How Secure AGM Voting Protects Members, Directors and Organisations

Tuesday, 11 August 2026, 8:05 pm

How Secure AGM Voting Protects Members, Directors and Organisations
BlogMeetingsVoting

An AGM might only last a few hours, but the decisions made during it can affect an organisation for months or even years.

Directors may be elected. Resolutions may be approved. Members may decide on constitutional changes. Shareholders may vote on significant corporate matters.

That makes the voting process more than an administrative exercise.

It needs to be accurate, secure, transparent and capable of standing up to scrutiny afterwards.

This becomes particularly important when an AGM involves hundreds or thousands of members, proxy votes, different voting entitlements, remote participants or sensitive member information.

A secure AGM voting system helps address those risks by controlling who can vote, protecting voting information, recording what happened and producing a reliable record of the final result.

For companies using virtual or hybrid meetings, there is another consideration: members must be given a reasonable opportunity to participate. ASIC specifically expects the technology used for virtual meetings to support meaningful participation, including asking questions, making comments and voting.

The goal isn’t simply to make voting digital.

The goal is to make the entire voting process defensible.

What is secure AGM voting?

Secure AGM voting is the use of controlled processes and technology to ensure that eligible members can cast valid votes while protecting the confidentiality, integrity and availability of voting information.

A well-designed system should address several questions:

Is the person entitled to vote?
Has their voting entitlement been correctly applied?
Can someone vote more than once when they shouldn’t?
Can an unauthorised person access the ballot?
Can votes be changed or manipulated?
Can the organisation demonstrate how the result was calculated?
Can the process be independently reviewed if the result is challenged?

These questions apply whether voting happens in a physical meeting, a hybrid AGM or a fully virtual meeting.

For companies covered by the Corporations Act 2001 (Cth), the legislation allows meetings to be held at physical venues, using physical venues and virtual meeting technology, or using virtual meeting technology only where the constitution expressly requires or permits it. The Act also requires members as a whole to have a reasonable opportunity to participate.

That makes the choice of voting technology a governance issue, not merely an IT decision.

Why AGM voting security matters

There are three groups with a lot at stake in an AGM vote:

Members and shareholders
Directors and office bearers
The organisation itself

Each group faces a different risk.

Protecting members and shareholders

Members need confidence that their vote will be counted correctly and that their personal information will not be unnecessarily exposed.

Consider a contested board election.

If members believe that another person could access their voting credentials, that votes could be altered, or that the organisation could see how they voted when the ballot was intended to be confidential, confidence in the election can quickly disappear.

Security therefore has a direct connection with member trust.

A voting system should separate voter eligibility and authentication from the confidentiality requirements of the ballot wherever the voting rules require an anonymous or secret vote.

Protecting directors and office bearers

Directors and committee members are often responsible for ensuring that the organisation’s governance processes are properly administered.

A poorly controlled voting process can create difficult questions afterwards:

Who was entitled to vote?
How were proxies handled?
Were voting rights applied correctly?
Was the result calculated according to the constitution?
Can the organisation prove what happened?

A secure and auditable process gives directors something much more useful than a spreadsheet containing a final number.

It gives them evidence of how that number was reached.

Protecting the organisation

The organisation has operational, legal and reputational interests in getting the process right.

A disputed election can delay appointments. A disputed resolution can create uncertainty around subsequent decisions. A privacy incident can damage member confidence.

The risks become greater when voting data is combined with member databases, proxy appointments, shareholder information or other personal information.

The Office of the Australian Information Commissioner (OAIC) says organisations covered by the Privacy Act must take reasonable steps to protect personal information from misuse, interference and loss, as well as unauthorised access, modification or disclosure. The OAIC also recommends considering security throughout the information lifecycle.

The five pillars of secure AGM voting

Security isn’t one feature.

A genuinely secure AGM voting process normally combines several controls.

1. Voter authentication and eligibility

The first question is simple:
Is this person entitled to vote?

Depending on the organisation, voter validation might involve:

a unique voting link
membership details
shareholder information
a secure login
two-factor authentication
a controlled voter roll
proxy validation
voting entitlement checks

The right approach depends on the organisation and its governing rules.

For example, a company election involving shareholders with different voting entitlements may require considerably more complex validation than a small association where every financial member has one vote.

The important point is that authentication should not be treated as an afterthought.

The system should establish eligibility before the vote is accepted.

