Callstrike
Compliance

Voice phishing simulations in Australia

Phone numbers in AustraliaProvisioned by Callstrike after approval

Australia has no single answer on recording a voice phishing simulation, and the usual two-way split is wrong: three jurisdictions put someone on the call outside the offence by definition, five attach conditions, and four restrict what you may do with a recording that was lawful to make. So the Australian decision is where each person you call is sitting, and it belongs to the target list rather than to a review afterwards.

Phone numbers

Supplied by Callstrike

Local numbers in Australia, after a one-time approval.

Running a simulation

Permitted, and it changes at the border

Eight jurisdictions and three different answers on whether you may record at all.

Consent

What settles five of the eight

All principal parties, obtained in advance, avoids the conditional limbs entirely.

Getting a phone number in Australia

One approval per country, completed in the console.

Provisioned by Callstrike after approval

Numbers here are not released from open inventory. Your workspace is cleared for this country once, and Callstrike then provisions a dedicated number against it for your simulations. Approval is a one-time, per-country step and usually takes 3 to 5 business days. We only ask for what the regulator requires.

One line in the Australian table below is conditional on another, and pulling the documents in the wrong order is what costs a week. Proof of business identity is the long-form company extract from the corporate regulator, the version that includes the officer names and the business address rather than the short one. Whether you then need a letter of authority depends on what that extract says: if your authorised representative is listed on it as a director, officer or other official contact, the extract is itself the proof and no letter is needed. If they are not, a letter of authority signed by one of the directors named on the extract has to accompany it. So pull the extract first and read it before deciding who signs.

The rest is ordinary: a government-issued photo identity document or passport for that representative, and proof of an address within Australia, which will take the extract, a utility bill, a tax notice, a rent receipt or a title deed, with no post office box where a local address is required. Alongside the uploads the console form asks for your business registration number, your website, your business classification and the representative's contact details.

  1. 01Complete the regulatory clearance formYour administrator, in the Callstrike console. The form asks only for what the regulator requires.
  2. 02Approval is granted against your workspaceTypically three to five business days, and once only for as long as you operate here.
  3. 03A dedicated number in Australia is assigned to youCallstrike
  4. 04Build and launch the campaignYour team
What you provideAccepted evidence, any one of
Proof of business identityAustralian businesses must provide the Current Company Extract or Record of Registration for Business which can be obtained through the ASIC Portal. All businesses must provide the long form extract, which includes the officer names and business address.Commercial registry or equivalent showing officers and address
Proof of addressMust be within Australia; a PO Box is not acceptable where a local address is required.Commercial registry or equivalent showing address, Utility bill, Tax notice, Rent receipt, Title deed
Proof of authorized representative identityGovernment-issued ID, Passport
Proof of authorizationIf the Authorized Representative’s name is listed on the Extract as a Director/Officer or other official contact person, no LOA is required. Your extract serves as direct proof. If the Authorized Representative’s name is NOT listed on the Extract, you must upload a Letter of Authorization signed by one of the Directors named on your Extract (e.g., if "John Citizen" is the Director on the Registry document, John must sign the LOA authorizing the named Authorized Representative).Letter of authorization, Commercial registry or equivalent showing name of authorized representative

These requirements are set by the carrier and can change. The form in the console is generated from their current rules, so treat it as authoritative and this table as a summary of what to have ready. Checked 2026-09-07.

Is it lawful to run a simulation in Australia?

The position in short, before your counsel reads the detail below.

Yes, and the first Australian surprise is that the federal privacy statute may not reach you at all. An act by an organisation that is or was an employer is exempt from the privacy principles where it is directly related both to a current or former employment relationship and to an employee record about that individual. Its limits are numerous: it is available to organisations only, a small business operator never reaches it because the definition excludes them from being an organisation in the first place, and it covers neither prospective employees, nor volunteers, nor a third party the call happens to reach. The limit that matters commercially is the one people miss. The regulator states that the exemption does not cover contractors handling another organisation's employee records, whatever the contractual arrangements, and that such a contractor must comply with the principles including the notification requirements. So Callstrike is fully bound by them even where the exemption covers your own side of the programme.

