Why accounting IT requires specialist handling
The Tax Practitioners Board issued Guidance Statement TPB(GS) 55/2026 on 22 July 2026 making clear that a tax practitioner remains responsible for all work product even when AI-assisted or outsourced, must obtain client permission before disclosing client information to an AI tool, and must maintain competence in the IT systems used for tax agent services, so the IT governance choices an accounting firm makes now feed directly into a live professional conduct obligation. TPB Guidance Statement TPB(GS) 55/2026.
Legal, accounting and management services accounted for 81 of the 1,205 data breach notifications the OAIC received in 2025, making it one of the top five sectors by volume, so an accounting firm is a measured target for attackers who know the firm holds financial data and the ability to move money on behalf of clients. OAIC, data breach notifications increase to all-time high in 2025.
Accounting firms hold some of the most sensitive data in Australian business. Tax File Numbers, financial statements, business activity statements, personal financial affairs, and client money in trust accounts. A breach at an accounting firm affects multiple clients simultaneously, multiplying regulatory exposure.
The Tax Practitioners Board holds registered agents to the Code of Professional Conduct. You must maintain competence in the IT systems you use for client work. Confidentiality obligations extend to how you store, transmit, and dispose of client data.
Generic MSPs often miss accounting-specific requirements. They apply standard SMB baselines that do not account for TFN Guidelines, practice management workflows, or the seasonal intensity of tax time. This guide covers what Australian accounting firms specifically need.
Compliance requirements for Australian accounting firms
TPB(GS) 55/2026 requires tax practitioners to inform clients about the proposed disclosure of information to AI tools, including to whom and where the disclosure will be made, where data will be stored and whether AI tools may be used, and the TPB recommends practitioners perform their own due diligence when selecting commercial or internally developed AI tools, which means your IT systems must now evidence client consent and AI tool governance for TPB audits. Wolters Kluwer, TPB message on AI.
TPB Guidance Statement TPB(GS) 36/2021 already restricts the use and disclosure of a client TFN and TFN information in email communications, and the OAIC can investigate TFN misuse as a criminal offence under Privacy Act section 17, so an accounting firm that emails TFNs unencrypted or lets staff paste client data into free-tier AI tools is carrying both a TPB and a Privacy Act exposure simultaneously. TPB Guidance Statement TPB(GS) 36/2021.
Five regulatory frameworks that shape your IT requirements. Non-compliance carries financial penalties, TPB sanctions, and reputational damage.
| Regulation | Requirement | Applies To | Penalty |
|---|---|---|---|
| Privacy Act 1988 (Cth) | Protect TFN, financial data, and personal information under the Australian Privacy Principles. | All firms handling client tax and financial data | Up to $62.5 million for serious or repeated breaches (2026) |
| Tax File Number Guidelines (Privacy Act s.17) | Secure collection, storage, use, disclosure and disposal of TFN information. OAIC enforcement. | All entities handling TFN data | Criminal offence for TFN misuse. OAIC complaints, civil penalties. |
| TPB Code of Professional Conduct | Maintain confidentiality and competence in the IT systems used for tax agent services. | Registered tax agents and BAS agents | TPB sanctions, suspension, termination of registration |
| Notifiable Data Breaches Scheme | Report eligible breaches to the OAIC and affected individuals. | All firms with personal data | Investigation, enforceable undertakings, civil penalties |
| Client Money Handling | Segregated trust accounts, reconciliation, audit trail. | Firms holding client funds | Professional indemnity implications, TPB action |
TPB Code of Professional Conduct
The Tax Practitioners Board Code of Professional Conduct (section 10) requires registered agents to maintain competence in the IT systems used for tax agent services. This includes understanding security controls, backup arrangements, data handling practices, and ensuring staff are adequately supervised.
From 1 July 2025, the TPB introduced new guidance on use of AI and third-party tools. You remain responsible for all work product even if outsourced or AI-assisted. Document your IT governance, review annually, and maintain evidence of compliance for TPB audits.
Practice management system security
The TPB Chair stated in July 2026 that AI has the potential to increase productivity, drive efficiencies and enhance client service across the tax profession when used appropriately, but the guidance reaffirms that competency is a human responsibility, so the practice management security controls below must extend to how AI tools are connected to MYOB, Xero and FYI docs via API and who has authority to approve those integrations. TPB Guidance Statement TPB(GS) 55/2026.
Common platforms in Australian accounting practices. Each requires specific security configurations beyond default settings.
MYOB AO and AO Next
On-prem or hosted. Requires secure remote access. Backup separately from the MYOB default. User access reviewed quarterly.
Xero Practice Manager
Cloud-based. Enforce MFA. Review third-party app connections. Export data regularly for independent backup.
Class Super
SMSF specialist. Cloud-based with Australian data centres. MFA required. Audit trail maintained.
BGL Simple Fund 360
Cloud-based SMSF platform. MFA enforced. API integrations reviewed quarterly.
FYI docs
Document management. Integrate with the practice platform. Apply retention policies. External sharing controlled.
FYI docs and document management
FYI docs is widely used in Australian accounting firms for document management and workflow. Integrate with your practice management platform. Apply retention policies aligned with tax record-keeping requirements (typically 5 years minimum). Control external sharing and audit document access quarterly.
Six common IT gaps in Australian accounting firms
Letting staff paste client financial data into free-tier AI tools is now a live TPB and Privacy Act exposure because TPB(GS) 55/2026 requires client permission before disclosing client information to an AI tool and the free tiers of consumer AI platforms can use prompts for training unless opted out, so the gap is no longer just shadow IT but an undocumented professional conduct breach. Wolters Kluwer, TPB message on AI.
