Money moves fast. Verification should move faster.
Direct access to money and identity makes financial and accounting firms a first-choice target for organised crime. We map controls to the obligations that apply to the entity, including APRA, AML/CTF and TPB requirements where relevant, and document the evidence.
Dossier 03 / 10
Financial & Accounting
Direct access to money and identity makes financial firms a first-choice target for organised crime.
- APRA CPS 234
- AML/CTF Act 2006
- Tax Practitioners Board (TPB)
- Privacy Act 1988
What the obligation actually requires of you.
- 01
APRA CPS 234
APRA-regulated entities and their outsourced providers must maintain information security capability proportionate to the threat — a standard your controls need to demonstrate, not just assert.
- 02
AML/CTF Act 2006
Customer due-diligence records and transaction data must be held securely; a breach of that data is a compliance failure on top of a security one.
- 03
Tax Practitioners Board (TPB)
Registered agents carry a Code of Professional Conduct duty to protect client information — a breach can trigger a Tax Practitioners Board conduct matter alongside the incident itself.
- 04
Privacy Act 1988
Financial data is high-value and tightly regulated; where the Privacy Act applies, the Australian Privacy Principles govern personal information in client files, from a single tax return to a full financial plan.
controls to review
Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.
A credential-phishing campaign before tax season.
Illustrative scenario — In this example, During the lead-up to lodgement season, a phishing campaign targeted the firm's client-portal login page with a near-identical clone. Several staff credentials were captured and offered for sale on a dark-web marketplace within 48 hours.
Example response — A suitable response is to reset exposed credentials, revoke sessions, enforce MFA on client and banking access, and review portal and email logs before restoring access.
What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.
Control evidence to collect
Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.
Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.
Run it yourself, before we ever speak.
- MFA enforced across client portals, practice-management systems and banking access
- Third-party and outsourcing risk assessed against APRA CPS 234, where applicable
- AML/CTF customer due-diligence records held securely and access-logged
- Dark-web monitoring for leaked staff and client credentials
- An incident response plan tested against a simulated business-email-compromise scenario
- TPB-relevant client data encrypted at rest and in transit
- Principals briefed annually on the firm's cyber risk posture
These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.
The questions this vertical always asks.
An audit confirms a point-in-time state. We build and monitor the controls that keep you compliant between audits, and prove it with evidence rather than a checklist filled out once a year.
The customer due-diligence records your AML/CTF program depends on are only as safe as the systems storing them. A breach there is a compliance failure, not just a technical one.
Call us before you move anything. Verifying a payment instruction through a second channel takes minutes and can be the difference between a close call and a genuine loss.
Find out exactly where your firm’s controls fall short.
The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.
Melbourne VIC · Australia · gmanit.com.au