How Secure AGM Voting Protects Members, Directors and Organisations
Tuesday, 11 August 2026, 8:05 pm
An AGM might only last a few hours, but the decisions made during it can affect an organisation for months or even years.
Directors may be elected. Resolutions may be approved. Members may decide on constitutional changes. Shareholders may vote on significant corporate matters.
That makes the voting process more than an administrative exercise.
It needs to be accurate, secure, transparent and capable of standing up to scrutiny afterwards.
This becomes particularly important when an AGM involves hundreds or thousands of members, proxy votes, different voting entitlements, remote participants or sensitive member information.
A secure AGM voting system helps address those risks by controlling who can vote, protecting voting information, recording what happened and producing a reliable record of the final result.
For companies using virtual or hybrid meetings, there is another consideration: members must be given a reasonable opportunity to participate. ASIC specifically expects the technology used for virtual meetings to support meaningful participation, including asking questions, making comments and voting.
The goal isn’t simply to make voting digital.
The goal is to make the entire voting process defensible.
What is secure AGM voting?
Secure AGM voting is the use of controlled processes and technology to ensure that eligible members can cast valid votes while protecting the confidentiality, integrity and availability of voting information.
A well-designed system should address several questions:
These questions apply whether voting happens in a physical meeting, a hybrid AGM or a fully virtual meeting.
For companies covered by the Corporations Act 2001 (Cth), the legislation allows meetings to be held at physical venues, using physical venues and virtual meeting technology, or using virtual meeting technology only where the constitution expressly requires or permits it. The Act also requires members as a whole to have a reasonable opportunity to participate.
That makes the choice of voting technology a governance issue, not merely an IT decision.
Why AGM voting security matters
There are three groups with a lot at stake in an AGM vote:
Each group faces a different risk.
Protecting members and shareholders
Members need confidence that their vote will be counted correctly and that their personal information will not be unnecessarily exposed.
Consider a contested board election.
If members believe that another person could access their voting credentials, that votes could be altered, or that the organisation could see how they voted when the ballot was intended to be confidential, confidence in the election can quickly disappear.
Security therefore has a direct connection with member trust.
A voting system should separate voter eligibility and authentication from the confidentiality requirements of the ballot wherever the voting rules require an anonymous or secret vote.
Protecting directors and office bearers
Directors and committee members are often responsible for ensuring that the organisation’s governance processes are properly administered.
A poorly controlled voting process can create difficult questions afterwards:
A secure and auditable process gives directors something much more useful than a spreadsheet containing a final number.
It gives them evidence of how that number was reached.
Protecting the organisation
The organisation has operational, legal and reputational interests in getting the process right.
A disputed election can delay appointments. A disputed resolution can create uncertainty around subsequent decisions. A privacy incident can damage member confidence.
The risks become greater when voting data is combined with member databases, proxy appointments, shareholder information or other personal information.
The Office of the Australian Information Commissioner (OAIC) says organisations covered by the Privacy Act must take reasonable steps to protect personal information from misuse, interference and loss, as well as unauthorised access, modification or disclosure. The OAIC also recommends considering security throughout the information lifecycle.
The five pillars of secure AGM voting
Security isn’t one feature.
A genuinely secure AGM voting process normally combines several controls.
1. Voter authentication and eligibility
The first question is simple:
Is this person entitled to vote?
Depending on the organisation, voter validation might involve:
The right approach depends on the organisation and its governing rules.
For example, a company election involving shareholders with different voting entitlements may require considerably more complex validation than a small association where every financial member has one vote.
The important point is that authentication should not be treated as an afterthought.
The system should establish eligibility before the vote is accepted.
2. Protection of the ballot
Authentication and ballot secrecy are not necessarily the same thing.
An organisation may need to verify that a particular member is entitled to vote while ensuring that the member’s individual choices remain confidential.
This is especially relevant for:
A secure voting architecture should therefore consider what information needs to be linked together — and what information should remain separated.
Collecting more information than necessary can also increase risk. OAIC guidance recommends considering whether personal information is reasonably necessary to collect in the first place and taking a lifecycle approach to how that information is stored, accessed and ultimately destroyed or de-identified.
3. Accurate vote counting
Security is not only about preventing hackers.
It is also about preventing administrative mistakes.
AGM voting can involve:
A system that securely records the wrong voting entitlement is still a governance problem.
This is why the voting rules should be configured before the AGM and tested using realistic scenarios.
For example, suppose an organisation has:
The voting system should not simply count the number of clicks.
It needs to apply the rules that determine which votes count and how they count.
4. A reliable audit trail
One of the most valuable features of secure electronic voting is the ability to retain an appropriate record of the voting process.
An audit trail can help answer questions such as:
The purpose isn’t to expose confidential individual votes.
It is to provide sufficient evidence to reconstruct and verify the process without compromising ballot secrecy.
That distinction matters.
A good audit trail should increase transparency without undermining voter confidentiality.
For listed entities, ASX Guidance Note 35 also recognises the importance of the voting process, voting exclusions, scrutineers and reporting voting results in the context of security holder resolutions.
