For Australian accounting and tax practices
Tax returns. TFNs. Bank details. Could you prove how you protect them?
Plus the identity documents you verify and the payroll files you administer. Confidentiality of client information is a Code of Professional Conduct obligation, and antivirus, MFA and a privacy policy all help you meet it. None of them show what your people were required to do.
Your IT provider secures the systems. Cleverer keeps the organisational proof: named responsibilities, dated training, policy acknowledgements, recurring partner review, and an evidence trail you can hand over.
Five minutes, no email required to see your result. Built for practices with teams, from three people to thirty.
Nothing a criminal wants is missing from a tax file.
A stolen credit card gets cancelled in an afternoon. A stolen tax file follows someone for years.
- Tax file numbers For clients, their spouses, their children and every employee on a payroll you administer.
- Identity documents Licences and passports collected for proof of identity, then kept in the client folder indefinitely.
- Bank account and payment details Refund accounts, direct debits and supplier details, which is exactly what payment redirection fraud targets.
- Payroll and employee records Salaries, super, TFN declarations and personal details for staff of clients who never engaged you directly.
- Complete financial history Returns, BAS, financial statements, loan documents, trust deeds and company registers going back years.
- Privileged system access Portal access on behalf of clients, plus lodgement and correspondence rights that carry real authority.
Bookkeepers, administrators, offshore support and seasonal staff usually touch most of this. The obligation to handle it properly attaches to the practice, not only to the registered agent whose name is on the lodgement.
Two things changed for accounting practices, and both are already in force.
From 1 July 2026, a practice that provides designated services under the AML/CTF Act is a reporting entity for that work. The OAIC's guidance for reporting entities sets out what follows: a small business below the $3 million turnover threshold that becomes a reporting entity must comply with the Privacy Act when it handles personal information for AML/CTF purposes. Read that precisely. It does not put every accounting firm inside the Privacy Act for everything it does, and it is not the only way in. Coverage can arise independently, for instance where a practice is over the turnover threshold. What changed is that for practices relying on the small business exemption, a defined slice of the work now sits inside the Act, and APP 11 applies to it.
Privacy enforcement has also changed character. In March 2026 the Privacy Commissioner described an intentional shift toward a greater focus on enforcement over the preceding 12 months, citing a $5.8 million civil penalty against Australian Clinical Labs, civil penalty proceedings against Optus and Medibank, and a $50 million settlement with Meta. In January 2026 the OAIC ran its first targeted compliance sweep, checking around 60 businesses' privacy policies against the Act rather than waiting for a complaint. Accounting practices were not in that sweep. The direction is what matters: monitoring rather than guidance.
Separately, the TPB's guidance to registered practitioners is that sufficient IT controls over client records assist in meeting Code of Professional Conduct obligations, and confidentiality of client information is a Code obligation in its own right. The TPB does not mandate a specific cyber framework, and we will not tell you it does.
Having a control and being able to prove it are two different positions.
Almost every practice we speak to is in the left column and assumes it is in the right one.
| What the practice usually has | What actually gets asked for |
|---|---|
| A privacy policy on the website | Evidence that practices, procedures and systems supporting it are implemented and running, which is the APP 1.2 test. |
| Staff who have "done the training" | A dated completion record naming each person, including the bookkeeper and the seasonal preparer. |
| Policies in a shared folder | Who acknowledged the current version, and on what date. |
| Partners who take cyber seriously | A dated management review, with participants and decisions recorded. |
| MFA and endpoint protection from an MSP | The organisational half of reasonable steps: responsibility, training, governance and oversight. |
| An incident that was handled well | The record showing it was raised, assessed, actioned and closed. |
Cleverer sits on the right-hand side of that table. It does not replace your IT provider, and it does not supply technical security controls.
If someone asked today, what could your practice actually prove?
Answer as though you had to reply in writing, this week, with documents attached.
- Can you produce a dated training record for every person who opens a client file? Partners, accountants, bookkeepers, administrators and anyone offshore with system access.
- Can you show who acknowledged your current confidentiality and information handling expectations? Signed once at induction three years ago does not describe your current policy.
- Can you name the person accountable for privacy and cyber in the practice? In writing, with the obligation attached to a role rather than to whoever is free.
- Can you show a partner-level review of cyber and privacy in the last 12 months? Dated, with what was reviewed and what was decided.
- Can you show that a departing staff member's access was actually removed? Practice systems, portal delegations, cloud folders and the mailbox they shared.
- Can you show what happened after the last suspicious email or payment change request? Raised by whom, assessed how, closed when.
- If your AML client verification work is now inside the Privacy Act, can you show how that information is handled and how long you keep it? APP 11 asks you to protect it and to consider whether you still need it.
Ten questions, and an honest read on where the practice stands.
Short version of the full check. No email needed to see the result.
The record builds itself while the practice gets on with the work.
- Responsibility Every role carries a named set of cyber and privacy obligations. An administrator's obligations are not a partner's. Both are written down, and both are visible.
- Training Produce a dated training record without searching inboxes or spreadsheets. Assigned by role, completed by person, timestamped, and kept as evidence rather than as a certificate in a folder.
- Policies Know exactly who has acknowledged each current policy, and when. Revise a policy and the practice can see immediately who still needs to accept the new version.
- Oversight See overdue responsibilities and gaps before someone else finds them. Useful in the fortnight before a renewal, an audit or a client questionnaire lands.
- Review cycles Recurring reviews that happen on schedule and leave a record behind. Reminders escalate instead of expiring quietly, so a review becomes a dated event.
- Issues Log a concern, show what was done about it, and close it out. Handled well, an incident strengthens your position instead of exposing a gap in it.
What you can hand over when the request arrives.
Reasonable steps are assessed on what was in place at the time. That is an argument you win with records, or lose without them.
- A dated register of who holds which obligation, and how that changed over time So you can answer for last financial year, not only for this week.
- Training completion and certification per person, per role Exported as a report instead of reconstructed from memory the day it is requested.
- Policy acknowledgement history against each version Who accepted what, on what date, against which version of the document.
- A management review trail Evidence that oversight recurs, which is the difference between having a policy and running a compliance practice.
- An issues and escalation log Concerns raised, actions taken, dates closed.
Cleverer maintains organisational evidence. It does not provide technical security controls, it does not prevent breaches, and nothing on this page is legal or tax advice.
Next step
Do not find the gaps during a breach, a complaint or an insurance claim.
The Compliance Check scores the controls and the evidence separately. Most practices are surprised by the second number, and it is the one that decides how defensible you look.
Sources
- OAIC, Privacy guidance for reporting entities under the AML/CTF Act.
- OAIC, Handling privacy complaints, a new approach for a new era (2 March 2026), and the January 2026 compliance sweep.
- OAIC, APP guidelines, Chapter 1: APP 1, and Chapter 11: APP 11.
- Tax Practitioners Board, Protect your practice from cyber attacks and the Code of Professional Conduct.
General information only. This page is not legal advice.