-
Business valuations
We offer expert valuation advice in transactions, regulatory and administrative matters, and matters subject to dispute – valuing businesses, shares and intangible assets in a wide range of industries.
-
Capital markets
You need corporate finance specialists experienced in international capital markets on your side if you’re buying or selling financial securities.
-
Complex and international services
Our experience of multi-jurisdictional insolvencies coupled with our international reputation allows us to deliver the best possible outcome for all stakeholders.
-
Corporate insolvency
Our corporate investigation and recovery teams can help you manage insolvency situations and facilitate the best outcome.
-
Debt advisory
An optimal funding structure for your organisation presents unprecedented opportunities, but achieving this can be difficult without a trusted advisor.
-
Expert witness
Our expert witnesses analyse, interpret, summarise and present complex financial and business-related issues which are understandable and properly supported.
-
Financial models
A sound financial model will help you understand the impact of your decisions before you make them. Talk to us about our user-friendly models.
-
Forensic and investigation services
We provide investigative accounting and litigation support services for commercial, matrimonial, criminal, business valuation and insurance disputes.
-
Independent business review
Is your business viable? Will it remain viable in the future? A thorough independent business review can help your organisation answer these fundamental questions.
-
IT forensics
Effective ESI analysis is integral to the success of your business. Our IT forensics experts have the technical expertise to identify, preserve and interrogate electronic data.
-
Mergers and acquisitions
Grant Thornton provides strategic and execution support for mergers, acquisitions, sales and fundraising.
-
Raising finance
Raising finance - funders value partners who can deliver a robust financial model, a sound business strategy and rigorous planning. We can guide you through the challenges that these transactions can pose and help you build a foundation for long term success once the deal is done.
-
Relationship property services
Grant Thornton offers high quality independent advice on the many financial issues associated with relationship property from considering an individual financial issue to all aspects of a complex settlement.
-
Restructuring and turnaround
Grant Thornton’s restructuring and turnaround service capabilities include cash flow, liquidity management and forecasting; crisis and interim management; financial advisory services to companies and parties in transition and distress
-
Transaction advisory
Our depth of market knowledge will steer you through the transaction process. Grant Thornton’s dynamic teams offer range of financial, commercial and operational expertise.
-
Virtual asset advisory
Helping you navigate the world of virtual currencies and decentralised financial systems.
-
Corporate tax
Grant Thornton can identify tax issues, risks and opportunities in your organisation and implement strategies to improve your bottom line.
-
Employment tax
Grant Thornton’s advisers can help you with PAYE (payroll tax), Kiwisaver, fringe benefits tax (FBT), student loans, global mobility services, international tax
-
Global mobility services
Our team can help expatriates and their employers deal with tax and employment matters both in New Zealand and overseas. With the correct planning advice, employee allowances and benefits may be structured to avoid double taxation and achieve tax savings.
-
GST
GST has the potential to become a minefield and can be expensive when it goes wrong. Our technical knowledge can help you minimise the negative impact of GST
-
International tax
International tax rules are undergoing their biggest change in a generation. Tax authorities around the world are increasingly vigilant, especially when it comes to global operations.
-
Research and Development
R&D tax incentives are often underused and misunderstood – is your business maximising opportunities for making claims?
-
Tax compliance
Our advisers help clients manage the critical issue of compliance across accountancy regulations, corporation law and tax. We also offer business and wealth advisory services, which means we can provide a seamless and tax-effective offering to our clients.
-
Tax governance
Mitigate tax risks and implement best practice governance that will stand up to IRD scrutiny and audits.
-
Transfer pricing
Tax authorities are demanding transparency in international arrangements. We businesses comply with regulations and use transfer pricing as a strategic planning tool.
-
Audit methodology
Our five step audit methodology offers a high quality service wherever you are in the world and includes planning, risk assessment, testing internal controls, substantive testing, and concluding and reporting
-
Audit technology
We apply our audit methodology with an integrated set of software tools known as the Voyager suite. Our technology has been developed to produce quality audits that are effective and efficient.
-
Financial reporting advisory
Our financial reporting advisers have the expertise to help you deal with the constantly evolving regulatory environment.
-
Business architecture
Our business architects help businesses with disruptive conditions, business expansion and competitive challenges; the deployment of your strategy is critical to success.
-
Cloud services
Leverage the cloud to keep your data safe, operate more efficiently, reduce costs and create a better experience for your employees and clients.
-
Internal audit
Our internal audits deliver independent assurance over key controls within your riskiest processes, proving what works and what doesn’t and recommending improvements.
-
IT advisory
Our hands on product experience, extensive functional knowledge and industry insights help clients solve complex IT and technology issues
-
IT privacy and security
IT privacy and security should support your business strategy. Our pragmatic approach focuses on reducing cyber security risks specific to your organisation
-
Payroll assurance
Our specialist payroll assurance team can conduct a review of your payroll system configuration and processes, and then help you and your team to implement any necessary recalculations.
-
PCI DSS
Our information security specialists are approved Qualified Security Assessors (QSAs) that have been qualified by the PCI Security Standards Council to independently assess merchants and service providers.
