Foreign Investment, FIRB & FOCI Security Compliance
Independent security assessment and assurance for foreign investors, defence-industry members and critical-infrastructure operators who must meet the security conditions attached to their investment or their government obligations.
What is FIRB and FOCI security compliance?
FIRB security compliance is the ongoing task of meeting the security conditions attached to a foreign-investment approval under the Foreign Acquisitions and Takeovers Act 1975. FOCI, foreign ownership, control or influence, is the parallel obligation carried by Defence Industry Security Program members and government suppliers. Both come down to the same work: understanding where a foreign interest could reach sensitive data, people or systems, putting proportionate controls in place, and demonstrating to a regulator that those controls are real and operating.


why choose us
Why Choose Agilient Security Services?
Agilient embraces continuous improvement with dynamic risk profiling, regular security audits, and business continuity management tools that build organisational resilience.

Industry Aligned and Customised Planning
Industry-aligned protection, supported by customised planning and free security tools and templates, aligns your risk and security management strategies with common organisational objectives.

Discreet and Confidential Service
Risk management security has been a vital part of our resilience solutions in high-stakes environments for many years. We understand the sensitivity of data and the importance of controls at every level of operations aligned with nationally approved security frameworks.

Lean and Agile Solutions
Agilient manages review and internal change requirements to the most cost-effective level possible. We tailor a risk management security plan tailored to the scale and context of your operations, focusing on essentials only, with an emphasis on continual review to meet evolving threats.
Why FIRB and FOCI Compliance Matters
Since the January 2021 national-security reforms, foreign-investment approvals increasingly carry security and data conditions, and the Government has expanded its audit and enforcement activity. With espionage and foreign interference assessed at extreme levels in the ASIO Annual Threat Assessment, these conditions exist to manage real risk, and demonstrable, independent compliance is what protects the investment.
the process
What is involved in a FIRB compliance audit?
Agilient works to a straightforward, evidence-led method that suits both the pre-approval and post-approval stages of a foreign-investment or FOCI engagement.

Scope Against the Conditions
We start from the specific wording of the no-objection notification, exemption certificate, variation letter, or DISP and contractual obligation, not a generic checklist.

Assess the Exposure
A security risk assessment of the data holdings, critical systems, and physical and personnel access points where a foreign interest could reach sensitive information.

Design Proportionate Controls
A security and data plan that maps each condition to a real control, benchmarked to the PSPF, the ISM, the SOCI risk program and ISO/IEC 27001 so the result is defensible.

Test and Assure Independently
An independent audit of the controls in place, identifying gaps against each condition and producing assurance reporting suitable for provision to Treasury or the regulator.

Report to the Regulator
Clear assurance reporting with the supporting evidence, representation letters and documentation the regulator expects, in a form the business can stand behind.

Sustain Recurring Assurance
Because most conditions are recurring, Agilient re-audits on the required cycle and keeps the evidence current as the business and its obligations change.
Contact Agilient for Professional Security Consulting
Agilient provides comprehensive security consulting to coordinate your resources and manage complex risks that could seriously harm your organisation. We identify vulnerabilities, reduce risk, improve compliance, and strengthen protection. Compared to the cost of breaches or cyberattacks, a consultation is minimal. Contact Agilient to manage your operations with confidence.
Agilient is appointed to multiple Australian Government procurement panels, including the Department of Home Affairs Security Services Panel, the DFAT Security Services Panel, and the Defence Support Services Standing Panel, so government clients can engage Agilient directly. Agilient is independent and vendor-neutral; its founder, Mark Bezzina, led the development of national risk and security standards as a former Executive Director of Standards Australia, and the team includes former senior Australian Defence, intelligence, and police personnel. Agilient is licensed to operate in New South Wales, the Australian Capital Territory, Victoria, Queensland and South Australia, and has delivered more than 300 projects for Australian organisations. Contact Agilient to discuss your requirements.
Security Solutions Nation-Wide
With a national footprint, our security consulting services support organisations across Australia in managing risk, compliance, and security strategy. We combine industry expertise with a practical approach to deliver consistent outcomes across all states and territories.
faqs
Frequently Asked Questions
An independent assessment of whether a foreign investor is meeting the security and data conditions attached to its approval, resulting in an assurance report that can be provided to Treasury. It is usually repeated at set intervals for recurring conditions.
A FOCI assessment identifies and evaluates foreign ownership, control or influence over a business, and the measures needed to manage it. Defence Industry Security Program members and many government suppliers must assess and report FOCI.
No. There is no published standard set of conditions. They are settled case by case, though the recurring themes are data location, access restrictions, governance, reporting and independent assurance.
An assessor independent of both the investor and the vendors whose systems are under review. A firm that supplies or maintains those controls has a conflict that weakens the assurance.
Ideally before. A credible, risk-based security and data plan presented at the application stage helps shape proportionate conditions and reduces later remediation.
