Foreign investment into Australia is rarely a simple yes or no. Where the Treasurer approves an acquisition, the approval increasingly arrives with conditions attached, and a growing share of those conditions deal with security: how sensitive data is stored and accessed, who can reach critical systems, and how the investor proves, on an ongoing basis, that it is doing what it agreed to do. For many investors, meeting those conditions has become a standing obligation that outlasts the deal itself.
Key takeaways
- FIRB approvals are frequently granted subject to conditions, and since the January 2021 national-security reforms those conditions have focused heavily on data and security.
- Some conditions require the investor to commission an independent audit and provide an assurance report to Treasury, rather than simply self-attesting.
- Standard security conditions are not published; they are negotiated case by case and commonly cover data location, access controls, governance, and reporting.
- The same foreign-influence question drives FOCI obligations for Defence Industry Security Program members and government suppliers.
- Independence is central: the assessor should have no commercial interest in the systems or equipment being reviewed.
What are FIRB conditions, and why do they now focus on security?
The Foreign Investment Review Board advises the Treasurer on whether a proposed foreign investment is consistent with Australia’s national interest, under the Foreign Acquisitions and Takeovers Act 1975. Where a proposal is approved, the Treasurer can attach conditions to the no-objection notification. Compliance with those conditions is monitored by Treasury for commercial investments.
Reforms that commenced on 1 January 2021 sharpened the national-security element of the regime. They introduced a dedicated national-security test, a notifiable national security action pathway, and call-in and last-resort review powers. In practice, investments touching sensitive sectors are now examined for the risk of espionage, sabotage and foreign interference, and conditions are used to manage the residual risk that approval leaves behind. That risk is not hypothetical: the ASIO Annual Threat Assessment describes espionage and foreign interference against Australia at extreme levels, with foreign services targeting defence, critical infrastructure and the data that sits behind them.
Which investments attract security conditions?
The heaviest scrutiny falls on assets where a loss of control or confidentiality would cause national harm. A foreign person acquiring a direct interest of 10 per cent or more in a national-security business, or starting one, faces a notifiable national security action with a nil monetary threshold, meaning value alone does not exempt it. Beyond that defined category, security and data conditions commonly appear in dealings involving:
- Critical infrastructure, including energy, water, ports, communications and data-storage assets regulated under the Security of Critical Infrastructure Act.
- Businesses holding large volumes of personal, health, or otherwise sensitive data on Australians.
- Defence-adjacent suppliers, and technology, minerals and advanced-manufacturing assets.
What does a FIRB compliance audit involve?
Where a condition requires independent assurance, the investor engages a third party to test whether the business is actually meeting the conditions set out in its no-objection notification, exemption certificate, or variation decision letter, and to report the result. A typical security audit establishes the scope with reference to the specific conditions, gathers evidence of the controls in place, identifies any gaps against each condition, and produces an independent assurance report for provision to Treasury. Many conditions are recurring, so the audit is repeated at defined intervals rather than done once.
The value of the exercise is not only the report. A well-run audit also shows the investor where compliance is fragile before a regulator finds it, and turns a set of legal obligations into a practical control framework the business can operate.
What do standard FIRB security conditions require?
There is no published set of standard data-security conditions; the Board has said this remains an area of active development, and conditions are settled case by case. That said, the measures that recur across approvals are reasonably consistent, and commonly include:
- Storing Australian data onshore, in facilities that meet defined security requirements.
- Restricting access to sensitive data and systems, including limits on access by overseas personnel and by upstream investors.
- Governance and physical access controls over the premises and systems that hold protected information.
- Record-keeping of any offshore or privileged access, and periodic reporting to Treasury.
- Independent audit or assurance against the above, provided to the regulator on request or on a set cycle.
These are typically benchmarked against recognised frameworks, such as the Protective Security Policy Framework, the ASD Information Security Manual, the risk-management obligations under the Security of Critical Infrastructure Act, and ISO/IEC 27001 for information security management. Aligning the business to a recognised framework early makes later assurance far simpler.
How does this relate to FOCI and defence obligations?
