Obsidian Systems: Why Cloud Migration Doesn't Erase Financial Compliance Obligations
By Lauren Towner · 10 September 2026

Financial institutions migrating to Atlassian Cloud face a critical compliance deadline following the implementation of Joint Standard 1 of 2023. While SaaS providers manage underlying infrastructure, the regulatory burden for data recovery and IT governance remains with the institution, requiring firms to align cloud operations with specific risk management and restoration mandates to avoid audit failures.
What was announced
The implementation of Joint Standard 1 of 2023 on IT Governance and Risk Management, which became effective on 15 November 2024, has fundamentally shifted the compliance landscape for financial institutions using cloud-based productivity suites. Under this standard, the governing body of an institution retains ultimate responsibility for compliance, regardless of whether their infrastructure is hosted on-premises or via a SaaS provider like Atlassian. The regulation specifically mandates that institutions define and implement robust backup and restoration procedures that align with business recovery requirements and system criticality.
For those utilizing Jira, Confluence, or Jira Service Management in the cloud, the transition involves navigating a shared responsibility model. While Atlassian maintains the underlying infrastructure, the institution must ensure its specific data and workflows remain recoverable. Atlassian provides native backup and export capabilities, though these have defined limitations; for instance, Jira Cloud exports do not automatically include automation flows or certain Jira Service Management data. Furthermore, the standard requires that all changes to IT systems—including SaaS configuration changes like altering a Jira workflow or permission scheme—be recorded, tested, and verified.
To support these requirements, Atlassian offers audit logs and, for Premium and Enterprise subscribers, sandbox environments for testing configuration changes before they are deployed to production. Atlassian also currently offers a beta feature to deploy supported configuration changes from a sandbox to production. However, the responsibility remains with the institution to determine which changes require formal control and how approval is evidenced.
"Joint Standard 1 makes the accountability clear. The governing body remains ultimately responsible for compliance regardless of where the technology runs. A compliance gap appears when an organisation assumes that controls supplied by a cloud platform automatically satisfy the controls required by its own risk environment."
The source release.
The companies involved
Atlassian is a global technology company that develops products for software developers, project managers, and other software development teams. Its core offerings include Jira, a tool for issue tracking and project management, and Confluence, a collaborative workspace for documentation and knowledge sharing. The company also provides Jira Service Management for IT service delivery. Atlassian has increasingly focused on its cloud platform, which shifts infrastructure management to the provider while offering SaaS capabilities to its customers.
Obsidian Systems is a company involved in the Atlassian ecosystem, with a focus on enterprise solutions. Based in South Africa, it works alongside other entities such as RadixTrie and Autumn Leaf. These companies operate within a market that requires bridging the gap between standard cloud software functionality and the specific regulatory needs of large-scale organizations. Obsidian Systems has a history of providing technical expertise to firms navigating the complexities of the "system of work," particularly as they move critical operational processes into cloud environments. The relationship between these companies highlights a specialized segment of the fintech market dedicated to ensuring that global SaaS platforms can meet local governance requirements.
What FF News has reported before
FF News has previously explored the evolving partnership between these technology providers and their impact on corporate operations. In March 2025, the publication detailed how Obsidian Systems, Atlassian Rethink the System of Work, highlighting the collaborative efforts to modernize workflow management within the enterprise. This prior coverage examined how the integration of Atlassian’s cloud capabilities with Obsidian’s local expertise allows firms to move beyond traditional silos. The report emphasized that as organizations transition to more agile, cloud-based systems, the focus must shift toward maintaining visibility and control over critical business processes. This ongoing narrative underscores the importance of the current regulatory focus, as the "system of work" now encompasses not just productivity, but the fundamental governance and risk management structures required by financial authorities.
What this means
This announcement signals a definitive end to the "hands-off" era of SaaS adoption in the financial sector. Regulators are no longer satisfied with the mere availability of a service; they are demanding granular proof of recoverability and change control. This puts significant pressure on IT administrators who have historically treated SaaS configuration as routine maintenance rather than system-level engineering. The industry is moving toward a model where the "configuration as code" mindset must be applied to every administrative toggle. For the broader fintech market, this raises a vital question: can existing SaaS platforms evolve their native governance tools fast enough to keep pace with tightening global standards?
Companies in this story: Atlassian, RadixTrie, Autumn Leaf, Obsidian Systems
People in this story: Muggie van Staden