Recording is state and territory law and it falls into three groups rather than the two most summaries offer. Victoria, Queensland and the Northern Territory each confine the offence to a conversation the person is not a party to, or supply an express exception where the person using the device is a party, so no condition and no balancing test applies. The Northern Territory belongs in that group and is routinely misfiled into the restrictive one. New South Wales, Western Australia, South Australia, Tasmania and the Australian Capital Territory each permit a party to record where all principal parties consent, or where one consents and the recording is reasonably necessary to protect that party's lawful interests.

Three of those five add a further route, and it is where the trap sits. They permit a recording made otherwise than for the purpose of communicating or publishing the conversation to people who are not parties to it, and a simulation exists in order to report the result to a security team or to human resources, who are not parties. So it falls outside that limb by design and throws you back on reasonably necessary for the protection of lawful interests, which no primary source resolves for an authorised security test. Obtaining the consent of all principal parties in advance, through the programme notice, avoids the question in all five. The reverse surprise is worth planning for too: four jurisdictions restrict what may be done with a recording regardless of whether making it was lawful, so the two most permissive on making one are among the strictest on circulating it.

Two corrections close the position. Do not describe Australia as one-party-consent at federal level, because the federal interception statute contains no participant exception anywhere and its definition keys on the knowledge of the person making the communication, which in a two-way call is a different person each way. What keeps endpoint recording outside the federal prohibition is a definitional provision: a communication passes over the system only until it becomes accessible to the intended recipient, so the federal question is architecture rather than agreement. And the New South Wales workplace surveillance statute, which looks like the centrepiece of an Australian monitoring analysis, does not reach a telephone call at all: its definition is closed to camera, computer and tracking surveillance, as is the Australian Capital Territory's. Those regimes matter the moment a campaign adds email or endpoint telemetry, and not before.

What your company needs to do

8 items, in the order you will need them.

  • Record which state or territory each person sits inAustralia-specificThe recording answer changes at a state border and there are three of them, so the jurisdiction has to be a field on the target list rather than something reconstructed later. It is also what tells you which of the eight maxima you would be exposed to, and they range from twelve months to five years.
  • Obtain all-principal-party consent in advance through the programme noticeAustralia-specificThis is the design that avoids the question in all five conditional jurisdictions without needing anyone to resolve whether an authorised security test is reasonably necessary to protect your lawful interests. It has to be per employee and it has to predate the first call.
  • Take a separate decision about onward circulationAustralia-specificVictoria, Western Australia, South Australia and the Northern Territory restrict what may be done with a record made by a listening device whether or not making it was lawful, and South Australia specifically restricts use where the lawful-interests limb was the basis for making it. Reporting a result is a different question from capturing it.
  • Do not assume your vendor is covered by your exemptionAustralia-specificThe employee records exemption is available to an organisation about its own employees. The regulator says a contractor handling another organisation's employee records must comply with the principles including notification, whatever the contract says, and the contractor is the one holding the recordings.
  • Record at the endpoint, once the call has been deliveredAustralia-specificThe federal statute protects a communication while it passes over the system, and passage ends when the communication becomes accessible to the intended recipient. Recording on the handset, the exchange or the platform's own leg after delivery is outside that passage. Getting it wrong is an indictable offence carrying up to two years.
  • Give fourteen days' notice if the campaign adds email or endpoint telemetryAustralia-specificThat is computer surveillance, and in New South Wales it needs prior written notice at least fourteen days beforehand stating the kind of surveillance, how it will be carried out, when it starts, whether it is continuous or intermittent and whether it is time-limited, plus a policy notified in a way that makes it reasonable to assume the person understands it. The Australian Capital Territory adds good-faith consultation for at least the notice period, defined as a genuine opportunity to influence the conduct of the surveillance.
  • Do not reach for a covert surveillance authorityIn New South Wales it comes from a Judge of the Local Court, does not authorise covert surveillance for monitoring work performance, and lasts at most thirty days. In the Australian Capital Territory it is available only to find out whether a worker is engaged in unlawful activity. A simulation suspects nobody, so neither door opens.
  • Do not cite the phishing-resistant authentication rule as supportThe critical infrastructure risk management rules return five hits for phishing and every one is the phrase phishing resistant multi-factor authentication. It is a credential control rather than a testing requirement, and quoting it is the misread a bare term count invites. The prudential information security standard, meanwhile, contains the word training zero times.

