MICROSOFT PURVIEW · AUSTRALIA
Your tenant already shows what it exposes. We read it, fix it, and prove it.
LensIQ is a Microsoft Purview consultancy for Australian regulated organisations. We read what your Microsoft 365 tenant enforces today, configure Purview so labels, DLP and retention act in production, and hand you the evidence when an auditor, insurer or board asks.
The licence is not the control.
E5 includes Microsoft Purview. It does not configure it. Most tenants we open have sensitivity labels nobody applies, DLP policies left in simulation mode, and retention settings never mapped to an obligation.
Simulation mode is a test harness, not a control. Microsoft’s own documentation says a policy in simulation mode is “run as if it were being enforced, without any actual enforcement.” The report looks healthy. Nothing is blocked. 1
The gap stays invisible until an audit or a breach. We make it visible first.
1 · MICROSOFT LEARN, LEARN ABOUT DLP SIMULATION MODE
Two ways in. One standard of evidence.
Each engagement reads from your tenant or your records, not from a questionnaire. Each ends with artefacts you keep.
- AVAILABLE
Purview configuration review
We read your sensitivity labels, DLP, retention, audit and insider risk settings as deployed, compare them to what your obligations require, and configure the gaps in production with your team.
Explore Purview services - EARLY ACCESS
AUSTRAC Tranche 2 program
One program for accountants, lawyers and real estate firms: enrolment, a business risk assessment built on your client base, training records, initial and enhanced due diligence, and risk scoring that updates as relationships change.
Check your obligations
Tranche 2 is in force. The evidence clock is running.
From 1 July 2026, accountants, lawyers, conveyancers and real estate professionals who provide a designated service are reporting entities under AUSTRAC. Enrolment is due within 28 days of first providing that service, which for most firms was 29 July 2026. 2 3
The obligations are live now: an AML/CTF program approved by senior management, a business risk assessment that reflects your actual clients, due diligence before service, ongoing monitoring, reporting inside fixed windows, and seven years of records. 3
2 · AUSTRAC, AML/CTF REFORM
3 · AUSTRAC, AML/CTF OBLIGATIONS FACTSHEET FOR TRANCHE 2 REPORTING ENTITIES
What the work returns
Every engagement ends with artefacts, not slides. When AUSTRAC, an insurer, a tender panel or your board asks, the answer already exists in writing.
- 01
Configuration baseline
A dated record of every setting we read, where it was read from, and its value.
- 02
Control-to-obligation map
Each control mapped to the obligation it satisfies: APP 11, Essential Eight, AML/CTF Rules, or your own policy.
- 03
Policy rationale
Why each label, DLP rule and retention period is set the way it is, in language an auditor can follow.
- 04
Change record
When each control moved from simulation to enforcement, who approved it, and what it has blocked since.
How an engagement runs
- 01
Assess
We read your tenant as deployed. You receive the readout whether or not you engage us further.
- 02
Prioritise
We map each failure to the obligation it affects and order the work by the risk it removes.
- 03
Configure
We build in your tenant, in production, alongside your team. Simulation is a step, not the destination.
- 04
Evidence
You keep the baselines, the rationale and the record.
Built for Australian regulated organisations
We work with organisations that answer to a regulator, an insurer or a board: financial services, health, professional services, education, and suppliers to government. Most run Microsoft 365 E3 or E5 and have Purview licensed but not fully configured.
If you already have an MSP, we sit alongside them. They run the service catalogue. We do the configuration depth, hand back a documented baseline, and leave.
We map to Australian obligations first. We do not translate a US control catalogue.
OBLIGATIONS WE MAP TO
- Privacy Act 1988 · APP 11
- AUSTRAC · AML/CTF Act and Rules
- ASD · Essential Eight
- PSPF · where it applies
Why this matters now
- 1,205Data breach notifications to the OAIC in 2025, the highest since the scheme began.
SOURCE · OAIC · 6 JUL 2026
- APP 11Reasonable steps now expressly include technical and organisational measures.
SOURCE · PRIVACY AND OTHER LEGISLATION AMENDMENT ACT 2024
- 1 JUL 2026Tranche 2 professions came under AUSTRAC regulation.
SOURCE · AUSTRAC · AML/CTF REFORM
Start with what your tenant enforces.
Request configuration reviewQuestions about LensIQ.
Which Purview areas do you cover?
Sensitivity labels, data loss prevention, retention and records, audit, insider risk, and data security posture management.
We provide a designated service but did not enrol by 29 July. What now?
Enrol. The obligation is to enrol within 28 days of providing a designated service, so the exposure grows while the gap stays open. Enrolling late is better than not enrolling.
Our accountant sent us a policy template. Is that an AML/CTF program?
No. A program has two parts: a risk assessment specific to your firm, and policies suited to its nature, size and complexity. A senior manager must approve both, and any updates to either.
Are you Australian based?
Yes. Australian owned, Australian staffed, and the work is done here.