Explanatory Memorandum
(Circulated by authority of the Minister for Home Affairs, the Honourable Clare O'Neil MP)SCHEDULE 1 - Security assessments
Part 1 Prescribed administrative action
Division 1 Decisions relating to parole, firearm licences and security guard licences
1. This division would amend the application of Part IV of the ASIO Act in respect of certain decisions.
2. Part IV, amongst other things, sets out the manner in which ASIO may provide advice to Commonwealth agencies, States and authorities of a State. It also provides a mechanism for review of adverse or qualified security assessments in the Administrative Appeals Tribunal (AAT).
3. Specifically, this division would provide that the exercise of power or the performance of functions in relation to a decision relating to parole, firearms and security guard licences is prescribed administrative action. These amendments will not change ASIO's ability to provide advice to States and Territories or authorities of a State or Territory about an individual's suitability to hold firearms or security guard licences, and to provide advice in relation to parole decisions. The amendments however would ensure the individual affected by the decision is to be notified of the advice, and also allows for review by the AAT. It also provides for circumstances in which ASIO may communicate information, not amounting to a security assessment, relating to these decisions.
4. This division would implement recommendation 193 of the Comprehensive Review.
Australian Security Intelligence Organisation Act 1979
Item 1 Subsection 35(1) (after paragraph (f) of the definition of prescribed administrative action )
5. This item would insert in the definition of prescribed administrative action two new categories.
6. Paragraph (g) relates to the exercise of any power or performance of any function in relation to a decision relating to parole.
7. Paragraph (h) relates to the exercise of any power or performance of any function in relation to a decision relating to a firearms licence or a licence for a person to work as a security guard.
Item 2 Subsection 39(1)
8. This item would omit "subsection (2)" and substitute "subsections (2) and (3)" in subsection 39(1). This would be a consequence of Item 3.
Item 3 At the end of section 39
9. This item would add subsection 39(3) to section 39. Subsection 39(3) would provide an exception to the restriction in subsection 39(1) which prevents Commonwealth agencies from taking, refusing to take or refraining from taking prescribed administrative action on the basis of communications by ASIO that does not amount to a security assessment.
10. Subsection 39(3) would enable a Commonwealth agency to make a decision relating to a firearms licence or a licence for a person to work as a security guard on the basis of a communication made by ASIO under subsections 18(3) or 19A(4). Subsections 18(3) and 19A(4) allow ASIO to communicate information to authorities of the Commonwealth or State that ASIO has received in the course of ASIO performing its functions where the information relates to the commission or intended commission of a serious crime, communications in the national interest or for the purposes of co-operating with or assisting another body in the performance of that body's functions.
11. As a communication under subsections 18(3) or 19A(4) may be for purposes unrelated to security, such a communication might not meet the definition of a security assessment.
Item 4 At the end of section 40
12. This item would add subsection 40(3) to section 40 to provide an exception to the restriction in subsection 40(2). Subsection 40(2) prevents ASIO from furnishing information, recommendations, opinions or advice (except in the form of a security assessment) to States or authorities of a State where ASIO knows the State or authority intends or is likely to use the recommendation, opinion or advice in considering prescribed administrative action. Subsection 40(2) also prevents ASIO from furnishing information, recommendations, opinions or advice (except in the form of a security assessment) to a Commonwealth agency if ASIO knows the Commonwealth agency intends to communicate it to a State or authority for use in considering prescribed administrative action.
13. Subsection 40(3) would enable ASIO to communicate information under subsections 18(3) or 19A(4), to a State or authority of a State, to enable the State or authority of a State to make a decision relating to a firearms licence or a licence for a person to work as a security guard. Subsection 18(3) and 19A(4) allow ASIO to communicate information to authorities of the Commonwealth or State that ASIO has received in the course of ASIO performing its functions where the information relates to the commission or intended commission of a serious crime, communications in the national interest or for the purposes of co-operating with or assisting another body in the performance of that body's functions.
14. As a communication under subsections 18(3) or 19A(4) may be for purposes unrelated to security, such a communication might not meet the definition of a security assessment.
