MYOB

Australia · www.myob.com · 32 vendors

MYOB is an Australian technology company specializing in cloud-based business management software solutions. It provides tools for accounting, payroll, tax, and other business services primarily to small and medium-sized enterprises in Australia and New Zealand.

Resilience scores

Disruption prediction

MYOB has an estimated 11% probability of disruption in the next 6 months.

15 of MYOB's 32 vendors monitored for disruptions.

Technology vendors

Services catalogue

6 services in catalogue across 2 categories; runs on 32 sub-vendors.

Insights

Last updated 2026-08-10 · revision 1

32 direct vendors, 287 subvendors

Direct vendors by controlling owner country (sample)

Subvendors by controlling owner country (sample)

Migration Readiness: 2/10

Assessed by AI based on technology stack characteristics (cloud-native vs legacy, containerization, microservices), regulatory environment, data residency requirements, financial stability, and vendor lock-in risks. The score ranges from 0-10, where higher scores indicate better readiness for technology migration.

MYOB's migration readiness is severely hampered by a significant lack of critical data. The most crucial factor, the company's internal tech stack (e.g., cloud-native adoption, containerization, microservices architecture), is entirely unspecified. Without this information, it's impossible to determine the ease or complexity of migrating existing applications and infrastructure. Further compounding this uncertainty are several other data gaps: * Regulatory environment and data residency requirements are not specified. These factors can introduce significant constraints and costs to any migration effort, particularly for a technology company operating in Australia. * Financial stability, which dictates the ability to fund a potentially large and complex migration project, is also unknown (no data on revenue concentration or growth history). * Regarding vendor relationships, while MYOB utilizes 32 services from vendors with diverse geographic HQs and owner countries (6-7 unique countries), the "Total Vendors: 0" is interpreted as "number of distinct vendors unknown." This prevents an assessment of vendor concentration. More critically, the "Vendor Lock-in Risk" is explicitly stated as "Unknown." If the 32 services are provided by a small number of highly integrated vendors, this could pose a substantial lock-in challenge, increasing migration complexity and cost. The geographic diversity of vendors, while beneficial for resilience, does not inherently reduce vendor lock-in if the services themselves are proprietary or deeply embedded. Due to the absence of information on its core technology, regulatory landscape, financial capacity, and the unknown vendor lock-in risk, MYOB's migration readiness is assessed as very low. There are no identifiable strengths in the provided data to suggest a smooth or straightforward migration path.

Compliance

11 in-scope frameworks identified; showing 3.

New Zealand Privacy Act 2020 — Compliant

MYOB operates in New Zealand and explicitly maintains a separate NZ Privacy Policy, indicating active compliance with the New Zealand Privacy Act 2020. Risk is Medium because MYOB processes financial and payroll data for New Zealand businesses, and the NZ Privacy Act 2020 introduced mandatory breach notification requirements and increased penalties. The NZ Privacy Commissioner has increased enforcement activity since the Act came into force.

Evidence: https://www.myob.com/au/legal/privacy-policy, https://www.myob.com/nz/legal/privacy-policy, https://www.privacy.org.nz/privacy-act-2020/

GDPR (source) — Assessment Required

MYOB's HQ is in Australia and its primary markets are Australia and New Zealand. MYOB does not appear to actively market to EU/EEA residents. However, GDPR risk cannot be dismissed entirely because: (1) MYOB's cloud platform is accessible globally and EU-based individuals (e.g., employees of Australian subsidiaries, EU-resident contractors, or EU-based users of MYOB products) may have their data processed; (2) MYOB's Privacy Policy discloses data transfers to the United States and the Philippines, which are common GDPR transfer risk indicators; (3) MYOB employs staff globally and may have EU-based employees whose HR data is processed. Risk is Medium rather than High because MYOB does not appear to specifically target EU markets, reducing the likelihood of large-scale EU personal data processing. However, without explicit confirmation that no EU personal data is processed, the risk cannot be rated Low.

Evidence: https://www.myob.com/au/legal/privacy-policy, https://gdpr.eu/what-is-gdpr/, https://www.myob.com/au/support/security

SOC 2 (source) — Assessment Required

MYOB is a cloud-based SaaS provider serving over one million businesses in Australia and New Zealand, processing highly sensitive financial, payroll, and tax data. SOC 2 is the globally recognised standard for cloud service providers demonstrating security, availability, processing integrity, confidentiality, and privacy controls. MYOB's security page references ISO 27001-based controls and PCI DSS compliance but does not explicitly mention SOC 2 certification. The absence of a publicly disclosed SOC 2 report is a medium risk because enterprise customers and accountants/bookkeepers increasingly require SOC 2 Type II reports as part of vendor due diligence. Without a SOC 2 report, MYOB's enterprise customers cannot independently verify the adequacy of MYOB's internal controls over financial reporting data.

Evidence: https://www.myob.com/au/support/security, https://www.myob.com/au/legal/category/trust-centre, https://www.myob.com/au/legal/commitment

Financials

Three-year financials

Financial Resilience Score: 6/10

MYOB demonstrates solid underlying business resilience through its entrenched incumbent position in the Australian and New Zealand SME software market, backed by 35 years of brand equity and a large installed base of small businesses, accountants, and bookkeepers. The company benefits from high recurring subscription revenue with strong visibility, low churn driven by compliance-linked products (Single Touch Payroll, BAS/GST, ATO integrations), and regulatory moats that create significant switching costs. Historical financials from its listed period (2016-2018) showed consistent revenue growth and stable EBITDA margins in the 43-45% range. However, resilience is materially constrained by the leveraged buyout capital structure imposed by KKR's 2019 take-private acquisition. Credit rating agencies have assigned speculative-grade ratings (Moody's B2, S&P B/B+), reflecting high leverage and refinancing risk in a higher-rate environment. The company faces intense competition from Xero and Intuit QuickBooks, with Xero having taken meaningful market share in cloud accounting. Geographic concentration in only Australia and New Zealand limits diversification, and reported book equity in ASIC-filed accounts has at times been negative or thin due to LBO structure. Limited public disclosure since going private reduces transparency for external stakeholders.

Key strengths: Deep incumbent position in AU/NZ SME software market with 35 years of brand equity, High recurring SaaS subscription revenue with strong visibility, Regulatory moat via compliance features (STP, BAS/GST, ATO integrations), Product breadth across sole traders, SME, mid-market ERP, and accounting practices, KKR sponsor backing providing capital for R&D and bolt-on M&A, Historical EBITDA margins of 43-45% during listed period

Risk factors: Intense competition from Xero and Intuit QuickBooks eroding market share, Leveraged LBO capital structure with B2/B credit ratings, Refinancing risk in higher-rate environment, Geographic concentration in only Australia and New Zealand, Legacy desktop-to-cloud migration execution risk, AI disruption potentially compressing pricing power in SME accounting, Limited public disclosure reduces stakeholder visibility

Revenue by geography

Revenue by product/service

Workforce by country

Signed-in users can see whether their own company is exposed to this vendor's disruption, plus the full sub-vendor list and country breakdowns, every in-scope compliance framework plus gaps and next steps, and alerts when any of it changes.

View the full interactive report