All Guides
Industry Guide

Managed IT for Australian Accounting Firms

Privacy Act compliance, TFN Guidelines, TPB Code of Professional Conduct, practice management security, and Essential Eight alignment. Built for Australian accounting practices between 3 and 50 staff.

Last updated 4 October 202618 min read

Why accounting IT requires specialist handling

The Tax Practitioners Board issued Guidance Statement TPB(GS) 55/2026 on 22 July 2026 making clear that a tax practitioner remains responsible for all work product even when AI-assisted or outsourced, must obtain client permission before disclosing client information to an AI tool, and must maintain competence in the IT systems used for tax agent services, so the IT governance choices an accounting firm makes now feed directly into a live professional conduct obligation. TPB Guidance Statement TPB(GS) 55/2026.

Legal, accounting and management services accounted for 81 of the 1,205 data breach notifications the OAIC received in 2025, making it one of the top five sectors by volume, so an accounting firm is a measured target for attackers who know the firm holds financial data and the ability to move money on behalf of clients. OAIC, data breach notifications increase to all-time high in 2025.

Accounting firms hold some of the most sensitive data in Australian business. Tax File Numbers, financial statements, business activity statements, personal financial affairs, and client money in trust accounts. A breach at an accounting firm affects multiple clients simultaneously, multiplying regulatory exposure.

The Tax Practitioners Board holds registered agents to the Code of Professional Conduct. You must maintain competence in the IT systems you use for client work. Confidentiality obligations extend to how you store, transmit, and dispose of client data.

Generic MSPs often miss accounting-specific requirements. They apply standard SMB baselines that do not account for TFN Guidelines, practice management workflows, or the seasonal intensity of tax time. This guide covers what Australian accounting firms specifically need.

Compliance requirements for Australian accounting firms

TPB(GS) 55/2026 requires tax practitioners to inform clients about the proposed disclosure of information to AI tools, including to whom and where the disclosure will be made, where data will be stored and whether AI tools may be used, and the TPB recommends practitioners perform their own due diligence when selecting commercial or internally developed AI tools, which means your IT systems must now evidence client consent and AI tool governance for TPB audits. Wolters Kluwer, TPB message on AI.

TPB Guidance Statement TPB(GS) 36/2021 already restricts the use and disclosure of a client TFN and TFN information in email communications, and the OAIC can investigate TFN misuse as a criminal offence under Privacy Act section 17, so an accounting firm that emails TFNs unencrypted or lets staff paste client data into free-tier AI tools is carrying both a TPB and a Privacy Act exposure simultaneously. TPB Guidance Statement TPB(GS) 36/2021.

Five regulatory frameworks that shape your IT requirements. Non-compliance carries financial penalties, TPB sanctions, and reputational damage.

RegulationRequirementApplies ToPenalty
Privacy Act 1988 (Cth)Protect TFN, financial data, and personal information under the Australian Privacy Principles.All firms handling client tax and financial dataUp to $62.5 million for serious or repeated breaches (2026)
Tax File Number Guidelines (Privacy Act s.17)Secure collection, storage, use, disclosure and disposal of TFN information. OAIC enforcement.All entities handling TFN dataCriminal offence for TFN misuse. OAIC complaints, civil penalties.
TPB Code of Professional ConductMaintain confidentiality and competence in the IT systems used for tax agent services.Registered tax agents and BAS agentsTPB sanctions, suspension, termination of registration
Notifiable Data Breaches SchemeReport eligible breaches to the OAIC and affected individuals.All firms with personal dataInvestigation, enforceable undertakings, civil penalties
Client Money HandlingSegregated trust accounts, reconciliation, audit trail.Firms holding client fundsProfessional indemnity implications, TPB action

TPB Code of Professional Conduct

The Tax Practitioners Board Code of Professional Conduct (section 10) requires registered agents to maintain competence in the IT systems used for tax agent services. This includes understanding security controls, backup arrangements, data handling practices, and ensuring staff are adequately supervised.

From 1 July 2025, the TPB introduced new guidance on use of AI and third-party tools. You remain responsible for all work product even if outsourced or AI-assisted. Document your IT governance, review annually, and maintain evidence of compliance for TPB audits.

Practice management system security

The TPB Chair stated in July 2026 that AI has the potential to increase productivity, drive efficiencies and enhance client service across the tax profession when used appropriately, but the guidance reaffirms that competency is a human responsibility, so the practice management security controls below must extend to how AI tools are connected to MYOB, Xero and FYI docs via API and who has authority to approve those integrations. TPB Guidance Statement TPB(GS) 55/2026.