15. Without Item 4, the effect of Item 1 would be to prevent ASIO from communicating information under subsections 18(3) or 19A(4) which ASIO knows is intended or likely to be used by a State or an authority of a State in considering decisions about firearms or security licences, because subsection 40(2) prohibits ASIO from furnishing information for use by a State or an authority of a State in considering prescribed administrative action, otherwise than in the form of a security assessment. Item 4 is therefore necessary to ensure ASIO maintains its ability to communicate information in its possession consistent with subsections 18(3) and 19A(4).
Item 5 Application of amendments
16. This item would provide that the amendments made by this division apply only in relation to a communication by ASIO on or after the commencement of this item.
Division 2 Regulations to prescribe actions as prescribed administrative action
17. This division would provide a mechanism to introduce new classes of prescribed administrative action, for the purposes of determining whether a recommendation, opinion or advice by ASIO constitutes a security assessment for the purposes of Part IV. This division would implement recommendation 194 of the Comprehensive Review.
Australian Security Intelligence Organisation Act 1979
Item 6 Subsection 35(1) (after paragraph (h) of the definition of prescribed administrative action )
18. This item would insert paragraph (i) in the definition of prescribed administrative action, an action prescribed by the regulations for the purposes of this paragraph.
Item 7 After section 35
19. This item would insert new section 36AA of the ASIO Act, which relates to prescribing action as prescribed administrative action.
20. Subsection 36AA(1) would provide that regulations made for the purposes of paragraph (i) of the definition of prescribed administrative action may only prescribe an action if the action is likely to affect a person's liberty or livelihood and matters relating to security would be a primary consideration in deciding whether to take the action.
21. This threshold is included to ensure that ASIO advice about actions that may substantially adversely affect a person's interests, where the matters relating to security would be a primary consideration in deciding whether to take action, is regulated by Part IV (which may require the person to be notified and provide for review by the AAT).
22. For the avoidance of doubt, there is no requirement for security to be the primary consideration whether action is taken, as long as it is a primary consideration, amongst other key considerations.
23. Subsection 36AA(2) would provide that a decision to prescribe new types of prescribed administrative action must be reviewed by the Parliamentary Joint Committee on Intelligence and Security as soon as possible after relevant regulations are made, and the Committee's comments and recommendations must be reported to each House of the Parliament before the end of the applicable disallowance period.
24. This will ensure there is parliamentary scrutiny in respect of matters that may impact a person's rights, whilst at the same time providing greater flexibility to clarify when notification requirements and review rights should be available in respect of ASIO advice and communications.
25. Subsections 36AA(3) and (4) extends the applicable disallowance period for the regulations, depending on when the Committee provides its report under subsection 36AA(2). This will ensure that each House of Parliament has at least a week from when the report is tabled in that House to consider the regulations in light of the Committee's comments and recommendations.
Item 8 At the end of section 95
26. Section 95 of the ASIO Act is a regulation making power relating to matters required or permitted by the ASIO Act to be prescribed, or necessary or convenient to be prescribed for carrying out or giving effect to the ASIO Act.
27. Generally, the disallowance period for a legislative instrument is 15 sitting days of a House after a copy of the instrument was laid before that House under section 42 of the Legislation Act 2003.
28. This item inserts a note in section 95 stating that the disallowance period for regulations made for the purposes of paragraph (i) of the definition of prescribed administrative action in section 35(1) could be extended by reason of section 36AA. The purpose of this note is to highlight the different disallowance periods that could apply to regulations made under the ASIO Act to facilitate the proper administration of the legislation.
Part 2 Security assessments and preliminary communications
Division 1 Decisions under the Foreign Acquisitions and Takeovers Act 1975
29. This division would amend the application of Part IV of the ASIO Act in respect of certain decisions.
30. Part IV, amongst other things, sets out the manner in which ASIO may provide advice to Commonwealth agencies, States and authorities of a State. It also provides a mechanism for review of adverse or qualified security assessments in the AAT.
