Why Industry Matters: Regulatory Intensity Across Australian Business
Why Industry Matters: Regulatory Intensity Across Australian Business
David Cantrick-Brooks | 01/09/2026

This article considers mandatory regulatory requirements in force as at 31 August 2026.

How heavily regulated is Australian business? There is no single answer.

Most Australian businesses operate within a common regulatory baseline: corporations and business-registration requirements, taxation, employment law, workplace health and safety, competition and consumer law, privacy and other generally applicable obligations. Above that baseline, however, the intensity of mandatory industry-specific regulation varies markedly.

That difference matters for governance.

A better way to think about regulation

It is tempting to ask which industries have the greatest “amount” of regulation or the heaviest regulatory “burden”. Neither expression is ideal. Regulation cannot readily be counted, and compliance cost is not the same thing as regulatory intensity.

“Regulatory intensity” better captures the breadth, depth, prescriptiveness and supervisory reach of additional mandatory requirements applying to a particular activity or industry. Those requirements can extend well beyond corporate governance in the narrow sense. They may include licensing and registration, prudential standards, safety-management systems, product approvals, clinical standards, environmental controls, prescribed governance arrangements, reporting, audit, accreditation, incident notification and active regulator supervision.

At one end of the spectrum are businesses for which regulation forms part of the operating architecture itself. Banks, superannuation trustees, insurers, aged-care providers, healthcare operators, airlines, mining companies, energy businesses, telecommunications carriers and safety-critical transport operators are obvious examples. Their regulatory obligations do not merely sit around the edges of the business. They can influence who may operate, who may govern, how risk must be managed, what systems must exist, what must be reported and how regulators engage with the organisation.

At the other end are businesses such as many general consultancies, ordinary IT service providers, recruitment firms, fitness businesses and tourism operators. They remain subject to substantial general law but often have comparatively limited industry-specific mandatory regulation unless a particular product, activity or circumstance triggers a specialist regime.

What drives regulatory intensity?

The strongest pattern is not industry size. It is the consequence of failure and the public-policy significance of the activity.

Financial services are intensively regulated because failures can threaten customers’ money, retirement savings, market confidence and, in some cases, financial stability. Healthcare, aged care and childcare involve life, health, dignity and vulnerable people. Aviation, rail, maritime transport, mining and hazardous manufacturing can involve catastrophic physical or environmental harm. Energy, telecommunications, water and critical data infrastructure raise continuity, resilience and national-security concerns.

These are different policy rationales, but they point in the same direction: the greater the potential harm from failure, the stronger the case for governments to prescribe how the business must be authorised, controlled, monitored and held accountable.

This also explains why regulatory intensity and organisational size should not be confused. A relatively small business operating in a highly regulated sector may face far more specialised mandatory requirements than a very large business in a comparatively lightly regulated sector.

Is Australia a highly regulated economy?

There is credible evidence that the answer is yes, at least in comparative terms.

The OECD’s Economic Survey of Australia 2026 states that “administrative and regulatory burdens in Australia are relatively high by OECD standards”. It identifies regulatory fragmentation within Australia’s federal system as an important contributor, with differences between Commonwealth, State and Territory requirements increasing the cost and complexity of operating across jurisdictions.

This is an important qualification to any discussion of regulatory intensity. Complexity does not arise only from the number of rules. It can also arise from overlapping regulators, duplicated processes, inconsistent licensing systems, different State or Territory requirements and the need to reconcile national and local regimes.

Many of Australia’s economically and socially significant industries are also among its more intensively regulated. The Reserve Bank of Australia’s August 2026 composition snapshot identifies health and education, mining, finance and construction among the major contributors to Australian output. Jobs and Skills Australia similarly identifies health care and social assistance, professional, scientific and technical services, construction, retail trade and education and training among Australia’s largest employing industries.

But it would be too strong to conclude that all economically important industries are highly regulated. Education, retail, professional services and manufacturing, for example, contain activities with very different regulatory profiles. Economic significance and regulatory intensity are related in some sectors, but they are not the same thing.

Federalism matters

Australia’s federal structure deserves particular attention.

Some industries are governed predominantly through national frameworks. Others encounter a patchwork of Commonwealth, State, Territory and local requirements. Construction, real estate, private security, labour hire, gambling, hospitality, road transport and parts of the automotive sector are examples where jurisdictional variation can itself be a major source of compliance complexity.

This does not necessarily mean that the underlying policy objectives are unsound. It means that an organisation operating across borders may need to manage several versions of broadly similar licensing, reporting, technical or conduct obligations.

For governance purposes, that fragmentation matters. It affects compliance frameworks, delegations, accountabilities, assurance, legal-entity structures, regulatory reporting and the information that boards and senior management need to receive.

Broad industry labels can also mislead

Another important lesson is that industry categories can conceal material differences.