5. Security controls around the platform
The voting application is only one part of the security picture.
Organisations should also consider:
The Australian Signals Directorate’s Essential Eight provides a useful baseline for organisations considering broader cyber security controls, including multi-factor authentication, restricting administrative privileges, patching, application control and backups.
For organisations assessing a voting provider, it’s worth asking not just “Is the voting page encrypted?” but:
What security framework sits behind the voting platform?
Why ISO 27001 matters when choosing a voting provider
Security claims are easy to make.
Independent certification provides stronger evidence.
ISO/IEC 27001:2022 is an international standard for information security management systems. It sets requirements for establishing, implementing, maintaining and continually improving an information security management system. ISO describes the standard as a risk-based approach covering the confidentiality, integrity and availability of information.
For an organisation selecting an AGM voting provider, ISO 27001 certification can therefore be a useful part of the supplier due-diligence process.
It doesn’t mean a system can never be compromised.
No responsible security professional should make that promise.
Instead, certification provides evidence that the provider operates an established information security management system and has undergone an independent conformity assessment process.
Organisations should still ask what the certification covers, who certified it and whether the scope includes the systems and services being purchased.
Secure AGM voting is also about privacy
An AGM voting platform may handle more information than the final vote count suggests.
Depending on the organisation, this could include:
The Privacy Act 1988 applies to APP entities, including many organisations with annual turnover above $3 million and certain other organisations regardless of turnover. The precise application depends on the entity and the circumstances.
Where the Privacy Act applies, APP 11 requires reasonable steps to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure.
That means privacy should be considered when selecting and configuring an AGM voting system.
It should not be something the organisation thinks about after the election.
Ask where the data goes
When assessing a voting provider, ask:
OAIC guidance specifically identifies third-party providers, including cloud computing providers, as an area organisations should consider when protecting personal information.
Secure voting and member confidence go together
There is another side to security that is often overlooked.
Members need to understand that the process is secure.
A technically sophisticated system is not much help if members don’t trust it.
Clear instructions can make a significant difference.
Before the AGM, members should understand:
This is particularly important for hybrid and virtual meetings.
ASIC states that companies must provide members as a whole with a reasonable opportunity to participate, and virtual meeting technology must support relevant participation rights.
A member who cannot vote because they cannot access the platform is not simply experiencing a technical inconvenience.
It can become a governance issue.
Common AGM voting security mistakes
Relying on a generic meeting platform alone
Video conferencing software is excellent for communication.
It isn’t necessarily designed to manage complex voting entitlements, proxies, elections or formal ballot processes.
The meeting platform and voting platform can work together, but they serve different purposes.
Treating a spreadsheet as the source of truth
Spreadsheets can be useful for preparing voter data.
They become risky when they’re being used to manually reconcile eligibility, proxies, voting rights and final results during a live AGM.
Manual processes create opportunities for transcription errors and inconsistent records.
Using the same credentials for everyone
If everyone receives the same meeting password or generic voting access, it becomes difficult to establish who actually voted.
Individualised access is generally much easier to control and audit.
Ignoring administrator access
People often focus heavily on voter security while overlooking administrative accounts.
An administrator with excessive privileges can potentially make changes that have a greater impact than an ordinary voter.
Administrative access should therefore be limited, controlled and monitored.
Failing to test unusual scenarios
A system may work perfectly when everyone follows the expected workflow.
The real test is what happens when:
Testing these scenarios before the AGM is far cheaper than discovering the problem while hundreds of members are watching.
A practical security checklist for your next AGM
Before selecting or approving an AGM voting system, ask these questions.
Governance
Voter security
Ballot integrity
Auditability
Privacy
Cyber security
Meeting participation
Where Vero Voting can assist
For organisations that need more than a simple online poll, Vero Voting provides voting and meeting services designed around formal governance processes.
Vero supports virtual, hybrid and in-person AGMs, including live voting, proxy management, elections and member resolutions. Its AGM solution can also integrate with commonly used meeting platforms such as Zoom, Microsoft Teams and Webex.
The voting process can be configured around the organisation’s particular requirements, including different member rights, voting entitlements and proxy arrangements.
Vero also provides an independently managed voting process, with auditability and verification built into the workflow rather than relying on a manually prepared result at the end.
From a security perspective, Vero Voting states that its information security management system is certified to ISO/IEC 27001:2022 and independently audited.
That matters because the question organisations should be asking is not simply:
“Can this software run a vote?”
It should be:
“Can this voting process produce an outcome we can confidently defend?”
What secure AGM voting ultimately achieves
A secure AGM voting process protects more than data.
It protects the integrity of the decision itself.
For members, it provides confidence that their vote has been handled properly.
For directors and committees, it provides a defensible governance process.
For the organisation, it reduces the risk of disputes, errors, privacy incidents and uncertainty around important decisions.
And for everyone involved, it creates a clearer record of what happened.
That is the real value of secure AGM voting.
The technology is only part of it. The stronger approach combines appropriate security controls, accurate voter eligibility, sound governance procedures, privacy safeguards, transparent communication and a reliable audit trail.