-
Process improvement
As your organisation grows in size and complexity, processes that were once enabling often become cumbersome and inefficient. To maintain growth, your business must remain flexible, agile and profitable
-
Procurement/supply chain
Procurement and supply chain inputs will often dominate your balance sheet and constantly evolve for organisations to remain competitive and meet changing customer requirements
-
Project assurance
Major programmes and projects expose you to significant financial and reputational risk throughout their life cycle. Don’t let these risks become a reality.
-
Risk management
We understand that growing companies need to establish robust internal controls, and use information technology to effectively mitigate risk.
-
Robotic process automation (RPA)
RPA is emerging as the most sophisticated form of automation used to help businesses become more agile and remain competitive in the face of today’s ongoing digital disruption.
Many business owners are unaware of these obligations which can not only expose them to hacking attempts, but a big shock when their bank discovers they're non-compliant, as this usually results in the suspension of payment facilities. Non-compliance can also cause reputational damage for a brand, and fines ranging from $10,000 to $100,000 (or more) per month until compliance is achieved.
Getting started: The road to PCI DSS compliance
PCI DSS standards comprise several areas of compliance from network security and physical security to hiring and training practices. The specific level of compliance required for your business is based on your transaction volumes, or your company’s level of risk which is determined by your bank.
These high-level requirements are supported by a number of sub-requirements which may make seem overwhelming or even impossible for an organisation looking at it for the first time. But in reality, it’s not too daunting and well worth the effort which will make the organisation better off in terms of preventing data breaches, large fines and the inability to accept card payments.
Here’s six steps to help you get started.
- Scope your cardholder data environment
The most critical first step is to separate your cardholder data (CHD) environment from the rest of your network. This is known as segmentation and helps you clearly differentiate between the environments which are in-scope and out-of-scope for PCI DSS compliance. This will help deliver a more focused PCI DSS audit specifically targeting the key in-scope areas that involve the flow of cardholder data. - Cardholder data flow awareness
This involves raising awareness among key security personnel about the flow of cardholder data within the organisation in relation to the PCI DSS scope you established in step one. Implementing necessary controls to protect this data is also a vital part of the process and can include installing a Web Application Firewall in your network to prevent unauthorised access to the data flow. - Identify who needs access to resources and the devices they use
You also need to ensure user access to this data is solely based on your team members' job functions, and perform periodic user access reviews for all employees – this includes an overall assessment of user roles, access rights and privileged rights. You should also pay special attention to past employees and check if there have been any role changes which could potentially impact access rights. This helps with issues such as unauthorised access and lack of accountability.
And when it comes to monitoring the devices used to access your network (such as servers and firewalls among other network devices), it's easy for a lot of organisations to overlook maintaining asset registers. But, as the number of devices used throughout your business increases, it becomes more challenging to keep track of assets, and the chances of these being misplaced or stolen increases. So it's important to establish and maintain a centralised asset register. - Establish if the cardholder data you store is necessary ... and legal
PCI DSS requires the account number on customers' payment cards – also known as the Primary Account Number (PAN) - to be unreadable when stored. The PAN, cardholder's name and expiration date can only be stored if there is a valid and regulatory needed. All the data you store must be encrypted, and other sensitive data such as PIN or CVV numbers must never be stored – even if they're encrypted.
Merchants who do not save any cardholder data are significantly less prone to suffering from data breaches that can be expensive, time-consuming, and detrimental to their reputation. Put simply, if you don't need to store the data, then don't. - Develop policies, standards and procedures
To achieve successful ongoing PCI DSS compliance, you need to have the three key documents in place:
Policies to help your organisation navigate cybersecurity decision making and to ensure consistency and alignment with PCI DSS compliance requirements.
Standards which outline the necessary measures to maintain effective policies. Good management practices are supported by clear guidelines that serve as a reference for evaluating your company's compliance with the standards.
A set of management and personnel procedures to effectively enforce PCI DSS requirements. Each procedure should outline the necessary steps to carry out a specific task; for example, a documented procedure will help guide your team members through a security breach.
- Security awareness
Establishing a robust security awareness programme for your team members is also a must for organisations to meet PCI DSS regulations and protect against security threats. This could include implementing annual security training, fake phishing campaigns to ensure employees are vigilant and can spot scams, and setting up lunch and learn sessions to get your employees involved and understand the repercussions of disregarding security best practices. And it is equally important to ensure that employees are aware of the consequences of not adhering to security best practices.
Controls for compliance must be part of your BAU processes
PCI DSS is simply another security standard designed to protect businesses and their customers. If your organisation wants to improve its security, then compliance to the standard will come almost naturally if you incorporate best practice into your BAU processes. One of the common mistakes businesses make is treating PCI DSS standards – or any IT security compliance measures - as a project with a completion date that is no longer given any attention once the initial work has been completed. We often see this as the main cause of failed results during organisations’ second year audits.
The best approach to successful compliance is treating it as a programme, where the processes and controls that have been developed are embedded into your BAU processes. This ensures that security is consistently maintained to keep your organisation safe.