsAccommodation &specialist registersAccommodation & specialist registersData & RecordsAnalytics, reporting &insightsAnalytics, reporting & insightsGovernance & EnablingData governance, privacy& Aboriginal datasovereigntyData governance, privacy & Aboriginal data sovereigntyGovernance & EnablingInteroperabilitystandardsInteroperability standardsGovernance & EnablingSecurity & accesscontrolSecurity & access controlGovernance & EnablingAudit and assuranceAudit and assuranceDHSFSF PortalFamily Safety Framework PortalDHSHomelessness2HomeHomelessness2HomeDHSCFSSChild and Family Support SystemSAPOLMAPSMulti-Agency Protection Service systemsCAACAA platformCAA planned online platform for protected personsSectorProvider CRMsProvider CRM and case management systemsDCPC3MSC3MSSectorDVSODDomestic Violence Serial Offender Database Cross-agency riskassessmentStep by step scenarioCoordinatedaccommodationplacementStep by step scenarioAboriginalcommunity-controlledaccess and datasovereigntyStep by step scenarioDigital disclosurescheme accessSummary level only Cross-agencyanalytics andreportingSummary level only+Further scenariosTo be identified andprioritised with theworking groups, technicaland functionalsubject-matter experts,and the sector.
Hover or select a scenario to trace it down through the model. Selecting a chip highlights every scenario that depends on it. The two scenarios held at summary level have not been worked step by step, so their threads stop at the capability layer. Working them through, and adding others, is Phase 2 work with the working groups.

Scenario 1 · Repeating the same risk assessment across services

Cross-agency risk assessment

This scenario was chosen because a pre-visit risk check is a common interaction across the DFSV service system, and one where the cost of fragmentation falls on a safety decision. What a worker learns currently depends on which agency they reach and who is available to answer. It tests the capabilities Recommendation 20 depends on: identity matching, aggregation, legal basis and audit, and the frequency and cost of the current check will be tested during Phase 1.

Key stakeholders involved
Child protection caseworker preparing for a home visit to a family with a known DFSV history.
Trigger and focus of the scenario
Before attending, the caseworker needs to confirm whether SAPOL or a specialist DFSV service has recorded an active risk indicator for anyone in the household.
The gap today
The current check relies on separate phone calls and manual cross-referencing across agency systems. No consolidated risk view was identified in the public material reviewed, so the quality and completeness of the check depends on staff availability, local knowledge and time.

How the activity would run

Raise a cross-agency risk check in one place AlignedR20

I raise a DFSV risk check on the household from inside the case-management system I already work in, and the request carries the identifying details the department holds. The check runs against the whole-of-government sharing capability. One request reaches every agency holding information relevant to this family.

Today I telephone each agency in turn and wait for a response, so what I learn before the visit depends on who is available that morning.

Current systems used to support the activity

Rec. 20 — a whole-of-government technological solution for DFSV information aggregation and sharing

Match the family across agency records KPMG hypothesis for validationR20

I see each family member matched against records held by other participating agencies, using a configurable set of identifying attributes and without depending on one shared client number across the state. Where a match is partial, it is put to me to confirm or reject, and my decision improves the next attempt against the same person.

Today Each new contact re-establishes who the person is from the beginning, so a variant spelling or an out-of-date address can conceal a history that would have changed how I approached the visit.

Current systems used to support the activity
See aggregated risk with its legal basis AlignedR20

I see the aggregated risk picture in one place: active flags, the most recent risk assessment and its date, and which agency holds each item. Every item shows the consent or legal basis it was shared under, so I can see whether I am reading something disclosed with consent or through the high-risk pathway the Family Safety Framework provides.

Today Risk information stays with whichever agency captured it, and the Family Safety Framework's risk assessment moves as a form ahead of a meeting, so I can only see it if I am at that meeting.

Current systems used to support the activity

Rec. 20; SA Information Sharing Guidelines; Family Safety Framework Practice Manual

Read the coordinated response as it stands AlignedR20

Where this family has been through MAPS or a Family Safety Meeting, the coordinating record is in front of me at the moment I need it, with meeting outcomes and the current action plan attached. One mechanism holds the coordinated view. I am not reconciling two parallel processes to work out what was decided.

