The compliance gap in security risk assessments done without formal qualifications
Experienced security staff conducting risk assessments without a Cert IV Security Risk Management qualification may expose your organisation to compliance risk.

When experience is not enough: The qualification gap creating institutional risk
Your security team knows how to assess risk. They have done it for years, identifying threats, advising on protective measures, and preparing assessments that inform real operational decisions. The practical competence is there. The question compliance managers are increasingly being asked is whether the formal documentation is also there to prove it.
Across government contracting, enterprise security services, and crowded places management, expectations are shifting. It is no longer sufficient for personnel conducting security risk assessments to demonstrate experience alone. Formal qualification, specifically the CPP41519 Certificate IV in Security Risk Analysis, which is the nationally recognised qualification for this role, is increasingly the benchmark that procurement bodies, principals, and WHS frameworks point to when they ask whether your team is appropriately credentialled.
For many compliance managers, this creates a difficult reality. The people most capable of conducting a security risk assessment, those with ten or fifteen years of operational experience, are often the ones without the formal credential. Their expertise is real. The formal system simply does not yet have the evidence to recognise it.
What the Cert IV Security Risk Management covers
The CPP41519 Certificate IV in Security Risk Analysis is the nationally recognised AQF Level 4 qualification for security risk analysts who apply technical security and operational knowledge within a risk management framework. It is listed on training.gov.au, Australia's national VET register, and is regulated by ASQA.

The qualification comprises 12 units of competency, including five core units and seven elective units. The core units, as listed by registered training providers, cover the foundational competencies of the role:
- CPPSEC4003 Assess and advise on client security needs
- CPPSEC4006 Conduct security risk assessment of client operations
- CPPSEC4007 Identify security threats and assess impact on client operations
- CPPSEC4012 Assess security vulnerabilities of assets
- CPPSEC4022 Establish and implement ethics and governance arrangements for security businesses
Elective units offered by providers can include units covering advanced technology security systems, crowded place security assessment, security risk management planning, and critical infrastructure protection. The full current unit list and packaging rules should be confirmed on training.gov.au, as elective options can vary between providers and may be updated over time.
Several related qualifications exist within the CPP training package, including the CPP40719 Certificate IV in Security Management and the CPP50619 Diploma of Security Risk Management. The CPP41519 Certificate IV in Security Risk Analysis is the qualification aligned to risk assessment and advisory roles. Confirming the correct qualification for your team's roles is an important first step.
Three pressures driving security teams to formalise qualifications
Compliance managers in the security sector are navigating three converging pressures that make formal qualifications increasingly necessary.

1. Government and contract expectations
Australian Government guidance on security contracting is explicit about the due diligence expected of those engaging security staff or consultants. The Security Contract Guiding Principles, published by the Australian Government's National Security portal, state that there is a responsibility for employers, or persons engaging security staff or consultants, to ensure those persons are appropriately licensed and have the capability, education and experience for the function they have been employed to fulfil.
The same guidance includes due diligence questions that ask whether the engaging party knows the contractor's qualifications and experience, whether the workforce will have appropriate training, education and skills for the duties expected, and whether there will be accreditation or a mechanism to recognise specific skills and competencies required. These are not optional questions; they form the baseline due diligence framework that government guidance directs entities to apply.
The Australian Government's Security Contract Guiding Principles also make clear that the owner or operator of a crowded place remains responsible for a safe environment and cannot transfer their risk to a contractor. They still own the risk, though stringent safeguards can mitigate it. This principle extends the qualification question beyond the contractor to the principal engaging them.
2. The Protective Security Policy Framework
For organisations operating in or contracting to Commonwealth entities, the Protective Security Policy Framework (PSPF) establishes mandatory requirements for protective security. The Australian National Audit Office has previously identified high rates of non-compliance by Commonwealth entities with mandatory PSPF requirements, and has noted that the PSPF recommends entities include security requirements in their contracts. The PSPF publications library includes guidance specifically for Chief Security Officers on implementing the framework, signalling that security leadership roles are expected to operate within a structured competency and governance context.
3. Work health and safety obligations
Under Australian WHS laws, a business must ensure the health and safety of its workers and must not put the health and safety of other people at risk. Meeting those obligations includes giving workers the information, training, instruction or supervision needed for safety, and having controls in place to eliminate or minimise risks. While WHS law does not mandate a specific qualification for security risk assessment roles, documented evidence of worker competency, such as a nationally recognised qualification, can support an organisation's ability to demonstrate it has met its obligations. Requirements vary by jurisdiction, and organisations should confirm the specific obligations applicable to their operations.
The Australian Government's business.gov.au guidance on work health and safety outlines these obligations clearly for businesses of all sizes, including the requirement to give workers any information, training, instruction or supervision needed for safety.
Why your most experienced risk assessors may be your biggest compliance gap
Here is the compliance paradox that many security operations leaders recognise immediately: the people most likely to be conducting security risk assessments are often the most experienced and the least likely to hold a formal qualification.
They learned the discipline on the job. They built their methodology through years of operational exposure, including policing, corrections, defence, or private security roles where risk assessment was simply part of what they did. They have never needed a certificate to do the work well until now.
The Australian security industry employs a large and growing workforce. ASIAL, the peak body for the Australian security industry, reported that as at 31 December 2022, Australia had more than 12,700 licensed security companies and over 155,000 licensed security personnel, in an industry generating revenue in excess of $11 billion per annum. Within that workforce, the proportion holding formal risk assessment qualifications, particularly at the Cert IV level, is not comprehensively measured. What is clear is that the qualification pathway for experienced practitioners has historically been informal, and formal credentials are now being demanded by the systems those practitioners operate within.
Your team has the competency. The formal system does not yet have the evidence. That gap between what your people know and what the documentation shows is the compliance liability this article is about.
RPL as a workforce compliance strategy
Recognition of Prior Learning (RPL) is the formal assessment pathway within Australia's national vocational education and training system that allows experienced practitioners to have their existing competency assessed against qualification requirements without repeating learning they have already demonstrated through work.