31. Specifically, this division would provide that decisions made under the Foreign Acquisitions and Takeovers Act 1975 or the regulations under that Act are not prescribed administrative action. As such, a recommendation, opinion or advice by ASIO would not constitute a security assessment for the purposes of Part IV. This item would give effect to recommendation 197 of the Comprehensive Review.
Australian Security Intelligence Organisation Act 1979
Item 9 Subsection 35(1) (definition of prescribed administrative action )
32. This item would insert the phrase ", subject to subsections (1A) and (2)," into the definition of prescribed administrative action. This would be a consequence of Item 11.
Item 10 Subsection 35(1) (at the end of the note to the definition of prescribed administrative action )
33. This item would add to the note to the definition of prescribed administrative action that a decision made under the Foreign Acquisitions and Takeovers Act 1975 or the regulations under that Act is also not prescribed administrative action (see subsection (1A)). This would be a consequence of Item 11.
Item 11 After subsection 35(1)
34. This item would insert new subsection 35(1A) to clarify that a decision made under the Foreign Acquisitions and Takeovers Act 1975 or the regulations under that Act is not prescribed administrative action.
35. Under the Foreign Acquisitions and Takeovers Act 1975, the Treasurer may make orders to prohibit a foreign entity from taking certain action on grounds relating to national security. In considering whether to make a decision, ASIO may provide advice relating to security to the Treasurer.
36. The effect of Item 11 is to clarify therefore that any advice provided by ASIO to the Treasurer for the purpose of a decision under the Foreign Acquisitions and Takeovers Act 1975 would not be covered by Part IV of the ASIO Act, as the action taken as a result of such communication would not be prescribed administrative action. The entity would not be required to be notified of that advice and would have no right of merits review at the AAT. Clarifying that ASIO advice is not covered by Part IV is also consistent with the position on the Treasurer's decisions under the Foreign Acquisitions and Takeovers Act 1975 themselves, which are exempt from review under the Administrative Decisions (Judicial Review) Act 1977.
Item 12 Application of amendments
37. This item would provide that the amendments made by this division apply only in relation to a communication by ASIO on or after the commencement of this item.
Division 2 Clarification of effect of definitions on certain security assessments
Australian Security Intelligence Organisation Act 1979
Item 13 Subsection 36(1)
38. This item would insert a reference to section 35 in subsection 36(1), to ensure the defined terms set out in section 35 apply in respect of security assessments to which Part IV does not otherwise apply.
39. Section 35 contains a number of definitions for the purposes of Part IV of the Act. Section 36 sets out certain security assessments to which the notice and review provisions of Part IV does not apply. In addition the chapeau in subsection 36(1) provides an exception for these security assessment so that subsections 37(1), 37(3) and 37(4) (which are in Part IV of the Act) will apply to these security assessments. By inserting a reference to section 35 into subsection 36(1), the amendment clarifies that the definitions in section 35 apply to the security assessments described in section 36 to which Part IV of the Act does not otherwise apply.
Item 14 At the end of section 36
40. This item would add subsection 36(3), which clarifies that section 36 is not intended to affect the interpretation of any other provision of Part IV.
Division 3 Preliminary communications to States
41. This division would amend the ASIO Act to enable ASIO to communicate information, whether directly, or indirectly through a Commonwealth agency, to a State or an authority of a State for the purpose of enabling that State or authority to take certain prescribed administrative action, where it would be necessary as a matter of urgency to take that action. These provisions are modelled on the existing section 39, which relate to Commonwealth agencies. This would give effect to recommendation 198 of the Comprehensive Review.
42. Nothing in this division is intended to impact or otherwise limit ASIO's ability to provide information, recommendation, opinion or advice concerning a person, which is not intended or likely to be used by a State or an authority of a State in considering prescribed administrative action in relation to the person, or ASIO's ability to cooperate with Departments, Police Forces and authorities of the States.
Australian Security Intelligence Organisation Act 1979
Item 15 Paragraph 17(1)(ca)
43. This item would insert the words "and make preliminary communications" to ASIO's function at paragraph 17(1)(ca) to ensure that ASIO can make preliminary communications to a State or authority of a State in accordance with section 40.