Today MAPS Information Summary Documents can take weeks or months to produce, and the Royal Commission found the delay often makes the MAPS response redundant because risk has already been managed through local responses and the Family Safety Meeting.

With Courage, Ch.2, pp.157–159 — Information Summary Document delays; MAPS and the Family Safety Framework working in parallel

Check whether the perpetrator is known AlignedR47R80

I check whether the perpetrator in this household is currently receiving services from another provider, which tells me which other services hold relevant information. Records for perpetrators are held and managed separately from the victim-survivor's records throughout. The check answers my question without merging the two people's histories into one file.

Today This check depends on the Serial Offender Database, which the Royal Commission identified for replacement alongside Homelessness2Home.

Capabilities this activity draws on
Current systems used to support the activity

Rec. 47 — replacement of the Serial Offender Database; Rec. 80 — separate management of records for people using violence

Attend informed, and write back once AlignedR47

I attend the visit with an accurate account of what is known, who holds it and when it was last assessed, covering the adults and the children in the family. That changes the decision I am able to make about the level of risk to the children and the right intervention, and it means the family is not asked to account again for what services already hold. What I observe and decide is written back to the shared record, timestamped and versioned. The next worker can see what was known at the point each decision was made.

Today My notes stay in my agency's file, and the next service the family reaches starts again by asking them to retell what they have already told several others.

Capabilities this activity draws on
Current systems used to support the activity

Rec. 47; With Courage, Ch.4, p.275 — over half of survey respondents who sought help had contacted four or more services

Leave an auditable disclosure trail AlignedR20

My access to the aggregated record is role-based and reviewable, and the disclosure decision behind each item I saw is logged with its legal basis. A manager can establish afterwards who looked, when, and on what authority they were entitled to.

Today A cross-agency disclosure rests on an individual worker's judgement recorded in a case note, which leaves little that can be reviewed or defended later.

With Courage, Fig. 2.3(f)(ii) — role and permission-based case visibility

A single pre-visit risk check draws on seven capabilities across four layers of the model, most of which sit outside the caseworker's own system. This indicates that Recommendation 20 should be assessed as an integration, identity and governance problem as much as a records management one.

Scenario 2 · New contact-risk controls required by accommodation reform

Coordinated accommodation placement

This scenario tests a risk the reform creates rather than one observed today. Recommendation 80 brings accommodation for perpetrators into the statewide register Recommendation 104 establishes, so that victim-survivors are not always the ones who have to leave. Once both cohorts sit in one register, it has to make a placement findable and a protected location invisible at the same time.

KPMG's hypothesis, for validation, is that this situation does not arise routinely today, because provision for perpetrators is limited and separately arranged. A risk introduced by the reform is the kind most easily missed when requirements are drawn from current practice, so the separation, contact-risk and visibility rules will be tested with accommodation providers and DHS during Phase 2.

Key stakeholders involved
Coordinator in a specialist homelessness and DFSV accommodation service, placing clients across a region.
Trigger and focus of the scenario
Under the future model, a perpetrator needs alternative accommodation while a victim-survivor from the same household is already in a placement whose location must stay protected.
The gap today
Current public material does not establish a routine process for placing perpetrators and victim-survivors through one register. Phase 2 will specify the separation, contact-risk checking and protected-address visibility rules rather than deriving them from current practice.

How the activity would run

Search one statewide register for availability AlignedR104R80

I search a single statewide register for what is genuinely available today, filtered by accommodation type, suitability and capacity across my region. The register holds accommodation options for perpetrators as a separately identifiable set alongside victim-survivor accommodation, so I can see the whole picture from one search.

Today I ring providers one at a time to build a picture of vacancies, and there is no statewide view of capacity to check that picture against.

