---
title: "Applying for accreditation"
source: "https://www.digitalidsystem.gov.au/sites/default/files/2025-02/ACCC%20Digital%20ID%20Guidance%20-%20Applying%20for%20Accreditation%20v1.1.pdf"
collection: "digital-id-accreditation"
guidance_commit: "db3111cd9d11643ac08b34b4d75b0d0d983ca388"
---

Applying for
accreditation
Guidance for organisations seeking to become
accredited in Australia’s Digital ID System


Version 1.3
May 2026
      Acknowledgment of country

      The ACCC acknowledges the traditional owners and custodians of Country throughout
      Australia and recognises their continuing connection to the land, sea and community. We pay
      our respects to them and their cultures; and to their Elders past, present and future.


     Date                              Version               Description of the changes

     November 2024                     Version 1             Initial version

     February 2025                     Version 1.1           Minor typographical changes

     September 2025                    Version 1.2           Updates to Chapters 2, 7, 9, 10, 12, 13 and minor administrative
                                                             changes

     May 2026                          Version 1.3           Updates to Chapters 7, 9 and Appendix A to reflect November 2025
                                                             Rule changes and information on applying for a restricted attributes
                                                             condition

Any updates to this guidance will be recorded in the table above. Readers should check the Digital ID System website to ensure
they have the latest version.


Australian Competition and Consumer Commission
Land of the Ngunnawal people
23 Marcus Clarke Street, Canberra, Australian Capital Territory, 2601
© Commonwealth of Australia 2024
This work is copyright. In addition to any use permitted under the Copyright Act 1968, all material contained within this work is provided under a
Creative Commons Attribution 4.0 Australia licence, with the exception of:
     the Commonwealth Coat of Arms
     the ACCC and AER logos
     any illustration, diagram, photograph or graphic over which the Australian Competition and Consumer Commission does not hold copyright, but
      which may be part of or contained within this publication.
The details of the relevant licence conditions are available on the Creative Commons website, as is the full legal code for the CC BY 4.0 AU licence.
Requests and inquiries concerning reproduction and rights should be addressed to the General Manager, Strategic Communications, ACCC,
GPO Box 3131, Canberra ACT 2601.
Important notice
The information in this publication is for general guidance only. It does not constitute legal or other professional advice, and should not be relied
on as a statement of the law in any jurisdiction. Because it is intended only as a general guide, it may contain generalisations. You should obtain
professional advice if you have any specific concern.
The ACCC has made every reasonable effort to provide current and accurate information, but it does not make any guarantees regarding the
accuracy, currency or completeness of that information.
Parties who wish to re-publish or otherwise use the information in this publication must check this information for currency and accuracy prior to
publication. This should be done prior to each publication edition, as ACCC guidance and relevant transitional legislation frequently change. Any
queries parties have should be addressed to the General Manager, Strategic Communications, ACCC, GPO Box 3131, Canberra ACT 2601.
ACCC 05/26_24–79
www.accc.gov.au


ii                                                                                        ACCC     |   Applying for accreditation        |   Version 1.3
Contents
1.    Introduction                                                                                                1
      1.1    Australia’s Digital ID System                                                                        1
      1.2    This guidance                                                                                        1

2.    Regulation of Digital ID                                                                                    2
      2.1    Legal Framework                                                                                      2
      2.2    Agency roles                                                                                         3
      2.3    About the ACCC                                                                                       4

3.    Communicating with the Regulator                                                                            5

4.    Accreditation under the Digital ID System                                                                   6

5.    Application steps                                                                                           7
      5.1    Registration                                                                                         7
      5.2    Accreditation application form                                                                       7
      5.3    Completing an application                                                                            8

6.    Regulator’s assessment                                                                                      9
      6.1    Completeness check                                                                                   9
      6.2    Assessment                                                                                           9
      6.3    Decision                                                                                             9

7.    Conditions on accreditation                                                                               10
      7.1    Accreditation is subject to conditions                                                             10
      7.2    Conditions requested by an applicant                                                                11
      7.3    Categories of conditions                                                                            11

8.    Appropriateness to accredit                                                                               14
      8.1    Fit and proper person test or alternative evidence                                                  14
      8.2    Evidence in line with the fit and proper person test                                                15
      8.3    Alternative evidence of appropriateness                                                            18
      8.4    Ongoing reporting requirements                                                                      19


iii                                                       ACCC      |   Applying for accreditation   |   Version 1.3
9.     Accreditation criteria and evidence requirements                                                      20
       9.1     DI data environment                                                                           20
       9.2     Statement of scope and applicability                                                          21
       9.3     Privacy impact assessment                                                                     22
       9.4     Technical testing                                                                             22
       9.5     Protective Security Framework                                                                 24
       9.6     Biometrics                                                                                    24

10.    Assurance assessments and systems testing                                                             26
       10.1    Reports for assurance assessments and systems testing                                         26
       10.2    Assessor requirements                                                                         27
       10.3    Assurance assessments                                                                         28
       10.4    Systems testing                                                                               29

11.    Review of Regulator decisions                                                                         30
       11.1    Internal review                                                                               30
       11.2    Review by the Administrative Review Tribunal                                                  31
       11.3    Judicial review                                                                               31

12.    Following accreditation                                                                               32
       12.1    Digital ID Accredited Entities Register                                                       32
       12.2    Digital ID Accreditation Trustmark                                                            32
       12.3    Changes to accreditation                                                                      33

13.    Compliance obligations                                                                                34
       13.1    Record keeping obligations                                                                    35
       13.2    Reportable incident obligations                                                               35
       13.3    Annual review and reporting                                                                   36

Appendix A – Assessor qualifications                                                                         37

Appendix B – Evidence listed in the accreditation application form                                           39


iv                                                        ACCC   |   Applying for accreditation   |   Version 1.3
1. Introduction

1.1        Australia’s Digital ID System
Australia’s Digital ID System aims to provide consumers with a secure, convenient, voluntary and
inclusive way to verify their identity online.

By using a digital ID, consumers can gain greater control over their personal information and reduce
the number of copies of their identity documents out in the world.

This guidance focuses on Australia’s Digital ID System, which has been designed to protect
consumers’ privacy and security. Reflecting this, there is a robust, independent regulatory framework
built into the scheme.

Australia’s Digital ID System is broadly made up of 2 interconnected initiatives:
 A voluntary accreditation scheme for Digital ID providers throughout the economy.
 The Australian Government Digital ID System (AGDIS).


1.2        This guidance
The purpose of this guidance is to assist organisations that are interested in applying to be an
accredited Digital ID service provider with lodging a valid application for accreditation.

The guidance also explains the legal framework governing Australia’s Digital ID System, and how the
Australian Competition and Consumer Commission (ACCC), in its role as the Digital ID Regulator,
assesses applications for accreditation.

The ACCC may update this guidance periodically. Organisations should visit the Digital ID System
website to ensure they are reading the latest version of this guidance. The website contains detailed
information for applicants and accredited entities including their ongoing obligations.

While this guidance provides general information to help organisations lodge a valid application for
accreditation, it is not an exhaustive statement of all requirements for an application. Organisations
should seek their own professional advice about the Digital ID legislation.

The ACCC’s guidance does not replace the requirement for applicants and accredited entities to have
a full understanding of the Digital ID legislation (see section 2.1).

An accredited entity that wishes to participate in the AGDIS will also need to apply for approval to
participate. The ACCC has prepared separate guidance on this. See Applying for approval: Guidance
for organisations seeking to become approved in the Australian Government Digital ID System,
available on the Digital ID System website.

Organisations should also ensure they are familiar with any guidance or other information prepared
by the Office of the System Administrator (System Administrator), the Office of the Australian
Information Commissioner (OAIC) and the Digital ID Data Standards Chair.


1                                                            ACCC   |   Applying for accreditation   |   Version 1.3
2. Regulation of Digital ID

2.1          Legal Framework
The legal framework governing Australia’s Digital ID System is made up of the following
3 components – the Act, the Rules and the Data Standards, collectively referred to as the Digital
ID legislation.

Organisations are responsible for ensuring they familiarise themselves with and understand their
obligations under the Digital ID legislation.

The Digital ID legislation (including Explanatory Statements) is available on the Federal Register
of Legislation.

                        Name                                 Explanation

 Acts – The Acts are    Digital ID Act 2024 (the Act)        This is the primary Act governing both the
 supported by the                                            accreditation scheme and the Australian
 below rules and data                                        Government Digital ID System (AGDIS)..
 standards
                        Digital ID (Transitional and         This Act establishes the mechanism for how
                        Consequential Provisions) Act 2024   entities accredited or approved to participate
                                                             in the AGDIS under the Trusted Digital Identity
                                                             Framework transition into the new legislated
                                                             framework.

 Rules                  Digital ID Rules 2024 (the Digital   These rules set out the requirements for
                        ID Rules) and corresponding          services participating in the AGDIS, and the
                        Explanatory Statement                obligations and conditions for using the Digital
                                                             ID Accreditation Trustmark.

                        Digital ID (Accreditation) Rules     These rules cover requirements entities must
                        2024 (the Accreditation Rules)       meet to become and remain accredited,
                        and corresponding Explanatory        including to manage fraud, security, privacy,
                        Statement                            accessibility, and useability, and to undertake
                                                             annual reviews.

                        Digital ID (Transitional and         These rules provide the transitional
                        Consequential Provisions) Rules      arrangements for entities that were accredited
                        2024 (the Transitional Rules)        under the Trusted Digital Identity Framework
                        and corresponding Explanatory        and/or participating in the unlegislated AGDIS to
                        Statement                            transition to the legislated accreditation scheme
                                                             and/or to participate in the legislated AGDIS.