The controls that do the work

How Callstrike is configured, and which provision in Australia each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

The collection principle requires an organisation to collect personal information only by lawful and fair means, and the directly-related limb that agencies enjoy is not available to a company, so the standard here is the higher one and fair means is what a deception-based exercise has to satisfy. A call that ends the moment an employee begins to give up a credential collects the behaviour and never the thing the pretext asked for. It also protects the exemption you may be relying on: the regulator's own example of drift is a monitoring record that does not directly relate to the employment, and a captured credential is exactly the kind of record that wanders outside both limbs.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

Australia's notification principle does the opposite of what people expect: one of the matters it lists is the case where the individual may not be aware that the information was collected, so covertness triggers the notification duty rather than excusing it, and the vendor owes that duty even where the employer is exempt. A second voice that breaks character as the call ends, with vishing training in writing the same day, is the earliest possible discharge of a duty that was going to fall due anyway.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

This control does more in Australia than almost anywhere else in the portal, because here the record is not merely evidence of a notice: consent from all principal parties, obtained in advance, is the statutory route that makes the recording lawful in five of the eight jurisdictions. That makes two things load-bearing rather than tidy. It has to be per employee, since a jurisdiction-wide assertion proves nothing about the person who was called. And it has to be dated before the campaign, because a consent obtained afterwards is not a consent to the recording that was already made.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

Technology is not a route out of any Australian telephony instrument, and the statute says so: a voice call is defined to include one involving a recorded or synthetic voice, so an AI-voiced call is a voice call. What this route changes is that there is no call. Callstrike's vishing simulator carries the same deepfake voice into a web session the learner opens themselves after working through the module, which is the cleanest way to reach staff in a jurisdiction whose conditional recording limb you would rather not argue about. No Australian law in force requires disclosing that a voice is generated, so the module is not answering a disclosure duty, and the privacy principles follow whatever either route collects.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

An exemption the employer may have and the vendor never does

Australia's structure is the biggest difference between this page and the European ones. There is a federal privacy statute, but a private-sector employer may be outside it altogether for this activity.

Start with what applies when it does apply. An organisation must not collect personal information unless it is reasonably necessary for one or more of the entity's functions or activities, and must collect only by lawful and fair means. The directly-related limb that agencies enjoy is not available to a company, so the standard is the higher one, and fair means is the provision a deception-based exercise has to satisfy.

The notification principle is worth reading closely because it does the opposite of what people assume. It requires reasonable steps to notify the individual of listed matters at or before collection or, if that is not practicable, as soon as practicable afterwards. And one of the listed matters is expressly the case where the individual may not be aware that the entity has collected the information: the fact of that collection and the circumstances of it are themselves notifiable. Covertness triggers the notification duty; it does not excuse it.

Now the exemption. An act or practice by an organisation that is or was an employer is exempt from the principles if it is directly related both to a current or former employment relationship and to an employee record held by the organisation relating to that individual. Two limbs, joined by and, and the effect is to take the act outside the principles entirely rather than to soften them.

Its limits are where the work is, and they are more numerous than the headline suggests. It is available to organisations only, and an agency or a State or Territory authority is not an organisation. A small business operator never reaches the exemption at all, because the definitional provision is structurally prior: a business with annual turnover of three million dollars or less is not an organisation in the first place, though it is disqualified from that status if it discloses or collects personal information for a benefit. The definition of an employee record is limited by the words relating to the employment, with the lettered list being examples rather than the boundary. It does not cover prospective employees, so an unsuccessful applicant is outside it. It does not cover volunteers. And it is framed around the employee, so personal information about a third party the call happens to reach is outside both limbs.