A conventional data-services business is very different from an operator of critical data infrastructure. Gambling is very different from arts and recreation. Labour hire is different from recruitment. Heavy or hazardous manufacturing is different from light manufacturing. A regulated financial-services or audit practice is different from a general management consultancy.

Accordingly, governance should be designed around what the organisation actually does, not merely the industry label attached to it.

This is particularly important for diversified groups and subsidiaries. A group may contain entities exposed to very different regulatory regimes, even where they share common systems, directors, policies or corporate services. A single generic governance framework can therefore create false comfort if it fails to recognise the obligations attaching to particular activities, licences, assets or jurisdictions.

The governance implication: one size does not fit all

Good governance principles are broadly transferable. Accountability, effective oversight, sound decision-making, appropriate delegation, risk management, assurance, conflicts management, reliable information and clear responsibility matter in every sector.

The governance architecture needed to give effect to those principles, however, cannot be entirely industry-neutral.

A highly regulated business may require more specialised board skills, detailed committee mandates, formal compliance plans, prescribed responsible-person arrangements, stronger regulatory reporting, more extensive assurance, licence-condition monitoring, incident escalation, regulator-engagement protocols and deeper documentary infrastructure. A less regulated business may achieve effective governance with a substantially simpler framework.

The objective should not be to maximise governance infrastructure. It should be to make it proportionate to the organisation’s regulatory intensity, risk profile, complexity and public-policy significance.

This is why governance benchmarking also requires care. Comparing the number of policies, committees, reports or assurance processes between two organisations can be meaningless if the businesses operate under materially different regulatory architectures.

High regulation does not mean bad regulation

A final distinction is important.

Describing an industry as highly regulated is not a conclusion that it is over-regulated, inefficiently regulated or subject to poor-quality regulation. Regulatory intensity is descriptive, not normative.

Many highly regulated sectors have compelling reasons for substantial government intervention. The relevant policy question – whether a particular regime is proportionate, coherent and well designed – is a different inquiry.

Nor is regulatory intensity static. New legislation, changing technology, emerging risks, market failures and regulatory reform can alter the position over time. Any assessment should therefore be made by reference to requirements actually in force at a specified date and reviewed periodically.

Conclusion

Australia has a dense and uneven regulatory landscape. The OECD’s 2026 assessment supports the broader proposition that Australian businesses face relatively high administrative and regulatory burdens by OECD standards, while industry-level analysis shows that those burdens are distributed very differently across the economy.

The most intensively regulated sectors tend to be those where failure can cause the greatest financial, human, environmental or infrastructure harm. But industry size alone is not a reliable guide, and broad sector labels can disguise important differences between activities.

For boards, company secretaries, governance professionals and senior management, the practical implication is significant: governance frameworks should not simply reflect generic notions of “best practice”. They need to reflect the actual regulatory architecture of the business.

The better question is not simply:

“Do we have a governance framework?”

It is:

“Does our governance framework match the regulatory intensity, risk profile and operating reality of this organisation?”

Governance in Action Pty Ltd can assist clients with industry-specific governance frameworks and documentary infrastructure (including the development and review of relevant policies and procedures, etc.).

David Cantrick-Brooks FGIA FCG, Principal & Director of Governance in Action Pty Ltd, would be pleased to assist with enquiries. Please feel free to reach out via LinkedIn or via gia.net.au.

AI-assisted tools and techniques were used here to support the research, drafting and editing of this publication. Responsibility for the final content rests with David Cantrick-Brooks.

Whilst accounting and legal terms and references may be contained in this publication, it does not constitute or purport to be or represent accounting or legal advice of any kind – whatsoever. Readers should seek their own independent professional advice.

PreviousNext

Related Articles

From the Helm to the Boardroom: What the Ancient Roots of “Governance” Still Teach Us

What does corporate governance have to do with steering a ship in Ancient Greece? Quite a lot. The word “governance” ultimately derives from the Ancient Greek idea of steering or piloting a vessel. Plato's famous ship analogy later explored the difference between gaining control of the helm and possessing the knowledge required to navigate safely. More than two thousand years later, the metaphor remains remarkably relevant to modern boards. This article explores what the ancient origins of governance can teach us about direction, competence, information, accountability and navigating complexity – and explains the Greek-inspired thinking behind the Governance in Action logo.

08/29/2026

Governance Audits in Australia: What Boards Can Learn from the Public Sector

Governance frameworks can look impressive on paper. The more important question is whether they work in practice. This article examines governance audits as evidence-based assessments of the design, operation and outcomes of an organisation’s governance arrangements. It considers why governance assurance is more formalised and visible in the Australian public sector, why private-sector organisations often perform equivalent work under different labels, and what boards can learn from each approach. It also explores appropriate audit scope, culture and behavioural evidence, review frequency, the role of internal and external reviewers, and the opportunities and risks associated with using AI. The central message is simple: good governance assurance should go beyond confirming that policies, charters and controls exist. It should test whether they are understood, used, effective and capable of identifying and correcting governance weaknesses before they become larger problems.

08/18/2026