Voice phishing simulations in Australia
Australia has no single answer on recording a voice phishing simulation, and the usual two-way split is wrong: three jurisdictions put someone on the call outside the offence by definition, five attach conditions, and four restrict what you may do with a recording that was lawful to make. So the Australian decision is where each person you call is sitting, and it belongs to the target list rather than to a review afterwards.
Phone numbers
Supplied by Callstrike
Local numbers in Australia, after a one-time approval.
Running a simulation
Permitted, and it changes at the border
Eight jurisdictions and three different answers on whether you may record at all.
Consent
What settles five of the eight
All principal parties, obtained in advance, avoids the conditional limbs entirely.
Getting a phone number in Australia
One approval per country, completed in the console.
Provisioned by Callstrike after approval
Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.
One line in the Australian table below is conditional on another, and pulling the documents in the wrong order is what costs a week. Proof of business identity is the long-form company extract from the corporate regulator, the version that includes the officer names and the business address rather than the short one. Whether you then need a letter of authority depends on what that extract says: if your authorised representative is listed on it as a director, officer or other official contact, the extract is itself the proof and no letter is needed. If they are not, a letter of authority signed by one of the directors named on the extract has to accompany it. So pull the extract first and read it before deciding who signs.
The rest is ordinary: a government-issued photo identity document or passport for that representative, and proof of an address within Australia, which will take the extract, a utility bill, a tax notice, a rent receipt or a title deed, with no post office box where a local address is required. Alongside the uploads the console form asks for your business registration number, your website, your business classification and the representative's contact details.
- 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
- 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
- 03A dedicated number in Australia is assigned to youCallstrike
- 04Build and launch the campaignYour team
| What you provide | Accepted evidence, any one of |
|---|---|
| Proof of business identityAustralian businesses must provide the Current Company Extract or Record of Registration for Business which can be obtained through the ASIC Portal. All businesses must provide the long form extract, which includes the officer names and business address. | Commercial registry or equivalent showing officers and address |
| Proof of addressMust be within Australia; a PO Box is not acceptable where a local address is required. | Commercial registry or equivalent showing address, Utility bill, Tax notice, Rent receipt, Title deed |
| Proof of authorized representative identity | Government-issued ID, Passport |
| Proof of authorizationIf the Authorized Representative’s name is listed on the Extract as a Director/Officer or other official contact person, no LOA is required. Your extract serves as direct proof. If the Authorized Representative’s name is NOT listed on the Extract, you must upload a Letter of Authorization signed by one of the Directors named on your Extract (e.g., if "John Citizen" is the Director on the Registry document, John must sign the LOA authorizing the named Authorized Representative). | Letter of authorization, Commercial registry or equivalent showing name of authorized representative |
These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.
Is it lawful to run a simulation in Australia?
The position in short, before your counsel reads the detail below.
Yes, and the first Australian surprise is that the federal privacy statute may not reach you at all. An act by an organisation that is or was an employer is exempt from the privacy principles where it is directly related both to a current or former employment relationship and to an employee record about that individual. Its limits are numerous: it is available to organisations only, a small business operator never reaches it because the definition excludes them from being an organisation in the first place, and it covers neither prospective employees, nor volunteers, nor a third party the call happens to reach. The limit that matters commercially is the one people miss. The regulator states that the exemption does not cover contractors handling another organisation's employee records, whatever the contractual arrangements, and that such a contractor must comply with the principles including the notification requirements. So Callstrike is fully bound by them even where the exemption covers your own side of the programme.
Recording is state and territory law and it falls into three groups rather than the two most summaries offer. Victoria, Queensland and the Northern Territory each confine the offence to a conversation the person is not a party to, or supply an express exception where the person using the device is a party, so no condition and no balancing test applies. The Northern Territory belongs in that group and is routinely misfiled into the restrictive one. New South Wales, Western Australia, South Australia, Tasmania and the Australian Capital Territory each permit a party to record where all principal parties consent, or where one consents and the recording is reasonably necessary to protect that party's lawful interests.
Three of those five add a further route, and it is where the trap sits. They permit a recording made otherwise than for the purpose of communicating or publishing the conversation to people who are not parties to it, and a simulation exists in order to report the result to a security team or to human resources, who are not parties. So it falls outside that limb by design and throws you back on reasonably necessary for the protection of lawful interests, which no primary source resolves for an authorised security test. Obtaining the consent of all principal parties in advance, through the programme notice, avoids the question in all five. The reverse surprise is worth planning for too: four jurisdictions restrict what may be done with a recording regardless of whether making it was lawful, so the two most permissive on making one are among the strictest on circulating it.