The limit that matters commercially is the one people miss. The regulator states in terms that the exemption does not cover contractors and subcontractors handling the personal information of another organisation's employees, whatever their contractual arrangements, and that such a contractor must comply with the principles including the notification requirements. So a simulation platform is fully bound even where its customer is exempt. A page that says the principles do not apply is right about the employer and wrong about the vendor, and the vendor is the one holding the recordings.

The regulator adds one more thing that reopens the door. Its position is that the Privacy Act does not specifically cover workplace surveillance, that an employer must follow the relevant Australian, state or territory laws including those on monitoring and recording telephone conversations, and that if the employer keeps a record of its monitoring the principles may apply, giving as its example a record that does not directly relate to the employment. The exemption is about employee records, not about monitoring, and a record that drifts outside the employment relationship drifts back into the statute.

Eight jurisdictions, three answers, and a trap in the middle group

There is no Australian answer to whether you may record. There are eight, and they fall into three groups rather than the two most summaries offer.

Three jurisdictions put a participant outside the offence by definition. Victoria, Queensland and the Northern Territory each confine the prohibition to a private conversation to which the person is not a party, or in Queensland's case supply an express exception where the person using the device is a party. No consent, no condition and no balancing test is needed. The Northern Territory belongs in this group and is routinely misfiled into the restrictive one.

Five jurisdictions attach conditions. New South Wales, Western Australia, South Australia, Tasmania and the Australian Capital Territory each permit a party to record where all principal parties consent expressly or impliedly, or where one principal party consents and the recording is reasonably necessary for the protection of that party's lawful interests. New South Wales, Tasmania and the ACT add a third route: where the recording is not made for the purpose of communicating or publishing the conversation to persons who are not parties to it.

That third route contains the trap. A simulation exists in order to report the result to a security team or to human resources, who are not parties to the call, so it appears to fall outside that limb by design, throwing the employer back on reasonably necessary for the protection of lawful interests. No primary source resolves whether an authorised security test satisfies that test, and we are not going to resolve it for you. Obtaining the consent of all principal parties in advance, through the programme notice, avoids the question in all five conditional jurisdictions and is the design we would recommend.

The second surprise is that permissive and restrictive swap places once you circulate the file. Victoria, Western Australia, South Australia and the Northern Territory each restrict what may be done with a record made by a listening device regardless of whether making it was lawful; New South Wales does not, because its provision bites only on recordings made in contravention of the relevant Part. So the two most permissive jurisdictions on making a recording, Victoria and the Territory, are among the strictest on reporting it, and South Australia specifically restricts use where the lawful-interests limb was the basis for making it.

The maxima are real money. New South Wales runs to one hundred penalty units or five years or both for an individual and five hundred penalty units for a corporation; South Australia to fifteen thousand dollars or three years for an individual and seventy-five thousand for a body corporate; Western Australia to five thousand dollars or twelve months for an individual and fifty thousand for a body corporate; Tasmania to forty penalty units or two years, with five hundred penalty units for a corporation.

Above all of it sits a Commonwealth statute that is widely described incorrectly. The federal interception prohibition contains no participant exception anywhere, and its carve-outs are for carrier employees, installers, authorised network-protection duties and warrants. Its definition of interception keys on the knowledge of the person making the communication, which in a two-way call is a different person for each direction of speech. Do not describe Australia as a one-party-consent country at federal level: the Act contains no such rule.

What actually keeps endpoint recording outside the federal prohibition is a definitional provision. A communication is taken to pass over a telecommunications system until it becomes accessible to the intended recipient, and it is accessible once it has been received by the service provided to that recipient, is under their control, or has been delivered to their service. So the federal question is architecture rather than consent: recording at the endpoint, on the handset, the exchange or the platform's own leg once the call has been delivered, is outside the passage the Act protects. Getting it wrong is an indictable offence carrying up to two years.

A purpose test, an eligibility test, and no AI disclosure duty

Australia's telemarketing regime is scoped by purpose, and an internal security test fails to reach it on two independent grounds.

