- Documentation
- /
- Lsrr
- /
- 00 — Overview
00 — Overview
Queensland Audit Office (QAO) reference application. This is a demonstration prototype modelled on the Queensland Audit Office's public-facing documentation, reports, guidance and activities. It is not an official QAO system and holds no real audit information — every entity, system, service, risk and decision in the demo data is fictional and illustrates the data model and workflow only.
What LSRR is
The Legacy Systems Risk & Replacement Register turns legacy-systems assurance into a structured, evidence-backed register. A legacy system isn't "handled" because a replacement is planned — it is assured when its dependencies are mapped, its obsolescence and risk are assessed, effective compensating controls hold the residual risk, the replacement is progressing with evidenced readiness, and its eventual retirement is authorised and checklisted (data retained, interfaces disabled, access removed, business signed off). LSRR holds every one of those links so the state of legacy risk is always demonstrable.
The domain
Auditors repeatedly find agencies running critical services on unsupported, obsolete systems that are hard to secure and staff, with replacements that slip. The hard parts are dependency mapping (what breaks if this fails?), obsolescence & risk (how bad is it, and what holds the line?), and controlled retirement (you can't just switch it off). LSRR models all three, and keeps the replacement and retirement honest against evidence.
The 17 models by area
Systems & Services (5) - Entity — the audited organisation. · LegacySystem — a system in scope (criticality, lifecycle, support status). - BusinessService — a service the agency delivers. · ServiceDependency — a service's reliance on a system. - SystemDependency — a system-to-system dependency (source → target).
Risk & Controls (5) - ObsolescenceAssessment — a scored obsolescence assessment of a system. - Risk — a risk arising from a system (inherent & residual scored). · CompensatingControl — a control holding a risk. - EvidenceRequirement — what evidence is required. · EvidenceSubmission — the evidence provided.
Replacement (4) - ReplacementInitiative — the project to replace a system. · ReplacementMilestone — a milestone within it. - ReplacementDependency — a dependency the replacement relies on. · CutoverReadiness — a cutover readiness area.
Retirement & Assurance (3) - RetirementPlan — the controlled retirement of a system (with a confirmation checklist). - AssuranceDecision — an authorised decision (approve/defer/conditional). · StatusHistory — the system's lifecycle trail.
(The source pack's DomainEvent outbox is Phase 2 — see page 03.)
The demo scenario
A QAO-style register centred on the Department of Justice & Attorney-General's legacy
Case Management System (CMS) — COBOL/mainframe, unsupported since 2023, CRITICAL,
holding personal information:
- Dependencies:
Court case processing(MTO 4h) depends entirely on the CMS; the CMS feeds the legacy Document Store. - Obsolescence & risk: a 4.5/5 obsolescence assessment; RSK-001 (unsupported
platform security exposure,
CRITICAL) mitigated by CC-001 (segmentation + monitoring,EFFECTIVE) with an accepted pen-test evidence; RSK-002 (scarce COBOL skills). - Replacement: REPL-001 (cloud CMS, 55% complete) with a completed design milestone, a UAT milestone in progress, a blocking document-migration dependency, and mixed cutover readiness.
- Retirement & decision: a planned retirement (checklist part-confirmed) and a CONDITIONAL assurance decision to continue to cutover.
26 rows across all 17 models — a realistic "critical legacy system, risk held, replacement mid-flight, retirement conditional" state.