Skip to content
Financial & accounting · Australia

Money moves fast. Verification should move faster.

Direct access to money and identity makes financial and accounting firms a first-choice target for organised crime. We map controls to the obligations that apply to the entity, including APRA, AML/CTF and TPB requirements where relevant, and document the evidence.

Dossier 03 / 10

Financial & Accounting

Direct access to money and identity makes financial firms a first-choice target for organised crime.

  • APRA CPS 234
  • AML/CTF Act 2006
  • Tax Practitioners Board (TPB)
  • Privacy Act 1988
Named obligations

What the obligation actually requires of you.

  1. 01

    APRA CPS 234

    APRA-regulated entities and their outsourced providers must maintain information security capability proportionate to the threat — a standard your controls need to demonstrate, not just assert.

  2. 02

    AML/CTF Act 2006

    Customer due-diligence records and transaction data must be held securely; a breach of that data is a compliance failure on top of a security one.

  3. 03

    Tax Practitioners Board (TPB)

    Registered agents carry a Code of Professional Conduct duty to protect client information — a breach can trigger a Tax Practitioners Board conduct matter alongside the incident itself.

  4. 04

    Privacy Act 1988

    Financial data is high-value and tightly regulated; where the Privacy Act applies, the Australian Privacy Principles govern personal information in client files, from a single tax return to a full financial plan.

7

controls to review

Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.

Illustrative scenario · Tax and advisory firm, NSW

A credential-phishing campaign before tax season.

Illustrative scenario — In this example, During the lead-up to lodgement season, a phishing campaign targeted the firm's client-portal login page with a near-identical clone. Several staff credentials were captured and offered for sale on a dark-web marketplace within 48 hours.

Example response — A suitable response is to reset exposed credentials, revoke sessions, enforce MFA on client and banking access, and review portal and email logs before restoring access.

What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.

Control evidence to collect

Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.

Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.

The compliance checklist

Run it yourself, before we ever speak.

  • MFA enforced across client portals, practice-management systems and banking access
  • Third-party and outsourcing risk assessed against APRA CPS 234, where applicable
  • AML/CTF customer due-diligence records held securely and access-logged
  • Dark-web monitoring for leaked staff and client credentials
  • An incident response plan tested against a simulated business-email-compromise scenario
  • TPB-relevant client data encrypted at rest and in transit
  • Principals briefed annually on the firm's cyber risk posture

These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.

Get the Financial & Accounting compliance checklist

A practical web checklist for your sector’s controls and obligations. No call. No obligation.

Before you call us

The questions this vertical always asks.

Find out exactly where your firm’s controls fall short.

The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.

Melbourne VIC · Australia · gmanit.com.au