Australia's Regulatory Reform Agenda: How Boards and Executives Can Prioritise What Matters
Australia's Regulatory Reform Agenda: How Boards and Executives Can Prioritise What Matters
David Cantrick-Brooks | 14/09/2026

Australian businesses are confronting an unusually crowded regulatory change agenda.

Climate-related financial reporting is moving through its phased implementation. APRA is redesigning its governance standard. ASX is consulting on the fifth edition of its Corporate Governance Principles and Recommendations. Further major privacy reforms have been released for consultation. The Government is examining tougher regulation of accounting, auditing and consulting firms, reviewing whistleblower protections and proposing a criminal “failure to prevent” modern slavery offence.

And that is only part of the picture.

AML/CTF reforms have brought thousands of additional professional and property businesses into the regime. Australia's mandatory merger-control system is now operating. Payday Super commenced on 1 July. Listed entities and substantial holders face enhanced beneficial-ownership disclosure from December. Banks, telecommunications businesses and digital platforms are implementing the Scams Prevention Framework. New digital-asset legislation is moving towards commencement. Meanwhile, APRA and ASIC are consulting on ways of reducing the administrative load of the Financial Accountability Regime.

For boards, executives and governance professionals, the problem is no longer simply “What new regulation applies to us?”

The more useful question is:

How do we absorb a portfolio of overlapping regulatory changes without allowing regulatory implementation itself to overwhelm the organisation?

More regulation – but also regulatory simplification

There is an understandable temptation to view the present environment as a relentless expansion of regulation. That description, however, is incomplete.

Some reforms unquestionably increase obligations. The current privacy exposure draft, for example, would significantly reshape the way APP entities collect, use and disclose personal information. Allens has described it as potentially the most significant overhaul of Australian privacy law since the APPs were introduced.

The proposed modern-slavery offence would similarly move larger businesses beyond transparency reporting towards potential criminal exposure where reasonable preventative steps have not been taken.

But other developments are deliberately deregulatory.

The draft fifth edition of the ASX Corporate Governance Principles seeks to remove duplication and reduce prescription. APRA's governance reforms include streamlining elements alongside stronger substantive expectations. APRA and ASIC are proposing to simplify FAR reporting. The SOCI review expressly seeks to reduce complexity and regulatory duplication. Treasury is considering ways of making climate reporting more efficient without reopening the core architecture of the regime.

More broadly, the Commonwealth's whole-of-government regulatory-reform program is expressly focused on productivity and unnecessary regulatory burden. The Department of Finance reported in September 2026 that regulators had identified more than 400 reform ideas and approximately 150 potential actions capable of being progressed without additional legislation or Budget funding.

The better description, therefore, is not simply “more regulation”. It is a large volume of simultaneous regulatory change – some additive, some corrective and some simplificatory.

That distinction matters.

The real risk is cumulative

A single regulatory reform can usually be managed. The difficulty arises when several changes compete simultaneously for the same people, systems, data and governance capacity.

Climate reporting may require finance, risk, sustainability, procurement, internal audit and external assurance resources. Privacy reforms touch technology, cyber security, marketing, procurement, legal, HR and data governance. Modern-slavery reforms involve supply chains, procurement and risk. AML/CTF changes involve customer onboarding, transaction monitoring, recordkeeping, training and governance. CPS 510 and FAR involve boards, senior executives, accountability frameworks and organisational design.

Viewed individually, each project can appear manageable. Viewed collectively, they can create change congestion.

That is where regulatory fatigue becomes a genuine governance risk.

The danger is not simply that employees become tired of regulation. It is that scarce subject-matter experts become spread across too many projects; temporary solutions proliferate; the same data is collected several times for different purposes; policies are amended without underlying processes changing; technology work is rushed; and boards receive multiple disconnected regulatory updates without a clear picture of aggregate implementation risk.

Proportionality matters

There is also a legitimate public-policy question about cumulative regulatory cost.

The point should not be overstated. Regulation can generate substantial economic benefits by supporting market confidence, protecting customers and investors, reducing financial crime and systemic risk, increasing transparency and establishing common standards.

But benefits do not eliminate the need to test cost, proportionality and implementation practicality.

That concern is apparent in recent professional commentary. In responding to Treasury's options for audit and consulting firm regulation, the AICD supported stronger accountability and oversight in several areas but cautioned against disproportionate, one-size-fits-all measures and downstream costs for reporting entities. CPA Australia similarly supported stronger firm-level accountability while opposing structural measures it considered unnecessarily disruptive.

This is an important distinction. The relevant debate should not be regulation versus deregulation. It should be about designing regulation that achieves a demonstrable objective at a proportionate cost and interacts sensibly with the rest of the regulatory architecture.

What should businesses do?

The answer is not to launch another stand-alone compliance project every time a consultation paper appears. A better approach is to manage regulatory change as an enterprise portfolio.

Create one regulatory-change register. Record each significant reform, its status, applicability, likely commencement, accountable executive, affected board committee, dependencies and required changes to policies, systems, contracts, data and controls. Critically, distinguish between enacted obligations, exposure drafts, policy proposals and reviews.