 Standards              Digital ID (AGDIS) Data Standards    These standards cover the technical integration
                        2024 and corresponding               and design requirements for entities to
                        Explanatory Statement                participate in the AGDIS.

                        Digital ID (Accreditation) Data      These standards cover the technical
                        Standards 2024 (the Accreditation    requirements of the accreditation scheme
                        Data Standards) and corresponding    relating to biometric testing and the use of
                        Explanatory Statement                authentication technologies.


2                                                             ACCC    |   Applying for accreditation   |   Version 1.3
2.2        Agency roles

ACCC
The ACCC, in its role as the Digital ID Regulator, is responsible for promoting compliance with the
Digital ID legislation. This includes:
 accrediting entities that provide digital ID services under the Digital ID legislation
 approving entities to participate in the AGDIS
 undertaking compliance and enforcement activities.
References to “the Regulator” throughout this guidance refer to the ACCC in its role as the Digital
ID Regulator.


OAIC
The OAIC is the privacy regulator of the Digital ID System and is responsible for ensuring individuals’
privacy is protected. Specifically, the OAIC’s role includes:
 providing oversight of the new ‘additional privacy safeguards’ (that apply to all accredited entities
    in their provision of accredited services), including developing guidance, complaint-handling,
    conducting investigations and taking enforcement action in respect of the privacy aspects of the
    Digital ID Act
 performing Notifiable Data Breach scheme functions in relation to the Digital ID System
 undertaking assessments of the handling and maintenance of personal information in
    accordance with the Act.

The privacy obligations in the Digital ID legislation operate in addition to existing privacy obligations
under either the Privacy Act 1988 or relevant state or territory privacy legislation.


Office of the System Administrator
The Office of the System Administrator (System Administrator) is responsible for administering
operational aspects of the AGDIS, including the security, integrity, and performance of the system.
The System Administrator also manages applicant testing and onboards organisations that have
been approved to participate in the AGDIS. More information about the System Administrator’s role
in the AGDIS is in Applying for approval: guidance for organisations seeking to become approved in the
Australian Government Digital ID System, available on the Digital ID System website.


Digital ID Data Standards Chair
The Digital ID Data Standards Chair makes Digital ID Data Standards for various matters, including
technical integration and design requirements for organisations to participate in the AGDIS, and
other technical requirements associated with the accreditation scheme. The Data Standards Body
supports the Digital ID Data Standards Chair in the delivery of its functions and powers.


3                                                              ACCC   |   Applying for accreditation   |   Version 1.3
2.3        About the ACCC
The ACCC is an independent Commonwealth statutory authority. As well as being the Digital ID
Regulator, the ACCC administers and enforces the Competition and Consumer Act 2010 (Cth) and
other legislation, to promote competition and fair trading in markets for the benefit of all Australians.
The ACCC also regulates national infrastructure services.

More information about the ACCC’s purpose, role and structure is available at About the ACCC.


               Section 90 of the Act provides that the ACCC is the Digital ID Regulator.


4                                                             ACCC   |   Applying for accreditation   |   Version 1.3
3. Communicating with the
   Regulator
All organisations that wish to make an application for accreditation must first email the
ACCC at DigitalIDRegulator@accc.gov.au to receive details of the submission process for
completed applications.

More information about the application process is detailed throughout this guidance.

Accredited entities that need to submit an application (for example, to add or vary a condition) should
email the ACCC at DigitalIDRegulator@accc.gov.au to receive details of the submission process.


5                                                           ACCC   |   Applying for accreditation   |   Version 1.3
4. Accreditation under the
   Digital ID System
Organisations, including Commonwealth, state and territory departments, and private businesses,
can apply to become accredited entities under the Digital ID legislation.

Accreditation allows organisations to demonstrate that their Digital ID services meet high standards
in areas such as privacy protection, protective security, and fraud control.

Organisations can apply to the Regulator to become one (or more) of 3 kinds of accredited entities:
 Identity service provider – provides services that:
    –   generate, manage, maintain or verify information relating to the identity of an individual,
    –   generate, bind, manage or distribute authenticators to an individual
    –   bind, manage or distribute authenticators generated by an individual.

 Attribute service provider – provides services that verify and manage an attribute of
    an individual.
 Identity exchange provider – provides services that convey, manage and coordinate the flow of
    data or other information between participants in the Digital ID System.

The AGDIS approval process allows eligible accredited entities and relying parties to apply to the
Regulator to participate in the AGDIS. Relying parties are the organisations that provide a service,
or access to a service, to consumers by verifying the consumer’s identity or attributes through an
accredited entity.


6                                                             ACCC   |   Applying for accreditation   |   Version 1.3
5. Application steps

5.1        Registration
As part of making an application, an organisation should submit the following forms, available on the
Digital ID system website:
 Organisation and Authorised Officer form – used by an organisation to provide the Regulator with
    information about:

    –   the organisation that is applying to be accredited
    –   the Authorised Officer for the organisation, which is a person who is authorised to act on
        behalf of the organisation
    –   the primary contact person/s for the organisation.

 Service and Contact Person form – used by an organisation to provide the Regulator with
    information about:

    –   a service seeking to be, or already accredited under the Act
    –   the contact person/s for the service.


5.2        Accreditation application form
An organisation seeking accreditation within Australia’s Digital ID System is required to use the
Regulator’s Accreditation application form (application form), available on the Digital ID System
website. This form must be submitted to the Regulator with all required documents.

The application form has mandatory sections covering:
 general information about the organisation
 requests for conditions to be applied to the accredited service
 privacy requirements
 fraud requirements
 protective security requirements
 details related to accessibility and useability.
The application form contains additional sections specific to the service type (i.e. identity
service provider, identity exchange provider, or attribute service provider) or characteristics of
the accreditation being sought (e.g. identity proofing level, intended use of biometric information
or alternative proofing processes). Applicants are only required to answer questions relevant to
their application.

The application form lists documents that applicants should provide to satisfy the Regulator that
they are able to comply with the legislative requirements. Where the application form indicates a
document is mandatory, it must be provided. The documents listed in the application form include
documents required by the legislation to be provided to the Regulator, and documents that are likely
to be held by the applicant. Applicants may also submit additional evidence to demonstrate they can
meet applicable requirements.


7                                                            ACCC   |   Applying for accreditation   |   Version 1.3
The application form also contains a section addressing evidence that it is appropriate to accredit the
organisation. Applicants should consider the information in section 8 and then complete the separate
Evidence it is appropriate to accredit or approve the organisation form (evidence of appropriateness
form), available on the Digital ID System website. The completed form and supporting evidence
should be submitted to the Regulator as part of the application for accreditation.

A list of the documents requested or mandated in the application form is available in Appendix B.

A submitted application will be subject to a completeness check prior to being accepted by
the Regulator for the purposes of assessing the application (section 6 lists the steps in the
assessment process).

Once the Regulator has assessed the information submitted in an application, it will decide whether
to accredit or refuse to accredit the organisation.


     Section 15 of the Act details the Regulator’s obligations regarding accreditation decisions.


5.3        Completing an application
For the Regulator to assess an application for accreditation, the applicant must have submitted the
completed application to the Regulator with all required documents. In summary, the applicant will be
required to provide:
 the completed Organisation and Authorised Officer form and Service and Contact Person form (as
    detailed in section 5.1)
 the completed application form (as detailed in section 5.2)
 evidence in support of the application, including evidence in support of any conditions requested
 a completed evidence of appropriateness form (as detailed in section 5.2) and
    associated documentation
 a completed Declaration for entities seeking accreditation form that confirms they understand
    their legal obligations under the Act, Rules, and Data Standards (available on the Digital ID System
    website) and associated documentation.


8                                                            ACCC   |   Applying for accreditation   |   Version 1.3
6. Regulator’s assessment

6.1         Completeness check
Prior to accepting an application for accreditation, the Regulator will carry out a ‘completeness check’
to verify that:
 the statement of scope and applicability is accurate
 the documents provided are consistent with the applicant’s stated DI data environment (detailed
    in section 9.1)
 all necessary information and documents have been provided and address the legislative
    requirements
 assessors providing privacy impact assessments, assurance assessments and systems testing
    reports are appropriately experienced and qualified.


6.2         Assessment
If an application is complete, it will proceed to the assessment stage. If the Regulator identifies any
gaps or deficiencies during the completeness check, it will advise the applicant and identify the
issues requiring rectification prior to re-submission.

The Regulator may request further information from an applicant at any stage during the assessment
process. The Regulator may also consult or share information with other Australian Government
authorities such as the OAIC, national security agencies, or similar authorities overseas.


6.3         Decision
The Regulator will advise applicants in writing of its decision to grant, or not to grant, accreditation.

If the Regulator decides not to grant accreditation, it will also provide reasons for the decision
and information about the applicant’s rights to have the decision reviewed (section 11 has more
information about reviewable decisions).


9                                                              ACCC   |   Applying for accreditation   |   Version 1.3
7.         Conditions on accreditation

7.1        Accreditation is subject to conditions
An accredited entity must comply with the conditions imposed on its accreditation. Failure to comply
with imposed conditions may result in suspension or revocation of accreditation.

Some conditions are imposed by default by the Act and the Accreditation Rules. For example, a
default condition that applies broadly is simply that accredited entities must comply with the Act (see
section 17 of the Act).

