-
Compliance and audit reviews
From mandates, best practice procedures or accreditations, to simply gaining peace of mind, our technical and industry experts have you covered.
-
External audit
Strengthen business and stakeholder confidence with professionally verified results and insights.
-
Financial reporting advisory
Deep expertise to help you navigate New Zealand’s constantly evolving regulatory environment.
-
Corporate tax
Identify tax issues, risks and opportunities in your organisation, and implement strategies to improve your bottom line.
-
Indirect tax
Stay on top of the indirect taxes that can impact your business at any given time.
-
Individual tax
Preparing today to help you invest in tomorrow.
-
Private business tax structuring
Find the best tax structure for your business.
-
Tax disputes
In a dispute with Inland Revenue or facing an audit? Don’t go it alone.
-
Research & development
R&D tax incentives are often underused and misunderstood – is your business maximising opportunities for making claims?
-
Management reporting
You’re doing well, but could you be doing even better? Discover the power of management reporting.
-
Financial reporting advisory
Deep expertise to help you navigate New Zealand’s constantly evolving regulatory environment.
-
Succession planning
When it comes to a business strategy that’s as important as succession planning, you can’t afford to leave things to chance.
-
Trust management
Fresh perspectives, practical solutions and flexible support for trusts and estate planning.
-
Forecasting and budgeting
Prepare for every likely situation with robust budgeting and forecasting models.
-
Outsourced accounting services
An extension of your team when you need us, so you can focus your time, energy and passion on your business.
-
Setting up in New Zealand
Looking to set up a business in New Zealand? You’ve come to the right place.
-
Policy reviews & development
Turn your risks into strengths with tailored policies that protect, guide and empower your business.
-
Performance improvement
Every business has untapped potential. Unlock yours.
-
Programme & project management
Successfully execute mission-critical changes to your organisation.
-
Strategy
Make a choice about your vision and purpose, where you will play and how you will win – now and into the future.
-
Risk
Manage risks with confidence to support your strategy.
-
Cloud services
Leverage the cloud to keep your data safe, operate more efficiently, reduce costs and create a better experience for your employees and clients.
-
Data analytics
Use your data to make better business decisions.
-
IT assurance
Are your IT systems reliable, safe and compliant?
-
Cyber resilience
As the benefits technology can deliver to your business increases, so too do the opportunities for cybercriminals.
-
Virtual asset advisory
Helping you navigate the world of virtual currencies and decentralised financial systems.
-
Virtual CSO
Security leadership and expertise when you need it.
-
Debt advisory
Raise, refinance, restructure or manage debt to achieve the optimal funding structure for your organisation.
-
Financial modelling
Understand the impact of your decisions before you make them.
-
Raising finance
Access the best source of funding for your business with a sound business strategy and rigorous planning.
-
Business valuations
Valuable decisions require valued insights.
-
Complex and international services
Navigate the complexities of multi-jurisdictional insolvencies.
-
Corporate insolvency
Achieve fair and orderly outcomes if your business – or part of it - is facing insolvency.
-
Independent business review
Is your business viable today? Will it be viable tomorrow? Give your business a health check to find out.
-
Litigation support
Straight forward advice from trusted advisors to support litigation and arbitration matters, expert determinations and other specialist hearings.
-
Business valuations
Valuable decisions require valued insights.
-
Forensic accounting & dispute advisory
Understand the true values, numbers and dollars at stake, as well as your obligations and rights to ensure value is preserved and complexities are managed.
-
Expert witness
Our expert witnesses analyse, interpret, summarise and present complex financial and business-related issues which are understandable and properly supported.
-
Investigation services
A fast and customised response when misconduct occurs in your business.

Since 2003, PCI DSS has been a required international security standard for anyone accepting card payments, and occasionally it’s updated to ensure it is maintaining data safety. The fourth generation PCI DSS modernises the standard, which previously didn’t consider new controls such as heuristic or biometric authentication options in lieu of traditional passwords. It will also protect customers and merchants from new vulnerabilities that weren’t a risk when the previous iteration was designed.
