Why Security Certifications Matter During AGM Voting

Monday, 17 August 2026, 9:17 am

Why Security Certifications Matter During AGM Voting
BlogMeetings

Annual General Meetings are built on trust.

Members trust that their votes will be counted correctly. Directors trust the integrity of the results. Company secretaries and governance professionals trust that the meeting complies with legal and organisational requirements.

Increasingly, that trust also depends on technology.

As more Australian organisations conduct hybrid and virtual AGMs, the voting platform becomes part of the governance process. It’s no longer enough for software to be easy to use—it also needs to demonstrate that member information, voting data and election processes are properly protected.

That’s where recognised security certifications become important.

Rather than relying on marketing claims about being “secure”, organisations can look for independently assessed security standards that provide evidence of mature information security practices.

Why security matters in AGM voting

An AGM voting platform processes information that organisations cannot afford to compromise.

Depending on the meeting, this may include:

Member and shareholder identities
Voting entitlements
Proxy appointments
Ballot selections
Meeting attendance records
Audit logs
Election results

If these systems are poorly secured, organisations face risks such as:

unauthorised access
data breaches
disrupted meetings
manipulation of voting processes
reputational damage
regulatory scrutiny

Even if none of these events occur, uncertainty around security can reduce confidence in the outcome.

Governance isn’t only about getting the right result. It’s also about demonstrating that the result can be trusted.

Security certifications provide independent assurance

Any software provider can claim to take cybersecurity seriously.

Independent certification is different.

It requires external auditors to examine policies, controls, operational processes and ongoing security management against recognised standards.

This provides customers with objective evidence rather than relying solely on vendor promises.

For organisations selecting an AGM voting provider, that independent verification significantly reduces procurement risk.

Why ISO/IEC 27001 matters

ISO/IEC 27001 is the world’s leading standard for Information Security Management Systems (ISMS).

Rather than focusing on one feature or one piece of software, ISO 27001 assesses how an organisation manages information security across its entire business.

Certification covers areas including:

risk management
access control
incident response
supplier management
employee security
asset management
business continuity
continual improvement

Importantly, certification isn’t permanent.

Organisations undergo regular surveillance audits and periodic recertification to demonstrate that security controls continue to operate effectively.

For customers, ISO 27001 shows that security is embedded into organisational governance—not added as an afterthought.

What is SOC 2 Type II?

SOC 2 Type II is often misunderstood.

Unlike ISO 27001, it isn’t a certification.

It’s an independent assurance report that evaluates whether security controls not only exist but operate effectively over an extended period.

Type II reports assess controls against the Trust Services Criteria, including:

Security
Availability
Processing Integrity
Confidentiality
Privacy

The critical difference is that auditors examine how controls perform over time rather than assessing them at a single point.

For organisations purchasing SaaS platforms, SOC 2 Type II provides additional confidence that operational security is consistently maintained.

Why both standards matter

Many procurement teams now ask technology vendors for both ISO 27001 and SOC 2 Type II because they evaluate different aspects of security.

ISO/IEC 27001 SOC 2 Type II

Information Security Management System

Operational effectiveness of controls

International certification

Independent assurance report

Organisation-wide security governance

Service-specific operational controls

Focuses on managing information security risks

Focuses on ongoing control performance

Together, they demonstrate both mature governance and effective day-to-day security practices.

Security is about more than encryption

Encryption is essential.

But secure AGM voting requires much more than encrypted data.

A trustworthy voting platform should also include:

Strong authentication
Only eligible members should be able to access their ballot. Authentication methods may include shareholder reference numbers (SRNs), holder identification numbers (HINs), member IDs or unique secure credentials appropriate to the organisation.

Role-based access
Administrative access should be tightly controlled and limited only to authorised personnel.

Audit trails
Every significant action should be recorded with tamper-evident logs, providing transparency if questions arise after the meeting.

Business continuity
If unexpected technical issues occur, the provider should have documented recovery procedures to minimise disruption.

Ongoing monitoring
Security isn’t something performed once a year. Effective providers continually monitor systems, manage vulnerabilities and review risks as part of normal operations.