Common platforms in Australian accounting practices. Each requires specific security configurations beyond default settings.

MYOB AO and AO Next

On-prem or hosted. Requires secure remote access. Backup separately from the MYOB default. User access reviewed quarterly.

Xero Practice Manager

Cloud-based. Enforce MFA. Review third-party app connections. Export data regularly for independent backup.

Class Super

SMSF specialist. Cloud-based with Australian data centres. MFA required. Audit trail maintained.

BGL Simple Fund 360

Cloud-based SMSF platform. MFA enforced. API integrations reviewed quarterly.

FYI docs

Document management. Integrate with the practice platform. Apply retention policies. External sharing controlled.

FYI docs and document management

FYI docs is widely used in Australian accounting firms for document management and workflow. Integrate with your practice management platform. Apply retention policies aligned with tax record-keeping requirements (typically 5 years minimum). Control external sharing and audit document access quarterly.

Six common IT gaps in Australian accounting firms

Letting staff paste client financial data into free-tier AI tools is now a live TPB and Privacy Act exposure because TPB(GS) 55/2026 requires client permission before disclosing client information to an AI tool and the free tiers of consumer AI platforms can use prompts for training unless opted out, so the gap is no longer just shadow IT but an undocumented professional conduct breach. Wolters Kluwer, TPB message on AI.

These gaps appear repeatedly in accounting practice assessments. Each one carries Privacy Act, TPB, or ATO risk.

No MFA on practice management or email

Risk: Account takeover via phishing. Client tax data exposed. ATO notification may be required.

Fix: Enforce MFA on all platforms. Use app-based or FIDO2. SMS is acceptable as an interim but plan to upgrade.

Client files emailed unencrypted

Risk: Interception in transit. Privacy Act breach. TFN Guidelines violation.

Fix: Use a secure client portal or encrypted email for sensitive documents. Never email TFNs unencrypted.

Shared workpapers with no version control

Risk: Overwritten work. No audit trail. Quality control failures.

Fix: Use FYI docs or similar with version history. Lock finalised workpapers.

Staff access not removed on departure

Risk: Former staff access client files. Data theft. Conflict of interest.

Fix: Documented offboarding checklist. Remove access within 24 hours. Exit interview conducted.

Backup without testing

Risk: Backup corrupted or incomplete. Cannot restore after an incident.

Fix: Test restores quarterly. Document results. Include practice management data and email.

Personal devices accessing client data

Risk: Unsecured devices. No encryption. No remote wipe. Data exfiltration.

Fix: Intune App Protection Policies. Block access from non-compliant devices. Encrypted laptops only.

Essential Eight for accounting practices

Accounting firms should target Essential Eight Maturity Level 2 as a minimum because insurers and professional bodies increasingly expect it, and Maturity Level 2 requires patching within 48 hours for critical updates, application control to block consumer cloud sync, immutable 90 day backup and MFA on all accounts using the Microsoft Authenticator app or FIDO2 keys rather than SMS. ACSC Essential Eight maturity model.

The ACSC Essential Eight is the baseline for Australian cyber security. Accounting firms should target Maturity Level 2 as a minimum. Insurers and professional bodies increasingly expect this.

Application Control

Windows Defender Application Control (WDAC) or AppLocker. Block execution from user-writable paths. Allow-list: MYOB, Xero, Adobe Acrobat, Microsoft Office, Chrome or Edge, FYI docs. Prevents ransomware and unauthorised cloud sync (personal Dropbox, Google Drive). Block consumer cloud storage via DLP policies.

Patch Applications

Microsoft Intune Update Rings. Patch Adobe Acrobat, Chrome and Edge, Microsoft Office within 48 hours of critical updates. Automate with Intune. A pilot group tests patches before firm-wide deployment. Critical during tax time (January to April) so patch on weekends to avoid disruption.

Configure Microsoft Office Macros

Group Policy: block macros from internet enabled. Excel macros in workpapers must be signed with a trusted certificate. VBA projects password-protected. Macro execution logged via Microsoft 365 audit. Prevents macro-based ransomware commonly delivered via tax-time phishing.

User Application Hardening

Disable Flash (EOL 2020), Java browser plugins, unnecessary browser extensions. Edge and Chrome policies: block sideloading extensions, enforce Safe Browsing, disable password save. Reduce attack surface for browser-based exploits and credential theft.

Restrict Administrative Privileges

No daily-use accounts with local or admin rights. Separate Entra ID accounts for IT staff. Just-In-Time (JIT) access via PIM for elevated tasks. Local admin passwords managed via LAPS. Partners get standard user accounts, no exceptions.

