Home / FAQ / Regulatory Compliance
FAQ · AU

Regulatory Compliance FAQ

Regulatory compliance spans dozens of Australian laws and regulators. This FAQ covers questions relevant to financial services, consumer-facing businesses, and firms dealing with personal information, whistleblowing, and AML obligations.

In short

This FAQ covers 20 of the most common questions Australian compliance lawyers are asked, covering AFSL, ACL, AML/CTF, privacy, consumer law, and regulator investigations.

Research these in context — free trial
20 questions

Common questions

Who are the main Australian business regulators?

The main regulators are ASIC (corporations and financial services), APRA (prudential), the ACCC (competition and consumer), AUSTRAC (AML/CTF), the OAIC (privacy), the ATO (tax), Fair Work (workplace), and industry regulators such as AHPRA and TGA.

When is an AFSL required?

An Australian Financial Services Licence is required to carry on a financial services business in Australia — providing financial product advice, dealing, making a market, operating a registered scheme, providing custodial services, or providing a traditional trustee service.

Corporations Act 2001 (Cth) s 911A
What are general and specific AFSL obligations?

Licensees must do all things necessary to ensure services are provided efficiently, honestly and fairly; maintain competence; have adequate resources; comply with financial services laws; manage conflicts; have dispute resolution arrangements; and maintain adequate risk management systems.

Corporations Act 2001 (Cth) s 912A
What is the AML/CTF regime in Australia?

The AML/CTF Act requires reporting entities (banks, remittance providers, gambling operators, bullion dealers) to identify customers, conduct ongoing due diligence, report suspicious matters and threshold transactions, and maintain an AML/CTF program. AUSTRAC is the regulator.

Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Are lawyers and accountants covered by AML rules?

At present lawyers, accountants, and real estate agents are not reporting entities under the AML/CTF Act, but Tranche 2 reforms expanding the regime to these gatekeeper professions have been announced. Firms should be preparing systems and client due diligence processes now.

Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth)
What is the Privacy Act and who must comply?

The Privacy Act regulates how personal information is handled. It applies to Australian government agencies, private sector organisations with annual turnover over $3 million, and all health service providers, regardless of turnover. The 13 Australian Privacy Principles set the core obligations.

Privacy Act 1988 (Cth)
What is a notifiable data breach?

Under the Notifiable Data Breaches scheme, organisations must notify affected individuals and the OAIC of a data breach that is likely to result in serious harm and cannot be effectively remediated. Reforms have increased maximum penalties and expanded the Commissioner's powers.

Privacy Act 1988 (Cth) Part IIIC
What are the Australian Consumer Law's core protections?

The ACL prohibits misleading or deceptive conduct, unconscionable conduct, unfair contract terms, and false representations. It also provides consumer guarantees for goods and services, and specific product safety rules. It applies nationally and is administered by the ACCC and state regulators.

Competition and Consumer Act 2010 (Cth) Schedule 2
What is misleading or deceptive conduct under section 18?

Section 18 of the ACL prohibits a person, in trade or commerce, from engaging in conduct that is misleading or deceptive or is likely to mislead or deceive. It is a strict liability provision — there is no need to prove intention or fault to obtain remedies.

Australian Consumer Law s 18
What is the unfair contract terms regime?

The unfair contract terms regime voids unfair terms in standard form small business and consumer contracts. A term is unfair if it creates a significant imbalance, is not reasonably necessary, and would cause detriment. Since 9 November 2023 proposing unfair terms attracts civil penalties.

Australian Consumer Law s 23
What happens in an ASIC investigation?

ASIC can issue notices under section 19 requiring attendance at an examination, and under section 30-33 for production of documents. Non-compliance is an offence. Examinations are compulsory and answers can be used in some proceedings; claims of privilege must be made contemporaneously.

Australian Securities and Investments Commission Act 2001 (Cth) ss 19, 30-33
What is legal professional privilege in regulator investigations?

Legal professional privilege is recognised at common law and protects confidential communications made for the dominant purpose of obtaining or providing legal advice or for use in anticipated litigation. Regulators must respect privilege but may test claims strictly.

Daniels Corporation International Pty Ltd v ACCC (2002) 213 CLR 543
What are whistleblower protections?

The Corporations Act and Taxation Administration Act provide protections for eligible whistleblowers who make disclosures about misconduct to eligible recipients. Protections include criminal and civil immunity, compensation, and confidentiality. Public and large private companies must have a whistleblower policy.

Corporations Act 2001 (Cth) Part 9.4AAA
What are the modern slavery reporting obligations?

Entities with annual consolidated revenue of $100 million or more must publish annual modern slavery statements describing the risks of modern slavery in their operations and supply chains and actions taken to address them. Statements are lodged on a central register.

Modern Slavery Act 2018 (Cth)
What are the foreign bribery laws?

Bribery of foreign public officials is a criminal offence under division 70 of the Commonwealth Criminal Code. The offence applies extra-territorially to Australian citizens, residents, and companies. Pending reforms include a new failure to prevent offence with an adequate procedures defence.

Criminal Code Act 1995 (Cth) Division 70
What is continuous disclosure compliance?

Listed entities must immediately disclose price-sensitive information to the market unless it falls within a carve-out. Since 2020 reforms require proof of knowledge, recklessness, or negligence for civil penalty and class action liability — but the obligation itself remains strict.

Corporations Act 2001 (Cth) s 674
What are workplace health and safety compliance obligations?

Under harmonised WHS laws, a person conducting a business or undertaking (PCBU) must ensure, so far as is reasonably practicable, the health and safety of workers. Officers have a parallel duty of due diligence. Failures can lead to category 1-3 offences and civil penalties.

Work Health and Safety Act 2011 (NSW) ss 19, 27
What is the Consumer Data Right?

The Consumer Data Right (CDR) gives consumers the right to safely access specified data about them held by businesses, and to direct that it be shared with accredited recipients. It is live in banking and energy, with phased rollout to other sectors.

Competition and Consumer Act 2010 (Cth) Part IVD
What are director obligations for compliance?

Directors must exercise due diligence to ensure compliance with laws affecting the company (for example WHS, environmental, financial services, competition). Regulators increasingly focus on director accountability, supported by the FAR/BEAR accountability regimes for financial institutions.

Financial Accountability Regime Act 2023 (Cth)
How much does compliance advice cost?

One-off compliance reviews typically cost $10,000-$75,000. AFSL or CDR accreditation projects are larger. Many firms engage external compliance advisers on retainers of $3,000-$20,000 per month. The cost of non-compliance vastly exceeds the cost of prevention.

Use with Quillio

Research any of these in context

Quillio helps Australian compliance lawyers research regulatory guides, analyse notices, and draft compliance policies with citations to the relevant legislation and regulator guidance. See /practice-areas/compliance-lawyers or start a free trial.

These FAQs are general explanations for educational purposes — not legal advice. Compliance law changes frequently; always verify against current legislation, regulator guidance, and specific industry rules.

Get cited answers, not just FAQs.

Quillio gives you the answer plus a clickable citation to the underlying AU authority. The free trial requires no credit card and no sales call.

Start your free trial