SISS Data Services has recently completed an uplift to the latest version of ISO 27001: the 2022 version. This further strengthens their already robust security framework, so clients can be confident their data is handled safely, securely and in line with global best practice.
Raising the bar on security
ISO 27001 is the leading international standard for managing information security, setting out how organisations protect data, manage risk and respond to incidents. SISS has upgraded its certification to the latest 2022 version, which introduces new controls designed for today’s cloud-based, always on environment.
This uplift builds on more than a decade of experience delivering secure financial data and Open Banking services to software platforms and over 500,000 Australians. It reinforces SISS’s position as Australia’s leading independent provider of secure, accounting-grade data and CDR compliant Open Banking APIs.
Future ready protection for your data
The ISO 27001:2022 update adds specific controls for business continuity, ensuring SISS is prepared for modern cyber risks and outages. These controls help SISS anticipate emerging threats, harden its cloud environments and recover quickly if something goes wrong, to help prevent interruptions of to clients’ services.
There are also enhancements for data masking, data leakage prevention and secure coding practices, which further protect sensitive financial information moving through SISS platforms. For clients, this means their data is shielded by stronger safeguards at every stage: in transit, at rest and within applications.
Designed for modern business
As more businesses embrace cloud and remote work, ISO 27001:2022 places greater emphasis on secure use of cloud providers and teleworking. SISS aligns with this by operating its ACSISS solutions on Microsoft Azure in Australia, with encryption, independent security reviews and resilience built in.
Business continuity is also front and centre, with the new ICT readiness for business continuity control complementing SISS’s existing disaster recovery and monitoring programs. These measures help ensure that, even in the face of disruption, clients can continue to access the accurate, up to date bank data they rely on.
Strong governance and assurance
ISO 27001:2022 refines governance expectations, clarifying roles, responsibilities and segregation of duties to strengthen accountability across the organisation. For SISS, this supports a culture where security is embedded from leadership through to operations, not treated as an afterthought.
SISS already operates under strict risk management, incident response and compliance obligations as an Accredited Data Recipient under the Consumer Data Right (CDR). The updated standard enhances this framework, providing additional structure around how risks are assessed, treated and regularly reviewed.
Why this matters for SISS clients
For clients, the ISO 27001:2022 uplift is a clear signal that SISS is investing ahead of the curve in security, compliance and resilience. It means working with a partner whose controls are independently audited against a globally recognised benchmark, and whose systems are designed to meet stringent Australian regulatory expectations including CDR.
In practical terms, choosing SISS means choosing a platform that is ISO 27001 certified, CDR accredited and proven at scale across banks, fintechs and accounting software with customers like Intuit QuickBooks and Oracle NetSuite. For organisations handling sensitive financial data, this combination of certification and accreditation makes SISS a safe choice for secure data sharing and Open Banking.