Item 16 Paragraph 17(1)(ca)
44. This item would insert a reference to paragraph 40(1A)(a) to ASIO's function at paragraph 17(1)(ca) to ensure that ASIO can make preliminary communications to a State or authority of a State in accordance with section 40.
Item 17 Section 40 (heading)
45. This item would insert "and preliminary communications" into the heading of section 40.
Item 18 After subsection 40(1)
46. This item would insert provisions to ensure that ASIO can make a preliminary communication to a State, an authority of a State, or a Commonwealth agency for transmission to a State or an authority of a State to enable that State or authority to take certain prescribed administrative action as a matter of urgency, pending the furnishing of a security assessment.
47. Subsection 40(1A) would make it a function of ASIO to make a preliminary communication directly to the State or the authority of the State, or indirectly through a Commonwealth agency for transmission to a State or authority of State, if the Director-General or an authorised person is satisfied that the requirements of security make it necessary as a matter of urgency for the State or authority to take certain prescribed administrative action. The classes of action that can be taken is specified in paragraph 40(1B)(a). Following the preliminary communication, ASIO must furnish a security assessment, to inform the taking of permanent action. The provision does not specify a timeframe for ASIO to furnish the security assessment, but this should take place as soon as reasonably practicable taking into account the circumstances of each case.
48. Paragraph 40(1B)(a) would provide that for the purposes of subsection 40(1A), the action can be action of a temporary nature to prevent access by a person to any information or place access to which is controlled or limited on security grounds, or prevent a person from performing an activity in relation to, or involving, a thing if the person's ability to perform that activity is controlled or limited on security grounds. This is intended to align with paragraph (a) of the definition of prescribed administrative action in subsection 35(1) of the ASIO Act.
49. Paragraph 40(1B)(b) would provide that for the purposes of subsection 40(1A), the action can be action of a temporary nature, of a kind referred to in paragraphs (g) and (h) of the definition of prescribed administrative action, being action in relation to decisions relating to parole, firearms licences and licences to work as a security guard. This aligns with the new categories of prescribed administrative action that would be introduced by Item 1.
50. Paragraph 40(1B)(c) would provide that for the purposes of subsection 40(1A), the action can be action of a temporary nature, of a kind referred to in paragraph (i) of the definition of prescribed administrative action, that has also been prescribed by the regulations for the purpose of subparagraph 40(1B)(c)(ii). This is to account for the possibility that it might be appropriate for ASIO to communicate information, on an urgent basis to a State or an authority of a State in respect of new classes of prescribed administrative action, pending the furnishing of a security assessment. New classes of prescribed administrative action, as introduced by Item 6, also need to be prescribed for subparagraph 40(1B)(c)(ii) in order for ASIO to make a preliminary communication directly or indirectly to a State or authority.
Item 19 Subsection 40(2)
51. This item would omit "shall not" and substitute "must not, other than in the form of an assessment or in accordance with subsection (1A)" in subsection 40(2).
52. This item, and Item 20 would modify the provision that prohibits ASIO from giving advice to a State or an authority of State otherwise than in the form of a security assessment. Relevantly, it enables ASIO to make a preliminary communication in accordance with subsection 40(1A).
Item 20 Paragraphs 40(2)(a) and (b)
53. This item would omit the words "otherwise than in the form of an assessment" in paragraphs 40(2)(a) and 40(2)(b).
54. This item, and Item 19 would modify the provision that prohibits ASIO from giving advice to a State or an authority of State otherwise than in the form of a security assessment. Relevantly, it enables ASIO to make a preliminary communication in accordance with subsection 40(1A).
Item 21 At the end of section 40
55. This item would insert subsection 40(4) to enable the Director-General of Security to authorise in writing, a person for the purposes of subsection 40(1A). The authorisation can be made in respect of a person who is an ASIO employee or an ASIO affiliate who holds, or is acting in a SES equivalent or higher position within ASIO.
