Legal · Supply Chain
Modern Slavery Statement
The constraint this document is designed around first is where our supply chain actually is. We assemble compute from hardware made on the other side of the world, from minerals extracted several tiers below our direct suppliers. Our visibility falls away fast past tier one, and pretending otherwise would make the statement worthless.
- Document status
- Structural template. Not reviewed by a lawyer. Not approved. Not lodged.
- Statutory framework
- Modern Slavery Act 2018 (Cth), seven mandatory reporting criteria
- Reporting threshold
- Consolidated revenue of at least A$100 million in a financial year
- Our position
- Unconfirmed. If below the threshold, any statement is voluntary
- Reporting period
- To be set once the reporting entity and financial year are confirmed
Draft structure only. This is not legal advice. This page was written by the team building the website, not by a lawyer, and no lawyer has reviewed it. It is not an approved modern slavery statement, it has not been considered by a board, and it has not been given to the Australian Border Force for the register.
It must be replaced with counsel-reviewed text, based on a real supply chain assessment, before this site is published. Every description of a risk, an action or a supplier below is illustrative. Publishing it as fact would misrepresent work that has not been done.
Status, threshold and reporting obligation
Template generated 14 September 2026 · Version 0.1 (draft) · Not approved, not lodged
The Modern Slavery Act 2018 (Cth) requires an annual statement from entities based or operating in Australia with consolidated revenue at or above A$100 million in a reporting period. Whether Cloud Natives is a reporting entity has not been confirmed, and the answer changes with growth and with group structure.
Two honest positions are available and both are respectable. If the threshold is met, a statement is mandatory, must address all seven criteria, must be approved by the principal governing body, signed by a responsible member, and given to the Minister for the register within six months of the end of the reporting period. If the threshold is not met, a voluntary statement may still be lodged — several suppliers to government do this because their customers ask.
What is not available is a statement that looks mandatory, claims due diligence that has not happened, and hopes nobody checks the register.
- Reporting entity
- Cloud Natives Pty Ltd (ABN to be confirmed), and any entity it controls
- Reporting period
- To be set. Must align to the entity's financial year
- Threshold position
- Unconfirmed. Requires consolidated revenue advice from the auditor
- Approval
- Board resolution required, with the resolution date recorded in the statement itself
- Signature
- A responsible member of the principal governing body, named and dated
- Publication
- Given to the Minister for inclusion on the public register, and published here with every prior year retained
Reporting Criteria
Seven criteria. All seven must be answered.
A statement that addresses five of the seven is not a shorter statement, it is a non-compliant one. This table exists so the drafter can see which criterion each section below carries, and where the evidence for it has to come from.
| Criterion | What it requires | Evidence needed |
|---|---|---|
| One | Identify the reporting entity | Company register extract, group structure, consolidated revenue advice |
| Two | Describe its structure, operations and supply chains | Headcount by role, site list, procurement spend by category and country |
| Three | Describe the risks of modern slavery practices in those operations and supply chains | Tiered risk assessment, sector and geographic risk indices, commodity analysis |
| Four | Describe the actions taken to assess and address those risks, including due diligence and remediation | Supplier code, contract clauses, questionnaire results, training records |
| Five | Describe how the entity assesses the effectiveness of those actions | Indicator definitions, baseline data, internal audit findings |
| Six | Describe the process of consultation with entities the reporting entity owns or controls | Meeting records, a joint-statement agreement if one applies |
| Seven | Any other relevant information | Grievance reports, industry collaboration, forward commitments |
Criteria One & Two
Structure, operations and supply chains.
This is the section reviewers judge hardest, because it is the one that shows whether an organisation has actually mapped its spend. A list of office locations is not a supply chain description.
Structure and operations — what to state
The legal entity, where it is incorporated, its ownership, and any entity it owns or controls. Then the operations: design, integration and operation of compute infrastructure, delivered from Australian offices with engineers on client sites and in third-party data centres. State headcount, the split between employees and contractors, and which roles require a security clearance.
Supply chain categories that carry the real exposure
An infrastructure integrator's slavery risk is concentrated in things it buys rather than things it does. The categories below are where the drafter should direct the spend analysis.