You must comply with the new PCI DSS
Not all merchants are aware that they must comply with the PCI DSS – but even if you’re a tiny business, the standard is covered in the merchant agreement you signed with your bank which allows you to accept credit card funds.
Complying with PCI DSS v4.0 varies depending on which tier your business falls into:
- If you’re transacting more than six million credit/debit card payments each year, you must use an external independent provider to ensure your business is compliant.
- If your business is transacting between one and six million card payments annually, you will require an internal trained assessor or an external independent provider to work with you to ensure you’re compliant.
- If you’re carrying out between 20,000 and one million transactions annually, your bank will call you and talk to you about complying with the new standard. Your business can choose to self-attest and check your own compliance, although it may be well worthwhile getting some advice to ensure you’re getting it right.
- If your business generates fewer than 20,000 credit/debit card transactions each year, you may not hear from your bank. You’ll need to think about how to be compliant and whether you need to make changes (refer to the starting points below).
Compliance is a commercial requirement, rather than a regulatory one, but your bank agreement does necessitate your compliance. The penalties for non-compliance can be high depending what tier you’re in; this can include immediate suspension of your payment facility and financial penalties for breaching your agreement. When you rely on your payments network to receive income, a suspension can quickly paralyse your cashflow and cause major problems for your organisation.
How to get started on PCI DSS compliance
The high-tier businesses will leave PCI DSS compliance to their internal cybersecurity teams, who will understand all the ins and outs of data security. But for smaller-tier businesses, particularly those in the sub-20,000 transaction category, it might come as a surprise to know that compliance is required before March next year. Here are some tips for getting started:
- Know your PCI DSS requirement and what you’re liable for. Depending on your business and how your customers process their cards, you may not need to make any changes.
- Talk to your bank and your payment processor (such as Windcave or Worldline/Paymark). Both have a strong interest in ensuring you are compliant and they will be able to guide you. They can tell you about what payment types you’re using, how secure they are, what other options might be available, and whether you need to make a change.
- Avoid storing cardholder data as much as possible. If your business does not need to store the cardholder data at all, that is preferable. If you do need to store it, find out whether you can eliminate this need by using a different type of payment, or make sure you have strong data storage policies in place.
- Consider talking to a qualified security assessor to help you understand the compliance requirements for your business. This is particularly important for larger businesses running ecommerce operations, and at a certain tier, it will be mandatory.
- For larger organisations, think about segmenting your network to reduce the parts that handle card information. This makes it much easier to assess your network.
Some payment types make compliance easy
When someone is buying online from your business, they can enter their credit card details in various ways – and some are riskier than others.
If the shopper enters their details directly into your site, your business is holding their card information to some extent, which increases the risk and makes your responsibilities for compliance with PCI DSS more onerous. This risk increases again if you are processing the card transaction, or holding a physical copy of the information such as a written form. Options to reduce this risk might include saving the card details as a token for an online transaction or switching to a different payment type.
A safer payment type is one where your customers enter their card details into a third-party payment portal, such as one provided by your bank or payment gateway. This means your business is not storing any card data, which means you are likely to already be complying with PCI DSS, and reducing your compliance burden in the future.
Make compliance and data security part of your business's BAU
To get a good understanding of your risks and obligations, you should start by speaking to your bank and payment gateway. You might then use a specialist advisor for more help, and get in the habit of auditing your cyber security regularly, even if your business is small. We’ve seen problems arise, even with major businesses, when a company only checks on PCI DSS compliance annually and suddenly realises there’s a big problem. Checking on compliance and data security should be a ‘business as usual’ part of any operation, as automatic as breathing.
Give yourself plenty of time to get your ducks in a row, so you’re all set up before the end of March 2024 – and your business remains compliant, and your customers’ data remains safe.