For compliance managers, RPL is not a shortcut. It is the appropriate pathway for staff who already possess the competency but lack the formal credential. The assessment is conducted by a qualified assessor from a registered training organisation (RTO). The RTO issues the qualification. The process involves genuine evidence gathering and assessment; it is rigorous because the resulting qualification is nationally recognised precisely because the assessment is genuine.
Multiple registered training providers offer RPL as a pathway for CPP41519, and some specifically note that experienced consultants or managers with qualifications and skills obtained through the Police Force, Corrections and Defence may be well placed to pursue the qualification through this route.
The RPL process for CPP41519 typically involves an initial skills review to assess suitability, followed by evidence gathering, which may include work samples, employer references, risk assessment documents, incident reports, and professional records, and then formal assessment by an RTO assessor. Indicative timeframes vary depending on the candidate's evidence readiness and the RTO's assessment schedule. Providers indicate timeframes can range from several weeks to a few months. These are indicative only; actual timeframes depend on individual circumstances and the delivering RTO.
The Australian National Audit Office has documented the scale of Commonwealth ICT and security-related procurement, noting that Australian Government entities committed $14.8 billion to ICT-related goods and services in 2021–22. This operational scale explains why formal competency frameworks for security practitioners are receiving increased attention across government and enterprise contracting.
What compliance managers need to know before starting the RPL process
Before initiating an RPL program for your security risk personnel, there are several factors compliance managers should understand clearly.
Not every staff member will be suitable. RPL suitability depends on the nature and depth of an individual's experience, the evidence they can produce, and how well that evidence maps to the qualification's units of competency. Honest suitability assessment comes before enrolment, not after. Enrolling staff who are not yet ready wastes resources and can be demoralising.
The RTO conducts the assessment and issues the qualification. RPL it guides candidates through the process, helping them understand what evidence is needed, how to document their experience, and how to navigate the assessment pathway. The assessment itself is conducted by a qualified assessor from the delivering RTO. The qualification is issued by the RTO, not by RPL it.
Gap training may be required. If a candidate's evidence does not fully demonstrate competency against all units, gap training may be identified as part of the assessment process. Where this occurs, it is provided at no additional cost. This is a standard feature of the RPL process, not an exception.
The qualification is nationally recognised because the assessment is genuine. The value of a nationally recognised qualification for procurement compliance, WHS documentation, and professional credibility depends on the rigour of the assessment process. RPL does not produce a credential by default; it produces one when competency is demonstrated.
Licensing requirements vary by state and territory. Some states may have specific licensing requirements for security consultant or risk assessment roles that reference formal qualifications. Compliance managers should confirm the applicable requirements with their relevant state or territory regulator before drawing conclusions about which qualification is required for which role.
Starting the conversation: A free skills review for your security team
The first step is understanding where your team actually stands. A free skills review provides an honest assessment of whether each team member's experience is likely to support a successful RPL application for the Cert IV Security Risk Management, before any commitment is made.
This is not a sales step. It is a genuine assessment tool designed to give compliance managers actionable information. If a team member is not yet a strong RPL candidate, you will know that before any enrolment decision is made. If they are, you will have a clear picture of the pathway ahead.
Your team has the experience. The decision about what to do with it is yours.
Ready to Get Recognised?
Start with a free skills review to find out if RPL is right for you.