Back to Blog
    Compliance

    IT Compliance Checklist for Australian Professional Services Firms

    9 August 2026
    6 min read

    Compliance Is Not Optional in Professional Services

    Professional services firms handle sensitive client information as a core function of their work. Tax records, financial statements, legal files, and personal financial data are all subject to the Privacy Act 1988, Australian Privacy Principles, and in many cases additional obligations from professional regulatory bodies (CPA Australia, the Law Society, ASIC, AFCA).

    Getting IT right in a professional services context is not just about efficiency — it is about meeting professional and legal obligations.

    Identity and Access

    • [ ] Individual user accounts for all staff — no shared logins to any system
    • [ ] MFA enabled on all Microsoft 365 or Google Workspace accounts
    • [ ] MFA enabled on practice management and client management software (CCH, Xero Practice Manager, LEAP, Smokeball, etc.)
    • [ ] Admin accounts separate from daily-use accounts
    • [ ] Access permissions reviewed: staff can only access client files relevant to their role
    • [ ] Offboarding process: accounts disabled on last day of employment
    • [ ] Annual access review: confirm current staff and current permissions are aligned

    Data Security

    • [ ] Client files stored in access-controlled systems — not in individual email inboxes or personal drives
    • [ ] Drive encryption on all devices containing client data (BitLocker, FileVault)
    • [ ] Mobile Device Management (MDM) on all devices used to access client data
    • [ ] Policy on personal device use for client work — BYOD must be enrolled in MDM or prohibited

    Email and Communication Security

    • [ ] SPF, DKIM, and DMARC configured on your email domain — DMARC at p=reject
    • [ ] Email filtering active
    • [ ] Client-facing communication sent from business domain — not personal email accounts
    • [ ] Secure file transfer in place for sharing sensitive documents (client portal or encrypted file share)
    • [ ] Staff trained on payment redirection fraud — specific to professional services

    Backup and Records

    • [ ] Daily automated backup of all client files
    • [ ] Backup tested — restore verified in last 90 days
    • [ ] Records retention policy documented and aligned with ATO requirements (7 years for tax practitioners), Law Society requirements, or ASIC requirements as applicable
    • [ ] Records destruction process documented — secure disposal when retention period expires

    Privacy Act Compliance

    • [ ] Privacy policy current and accessible to clients
    • [ ] Client consent obtained for all data collection and processing purposes
    • [ ] Notifiable Data Breach response procedure documented
    • [ ] Breach register maintained
    • [ ] Staff trained on Privacy Act obligations annually

    Professional Body Requirements

    • [ ]
      Tax practitionersTax Practitioners Board professional indemnity insurance current; client record access controls documented
    • [ ]
      SolicitorsQueensland Law Society requirements for file security and confidentiality met; legal professional privilege protection addressed in IT security design
    • [ ]
      Financial advisersASIC record-keeping requirements (7 years for advice records) met; AFCA complaint and record management process documented

    Incident Response

    • [ ] IT incident response plan documented — who to call, what to do, how to notify clients and regulators
    • [ ] Cyber insurance reviewed — does it cover BEC, ransomware, and data breach notification costs?

    Compliance Is Not the Same as Security

    A critical distinction for professional services firms: meeting compliance requirements and having adequate security are related but not identical.

    Compliance is about satisfying a defined standard — the Law Society's practice management requirements, APES 305 for accountants, TASA obligations for tax agents. A firm can be technically compliant while still having security gaps that create real risk. Conversely, a firm with strong security practices might not have the specific documentation or processes required for a compliance audit.

    The right approach: use compliance requirements as the floor, not the ceiling. Meet the compliance obligations because they are legally required. Then build security beyond compliance requirements because the regulatory minimums do not represent adequate protection against current threats.

    For professional services firms in Brisbane and Gold Coast, the practical checklist covers both dimensions.

    Law Society of Queensland IT Compliance Checklist

    For Queensland solicitors:

    Practice management:

    • [ ] Trust accounting software is compliant with Law Society requirements and current version
    • [ ] Trust account records are retained for seven years
    • [ ] Client files are accessible and can be produced on demand
    • [ ] Client file access is restricted to authorised staff
    • [ ] Conflict of interest checks are documented and maintained
    Confidentiality and data security:
    • [ ] Client documents are stored in a system with appropriate access controls
    • [ ] Identification documents are stored securely and destroyed when no longer needed
    • [ ] Emails containing client-sensitive information are protected appropriately
    • [ ] Remote access to client files is secured (VPN or Zero Trust, MFA)
    Professional Indemnity requirements:
    • [ ] Current PI insurance coverage that meets LSQ requirements
    • [ ] IT security controls meet insurer's requirements (check PI renewal questionnaire)
    • [ ] Incident reporting process documented for potential breach scenarios

    Queensland Accounting Firm IT Compliance Checklist

    For CPA and CA firms in Queensland:

    TASA and Tax Practitioners Board:

    • [ ] Client tax records retained for five years minimum (seven years recommended)
    • [ ] ATO digital identity credentials (myGovID) managed and secured with appropriate access controls
    • [ ] Tax agent number and practice credentials are company-controlled, not individual-controlled
    • [ ] Client tax records are accessible and can be produced on demand
    APES 305 (Terms of Engagement):
    • [ ] Client engagement letters are stored and accessible
    • [ ] Electronic engagement letter processes comply with e-signature requirements
    • [ ] Files are retained for the required period post-engagement
    CPA Australia / CA ANZ practice quality review:
    • [ ] File management processes are documented
    • [ ] Practice management software (HandiSoft, CCH, MYOB Practice) is on a current, supported version
    • [ ] Backup of practice management data is in place and tested
    Financial planning (AFSL holders):
    • [ ] SOA and ROA records retained for seven years
    • [ ] Client data stored in AFSL-appropriate systems with adequate access controls
    • [ ] Breach reporting processes in place for Privacy Act obligations

    The Privacy Act Compliance Layer

    Both legal and accounting firms are subject to the Privacy Act, and the Privacy Act applies to the IT systems used to store and manage client information.

    Practical Privacy Act IT requirements:

    • [ ] Privacy policy is current, accessible to clients, and reflects actual data handling practices
    • [ ] Collection notices are given at point of collection (new client intake forms)
    • [ ] Data subject access request process is documented (if a client asks what data you hold about them, can you answer?)
    • [ ] Data breach response plan is documented (who decides if a breach is notifiable, how do you notify?)
    • [ ] Data retention and destruction schedule exists and is followed
    Third-party processor assessment:
    • [ ] Cloud storage providers (Microsoft, Google, Dropbox) — are they processing Australian data in accordance with Australian Privacy Principles?
    • [ ] Practice management software — what data does the vendor access? What is their data handling policy?
    • [ ] Email marketing tools — if client contact details are in a marketing platform, is that disclosed in the privacy policy?
    Netluma IT conducts IT compliance reviews for professional services firms in Brisbane and Gold Coast. Call 1300 521 162 to arrange a review of your current IT compliance posture.

    Netluma IT works with professional services firms across Brisbane and SE Queensland. Call 1300 521 162 for a compliance-focused IT review.

    Struggling With IT Compliance?

    We help Australian businesses meet Privacy Act, industry, and insurance compliance requirements — without the stress.

    Related Services

    96% first-hour resolution
    Local Gold Coast team