56. The effect of an authorisation is that ASIO may, make a preliminary communication to a State or an authority of a State if the Director-General of Security or an authorised person is satisfied the requirements of security make it necessary as a matter of urgency for the State or authority to take the action.
57. Under this item, the Director-General of Security may authorise an ASIO employee or an ASIO affiliate who holds, or is acting in an SES equivalent or higher position within ASIO. The inclusion of ASIO affiliates is necessary to ensure persons seconded to ASIO from partner agencies can exercise these functions. Any action taken by the ASIO affiliate would be done on behalf of ASIO in the performance of its statutory functions, as set out in section 17. This ability to only authorise persons holding or acting in a SES position is important in that it significantly limits who may enable ASIO to make a preliminary communication to a State or authority of a State (or a Commonwealth agency who intends to communicate it to a State or authority of a State), where they are satisfied that the requirements of security make it necessary as a matter of urgency for relevant action to be taken.
58. Insofar as the authorisation extends to ASIO affiliates holding or acting in an ASIO SES position, the ASIO affiliate could be a secondee from another agency. The Director-General of Security can be expected to give appropriate consideration as to whether such an affiliate is suitable to occupy such a position when appointing the affiliate to that position. Persons holding SES positions within ASIO are the most senior public servants in ASIO, with extensive relevant experience, whether they are ASIO employees or ASIO affiliates.
Item 22 Application of amendments
59. This item would provide that the amendments made by this Division apply in relation to a communication made by ASIO after the commencement of this item.
Division 4 Temporary action by Commonwealth agencies
60. This division would amend the ASIO Act to expand the circumstances in which a Commonwealth agency can take prescribed administrative action on the basis of a communication made by ASIO not amounting to a security assessment, where it would be necessary as a matter of urgency to take that action. These provisions are a consequence of the new categories of prescribed administrative action that would be introduced by Item 1.
Australian Security Intelligence Organisation Act 1979
Item 23 Subsection 39(1)
61. This item would include a reference to subsection 39(4) in subsection 39(1). This would be a consequence of Item 24.
Item 24 At the end of section 39
62. This item would insert provisions to enable a Commonwealth agency to take certain prescribed administrative action as a matter of urgency on the basis of a communication made by ASIO not amounting to a security assessment, pending the furnishing of a security assessment.
63. Paragraph 39(4)(a) would provide that subsection 39(1) does not prevent a Commonwealth agency from taking action that is of a temporary nature and is of a kind referred to in paragraphs (g) and (h) of the definition of prescribed administrative action, being decisions relating to parole, firearms licences and licences to work as a security guard, if on the basis of a preliminary communication by ASIO, the Commonwealth agency is satisfied the requirements of security make it necessary to take action as a matter of urgency, pending the furnishing of a security assessment. This aligns with the new categories of prescribed administrative action that would be introduced by Item 1.
64. Paragraph 39(4)(b) would provide that subsection 39(1) does not prevent a Commonwealth agency from taking action that is of a temporary nature and is prescribed administrative action of a kind prescribed in the regulation, that is also prescribed for the purposes of subparagraph 39(4)(b)(ii), if on the basis of a preliminary communication by ASIO, the Commonwealth agency is satisfied the requirements of security make it necessary to take action as a matter of urgency, pending the furnishing of a security assessment. This is to account for possibility that it might be appropriate for a Commonwealth agency to take action of a temporary nature, on an urgent basis on the basis of a communication made by ASIO not amounting to a security assessment, pending the furnishing of a security assessment in respect of new classes of prescribed administrative action. This aligns with the new category of prescribed administrative action that would be introduced by Item 6.
Item 25 Application of amendments
65. This item would provide that the amendments made by this Division apply in relation to a communication made by ASIO after the commencement of this item.
Part 3 Delayed security assessments
66. This part would amend the ASIO Act to require the Director-General to cause the Inspector-General of Intelligence and Security to be notified of certain security assessments not made within 12 months from when ASIO commences preparation of the assessment.
