top of page

AFSL, ASIC and APRA: The 2026–27 Compliance Outlook

Zoe Beesley

14 Sept 2026

The regulatory themes shaping financial services across ASIC and APRA in 2026–27.

If 2025 was about preparing for a more demanding regulatory environment, 2026–27 is increasingly about demonstrating that the business can operate effectively within it.


Across ASIC and APRA, several themes are converging:


resilience, technology, AI, governance, consumer outcomes, third-party risk and accountability.


The result is a regulatory environment where compliance can no longer be separated neatly from business operations.


The question is becoming less about whether a policy exists and more about whether an organisation can demonstrate that its policies, controls and decisions work in practice.


1. AI becomes a governance issue


AI is perhaps the clearest example of this shift.


ASIC has identified advanced technology, AI-driven consumer interactions, agentic AI, cybercrime and AI-enabled misconduct among emerging areas of concern.


APRA has separately emphasised the need for appropriate AI risk management, including governance, accountability, risk management and security controls.


The important point is that AI is moving beyond an IT discussion.


If employees are using AI tools, if AI is embedded in customer interactions, or if automated systems are influencing decisions, questions of accountability and oversight inevitably follow.


If AI is part of how a business operates, it is also becoming part of how that business needs to be governed.


That does not necessarily mean every use of AI presents the same level of risk.


It does mean the organisation needs to understand where AI is being used, what decisions it influences and who is accountable for the outcome.


2. Operational resilience moves further into the boardroom


For APRA-regulated entities, CPS 230 has brought operational risk, critical operations and service-provider management firmly into the regulatory framework.


More broadly, ASIC's 2026 outlook highlights cyber attacks, data breaches, third-party dependencies and inadequate operational resilience as risks that can affect consumers and market confidence.


The underlying theme is straightforward:


A business needs to understand how it will continue operating when something goes wrong.


That includes questions around:


  • critical operations;

  • outsourcing and service providers;

  • incident management;

  • business continuity;

  • cyber resilience;

  • recovery capability; and

  • technology dependencies.


Operational resilience is therefore becoming less of a specialist risk function and more of a leadership issue.


3. Consumer harm remains central


Regulatory focus ultimately comes back to outcomes.


ASIC's 2026 enforcement priorities include misleading pricing practices, poor private credit practices, financial reporting misconduct, and insurance complaints and claims handling, alongside broader concerns about systemic compliance failures and misconduct causing significant consumer harm.


The broader lesson is not simply “avoid enforcement”.


It is that the way a business is designed and operated can create risks for customers long before a breach becomes obvious.


A useful question is:


Where could the way we operate produce a poor customer outcome — and how would we know?


That takes the discussion beyond individual complaints or isolated incidents.


Patterns matter.


Repeated complaints, unexpected customer behaviour, unusual remediation activity or recurring control failures can all provide information about whether something deeper is occurring.


4. Private markets deserve attention


Private credit and other private market activities are receiving increasing regulatory attention.


ASIC has highlighted issues including governance, valuation, liquidity, conflicts, fees, disclosure and distribution in private market products.


These are not simply technical investment-management questions.


They go to the quality of governance around products and the way risks are communicated to investors.


Distribution is particularly important.


A product can be appropriately designed and still create problems if it reaches the wrong customer, is distributed through an unsuitable channel or is not accompanied by sufficiently clear information about its risks.


The broader regulatory direction is toward greater scrutiny of how private market products are governed throughout their lifecycle — not simply at the point they are created.


5. Geopolitical risk is becoming business risk


Geopolitical risk has also moved further into the regulatory conversation.


APRA's 2026–27 Corporate Plan includes a focus on readiness for geopolitical shocks, with targeted readiness assessments for larger entities with heightened exposure to these risks.


That reflects a broader shift in the way organisations think about risk.


Historical data can tell us a great deal about what has happened.


It cannot necessarily tell us what happens when something genuinely unfamiliar occurs.


Consider scenarios such as:


  • an offshore provider becoming unavailable;

  • a cyber event affecting a critical supplier;

  • severe disruption to international markets;

  • interruption to a critical technology service; or

  • a geopolitical event materially changing a counterparty's risk profile.


The point is not to predict which event will occur.


It is to understand how the organisation might respond if the assumptions underlying its normal operations suddenly changed.


Scenario thinking is therefore becoming an increasingly important management capability.


6. Regulatory burden and regulatory accountability can coexist


One of the more interesting developments is ASIC's stated intention to become easier to deal with while remaining harder to avoid.


ASIC has indicated that it wants to reduce unnecessary regulatory burden through simpler guidance, better digital services, more efficient licensing processes and closer coordination on data collection.


That distinction is important.


Reducing unnecessary complexity does not mean reducing accountability.


The direction appears to be toward clearer expectations and more efficient regulatory interactions, while maintaining consequences for serious misconduct and poor outcomes.


For AFSL holders, that creates an interesting balance.


Regulation does not necessarily have to become more complicated to become more demanding.


Clearer expectations can actually make it easier to identify where governance, controls or decision-making are falling short.


The 2026–27 executive checklist


Taken together, these developments point to a useful set of questions for boards and executive teams.


AI: Where is it being used, and who is accountable for the outcomes?


Resilience: What are the organisation's critical operations?


Third parties: Which suppliers or service providers could materially disrupt the business?


Consumers: Where could the business model produce poor customer outcomes?


Compliance: Are incidents and complaints revealing recurring or systemic issues?


Governance: Can executives explain the organisation's major risks without relying solely on a compliance report?


People: Does the organisation have the capability and leadership needed to manage these risks effectively?


The value of these questions is not in producing another checklist.


It is in testing whether the organisation has a shared understanding of how its business actually works — and where it could fail.


The bigger picture


The future of compliance is unlikely to be about simply adding another layer of bureaucracy.

It is increasingly about building organisations that are well governed, operationally resilient, technologically aware and capable of demonstrating good judgement.


That is good regulation.


But it is also good business.


The strongest organisations are unlikely to treat compliance, risk, technology, operations and leadership as separate conversations.


They will see how those pieces connect.


Better compliance. Stronger operations. Better leadership.


That is the opportunity for 2026–27.




Sources: 


Disclaimer: This article is provided for general information and educational purposes only and does not constitute financial, legal, regulatory, tax, accounting or other professional advice. Regulatory requirements and guidance can change. Readers should check current primary sources and seek independent professional advice where appropriate.

Disclaimer: Compliance & Leadership Insights is an independent editorial blog. Content is provided for general information and educational purposes only and does not constitute financial, legal, regulatory, tax, accounting or other professional advice. Regulatory information may change. Please check current primary sources and seek independent professional advice where appropriate.

© 2026 Compliance & Leadership Insights · Privacy · Terms · Disclaimer · Editorial Policy · About · Contact

bottom of page