Foreign Investment, FIRB & FOCI Security Compliance

Independent security assessment and assurance for foreign investors, defence-industry members and critical-infrastructure operators who must meet the security conditions attached to their investment or their government obligations.

What is FIRB and FOCI security compliance?

FIRB security compliance is the ongoing task of meeting the security conditions attached to a foreign-investment approval under the Foreign Acquisitions and Takeovers Act 1975. FOCI, foreign ownership, control or influence, is the parallel obligation carried by Defence Industry Security Program members and government suppliers. Both come down to the same work: understanding where a foreign interest could reach sensitive data, people or systems, putting proportionate controls in place, and demonstrating to a regulator that those controls are real and operating.

Hands typing on a laptop with a digital data overlay
Laptop screen displaying a red warning alert symbol

why choose us

Why Choose Agilient Security Services?

Agilient embraces continuous improvement with dynamic risk profiling, regular security audits, and business continuity management tools that build organisational resilience. 

Line icon of a head silhouette with a cog

Industry Aligned and Customised Planning

Industry-aligned protection, supported by customised planning and free security tools and templates, aligns your risk and security management strategies with common organisational objectives. 

Line icon of an award medal

Discreet and Confidential Service

Risk management security has been a vital part of our resilience solutions in high-stakes environments for many years. We understand the sensitivity of data and the importance of controls at every level of operations aligned with nationally approved security frameworks.

Line icon of a badge with a tick and stars

Lean and Agile Solutions

Agilient manages review and internal change requirements to the most cost-effective level possible. We tailor a risk management security plan tailored to the scale and context of your operations, focusing on essentials only, with an emphasis on continual review to meet evolving threats.

Why FIRB and FOCI Compliance Matters

Since the January 2021 national-security reforms, foreign-investment approvals increasingly carry security and data conditions, and the Government has expanded its audit and enforcement activity. With espionage and foreign interference assessed at extreme levels in the ASIO Annual Threat Assessment, these conditions exist to manage real risk, and demonstrable, independent compliance is what protects the investment.

the process

What is involved in a FIRB compliance audit?

Agilient works to a straightforward, evidence-led method that suits both the pre-approval and post-approval stages of a foreign-investment or FOCI engagement.

Line icon of a padlock inside a warning triangle

Scope Against the Conditions

We start from the specific wording of the no-objection notification, exemption certificate, variation letter, or DISP and contractual obligation, not a generic checklist.

Line icon of a browser window with a security shield

Assess the Exposure

A security risk assessment of the data holdings, critical systems, and physical and personnel access points where a foreign interest could reach sensitive information.

Line icon of a hooded figure with a padlock

Design Proportionate Controls

A security and data plan that maps each condition to a real control, benchmarked to the PSPF, the ISM, the SOCI risk program and ISO/IEC 27001 so the result is defensible.

Line icon of a group of people with a padlock

Test and Assure Independently

An independent audit of the controls in place, identifying gaps against each condition and producing assurance reporting suitable for provision to Treasury or the regulator.

Line icon of a shield with a padlock

Report to the Regulator

Clear assurance reporting with the supporting evidence, representation letters and documentation the regulator expects, in a form the business can stand behind.

Line icon of a hand holding a shield with a padlock

Sustain Recurring Assurance

Because most conditions are recurring, Agilient re-audits on the required cycle and keeps the evidence current as the business and its obligations change.

Contact Agilient for Professional Security Consulting

Agilient provides comprehensive security consulting to coordinate your resources and manage complex risks that could seriously harm your organisation. We identify vulnerabilities, reduce risk, improve compliance, and strengthen protection. Compared to the cost of breaches or cyberattacks, a consultation is minimal. Contact Agilient to manage your operations with confidence. 

Agilient is appointed to multiple Australian Government procurement panels, including the Department of Home Affairs Security Services Panel, the DFAT Security Services Panel, and the Defence Support Services Standing Panel, so government clients can engage Agilient directly. Agilient is independent and vendor-neutral; its founder, Mark Bezzina, led the development of national risk and security standards as a former Executive Director of Standards Australia, and the team includes former senior Australian Defence, intelligence, and police personnel. Agilient is licensed to operate in New South Wales, the Australian Capital Territory, Victoria, Queensland and South Australia, and has delivered more than 300 projects for Australian organisations. Contact Agilient to discuss your requirements.

OUR LOCATIONS

Security Solutions Nation-Wide

With a national footprint, our security consulting services support organisations across Australia in managing risk, compliance, and security strategy. We combine industry expertise with a practical approach to deliver consistent outcomes across all states and territories.

faqs

Frequently Asked Questions

An independent assessment of whether a foreign investor is meeting the security and data conditions attached to its approval, resulting in an assurance report that can be provided to Treasury. It is usually repeated at set intervals for recurring conditions.

A FOCI assessment identifies and evaluates foreign ownership, control or influence over a business, and the measures needed to manage it. Defence Industry Security Program members and many government suppliers must assess and report FOCI.

No. There is no published standard set of conditions. They are settled case by case, though the recurring themes are data location, access restrictions, governance, reporting and independent assurance.

An assessor independent of both the investor and the vendors whose systems are under review. A firm that supplies or maintains those controls has a conflict that weakens the assurance.

Ideally before. A credible, risk-based security and data plan presented at the application stage helps shape proportionate conditions and reduces later remediation.

Security operators monitoring screens in a control room