2. Protection of the ballot

Authentication and ballot secrecy are not necessarily the same thing.

An organisation may need to verify that a particular member is entitled to vote while ensuring that the member’s individual choices remain confidential.

This is especially relevant for:

director elections
committee elections
office bearer elections
contested resolutions
sensitive member ballots
employee or workforce elections

A secure voting architecture should therefore consider what information needs to be linked together — and what information should remain separated.

Collecting more information than necessary can also increase risk. OAIC guidance recommends considering whether personal information is reasonably necessary to collect in the first place and taking a lifecycle approach to how that information is stored, accessed and ultimately destroyed or de-identified.

3. Accurate vote counting

Security is not only about preventing hackers.

It is also about preventing administrative mistakes.

AGM voting can involve:

ordinary resolutions
special resolutions
poll votes
proxy votes
preferential voting
weighted voting
different classes of members
shareholder voting entitlements
abstentions
multiple resolutions

A system that securely records the wrong voting entitlement is still a governance problem.

This is why the voting rules should be configured before the AGM and tested using realistic scenarios.

For example, suppose an organisation has:

500 eligible members
50 proxy appointments
different voting rights for different membership classes
an election with five candidates

The voting system should not simply count the number of clicks.

It needs to apply the rules that determine which votes count and how they count.

4. A reliable audit trail

One of the most valuable features of secure electronic voting is the ability to retain an appropriate record of the voting process.

An audit trail can help answer questions such as:

When was the ballot opened?
Who was eligible to vote?
How was eligibility established?
Which voting method was used?
Were proxy votes included?
Were voting entitlements applied correctly?
When did voting close?
How was the result calculated?
Were administrative changes made during the process?

The purpose isn’t to expose confidential individual votes.

It is to provide sufficient evidence to reconstruct and verify the process without compromising ballot secrecy.

That distinction matters.

A good audit trail should increase transparency without undermining voter confidentiality.

For listed entities, ASX Guidance Note 35 also recognises the importance of the voting process, voting exclusions, scrutineers and reporting voting results in the context of security holder resolutions.

5. Security controls around the platform

The voting application is only one part of the security picture.

Organisations should also consider:

access controls
administrator permissions
authentication
encryption
system monitoring
logging
backups
vulnerability management
incident response
third-party providers
data retention
hosting arrangements
security testing

The Australian Signals Directorate’s Essential Eight provides a useful baseline for organisations considering broader cyber security controls, including multi-factor authentication, restricting administrative privileges, patching, application control and backups.

For organisations assessing a voting provider, it’s worth asking not just “Is the voting page encrypted?” but:
What security framework sits behind the voting platform?

Why ISO 27001 matters when choosing a voting provider

Security claims are easy to make.

Independent certification provides stronger evidence.

ISO/IEC 27001:2022 is an international standard for information security management systems. It sets requirements for establishing, implementing, maintaining and continually improving an information security management system. ISO describes the standard as a risk-based approach covering the confidentiality, integrity and availability of information.

For an organisation selecting an AGM voting provider, ISO 27001 certification can therefore be a useful part of the supplier due-diligence process.

It doesn’t mean a system can never be compromised.

No responsible security professional should make that promise.

Instead, certification provides evidence that the provider operates an established information security management system and has undergone an independent conformity assessment process.

Organisations should still ask what the certification covers, who certified it and whether the scope includes the systems and services being purchased.

Secure AGM voting is also about privacy

An AGM voting platform may handle more information than the final vote count suggests.

Depending on the organisation, this could include:

names
membership numbers
email addresses
shareholder information
voting entitlements
proxy information
attendance information
authentication information
voting records
technical logs

The Privacy Act 1988 applies to APP entities, including many organisations with annual turnover above $3 million and certain other organisations regardless of turnover. The precise application depends on the entity and the circumstances.

Where the Privacy Act applies, APP 11 requires reasonable steps to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure.

That means privacy should be considered when selecting and configuring an AGM voting system.

It should not be something the organisation thinks about after the election.

Ask where the data goes

When assessing a voting provider, ask:

Where is the information stored?
Is any information transferred overseas?
Who can access it?
What information does the provider retain?
How long is it retained?
How is it destroyed or de-identified?
What happens if there is a security incident?
Does the provider use subcontractors or cloud services?
What contractual protections are in place?

OAIC guidance specifically identifies third-party providers, including cloud computing providers, as an area organisations should consider when protecting personal information.

