Key points
- ASIC’s 2026–27 Corporate Plan promises simpler regulatory engagement, not lighter regulatory scrutiny.
- ASIC plans to reduce unnecessary regulatory friction while setting measurable targets for faster enforcement and intervention.
- Better use of regulatory data, analytics, and AI should help ASIC identify risk and potential harm more effectively.
- For boards, Responsible Managers and compliance teams, the practical response is better controls and better evidence, not simply more compliance activity.
- The real test is whether a licensee can demonstrate that its compliance arrangements operate effectively in practice, not merely on paper.
ASIC’s New Corporate Plan Promises Less Regulatory Friction. Don’t Mistake That For Less Regulatory Scrutiny.
There is an attractive line buried near the front of ASIC’s new Corporate Plan: “We don’t have to choose between strong regulation and growth.” [p2]
While some might dismiss this as spin, in our view it’s more important than they recognise.
Historically, successive commissioners have been forced to face “Sophie’s Choice”; do they prioritise consumer protection, enforcement and accountability or address productivity, innovation (and the increasingly familiar complaint that regulation has become too complicated, too expensive and too slow).
ASIC’s Corporate Plan 2026–27 suggests the regulator wants out of that argument, but its answer isn’t deregulation, it’s better regulation combined with sharper enforcement.
ASIC says it wants to be “easier to deal with for those trying to comply with the law, while being harder to avoid for those causing harm”. [p 2] That formulation matters because it tells boards, Responsible Managers and compliance teams something quite specific about the next phase of regulation.
Expect simpler regulatory engagement, but don’t expect less scrutiny.
That distinction may be one of the most important messages in ASIC’s new Plan.
Less Friction Isn’t Less Regulation
There’s plenty in the Corporate Plan that industry should welcome beyond ASIC’s intentions to streamline regulatory processes and reduce duplication. In short, ASIC wants to lower compliance costs associated with the way it requests and receives information. [p23] It’s committed to reducing the number of thematic surveillance notices it issues by 15%. It plans to work with APRA to streamline and harmonise regulatory data collection. [p24]
Thankfully, licensing is getting attention too.
ASIC wants to improve AFS licensing to enable faster market entry and reduce the regulatory load for low-risk entities. ASIC’s 2026–27 target is to finalise 80% of completed routine AFS and credit licence applications within 120 days, down from the previous 150-day timeframe. ASIC also specifically proposes streamlining its assessment of the organisational competence of Responsible Managers. [pp 24, 44]
In our experience, given that ASIC seem to routinely breach their licensing targets, this may be their most ambitious goal.
But ASIC promises more: simpler regulatory instruments, better guidance, expanded digital transactions, electronic signatures, improved registers and more usable online services. [pp 23–25]
These are great initiatives and ones that we should all support.
We’ve previously argued that compliance costs aren’t confined to the cost of actually complying with the law. Poor regulatory administration, repetition and a lack of clarity creates additional costs. Repeated requests for substantially the same information, unnecessarily complicated instruments, ageing technology and lengthy administrative processes consume resources that could otherwise be directed to clients, supervision and the business itself.
ASIC appears to recognise that, but don’t draw the wrong conclusion from these statements; making compliance easier isn’t the same as making compliance optional. And please don’t presume that reducing the burden of regulatory engagement means reducing the consequences when the underlying systems fail.
The Other Half Of The Plan
Don’t limit yourself to the headlines, read the simplification commitments alongside ASIC’s enforcement statements and a different picture emerges. ASIC describes enforcement and compliance as “critical parts” of its work and says it directs significant expertise and resources towards detecting, disrupting, investigating and responding to unlawful conduct. [p6]
More importantly:
“We are also committed to pursuing high penalties and sentences through the courts, so that the cost of breaking the law has a material impact on companies and individuals and there is a strong deterrence message to the sector more broadly.” [p6]
That’s difficult to reconcile with any suggestion that ASIC is going soft. It isn’t and, in fact, regulatory relief might be balanced against faster and more rigorous enforcement.