Conditions may be imposed at the time of accreditation or at a later stage. Conditions can also be
imposed on application by the entity, or by the Regulator either on its own initiative or as directed by
the Minister for Finance for reasons of national security.

The Regulator will notify an entity of any proposed conditions at the time accreditation is granted.
The Regulator will also provide the entity with notice of any intention to impose, vary or revoke a
condition after accreditation is granted, except where the condition is deemed to be serious or urgent
in nature.

For an accredited entity participating in the AGDIS, additional conditions may apply on an entity’s
approval to participate.

Conditions on an entity’s accreditation and approval to participate in the AGDIS do not necessarily
have to be the same, meaning that an accredited entity participating in the AGDIS may have
separate conditions on its accreditation and approval. However, conditions applying to participants
in the AGDIS cannot be more permissive than the conditions the entity holds as an accredited
service provider.


Common conditions
Another set of conditions that entities can rely on after receiving accreditation are those specified
in rule 7.3 of the Accreditation Rules, which are common conditions imposing limitations on the
collection and disclosure of restricted attributes and biometric information of individuals. The
application of these conditions will vary depending on the kind of accredited services being provided
and an entity’s circumstances.

If an entity intends to rely on one or more of the common conditions specified in rule 7.3 after
receiving accreditation, it is recommended the entity notify the Regulator in advance. Notification can
be included in the accreditation application or as soon as practicable thereafter.

An entity relying on a common condition must also comply with related requirements in the Digital
ID legislation.

For example, if collecting biometric information of an individual under item 6 of rule 7.3, an entity
would be required to comply with all legislative requirements relevant to biometric information
collection, including the relevant data standards for biometric testing, as well as the additional privacy
safeguards that relate to biometric information.

The Regulator may require the entity to provide evidence to demonstrate its compliance with
the legislation.


10                                                            ACCC   |   Applying for accreditation   |   Version 1.3
          See sections 16–23 of the Digital ID Act and Part 7.2 of the Accreditation Rules for
                                   information about conditions.


7.2          Conditions requested by an applicant
In the accreditation application form, applicants can request that conditions relevant to their
accreditation be imposed by the Regulator.

Applicants should review both the default and common conditions under the Digital ID legislation
before applying to the Regulator for a condition to be imposed.

Applicants applying for conditions to be imposed are required to provide details, justification and
supporting evidence relevant to the condition(s) they are seeking. Applicants can contact the
Regulator via email at DigitalIDRegulator@accc.gov.au to discuss the documentation required to
support its application.

Supporting evidence might include plans and procedures for how the applicant will comply with
the condition.

For example, if an applicant seeks to conduct an alternative proofing process, it will be required to
apply for a condition that authorises this. Examples of the kinds of supporting evidence expected for
this kind of condition include:
 details of the proposed alternative proofing process
 evidence that an exceptional use case exists in respect of individuals proposed to undertake an
     alternative proofing process
 a risk assessment in relation to the proposed alternative proofing process, including of the risks to
     relying parties that may rely on the individual’s digital ID, if created
 a report of the risk assessment, including details of the controls and risk mitigation strategies to
     be implemented in response to the identified risks.

The Regulator may also contact the entity to seek further clarity around the purpose and proposed
wording of the condition to ensure it is fit for purpose.

Accredited entities can also apply for a condition to be imposed after being accredited, as well as
apply to vary or revoke a condition. See section 12.3 for information about the application process for
a condition to be imposed, varied or revoked.


7.3          Categories of conditions
The Regulator has a broad power to impose conditions (including those requested by applicants),
which fall into 3 main categories.


1. Conditions to define the scope of accredited services
The Regulator will impose conditions to define the scope of the accredited services, as well as
declare the features and behaviours that a service may or must have and the circumstances or way
these services must be provided.


11                                                                ACCC   |   Applying for accreditation   |   Version 1.3
Types of conditions that fall under this category include but are not limited to:
 the features of the accredited service (i.e. identity proofing levels, authentication levels, reusable
     or one-off digital ID)
 the circumstances or manner in which the accredited services must be provided
 any limitations, exclusions or restrictions in relation to the accredited service.


2. Condition to authorise certain conduct
The Regulator may impose conditions to authorise accredited entities to engage in certain conduct
that would otherwise be prohibited or restricted under the Act.

Types of conditions that fall under this category include but are not limited to:
 whether the accredited entity is authorised to collect or disclose a restricted attribute of an
     individual (e.g. health information, information about a criminal record, or an identifier of an
     individual contained on a government issued document)
 whether the accredited entity is authorised to collect, use or disclose the biometric information of
     an individual
 whether the accredited entity is authorised to perform an alternative proofing process.

Applying for a restricted attributes condition
Entities intending to apply for a restricted attributes condition should provide:
 justification as to why restricted attributes need be collected or disclosed, including:
     –   reasons why an outcome cannot be achieved without collection or disclosure of restricted
         attributes
     –   what alternatives have been explored
     –   what the consequences are for individuals and the AGDIS (if the entity is approved to
         participate in AGDIS), if restricted attributes are not collected or disclosed

 a risk assessment and privacy impact assessment relating to the collection or disclosure of
     restricted attributes
 details of the entity’s protective security, privacy and fraud control arrangements
 any information the entity considers relevant to the Digital ID Regulator’s consideration of matters,
     including:

     –   potential harm that could result if restricted attributes were disclosed to an entity that was not
         authorised to collect them
     –   community expectations as to whether restricted attributes must be handled more securely
         than other kinds of attributes

 the arrangements in place between the entity and each relying party to ensure the protection of
     the restricted attribute(s) from further disclosure.

It is important for entities applying for a restricted attributes condition to provide sufficient
information to support an informed decision by the Regulator.

If a restricted attributes condition is imposed, the Regulator will publish a statement of reasons for
granting the condition on the Accreditation Register (also available on the Digital ID System website).


12                                                              ACCC   |   Applying for accreditation   |   Version 1.3
3. Conditions to direct certain conduct
The Regulator may impose conditions to direct accredited entities to engage in certain conduct or
take certain actions.

Types of conditions that fall under this category include but are not limited to:
 directing an entity to take certain actions before suspending or revoking the entity’s accreditation
     or approval
 directing an entity to maintain adequate insurance against any liabilities arising in connection with
     the obligations under the statutory contract between entities participating in the AGDIS.


13                                                            ACCC   |   Applying for accreditation   |   Version 1.3
8. Appropriateness to accredit
Before approving an application for accreditation, the Regulator must be satisfied it is appropriate
to accredit the organisation in light of the objects of the Act, which include promoting privacy, the
security of personal information, and trust in digital ID services among the Australian community.

In deciding whether it is appropriate to accredit an organisation, the Regulator may have regard
to whether an organisation is a fit and proper person and any other matters the Regulator
considers relevant.

To assist this determination, applicants for accreditation must complete the evidence of
appropriateness form (discussed in section 5.2) and submit the form and associated documents to
the Regulator. The evidence of appropriateness form is available on the Digital ID System website.

The evidence of appropriateness form enables an organisation to demonstrate it is appropriate for
the Regulator to accredit them, by electing to either:
 provide evidence in line with the fit and proper person test as set out in Chapter 2 of the Digital ID
     Rules, or
 provide alternative evidence to satisfy the Regulator.
Further information on these options is set out in the sections below.


8.1         Fit and proper person test or alternative
            evidence
When deciding whether to accredit an applicant, the Regulator may have regard to whether the
applicant is a ‘fit and proper person’. If the Regulator does consider whether an applicant is a fit and
proper person, it must consider the fit and proper person test set out in the Digital ID Rules, which
set out a number of mandatory matters (including but not limited to whether the applicant has been
convicted of a serious criminal offence or has a history of insolvency or bankruptcy).

Due to the broad range of organisations that may seek accreditation, including government
organisations and private entities, the criteria in the fit and proper person test may not be relevant
to all applicants. For some applicants, there may be alternative evidence that is more pertinent
to determining if it is appropriate to accredit the organisation. For this reason, the Regulator has
discretion about whether it is necessary to consider the fit and proper person test for all applications.

Whether an applicant will be able to satisfy the Regulator it is appropriate to accredit the organisation
without providing evidence in line with the fit and proper person test set out in the Digital ID Rules will
depend on the circumstances.

The Regulator expects most applicants to provide evidence in line with the fit and proper person
test. However, examples of circumstances where it may be appropriate for an applicant to provide
alternative evidence to satisfy the Regulator include:
 The organisation has previously been accredited or approved to participate in the AGDIS under
     the Act – for example, if an organisation accredited as an identity service provider later seeks to
     also be accredited as an attribute service provider.
 In this scenario, the Regulator would have already assessed the appropriateness of the
     organisation to be accredited and the organisation will be subject to ongoing reporting obligations
     in relation to their fitness and propriety.


14                                                             ACCC   |   Applying for accreditation   |   Version 1.3
 The organisation is currently accredited under the Consumer Data Right regime.
 The fit and proper person test under the Competition and Consumer (Consumer Data Right) Rules
     2020 (Cth) and the fit and proper person test in the Digital ID Rules are substantially similar.
     Organisations accredited under the Consumer Data Right regime also have ongoing reporting
     obligations in relation to fitness and propriety.
 The organisation is a non-corporate Commonwealth entity, such as a department of state, a
     parliamentary department or an entity prescribed by legislation.
 These entities are subject to a high level of oversight and accountability obligations, and their
     officials are subject to ongoing statutory duties which relate to fitness and propriety, such as
     under the Public Governance, Performance and Accountability Act 2013 (Cth). Alternative evidence
     of the organisation’s oversight and accountability frameworks, and compliance with their ongoing
     statutory duties, may be more pertinent to the Regulator’s assessment of appropriateness than
     some of the mandatory matters set out in the Digital ID Rules.
 The organisation is subject to other significant regulatory controls relating to oversight and
     accountability, character obligations of employees, and privacy obligations, or is subject to
     another similar fit and proper person test.