Rec. 104 — a statewide DFSV accommodation register covering availability, suitability and capacity

Place within the required cohort separation AlignedR80

The accommodation I am placing this person into is held separately from victim-survivor accommodation, with its own visibility settings. I can see enough to make and manage the placement, and the victim-survivor's current safe address stays outside what my role can reach.

Today KPMG understands that separation is not a system setting today, and holds because accommodation for perpetrators is rare and separately arranged. That is the condition Recommendation 80 sets out to change.

Current systems used to support the activity

Rec. 80 — accommodation options for people using violence held within the register with clear separation from victim-survivor accommodation

Run the contact-risk check before committing KPMG hypothesis for validationR80

The register links this person and the victim-survivor for me as parties to the same case, and the register tests my proposed placement against current placements, geography and service-delivery territory. If the placement would create a proximity or contact risk, I see the flag before I commit to it, and the flag tells me a risk exists without exposing the protected location behind it.

Today No such check was identified, and KPMG understands there is little occasion for one, because both parties are rarely in funded accommodation at the same time. Recommendation 80 creates the need for it, so the check would have to be specified rather than documented from practice.

Test the placement against orders and conditions AlignedR104R118

Before I commit, the register tests my proposed placement against the case conditions, orders and restrictions recorded against both people. Where an intervention order is in force, the conditions I need reach me through a defined interface with the Courts Administration Authority, whose own delivery of that connection is scoped separately from this system.

Today Order conditions sit with the courts and police, and reach an accommodation coordinator through whatever the client or the referring worker thinks to pass on.

Rec. 104 / Rec. 47(d) — register integrated with records management; Rec. 118 (dependency, CAA-led); Intervention Orders (Prevention of Abuse) Act 2009

Record the placement against the case AlignedR47R104

I record accommodation type, location and dates of effect against the person and link the placement to the case and to the payment system. Placement ordering follows the register's business rules for preferred, emergency and temporary options. An emergency placement is visible as an emergency placement to everyone who reads the record afterwards.

Today Crisis placement data goes into Homelessness2Home, a system built for homelessness that the Royal Commission found is not meeting the needs of specialist DFSV service providers.

Current systems used to support the activity

Rec. 47; With Courage, Ch.4, p.298 — Homelessness2Home is not meeting the needs of specialist DFV providers

Notify only the workers who need to know KPMG hypothesis for validationR80

The workers supporting the victim-survivor receive an event notification that a placement has been made and that the contact-risk check cleared. Neither party's address travels with that notification, and the victim-survivor's current safe-accommodation address stays restricted to a need-to-know list narrower than general case access.

Today This coordination happens worker to worker by phone or email, and once a protected address has been passed on there is no systematic control over where it goes next.

Keep the trail over a safety-critical record KPMG hypothesis for validationR104

Every access to and amendment of accommodation and placement information is recorded, because a disclosed location here is a life-safety risk before it is a privacy one. If either person's whereabouts become unknown, I flag that on the record and the people working the case can see it immediately.

Today No single record holds the placement, so there is no complete trail to audit and no shared way to signal that someone's whereabouts are no longer known.

This handoff requires separation and matching to work together, because the register needs to identify contact risk without exposing protected accommodation details. Since the situation it describes is created by Recommendation 80 rather than observed today, there is no current process to document and improve on. Recommendations 80 and 104 should therefore be assessed as a connected design problem, with the separation and visibility rules specified before a register is procured.

Scenario 3 · ACCO participation without defined access and control

Aboriginal community-controlled access and data sovereignty

This scenario tests the access model rather than the data model. Aboriginal people are overrepresented across the DFSV service system, and are represented in around 40 per cent of Mapped incidents at MAPS, where the Royal Commission noted that no ACCO or specialist Aboriginal worker sits.

A common delivery risk is that access control is treated as configuration after platform selection. Community-level control over onward use cannot reliably be added that way, so access-model requirements should be specified before product selection. This scenario asks whether a solution can carry community-level control over data as well as organisation-level access.

