IT Requirements for Accounting Firms in Australia: The 2026 Baseline (Including Offshore Teams)

IT Requirements for Accounting Firms in Australia: The 2026 Baseline (Including Offshore Teams)

Accounting practices have spent the last decade getting more efficient: cloud ledgers, workflow automation, client portals, and capable staff working from Manila, Colombo or Bengaluru. You built the efficiency faster than the governance. In 2026, an accounting firm’s technology stack carries statutory obligations, reporting clocks measured in hours, and a professional conduct overlay that follows your client data wherever in the world it happens to be processed.

Three things have changed the picture for Australian accountants in particular.

The first is anti-money laundering. Since 1 July 2026, accountants providing “designated services” have been reporting entities under the amended Anti-Money Laundering and Counter-Terrorism Financing Act 2006. The Tranche 2 reforms brought roughly 80,000 new businesses — accountants, lawyers, conveyancers, real estate professionals, trust and company service providers — into a regime that previously covered banks and casinos. AUSTRAC enrolment opened 31 March 2026, and firms providing designated services from 1 July had until 29 July to enrol.

The second is the Tax Practitioners Board. The eight additional obligations under the Tax Agent Services (Code of Professional Conduct) Determination 2024 now apply to every registered practitioner: from 1 January 2025 for firms with more than 100 employees, and from 1 July 2025 for everyone else. Several are documentation and systems obligations.

The third is the breach picture. The OAIC recorded 1,205 notifications under the Notifiable Data Breaches scheme in the 2025 calendar year, the highest annual total since the scheme began in 2018, and an 8% increase on 2024. Of those, 716 came from malicious or criminal activity. Legal, accounting and management services firms accounted for 81 notifications.

1,205
data breach notifications to the OAIC in 2025, the highest since the scheme began
72 hrs
to report a ransomware payment, with no minimum payment threshold
7 years
minimum retention for AML/CTF records under the Tranche 2 regime

The dates that matter

  • 1 January 2025: TPB Code Determination obligations began for practices with 100+ employees
  • 30 May 2025: mandatory ransomware payment reporting commenced
  • 10 June 2025: statutory tort for serious invasions of privacy commenced
  • 1 July 2025: TPB Code Determination obligations began for practices with 100 or fewer employees
  • 1 July 2026: Tranche 2 AML/CTF obligations began applying to accountants
  • 10 December 2026: automated decision-making transparency required in privacy policies

The regulatory stack

Privacy Act 1988 and the Notifiable Data Breaches scheme

The Australian Privacy Principles govern how a practice collects, holds, uses and discloses personal information. APP 11 is the one that bites on IT: reasonable steps to protect information from misuse, interference, loss, and unauthorised access or disclosure.

Many small practices historically sat outside the Act via the small business exemption for entities under $3 million annual turnover. That assumption is now unsafe. The interaction between AML/CTF reporting entity status and the Privacy Act’s exemptions means a practice comfortably outside the Act in June 2026 may not be outside it now. Have a specific conversation with your own advisers. Do not plan your IT on the basis that the exemption still protects you.

Under the NDB scheme, an eligible data breach must be notified to the OAIC and affected individuals where unauthorised access, disclosure or loss of personal information is likely to result in serious harm and remedial action has not prevented that risk. The OAIC has been explicit that the clock starts when any employee becomes aware of the incident, not when it reaches the partners or the IT provider.

Accounting practices hold a concentrated set of the data identity criminals want: tax file numbers, bank details, dates of birth, identity documents, payroll files for every employee of every client. A single practice compromise can expose thousands of individuals across dozens of businesses.

Enforcement has changed too. The tiered civil penalty regime and the OAIC’s infringement notice powers commenced 11 December 2024, and on 10 June 2025 a statutory tort for serious invasions of privacy commenced, giving individuals a direct cause of action against any person, not only APP entities.

AML/CTF and the new record-keeping burden

Tranche 2 obligations are procedural, but they land on IT as a data problem. Reporting entities must enrol with AUSTRAC, maintain an AML/CTF programme, conduct customer due diligence before providing a designated service, screen against sanctions lists and politically exposed persons, submit suspicious matter reports, and retain records for seven years.