An organisation that falls within one or more of the above categories may still prefer to provide
evidence in line with the fit and proper person test set out in the Digital ID Rules.

Whatever evidence the applicant provides, the Regulator will request further information and
documents if required to be satisfied it is appropriate to accredit the applicant, in line with the objects
of the Act.

If an applicant chooses to provide alternative evidence, the Regulator may request it provide evidence
in line with the fit and proper person test in the Digital ID Rules if the Regulator is not satisfied it is
appropriate to approve the applicant on the basis of the alternative evidence provided. This may
extend the timeframes for assessment of the application for accreditation.


8.2         Evidence in line with the fit and proper person
            test
The information in this section is relevant to an applicant that has elected to provide evidence in line
with the fit and proper person test set out in the Digital ID Rules.


15                                                            ACCC   |   Applying for accreditation   |   Version 1.3
     Documents to be submitted with the application
         Completed Evidence it is appropriate to accredit or approve the organisation form.
         Current organisation chart reflecting all relevant associated persons and their relationships
         with the organisation.
         If the organisation is a body corporate – current corporate structure chart that identifies
         the organisation and its associates and associated entities (within the meaning of the
         Corporations Act 2001 (Cth)).
         Associated persons declarations via the Fit and Proper Person Declaration for Associated
         Persons form – the organisation must provide a separate signed declaration from
         each associated person. The template declaration form is available on the Digital ID
         System website.

     To the extent any of this information has been provided in response to other sections of the
     application form there is no need to provide the information again – instead an organisation
     can refer to the relevant document or response.


The Regulator will consider whether the organisation, and associated person/s (see section on
associated persons below) of the organisation, has:
 within the previous 10 years, been convicted or found guilty of a serious criminal offence or an
     offence of dishonesty against any law of the Commonwealth or of a State or Territory, or a law of
     a foreign jurisdiction
 been found to have contravened a law relevant to the management of its DI data environment or
     a similar law of a foreign jurisdiction. Which laws are relevant will depend on the organisation’s
     circumstances, including the type of organisation, the industry it operates in and the data it
     proposes to handle. Laws likely to be relevant include, but are not limited to:

     –   the Act, Accreditation Rules and Digital ID Rules
     –   Privacy Act 1988 (Cth) and similar State or Territory laws
     –   Corporations Act 2001 (Cth)
     –   Corporations Regulations 2001 (Cth)
     –   Security of Critical Infrastructure Act 2018 (Cth)

 been the subject of a determination under sections 52(1)(b) or 52(1A)(a)–(d) of the Privacy
     Act 1988 (Cth), which relates to an interference with the privacy of an individual, or a finding or
     determination of a similar nature under a similar law of a State or Territory or a foreign jurisdiction
 a history of insolvency or bankruptcy, and/or
 been the subject of a determination made under an external dispute resolution scheme that
     included a requirement to pay compensation and was, at the time the determination was made,
     recognised under section 35A of the Privacy Act 1988 (Cth) or section 56DA of the Competition
     and Consumer Act 2010 (Cth) (which sets out recognised external dispute resolution schemes for
     the purposes of the Consumer Data Right).

If the organisation is a body corporate, the Regulator will also consider whether any of the directors
of the organisation, or of an associated person of the organisation, have been disqualified from
managing corporations or been subject to a banning order.

The Regulator will also have regard to whether the organisation has previously had an application
to be accredited or approved to participate in the AGDIS refused. If the organisation is or has been


16                                                             ACCC   |   Applying for accreditation   |   Version 1.3
accredited or approved, the Regulator will consider whether that accreditation or approval has been
suspended or revoked.

An organisation should disclose any other matters that may negatively impact the Regulator’s
assessment of whether the organisation is a fit and proper person. This could include details of any:
 investigation or disciplinary action by a professional body
 inquiry or investigation by a government agency
 court proceedings initiated by a government agency
 data breaches that have impacted the organisation and the organisation’s response.
The Regulator may conduct searches and undertake relevant checks to verify the information
and documents provided by the organisation. This may include criminal background checks of
associated persons.


Associated persons
An applicant providing evidence in line with the fit and proper person test is required to provide the
names of all associated persons and their relationship to the organisation as part of the evidence
of appropriateness form. An applicant must also provide a separate signed declaration from each
associated person addressing the criteria in the fit and proper person test: Fit and Proper Person
Declaration for Associated Persons form. The template declaration form is available on the Digital ID
System website.


Identifying associated persons
‘Associated person’ is defined in rule 1.4 of the Digital ID Rules. It is essential that an organisation
carefully considers the definition of ‘associated person’ and identifies all their associated persons,
even if there is a substantial number of them.

When determining who their associated persons are, an organisation should:
 consider which persons – within or outside their organisation – make, or participate in making,
     decisions that affect the management of the organisation’s DI data environment or have the
     capacity to significantly affect the management of the DI data environment. This may include:

     –   office holders, for instance a director or company secretary
     –   operations managers or data security managers
     –   accountable executives, for instance a senior executive of the organisation responsible for the
         overall management of the organisation’s DI data environment and accredited services
     –   any other staff who have influence over the work that could significantly affect or influence
         the management of the DI data environment
     –   any relevant contractors

 if the organisation is a body corporate – also refer to the definitions of associate and associated
     entity in the Corporations Act 2001 (Cth). These definitions encompass a wide group of individual
     and corporate persons associated with the organisation, including persons who belong to
     overseas entities. For example, an associated entity can include related bodies corporate such as
     a holding company or a subsidiary and an associate can include a director or company secretary
     of either of those entities.

An organisation may wish to seek appropriate professional advice to assist with identifying their
associated persons.


17                                                             ACCC   |   Applying for accreditation   |   Version 1.3
8.3         Alternative evidence of appropriateness
The information in this section is relevant to an applicant that has elected to provide alternative
evidence to satisfy the Regulator it is appropriate to accredit them.


     Documents to be submitted with the application
        Completed Evidence it is appropriate to accredit or approve the organisation form.
        Any documents that detail or support the information provided in the evidence of
        appropriateness form.
        If the organisation is a body corporate – current corporate structure chart that identifies the
        organisation, its subsidiaries, and its related bodies corporate.
        Current organisation chart identifying any persons who have the capacity to significantly
        affect the organisation’s management of its DI data environment.

     To the extent any of this information has been provided in response to other sections of the
     application form there is no need to provide the information again – instead an organisation
     can refer to the relevant document or response.


The Regulator will consider whether the organisation, and any persons that have the capacity to
significantly affect the organisation’s management of its DI data environment, possess appropriate
qualities such as competence, character, diligence, honesty, integrity, and judgement. The Regulator
will also consider whether the organisation has sufficient processes or controls in place to ensure the
organisation and its key relevant persons maintain and act in accordance with these qualities.


Types of alternative evidence
The types of alternative evidence an applicant should provide, as well as the level of detail required,
will depend on its individual circumstances.

Information likely to be relevant includes:
 Details of any relevant legislative or regulatory controls that apply to the organisation or its
     employees, particularly controls relating to oversight and accountability, character obligations
     of employees, and privacy obligations. For example, authorised deposit-taking institutions are
     regulated by the Australian Prudential Regulation Authority, Commonwealth companies and
     entities are subject to the Public Governance, Performance and Accountability Act 2013 (Cth) and
     Australian Public Service employees are subject to the Public Service Act 1999 (Cth).
 Details of any similar fit and proper person tests under other regulatory regimes the organisation
     or its employees have been subject to, e.g. most entities accredited under the Consumer Data
     Right regime will have been subject to a similar fit and proper person test during that accreditation
     process. The more similar the other fit and proper person test is to the mandatory matters set out
     in the Digital ID Rules, the more likely it is to be relevant.
 Details of pre-employment checks the organisation conducts, e.g. whether relevant staff and/or
     directors are subject to police and/or security checks.


18                                                             ACCC   |   Applying for accreditation   |   Version 1.3
For government organisations, relevant information may also include:
 details of the organisation’s status, e.g. whether the organisation is a central government agency
     or department, or, if the organisation is a corporation, who controls it
 whether there is an accountable authority responsible for the organisation and, if so, what the
     obligations of this authority are
 whether the organisation is generally subject to government policy and directions
 whether the organisation is subject to Ministerial or other governmental control over its
     operations
 whether the organisation is subject to reporting obligations to the relevant government
 whether the organisation is subject to auditing obligations to the relevant government
 whether the organisation is otherwise subject to oversight over its operations
 whether the organisation is subject to public interest disclosure obligations.


Adverse information
An applicant should also disclose any other matters that may negatively impact the Regulator’s
assessment of whether it is appropriate to accredit it. This could include details of any:
 investigation or disciplinary action by a professional body
 inquiry or investigation by a government agency
 court proceedings initiated by a government agency
 details of any data breaches that have impacted the organisation and the organisation’s response.
The Regulator may conduct searches and undertake relevant checks to verify the information and
documents provided by the applicant. This may include criminal background checks.


8.4         Ongoing reporting requirements
Accredited entities are required to notify the Regulator within 5 business days of any matter that
could be relevant to a decision as to whether they are a fit and proper person. Importantly, this
reporting obligation applies even if the entity does not provide evidence in line with the fit and proper
person test as part of its application for accreditation.