Two corrections close the position. Do not describe Australia as one-party-consent at federal level, because the federal interception statute contains no participant exception anywhere and its definition keys on the knowledge of the person making the communication, which in a two-way call is a different person each way. What keeps endpoint recording outside the federal prohibition is a definitional provision: a communication passes over the system only until it becomes accessible to the intended recipient, so the federal question is architecture rather than agreement. And the New South Wales workplace surveillance statute, which looks like the centrepiece of an Australian monitoring analysis, does not reach a telephone call at all: its definition is closed to camera, computer and tracking surveillance, as is the Australian Capital Territory's. Those regimes matter the moment a campaign adds email or endpoint telemetry, and not before.
What your company needs to do
8 items, in the order you will need them.
- Record which state or territory each person sits inAustralia-specificThe recording answer changes at a state border and there are three of them, so the jurisdiction has to be a field on the target list rather than something reconstructed later. It is also what tells you which of the eight maxima you would be exposed to, and they range from twelve months to five years.
- Obtain all-principal-party consent in advance through the programme noticeAustralia-specificThis is the design that avoids the question in all five conditional jurisdictions without needing anyone to resolve whether an authorised security test is reasonably necessary to protect your lawful interests. It has to be per employee and it has to predate the first call.
- Take a separate decision about onward circulationAustralia-specificVictoria, Western Australia, South Australia and the Northern Territory restrict what may be done with a record made by a listening device whether or not making it was lawful, and South Australia specifically restricts use where the lawful-interests limb was the basis for making it. Reporting a result is a different question from capturing it.
- Do not assume your vendor is covered by your exemptionAustralia-specificThe employee records exemption is available to an organisation about its own employees. The regulator says a contractor handling another organisation's employee records must comply with the principles including notification, whatever the contract says, and the contractor is the one holding the recordings.
- Record at the endpoint, once the call has been deliveredAustralia-specificThe federal statute protects a communication while it passes over the system, and passage ends when the communication becomes accessible to the intended recipient. Recording on the handset, the exchange or the platform's own leg after delivery is outside that passage. Getting it wrong is an indictable offence carrying up to two years.
- Give fourteen days' notice if the campaign adds email or endpoint telemetryAustralia-specificThat is computer surveillance, and in New South Wales it needs prior written notice at least fourteen days beforehand stating the kind of surveillance, how it will be carried out, when it starts, whether it is continuous or intermittent and whether it is time-limited, plus a policy notified in a way that makes it reasonable to assume the person understands it. The Australian Capital Territory adds good-faith consultation for at least the notice period, defined as a genuine opportunity to influence the conduct of the surveillance.
- Do not reach for a covert surveillance authorityIn New South Wales it comes from a Judge of the Local Court, does not authorise covert surveillance for monitoring work performance, and lasts at most thirty days. In the Australian Capital Territory it is available only to find out whether a worker is engaged in unlawful activity. A simulation suspects nobody, so neither door opens.
- Do not cite the phishing-resistant authentication rule as supportThe critical infrastructure risk management rules return five hits for phishing and every one is the phrase phishing resistant multi-factor authentication. It is a credential control rather than a testing requirement, and quoting it is the misread a bare term count invites. The prudential information security standard, meanwhile, contains the word training zero times.
The controls that do the work
How Callstrike is configured, and which provision in Australia each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
The collection principle requires an organisation to collect personal information only by lawful and fair means, and the directly-related limb that agencies enjoy is not available to a company, so the standard here is the higher one and fair means is what a deception-based exercise has to satisfy. A call that ends the moment an employee begins to give up a credential collects the behaviour and never the thing the pretext asked for. It also protects the exemption you may be relying on: the regulator's own example of drift is a monitoring record that does not directly relate to the employment, and a captured credential is exactly the kind of record that wanders outside both limbs.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
Australia's notification principle does the opposite of what people expect: one of the matters it lists is the case where the individual may not be aware that the information was collected, so covertness triggers the notification duty rather than excusing it, and the vendor owes that duty even where the employer is exempt. A second voice that breaks character as the call ends, with vishing training in writing the same day, is the earliest possible discharge of a duty that was going to fall due anyway.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
This control does more in Australia than almost anywhere else in the portal, because here the record is not merely evidence of a notice: consent from all principal parties, obtained in advance, is the statutory route that makes the recording lawful in five of the eight jurisdictions. That makes two things load-bearing rather than tidy. It has to be per employee, since a jurisdiction-wide assertion proves nothing about the person who was called. And it has to be dated before the campaign, because a consent obtained afterwards is not a consent to the recording that was already made.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
Technology is not a route out of any Australian telephony instrument, and the statute says so: a voice call is defined to include one involving a recorded or synthetic voice, so an AI-voiced call is a voice call. What this route changes is that there is no call. Callstrike's vishing simulator carries the same deepfake voice into a web session the learner opens themselves after working through the module, which is the cleanest way to reach staff in a jurisdiction whose conditional recording limb you would rather not argue about. No Australian law in force requires disclosing that a voice is generated, so the module is not answering a disclosure duty, and the privacy principles follow whatever either route collects.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.