Secure voting and member confidence go together

There is another side to security that is often overlooked.

Members need to understand that the process is secure.

A technically sophisticated system is not much help if members don’t trust it.

Clear instructions can make a significant difference.

Before the AGM, members should understand:

how they will access the meeting
how they will authenticate
when voting opens
how they will vote
whether votes are confidential
how proxies are handled
what happens if they experience a technical problem
when voting closes

This is particularly important for hybrid and virtual meetings.

ASIC states that companies must provide members as a whole with a reasonable opportunity to participate, and virtual meeting technology must support relevant participation rights.

A member who cannot vote because they cannot access the platform is not simply experiencing a technical inconvenience.

It can become a governance issue.

Common AGM voting security mistakes

Relying on a generic meeting platform alone

Video conferencing software is excellent for communication.

It isn’t necessarily designed to manage complex voting entitlements, proxies, elections or formal ballot processes.

The meeting platform and voting platform can work together, but they serve different purposes.

Treating a spreadsheet as the source of truth

Spreadsheets can be useful for preparing voter data.

They become risky when they’re being used to manually reconcile eligibility, proxies, voting rights and final results during a live AGM.

Manual processes create opportunities for transcription errors and inconsistent records.

Using the same credentials for everyone

If everyone receives the same meeting password or generic voting access, it becomes difficult to establish who actually voted.

Individualised access is generally much easier to control and audit.

Ignoring administrator access

People often focus heavily on voter security while overlooking administrative accounts.

An administrator with excessive privileges can potentially make changes that have a greater impact than an ordinary voter.

Administrative access should therefore be limited, controlled and monitored.

Failing to test unusual scenarios

A system may work perfectly when everyone follows the expected workflow.

The real test is what happens when:

a member loses their login
a proxy is changed
someone attempts to vote twice
a member joins late
the chair changes the voting procedure
a resolution is withdrawn
an election requires preferential counting
the meeting is interrupted
internet connectivity fails

Testing these scenarios before the AGM is far cheaper than discovering the problem while hundreds of members are watching.

A practical security checklist for your next AGM

Before selecting or approving an AGM voting system, ask these questions.

Governance

Does the voting method comply with the organisation’s constitution, rules and applicable legislation?
Are the voting rights clearly defined?
Are proxy arrangements documented?
Has the meeting format been approved appropriately?
Is the voting process documented?

Voter security

How are voters authenticated?
How is eligibility checked?
Can a voter submit multiple votes?
How are proxy votes managed?
Can voting access be revoked or corrected?

Ballot integrity

Can votes be altered after submission?
How is ballot secrecy maintained?
How are voting entitlements applied?
How are preferential or weighted votes counted?
Can the result be independently verified?

Auditability

Is there a complete audit trail?
Are important administrative actions logged?
Can the final result be reconciled to the voting records?
Can the process be reviewed if a member challenges the outcome?

Privacy

What personal information is collected?
Why is each piece of information required?
Where is it stored?
Who can access it?
How long is it retained?
What happens when it is no longer required?

Cyber security

Does the provider have an established information security management system?
Is the provider independently certified or audited?
Is multi-factor authentication available where appropriate?
How are administrator accounts protected?
How are incidents detected and managed?
Does the provider have a documented incident response process?

Meeting participation

Can members vote remotely where required?
Can members ask questions and make comments?
Is the voting process accessible from common devices?
What happens if a member loses connectivity?
Has the technology been tested under realistic conditions?

Where Vero Voting can assist

For organisations that need more than a simple online poll, Vero Voting provides voting and meeting services designed around formal governance processes.

Vero supports virtual, hybrid and in-person AGMs, including live voting, proxy management, elections and member resolutions. Its AGM solution can also integrate with commonly used meeting platforms such as Zoom, Microsoft Teams and Webex.

The voting process can be configured around the organisation’s particular requirements, including different member rights, voting entitlements and proxy arrangements.

Vero also provides an independently managed voting process, with auditability and verification built into the workflow rather than relying on a manually prepared result at the end.

From a security perspective, Vero Voting states that its information security management system is certified to ISO/IEC 27001:2022 and independently audited.

That matters because the question organisations should be asking is not simply:
“Can this software run a vote?”

It should be:
“Can this voting process produce an outcome we can confidently defend?”

What secure AGM voting ultimately achieves

A secure AGM voting process protects more than data.

