What the checklist covers.
11 areasFor partners, practice managers, and operations leads at small-to-mid New Zealand accounting firms. It is the same control set we work through with our own accounting clients before AML audits, cyber insurance renewals, and Privacy Act incident reviews. Each area is grounded in a specific NZ obligation or a specific failure mode we see in practice.
- ✓ Privacy Act 2020 obligations for client data Mandatory breach notification, and how the thirteen Information Privacy Principles map to your Xero or MYOB permissions.
- ✓ AML/CFT supervision evidence (DIA) Demonstrating access control on your CDD repository, retaining SAR drafts, and locking down the compliance officer mailbox.
- ✓ Inland Revenue retention (seven years) A concrete retention matrix for workpapers, trust ledgers, and the supporting evidence behind every return position.
- ✓ MFA on Xero, MYOB, FYI, SuiteFiles, and Karbon The gotchas: shared logins that bypass MFA, contractor accounts left enabled, and SMS-based MFA on partner accounts.
- ✓ Email authentication: SPF, DKIM, DMARC The three records, alignment for your marketing platforms, and moving DMARC to enforcement without breaking legitimate mail.
- ✓ Backup of practice data, and the restore test What to back up, retention aligned to the seven-year obligation, and the restore cadence an auditor or insurer will ask about.
- ✓ Audit trails on practice management and the file server What to log, how long to keep it, and how to make the audit trail itself tamper-evident.
- ✓ Third-party tool review A starting inventory format, the questions to ask each vendor, and the cadence for re-reviewing the list.
- ✓ Staff onboarding and offboarding controls An offboarding sequence in dependency order: disable identity, revoke tokens, remove from tools, archive, transfer, retrieve the device.
- ✓ Incident response plan for client data exposure A one-page plan template with the OPC notification fields, the CERT NZ path, and triggers for each external party.
- ✓ Cyber insurance readiness The underwriter-question checklist NZ brokers now use, with notes on the evidence to keep so a claim is paid, not disputed.
Want the controls
implemented, not just listed?
We work with NZ accounting firms on the full stack: identity, backup, audit, and compliance evidence.