  • Identity documents now sit in your systems in volume. Passports, licences, company structures, beneficial ownership records, now collected in bulk.
  • Log every screening. “We checked” is not evidence. The system needs to record who screened, against what list, when, and what the result was.
  • Build seven-year retention into the records system. Backups age out on a cycle measured in weeks or months, so your backup rotation cannot hold a record for seven years.
  • Tipping-off provisions create a confidentiality problem inside your own practice. Access to suspicious matter documentation needs restricting, including from staff working on the engagement, and including offshore staff.

The TPB Code of Professional Conduct

The eight additional obligations under the 2024 Determination are now in force. Several are systems obligations:

  • Proper record-keeping. Accurate and complete records of tax agent services provided.
  • Quality management systems. Companies, partnerships and trusts must implement a documented QMS proportionate to the size and complexity of the practice.
  • Supervision and competency. Appropriate supervisory arrangements and competency checks, which becomes harder to evidence when the person doing the work is in another timezone.
  • Keeping clients informed of matters that materially affect their tax obligations, and disclosing prescribed events within 30 days.

Underneath the Determination, Code item 6 (confidentiality of client information) remains the obligation that most often collides with technology decisions. It is the reason offshoring requires client permission, and the reason your cloud stack is a professional conduct question.

ATO digital services: credentials are personal, and non-transferable

Access to Online Services for Agents runs through myID (the renamed myGovID) and the Relationship Authorisation Manager. The ATO’s terms and conditions are unambiguous about what that means operationally:

  • Each person acting on behalf of a practice needs their own Digital ID, set up on a unique device. Staff cannot share a myID or a device.
  • You must never provide your login code to anyone or enter a code on someone else’s behalf.
  • Access must be restricted to your employees, managed through Access Manager, and revoked when it is no longer needed.
  • You must not leave a machine unattended while logged in, and must make reasonable efforts to ensure controls are in place to safeguard your systems.
  • Compromised credentials must be reported immediately.

Client-to-agent linking adds a further control: clients with an ABN must nominate you in Online Services for Business before you can add them, and you cannot ask a client to share their myID or login code to complete it for them. Proof of identity requirements for client verification have been mandatory since 1 July 2023.

Shared credentials are the most common failure in this area. The practice that keeps one myID on a shared iPad “because it is easier at lodgement time” has breached the ATO’s terms, destroyed its own audit trail, and removed any ability to say who did what if an account is later compromised.

Cyber Security Act 2024 and the 72-hour ransomware clock

Since 30 May 2025, entities carrying on business in Australia with annual turnover of $3 million or more (and responsible entities for certain critical infrastructure assets, regardless of turnover) must report ransomware or cyber extortion payments to government within 72 hours of making the payment, or of learning that someone paid on their behalf, including an insurer or incident response firm. There is no minimum payment threshold. Civil penalties for non-reporting run to $19,800.

This sits on top of the NDB scheme rather than replacing it. A single ransomware incident involving client personal information triggers both, with different triggers and different clocks. If tax agent credentials or client tax data are implicated, the ATO expects to hear from you as well.


Offshore and remote workers

Offshoring is legal in Australia. Neither the TPB nor the APESB prohibits it, and for many practices it is the only viable answer to a shortage of qualified staff. It adds a layer of obligations that you do not carry when the same work happens in the office in Southport, and you satisfy most of them technically.

You need the client’s informed permission

Under Code item 6, the client must be informed of the arrangement and give permission before their information is disclosed to a third party. The TPB’s guidance is specific about what “informed” means: you must clearly tell the client to whom the disclosure will be made, where it will be made, and where the data will be stored, for example on overseas servers. This is normally done through the engagement letter or another signed agreement, and it should specify the type of information disclosed.

Two points practices get wrong:

  • It applies to your own offshore staff as well as outsourcing vendors. Where offshore workers are engaged through an agency or a service trust, the TPB’s position is that the client should still be made aware of to whom and where their information is being disclosed, even if you retain, organise and control the information within your own software and your own controls.
  • It applies to a practitioner working overseas personally. A practitioner who relocates must disclose the move, the arrangements for providing services and storing client records, and obtain written client consent to continue acting.

APES GN 30 Outsourced Services covers similar ground for members of the professional bodies: written consent, quality control over outsourced work, and confidentiality safeguards. A signed engagement letter incorporating the details of the intended outsourcing is an accepted form of consent, and firms outsourcing routinely may use a standard form of disclosure.