- Compute hardware
- Accelerators, servers, switches and storage arrays. Designed in one country, fabricated in another, assembled in a third. Electronics assembly is a well-documented forced-labour risk sector
- Minerals and components
- Cobalt, tantalum, tin, tungsten and gold sit several tiers below our direct suppliers. Extraction is where the documented abuses are worst and our visibility is weakest
- Data centre facilities
- Construction, fit-out, cleaning, catering and security. Low-wage, heavily sub-contracted labour, often engaged through layered labour-hire arrangements
- Cabling and consumables
- Optics, copper, racks, rails and packaging. Low-value, high-volume purchases that rarely receive procurement attention proportionate to their risk
- Freight and logistics
- International shipping, air freight, customs handling and local delivery. Seafarer exploitation is a recognised risk in maritime supply chains
- End-of-life disposal
- Decommissioned drives and servers. Informal electronic-waste processing in lower-income economies involves child and forced labour, and a certificate of destruction does not prove where the material went
- Offshore software and support
- Contract development and follow-the-sun support. Risk here looks like debt bondage, recruitment fees charged to workers, and passport retention rather than the imagery usually associated with the term
- Corporate services
- Office cleaning, security, uniforms and promotional goods. Small spend, real risk, and usually the easiest category to fix first
What has to happen before this section can be written. A spend analysis covering the last full financial year, broken down by supplier, category and country of origin, with tier-one suppliers identified by name. Without that data, any description of the supply chain is guesswork dressed as disclosure.
Criterion Three
Where the risk actually sits.
The Act asks about risks to people, not risks to the business. That distinction changes the whole analysis. A reputational risk register is not a modern slavery risk assessment, and reviewers can tell the difference immediately.
Direct operations — low risk, and we should say why
Australian employees on award or above-award terms, with security-cleared roles subject to Commonwealth vetting. The residual exposure is in labour hire and sub-contracted engineering, where a worker several arrangements removed from us may not hold the conditions we assume they do.
Tier one — visible, and therefore manageable
Hardware distributors, integrators and facilities contractors we contract with directly. We know who they are, and a renewal negotiation gives us real influence. Most large hardware vendors publish their own statements and audit programmes, which is a starting point for assessment rather than a substitute for it.
Tier two and beyond — the honest limit of our visibility
Component fabrication, board assembly, and mineral extraction. We do not select these suppliers, we do not contract with them, and we will not be able to audit them. Claiming otherwise would be the single least credible thing this statement could say. What we can do is choose vendors whose own due diligence is credible, and ask for evidence rather than a marketing page.
Facilities labour in data centres we do not own
Colocation means our equipment sits in a building cleaned, guarded and maintained by someone else's sub-contractors. Our influence is limited to supplier selection and the questions we ask during facility due diligence, so those questions need to be specific and repeated at renewal.
Pressure we create ourselves
Compressed delivery deadlines, hardware shortages and aggressive price negotiation push risk down the chain. When a cluster has to be racked before a grant milestone, somebody works the overtime. Naming our own purchasing behaviour as a risk factor is unusual in these statements, and it is the part most within our control.
Electronic waste at end of life
Decommissioning a petabyte-scale storage estate produces a large volume of drives and chassis. Where that material is exported for processing, the labour conditions are frequently unacceptable. Secure destruction and ethical disposal are the same procurement decision and should be assessed together.
Criterion four — actions to assess and address the risks
This is where most statements weaken, because describing a policy is easier than describing a consequence. The test for each item below is whether it changes a purchasing decision.
Governance and policy
A supplier code of conduct that prohibits forced labour, child labour, debt bondage, recruitment fees charged to workers and the retention of identity documents. An owner for it at executive level, and board visibility at a stated frequency. A policy nobody owns is not an action.
Contractual terms
Modern slavery clauses in supplier agreements, covering warranties, a right to information, a right to audit where proportionate, flow-down to sub-contractors, and a remediation-first response to a confirmed finding. Immediate termination sounds strong and often harms the affected workers, so the clause should require engagement before exit.