The Regulator may suspend or revoke an entity’s accreditation if it is satisfied that it is not
appropriate for the entity to be accredited. In deciding this, the Regulator may have regard to the fit
and proper person test.


                     See rule 7.4(b) in the Accreditation Rules for more information.


19                                                             ACCC   |   Applying for accreditation   |   Version 1.3
9. Accreditation criteria and
   evidence requirements
To accredit an applicant, the Regulator must be satisfied that the organisation:
 can comply with all relevant legislative requirements
 has correctly defined and documented the boundaries of its DI data environment, and has limited
     it to the extent practicable
 has provided all information and documentation required to accompany an application for
     accreditation
 has an operational information technology (IT) system through which it will provide its accredited
     services
 has conducted each kind of assessment and testing required by the Accreditation Rules and
     Accreditation Data Standards (see section 10).

In deciding whether to accredit an applicant, the Regulator must also have regard to the level
of the applicant’s tolerance for fraud and cyber security risks, and whether the applicant’s risk
tolerance level is likely to create an unacceptable risk if accredited. An applicant’s protective security
assessment and fraud assessment, and its responses to risks identified in those reports, including
risk mitigation strategies, will be particularly important to the Regulator in making this judgment.

The Regulator must also consider whether the applicant’s privacy impact assessment and response
identify any matters that may give rise to an unacceptable risk to the privacy of individuals.


      See rule 2.6 in the Accreditation Rules for more information on matters that the Regulator
                      must consider in deciding whether to accredit an applicant.


9.1         DI data environment
The Regulator must not accredit an applicant unless it is satisfied that it has correctly identified
and documented the boundaries of its DI data environment and has limited the boundaries of that
environment to the extent practicable.


        See rules 1.4 and 2.1 in the Accreditation Rules for the requirements relating to DI data
                                              environment.


The DI data environment means the IT systems used for, and the processes that relate to, the
provision of an organisation’s proposed accredited services. An applicant must define the boundaries
of its DI data environment, including the people, processes, technology and infrastructure through
which the proposed accredited services are provided. Each applicant’s DI data environment will
be different, subject to factors including what kind of supply chain it operates, use of third-party
contractors, and the delivery (mobile, website or in-person) of these services.


20                                                             ACCC   |   Applying for accreditation   |   Version 1.3
A well-defined DI data environment is an important reference document for the Regulator, assessors,
and the applicant itself to understand exactly where the boundaries of the proposed accredited
services lie.

It is critical that an applicant demonstrates to the satisfaction of the Regulator that the DI data
environment documentation:
 clearly defines the scope and boundaries of its proposed accredited services
 specifies any infrastructure owned or managed by contractors
 segregates the environment, to the extent practicable, from other systems and minimises
     the number of people (including contractors) or systems hosting, processing or accessing
     information generated, collected, used, held or disclosed for the purpose of providing the
     proposed accredited services.

Defining the DI data environment is particularly important where an accredited entity uses the
same infrastructure, IT systems and/or contractors, in whole or in part, for both accredited and
unaccredited services. The Digital ID legislation will apply whenever an accredited entity collects,
generates, uses, holds, or discloses information for the purpose of providing an accredited service.

To satisfy this requirement, documentation of the DI data environment should include:
 a narrative description and illustrative diagrams for the proposed accredited service
 identification of the proposed accredited service’s boundary and information flows and interfaces.
     This would include data transmission, data in use, internal transmission (i.e. audit trails, event
     logs, disclosure to third parties)
 key infrastructure and software required for operation/support of the proposed accredited
     service, including major versions and data storage (back-ups, repositories, caches etc.)
 key people involved in the operation and development of the proposed accredited service and
     their location (branch, department etc.) in the organisation. An organisational chart is helpful
     context, especially reporting lines/escalation pathways
 significant third parties supporting the development or operation of the proposed accredited
     service (e.g. cloud service providers, managed service providers, physical security services,
     critical design and delivery partners etc.)
 key evidence documents supporting the operation of the proposed accredited service
     (procedures, plans etc.).


9.2         Statement of scope and applicability
An applicant must provide a statement of scope and applicability that lists:
 each requirement in the Accreditation Rules and the Accreditation Data Standards with which the
     applicant must comply in relation to its proposed accredited services
 the evidence that demonstrates that the applicant complies with those requirements or will
     comply if accredited.


          See rules 1.4 and 2.2 in the Accreditation Rules for the requirements relating to the
                                  statement of scope and applicability.


21                                                             ACCC   |   Applying for accreditation   |   Version 1.3
While the Accreditation Rules do not mandate the form of the statement of scope and applicability,
an applicant may find it useful to submit a spreadsheet detailing the requirements and corresponding
evidence that demonstrates compliance. Where an applicant’s evidence is more than one document,
or contains other information, it would be useful to pinpoint the sections that demonstrate
compliance with the relevant legislative requirement.


9.3         Privacy impact assessment
An applicant must provide a privacy impact assessment that assesses compliance against the
privacy requirements in the Act and the Accreditation Rules, and that provides analysis of the privacy
impacts of the proposed accredited services.

A privacy impact assessment should include analysis of how an applicant’s proposed services will
impact the privacy of individuals and protection of personal information, if accredited. An assessment
report should include any recommendations by the assessor, including recommendations that the
applicant undertake activities to mitigate any identified privacy risks.

A privacy impact assessment must be undertaken by an assessor with relevant experience, training
and qualifications (see Appendix A). The assessor must be external to the organisation and must not
have been involved in the design, implementation, operation or management of the applicant’s DI
data environment or accredited services.

A privacy impact assessment will include an assessment of the relevant documentation, processes
and mechanisms that facilitate an applicant’s ability to comply with the relevant privacy requirements
(e.g. privacy management plans, privacy policies and data breach response plans). These underlying
documents must be submitted with an application for accreditation.


        See rule 2.4 in the Accreditation Rules for the requirements relating to privacy impact
                                             assessments.


An applicant must:
 respond in writing to the findings and recommendations in the privacy impact assessment,
     with the response signed by the entity’s accountable executive (an organisation’s accountable
     executive is a senior executive responsible for the overall management of the organisation’s DI
     data environment and proposed accredited services)
 conduct a risk assessment and assign a rating for each risk and recommendation identified
     against the applicant’s risk matrix, which must be based on an established risk management
     framework, or standard
 respond to each risk or recommendation identified by an assessor. An applicant’s response to
     each risk will be determined by the risk rating and must include details of the actions to address
     the risk, timeframes for completion of actions, and the residual risk following completion of the
     planned action.


9.4         Technical testing
Applicants are required to verify that the information systems through which an entity will provide
its accredited service includes and can execute the necessary functionality to support the kind of
accredited service(s) that the entity is seeking to be accredited for. This technical testing should be


22                                                            ACCC   |   Applying for accreditation   |   Version 1.3
appropriately scoped based on the features and behaviours of the proposed accredited service(s) and
the statement of scope and applicability.

Entities seeking accreditation are required to undertake technical testing to determine whether their
systems have the functionality necessary to meet the requirements within the Accreditation Rules
and Accreditation Data Standards, including the following:
 cyber security incident monitoring, detection, investigation, management, and response
 logging requirements
 fraud incident monitoring, detection, investigation, management, and response
 user support requirements
 data minimisation requirements
 compliance with the relevant Accreditation Data Standards.
The application form also requests evidence of technical testing which refers to the information
an applicant is required to provide under subrule 2.5(3) of the Accreditation Rules. An applicant is
required to record:
 the test completion criteria used
 the assumptions, limitations and dependencies used
 the methodology used
 how each test conducted maps to each requirement that the applicant’s IT system must meet
 the results of the technical testing.
Applicants should consider how to best provide this evidence to the Regulator. A requirements
traceability matrix is an example of how this information may be provided.


Technical testing attestation statement
When applying for accreditation, applicants are required to provide a statement, signed by the
applicant’s accountable executive, attesting that:
 the technical testing has been conducted
 the accountable executive is satisfied the results of the technical testing demonstrate that the
     requirements are met
 where applicable, the accountable executive is satisfied that a cloud service provider within its DI
     data environment has conducted penetration testing as per the legislative requirements.

Applicants should utilise the Declaration technical testing attestation statement for entities seeking
accreditation form (available on the Digital ID System website) to attest the technical testing
requirements have been met.


       See rule 2.5 in the Accreditation Rules for the requirements relating to technical testing.


Applicants have additional record keeping requirements relating to the technical testing they conduct.
The Regulator may request these records as part of its assessment.


23                                                            ACCC   |   Applying for accreditation   |   Version 1.3
9.5         Protective Security Framework
The protective security framework an applicant adopts will depend on whether it is a non-corporate
Commonwealth entity.


Protective Security Policy Framework – PSPF
Non-corporate Commonwealth accredited entities, as defined in the Public Governance, Performance
and Accountability Act 2013 are required to comply with the PSPF.

Non-corporate Commonwealth entities need to ensure that each of the specific individual protective
security controls that are specified in rule 4.3 of the Accreditation Rules are properly applied.

In order to align the PSPF with the scope of the Accreditation Rules, rule 1.7A deems certain terms in
the PSPF to have the same meaning as terms used in the Act. Entities should ensure that terms are
referenced in accordance with their meaning under the Act.

The PSPF is reviewed annually and if any relevant PSPF controls are amended, non-corporate
Commonwealth entities will be provided with a 3 month transition period to achieve compliance with
the new version in accordance with rule 1.7(2)(a) of the Accreditation Rules.