67. This part would respond to recommendation 199 of the Comprehensive Review.
Australian Security Intelligence Organisation Act 1979
Item 26 Subsection 35(1)
68. This item would insert a definition of "delayed security assessment" into subsection 35(1). The effect of this item would be that a reference to "delayed security assessment" in Part IV would have the meaning given by subsection 41(1).
Item 27 Subsection 36(1)
69. This item would omit the reference to "subsection 35" and substitute "sections 35, 41 and 42" into subsection 36(1). The effect of this item would be that notwithstanding that the requirements of Part IV do not apply to the classes of security assessments mentioned in section 36, ASIO would still be required to notify the Inspector-General of Intelligence and Security of delays in the furnishing of such assessments should they fall within the definition of delayed security assessment.
Item 28 At the end of Division 2 of Part IV
70. This item would add provisions to require the Director-General of Security to cause the Inspector-General of Intelligence and Security to be notified of certain security assessments that are not furnished within 12 months after ASIO starts to prepare the assessment, in accordance with a written protocol made by the Director-General of Security.
71. Subsection 41(1) would provide that if a security assessment is not furnished under Part IV within 12 months after ASIO starts to prepare the assessment, the Director-General of Security must cause the Inspector-General of Intelligence and Security to be notified of the delayed security assessment. These security assessments are defined as "delayed security assessments". The method by which the Director-General may cause the Inspector-General of Intelligence and Security to be notified is not prescriptive, but may include directing an ASIO employee or ASIO affiliate, developing policies and procedures requiring a person holding a particular position to do the notifying, or set up processes (including automated processes) to cause the notification.
72. The note to subsection 41(1) would direct the reader to subsection 42(1) which provides that a protocol must be made under that subsection, and specify when ASIO is taken to have started to prepare a security assessment, which may be specified differently for different classes of security assessments (referencing subsections 42(3) and (4)).
73. Subsection 41(2) would provide that the notification under subsection 41(1) must be made within the period specified in the protocol for the purposes of subparagraph 42(3)(b)(i), include the information specified in the protocol as required by subparagraph 42(3)(b)(ii), and comply with any other requirements specified in the protocol for the purposes of paragraph 42(3)(d). The reference to the protocol in subsection 41(2) is a reference to the protocol made under subsection 42(1) as in force from time to time (i.e. at the time the notification is made).
74. Subsection 41(3) would set out exceptions to the requirement to notify. Notification would not be required where ASIO has been notified that the security assessment is no longer required, or where ASIO had initiated the preparation of the security assessment. Paragraph 41(3)(a) is required because from time to time requests for security assessments will be withdrawn or are otherwise not required. Paragraph 41(3)(b) is required because ASIO, in the course of its activities, might self-initiate enquiries to establish whether prescribed administrative action is required in the interests of security. As this would be done internally by ASIO, without the subject being aware, it may be unnecessary for the assessment to be furnished within 12 months and therefore notification to the Inspector-General of Intelligence and Security would not be appropriate in the circumstances.
75. Subsection 41(4) would set out the application of section 41. It would provide that section 41 applies to a security assessment that ASIO starts to prepare on or after the commencement of section 41.
76. Subsection 42(1) would require the Director-General of Security to make a written protocol for dealing with delayed security assessments.
77. Note 1 to subsection 42(1) would alert the reader to subsection 33(3) of the Acts Interpretation Act 1901, which provides that where an Act confers a power to make an instrument, the power includes a power exercisable in the like manner and subject to the like conditions (if any) to repeal, rescind, revoke, amend, or vary any such instrument. This would confirm the power for the Director-General of Security to repeal, rescind, revoke, amend or vary a protocol made under subsection 42(1). For the avoidance of doubt, the Director-General of Security would be required to consult with the Inspector-General of Intelligence and Security before repealing, rescinding, revoking, amending or varying the protocol.
78. Note 2 to subsection 42(1) would note that such a protocol may be combined with a protocol made under subsection 82GB(1), which relates to delayed security clearance decisions and delayed security clearance suitability assessments. It is anticipated the Director-General of Security will prefer to make only one instrument, covering both subsection 42(1) and 82GB(1).
