-
Compliance and audit reviews
From mandates, best practice procedures or accreditations, to simply gaining peace of mind, our technical and industry experts have you covered.
-
External audit
Strengthen business and stakeholder confidence with professionally verified results and insights.
-
Financial reporting advisory
Deep expertise to help you navigate New Zealand’s constantly evolving regulatory environment.
-
Corporate tax
Identify tax issues, risks and opportunities in your organisation, and implement strategies to improve your bottom line.
-
Indirect tax
Stay on top of the indirect taxes that can impact your business at any given time.
-
Individual tax
Preparing today to help you invest in tomorrow.
-
Private business tax structuring
Find the best tax structure for your business.
-
Tax disputes
In a dispute with Inland Revenue or facing an audit? Don’t go it alone.
-
Research & development
R&D tax incentives are often underused and misunderstood – is your business maximising opportunities for making claims?
-
Management reporting
You’re doing well, but could you be doing even better? Discover the power of management reporting.
-
Financial reporting advisory
Deep expertise to help you navigate New Zealand’s constantly evolving regulatory environment.
-
Succession planning
When it comes to a business strategy that’s as important as succession planning, you can’t afford to leave things to chance.
-
Trust management
Fresh perspectives, practical solutions and flexible support for trusts and estate planning.
-
Forecasting and budgeting
Prepare for every likely situation with robust budgeting and forecasting models.
-
Outsourced accounting services
An extension of your team when you need us, so you can focus your time, energy and passion on your business.
-
Setting up in New Zealand
Looking to set up a business in New Zealand? You’ve come to the right place.
-
Policy reviews & development
Turn your risks into strengths with tailored policies that protect, guide and empower your business.
-
Performance improvement
Every business has untapped potential. Unlock yours.
-
Programme & project management
Successfully execute mission-critical changes to your organisation.
-
Strategy
Make a choice about your vision and purpose, where you will play and how you will win – now and into the future.
-
Risk
Manage risks with confidence to support your strategy.
-
Cloud services
Leverage the cloud to keep your data safe, operate more efficiently, reduce costs and create a better experience for your employees and clients.
-
Data analytics
Use your data to make better business decisions.
-
IT assurance
Are your IT systems reliable, safe and compliant?
-
Cyber resilience
As the benefits technology can deliver to your business increases, so too do the opportunities for cybercriminals.
-
Virtual asset advisory
Helping you navigate the world of virtual currencies and decentralised financial systems.
-
Virtual CSO
Security leadership and expertise when you need it.
-
Debt advisory
Raise, refinance, restructure or manage debt to achieve the optimal funding structure for your organisation.
-
Financial modelling
Understand the impact of your decisions before you make them.
-
Raising finance
Access the best source of funding for your business with a sound business strategy and rigorous planning.
-
Business valuations
Valuable decisions require valued insights.
-
Complex and international services
Navigate the complexities of multi-jurisdictional insolvencies.
-
Corporate insolvency
Achieve fair and orderly outcomes if your business – or part of it - is facing insolvency.
-
Independent business review
Is your business viable today? Will it be viable tomorrow? Give your business a health check to find out.
-
Litigation support
Straight forward advice from trusted advisors to support litigation and arbitration matters, expert determinations and other specialist hearings.
-
Business valuations
Valuable decisions require valued insights.
-
Forensic accounting & dispute advisory
Understand the true values, numbers and dollars at stake, as well as your obligations and rights to ensure value is preserved and complexities are managed.
-
Expert witness
Our expert witnesses analyse, interpret, summarise and present complex financial and business-related issues which are understandable and properly supported.
-
Investigation services
A fast and customised response when misconduct occurs in your business.

Many business owners are unaware of these obligations which can not only expose them to hacking attempts, but a big shock when their bank discovers they're non-compliant, as this usually results in the suspension of payment facilities. Non-compliance can also cause reputational damage for a brand, and fines ranging from $10,000 to $100,000 (or more) per month until compliance is achieved.