Other Frameworks
Accredited entities, other than non‑corporate Commonwealth entities, are required to comply with
ISO/IEC 27001 or the controls of an approved alternative framework (rule 4.2(1)). Entities that choose
to follow an alternative framework must demonstrate that they meet all the same kinds of controls
specified in ISO/IEC 27001 (rule 4.5 of the Accreditation Rules).

In order to align ISO/IEC27001 with the scope of the Accreditation Rules, rule 1.7B deems certain
terms in ISO/IEC 27001 have the same meaning as terms used in the Act. Entities should ensure that
terms are referenced in accordance with their meaning under the Act.

There is a 12 month transition period for entities to comply with any changes to ISO/IEC27001 or the
approved alternative framework. (rule 1.7(2)(b) of the Accreditation Rules).


      See Chapter 4, Part 4.1 Division 2 of the Accreditation Rules for information on Protective
                                     security framework controls.


9.6         Biometrics
An applicant seeking to be accredited as an identity service provider conducting identity proofing at
levels IP2 Plus or higher, is required to:
 demonstrate an ability to meet the relevant biometric requirements in the Act and in Chapter 5,
     Part 5.1, Division 2, Subdivision B of the Accreditation Rules
 provide a copy of reports of the biometric testing conducted in accordance with the Accreditation
     Data Standards.

Personnel conducting biometric testing must have appropriate experience in conducting
biometric testing, must be external to the applicant, and must not have been involved in the


24                                                             ACCC   |   Applying for accreditation   |   Version 1.3
design, implementation, operation or management of the applicant’s DI data environment or
accredited services.


         See data standard 2.2 of the Accreditation Data Standards for information about the
                                       Biometric testing entity.


Additional biometric requirements
Applicants that propose biometric capabilities as part of their application must be aware of the
additional privacy safeguards in relation to the collection, use, disclosure, and destruction of
biometric information, outlined in Chapter 3, Part 2, Division 2 of the Act.

Applicants seeking to use biometric information for testing activities must ensure that they are
compliant with the relevant rules in Chapter 4, Part 4.5 of the Accreditation Rules, including that:
 the testing is conducted in accordance with the purposes and circumstances in which testing
     may be conducted
 the testing is conducted in accordance with the requirements of policies covering the ethical
     use of biometric information to ensure biometric systems do not selectively disadvantage or
     discriminate against any group00.
 for each reporting period, prepare a report detailing the results of any testing using
     biometric information.

Applicants seeking to use biometric information for fraud activities must ensure that their digital ID
fraud risk management activities have been conducted in accordance with written ethical principles
aimed at avoiding disadvantage to, or discrimination against, individuals.

If applicants wish to collect, use, and disclose biometric information under their accreditation, and a
common condition does not otherwise provide authorisation, then applicants will need to apply for
this as a condition on their accreditation.

If a common condition already provides authorisation, it is recommended that applicants notify the
Regulator in advance of its intention to rely on a common condition.


25                                                            ACCC   |   Applying for accreditation   |   Version 1.3
10. Assurance assessments and
    systems testing
An organisation applying for accreditation must have conducted all assurance assessments and
systems testing as required by the Accreditation Rules and Accreditation Data Standards.

The results of the assessments and testing help demonstrate to the Regulator that the applicant will
be able to comply with the relevant legislation, if accredited. The findings and recommendations are
also key to the Regulator’s consideration of whether there are likely to be unacceptable fraud or cyber
security risks, or risks to the privacy of individuals, if an applicant is accredited.

The required assurance assessments and systems testing must be conducted having regard to the
relevant requirements from the Accreditation Rules and Accreditation Data Standards (as detailed
in the applicant’s statement of scope and applicability), and in respect of the applicant’s DI data
environment at the time of the assessment.


          See Chapter 3 in the Accreditation Rules for the requirements relating to assurance
                                  assessments and systems testing.


10.1 Reports for assurance assessments and
     systems testing
For each assurance assessment or systems test, an assessor must prepare a report that meets the
requirements of the Accreditation Rules, including but not limited to:
 a summary of activities undertaken
 the dates assessment or testing began and ended
 the release or version number of the information technology system assessed
 the version number of any documents considered
 details of the evaluation or test methodology used
 the assessment findings, including details of any relevant non-compliance with the Digital ID
     legislation, risks identified and recommendations to treat the risks or to ensure compliance
 the qualifications and experience of the assessor.
An applicant must:
 submit a written response, signed by the organisation’s accountable executive, to the findings of
     each assessor report
 conduct a risk assessment against a risk matrix for each risk and recommendation identified in
     an assessor’s report, based on an established risk management framework
 assign a risk rating in accordance with the risk matrix and respond to each risk identified in the
     assessor’s report as requiring treatment and to each recommendation in the report
 detail the action it will take to implement the treatment or recommendation, the timeframe in
     which it will complete the action, and the expected residual risk rating following the action.


26                                                             ACCC   |   Applying for accreditation   |   Version 1.3
Where an applicant does not propose to address a risk or recommendation, it must set out the
reasons for this decision, detail any alternative actions to be taken and associated timeframes, and
the expected residual risk rating following the alternative action.

Applicants have flexibility to implement an established risk management framework that is relevant
to them and appropriate for their industry. The Accreditation Rules Explanatory Statement provides
examples of established risk management frameworks.


     See Part 3.4 in the Accreditation Rules for the requirements relating to reports for assurance
                                  assessments and systems testing.


10.2 Assessor requirements
The role of independent assessors is critical in providing assurance to the Regulator that an applicant
will be able to comply with the relevant legislative requirements under the Act, Digital ID Rules,
Accreditation Rules, and Accreditation Data Standards.

It is the responsibility of an applicant to demonstrate to the Regulator that all required assurance
assessments and systems testing has been conducted by an individual who:
 has the appropriate experience, training and qualifications to undertake the required assessment
 meets any additional requirements in the Accreditation Rules for the specific assessment or
     testing undertaken.

For assessors undertaking fraud assessments, penetration testing, privacy impact assessments
and protective security assessments, the Accreditation Rules require that the assessor is external to
the applicant and, if applicable, external to the applicant’s corporate group. The Accreditation Rules
also require that the assessor has not been involved in the design, implementation, operation or
management of the applicant’s accredited services or DI data environment.

Details of the experience, training and qualifications of the assessor must be included with each
required assurance assessment and systems testing. This may include relevant and currently
maintained certifications, a current curriculum vitae, and any registrations with relevant bodies.
Applicants should consider relevant industry standards in deciding whether an assessor is
appropriate for a particular assessment or test.

For assessments or testing where there is no specific requirement in the Accreditation Rules for an
assessor to be external to the organisation, an applicant could consider providing evidence that there
is no conflict of interest. This evidence could take the form of an independence statement or similar.

Appendix A in this guidance contains more detailed information about assessor qualifications.


                  See rule 3.2 in the Accreditation Rules for assessor requirements.


27                                                           ACCC   |   Applying for accreditation   |   Version 1.3
10.3 Assurance assessments

Protective security assessment
The protective security assessment must review and assess the applicant’s compliance with the
controls in the protective security framework it uses, or intends to use. The protective security
assessment must review the findings and results of other protective security-related reports, such
as the penetration testing report (see section 10.4) and address any findings or recommendations
arising from the essential strategies review.

The assessor who prepares the protective security assessment must be external to the organisation
and must not have been involved in the design, implementation, operation or management of the
applicant’s DI data environment or accredited services.


      See rules 3.3–3.5 in the Accreditation Rules for the requirements relating to the protective
                                         security assessment.


Fraud assessment
The fraud assessment is a key mechanism for determining that the applicant has, or will, implement
and operate an effective framework of fraud controls associated with its DI data environment and
accredited services.

The assessor who prepares the fraud assessment must be external to the applicant and must not
have been involved in the design, implementation, operation or management of the applicant’s DI
data environment or accredited services.


     See rule 3.6 in the Accreditation Rules for the requirements relating to the fraud assessment.


Accessibility and useability assessment
The accessibility and useability assessment must review and assess the applicant’s compliance
with the accessibility and useability requirements of the Act and the Accreditation Rules, with the
aim of ensuring that accredited services are accessible for individuals who experience barriers when
creating or using a digital ID.

The assessment must review and assess the findings of the Web Content Accessibility Guidelines
testing and address any risks or recommendations identified by the assessor.

If the applicant is required to conduct useability testing, the assessment must address the findings
of the testing, including actions to address any risks and recommendations identified in the
assessor’s report.


     See rule 3.7 in the Accreditation Rules for the requirements relating to the accessibility and
                                        useability assessment.


28                                                          ACCC   |   Applying for accreditation   |   Version 1.3
10.4 Systems testing

Penetration testing
Penetration testing is an assessment and evaluation of the effectiveness of security controls in the IT
system through which the applicant provides, or will provide, its accredited services.

Penetration testing is intended to provide a level of confidence to the Regulator that the applicant’s IT
system does not include security vulnerabilities that could be exploited.

The assessor who prepares the penetration testing must be external to the organisation and must
not have been involved in the design, implementation, operation or management of the applicant’s DI
data environment or accredited services.


      See rules 3.8–3.10 in the Accreditation Rules for the requirements relating to penetration
                                               testing.


Useability testing
Useability testing is used to identify issues with user experience resulting from adverse issues in the
design, useability and accessibility of the applicant’s public-facing accredited services.

It also identifies to what degree those services can be accessed and used by a diverse range of
people within the Australian community, covering diversity in disability, age, gender and ethnicity, and
still operate as intended.