Security supports good governance

Australian regulators increasingly recognise that technology plays an important role in member participation.

ASIC expects companies using virtual meeting technology to provide members with a reasonable opportunity to participate, including voting and asking questions. Guidance also emphasises planning for technology risks and ensuring voting processes remain accessible and reliable.

Similarly, the Governance Institute of Australia and other governance bodies recommend considering cybersecurity and resilience when planning hybrid and virtual AGMs.

Security therefore supports governance outcomes—not just IT objectives.

Common misconceptions

“We’re only a small organisation.”
Cybercriminals don’t only target large listed companies. Associations, unions, strata bodies and not-for-profits all hold valuable personal information and financial records. Security standards benefit organisations of every size.

“Password protection is enough.”
Passwords are only one layer of defence. Modern security relies on multiple controls working together, including monitoring, access management, incident response and secure operational processes.

“If we’ve never had a breach, we’re secure.”
Past performance doesn’t guarantee future resilience. Independent certification demonstrates that security is actively managed rather than assumed.

Questions to ask your AGM voting provider

Before selecting an online voting platform, ask:

Is the organisation certified to ISO/IEC 27001?
Is it independently audited for SOC 2 Type II?
What information does the certification cover?
Where is member data stored?
How is access controlled?
Are audit logs maintained?
What business continuity processes exist?
How frequently are security controls reviewed?

These questions often reveal far more than product feature lists.

How Vero Voting helps

Security forms part of every trustworthy election.

Vero Voting operates with an Information Security Management System certified to ISO/IEC 27001:2022 and has also successfully completed a SOC 2 Type II independent audit.

Combined with Australian data hosting, encrypted communications, comprehensive audit trails and robust voter authentication, these independently assessed controls help organisations conduct AGMs, elections and ballots with greater confidence.

Rather than relying on marketing claims, customers can assess independently verified evidence that security practices are embedded into the organisation’s operations.

Key takeaways

Security certifications are no longer a “nice to have” when selecting an AGM voting platform.

They provide independent assurance that a provider has invested in structured security governance, operational controls and continual improvement.

For boards, company secretaries and governance professionals, that means greater confidence that voting processes, member information and election outcomes are protected.

When trust is the foundation of an AGM, independently verified security helps protect that trust.

If your organisation is reviewing its AGM voting platform, contact Vero Voting for a demonstration or speak with our team about how our certified security framework supports secure, transparent and compliant elections.

Sources

Australian Securities & Investments Commission (ASIC) – Virtual meetings FAQs

ASIC – Guidelines for investor meetings using virtual technology

Governance Institute of Australia – AGMs using technology

Australian Taxation Office – Operational Framework security standards (ISO 27001 and SOC 2)


Frequently Asked Questions

Why is ISO 27001 important for AGM voting?

ISO/IEC 27001 demonstrates that a provider has implemented and maintains a comprehensive Information Security Management System (ISMS). It shows security is managed systematically across people, processes and technology.

What is the difference between ISO 27001 and SOC 2 Type II?

ISO 27001 is an internationally recognised certification for an organisation’s information security management system. SOC 2 Type II is an independent assurance report evaluating whether security controls operate effectively over time.

Does Australian law require AGM voting providers to have ISO 27001 or SOC 2?

No. Australian legislation does not mandate these certifications. However, they provide strong independent evidence of mature security practices and are increasingly requested during procurement and vendor due diligence.

How do security certifications protect AGM voting?

While no certification guarantees immunity from cyber incidents, they require organisations to implement, monitor and continually improve security controls covering areas such as access management, incident response, risk management and operational resilience.

Should smaller organisations care about security certifications?

Yes. Associations, strata schemes, unions and not-for-profits all manage sensitive member information. Choosing a provider with independently verified security can reduce operational and governance risk regardless of organisation size.

Need support with your next Meetings?

Contact Us

Subscribe to our blog

Stay up to date on the latest topics for voting solutions

[stc-subscribe]



    Subscribe

    If you want to personalise your subscription, click here