Five service lines.
One operating
philosophy.
Senior advisors. Cleared, certified, probity-tight. Ex-Big-4 instincts, boutique economics. We're at home in Federal Government ICT modernisation, and just as comfortable on the corporate side — wherever the hard problems live.
How we show up
on every engagement.
Co.Lab Partners is a multidisciplinary consulting house built around senior practitioners — 15+ years on every project, 25+ for our senior advisors. Our directors and named experts have led work across Federal Government, Defence, State Government and corporate Australia. Ex-Big-4 instincts. Boutique economics.
We pick the methodology that fits the context — PRINCE2, AgilePM, SAFe, or a sensible hybrid — not the one our certifications make easiest to bill. Certifications across TOGAF, AgilePM, PRINCE2 and Prosci sit behind the team.
For Federal Government clients, we deliver Commonwealth Procurement Rules (CPR)–compliant work end-to-end. For corporate and state-government clients we apply the same probity discipline — defensible, auditable, and the way our clients' own internal audit functions would want it done.
Sovereign capability is part of how we work, not a marketing line. Australian workforce. Supply Nation engagement. SME subcontracting. Modern slavery and environmental sustainability commitments tracked across our supply chain.
Strategy, Policy
& Governance
Strategy, policy and governance for organisations going through real change. Decades of work across Federal and State Government and corporate Australia — former executives, board members and senior advisors who know what holds the answer in place when it gets tested.
Lead reference: Defence Information Warfare Project — Gate 0 submission and DSR reprioritisation.
Strategic policy development
Policy that ships, not policy that performs.
Digital governance design
Decision rights that match decision speed.
Business case development
Gate-ready, costed, defensible at Two-Pass.
Enterprise & workforce planning
Capacity that matches strategy, not yesterday's org chart.
Digital maturity assessments
Honest baselines. Useful next-step roadmaps.
Change & risk management
Prosci-grounded, risk-integrated, behaviourally informed.
Program, Project
& Change Management
Large-scale, high-value programs across Defence, ICT and business transformation. PRINCE2, AgilePM, SAFe and hybrid delivery — we pick the methodology that fits the program, not the one our certifications make easiest. We've stood up PMOs, scaled them, and deliberately scaled them back when the strategic context changed.
Lead reference: Defence IW Project — PM capacity for Gate 0, $120M program.
PRINCE2 / Agile / SAFe / hybrid delivery
Right tool, right context. We'll defend the choice.
Defence capability acquisition
Including the messy bits — DSR, reprioritisation, gate slips.
Integrated master scheduling
So you actually know when things will land.
Agile PMO establishment
Scaled to the program, not to the methodology poster.
Portfolio & program risk transformation
Where the IWE Gate-0/Gate-2 muscle was built.
Stand-up & stand-down
We can downsize an office by 75% in two months. We've done it.
Digital Sourcing,
Procurement & Contract Management
Digital sourcing, ICT procurement and contract management drawn from real-world experience on high-priority Defence projects. Probity-tight, CPR-compliant, sustainable and local sourcing where it matters. We've run BUYICT panel approaches and Defence prime-vendor procurements — and lived to write the lessons learned.
Lead references: Integrated Soldier Systems Procurement · IW Systems Integrator Procurement.
Needs identification & market research
So the RFT actually asks for the right thing.
Tender documentation
Statements of Requirements, Evaluation Plans, RFx drafting.
Supplier evaluation & negotiation
Probity-tight. Defensible. CPR-compliant.
Contract formation & administration
Outcomes-based, T&M, milestone, hybrid — we'll structure it.
Workforce planning
Aligning resourcing to procurement cycles, not the other way round.
Sustainable / local sourcing
Sovereign capability, Supply Nation, SME subcontracting.
Cybersecurity
Cybersecurity for government and critical infrastructure — designed to protect what matters and survive contact with your operating model. Strategy and governance that ships, not strategy and governance that PowerPoints. Designed with the people who actually have to run them.
Lead reference: IFCYBER (UNSW Canberra) — 18-month strategy design.
Cyber strategy design
Not the Word doc — the operating model behind it.
Governance frameworks
Roles, rituals, RACI that survives the first incident.
Stakeholder co-design
Workshop visits, not just "interviews".
Risk & compliance reviews
ISM, IRAP, PSPF — and what your auditor will actually ask.
Research & knowledge translation
Academic-to-operational, where most strategies get stuck.
Implementation planning
So the strategy actually gets executed.
Risk Management,
Benchmarking & Audit
Risk management, benchmarking and audit for complex multi-stakeholder environments. We co-authored the CASG Risk Management Practice Guide. We've run 130+ reviews across government and the private sector. We don't ship desktop frameworks — we ship the implementation that makes them work.
Lead reference: IMD Enterprise & Industry Strategy (Defence).
Risk assessment & mitigation
ISO 31000-grounded, project-specific, executive-readable.
Governance & strategy development
Risk integrated into how decisions actually get made.
Stakeholder engagement
Including the awkward conversation everyone's been avoiding.
Benchmarking
Against peers that are actually comparable.
Compliance & audit preparation
Done right means no surprises in the report.
Independent Assurance Reviews
Smart Buyer experience baked in. 50+ IARs delivered.
Six things we'll do
(and a few we won't).
Seniors on the job
Every engagement is staffed by the directors and our named-expert network — not a delivery pyramid.
Skin in the game
Outcomes-based commercials where it makes sense. Real risk-sharing, not contractual cosplay.
The Fears & Fools session
We kick off every job by asking: what are you afraid of? and what will you not risk because it might look foolish?
Knowledge transfer by default
"Teach a person to fish" is a value, not a tagline. We leave you with the muscle, not the dependency.
CPR-compliant procurement
Probity-tight, audit-defensible, ANAO-ready. We've been on the other side of those reviews.
Sovereign by design
Australian workforce. Supply Nation engagement. SME subcontracting. Modern slavery and environmental sustainability commitments — actually tracked.
Hard problem hiding
in plain sight?
Pick the service line closest to your ask — or skip the menu entirely and just describe the situation. We'll work it out.
Start a conversation →