Directors and Responsible Managers should acknowledge that ASIC’s enforcement priorities include misconduct causing significant consumer harm, systemic compliance failures by large institutions, emerging conduct risks and governance and directors’ duties failures. [p6] In our view, it’s an explicit refocus on materiality that justifies the significant commitment that responsible licensees have made in independent reviews and regulatory technology.
The Plan also puts numbers around the enforcement machinery.
For 2026–27, ASIC targets:
- at least 70% of reported alleged misconduct being referred for further consideration within 60 days;
- an average of no more than 50 days between accepting an enforcement referral and commencing a formal investigation;
- an average of no more than 12 months between commencing an investigation and first action or finalisation;
- at least 25 people or companies referred to the CDPP for consideration of criminal prosecution; and
- at least 30 civil proceedings commenced. [pp 35–40]
In simple terms, this timetable suggests that ASIC is trying to remove friction at one end of the regulatory relationship while improving the speed and effectiveness of intervention at the other.
ASIC intends to be easier to deal with for those trying to comply, but its Plan simultaneously sets measurable targets for faster enforcement. So, ASIC will be easier to deal with, until they’re not (so don’t give them a reason not to be easy to deal with).
That’s what “easier to deal with, harder to avoid” means in practice.
Better Regulation May Mean More Effective Regulation
There’s another part of the Plan that deserves more attention. After years advocating for risk-based compliance, ASIC is investing heavily in its ability to see risk. ASIC says it will modernise the way it receives and triages reports of misconduct and combine them with other sources, including reportable situations, internal dispute resolution, and external dispute resolution data. [p22]
ASIC intends to develop new intelligence capabilities to identify risks earlier and support “intelligence-led, risk-based decision making and regulatory action”. [p22] It will also expand its use of data analytics, machine learning and generative AI. [p22]
This changes the significance of, and reason for, regulatory simplification. A regulator doesn’t necessarily need to ask everyone for more information if it becomes better at identifying who it needs to ask.
It doesn’t need more surveillance if better data helps it target the entities, business models and conduct presenting greater risk. And it doesn’t need to make compliance administratively difficult to make enforcement effective.
ASIC effectively says as much in explaining its approach to enforcement. It acknowledges that it can’t take enforcement action in every instance. Instead, it targets its resources towards misconduct capable of producing significant harm and outcomes with broader deterrent effects. [p6]
ASIC may become more discriminating, not necessarily more forgiving.
For well-run businesses, that should be good news. For poorly controlled businesses, it may be the opposite.
Of course, we’ve heard it before, and while we may celebrate ASIC’s intentions, it’s unlikely that it will be able to achieve its ambitions unless ASIC is adequately resourced.
What This Means For Responsible Managers
It’s dangerously tempting for Responsible Managers to read ASIC’s licensing reforms as signalling its relaxation of expectations.
The Plan doesn’t support that conclusion.
Yes, ASIC wants to streamline assessment of Responsible Manager organisational competence. [p 24] But ASIC also describes licensing as a frontline gatekeeper function and says its targets must balance timely decision-making against its obligation to ensure that only fit and proper market participants are licensed or registered. [p44]
The process may become a little easier, but the expectation that the licensee is competent and capable doesn’t disappear.
In fact, that distinction extends beyond licensing.
Responsible Managers should be asking whether the compliance arrangements described to ASIC, the board or governing body are actually operating in practice. That’s consistent with a broader theme in our approach to governance: compliance infrastructure needs to withstand regulatory scrutiny, not merely exist on paper.
A beautifully documented framework that doesn’t describe how the business actually operates isn’t much protection when the evidence tells another story.
Found this article useful? You can select Assured Support as a ‘preferred source’ in Google. This may help you see more of our articles in Google Top Stories, AI Mode and AI Overviews when our content is relevant to your search.
Boards Should Pay Attention To The Evidence Layer
The same point applies at board level. ASIC’s Plan doesn’t suggest boards should accumulate more compliance paperwork. Quite the opposite conclusion may be available.
If ASIC moves towards more targeted, intelligence-led supervision, boards need better evidence rather than simply more information.
The relevant questions become practical ones.
- Can management demonstrate that controls operate?
- Do complaints reveal recurring conduct problems?
- Do incidents and breaches identify weaknesses that monitoring has missed?
