Skip to content

Pocket Trust Pack

Insurance Service Holdings Pty Ltd, trading as With Pocket · ABN 36 612 629 295 · ACN 612 629 295 · AFSL 491165

This is Pocket’s control documentation: what we do to protect client information and client money, who is accountable for each control, and what artefact demonstrates that it operates.

How to read it

Every material clause carries its actual state rather than an aspiration:

StateMeaning
[Implemented]The control operates now
[Approved, not yet implemented]Required by the policy; implementation outstanding
[Planned]Intended, not yet an approved requirement
[Not applicable]With the reason stated

A clause marked Implemented means the control operates. Whether Pocket can currently demonstrate it is a separate fact, carried in the evidence register. Both are disclosed, and neither is inferred from the other — a five-person business that has been running controls without writing them down is a different thing from one that has written down controls it does not run.

Each control names an artefact by evidence identifierEV-ACC-002, for example. Identifiers are permanent and resolve to a row in the evidence register, which records what the artefact is, who produces it, how often, and whether it exists yet. Identifiers are used rather than locations so that restricted material is never addressed by a path in a published document.

The register

Every policy in the pack, with its owner, version, approval state and review date — generated from each document’s own front matter at build time, so it cannot disagree with the documents.

19 policies · 19 approved · 0 in draft. A draft is disclosed as a draft: it describes how Pocket operates today, and has not yet been through approval by Sam Raco.

Policy Owner Version Status Next review
Information security
Access Control Policy POL-SEC-001 Ben Webster 1.2 Approved 2026-09-23 2027-09-23
Asset and System Inventory POL-SEC-008 Ben Webster 1.2 Approved 2026-09-23 2027-09-23
Business Continuity and Disaster Recovery Plan POL-SEC-005 Ben Webster 1.2 Approved 2026-09-23 2027-09-23
Incident Response Plan POL-SEC-004 Ben Webster 1.1 Approved 2026-09-23 2027-09-23
Information Security Policy POL-SEC-002 Ben Webster 1.2 Approved 2026-09-23 2027-09-23
Information Security Roles and Responsibilities POL-SEC-007 Ben Webster 1.0 Approved 2026-09-21 2027-09-21
Platform and Infrastructure Security POL-SEC-006 Ben Webster 1.2 Approved 2026-09-23 2027-09-23
Secure Development Policy POL-SEC-003 Ben Webster 1.1 Approved 2026-09-23 2027-09-23
Operations
Change Management Policy — Rating and Binding Configuration POL-OPS-003 Ben Webster 1.1 Approved 2026-09-23 2027-09-23
Document Control Policy POL-OPS-002 Ben Webster 1.0 Approved 2026-09-21 2027-09-21
Outsourcing and Vendor Management Policy POL-OPS-001 Ben Webster 1.2 Approved 2026-09-23 2027-09-23
Record Keeping and Retention Policy POL-OPS-004 Ben Webster 1.1 Approved 2026-09-23 2027-09-23
Privacy and AI
AI Use Policy POL-AI-001 Ben Webster 1.2 Approved 2026-09-23 2027-09-23
Data Privacy and Notifiable Data Breach Policy POL-PRV-001 Ben Webster 1.2 Approved 2026-09-23 2027-09-23
Client money and conduct
Client Money Policy — Trust Account and Insurance Broking Account POL-FIN-001 Sam Raco 1.0 Approved 2026-09-21 2027-09-21
Complaints and Internal Dispute Resolution Policy POL-CON-001 Sam Raco 1.0 Approved 2026-09-21 2027-09-21
Conflicts of Interest Policy POL-CON-002 Sam Raco 1.0 Approved 2026-09-21 2027-09-21
Design and Distribution Obligations — applicability and client classification POL-CON-003 Sam Raco 1.0 Approved 2026-09-21 2027-09-21
Sanctions, AML/CTF and Financial Crime POL-FIN-002 Sam Raco 1.0 Approved 2026-09-21 2027-09-21

Certification

Pocket holds no ISO 27001 certification and no SOC 2 report. No certification held by Agent Zero Group or Agile covers any part of Pocket’s environment.

Certification is not currently a requirement for Pocket. We operate a documented control set with named owners, evidence and annual review, set out in this pack.

See the scope and certification position for the full statement.