Client onboarding that stalls while someone chases ID documents and proof of address by email.
Tech for accounting and bookkeeping firms
Managed IT, cyber security and AI for New Zealand accounting practices. Keep client data safe, meet your AML obligations, and stop losing billable hours to data entry.
- 30 years in NZ business IT
- 4.9 from 95+ Google reviews
- NZ owned and operated
- SMB1001 aligned
The work that quietly costs you a day a week
Practice data spread across the practice management system, a shared drive, Xero and everyone's inbox.
The three months either side of tax time where nobody has capacity and everything manual becomes a bottleneck.
A phishing email that looks like a client asking you to change their refund bank account.
One partner, three jobs.
Managed IT, cyber security and AI for accounting & bookkeeping, under one agreement with one team accountable for all of it.
Always-on support
Managed IT
Fast, reliable support through compliance season, and a helpdesk that answers in about 25 minutes.
Learn moreProtection without panic
Cyber
Protect client financial records and prove your controls to clients, insurers and the DIA.
Learn moreUseful AI that ships
AI
Take the manual keying out of onboarding, reconciliations and client queries.
Learn moreAI built for accounting & bookkeeping.
Not AI in general. These are the specific workflows we automate in this industry, and the reason this page exists.
AML client onboarding
ID and address documents collected, checked and filed against the client record, with a clear trail of who verified what and when.
Document intake and coding
Client receipts, invoices and bank statements read and coded automatically instead of typed in one at a time.
Client query handling
Ask a plain question and get the answer out of your own files, workpapers and prior year returns.
Deadline and information chasing
Automatic follow-up on outstanding client records so nobody has to build the chase list by hand in March.
Proposal and engagement letters
Turn scope notes into a first-draft engagement letter or fee proposal in minutes, ready for you to check.
What your clients and insurers now ask you to prove.
As a reporting entity under the AML/CFT Act you already carry obligations most businesses don't, and the 1 July 2026 verification changes raised the bar again. We make the technical side of that boring: client records held securely, access limited to the people who need it, an audit trail that exists without anyone maintaining it, and evidence you can hand an auditor rather than assemble.
The rest is the same baseline we hold every client to. We map your setup against SMB1001, keep the Privacy Act side clean, and every agreement includes a cyber security assessment so you know your real position early rather than after an incident.
See our cyber security servicesReal businesses. Real outcomes.
AR & Associates Switches from a Solo IT Provider Seamlessly
AR & Associates had outgrown a one-person IT provider and needed a team behind them. We moved them across without a day of lost productivity, and gave them proper cover for the times of year that matter.
Read the case studyFrom signature to steady state.
A structured handover designed to minimise disruption and build trust before BAU begins.
-
Day 1
Onboarding
Kickoff & access
-
Day 14
Documentation
Full env capture
-
Day 30
Go Live
Cutover to iT360
-
Day 45
Post-Onboarding
Review meeting
-
Day 60
AM Handover
Account manager assigned
-
Day 75
Cyber Assessment
Baseline + roadmap
-
Day 100
AI Workshop
Quarterly BAU starts
Why businesses choose iT360 over the rest.
Typical IT Providers
- Just keeping the lights on
- Slow, patchy support
- Generic service
- One-size-fits-all
- Tech for tech's sake
The iT360 Way
- Always on, always accountable
- Driving growth, not just uptime
- Genuine partnership
- Solutions that scale
- Smart, secure, strategic
Frequently asked questions
Can you support us through tax time without adding risk?
Yes, and it's the season we plan around. Support is remote first, so someone stuck mid-return gets a person on the phone in about 25 minutes, and inside the hour if the firm has stopped working. We deliberately don't schedule change work into your busiest months, because a well-intentioned upgrade in the wrong week costs you more than it saves. If we think something can't wait, we'll say why and let you make the call.
Do we have to move off our practice management system?
No. Xero Practice Manager, MYOB, APS, Iris, FYI, whatever mix you've ended up with, we work with it and connect it up. Changing a core system is a business decision, not something your IT provider should push. The one exception is software that can't be secured or that the vendor has stopped supporting. We'll tell you straight if you're in that spot, show you the risk, and price the options before anything moves.
What does the AML side actually look like day to day?
Mostly it means the evidence exists without anyone building it. Client ID and address documents get collected through one channel, checked, and filed against the client record with a timestamp and a name attached. Access is limited to the staff who need it. When you're audited, you produce a trail instead of reconstructing one from email. We don't give you legal advice on your AML programme, that's your compliance adviser's job, but we make sure the systems side supports what your programme says you do.
How real is the risk of a client refund being redirected?
Real enough that we see it. The pattern is always the same: someone gets into an email account, reads quietly until they find a payment conversation, then sends a message changing the bank account. Nothing looks broken, so nobody checks. The fixes are unglamorous and they work: MFA on every account, monitoring that flags a login from somewhere odd, and a firm rule that any change of bank details is confirmed by phone on a number you already had.
Will AI touch client data we're not allowed to expose?
Not without you deciding it should. Automations run inside your own Microsoft 365 tenancy by default, so client data stays where it already lives rather than being handed to a public tool. Anything that would send data somewhere else gets flagged, explained and agreed before it's built, not after. And nothing goes to a client without a person reading it first.
What does this cost?
Managed IT is a fixed monthly fee per person covering helpdesk, monitoring, maintenance, backups and the security baseline. Automation is quoted per build against a fixed scope. What it comes to depends on headcount, devices, whether there's a server, and how much of your practice stack needs connecting, so any number on a website would be made up. The review costs nothing and you'll have real pricing before you decide anything.
Book a free accounting tech and AI review.
We work the same way across these.
Legal
Privileged client data properly protected, AML-ready onboarding, and automation for the document and time-recording grind.
See the pageFinance & Financial Services
Client data held to the standard the FMA expects, AML-ready onboarding, and automation for advice paperwork and reviews.
See the pageReal Estate & Property
AML-ready client checks, protected deposit and client data, and automation for listings, appraisals and follow-up.
See the page