79. Subsection 42(2) would provide that the Director-General of Security must consult with the Inspector-General of Intelligence and Security before making a protocol under subsection 42(1).
80. Subsection 42(3) would set out what can, and must be dealt with in a protocol.
81. Paragraph 42(3)(a) provides that the protocol must specify when ASIO is taken to have started to prepare a security assessment.
82. ASIO's functions to advise Ministers and authorities of the Commonwealth in respect of matters relating to security and to furnish security assessments to a State or an authority of a State span across a broad range of Commonwealth, State and Territory functions and purposes. It is critical to the performance of these functions that ASIO has all the information necessary to give its security advice. Different classes of security assessments may require more information to be collected before ASIO is able to start to prepare the assessment, due to the nature and complexity of the advice sought and the function to which the advice would be applied. This paragraph would enable greater flexibility to deal with different classes of security assessments, to ensure ASIO is not required to notify the Inspector-General of Intelligence and Security of delays in the furnishing of security assessments, when the delays are a result of matters that are beyond ASIO's control.
83. Paragraph 42(3)(b) would provide that the protocol must specify the period in which notification of a delayed security assessment must be made, and the information to be included in the notification. These matters will necessarily engage questions of ASIO's internal processes and procedures which are classified. It is therefore necessary they be included in the protocol and not made public or set out in legislation.
84. Paragraph 42(3)(c) would provide that the protocol must deal with steps to be taken by ASIO in relation to a delayed security assessment, after the notification under section 41 is made. The purpose of the paragraph is to ensure the protocol includes steps to be taken beyond merely notifying the Inspector-General of Intelligence and Security of the delayed security assessment. Such steps could include providing an explanation to Inspector-General of Intelligence and Security of the reasons for taking longer than 12 months, directions to take steps as set out in relevant policies or procedures, or requiring relevant senior executive officers to be briefed.
85. Paragraph 42(3)(d) would provide that the protocol may specify other requirements, or deal with any other matters that relate to a delayed security assessment, or the notification of the assessment under section 41 and the Director-General of Security considers appropriate.
86. Subsection 42(4) would provide that the protocol may provide differently for different classes of security assessments. For example, the protocol may provide differently for security assessments relating to visa referrals from the Department of Home Affairs compared to security assessments relating to the AusCheck scheme.
87. Subsection 42(5) would provide that a protocol made under subsection 42(1) is not a legislative instrument. This provision would exempt the protocol from being a legislative instrument under the Legislation Act 2003.
88. ASIO provides security assessments to Ministers and authorities of the Commonwealth and States in respect of matters relating to security, on a broad range of different subject matters. The nature and purpose of this advice may expand over time for example, to include decisions relating to parole, firearms licensing, and licences to work as a security guard as set out in Part 1 of Schedule 1 of this Bill.
89. It is necessary for this notification framework to take into account, the complexities and dependencies, relating to the classes of security assessments sought by the different Ministers and authorities, in the performance of their functions and responsibilities. It is thus, appropriate for the protocol to be made by instrument, which provides greater flexibility and adaptability for the provision of security advice, taking into account the environment in which ASIO operates.
90. Noting the types of information that are likely to be included in the protocol, including how ASIO manages different classes of security assessments ASIO furnishes, and the types of information ASIO requires to be able to perform its functions, the protocol will need to be classified in order to operate as intended. It therefore would not be suitable for inclusion in a legislative instrument, which would otherwise be available to the public. These processes are a key pillar of the Australian Government's overall ability to provide assurance that its classified information is secure. That the protocol is subject to consultation with the Inspector-General of Intelligence and Security, and its implementation will be monitored by the Inspector-General of Intelligence and Security, provides a safeguard to ensure the protocol is appropriately configured to the underlying purpose of promoting ASIO being accountable in respect of delayed security assessments.
91. Subsection 42(6) would provide that ASIO must in relation to a delayed security assessment to which subsection 41(1) applies, comply with a protocol made under subsection 42(1) as in force from time to time.
92.