The foreign-investment regime is not the only place this question is asked. Defence Industry Security Program members, and many government suppliers, carry a parallel obligation to identify and manage foreign ownership, control or influence, known as FOCI, over their business, and to report it. The underlying discipline is the same as a FIRB condition: understand where a foreign interest can reach sensitive people, systems or information, and put proportionate controls around it. An organisation that has already done this work for its Defence Industry Security Program membership is well placed to meet a foreign-investment security condition, and the reverse is equally true.
Why does independence matter in a FIRB audit?
A condition that calls for an independent assessment is undermined if the assessor has a stake in the outcome. A firm that sells, installs or maintains the security systems under review cannot credibly attest to their adequacy, and a regulator is entitled to weigh that conflict. Genuine independence, from both the investor and the vendors whose products sit in the control environment, is what gives an assurance report its weight.
How should an investor prepare before approval?
The strongest position is built before conditions are imposed, not after. An investor who can show the Treasurer a credible, risk-based security and data plan at the application stage is better placed to shape proportionate conditions than one who leaves the design to the regulator. Practical preparation includes a security risk assessment of the target’s data and critical assets, a clear picture of who can access what and from where, and a remediation plan for the gaps that assessment surfaces.

How Agilient can assist
Agilient is an independent, vendor-neutral security, risk and resilience consultancy. Because it does not sell or install security equipment, it can provide genuinely independent assessment of the controls a FIRB condition targets, without the conflict that comes from auditing one’s own products. Agilient is a Defence Industry Security Program member, and its consultants have long conducted foreign-ownership and national-security risk reviews for defence-industry and government clients, which is the same discipline a foreign-investment condition calls for.
That work is grounded in real sector experience. Agilient’s consultants have delivered security risk assessments and audits across most of the asset classes regulated under the Security of Critical Infrastructure Act, including electricity generation and distribution, gas and water utilities, ports and maritime, aviation, public transport and rail networks, telecommunications and data centres, and health care. The same experience extends to places of mass gathering, such as stadiums, convention and exhibition centres, cultural institutions and major public venues, and to defence and defence industry, financial services, and government and its suppliers. This is the same population of assets and operators where foreign-investment and FOCI security conditions most often apply.
Agilient supports foreign investors and their advisers at both ends of the process. Before approval, it can conduct a security risk assessment of the target’s data holdings, critical systems, and physical and personnel access, and help shape a defensible security plan to accompany the application. After approval, it can perform the independent compliance audit against the imposed conditions and produce the assurance reporting Treasury expects.
Frequently asked questions
What is a FIRB compliance audit?
It is an independent assessment of whether a foreign investor is meeting the security and data conditions attached to its foreign-investment approval, resulting in an assurance report that can be provided to Treasury. It is usually repeated at set intervals for recurring conditions.
Are FIRB security conditions the same for every investment?
No. There is no published standard set of conditions. They are negotiated case by case, though the recurring themes are data location, access restrictions, governance, reporting and independent assurance.
Who can perform an independent FIRB audit?
An assessor independent of both the investor and the vendors whose systems are being reviewed. A firm that supplies or maintains the security controls in question has a conflict that weakens the assurance.
What is the difference between FIRB conditions and FOCI?
FIRB conditions attach to a foreign-investment approval. FOCI, foreign ownership, control or influence, is an obligation on Defence Industry Security Program members and government suppliers. Both require an organisation to identify and manage foreign influence over sensitive systems and information.
When should security advice be sought, before or after approval?
Ideally before. A credible, risk-based security and data plan presented at the application stage helps shape proportionate conditions and reduces the remediation required later.
References
- Foreign Investment Review Board / The Treasury, Foreign Acquisitions and Takeovers Act 1975 and the foreign investment framework, foreigninvestment.gov.au
- Foreign Investment Review Board, Guidance Note: National security, foreigninvestment.gov.au
- Australian Security Intelligence Organisation, Director-General’s Annual Threat Assessment 2026, asio.gov.au
- The Treasury, Foreign investment reforms (commenced 1 January 2021), treasury.gov.au