It protects the integrity of the decision itself.

For members, it provides confidence that their vote has been handled properly.

For directors and committees, it provides a defensible governance process.

For the organisation, it reduces the risk of disputes, errors, privacy incidents and uncertainty around important decisions.

And for everyone involved, it creates a clearer record of what happened.

That is the real value of secure AGM voting.

The technology is only part of it. The stronger approach combines appropriate security controls, accurate voter eligibility, sound governance procedures, privacy safeguards, transparent communication and a reliable audit trail.

When those pieces work together, the AGM becomes much easier to trust.

Key takeaways

Secure AGM voting is about more than encryption. It includes authentication, eligibility, ballot integrity, privacy, auditability and operational controls.

Voting technology should reflect the organisation’s rules. Constitutions, legislation and voting entitlements need to be considered before selecting a system.

Privacy matters. AGM systems can process significant amounts of personal information, so organisations should consider how that information is collected, stored, accessed and retained.

Auditability is critical. A final result is more defensible when the organisation can demonstrate how it was produced.

Virtual participation creates additional requirements. For companies covered by the Corporations Act, members as a whole must have a reasonable opportunity to participate.

Independent security assurance is valuable. Certifications such as ISO/IEC 27001 can form part of a broader supplier due-diligence process.

Test before the AGM. The difficult scenarios are usually the ones worth testing most carefully.

If you’re planning an AGM, member election or formal ballot and want to understand what a secure voting process should look like, Vero Voting can help you assess the requirements and demonstrate the platform in practice.

Sources

The following sources were used to verify the Australian legal, privacy, cyber-security and governance information discussed in this article.

ASIC – Guidelines for investor meetings using virtual technology
https://asic.gov.au/regulatory-resources/corporate-governance/virtual-general-meetings/

Federal Register of Legislation – Corporations Act 2001
https://www.legislation.gov.au/Series/C2004A00818

ASX – Guidance Note 35: Security Holder Resolutions
https://www.asx.com.au/documents/rules/gn35_security_holder_resolutions.pdf

OAIC – Australian Privacy Principles, Chapter 11: Security of personal information
https://www.oaic.gov.au/privacy/australian-privacy-principles-guidelines/chapter-11-app-11-security-of-personal-information

OAIC – Guide to securing personal information
https://www.oaic.gov.au/privacy/privacy-guidance-for-organisations-and-government-agencies/handling-personal-information/guide-to-securing-personal-information

OAIC – Notifiable Data Breaches: Data breach preparation and response
https://www.oaic.gov.au/privacy/notifiable-data-breaches/data-breach-preparation-and-response

Australian Signals Directorate – Essential Eight
https://www.cyber.gov.au/resources-business-and-government/essential-cyber-security/essential-eight

ISO – ISO/IEC 27001:2022
https://www.iso.org/standard/27001.html


Frequently Asked Questions

What is the safest way to vote at an AGM?

There is no single voting method that is safest for every organisation. The appropriate method depends on the constitution, voting rules, member structure and risk profile. A secure electronic voting system should provide appropriate voter authentication, accurate eligibility checks, ballot integrity, privacy controls and an audit trail.

Is online AGM voting secure?

Online AGM voting can be secure when it is designed and operated with appropriate security controls. Organisations should look beyond basic website encryption and assess authentication, administrator access, data protection, logging, auditability, incident response and the provider’s independent security assurance.

How does electronic voting prevent duplicate votes?

Electronic voting systems can associate voting access with an individual eligible voter and record whether that voting entitlement has already been exercised. The exact mechanism depends on the voting rules and system design. Organisations should test duplicate-voting scenarios before the AGM.

Can AGM votes be anonymous?

Yes, depending on the organisation’s rules and the type of vote. A voting system can authenticate a person’s eligibility to vote while keeping their individual voting choice confidential. The design needs to balance voter verification with ballot secrecy.

What should I ask an AGM voting software provider?

Ask how the provider verifies voters, protects ballot information, manages proxies, applies voting entitlements, prevents duplicate voting, maintains audit trails, protects personal information and responds to security incidents. It is also worth asking whether the provider has independent security certifications or audits and what systems those assurances actually cover.

Need support with your next Meetings or Voting?

Contact Us

Subscribe to our blog

Stay up to date on the latest topics for voting solutions

[stc-subscribe]



    Subscribe

    If you want to personalise your subscription, click here