Privacy law makes you accountable for what happens overseas

APP 8 requires that before disclosing personal information to an overseas recipient, you take steps that are reasonable in the circumstances to ensure the recipient does not breach the APPs. Section 16C then does the heavy lifting: if the overseas recipient handles the information in a way that would have breached the APPs had you done it yourself, you are treated as having breached them.

You cannot contract this away. Pointing at your provider’s privacy policy does not discharge the obligation. The accountability sits with the Australian entity, and it sits there whether the offshore worker is a vendor’s employee, an agency placement, or your own staff member.

This bites on your cloud stack as well as on people. Any SaaS platform storing Australian client data outside Australia is an overseas recipient for these purposes, and most practices have never mapped their software against that question.

The ATO access problem

Offshore arrangements hit a technical wall at ATO access. myID is personal, non-shareable, must be set up on a unique device, and requires Australian identity verification to reach the identity strength the ATO’s services need. Offshore staff cannot hold one, and lending them yours breaches the ATO’s terms.

The workable architecture is to keep ATO-facing work with Australian-based authorised users, and give offshore staff access to the practice’s own systems (ledger, workpapers, document management) through controlled sessions. Design and enforce that distinction technically. It will not hold as a policy document alone.

What a defensible offshore access setup looks like

  • No local data. Offshore staff work inside a virtual desktop or published-application session. Client files are never downloaded to a personal machine in another jurisdiction, where you have no legal or practical ability to recover or wipe them.
  • Controlled data egress. Clipboard, file transfer, printing and USB redirection disabled or restricted within the session. This is the control that turns “we trust our team” into something you can evidence.
  • Named accounts and MFA for every person. No shared logins. Apply the ATO’s myID principle to every system in the practice.
  • Conditional access. Sign-in restricted by geography, device compliance and risk signal, so a leaked credential cannot be used from anywhere.
  • Least privilege by engagement. Offshore staff see the clients they work on, not the whole client base. This also gives you a defensible answer on AML/CTF tipping-off restrictions.
  • Session and access logging. When you have to answer “what was accessed, by whom, from where,” logging is the only thing that answers it. Without it, you over-notify because you cannot narrow the scope.
  • Structured offboarding. Revoke access the day someone leaves the offshore provider, which means your contract has to tell you when that happens.

What this means for the build

Reading the obligations back into infrastructure, a defensible accounting practice environment in 2026 needs:

Identity and access

Multi-factor authentication on every account without exception, and phishing-resistant factors for anyone with access to ledgers, payroll, banking files or administrative privileges. Individual myID per person on a unique device. Access Manager permissions reviewed, not set once and forgotten. Prompt de-provisioning on departure.

Email security and payment fraud

SPF, DKIM and enforced DMARC. Accounting practices are a prime target for business email compromise because they instruct payments and hold banking details for every client. Pair the technical controls with out-of-band verification for any change to payment or bank details: a call to a known number, never a number supplied in the email.

Endpoint protection and patching

Endpoint detection and response rather than legacy antivirus. Centrally managed operating system and application patching with defined timeframes. No end-of-life operating systems on the network. Take a clear position on whether offshore endpoints are in scope or excluded by design.

Backup and recovery, with immutability

Backups an attacker with domain credentials cannot encrypt or delete. Restoration testing that someone performs and documents. Losing a ledger in October is an inconvenience; losing it in the week before a lodgement deadline can end the practice. Test the restore before you need it.

Records, retention and disposal

Systems that hold records for the statutory periods, apply retention rules, and dispose of data when the period expires. Over-retention is a liability: five-year-old client tax files you no longer need can still be breached and still be sued over.

Logging and monitoring

You cannot assess whether a breach is notifiable without knowing what was accessed. Practices without meaningful audit logging end up over-notifying, telling every client their data may have been exposed, because they cannot rule anything out.

Offshore access architecture

Virtual sessions with no local data, restricted egress, named accounts, conditional access by geography and device, and per-engagement least privilege. The technical enforcement of what your engagement letter promised the client.

Third-party and data residency

Every SaaS platform in the practice mapped against where it stores data. Offshore providers, bookkeeping partners, document portals and AI tooling all handle client information, and the obligation does not leave the practice when the data does.