Patch Operating Systems

Windows 10 and 11 Enterprise with Windows Update for Business. Feature updates deferred 90 days, quality updates deferred 7 days. Critical and security patches within 48 hours (ACSC ML2). Intune for deployment. Tax time exception: patch non-billable staff first, partners and managers second.

Multi-Factor Authentication

MFA on email (Exchange Online), practice management (MYOB or Xero SSO), ATO portals (TAP, BAS Agent Portal), SharePoint and OneDrive. Microsoft enforcing MFA for all admin sign-ins from Feb 2026. Use Microsoft Authenticator (number match) or FIDO2 keys (YubiKey), not SMS. Conditional Access: require MFA for all cloud apps, block legacy authentication (POP3, IMAP, SMTP).

Daily Backup

Veeam Backup and Replication or Altaro VM Backup. Immutable backup with 90-day retention (ACSC ML2). 3-2-1 rule: 3 copies, 2 different media, 1 offsite. Include MYOB and Xero data, FYI docs, email (all mailboxes), Excel workpapers. Store backups separate from the production network (different VLAN or Azure Blob with object lock). Test restores quarterly. RTO under 4 hours, RPO under 1 hour.

Tax time IT readiness checklist

Tax time from January to April is when accounting firms are most exposed because staff are working extended hours, phishing campaigns targeting ATO portal credentials peak, and patching windows shrink, so completing the readiness checklist below before 1 January is what keeps a firm from a notifiable breach landing in the middle of the busiest quarter. OAIC, data breach notifications increase to all-time high in 2025.

January to April is peak intensity. IT must support the load without failures. Complete this checklist before 1 January.

Test backup restores for all practice management platforms (November)
Review and update staff access permissions (December)
Verify MFA is enforced on all accounts (December)
Check disk space on all workstations and servers (December)
Test remote access capacity for extended hours (December)
Confirm ATO portal credentials are current and MFA-enabled (December)
Document after-hours support contacts for tax time staff (December)
Review cyber insurance policy and ensure controls are documented (January)
Schedule IT check-ins during tax time (weekly minimum)
Plan post-tax-time backup archive and cleanup (March)

Related: Business Email Compromise Guide, Finance IT Solutions, Data Loss Prevention.

Common questions

What IT compliance obligations apply to Australian accounting firms?
Australian accounting firms must meet the Privacy Act 1988 (up to $62.5 million penalty), the Tax File Number Guidelines under Privacy Act section 17 (criminal offence for misuse), the TPB Code of Professional Conduct (sanctions or registration termination), the Notifiable Data Breaches Scheme (OAIC and client notification), and client money handling rules for firms holding trust funds.
What is the TPB Code of Professional Conduct IT requirement?
The TPB Code of Professional Conduct section 10 requires registered tax agents and BAS agents to maintain competence in the IT systems used for tax agent services, including security controls, backup arrangements, and data handling, and from 1 July 2025 the TPB added guidance making agents responsible for all work product even when AI-assisted or outsourced.
How should an accounting firm secure Tax File Number data?
Secure TFN data under the Tax File Number Guidelines (Privacy Act section 17) by enforcing MFA on all systems that touch TFNs, using a secure client portal instead of email for TFN exchange, applying Microsoft Purview DLP to block unencrypted TFN emails, and maintaining an audit trail of all TFN access for OAIC enforcement.
What Essential Eight maturity level should an accounting firm target?
Accounting firms should target Essential Eight Maturity Level 2 as a minimum, because insurers and professional bodies increasingly expect it, and it requires MFA on all accounts, patching within 48 hours for critical updates, application control to block consumer cloud sync, and immutable 90-day backup of MYOB, Xero and FYI docs data.
How should an accounting firm prepare IT for tax time?
Prepare IT for tax time by testing backup restores in November, reviewing staff access and MFA enforcement in December, checking disk space and remote access capacity, confirming ATO portal credentials are current, documenting after-hours support contacts, and scheduling weekly IT check-ins from January to April.
Does Microsoft 365 back up accounting practice data?
No, Microsoft 365 does not back up email or practice data forever, so accounting firms need third-party immutable backup (Veeam or Altaro) with 90-day retention (ACSC ML2) covering MYOB, Xero, FYI docs, email and Excel workpapers, with quarterly restore tests and RTO under 4 hours and RPO under 1 hour.

Need help with accounting firm IT compliance

We audit accounting practices for Privacy Act compliance, TPB Code alignment, practice management security, and cyber insurance readiness. Deliverables include a prioritised remediation plan and evidence documentation for TPB and insurers.