- Does adviser monitoring identify trends rather than simply count failed files?
- Where management says remediation has been completed, what proves it?
- Can the board distinguish an isolated error from a systemic control failure?
- And, critically, if ASIC identified a problem tomorrow, could the business reconstruct what happened, who knew about it, what was decided and what was done?
This is the difference between having a compliance framework and having compliance infrastructure.
We’ve previously argued that treating Responsible Managers as compliance clerks, or boards as passive recipients of risk reports, misunderstands accountability in a regulated business. ASIC’s new Corporate Plan validates our perspective and makes that distinction more important, not less.
Compliance Teams Should Resist The Wrong Productivity Debate
Here’s the lesson here for compliance teams. Compliance is frequently and relentlessly framed as business prevention and the natural enemy of productivity: every control adds time; every review delays revenue; every regulatory requirement adds cost; every no frustrates innovation.
ASIC’s formulation that “We don’t have to choose between strong regulation and growth.” [p2] challenges that assumption.
And licensees should take that in.
A poorly designed compliance process absolutely can create unnecessary friction. Duplicate approvals, indiscriminate file reviews, controls disconnected from risk and policies nobody can apply are not signs of regulatory maturity.
They’re signs of poor design, poor oversight and poor management.
Risk-based compliance asks a different question: where does failure matter most, and what control is proportionate to that risk? That approach is entirely consistent with ASIC’s own direction. The regulator repeatedly describes its supervision, surveillance and decision-making as risk-based. [pp 6, 17, 22]
So, the objective of a responsible and competent licensee shouldn’t be to maximise compliance activity, but to maximise control effectiveness.
That means using data and solutions like [complye] to identify risk earlier, concentrating supervision where consequences are greater, eliminating controls that add no meaningful protection and keeping evidence that demonstrates why decisions were reasonable.
Productivity, real productivity, reduces compliance effort while improving compliance outcomes.
Easier For Whom?
There’s one final point worth making.
ASIC’s promise to become easier to deal with is conditional. ASIC wants to be easier to deal with “for those trying to comply with the law” and harder to avoid “for those causing harm”. [p2]
That distinction puts considerable weight on the quality of a licensee’s governance.
A licensee with functioning controls, reliable records, effective monitoring, prompt remediation and Responsible Managers who understand the business should be well positioned to benefit from simpler regulatory processes.
A business relying on policies it doesn’t follow, monitoring it doesn’t interrogate and governance reports that can’t be substantiated may have a very different experience. ASIC is assiduously improving the technology and intelligence capability it uses to tell the difference [pp 22–23], so take little comfort in your belief that you’re flying under ASIC’s radar or are too small to attract attention.
The practical test is straightforward. If ASIC asked tomorrow why a control was designed as it was, whether it operated, what exceptions it identified and what happened next, could you answer from contemporaneous evidence rather than reconstructing the story after the event?
The Takeaway
ASIC’s Corporate Plan isn’t a retreat from enforcement dressed up as a productivity agenda, nor is it an enforcement agenda indifferent to the cost of regulation.
It’s an attempt to do both things better.
Instead of choosing between Salt and Chicken Salt, ASIC’s choosing both.
ASIC intends to reduce unnecessary regulatory friction, improve licensing, simplify interactions, coordinate information requests, use technology more effectively and simultaneously focus regulatory resources on the conduct and businesses presenting the greatest risk.
Although ASIC’s stated intentions may appear to sit uncomfortably together, there’s no necessary contradiction. The bargain ASIC is proposing is simpler regulation where complexity adds little value, and harder consequences where conduct causes harm.
For boards, Responsible Managers and compliance teams, the practical response shouldn’t be more compliance for compliance’s sake. It should be better governance, better controls and better evidence that those controls actually work.
Because while ASIC wants to be easier to deal with, it’s also investing heavily in becoming much harder to avoid.
If your framework looks stronger on paper than it does in the evidence, Assured Support can help test where control design and day-to-day operation have drifted apart.
Source: ASIC Corporate Plan 2026–27, 26 August 2026. The Plan covers 2026–27 to 2029–30.