Frameworks: which one, and a transition to watch

The ASD Essential Eight remains the de facto Australian baseline and the reference insurers, tenders and assessors measure against. Its eight strategies have not changed since the November 2023 update. However, in June 2026 the Australian Signals Directorate opened consultation on replacing it with a broader Essentials series, beginning with a chapter on enterprise IT. Consultation closed 12 July 2026, with a staged transition of roughly two years signalled. ASD’s position is that existing Essential Eight investment remains relevant under the new model.

SMB1001 suits smaller practices. It is a tiered Australian certification from Bronze to Diamond, designed for organisations that cannot attempt ISO 27001. The 2026 edition expanded the Gold tier from 23 to 27 controls, adding endpoint detection and response, enforced email authentication, mandatory cyber insurance, an incident response plan, a digital asset register and a responsible AI use policy.

Framework Best suited to Assurance Status
ASD Essential Eight Any practice; the default reference for insurers and tenders Self-assessed or independently assessed against four maturity levels Current, but being replaced by the Essentials series over roughly two years
SMB1001 Small and mid-sized practices needing a credential without enterprise cost Bronze to Gold self-attested; Platinum and Diamond independently audited Current; 2026 edition expanded Gold from 23 to 27 controls
ISO 27001 Larger firms, audit practices, and those acting for government or enterprise clients Externally certified management system Stable international standard

Whichever you choose, the TPB’s quality management obligation means the practice needs a documented system regardless. Aligning that documentation with a recognised framework means doing the work once rather than twice.


The incident response plan is now a compliance artefact

The clocks overlap. Seventy-two hours for a ransomware payment report. “As soon as practicable” for NDB notification, with a 30-day maximum assessment window. AUSTRAC obligations. ATO notification where tax data or agent credentials are implicated. Client notification duties under the Code. Your plan needs to be written, tested, and accessible when the network is down.

At minimum it should specify: who decides, who they call, which obligations are triggered by which facts, who talks to clients, who talks to the ATO and the regulators, who talks to insurers, and where the plan itself is stored in a form that survives the incident. A copy stored only on the file server gets encrypted along with it.

If you use offshore staff, the plan also needs to answer how you contain access outside your own network and outside business hours, and who has the authority to do it at 3am.

We have covered this in more depth, with a free fillable template you can complete for your practice, in Does Your Business Need an Incident Response Plan?


How Mobile Techs IT Consulting closes the gap

Parliament and the professional bodies write these obligations in legal language, and someone has to turn them into configuration. Mobile Techs IT Consulting works in that space, translating what the Privacy Act, the AML/CTF Act, the TPB Code and the ATO’s terms of access require into controls that exist on your network, and then keeping them there.

ThreatDown EDR and the modern detection baseline

Legacy antivirus no longer meets the standard. Endpoint detection and response is an explicit requirement at SMB1001:2026 Gold, an expectation under the Essential Eight’s malware defences, and a practical necessity for demonstrating APP 11 “reasonable steps.”

  • Behavioural detection and containment. Ransomware in an accounting practice starts a 72-hour reporting clock, a notifiable data breach assessment and a Code item 6 confidentiality problem, all at once, on top of the downtime. Isolating an infected endpoint before it reaches the ledger server or document store is the difference between an internal incident and a reportable one.
  • Rollback capability. Where encryption does occur on a protected endpoint, reverting changes shortens recovery and narrows the scope of what has to be assessed for notification.
  • Evidence you can hand to a third party. “EDR deployed and centrally managed across all endpoints” is an answer that survives an insurer’s questionnaire. “We have antivirus” is not.

Remote Monitoring and Management: patching, devices, and the asset register you don’t have

Two of the eight Essential Eight strategies are patching: operating systems and applications. Both are measured on timeframes, and neither can be demonstrated without central management. Most practices fail here through drift: the laptop offline for six weeks, the machine past end of support, the partner deferring restarts since March.

Our RMM platform, backed by our remote support service, addresses this:

  • Automated, enforced patching across operating systems and third-party applications, with defined maintenance windows and reporting on what actually applied rather than what was scheduled.
  • A live device inventory. SMB1001:2026 Gold requires a digital asset register. RMM produces it as a by-product of doing the work: every managed device, its operating system, patch state and protection status.
  • End-of-life detection, so unsupported machines are flagged and replaced before they become the entry point.
  • Proactive alerting on health and configuration drift, including failing drives and backup jobs that stopped completing without anyone noticing. That is how most practices find out their backups were failing.
  • Reporting for audits, QMS documentation and insurance renewals. When the underwriter or a corporate client’s procurement team asks for evidence of patch management, we produce a report rather than an assertion.

