Avani specialises in technology risk, information security assurance and regulatory compliance, with experience across control environment assessments in financial services and regulated industries. Experienced across frameworks including APRA CPS 234, ISO/IEC 27001, NIST and the NSW Cyber Security Policy, Avani has contributed to engagements that drive meaningful improvement in cyber and technology governance.

Having worked across engagements involving corporates, financial institutions, government entities and regulated entities, Avani has developed a practical understanding of how organisations manage IT risk, identify control gaps and prepare for assurance programmes including SOC 2. Known for bridging technical teams and business stakeholders, Avani brings clear, grounded thinking to complex technology risk challenges.

Avani brings a technology assurance background to their advisory work, having previously worked at a Big Four firm contributing to IT risk assessments, control design reviews and compliance programmes across a range of industries – building a hands-on understanding of how cyber risk operates in complex organisations.

NSW Government Agencies – NSW Cyber Security Policy Internal Audits

Supporting NSW Cyber Security Policy internal audits across multiple government agencies including a large multi-entity cluster. Assessing control design and implementation, identifying gaps across each agency and producing remediation recommendations that support coordinated cyber uplift and compliance with the NSW CSP framework.

Government Insurer – Combined NSW CSP & ISO/IEC 27001 Internal Audit

Supporting a combined Essential Eight and ISO/IEC 27001 internal audit for a government insurer. Assessing alignment across both frameworks simultaneously, identifying control gaps and delivering findings that inform the client’s path toward certification readiness and ongoing regulatory compliance.

Government Electoral Body – Assistive Voting Technology Audit

Supporting a technology internal audit of a government electoral body’s telephone assistive voting system. Reviewing security and operational controls over a critical public-facing platform, providing assurance over the integrity and accessibility of the voting service.

Banking & Financial Services Clients – APRA CPS 234 Internal Audits

Supporting APRA CPS 234 internal audits across multiple banking and financial services clients. Assessing information security capability and control alignment against APRA’s prudential requirements, identifying gaps and delivering findings that strengthen each client’s regulatory position and preparedness.

Government & Technology Clients – GS007/ASAE 3402 & SOC 2 Engagements

Supporting third-party assurance engagements across government shared services and technology providers, including GS007/ASAE 3402 and SOC 2 reporting. Conducting walkthroughs, reviewing evidence and assessing control design and operating effectiveness, contributing to the delivery of assurance reports that build confidence across each client’s service ecosystem.

Multiple Data Recipients – ACCC CDR Accreditation

Supporting ACCC Consumer Data Right accreditation assessments across multiple data recipients. Reviewing information security controls against CDR Rules and accreditation guidelines, helping each organisation navigate the regulatory accreditation process and achieve accreditation milestones.

Areas of Expertise
  • WK Advisory
  • Cyber Architecture
  • Cyber Assessment
  • Cyber Strategy
  • Cyber Transformation

Industry Representation
  • Financial Institutions and Services 
  • Government