About

About

Ārai Tika is te reo Māori for a shield done properly: tika, meaning correct, right, done well. It is also the standard we hold ourselves to.

Regulated organisations are asked to protect the people they serve while meeting obligations that change constantly, often with limited internal capacity to keep pace. Most compliance content available online is generic, written to rank rather than to be used. We built Ārai Tika to be different: practical guidance in privacy, information security, and compliance, written by people who have delivered this work, not just described it.

We are independent. We are not owned by, or answerable to, a technology vendor, an auditor, or a certification body. That independence is deliberate. It means the guidance here reflects what actually works, not what happens to suit a product roadmap or an audit fee.

What we believe

Proportionate, not performative

Compliance done well is not the thickest policy document or the longest control list. It is the right controls, applied consistently, and genuinely embedded in how an organisation operates. We favour frameworks that hold up under real scrutiny over ones designed to look complete on paper.

Plain language, properly sourced

Legislation and regulatory guidance are complex by nature. Explaining them does not need to be. Every piece of guidance we publish is grounded in the current legal position and written so a practitioner can act on it without a law degree.

Practical over theoretical

We are less interested in ticking compliance boxes, and more focused on strong compliance principles and frameworks that will protect your customers. That is the level we write at.

Where we focus

Four areas: information security and data privacy, AML compliance, fraud and financial crime, and transformation and risk. Our primary reference points are New Zealand, Australia, and the UK, reflecting where regulatory frameworks differ enough to matter and where we have the depth to speak with confidence.

Ārai Tika is written and maintained by practitioners with direct experience delivering compliance, privacy, and transformation programmes inside regulated organisations.