Key stakeholders involved
Caseworker in an Aboriginal Community Controlled Organisation supporting an Aboriginal family already known to child protection and to a mainstream DFSV service.
Trigger and focus of the scenario
The Aboriginal Community Controlled Organisation needs appropriate visibility of information used in decisions about the family, while retaining control over its own data and contributions.
The gap today
Recommendation 20 requires a whole-of-government sharing solution in which Aboriginal Community Controlled Organisations are core, resourced participants with defined access. Aboriginal people are overrepresented across the DFSV service system, and are represented in around 40 per cent of Mapped incidents at MAPS, where the Royal Commission noted that no ACCO or specialist Aboriginal worker sits.

How the activity would run

Hold a defined place in the sharing model AlignedR20

My ACCO has access to the same whole-of-government sharing arrangement as SAPOL, child protection and the mainstream DFSV services, covering the transaction types my role is authorised for, such as making risk assessments and referrals. Participation is configuration. An ACCO can be brought into the arrangement without negotiating a separate agreement with every other agency in it.

Today No ACCO worker or specialist Aboriginal worker sits within MAPS, so an organisation supporting a family through the response has no standing in the mechanism coordinating it.

Rec. 20; With Courage, Ch.2, p.158 — no ACCO or specialist Aboriginal worker sits within MAPS

See the shared record and its legal basis AlignedR20

I open the shared view of the family and see the active risk flags, the services currently involved and who is holding each part of the response. Each item shows the consent or legal basis it was shared under. Where information has come through the without-consent high-risk pathway, that is visible in the record.

Today My picture of the family is assembled from what the family tells me and what a mainstream service has time to pass on, which leaves me advising them on decisions I can only partly see.

Rec. 20; SA Information Sharing Guidelines

Contribute on the community's own terms AlignedR20R25

When I record our assessment or the family's expressed wishes, that information stays under my organisation's control over its onward use. We set who may see it and for what purpose, and those settings travel with the record wherever it is read.

Today An organisation that contributes information to a multi-agency process has no practical means of governing where that information travels afterwards.

Rec. 25 / Fig. 2.4, principles 6 & 9 — ACCOs retain sovereignty over their own data; applied here as a design constraint on Rec. 20

Receive child protection information through a governed pathway AlignedR20

Where the family has interactions with the child protection system, the information I need to take part in decisions reaches me through a defined interface, operating under the Children and Young People (Safety) Act 2017 information-sharing mandate. What is released, to whom and on what terms is settled as a governance decision in advance of the moment it is needed.

Today The conditions under which child protection information can be surfaced to an ACCO worker are unsettled, and that is a governance question before it is a technical one.

Children and Young People (Safety) Act 2017 — information-sharing mandate; Rec. 20

Take part in the coordinated response AlignedR20

I sit in the coordinated response for this family as a core member, working from the same single view of the case that every other member holds. Where a mainstream service is forming a decision that affects the family, I see it as it forms and can provide community-controlled input before the decision is finalised.

Today The Family Safety Framework and MAPS run as two parallel mechanisms, and the Royal Commission found some Family Safety Meetings operate irregularly with member agencies not sending representatives.

With Courage, Ch.2, pp.156–158; Fig. 2.3(e)(vi) — ACCO workers as core, resourced members of integrated response teams

Extend visibility to close a feedback loop AlignedR20

Where another practitioner, service provider, health or housing worker needs sight of part of this case to close a loop for the family, I extend visibility to that worker on a role and permission basis, time-limited and subject to review. The extension is logged with the reason it was granted and expires without anyone having to remember to withdraw it.

Today Closing that loop means forwarding information outside any system that records the disclosure happened, which leaves both the worker and the family unprotected if it is later questioned.

With Courage, Fig. 2.3(f)(ii) — core integrated-response-team members granting case visibility on a role and permission basis

Adjust access as the operating model changes AlignedR20

Who owns a dataset and who approves a new sharing arrangement is held as configuration in the data-governance framework, so another ACCO joining the arrangement is an administrative act. MAPS resourcing is due to consolidate into Integrated Response Teams through to 2030–31, and the access model has to carry that change without the sovereignty settings being renegotiated from the start.

