ATO Digital Service Provider (DSP) Operational Security Framework
Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

ATO Digital Service Provider (DSP) Operational Security Framework SEC.ENTITY: Entity validation of customers against an independent source

DSPs validate that the consumer or user of a commercial software product is a legitimate business with a genuine need to access ATO APIs: they verify the entity (its ABN, and that it is active) against a reliable and independent source such as the Australian Business Register, and obtain valid client contact details including a confirmed email address and phone number; customers without an ABN (for example a student using software for research) have only their contact details validated. Entity validation does not replace service-specific verification such as SuperMatch's customer verification terms.

Maintained by Gerard Blokdyk

Other controls in Security control requirements – ATO Digital Service Provider (DSP) Operational Security Framework

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.