Skip to content

Local engineers in Perth, WA. Zero offshoring.

Menu

For accounting & bookkeeping firms

IT built for AML/CTF, tax season and every client’s TFN.

Since 1 July 2026, accounting firms that provide designated services are regulated by AUSTRAC under anti-money laundering and counter-terrorism financing (AML/CTF) law. The Privacy Act covers that client data. We secure the systems, protect the records and keep the evidence ready, from Perth.

  • Secure storage and seven-year retention for client ID and know-your-customer (KYC) records
  • Multi-factor authentication (MFA) and access controls for practice software and ATO online services
  • Peak-period uptime for tax, ledger and practice management software
  • 40+ Google reviews
  • Perth clients since 2000
  • Zero offshoring

Free AML-readiness IT review

45 minutes with a Perth engineer. We check how your firm stores, protects and retains client identity records, and tell you plainly where the gaps are.

Firm type
Staff

A Perth-based engineer replies within one business day. Your details are never shared.

Your clients’ data just became regulated data.

AML/CTF Tranche 2 brought accountants into AUSTRAC regulation from 1 July 2026, with customer due diligence and seven-year record keeping. Firms previously exempt from the Privacy Act are now covered for that data.

  • KYC records you must now protect

    Passport scans, company extracts and beneficial-owner details, held for seven years. They are a high-value target, and a breach is reportable.

  • Tax-season attacks

    ATO-impersonation and phishing campaigns peak when your team is busiest. One click can lock files a week before lodgement.

  • Payment redirection

    Fake invoices and changed bank details arrive from a compromised mailbox, yours or a client’s. We set up the controls that catch them.

2026–27 outlook

What’s changing for accounting firms.

The dates that affect your IT and data obligations. We track them so you don’t have to.

  1. 1 Jul 2026

    AML/CTF obligations began for firms that provide designated services, and the Privacy Act now covers that data.

  2. 29 Jul 2026

    AUSTRAC enrolment deadline for firms already providing designated services.

  3. 10 Dec 2026

    Privacy policies must explain any automated decisions made using personal information, including decisions made with AI tools.

  4. 2026–27

    The second tranche of Privacy Act reform is in consultation. It proposes a “fair and reasonable” test for all data handling.

  1. Is MFA enforced on email, practice software and ATO online services?

    The ATO already requires MFA for its online services. Attackers target everything else.

  2. Are client ID documents kept in one secured location, not in inboxes and on desktops?

    Scattered KYC documents are the hardest to protect and the easiest to leak.

  3. Could you retrieve a client’s KYC records from five years ago?

    AML/CTF requires records to be kept for seven years.

  4. Do staff verify bank-detail changes by phone before acting?

    Payment redirection scams target firms that move client money and pay suppliers.

  5. Are Microsoft 365 and practice data backed up, with a tested restore?

    Microsoft does not back up your data for you by default.

  6. Is there a written incident response plan, including Notifiable Data Breaches (NDB) reporting?

    Work it out before a breach, not after.

What’s included

Everything accounting firms need, from one Perth team.

  • Helpdesk & device management

    Unlimited support for partners and staff. Laptops encrypted, patched and wipeable if lost.

  • Identity & access

    MFA across Microsoft 365, practice software and ATO portals. Access removed the day someone leaves.

  • Secure client documents

    Client portals and encrypted email, so ID documents and financials stay out of inboxes.

  • Records retention & backup

    Seven-year retention for KYC records, plus restore-tested backups of Microsoft 365 and practice data.

  • Email security

    Filtering, impersonation protection and SPF, DKIM and DMARC records, so nobody can send email that passes as yours.

  • Policies & evidence pack

    IT controls for your AML/CTF program, an incident response plan and privacy policy support.

Client words

Trusted by Perth organisations since 2000.

Local engineers, long relationships and a lot of referrals. That only happens when the work holds up.

“We have found CCP to be a very pro-active company… very knowledgeable and able to identify issues quickly and resolve them with great efficiency.”

Wendy Vaughan · Long-term client

“I have used them for many years and have referred them to many of our clients. They are professional, super knowledgeable and proactively make sure that the IT side of my business always works.”

Rueben Taylor · Google review
Does AML/CTF change our IT obligations?
Do you support our tax and practice software?
Who has access to our systems?
We’re a small firm. Is managed IT worth it?

Get your client data AUSTRAC-ready.

A free AML-readiness IT review with a Perth engineer. You keep the findings either way.