These gaps appear repeatedly in accounting practice assessments. Each one carries Privacy Act, TPB, or ATO risk.
No MFA on practice management or email
Risk: Account takeover via phishing. Client tax data exposed. ATO notification may be required.
Fix: Enforce MFA on all platforms. Use app-based or FIDO2. SMS is acceptable as an interim but plan to upgrade.
Client files emailed unencrypted
Risk: Interception in transit. Privacy Act breach. TFN Guidelines violation.
Fix: Use a secure client portal or encrypted email for sensitive documents. Never email TFNs unencrypted.
Shared workpapers with no version control
Risk: Overwritten work. No audit trail. Quality control failures.
Fix: Use FYI docs or similar with version history. Lock finalised workpapers.
Staff access not removed on departure
Risk: Former staff access client files. Data theft. Conflict of interest.
Fix: Documented offboarding checklist. Remove access within 24 hours. Exit interview conducted.
Backup without testing
Risk: Backup corrupted or incomplete. Cannot restore after an incident.
Fix: Test restores quarterly. Document results. Include practice management data and email.
Personal devices accessing client data
Risk: Unsecured devices. No encryption. No remote wipe. Data exfiltration.
Fix: Intune App Protection Policies. Block access from non-compliant devices. Encrypted laptops only.
Essential Eight for accounting practices
Accounting firms should target Essential Eight Maturity Level 2 as a minimum because insurers and professional bodies increasingly expect it, and Maturity Level 2 requires patching within 48 hours for critical updates, application control to block consumer cloud sync, immutable 90 day backup and MFA on all accounts using the Microsoft Authenticator app or FIDO2 keys rather than SMS. ACSC Essential Eight maturity model.
The ACSC Essential Eight is the baseline for Australian cyber security. Accounting firms should target Maturity Level 2 as a minimum. Insurers and professional bodies increasingly expect this.
Application Control
Windows Defender Application Control (WDAC) or AppLocker. Block execution from user-writable paths. Allow-list: MYOB, Xero, Adobe Acrobat, Microsoft Office, Chrome or Edge, FYI docs. Prevents ransomware and unauthorised cloud sync (personal Dropbox, Google Drive). Block consumer cloud storage via DLP policies.
Patch Applications
Microsoft Intune Update Rings. Patch Adobe Acrobat, Chrome and Edge, Microsoft Office within 48 hours of critical updates. Automate with Intune. A pilot group tests patches before firm-wide deployment. Critical during tax time (January to April) so patch on weekends to avoid disruption.
Configure Microsoft Office Macros
Group Policy: block macros from internet enabled. Excel macros in workpapers must be signed with a trusted certificate. VBA projects password-protected. Macro execution logged via Microsoft 365 audit. Prevents macro-based ransomware commonly delivered via tax-time phishing.
User Application Hardening
Disable Flash (EOL 2020), Java browser plugins, unnecessary browser extensions. Edge and Chrome policies: block sideloading extensions, enforce Safe Browsing, disable password save. Reduce attack surface for browser-based exploits and credential theft.
Restrict Administrative Privileges
No daily-use accounts with local or admin rights. Separate Entra ID accounts for IT staff. Just-In-Time (JIT) access via PIM for elevated tasks. Local admin passwords managed via LAPS. Partners get standard user accounts, no exceptions.
Patch Operating Systems
Windows 10 and 11 Enterprise with Windows Update for Business. Feature updates deferred 90 days, quality updates deferred 7 days. Critical and security patches within 48 hours (ACSC ML2). Intune for deployment. Tax time exception: patch non-billable staff first, partners and managers second.
Multi-Factor Authentication
MFA on email (Exchange Online), practice management (MYOB or Xero SSO), ATO portals (TAP, BAS Agent Portal), SharePoint and OneDrive. Microsoft enforcing MFA for all admin sign-ins from Feb 2026. Use Microsoft Authenticator (number match) or FIDO2 keys (YubiKey), not SMS. Conditional Access: require MFA for all cloud apps, block legacy authentication (POP3, IMAP, SMTP).
Daily Backup
Veeam Backup and Replication or Altaro VM Backup. Immutable backup with 90-day retention (ACSC ML2). 3-2-1 rule: 3 copies, 2 different media, 1 offsite. Include MYOB and Xero data, FYI docs, email (all mailboxes), Excel workpapers. Store backups separate from the production network (different VLAN or Azure Blob with object lock). Test restores quarterly. RTO under 4 hours, RPO under 1 hour.
Tax time IT readiness checklist
Tax time from January to April is when accounting firms are most exposed because staff are working extended hours, phishing campaigns targeting ATO portal credentials peak, and patching windows shrink, so completing the readiness checklist below before 1 January is what keeps a firm from a notifiable breach landing in the middle of the busiest quarter. OAIC, data breach notifications increase to all-time high in 2025.
January to April is peak intensity. IT must support the load without failures. Complete this checklist before 1 January.
Related: Business Email Compromise Guide, Finance IT Solutions, Data Loss Prevention.
Common questions
What IT compliance obligations apply to Australian accounting firms?
What is the TPB Code of Professional Conduct IT requirement?
How should an accounting firm secure Tax File Number data?
What Essential Eight maturity level should an accounting firm target?
How should an accounting firm prepare IT for tax time?
Does Microsoft 365 back up accounting practice data?
Need help with accounting firm IT compliance
We audit accounting practices for Privacy Act compliance, TPB Code alignment, practice management security, and cyber insurance readiness. Deliverables include a prioritised remediation plan and evidence documentation for TPB and insurers.

Remote Support