      See rules 3.11–3.13 in the Accreditation Rules for the requirements relating to useability
                                               testing.


Web Content Accessibility Guidelines
An applicant must test that its public facing accredited services and information relating to its
accredited services meet applicable Web Content Accessibility Guidelines.


     See rules 3.14–3.16 in the Accreditation Rules for the requirements relating to Web Content
                                   Accessibility Guidelines testing.


29                                                           ACCC   |   Applying for accreditation   |   Version 1.3
11. Review of Regulator decisions
Certain decisions of the Regulator are reviewable. This includes decisions of the Regulator to:
 refuse to accredit an entity
 impose, vary or revoke a condition, or refuse to impose or vary a condition on an
     entity’s accreditation
 suspend or refuse to suspend an entity’s accreditation
 revoke an entity’s accreditation.
A reviewable decision is eligible for internal review if it is made by a delegate of the decision maker.
Other reviewable decisions are only eligible for review by the Administrative Review Tribunal or
Federal Court (see below).

When the Regulator (the decision maker) advises an applicant of the outcome of a decision, the
Regulator’s correspondence to the applicant will include information on whether the decision is
eligible for internal review or external review by the Administrative Review Tribunal or Federal Court.


         See Chapter 9, Part 4 of the Digital ID Act for information about reviewable decisions.


11.1 Internal review
An application for internal review must be in writing and be made within 28 days after the day the
decision first came to the notice of the applicant. A request for review of a decision made by the
Regulator must be made by the affected entity.

An entity can submit a written request for internal review via email to the Regulator at
DigitalIDRegulator@accc.gov.au.

The Regulator is required to make an internal review decision to either uphold, vary or revoke the
original decision within 90 days of receipt of the request for review.

The applicant will be notified by the Regulator of the outcome of the internal review. If the Regulator’s
decision is to revoke the decision under review, the Regulator may make any other decision
considered appropriate. The Regulator will provide the applicant with a written statement of its
reasons for its decision.


              Refer to the factsheet Internal review of Digital ID Regulator decisions on the
                             Digital ID System website for additional details.


30                                                            ACCC   |   Applying for accreditation   |   Version 1.3
11.2 Review by the Administrative Review Tribunal
A reviewable decision will be eligible for external review by the Administrative Review Tribunal (ART)
if the decision was made by the decision maker personally (i.e. not a delegate), or if the decision is an
internal review decision made by the Regulator.

The Regulator will advise the applicant if the decision is eligible for external review by the ART. An
application to the ART for review of a reviewable decision made by the Regulator must be made by
the entity affected by the reviewable decision.

Information on applying to the Tribunal for a review of a decision is available on the ART website.


11.3 Judicial review
Applicants or accredited entities may apply to the Federal Court for judicial review of certain
decisions made by the Regulator.

Judicial review is concerned only with the legality of the decision and is limited to questions of law,
such as:
 whether the Regulator had the power to make the decision
 whether the decision maker took an irrelevant consideration into account or failed to take a
     relevant consideration into account
 whether the decision was so unreasonable that no reasonable decision maker could have made it.
Applicants may appeal to the Federal Court for judicial review of any decision of the ART. The Federal
Court can rule only on questions of law, not on the merits of the decision.

Information on the process to apply to the Federal Court for judicial review of a decision is on the
Federal Court of Australia website.


31                                                            ACCC   |   Applying for accreditation   |   Version 1.3
12. Following accreditation

12.1 Digital ID Accredited Entities Register
Upon notification by the Regulator that an application for accreditation has been successful,
details of the accredited entity and accredited services will be placed on the Digital ID Accredited
Entities Register, and the accredited entity can utilise the Digital ID Accreditation Trustmark for its
accredited services.
 The Digital ID Accredited Entities Register contains details of Digital ID providers that are, or have
     been, accredited under the Act.
 The Digital ID Accredited Entities Register includes the type of accredited service each
     organisation is accredited to provide, the day the accreditation came into force, and any
     conditions that were imposed on accreditation.

The Digital ID Accredited Entities Register may also contain any other information the Regulator
considers appropriate. The register is available on the:
 Digital ID System website
 ACCC Digital ID public register


12.2 Digital ID Accreditation Trustmark
Accredited entities are permitted to use and display the Digital ID Accreditation Trustmark
(Accreditation Trustmark), which is a registered trade mark in Australia.

An accredited entity that is not a Commonwealth entity must enter into a Trade Mark Licence
Agreement with the ACCC before using the Accreditation Trustmark.

The Trade Mark Licence Agreement sets out the legal rights and obligations of an accredited entity
wishing to use or display the Accreditation Trustmark, including the need to use it in accordance
with the Accreditation Trustmark Style Guide. Copies of the Trade Mark Licence Agreement and the
Accreditation Trustmark Style Guide are available on the Digital ID System website.

An accredited Commonwealth entity must agree to comply with ACCC conditions governing the use
of the Accreditation Trustmark, as communicated at the time of accreditation.

All accredited entities must ensure that any use of the Accreditation Trustmark complies with the
requirements prescribed in the Digital ID legislation and the Australian Consumer Law.

Under the Digital ID Rules an accredited entity using or displaying the Accreditation Trustmark must:
 take reasonable steps to make clear which services are accredited and which are not
 use and display a hyperlink to the Digital ID Accredited Entities Register near the Accreditation
     Trustmark
 use and display the internet address of the Digital ID Accredited Entities Register near the
     Accreditation Trustmark (for printed documents).


32                                                             ACCC   |   Applying for accreditation   |   Version 1.3
If an accredited identity exchange provider chooses to use or display the Accreditation Trustmark, it
must ensure it is only used or displayed on:
 public-facing accredited services
 documents that contain public-facing information related to the accredited services of that
     identity exchange provider or another accredited entity operating within the same digital ID
     system as the identity exchange provider.

Failure to comply with the provisions relating to the use or display of the Accreditation Trustmark may
give rise to substantial civil pecuniary penalties under the Act.

The Australian Consumer Law prohibits conduct in trade or commerce that is misleading or
deceptive, or is likely to mislead or deceive, as well as false or misleading representations.
Contraventions of the Australian Consumer Law may result in substantial civil pecuniary penalties.


         Chapter 5 of the Digital ID Rules details the requirements in relation to the Digital ID
                                       Accreditation Trustmark.


12.3 Changes to accreditation
An accredited entity may apply for changes to its accreditation, including:
 requesting the imposition, variation or revocation of a condition on its accreditation
 requesting the variation, suspension or revocation of its accreditation.
The Regulator may, on its own initiative, take action to impose new conditions, as well as vary or
revoke an existing condition on an entity’s accreditation, if it considers it appropriate to do so. The
Regulator may also be directed by the Minister for Finance to impose new conditions on an entity’s
accredited service.

The Regulator also must suspend or revoke an entity’s accreditation if the Minister for Finance directs
it to do so, for reasons of security (within the meaning of the Australian Security Intelligence Act 1979),
including because of an adverse or qualified security assessment in respect of a person.

See Guidance for accredited entities in Australia’s Digital ID System available on the Digital ID System
website for more detailed information on these processes.


33                                                            ACCC   |   Applying for accreditation   |   Version 1.3
13. Compliance obligations
Following accreditation, entities have continuing compliance, disclosure and reporting obligations
under the Digital ID legislation.

These obligations include:
 complying with conditions applied to the entity’s accreditation
 complying with the requirements for maintaining accreditation as set out in Chapter 4 of the
     Accreditation Rules, including ensuring that the accredited entity’s protective security and fraud
     management capabilities are adapted to respond to existing and emerging risks, threats and
     vulnerabilities
 complying with the requirements set out in Chapter 5 of the Accreditation Rules when providing
     accredited services
 ensuring that the accredited services an entity provides are accessible and inclusive as required
     by the Act
 complying with restrictions on the collection of restricted attributes of individuals (relevant to
     participating relying parties)
 notifying the Regulator of reportable incidents within required timeframes
 maintaining comprehensive records as required by the Accreditation Rules
 participating in annual review processes and ongoing reporting obligations as required by the
     Accreditation Rules.

In addition, an entity must ensure that any representation it makes regarding its accreditation or
accredited services provided under the Act is accurate, and not misleading or deceptive.


      Failure to meet compliance obligations may result in enforcement action by the Regulator,
       including proceedings seeking injunctions and/or substantial civil pecuniary penalties in
                                         appropriate cases.


This guidance contains a summary of some of the key obligations of accredited entities, including:
 record keeping obligations
 reportable incident obligations
 annual review and reporting obligations.
Accredited entities should refer to Guidance for accredited entities in Australia’s Digital ID System
available on the Digital ID System website for information about the ongoing obligations of
accredited entities.

This guidance contains general information only. It is not legal advice and is not a comprehensive or
exhaustive statement of all obligations accredited entities must comply with. Organisations should
seek their own professional advice about the Digital ID legislation.


34                                                            ACCC   |   Applying for accreditation   |   Version 1.3
13.1 Record keeping obligations
Accredited entities must comply with the record keeping requirements set out in the Accreditation
Rules. For example, accredited entities must prepare and keep records related to:
 cyber security incidents that cause, or are likely to cause, serious harm to one or more individuals
 digital ID fraud incidents
 data breaches.


           See rules 4.18, 4.35, 4.46 and 7.8 of the Accreditation Rules for the record keeping
                                                obligations.


