GS 007 Audit 

Build trust with a GS 007 audit. Demonstrate compliance with investment mandates and the related registry, administration, and custody activities.

Untitled-design-11
2026_ARIZENT_ACCOUNTING-TODAY_TOP-100-FIRMS_LOGO_RGB
Untitled-design-3
Untitled design (9)
Untitled design (8)
Untitled design (7)
Untitled-design-9-2

Build Trust and Simplify Compliance With GS 007

Guidance Statement 007 (GS 007) is an Australian reporting framework tailored for the financial services industry. GS 007 outlines defined control objectives across key areas such as investment management, fund administration, registry, and custody, demonstrating the secure and responsible handling of client assets.

Robust internal controls aren’t just a compliance requirement—they’re a signal to your clients that their assets are in safe hands. By aligning with GS 007, your organization can enhance transparency, strengthen operational integrity, and build long-term trust with customers and stakeholders.

As a registered CPA and Chartered Accountant firm, we deliver comprehensive GS 007 audit services with a cloud-native, agile approach. Our process is designed to reduce disruption, streamline compliance efforts, and move at the pace that works best for your business.

Four Steps to a GS 007 Audit

GS 007

Jun 20

GS 007 Readiness Assessment

We integrate with leading compliance platforms to deliver a clear, customized view of your control environment. Our readiness assessments help you identify gaps early so you can streamline your path to GS 007 assurance.

Jun 20

Practical Remediation

When gaps appear, we’re here to help you close them efficiently. Our team works with yours to implement practical processes that align with your organization’s culture and GS 007 objectives.

Jun 20

GS 007 Type 1 Report

Our tech-enabled GS 007 Type 1 assessments are designed to fit seamlessly into your schedule. With collaborative, milestone-based reviews, we help you stay on track while uncovering meaningful opportunities to strengthen your control framework and reporting.

Jun 20

GS 007 Type 2 Report

We offer year-round and fixed-schedule GS 007 Type 2 engagements that minimize disruption while delivering the assurance your stakeholders expect.

The Benefits of Certification 

Global Recognition

Build trust with clients, regulators, and stakeholders by earning a certification that’s respected across industries and borders.

Client Confidence

Share a comprehensive attestation report that addresses key due diligence questions and helps reassure customers and prospects.

Low Disruption

With flexible timing and streamlined processes, we help you meet deadlines while keeping your business running smoothly.

Foundation for Broader Compliance

GS 007 certification can support alignment with other frameworks and standards, providing a strategic step toward multi-standard compliance.

Progress That Counts

We can help you earn a GS 007 report while process improvements are underway, highlighting your progress and commitment to continuous improvement.

High Impact

Customizable compliance targets choose from a range of control objectives to align your certification with your business goals.

FAQs

What is GS 007 Reporting?

GS 007, or Guidance Statement 007, is an Australian assurance framework developed for financial services organizations. It outlines control objectives related to key investment management services, including custody, fund administration, registry, and information technology.

While GS 007 reporting is optional, it provides a powerful tool to build customer confidence. By demonstrating that your systems operate in accordance with relevant client agreements and industry expectations, GS 007 reporting helps establish trust, improve operational transparency, and streamline compliance.

GS 007 reporting covers the following investment management services:

A. Custody
B. Asset Management
C. Property Management
D. Superannuation Member Administration
E. Administration
F. Investment Administration
G. Registry
H. Information Technology

Which areas of GS 007 do we cover?

We currently support GS 007 reporting for the following sections:

• Section A – Custody
• Section B – Asset Management
• Section E – Investment Administration
• Section F – Registry
• Section G – Information Technology

We begin with a readiness assessment, mapping your systems, processes, and controls to the GS 007 objectives. From there, we identify any control gaps and help you prepare for a smooth, successful audit.

Currently, we do not cover:

• Section C – Property Management
• Section D – Superannuation Member Administration

Do I have to meet all investment management services to meet the GS 007 reporting requirements?

Not at all. Only the services relevant to your business operations are included in the scope of your GS 007 audit. The framework is designed to be flexible and tailored to your service offerings.

Type 1 and Type 2 reports: What's the difference?

A Type 1 report provides point-in-time assurance that your control design meets the GS 007 criteria. It shows that appropriate systems and processes are in place.

A Type 2 report offers assurance over a defined period—typically 3 to 12 months—that your controls exist and are operating consistently as intended.

Most organizations begin with a Type 1 report to baseline their compliance and move into an annual Type 2 audit cycle for ongoing validation.

Can you fail a GS 007 audit?

GS 007 reports aren’t pass/fail. However, they can be issued with exceptions or qualifications. Many companies opt to delay issuance until they can present a “clean” report. If you’re on a set reporting cycle with client obligations, a report may be issued with notes explaining any exceptions or control deficiencies.

Does GS 007 overlap with commonly required security compliance?

There is considerable overlap with other security and operational assurance frameworks such as SOC 1, SOC 2, and ISO/IEC 27001. Like these standards, GS 007 emphasizes the importance of robust internal controls, particularly around system security and process integrity.

SOC reports focus on the design and operating effectiveness of specific controls.
ISO 27001 looks at your broader Information Security Management System (ISMS) and prescribes a systematic approach to risk.

Each framework has a different lens, but they all aim to strengthen trust and compliance in your operations.

Can we use compliance automation platforms for GS 007?

GS 007 does not prescribe a fixed number of audit days, so compliance automation platforms can support a more efficient and scalable audit process. However, the success of automation depends on the compatibility between your control environment, the platform’s capabilities, and your auditor’s familiarity with the tool.

We integrate with leading compliance automation platforms to help you streamline your GS 007 audit while maintaining flexibility and alignment with your business processes.

NEWS, EVENTS, AND INSIGHTS

Related Governance, Risk, and Compliance Resources

Insight

Someone presenting

Understanding GS 007: Australia’s Assurance Framework for Investment Services

Case Study

ISO/IEC 27001 Case Study: Block Earner

Case Study

SOC 2 Case Study: Vertiseit

White Paper

CMMC Readiness Assessment Checklist white paper cover with a person on it

CMMC Readiness Assessment Checklist

Insight

Somone holding a tablet

AI Accuracy: Building Enterprise Trust Through Third-Party Attestation

Insight

Two people sitting at a desk

NIST vs. CMMC: Understanding the Security Mandate for DoD Contractors

White Paper

Consumer Data Right (CDR) and AWS Security 

Let’s talk about your project.

Whether you need to unravel a complex challenge, launch a new initiative, or want to take your business to the next level, we’re here. Share your vision and we can help you achieve it.