Due diligence, scaled to risk
A short questionnaire for every new supplier, and a deeper assessment for the categories identified as higher risk. Screen against sanctions and forced-labour import restrictions where they apply. Record the answers somewhere searchable, so next year's statement can describe a trend instead of starting again.
Procurement practice
Weight modern slavery performance in tender evaluation rather than treating it as a pass or fail gate at the end. Where a client is a Commonwealth or State buyer, their own procurement rules may impose requirements that flow to us, and those should be reflected here.
Grievance mechanism
A confidential route that a worker in our supply chain could realistically use. That means it is reachable without going through their employer, it works in a language they speak, and it protects them from retaliation. Publish it, and publish the number of reports received each year even when that number is zero.
Training
Targeted at the people who make purchasing decisions — procurement, engineering leads and account managers — rather than an annual module for everyone. Record completion, and record what changed in the way suppliers were selected afterwards.
Nothing above is in place yet. This section describes a programme that has not been built. The first year's statement should say exactly that, and then set out what will be done in the next period. A credible first statement admits a starting point; an incredible one describes maturity it has not earned.
Criterion Five
Assessing whether any of it worked.
Counting completed training modules measures activity, not effect. The indicators below are proposals, and each needs a baseline before it means anything. We have no baseline yet.
- Spend coverage
- Proportion of total procurement spend covered by a completed risk assessment. Measured by dollar value, not supplier count, because the two give very different pictures
- Tier-one visibility
- Number of direct suppliers identified, and how many have provided country of manufacture for the goods they supply
- Contract penetration
- Proportion of active supplier agreements containing current modern slavery clauses, including those renewed rather than newly signed
- Questionnaire quality
- Response rate, and separately the proportion of responses that were substantive rather than a policy attachment with no answers
- Issues identified
- Number of concerns raised, through any channel, and how each was resolved. A rise here is usually evidence the mechanism is working, not that risk grew
- Remediation outcomes
- What changed for the affected workers, described in outcomes. Terminating a contract is not a remediation outcome
- Decision influence
- Number of procurement decisions where a modern slavery finding changed the supplier chosen or the terms agreed. The hardest indicator to collect and the most informative
Reviewer expectation. Effectiveness is the criterion most often answered poorly across the public register. An honest first-year answer is that the framework is being established and effectiveness cannot yet be assessed, accompanied by the indicators and the baseline date. That is a better answer than a chart with no denominator.
Criteria Six & Seven
Consultation, approval and signature.
These two criteria are procedural, which is why they are the easiest to fail. A statement can be substantively good and still be non-compliant because the approval was not recorded properly.
Consultation with owned or controlled entities
The Act requires a description of the consultation process with each entity the reporting entity owns or controls. If there are none, say so directly — that is a complete answer to the criterion and a common one for a single-entity business. If there are, describe who was consulted, when, and how their input shaped the statement.
Approval and signature
- Approved by
- The principal governing body, by resolution. Record the date of the resolution
- Signed by
- A responsible member of that body, with name, role and date of signature
- Given to the Minister
- Within six months of the end of the reporting period, for the public register
- Published here
- This page, with every prior statement kept accessible rather than replaced
Signature block intentionally absent. A signature block on an unapproved statement is worse than a missing one. It will be added only after the board has resolved to approve a statement based on real assessment work, and the resolution date will be printed alongside the signature.
Other relevant information
Criterion seven is where an organisation can be useful rather than compliant. Worth including once there is something real to say: participation in industry collaboration on electronics supply chains, engagement with vendors on component traceability, and a plain account of what did not work in the previous period.
Raise a Concern
If you know something, tell us.
Concerns about labour conditions anywhere in our supply chain can be raised through the route below. You do not need to be certain, and you do not need to be our supplier or our employee.
Reports are treated confidentially. Where a report concerns a worker, their safety comes before our commercial relationship with the supplier, and we will not disclose their identity to that supplier without consent.
- Supply chain concerns
- hello@cloudnatives.example
- By phone
- +61 0 0000 0000
- Confidential channel
- To be established before publication
- Prior statements
- None. No statement has been approved or lodged
In an emergency, contact the police. Other ways to reach us are on the contact page.