Custom data storage and internal systems, including offshore access

This is where off-the-shelf products fall short for accounting practices, and where most of our work sits.

Seven-year AML/CTF retention, TPB record-keeping obligations, client engagement records, and workpaper archives are not the same requirement and do not share a lifecycle. A general-purpose cloud drive does not distinguish between them, and a backup rotation satisfies none of them.

  • Retention built into the storage. Records subject to statutory retention are held for those periods, in a location you can identify, and disposed of when the period expires, instead of sitting there by default.
  • Segregated access for sensitive categories. AML/CTF records, suspicious matter documentation and identity document repositories need controls that differ from general client files. Tipping-off obligations make this a compliance requirement. We build the segregation in rather than relying on staff to remember it.
  • Offshore access built the right way. Virtual sessions with no local data, restricted clipboard and file transfer, conditional access by geography and device, named accounts with MFA, and per-engagement permissions, so the arrangement your engagement letter describes is the arrangement that exists.
  • Audit logging that answers the notification question. When an incident occurs, the assessment is “what was accessed, by whom, from where.” Systems built without logging cannot answer, and practices in that position over-notify.
  • Integration with what you already run. Xero, MYOB, practice management, document management and portals are not going anywhere. We fill the gaps between them instead of replacing them.

What we do not do

Mobile Techs does not provide legal or tax advice on whether your practice provides designated services under the AML/CTF Act, does not draft your engagement letters, does not act as a certification body, and does not broker cyber insurance. Those are conversations for your own advisers, your professional body, an accredited assessor and your broker. We make sure that when those conversations happen, the technical answers are already in place and you can evidence them.

Compliance readiness review

Find out where your practice actually stands

Most practices are further ahead than they think in some areas and further behind in others. They usually find out which is which from an insurer’s renewal questionnaire, a client asking where their data is processed, or an incident that has already started the clock.

Mobile Techs assesses your current environment against the obligations set out above: endpoint protection, patching and device management, retention and access controls, email authentication, backup and recovery, offshore access architecture and incident response readiness. You get a written, prioritised list of what needs attention now, what can wait, and what each item involves.

No jargon and no obligation. You get a clear picture before someone else asks for one.

Book a review
Talk to us first

Call 1300 644 588  ·  office@mobiletechs.com.au
Supporting Gold Coast businesses on-site since 2008, and firms across Australia remotely.
More on our managed IT services, remote security audit and how we work.


A baseline by practice size

Practice size Baseline controls Target credential
Sole practitioner
to 10 staff
MFA everywhere, individual myID per person, EDR, managed patching, immutable backup with tested restores, DMARC enforced, written incident response plan, documented seven-year retention, AI use policy, cyber insurance SMB1001 Bronze or Silver
10–50 staff All of the above, plus centralised device management, conditional access, meaningful audit logging, Access Manager permission reviews, formal supplier and data-residency mapping, role-based controls around AML/CTF records, annual tabletop exercises SMB1001 Gold, or Essential Eight Maturity Level One with a documented path to Level Two
50+ staff, or any practice using offshore teams All of the above, plus virtual desktop infrastructure for offshore access with egress controls, security monitoring with defined response coverage, privileged access management, data loss prevention, a named individual accountable for information security Essential Eight Maturity Level Two, or ISO 27001

The gaps that show up most often

The recurring failures are mundane:

× A shared myID or a shared device, because it is faster at lodgement time
× Offshore staff working on client files downloaded to personal machines
× Engagement letters that never mention offshoring, or mention it so vaguely that no client could say to whom or where
× Backups that have never been restore-tested
× Departed staff, local or offshore, whose access was never revoked
× No map of which software stores client data outside Australia
× An incident response plan written for the pre-2025 obligations, with no 72-hour ransomware step

Closing these costs less than explaining them to an insurer or the TPB afterwards.

General information only. This article covers the technology and security implications of current Australian regulation. It is not legal, tax or professional conduct advice and does not account for any particular practice’s circumstances. Obligations under the Privacy Act, the AML/CTF Act, the Cyber Security Act, the Tax Agent Services Act and the professional standards vary by practice and continue to change. Practices should obtain their own advice on how these regimes apply to them, and should confirm current requirements with the TPB, the ATO and their professional body.