View more Cloud policy guidance.
On this page
About this guidance
This guidance helps agencies meet requirement 3 of the Whole-of-government cloud computing policy: Entities must adopt cloud technologies responsibly and securely.
The Cloud computing policy requires agencies to manage cloud adoption responsibly across the service lifecycle. Agencies should review cloud adoption regularly to confirm that strategy, controls, costs, capability and supplier arrangements remain fit for purpose.
Who this guidance is for
This guidance is for agency staff involved in governing, delivering, operating or reviewing cloud services. Different roles should use it to confirm that cloud adoption remains aligned to business outcomes, risk settings, cost expectations, capability needs and supplier performance.
- Accountable executives are expected to set the review cycle, confirm that cloud adoption continues to support agency priorities, review key risks and costs, assign decision owners, and approve decisions to continue, optimise, modernise, replace or retire services.
- Delivery and program teams are expected to use review findings to update roadmaps, delivery plans, benefits tracking, risk records and investment decisions. They should coordinate input from business, technology, finance, procurement, security and data teams so improvement actions are planned, funded and tracked.
- Operational and specialist teams are expected to provide evidence on service performance, controls, incidents, cost trends, supplier performance, capability gaps and optimisation opportunities. They should maintain the operational records needed to support assurance, continuous improvement and decisions about service change or retirement.
When to use this guidance
Use this guidance for scheduled governance reviews and when there is a material change in cost, risk, performance, supplier arrangements, technology, business needs or policy requirements.
Evidence to maintain
Maintain review records, updated risk registers, cost and performance reports, optimisation actions, supplier review outcomes, capability updates and decisions to continue, change or retire services.
What is important when reviewing cloud adoption
Reviews should confirm that cloud services continue to deliver expected outcomes and remain secure, affordable and sustainable.
Agencies should assess whether:
- services remain aligned with agency strategy, business outcomes and user needs
- risks remain within appetite and are actively managed
- security, privacy, data, resilience and operational controls remain effective
- costs, forecasts, consumption and value are visible and actively managed
- supplier arrangements, service levels and exit options remain fit for purpose
- roles and internal capability remain sufficient
- each service should be retained, optimised, modernised, replaced or retired.
Each review should result in clear, funded actions. Agencies should record the decision, accountable owner, completion date and reporting arrangements so continuous improvement becomes part of normal governance.
More cloud policy guidance
- Guide to meeting the requirements of the Whole-of-government cloud computing policy
- Guide to planning a cloud strategy
- Guide to cloud migration and legacy retirement
- Guide to procuring cloud services
- Guide to managing cloud provider lock-in, portability and exit planning
- Guide to managing security, privacy and operational risk
- Guide to managing cloud and usage costs, including AI costs
- Guide to developing cloud capability in your agency