A telemarketing call is a voice call to an Australian number where, having regard to the content and the presentational aspects of the call, it would be concluded that a purpose of the call is to offer to supply, advertise or promote goods, services, land or a business or investment opportunity, or to solicit donations, or a purpose specified in the regulations. An exercise that offers, promotes and solicits nothing is not a telemarketing call, and the prohibition on calling a registered number applies only to telemarketing calls.

The second gate is eligibility. A number may be entered on the register only if it is used or maintained primarily for private or domestic purposes, or exclusively for faxes, or belongs to a government body or an emergency service. A work number is generally not eligible at all, so there is usually nothing on the register to breach.

Technology is not a route out of either instrument, and it is worth saying because it is the obvious hope. The Act defines a voice call to include a call that involves a recorded or synthetic voice. An AI-voiced call is a voice call.

The industry standard that governs telemarketing practice is the best available operational template and it does not bind an internal test. It applies to participants in each section of the telemarketing industry and defines call throughout to mean a telemarketing call. Within its own scope it forbids calls on a weekday before nine or after eight in the evening, on a Saturday before nine or after five, or at any time on a Sunday; it requires the caller to give, as soon as the call starts, their name unless the call is made solely using a recorded or synthetic voice, the employer or business name and the purpose of the call; it requires immediate termination on request; and it requires calling line identification to be enabled. Every one of those is a sensible design choice for a simulation. None of them is a legal obligation on one.

One correction for anyone checking the citations: the definition of a research call is not in the do-not-call statute at all. It is in the Telecommunications Act, which covers opinion polling and standard questionnaire-based research.

On synthetic voice, the answer is a clean negative. There is no Australian law in force requiring disclosure that a caller's voice is AI-generated. A title search of the federal register returns two artificial intelligence instruments, both grant-programme instruments with no disclosure obligation, and one deepfake statute confined to sexual material. The only telecoms rule touching a synthetic voice runs the other way: the industry standard excuses the given-name disclosure precisely when the call is made solely by recorded or synthetic voice.

What exists is voluntary and says so. The national voluntary AI safety standard's sixth guardrail asks organisations to inform end users about interactions with AI and AI-generated content and to disclose when AI is used, and the standard describes itself as ten voluntary guardrails. The proposal to make guardrails mandatory was abandoned: the government has said it will not proceed at this time with the previous proposals.

Overstamping is lawful, and the carrier checks the right of use

Australia says out loud what most countries leave implicit, and the answer is more permissive than the neighbours: presenting a different number is lawful, presenting one you do not hold is not.

The regulator's own explanation is direct. Overstamping allows the caller to display a different number from the one they are calling from; freephone and local-rate numbers and invalid or unallocated Australian numbers cannot be used for it; overstamping is legal in Australia; and overstamping done for unlawful or malicious purposes, most commonly to carry out scams, is what is meant by spoofing.

The enforcement sits with the carriers under a registered industry code, which applies to the carrier and service provider section of the industry rather than to callers. Its operative requirement is short: originating providers must prevent carriage of calls where the calling party does not hold rights of use to the number. A companion clause forbids the use of freephone, local-rate and premium numbers as a calling identity. And the code itself notes the difficulty that makes all of this fuzzy in practice: legitimate calls, including telemarketing calls, can exhibit the same characteristics as scam calls, so further evidence is needed to identify one.

Rights of use is a defined creature of a different registered code and arises only from a service provider issuing the number to a customer, lasting only while the service remains active. So the compliant design in Australia is to hold the number through your carrier and present it, and the prohibition on presenting a number you do not hold is enforced upstream of you rather than against you.

One currency correction for anyone checking the numbering framework. The Telecommunications Numbering Plan of 2015 is repealed; the plan in force is the 2025 one, whose obligations likewise run to providers, requiring that a provider not issue a number to a customer unless the provider holds it, and that no other number be used in connection with the supply of carriage services to the public in Australia.

What the country matrix holds for Australia

Number types:
Local
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

The workplace surveillance statutes do not reach a phone call

This is the correction most likely to change how an Australian programme is designed, and it runs in the employer's favour.

