Black Shard

Industries · Financial services

Systems built around the licence.

We build the operating systems an AFSL holder runs on, and the security posture its investors diligence. Stone Leaf Capital already runs on ours.

An AFSL is a records regime as much as a licence: obligations to keep adequate risk-management systems, retain financial records, and prove to ASIC, to auditors, and to investors that the firm operates the way it says it does. The systems underneath either make that provable or make it hard.

Stone Leaf Capital, an Australian capital-markets firm, engaged us to build exactly that: a staff portal structured around the firm’s AFSL perimeter, with critical-event tracking, policy modules, and a compliance audit log capturing actor, action, and before-and-after state on every change.

What you carry, and what we do about it.

  • AFSL record-keeping is unforgiving: records must exist, be attributable, and be retrievable years later.

    We design operating portals around the licence perimeter, with compliance audit logs that capture actor, action, and before-and-after state on every change: the system Stone Leaf Capital runs on.

    Product & platform engineering
  • Investor due diligence now includes security questionnaires, and vague answers read as findings.

    A posture assessment maps where you stand against recognised controls, and a vCISO retainer gives you a named security lead whose answers you can put in front of investors.

    vCISO & posture assessment
  • Operational resilience sits inside the general obligations: could the firm keep operating, and recover, through an incident?

    Incident readiness built before you need it: a response plan written for your team, a tabletop exercise that pressure-tests it, and backup recovery verified against a real restore.

    Incident readiness
  • When a regulator or auditor asks what happened, the audit trail is the answer, or the problem.

    We review your logging and alerting coverage so you would actually see an attack, and we build audit trails into the systems we ship so the record exists before anyone asks.

    Detection & response advisory

The obligations in play

Corporations Act, s 912A
AFSL general obligations include adequate risk-management systems, a head ASIC has already litigated over cyber failures.
Corporations Act, s 286
Financial records must be kept for seven years, in a form that lets them be conveniently audited.
AML/CTF Act 2006
Many licensees are reporting entities: programs, customer identification, and transaction reporting.
Privacy Act 1988
Client personal and financial information under the APPs, with the Notifiable Data Breaches scheme behind it.
APRA CPS 234
Where a firm is APRA-regulated, information-security capability becomes a board-owned obligation.

This list orients the engineering work. It is not legal advice; your advisers own the interpretation.

The build behind this page

Stone Leaf Capital

An Australian capital-markets firm (funds management, capital raising, corporate advisory) running day-to-day on the brand, public site, and staff portal we built: critical-event tracking, policy modules, and a compliance audit log, structured around the firm’s AFSL perimeter.

See the work

Answer the due-diligence questionnaire with evidence.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au