Getting started: The road to PCI DSS compliance
PCI DSS standards comprise several areas of compliance from network security and physical security to hiring and training practices. The specific level of compliance required for your business is based on your transaction volumes, or your company’s level of risk which is determined by your bank.
These high-level requirements are supported by a number of sub-requirements which may make seem overwhelming or even impossible for an organisation looking at it for the first time. But in reality, it’s not too daunting and well worth the effort which will make the organisation better off in terms of preventing data breaches, large fines and the inability to accept card payments.
Here’s six steps to help you get started.
- Scope your cardholder data environment
The most critical first step is to separate your cardholder data (CHD) environment from the rest of your network. This is known as segmentation and helps you clearly differentiate between the environments which are in-scope and out-of-scope for PCI DSS compliance. This will help deliver a more focused PCI DSS audit specifically targeting the key in-scope areas that involve the flow of cardholder data. - Cardholder data flow awareness
This involves raising awareness among key security personnel about the flow of cardholder data within the organisation in relation to the PCI DSS scope you established in step one. Implementing necessary controls to protect this data is also a vital part of the process and can include installing a Web Application Firewall in your network to prevent unauthorised access to the data flow. - Identify who needs access to resources and the devices they use
You also need to ensure user access to this data is solely based on your team members' job functions, and perform periodic user access reviews for all employees – this includes an overall assessment of user roles, access rights and privileged rights. You should also pay special attention to past employees and check if there have been any role changes which could potentially impact access rights. This helps with issues such as unauthorised access and lack of accountability.
And when it comes to monitoring the devices used to access your network (such as servers and firewalls among other network devices), it's easy for a lot of organisations to overlook maintaining asset registers. But, as the number of devices used throughout your business increases, it becomes more challenging to keep track of assets, and the chances of these being misplaced or stolen increases. So it's important to establish and maintain a centralised asset register. - Establish if the cardholder data you store is necessary ... and legal
PCI DSS requires the account number on customers' payment cards – also known as the Primary Account Number (PAN) - to be unreadable when stored. The PAN, cardholder's name and expiration date can only be stored if there is a valid and regulatory needed. All the data you store must be encrypted, and other sensitive data such as PIN or CVV numbers must never be stored – even if they're encrypted.
Merchants who do not save any cardholder data are significantly less prone to suffering from data breaches that can be expensive, time-consuming, and detrimental to their reputation. Put simply, if you don't need to store the data, then don't. - Develop policies, standards and procedures
To achieve successful ongoing PCI DSS compliance, you need to have the three key documents in place:
Policies to help your organisation navigate cybersecurity decision making and to ensure consistency and alignment with PCI DSS compliance requirements.
Standards which outline the necessary measures to maintain effective policies. Good management practices are supported by clear guidelines that serve as a reference for evaluating your company's compliance with the standards.
A set of management and personnel procedures to effectively enforce PCI DSS requirements. Each procedure should outline the necessary steps to carry out a specific task; for example, a documented procedure will help guide your team members through a security breach.
- Security awareness
Establishing a robust security awareness programme for your team members is also a must for organisations to meet PCI DSS regulations and protect against security threats. This could include implementing annual security training, fake phishing campaigns to ensure employees are vigilant and can spot scams, and setting up lunch and learn sessions to get your employees involved and understand the repercussions of disregarding security best practices. And it is equally important to ensure that employees are aware of the consequences of not adhering to security best practices.
Controls for compliance must be part of your BAU processes
PCI DSS is simply another security standard designed to protect businesses and their customers. If your organisation wants to improve its security, then compliance to the standard will come almost naturally if you incorporate best practice into your BAU processes. One of the common mistakes businesses make is treating PCI DSS standards – or any IT security compliance measures - as a project with a completion date that is no longer given any attention once the initial work has been completed. We often see this as the main cause of failed results during organisations’ second year audits.
The best approach to successful compliance is treating it as a programme, where the processes and controls that have been developed are embedded into your BAU processes. This ensures that security is consistently maintained to keep your organisation safe.