Under the Accreditation Rules, certain records must be kept for a minimum of 3 years from the
day they were generated and must not contain biometric information. Additional record keeping
requirements apply to the destruction or de-identification of personal information that relates to
any current or anticipated legal or dispute resolution proceedings, or any current compliance or
enforcement investigations under the Act.

When destroying or de-identifying personal information, entities also need to comply with privacy
obligations under the Privacy Act 1988 (Cth) or applicable state or territory privacy laws.

For accredited entities participating in the AGDIS, there are additional record keeping obligations
under the Act and Digital ID Rules.


13.2 Reportable incident obligations
Accredited entities have obligations to report certain incidents to the Regulator within
specified timeframes.

The obligations to notify reportable incidents vary depending on whether the accredited entities are
providing their accredited services in:
 the AGDIS, or
 a digital ID system other than the AGDIS.
Under the Accreditation Rules, accredited entities must notify the Regulator of the reportable
incidents in the table below within the corresponding timeframes.

 An accredited entity must notify the Regulator:

    of any material change                                      Within 5 business days.

    of any matter that could reasonably be relevant to          Within 5 business days.
     whether the accredited entity, or an associated person
     of the accredited entity, is a fit and proper person

    of any change to, or error in, any of the information the   Within 5 business days.
     accredited entity has provided to the Regulator

    of any change in control of the accredited entity under     Within 72 hours of the entity becoming aware or the
     section 910B of the Corporations Act 2001 (Cth)             change in control occurring.

    if the entity intends to cease providing its accredited     As soon as practicable after forming the intent.
     services.


35                                                                    ACCC   |   Applying for accreditation   |   Version 1.3
To notify the Regulator of a reportable incident, entities must email the Regulator directly at
DigitalIDRegulator@accc.gov.au. The email subject line should clearly specify the type of incident and
that it constitutes a mandatory report.

In addition, accredited entities must provide the Regulator with a copy of any statement it gives to the
OAIC or another entity, as required under the Privacy Act 1988 (Cth) or a law of the state or territory
(notified entity), in relation to eligible data breaches or corresponding data breaches at the same time
as the statement is given to the OAIC or notified entity (see sections 39–41 of the Act).

For accredited entities participating in the AGDIS, there are additional notification obligations under
the Act and Digital ID Rules.

Failure to comply with certain notification requirements may result in enforcement action, including
proceedings seeking injunctions and/or substantial civil pecuniary penalties in appropriate cases.


      See Chapter 3 of the Digital ID Act and Chapter 7 of the Accreditation Rules for obligations
     relating to reportable incidents. For accredited entities that participate in the AGDIS, see also
                                    Chapter 4 of the Digital ID Rules.


13.3 Annual review and reporting
To maintain accreditation, accredited entities must conduct annual reviews and provide an annual
report to the Regulator.

The annual review reporting periods for accredited entities vary depending on whether the entity is a
transitioned entity under the Digital ID (Transitional and Consequential Provisions) Act 2024 (Cth) or an
entity accredited by the Regulator under the Act.

When submitting an annual report to the Regulator, accredited entities must also include an
attestation statement, signed by the accredited entity’s accountable executive, that attests to the
content of the report. This includes that in the relevant reporting period the entity met all its annual
review and reporting requirements, except for any non-compliance notified to the Regulator.

Accredited entities should refer to Guidance for accredited entities in Australia’s Digital ID System
available on the Digital ID System website for information about annual review requirements.


          See Chapter 6 of the Accreditation Rules for more information about annual review
                                            requirements.


36                                                            ACCC   |   Applying for accreditation   |   Version 1.3
Appendix A – Assessor
qualifications
The information below is intended to provide guidance on assessor qualifications. It is not intended
to be exhaustive, and an applicant should satisfy itself that an assessor is appropriately qualified to
conduct the relevant assessment.


Privacy impact assessment
When selecting assessors to undertake the required privacy impact assessment, applicants should
consider using assessors that have qualifications in privacy law and have experience in practicing
privacy law or privacy auditing. This can include assessors who are a Certified Information Privacy
Professional under the International Association of Privacy Professionals. The privacy assessment
must be conducted in consultation/coordination with the designated Privacy Officer of the applicant.


Fraud assessment
When selecting assessors to undertake the required fraud assessment, applicants could consider
the following:
 Government entities could utilise assessors that have undertaken relevant training through the
     following bodies:

     –   Commonwealth Fraud Prevention Centre
     –   Australian Government Investigation Standards (AGIS).

 Private entities could utilise assessors that are qualified and have an understanding of the
     Australian Standard AS8001 Fraud and Corruption Controls.


Protective security assessment
Relevant assessor qualifications to consider include:
 If the applicant utilises ISO/IEC 27001, in order to complete their protective security assessment,
     the assessor conducting the assessment must be accredited, or recognised, by the Joint
     Accreditation System of Australia and New Zealand (JASANZ) to certify entities against ISO/
     IEC 27001.
 If the applicant utilises a different security framework or standard from ISO/IEC/27001, they
     should ensure that the assessor meets the certification to conduct the assessment and maps the
     controls against ISO/IEC 27001. The applicant also needs to ensure the evidence is sufficient to
     cover the requirements under the Accreditation Rules.
 It is also recommended that the assessor be endorsed under the Australian Signals Directorate,
     Infosec Registered Assessors Program (IRAP), or have obtained the auditing qualification of an
     Infosec Registered Assessors Program. This could include but is not limited to:

     –   Certified Information Systems Auditor
     –   Certification in Risk and Information Systems


37                                                           ACCC   |   Applying for accreditation   |   Version 1.3
     –   GIAC Systems and Network Auditor certification
     –   ISO 27001 Lead Auditor
     –   PCI Qualified Security Assessor.


Penetration testing
The assessor for penetration testing could have qualifications relevant to Penetration Testing levels 4
or 5 outlined by the SFIA Foundation. The CREST (Council of Registered Ethical Security Testers) can
provide the information regarding Penetration Testing certification.


Useability testing
The assessors for useability testing could have qualifications that meets the User level of 4 or higher
under SFIA online User research URCH.


Web Content Accessibility Guidelines testing
Assessors used to undertake Web Content Accessibility Guidelines testing may be members of, or
certified under, associations or organisations such as the World Wide Web Consortium (W3C) or the
International Association of Accessibility Professionals (IAAP).


38                                                           ACCC   |   Applying for accreditation   |   Version 1.3
Appendix B – Evidence listed in
the accreditation application form

General Information – please note these documents
are mandatory
 Statement of scope and applicability
 Description of the DI Data Environment
 Evidence of technical testing (such as in the form of a requirements traceability matrix – see
     information under “technical testing” in section 9.4)
 Technical testing attestation statement
 Diagram showing corporate ownership (including percentages held by each owner)


Conditions
 Supporting evidence for any conditions sought by the applicant (if applicable)


Evidence it is appropriate to accredit the
organisation
 Evidence it is appropriate to accredit or approve the organisation form


Privacy
 Privacy impact assessment [mandatory]
 Organisation’s response to privacy impact assessment [mandatory]
 Privacy management plan(s)
 Privacy policy(s)
 Data breach response plan(s)
 Any other document supporting the applicant’s ability to comply with privacy requirements


Fraud
 Fraud assessment [mandatory]
 Organisation’s response to fraud assessment [mandatory]
 Fraud risk assessment [mandatory]


39                                                           ACCC   |   Applying for accreditation   |   Version 1.3
 Fraud control plan
 Fraud incident detection, investigation, response and reporting procedures
 Any other document supporting the applicant’s ability to comply with fraud requirements


Protective Security
 Protective security assessment [mandatory]
 Organisation’s response to protective security assessment [mandatory]
 Cyber security risk assessment [mandatory]
 System security plan
 Cloud services management plan (if applicable)
 Cloud services providers register (if applicable)
 Penetration testing report [mandatory]
 Essential strategies review report
 Protective security incident detection, investigation, response and reporting procedures
 Disaster recovery and business continuity plan
 Logging implementation and monitoring plan
 Any other document supporting the applicant’s ability to comply with protective security
     requirements


Accessibility and Useability
 Accessibility and useability assessment [mandatory]
 Organisation’s response to accessibility and useability assessment [mandatory]
 Useability testing report
 Web Content Accessibility Guidelines testing report
 Any other document supporting the applicant’s ability to comply with accessibility and useability
     requirements


Role specific requirements

Biometrics
 Biometric binding processes documentation
 Test plan and processes (as required)
 Ethical policies and procedures (as required)
 Presentation attack detection technology testing report [mandatory]
 Identity service provider’s response to presentation attack detection technology testing report
     (as required)


40                                                         ACCC   |   Applying for accreditation   |   Version 1.3
 Biometric matching algorithm testing report
 Evidence of source biometric matching testing
 eIDVT testing report
 Any other document supporting the applicant’s ability to comply with biometrics requirements


Identity proofing
 Identity proofing process
 Event logging implementation and monitoring plan
 Risk assessment for use of alternative proofing process (if applicable)
 Any other document supporting the applicant’s ability to comply with identity
     proofing requirements
 Alternative proofing proposal and processes (if applicable)


Authentication management
 Cryptographic key management processes and procedures
 Any other document supporting the applicant’s ability to comply with authentication requirements


Accredited identity service providers
 System design
 Any other document supporting the applicant’s ability to comply with the identity service provider
     requirements


Accredited identity exchange providers
 Digital ID system rules (for private organisations only who provide services in a system that
     includes non-accredited services)
 System design [mandatory]
 Any other document supporting the applicant’s ability to comply with identity exchange provider
     requirements


41                                                         ACCC   |   Applying for accreditation   |   Version 1.3