Further reading
Frequently Asked Questions
No. ASIC’s Corporate Plan supports reducing unnecessary regulatory friction, not weakening the controls needed to comply with the law. ASIC expressly combines simplification initiatives with risk-based supervision and continued enforcement against serious misconduct.
That distinction matters because inefficient compliance and ineffective compliance are different problems. A licensee may reasonably remove duplicated approvals, poorly targeted reviews or administrative processes that do not materially manage risk. It should not interpret regulatory simplification as justification for removing controls without understanding the risks those controls address.
The practical question isn’t “Can we do less compliance?” but “Which activities genuinely manage material regulatory risk, and what evidence demonstrates that they work?” A defensible simplification exercise should identify the obligation or risk, the control intended to address it, evidence of effectiveness and the basis for changing or removing it. ASIC itself describes its supervision as risk-based and says its guidance aims to help businesses comply with minimum compliance costs.
ASIC’s target is to finalise 80% of completed routine AFS and credit licence applications within 120 days; it is not a guarantee that every application will be determined within four months. The measure applies to routine applications received from 1 July 2026, while applications deemed complex are excluded.
Importantly, ASIC’s target is for 80% of completed routine AFS and credit licence applications to be finalised within 120 days. Complex applications are excluded, and the measure applies to applications received from 1 July 2026
ASIC has reduced the timeframe from 150 to 120 days as part of its productivity initiatives and separately says it intends to streamline assessment of Responsible Manager organisational competence. But it also describes licensing as a frontline gatekeeper function and says timeliness must be balanced against ensuring only fit and proper participants are licensed or registered.
Applicants should therefore treat faster processing as a reason to improve application readiness, not relax it. Organisational competence evidence, RM experience, authorisations, governance arrangements and supporting material should tell a coherent story when submitted. Faster regulatory processing has limited value if ASIC must repeatedly seek missing or inconsistent information.
A board should expect evidence that demonstrates the control operated as intended, identified relevant exceptions and produced an appropriate response — not simply evidence that the control exists.
That may include monitoring results, exception reports, complaint and breach trends, remediation records, control attestations, escalation records and evidence showing whether recurring problems were investigated. The appropriate evidence will depend on the risk and control; there is no universal document set.
The distinction matters particularly in light of ASIC’s stated move towards greater use of integrated regulatory data and intelligence-led, risk-based decision-making. ASIC plans to combine misconduct reports with reportable situations and dispute-resolution data and improve data integration to obtain a more comprehensive view of regulated entities. A board should therefore be asking whether its own information can reveal patterns across those same operational signals.
A policy proves what was intended. Governance evidence should help establish what actually happened.
A licensee should test the cause, recurrence, affected population and control implications of an incident before concluding that it is isolated. A single detected event does not necessarily mean the underlying weakness occurred only once.
The analysis should consider whether the same process, adviser cohort, product, system or control could have produced similar outcomes elsewhere; whether complaints, incidents, monitoring or breach data contain related signals; and whether the issue arose from individual execution or a weakness in control design or operation.
That distinction has practical regulatory significance. ASIC identifies systemic compliance failures by large financial institutions resulting in widespread consumer harm among its enduring enforcement priorities, while its intelligence strategy is expressly aimed at identifying patterns, trends and broader systemic problems.
A defensible “isolated” conclusion therefore needs evidence. Sampling, data analysis, root-cause work and documented reasoning may be more persuasive than simply recording that only one incident has so far been reported.
Potentially, but technology is useful only where it improves a licensee’s ability to identify, manage and evidence risk; it does not replace accountable judgement. ASIC itself plans to expand data analytics, machine learning and generative AI while integrating regulatory datasets to support earlier insights and regulatory action.
For licensees, the relevant lesson isn’t to replicate ASIC’s technology stack. It’s that fragmented information becomes increasingly problematic when complaints, breaches, monitoring findings, incidents and remediation activities cannot be connected.
Technology can help establish ownership, maintain review histories, surface recurring issues and preserve evidence of decisions. But dashboards and automated workflows are not evidence of effective compliance by themselves. Responsible Managers and boards still need to understand what the information means, challenge anomalies and determine whether identified weaknesses require escalation or remediation.
The test is whether technology improves risk visibility and accountability rather than merely digitising an ineffective process.