New South Wales has a dedicated workplace surveillance statute with a fourteen-day notice regime, and it does not reach a telephone call. Its definition of surveillance of an employee is closed to three means: camera surveillance, computer surveillance, and tracking surveillance. The Act carries a note saying it does not apply to surveillance by means of a listening device and pointing at the surveillance devices statute instead. Notes are not part of that Act, so the exclusion rests on the closed definition itself rather than on the note, which is a stronger foundation not a weaker one.

The Australian Capital Territory equivalent is the same shape: its surveillance device is closed to data, optical and tracking devices. So the two statutes that look like the centrepiece of an Australian workplace monitoring analysis are largely beside the point for a voice exercise. Victoria has no general workplace surveillance notice statute at all, its dedicated part being confined to toilets, washrooms, change rooms and lactation rooms, and Queensland has none.

They matter the moment a campaign acquires an email or endpoint telemetry component, because that is computer surveillance. In New South Wales, surveillance must not commence without prior written notice given at least fourteen days beforehand, stating the kind of surveillance, how it will be carried out, when it starts, whether it will be continuous or intermittent, and whether it is for a limited period or ongoing, with email counting as writing. Computer surveillance additionally requires a policy on it and advance notification of that policy in a way that makes it reasonable to assume the employee understands it.

The Australian Capital Territory adds a duty New South Wales does not have. On top of fourteen days' notice, the employer must consult the worker in good faith about the conduct of the surveillance for at least the notice period, and the Act defines good faith as giving the worker a genuine opportunity to influence the conduct of the surveillance. That is the strongest consultation duty anywhere in Australian workplace monitoring law.

Covert surveillance in both territories is essentially unavailable for this purpose. In New South Wales an employer must not carry out covert surveillance of an employee at work without an authority from a Judge of the Local Court, such an authority does not authorise covert surveillance for the purpose of monitoring work performance, and it lasts at most thirty days. In the Australian Capital Territory the application goes to the Magistrates Court and is available only for the purpose of finding out whether the worker is engaged in unlawful activity in the workplace. A simulation suspects nobody of unlawful activity, so neither door opens.

The Australian file is therefore assembled from several sources rather than prescribed by one. A programme notice or policy issued before the first call, stating that calls to staff may be recorded and simulated and naming the entity, purpose, retention and access, which the notification principle supplies the checklist for and which the vendor owes even where the employer is exempt. Recorded evidence of that notice per employee, because it is what supplies all-principal-party consent in the five conditional jurisdictions. A record of which jurisdiction each target sits in, because the answer changes at a state border. A separate decision about onward circulation, because four jurisdictions restrict publishing a lawfully made recording. And, if any endpoint or email telemetry is collected in New South Wales or the Australian Capital Territory, the fourteen-day written notice and, in the Territory, the good-faith consultation.

Five phishing hits that are all about authentication

Neither of Australia's critical-infrastructure instruments mandates, mentions or contemplates a vishing simulation, a phishing simulation or social engineering testing, and the way one of them appears to is a trap worth walking through.

Counted over the authorised texts, the critical infrastructure Act returns zero for phishing, voice phishing, social engineering and simulation alike. The risk management programme rules return zero for three of those and five for phishing. Read the five and they are all the same phrase: phishing resistant multi-factor authentication. It is a credential control requiring the entity to implement such authentication for specified systems and to centrally log, monitor and routinely review both successful and unsuccessful attempts. It is a control requirement, not a testing requirement, and citing it as support for running simulations would be a misread of exactly the kind a bare term count invites.

What the rules do require on the human side is a personnel-hazard process: identify the entity's critical workers, permit access to critical components only where a critical worker has been assessed as suitable, and so far as reasonably practicable minimise or eliminate material risks arising from malicious or negligent employees and contractors and from the off-boarding process. On the cyber hazard they require compliance with one of five named frameworks or an equivalent.

