Accounting firms hold some of their clients’ most sensitive financial, tax and personal information. Yet access to that information rarely sits with employees alone. Contractors, external specialists and client users may all require access across different systems, often for different periods and purposes.
That makes identity governance more than an IT administration issue. It is a governance question: who has access, why do they have it, who approved it, and can the firm prove that access is still appropriate?
Where Joiner, Mover and Leaver Processes Break Down
Access risk can develop quietly. An employee changes roles but retains permissions from a previous client portfolio. A contractor finishes an engagement, but an account remains active in a secondary application. A business team adopts a platform that is not fully visible to central IT.
Each scenario creates the same governance problem: access can outlive its legitimate business purpose.
Least privilege therefore has to operate throughout the identity lifecycle, not only when an account is created. Access should be approved for a defined need, reviewed when responsibilities change and removed promptly when that need ends.
Employees Are Only Part of the Identity Estate
Accounting practices also need to govern third-party and client identities.
Seasonal tax contractors may need rapid access during peak periods, but temporary access should have an owner, a defined scope and an expiry point. Client portals require the same discipline. If a client contact changes roles or leaves an organisation, their access should not depend solely on someone remembering to notify the accounting firm.
MFA remains an important control, but authentication and authorisation solve different problems. MFA helps establish who is signing in. It does not determine whether that person should still be able to access a particular client file, billing platform or administrative function.
Privileged accounts require stronger controls again. Administrative access should be limited, monitored and separated from routine user activity. Australia’s Essential Eight guidance specifically addresses restricting administrative privileges and revalidating privileged access.
What Defensible Identity Governance Looks Like in ANZ
For firms handling personal information, identity governance also supports privacy compliance.
In Australia, the Australian Privacy Principle 11.1 requires APP entities that hold personal information to take reasonable steps to protect it from misuse, interference and loss, as well as unauthorised access, modification or disclosure.
In New Zealand, Information Privacy Principle 5 requires organisations to use security safeguards that are reasonable in the circumstances to protect personal information against loss, unauthorised access, use, modification or disclosure, and other misuse.
For Australian registered tax practitioners, the Tax Practitioners Board also emphasises sufficient IT controls to protect the security and confidentiality of client records.
These obligations are broader than identity management, but identity evidence helps demonstrate that access controls are operating in practice.
A policy saying “access is reviewed” is not the same as being able to show who approved access, when it was last reviewed, whether privileged permissions were justified, and when obsolete accounts were removed.
That evidence matters during a cyber security audit, scrutiny from ISO 27001 information security auditors, client due diligence or an internal governance review.
Move from Assumption to Evidence
A mature identity governance programme should be able to answer four questions quickly:
1. Who has access?
2. What can they access?
3. Why do they still need it?
4. Where is the evidence that the access was approved and reviewed?
Cybernetic Global Intelligence’s Identity Control Review examines how identity, privilege and system behaviour interact across the live environment. Combined where appropriate with a secure configuration review, this can identify orphaned accounts, excessive privileges, configuration drift and gaps between documented policy and technical enforcement.
The objective is not another layer of paperwork. It is a repeatable governance process that gives boards, partners and risk leaders evidence that access decisions are controlled, reviewable and aligned with business need.
For firms seeking a certified cyber security consultant in Australia, the value of an identity review should be measured by the clarity of the evidence and the practicality of the control improvements it produces.
Identity risk should not remain buried in helpdesk workflows. When a firm can demonstrate who has access, why they have it and how that access is governed, security becomes more defensible, and accountability becomes clearer.