Today Participation is effectively fixed by which agencies were at the table when each mechanism was established, and adding a participant means reopening the arrangement itself.

Current systems used to support the activity

Rec. 21 (accepted) — MAPS resourcing consolidating into Integrated Response Teams to full implementation by 2030–31; Rec. 25 / Fig. 2.4

Recommendation 20 requires a whole-of-government sharing solution. This pathway shows that the access model is central to how that solution would work in practice. Aboriginal data sovereignty should be specified as a design requirement for data control, access and onward use, at the point requirements are set.

Additional scenarios for validation

Digital disclosure scheme access

Frontline DFSV service worker supporting a client through a Domestic Violence Disclosure Scheme application.

The Royal Commission's own recommendation names accessibility of the online application (language, disability) as a specific improvement area, and calls for it to move off SAPOL's website onto a central DFSV site. Accessibility and hosting decisions will affect the future operating model, custodianship and user experience.

Sourcing

Evidence base for the attachment

The attachment is based on the sources below. Where a claim extends beyond a source, it is marked as a KPMG hypothesis for validation.

  1. With Courage: South Australia's vision beyond violence

    Royal Commission into Domestic, Family and Sexual Violence, final report, 19 August 2025. 136 recommendations.

  2. Building safer futures — SA Government response to the Royal Commission (December 2025)

    The whole-of-government response, and the source for each recommendation's acceptance tier and for the delivery window attached to Recommendation 118.

  3. Invitation to Supply DTAF058979

    Part B Specification, and the Department's responses to supplier questions — the source for the named systems, the four interagency working groups, and confirmation that proof-of-concept work is analytical and scenario-based.

  4. South Australian legislation and policy

    SA Information Sharing Guidelines; Children and Young People (Safety) Act 2017; Intervention Orders (Prevention of Abuse) Act 2009; State Records Act 1997 (SA); Family Safety Framework and its Practice Manual; SA Risk Assessment and Management Framework.

  5. Sector and research evidence

    ANROWS research on domestic and family violence protection orders, information sharing and enforcement across Australian jurisdictions; SNAICC's Safe and Supported National Framework on Aboriginal and Torres Strait Islander data sovereignty and the Child Placement Principle.

  6. KPMG Connected Human and Social Services

    KPMG practice methods for value-stream, capability and operating model structuring.

The recommendations referenced in this attachment

  1. R3

    Linked-data DFSV dashboard

    A linked-data DFSV dashboard bringing together data across government to support the Government Steward and the Implementation and Impact Monitor.

  2. R20

    Whole-of-government information sharing

    A whole-of-government technological solution for information aggregation and sharing for DFSV.

  3. R47

    Records management system procurement

    Procurement of a records management and information-sharing system for the central entry-point service and its partner organisations.

  4. R59

    Disclosure Scheme enhancement

    Further enhancing the Domestic Violence Disclosure Scheme, including improvements to the online application portal.

  5. R80

    Accommodation for people using violence

    Inclusion of accommodation options for people using violence within the statewide DFSV accommodation register, with clear separation from accommodation for victim-survivors.

  6. R104

    DFSV accommodation register

    Development, implementation and ongoing maintenance of a statewide DFSV accommodation register covering availability, suitability and capacity.

  7. R118

    Courts information sharing dependency

    Potential integration with the Courts Administration Authority's victim-centred information-sharing system. It is being progressed separately and its delivery is out of scope for this procurement. What is in scope is engaging with the CAA to understand dependencies, integration points and constraints.

  8. R25

    Aboriginal data sovereignty

    Model principles for Aboriginal-led responses, including that Aboriginal Community Controlled Organisations retain sovereignty over their own data. This recommendation is not listed in Part B, but it is a direct dependency for information sharing design. The Department has confirmed that the relevant recommendation set extends beyond those Part B identifies.

What we have not yet been able to establish

Access to current-state documentation sits at the discretion of each system owner, as confirmed by the Department. Several named systems have limited published assessment material. These evidence gaps have been identified where relevant and will be closed through early Phase 1 engagement with system owners.