
SapphireOne has received confirmation from the Australian Taxation Office Digital Partnership Office that its approval under the DSP Operational Security Framework will continue, subject to the applicable terms and conditions.
Following the annual review process, SapphireOne formally accepted the requirements outlined by the ATO in relation to reference 39371261-84003419930.
The assessment acknowledges that SapphireOne operates through a desktop model hosted by the client and connected directly to the ATO. It also recognises SapphireOne’s current ISO27001:2022 self-assessed certification, multi-factor authentication arrangements, and use of services assessed up to risk rating 2 – low risk within the Single Touch Payroll category.
As part of the continued approval, SapphireOne has confirmed its commitment to:
- notify the ATO of relevant changes to its organisation or SapphireOne environment;
- participate in ATO monitoring, ad hoc reviews and reassessment activities where required;
- promptly notify the ATO of any identified data breach involving personally identifiable information; and
- maintain current certification throughout the approval period.
The next Operational Security Framework review is scheduled for August 2027.
SapphireOne remains committed to maintaining secure, reliable and compliant connectivity for organisations using SapphireOne Payroll/HR mode to meet their Single Touch Payroll obligations.