Pocket Trust Pack
Insurance Service Holdings Pty Ltd, trading as With Pocket · ABN 36 612 629 295 · ACN 612 629 295 · AFSL 491165
This is Pocket’s control documentation: what we do to protect client information and client money, who is accountable for each control, and what artefact demonstrates that it operates.
How to read it
Every material clause carries its actual state rather than an aspiration:
| State | Meaning |
|---|---|
| [Implemented] | The control operates now |
| [Approved, not yet implemented] | Required by the policy; implementation outstanding |
| [Planned] | Intended, not yet an approved requirement |
| [Not applicable] | With the reason stated |
A clause marked Implemented means the control operates. Whether Pocket can currently demonstrate it is a separate fact, carried in the evidence register. Both are disclosed, and neither is inferred from the other — a five-person business that has been running controls without writing them down is a different thing from one that has written down controls it does not run.
Each control names an artefact by evidence identifier — EV-ACC-002, for example. Identifiers are
permanent and resolve to a row in the evidence register, which records what the artefact is, who
produces it, how often, and whether it exists yet. Identifiers are used rather than locations so that
restricted material is never addressed by a path in a published document.
The register
Every policy in the pack, with its owner, version, approval state and review date — generated from each document’s own front matter at build time, so it cannot disagree with the documents.
19 policies · 19 approved · 0 in draft. A draft is disclosed as a draft: it describes how Pocket operates today, and has not yet been through approval by Sam Raco.
| Policy | Owner | Version | Status | Next review |
|---|---|---|---|---|
| Information security | ||||
| Access Control Policy POL-SEC-001 | Ben Webster | 1.2 | Approved 2026-09-23 | 2027-09-23 |
| Asset and System Inventory POL-SEC-008 | Ben Webster | 1.2 | Approved 2026-09-23 | 2027-09-23 |
| Business Continuity and Disaster Recovery Plan POL-SEC-005 | Ben Webster | 1.2 | Approved 2026-09-23 | 2027-09-23 |
| Incident Response Plan POL-SEC-004 | Ben Webster | 1.1 | Approved 2026-09-23 | 2027-09-23 |
| Information Security Policy POL-SEC-002 | Ben Webster | 1.2 | Approved 2026-09-23 | 2027-09-23 |
| Information Security Roles and Responsibilities POL-SEC-007 | Ben Webster | 1.0 | Approved 2026-09-21 | 2027-09-21 |
| Platform and Infrastructure Security POL-SEC-006 | Ben Webster | 1.2 | Approved 2026-09-23 | 2027-09-23 |
| Secure Development Policy POL-SEC-003 | Ben Webster | 1.1 | Approved 2026-09-23 | 2027-09-23 |
| Operations | ||||
| Change Management Policy — Rating and Binding Configuration POL-OPS-003 | Ben Webster | 1.1 | Approved 2026-09-23 | 2027-09-23 |
| Document Control Policy POL-OPS-002 | Ben Webster | 1.0 | Approved 2026-09-21 | 2027-09-21 |
| Outsourcing and Vendor Management Policy POL-OPS-001 | Ben Webster | 1.2 | Approved 2026-09-23 | 2027-09-23 |
| Record Keeping and Retention Policy POL-OPS-004 | Ben Webster | 1.1 | Approved 2026-09-23 | 2027-09-23 |
| Privacy and AI | ||||
| AI Use Policy POL-AI-001 | Ben Webster | 1.2 | Approved 2026-09-23 | 2027-09-23 |
| Data Privacy and Notifiable Data Breach Policy POL-PRV-001 | Ben Webster | 1.2 | Approved 2026-09-23 | 2027-09-23 |
| Client money and conduct | ||||
| Client Money Policy — Trust Account and Insurance Broking Account POL-FIN-001 | Sam Raco | 1.0 | Approved 2026-09-21 | 2027-09-21 |
| Complaints and Internal Dispute Resolution Policy POL-CON-001 | Sam Raco | 1.0 | Approved 2026-09-21 | 2027-09-21 |
| Conflicts of Interest Policy POL-CON-002 | Sam Raco | 1.0 | Approved 2026-09-21 | 2027-09-21 |
| Design and Distribution Obligations — applicability and client classification POL-CON-003 | Sam Raco | 1.0 | Approved 2026-09-21 | 2027-09-21 |
| Sanctions, AML/CTF and Financial Crime POL-FIN-002 | Sam Raco | 1.0 | Approved 2026-09-21 | 2027-09-21 |
Certification
Pocket holds no ISO 27001 certification and no SOC 2 report. No certification held by Agent Zero Group or Agile covers any part of Pocket’s environment.
Certification is not currently a requirement for Pocket. We operate a documented control set with named owners, evidence and annual review, set out in this pack.
See the scope and certification position for the full statement.