
Zoe Beesley
14 Sept 2026
A look at ASIC's current areas of focus — and the questions financial services businesses may want to consider.
If there is one message financial services businesses should take from ASIC's current direction, it is this:
ASIC wants clearer expectations, better risk management and earlier detection of misconduct.
In August 2026, ASIC announced a plan focused on being "easier to deal with, harder to avoid" — a useful description of the regulator's approach to reducing unnecessary regulatory burden while taking stronger action where serious misconduct or consumer harm is identified.
For businesses, that suggests 2026–27 is unlikely to be about compliance for compliance's sake.
The bigger question is whether a business can demonstrate that it understands its risks, has appropriate controls in place and responds when those controls reveal a problem.
Several areas of ASIC's current work illustrate that direction.
AI has moved firmly into the regulatory conversation
AI is no longer simply a future compliance issue.
ASIC has identified a range of emerging risks associated with artificial intelligence, including its impact on consumers, the use of AI in customer-facing services, AI-enabled market manipulation, deepfakes and misinformation.
ASIC's 2026 outlook has also highlighted advanced technologies, including agentic AI, as a source of emerging consumer and market risks.
For financial services businesses, that raises a practical question:
Where could AI create a compliance or conduct risk that did not exist — or was much harder to create — five years ago?
The possibilities are broad.
They may include:
inaccurate or misleading customer communications;
inappropriate automated decisions;
marketing generated at scale without adequate review;
privacy and confidentiality risks;
fabricated research or analysis;
inadequate human oversight;
AI-enabled fraud;
inappropriate use of customer data; and
employees relying on AI-generated advice or analysis without appropriate verification.
The technology may be new.
The underlying accountability is not.
Using AI does not remove existing obligations around accuracy, fairness, privacy, record-keeping, supervision or appropriate decision-making. In some cases, it may make those obligations more difficult to manage because decisions and communications can be produced at a much greater scale.
That makes AI governance an increasingly practical part of broader risk management, rather than something that sits entirely within an IT function.
Operational resilience remains more than an IT issue
ASIC's current direction also continues to emphasise cyber security, technology, data and operational resilience.
Its 2026 outlook highlights risks including cyber attacks, data breaches, legacy technology, third-party dependencies and crisis management.
For financial services businesses, resilience therefore extends beyond whether the IT team can restore a system.
Consider a scenario in which a critical system disappears tomorrow.
What happens next?
How quickly would the business know?
Who would make the key decisions?
How would customers be informed?
Which services could continue manually?
Which third parties would the business depend on?
What information would need to be recovered first?
When would regulators need to be notified?
And who would have authority to make decisions during the incident?
These questions are not necessarily about predicting a particular cyber event. They are about understanding how the organisation would respond when something important stops working.
A business continuity plan that has never been tested may look comprehensive on paper, but testing is what reveals whether the plan actually works.
That is increasingly relevant as financial services businesses rely on interconnected technology providers, cloud services, data systems and outsourced functions.
ASIC's focus on private credit matters
Private credit is another area where ASIC's current enforcement priorities provide a more specific indication of regulatory attention.
ASIC has identified poor private credit practices among its 2026 enforcement priorities, alongside areas including financial reporting misconduct, insurance complaints and claims handling, and other consumer and market risks.
For businesses involved in private credit or the distribution of private-market products, this brings particular attention to areas such as:
valuation governance;
conflicts of interest;
liquidity;
disclosure;
distribution practices;
investor classification;
product performance monitoring; and
accountability for decision-making.
ASIC has also highlighted broader risks in private markets, including governance, valuation, liquidity, conflicts, fees, disclosure and distribution.
For businesses operating in this space, the message is relatively straightforward:
governance and risk management cannot be treated as secondary considerations simply because an investment or market sits outside traditional listed markets.
As private markets continue to evolve, transparency around how decisions are made, risks are assessed and investors are treated becomes increasingly important.
What does this mean in practice?
ASIC's priorities do not necessarily mean that every financial services business needs another large compliance project.
They do, however, provide a useful opportunity to revisit some fundamental questions.
What are our most significant conduct risks?
Not every possible risk needs to receive equal attention.
Which three risks could cause the greatest harm to customers, investors or the business?
And does the organisation's attention reflect those risks?
Where could technology amplify those risks?
AI, automation and digital distribution can make good processes more efficient.
They can also make poor processes happen faster and at greater scale.
Where is technology changing the way customers are communicated with, decisions are made or products are distributed?
Which controls have never actually been tested?
A policy can exist without being effective.
A business continuity plan can exist without being workable.
A monitoring process can exist without identifying the problem it was designed to detect.
Testing provides a different kind of evidence: whether a control works in practice.
What would the business's complaints, incidents and remediation data reveal?
Individual complaints and incidents can be easy to treat as isolated events.
Patterns can tell a different story.
Repeated complaints about the same process, recurring operational failures or similar remediation issues may point to a broader underlying problem.
The quality of the information available to decision-makers matters almost as much as the existence of the underlying controls.
Could senior decision-makers explain the organisation's key risks without opening a policy document?
This is not a test of whether someone can memorise a risk framework.
It is a question about whether important risks are actually understood at the level where decisions are being made.
If the answer is no, it may be worth asking whether risk information is reaching the right people in a useful form.
The direction of travel
ASIC's current message is not that financial services businesses should become paralysed by regulation.
Quite the opposite.
ASIC has said it wants to reduce unnecessary regulatory burden through clearer guidance, better digital services, more efficient licensing processes and improved coordination, while continuing to pursue serious misconduct and consumer harm.
That creates an interesting distinction between regulatory burden and good governance.
Reducing unnecessary complexity does not mean reducing accountability.
For well-run businesses, clearer expectations and more effective systems can ultimately make it easier to demonstrate that risks are understood and managed.
The challenge is less about predicting what ASIC will focus on next and more about understanding whether the organisation could respond if difficult questions were asked today.
The goal isn't to predict what ASIC will do next.
It is to build a business that is ready when the regulator — or the next unexpected event — asks difficult questions.
Sources:
ASIC, Corporate Plan 2026–27 — ASIC's overall priorities for 2026–27;
ASIC, 2026 Enforcement Priorities.
Disclaimer: This article is provided for general information and educational purposes only and does not constitute financial, legal, regulatory, tax, accounting or other professional advice. Regulatory requirements and guidance can change. Readers should check current primary sources and seek independent professional advice where appropriate.