Skip to content

Compliance for accountants, advisers and AFSL holders.

Tax Practitioners Board record-keeping, ASIC cyber-resilience expectations, client-money handling, anti-money-laundering reporting from 2026. Financial-services obligations stack rather than replace each other. The practices that handle them without heroics put the IT discipline in place before anyone asked to see it.

Live right now ·  finance, advisers, accountants

What's hitting finance and accounting practices right now.

Regulatory changes with dates already set, and what each one asks of you.

AUSTRAC Tranche 2 AML/CTF

In force since 1 July 2026

Captures accounting practices providing designated services: corporate appointments, nominee services, company and trust formation, client-money handling. Enrolment closed on 29 July 2026, so the AML/CTF programme has to be in operation.

Read the full guide

What's being asked of you ·  finance, advisers, accountants

What finance and accounting practices have to prove on compliance in 2026.

Your obligations depend on the authorisations you hold, and they add rather than substitute. An accountant providing designated services becomes an AUSTRAC reporting entity from 1 July 2026. Hold an Australian financial services licence, or AFSL, and you answer to cyber-resilience expectations from the Australian Securities and Investments Commission. ASIC builds those into your licence conditions. A registered tax agent picks up Tax Practitioners Board record-keeping on top of ongoing Privacy Act work. Hold several authorisations at once and the load outgrows the people available to do it.

The evidence expectation is the same wherever it comes from. ASIC, AUSTRAC, the Tax Practitioners Board and any parent regulated by the Australian Prudential Regulation Authority all ask the same four things. How a control is implemented. When it was last tested. Who can reach which data. What happened the last time something went wrong. The interpretation differs between them. The machinery that evidences it does not.

Insurers and corporate clients add their own paperwork. Practices we onboard often arrive with three or four questionnaires open at once. A professional indemnity renewal, a corporate client's supplier-assurance program, a referral partner's vendor onboarding. The questions are broadly the same in different formats. One well-evidenced control environment answers all of them. Ten separate manual responses do not.

What we do ·  Map, build, maintain

What finance and accounting practices get from a compliance engagement.

The first thing you get is a map. Which obligations attach to which authorisation, and which technical controls answer more than one of them. The overlap is large. One well-designed stack usually covers the lot, which is cheaper and more defensible than ten separate implementations.

Most of the practical work is around client data. Where the files are. Who can reach them. What happens when a staff member leaves. How you would prove to an auditor that nobody opened something they should not have. Practices we onboard usually have good intentions here and uneven evidence. We close the gap with identity controls, logging, retention policy and document-management configuration. Then we keep the record current month by month.

The cycle is continuous rather than event-driven. Gap analysis against the authorisations you hold. Monitoring of the controls in operation. Remediation when something drifts. Evidence that produces on demand. That is the difference between walking into an ASIC review confident and scrambling the week before.

We do not give financial-services advice or sign off on compliance. Interpretations under your professional body's rules stay with your principals and your compliance officer. We build the systems those interpretations depend on.

The tools and the role ·  the operational toolkit

The capabilities most finance and accounting practices need at once, and rarely have in-house.

Whichever framework you are measured against, it asks for roughly the same operational set. These five we run as a service, so the framework cycle is a continuing operation rather than an annual scramble.

  • Trouble shows up while it is still recoverable

    Security information and event management, or SIEM, collects logs from your devices, identity, network and cloud services. The alerting answers 'are we under attack right now' rather than 'were we under attack last quarter'.

  • Unapproved software never gets to run

    Allowlisting stops unauthorised executables running on managed devices. One of the highest-impact Essential Eight controls, and one of the hardest for in-house IT to operate without breaking the business. We run it as a service, exception handling included.

  • Known vulnerabilities get closed, not just listed

    Most providers run a scanner and email you a list. We run the scanner and do the labour-intensive remediation work that actually closes the vulnerabilities inside the thirty-day window most frameworks expect.

  • Staff finish the training, and you can prove it

    Annual training your staff actually complete, plus phishing simulations that escalate rather than scold. Your compliance officer gets the completion reporting they can show an auditor or an insurer.

  • Someone senior owns the roadmap, without the salary

    Strategic IT advice, framework gap analysis, board-level reporting, risk register maintenance and vendor management oversight. That is the virtual chief information officer, or vCIO, role most firms our size cannot resource internally.

    More on our vCIO service

What goes wrong ·  for finance, advisers, accountants

The compliance risk that actually costs finance and accounting practices work.

The risk that matters is not the question you answered accurately and lost a tender over. It is the yes you gave on an ASIC, APRA or insurer questionnaire when the control was only partly there. A breach or an audit arrives, and the evidence you cannot produce becomes evidence against you. We have watched practices lose insurer cover and corporate clients over controls they could not substantiate. Preventing that is mostly process discipline rather than extra spend.

Already included ·  baseline plan

What your managed IT engagement already covers.

The baseline is already in every CCP plan. Multi-factor authentication, application control, vulnerability management, tested backups and offboarding discipline cover the core of what a financial-services questionnaire asks about. Where a specific regime applies, we add the extra controls for your engagement. AUSTRAC enrolment, ASIC market-participant obligations and an APRA-regulated parent are the three we see most.

Compliance is an overlay, not a plan tier. The Managed IT + Compliance plan exists for practices that need the overlay running continuously, with evidence generation and reporting as an ongoing service. Simpler obligations can run on the baseline plan, with overlays added where a regulator or a client makes them necessary.

Some of it stays with you. Regulatory interpretation, formal compliance sign-off, and the work a Responsible Manager owns under your licence or registration. We bring the IT and compliance capability most practices cannot resource internally, alongside the people who own the regulatory substance.

Common questions

The framework questions finance and accounting practices ask us first.

Can you help us prepare for an APRA CPS 234 assessment?
Do you handle AUSTRAC enrolment for accountants?
What do ASIC Regulatory Guide 271 and the Financial Accountability Regime mean for our systems?
Can you help with ASIC's cyber-resilience expectations on AFSL holders?
How does this fit our Tax Practitioners Board obligations?
Will this satisfy a Big 4 vendor due-diligence questionnaire?
What evidence will our compliance officer have?

Next step ·  start with the evidence

Find out what your Essential Eight maturity actually is.

Ten minutes of questions gives you a PDF report on your Essential Eight maturity. Hand it to your compliance officer, your insurer or your board the same day. If you want to check we are the right shop for the work, start with the fit check.

See if we're a fit