For regulated financial entities the prudential standard on information security requires testing the effectiveness of information security controls through a systematic testing programme whose nature and frequency is commensurate with the rate at which vulnerabilities and threats change, the criticality and sensitivity of the asset, the consequences of an incident, the risks of environments where the entity cannot enforce its policies, and the materiality and frequency of change. It requires testing by appropriately skilled and functionally independent specialists, and an annual review of whether the programme is sufficient.

It says nothing about people at all. Counted through, the standard contains the word training zero times, and phishing, voice phishing, social engineering and simulation zero times each. The newer operational risk standard, in force from 1 July 2026, requires scenario analysis to identify and assess the potential impact of severe operational risk events and to test operational resilience, and returns the same zeros.

So the honest Australian position on sector mandates is that none of them names this activity, and the closest thing to a hook is the requirement to test the effectiveness of controls through a systematic programme. Whether people are part of the controls being tested is a decision for the entity, not an instruction from the regulator.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in AUSTRALIA. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. A programme notice was issued to all staff before the first call.

Verify or correct each proposition below against primary Australian sources, and tell me what changes at each state border:

1. ⚠⚠ The recording partition is THREE PERMISSIVE (VIC s 6, QLD ss 43/45, and NT s 11(1)(a), which is confined to a conversation «to which the person is not a party») and FIVE CONDITIONAL (NSW, WA, SA, TAS, ACT). Confirm the NT sits with VIC and not with NSW.
2. ⚠ Four jurisdictions restrict USE of a lawfully made recording (VIC s 11, WA s 9, SA s 9, NT s 15) while NSW s 11 bites only on Part 2 contraventions. Confirm.
3. In NSW, TAS and the ACT, does the «not for the purpose of communicating or publishing to non-parties» limb fail by design for a programme that reports results to security or HR? If so, does an authorised security test satisfy «reasonably necessary for the protection of lawful interests»?
4. ⚠ DO NOT assume federal one-party consent: the TIA Act contains NO participant exception and s 6(1) keys on the knowledge of «the person making the communication». Confirm s 5F(b) (passage ends when the communication becomes accessible to the intended recipient) is what puts endpoint recording outside s 7.
5. ⚠⚠ Privacy Act s 7B(3): does the employee records exemption cover our VENDOR? OAIC says a contractor handling another organisation's employee records must comply with the APPs «including the notice requirements in APP 5». Confirm.
6. ⚠ Workplace Surveillance Act 2005 (NSW) s 3 and Workplace Privacy Act 2011 (ACT) define surveillance CLOSED to camera/optical, computer/data and tracking, so neither reaches a telephone call. Confirm, noting NSW s 7 says notes are not part of the Act.
7. APP 5.2 lists, as a notifiable matter, the case where the individual may not be aware the entity collected the information. Confirm covertness triggers rather than excuses notification.
8. The five «phishing» hits in the CIRMP Rules are all «phishing resistant multi-factor authentication» (r 8B), a control not a testing requirement, and CPS 234 contains «training» zero times. Confirm.

⚠ The Telecommunications Numbering Plan 2015 is REPEALED by the 2025 Plan, s 4. Flag anything that has changed since September 2026.

Common questions

Does the Privacy Act cover our simulation?
It may not cover the employer, because of the employee records exemption. It certainly covers the vendor: the regulator says a contractor handling another organisation's employee records must comply with the privacy principles including the notification requirements, whatever the contract says.
Can we record the call in Australia?
It depends which state the person is in. Victoria, Queensland and the Northern Territory put a party outside the offence by definition. New South Wales, Western Australia, South Australia, Tasmania and the ACT attach conditions. Consent from all principal parties, obtained in advance, works everywhere.
Does NSW workplace surveillance law apply to a phone call?
No. Its definition of surveillance is closed to camera, computer and tracking, and the Act points at the surveillance devices statute for listening devices. The same is true in the ACT. Those regimes bite only if your campaign also collects email or endpoint telemetry.
Must we disclose that the voice is AI-generated?
No Australian law in force requires it. The national AI safety standard asks for it and describes itself as voluntary, and the mandatory guardrails proposal was abandoned. The telemarketing standard actually excuses the caller's name disclosure when the call uses a synthetic voice.

Elsewhere in Asia Pacific

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.