When those pieces work together, the AGM becomes much easier to trust.
Key takeaways
Secure AGM voting is about more than encryption. It includes authentication, eligibility, ballot integrity, privacy, auditability and operational controls.
Voting technology should reflect the organisation’s rules. Constitutions, legislation and voting entitlements need to be considered before selecting a system.
Privacy matters. AGM systems can process significant amounts of personal information, so organisations should consider how that information is collected, stored, accessed and retained.
Auditability is critical. A final result is more defensible when the organisation can demonstrate how it was produced.
Virtual participation creates additional requirements. For companies covered by the Corporations Act, members as a whole must have a reasonable opportunity to participate.
Independent security assurance is valuable. Certifications such as ISO/IEC 27001 can form part of a broader supplier due-diligence process.
Test before the AGM. The difficult scenarios are usually the ones worth testing most carefully.
If you’re planning an AGM, member election or formal ballot and want to understand what a secure voting process should look like, Vero Voting can help you assess the requirements and demonstrate the platform in practice.
How Secure AGM Voting Protects Members
How Secure AGM Voting Protects Members
How Secure AGM Voting Protects Members
How Secure AGM Voting Protects Members
How Secure AGM Voting Protects Members
How Secure AGM Voting Protects Members
How Secure AGM Voting Protects Members
Frequently Asked Questions
What is the safest way to vote at an AGM?
There is no single voting method that is safest for every organisation. The appropriate method depends on the constitution, voting rules, member structure and risk profile. A secure electronic voting system should provide appropriate voter authentication, accurate eligibility checks, ballot integrity, privacy controls and an audit trail.
Is online AGM voting secure?
Online AGM voting can be secure when it is designed and operated with appropriate security controls. Organisations should look beyond basic website encryption and assess authentication, administrator access, data protection, logging, auditability, incident response and the provider’s independent security assurance.
How does electronic voting prevent duplicate votes?
Electronic voting systems can associate voting access with an individual eligible voter and record whether that voting entitlement has already been exercised. The exact mechanism depends on the voting rules and system design. Organisations should test duplicate-voting scenarios before the AGM.
Can AGM votes be anonymous?
Yes, depending on the organisation’s rules and the type of vote. A voting system can authenticate a person’s eligibility to vote while keeping their individual voting choice confidential. The design needs to balance voter verification with ballot secrecy.
What should I ask an AGM voting software provider?
Ask how the provider verifies voters, protects ballot information, manages proxies, applies voting entitlements, prevents duplicate voting, maintains audit trails, protects personal information and responds to security incidents. It is also worth asking whether the provider has independent security certifications or audits and what systems those assurances actually cover.
Sources
The following sources were used to verify the Australian legal, privacy, cyber-security and governance information discussed in this article.
ASIC – Guidelines for investor meetings using virtual technology
https://asic.gov.au/regulatory-resources/corporate-governance/virtual-general-meetings/
Federal Register of Legislation – Corporations Act 2001
https://www.legislation.gov.au/Series/C2004A00818
ASX – Guidance Note 35: Security Holder Resolutions
https://www.asx.com.au/documents/rules/gn35_security_holder_resolutions.pdf
OAIC – Australian Privacy Principles, Chapter 11: Security of personal information
https://www.oaic.gov.au/privacy/australian-privacy-principles-guidelines/chapter-11-app-11-security-of-personal-information
OAIC – Guide to securing personal information
https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/guide-to-securing-personal-information
OAIC – Notifiable Data Breaches: Data breach preparation and response
https://www.oaic.gov.au/privacy/notifiable-data-breaches/data-breach-preparation-and-response
Australian Signals Directorate – Essential Eight
https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight
ISO – ISO/IEC 27001:2022
https://www.iso.org/standard/27001.html
Frequently Asked Questions
What is the safest way to vote at an AGM?
There is no single voting method that is safest for every organisation. The appropriate method depends on the constitution, voting rules, member structure and risk profile. A secure electronic voting system should provide appropriate voter authentication, accurate eligibility checks, ballot integrity, privacy controls and an audit trail.
Is online AGM voting secure?
Online AGM voting can be secure when it is designed and operated with appropriate security controls. Organisations should look beyond basic website encryption and assess authentication, administrator access, data protection, logging, auditability, incident response and the provider’s independent security assurance.
How does electronic voting prevent duplicate votes?
Electronic voting systems can associate voting access with an individual eligible voter and record whether that voting entitlement has already been exercised. The exact mechanism depends on the voting rules and system design. Organisations should test duplicate-voting scenarios before the AGM.
Can AGM votes be anonymous?
Yes, depending on the organisation’s rules and the type of vote. A voting system can authenticate a person’s eligibility to vote while keeping their individual voting choice confidential. The design needs to balance voter verification with ballot secrecy.
What should I ask an AGM voting software provider?
Ask how the provider verifies voters, protects ballot information, manages proxies, applies voting entitlements, prevents duplicate voting, maintains audit trails, protects personal information and responds to security incidents. It is also worth asking whether the provider has independent security certifications or audits and what systems those assurances actually cover.