Triage by certainty, materiality and lead time. An enacted obligation commencing in three months should not compete on equal terms with a policy option that may never become law. High-impact changes with long technology or data lead times may nevertheless require early investment. The objective is to identify what must be done now, what represents sensible “no-regrets” preparation and what should simply be monitored.

Look for common capabilities rather than separate projects. Privacy, AI and cyber reform all depend on good data governance. Climate reporting, modern slavery and SOCI requirements intersect with supplier and third-party risk. CPS 510 and FAR intersect with governance, accountability and role clarity. Treating these as connected capabilities can reduce duplication and improve control quality.

Do not implement draft law as though it were final. Early preparation is often prudent; premature implementation is not. Data mapping, contract inventories, governance gap assessments and system-readiness work can often proceed before legislation is settled. Hard-coding an uncertain regulatory proposal into systems or operating models may simply create rework.

Give the board a portfolio view. Boards generally do not need twenty separate presentations on twenty regulatory developments. They need to know which changes are material, what decisions are required, whether implementation is on track, what dependencies or resource conflicts exist and where management believes the organisation is taking implementation risk.

Use consultation processes strategically. Where a proposal creates genuine implementation difficulty, businesses and industry bodies should provide evidence. Cost estimates, technology lead times, overlap with existing obligations and practical examples are considerably more persuasive than a general complaint about “red tape”. Notably, APRA and ASIC are expressly asking FAR respondents to quantify time and cost impacts where possible.

Could some reforms be deferred or wound back?

Yes – but “wound back” may be the wrong way to think about it.

Consultation can lead to narrower scope, longer transition periods, simpler reporting, proportionality mechanisms or removal of duplication. We are already seeing examples. Treasury is reconsidering aspects of climate-reporting assurance and implementation efficiency; APRA and ASIC are looking to reduce FAR administration; the revised ASX Principles deliberately remove regulatory duplication; and the SOCI review is partly a simplification exercise.

Business advocacy may influence those outcomes, but governments and regulators will ultimately need to balance cost against investor, consumer, employee, national-security and market-integrity objectives.

That is a healthier debate than assuming either that every proposed regulation is necessary or that every regulatory burden is inherently unproductive.

A governance issue in its own right

Australia's current regulatory pipeline presents an interesting paradox.

Good regulation is intended to improve behaviour, accountability, transparency and resilience. But a sufficiently large volume of poorly sequenced or duplicative regulation can itself create operational and governance risk.

Boards therefore need to look beyond individual regulatory obligations.

They should be asking whether the organisation has enough implementation capacity; whether different regulatory programs are being coordinated; whether scarce resources are being allocated to the highest risks; whether management is distinguishing settled obligations from policy uncertainty; and whether regulatory change is producing sustainable improvements in controls rather than additional layers of documentation.

The organisations that navigate the next few years most successfully will probably not be those that try to do everything immediately.

They will be those that know what is certain, what is material, what is connected, what requires action now – and what can sensibly wait.

That, ultimately, is as much a matter of governance as it is compliance.

PreviousNext

Related Articles

From Boardroom Adviser to Board Member: Could Company Secretaries Make Good Directors?

Could a career company secretary make a good non-executive director? The answer may be yes - provided boards look beyond job titles and assess the whole candidate. Experienced company secretaries can bring unusual boardroom fluency, governance and regulatory judgement, an enterprise-wide view of information flows and strong insight into board-management dynamics. But they may also need to demonstrate commercial depth, industry knowledge, decision ownership and the ability to move from adviser to director. This article tests the case against current Australian law, the draft 5th edition ASX Corporate Governance Principles, APRA's draft CPS 510, leading governance guidance and recent case law. It concludes that a former company secretary should not be treated as a board's “governance insurance policy” - governance remains a collective responsibility - but where governance, risk, information integrity and constructive challenge are genuine capability gaps, experienced company secretaries deserve serious consideration in board succession planning.

09/13/2026

Revisiting the Board Agenda: Read the Past, Discuss the Future

Are boards spending enough of their scarce meeting time looking forward? Board agendas necessarily contain backward-looking matters such as performance reporting, financial results, risk, compliance and assurance. But they must also preserve sufficient time for strategy, emerging risks and opportunities, capital allocation, succession and the decisions that will shape the organisation's future. This article considers whether recasting a board agenda through a backward-looking and forward-looking lens could provide a useful diagnostic of how board attention is being allocated. It also explores an important distinction between the time a board plans to spend on particular matters and the time it actually spends discussing them. The objective is not less oversight or less governance. It is to ask whether the board is making the best possible use of one of its scarcest resources: its collective attention.

09/08/2026

Why Industry Matters: Regulatory Intensity Across Australian Business

How heavily regulated is Australian business? The answer depends substantially on the industry concerned. While most businesses operate within a common regulatory baseline, some sectors are subject to extensive additional licensing, prudential, safety, operational, reporting and governance requirements. Regulatory intensity tends to be greatest where business failure could cause systemic financial harm, threaten life or vulnerable people, result in catastrophic safety or environmental consequences, or disrupt critical infrastructure. Australia’s federal structure can add further complexity through overlapping Commonwealth, State and Territory requirements. The governance implication is important: although good governance principles are broadly transferable, effective governance frameworks cannot be entirely industry-neutral. They need to reflect the organisation’s actual regulatory architecture, risk profile, complexity and operating environment.

09/01/2026