TL;DR: The Six Safest Bets for AFSLs (2026–2027)
If you only read one section, read this.
- The compliance industry has become exceptionally good at documenting governance but demonstrably poor at demonstrating that governance actually works.
- Many AFSLs are becoming over-governed and under-supervised.
- More reporting isn’t the same thing as more oversight.
- Technical compliance and good client outcomes aren’t always the same thing.
- Most supervision programs are still designed to prove compliance rather than prevent consumer harm.
- Product governance failures rarely occur at approval. They occur when firms stop paying attention after approval.
- Spreadsheet-based compliance management is becoming increasingly difficult to defend as regulatory complexity grows.
- The firms that win through 2027 will not be those with the most policies, committees or reports. They will be the firms that can demonstrate their compliance frameworks actually work.
The shift underway is simple: regulators are becoming less interested in documented compliance and increasingly focused on defensible compliance.
What’s coming and how to win
“Foresight is not about predicting the future, it’s about minimising surprise.” — Karl Schroeder
Predictions are easy. Identifying the trends that are already emerging and positioning your business to benefit from them is much harder.
Most regulatory forecasts are little more than educated guesswork.
While no one can predict every regulatory development between now and the end of 2027, several trends are becoming increasingly difficult to ignore. ASIC’s enforcement activity, industry surveillance, cyber expectations, governance reviews and consumer protection agenda all point in a similar direction.
For AFSLs, these are six of the safest bets you can make over the next 18 months, and how to position your business to win.
The next 18 months will be a defining period for Australian Financial Services Licensees.
Regulatory expectations continue to rise. Compliance obligations continue to expand. Operational complexity continues to increase. At the same time, licensees are being asked to deliver better consumer outcomes, stronger governance, greater operational resilience and more effective supervision, often with the same resources.
The firms that succeed between July 2026 and December 2027 are unlikely to be those that simply react to regulatory change. They will be the firms that build the capability to adapt continuously.
That means investing not only in governance, risk management and compliance frameworks, but also in the compliance infrastructure that supports them. Increasingly, the challenge isn’t understanding what the obligations are. It’s operationalising them in a way that is scalable, efficient and defensible.
Across the industry, a clear shift is emerging. Compliance is evolving from a support function into a strategic capability. Leading AFSLs are moving beyond policies, spreadsheets and disconnected registers towards integrated compliance operating systems that provide visibility across obligations, controls, incidents, complaints, breaches, supervision and governance.
In short, the future belongs to firms that can demonstrate defensible compliance, not simply documented compliance.
Here are six trends that will shape the AFSL landscape over the next 18 months, and the capabilities winning firms are building today to stay ahead of them.
1. Governance, Supervision and Accountability
Priority: Very High
If there is one area that consistently sits at the centre of ASIC enforcement outcomes, it is governance.
Governance should remain the highest priority for most AFSLs.
Recent ASIC enforcement actions and surveillance activities continue to demonstrate a growing focus on governance failures, inadequate supervision, poor breach management and ineffective oversight. Increasingly, the regulator is testing whether licensees can demonstrate that their controls operate effectively in practice, rather than merely existing on paper.
This represents a significant shift.
Historically, many firms approached compliance through policies, procedures and periodic reviews. Today, regulators increasingly expect evidence. They want to understand how issues are identified, escalated, monitored and resolved.
The underlying regulatory question is becoming increasingly straightforward:
Can the licensee demonstrate effective oversight across the business?
That requires more than documented policies. It requires evidence.
Boards, Responsible Managers and compliance leaders need visibility into how risks are identified, escalated, monitored and resolved. They need confidence that controls are operating as intended and that emerging issues are detected before they become systemic failures.
Most licensees can produce hundreds of pages of governance reporting. Far fewer can demonstrate how that reporting changed a decision, prevented a breach or altered supervisory activity.
The strongest firms are building governance models that generate evidence continuously rather than scrambling to produce documentation when regulators arrive.
The governance challenge of the next 18 months isn’t writing better policies. It is creating better oversight.
The uncomfortable reality is that many “leading” AFSLs are over-governed and under-supervised.
Boards and Management receive more reports than ever before. Committees meet more frequently. Registers continue to expand. Yet they’re still struggling to identify emerging conduct risks before they become regulatory issues.
We’ve become exceptionally good at documenting governance, but far less effective at measuring whether governance is actually working.
More reporting isn’t the same thing as more oversight.
2. Operational Resilience Will Become a Board-Level Capability
Priority: Very High
For many licensees, this may be the most important operational priority over the next 18 months.
As technology ecosystems become more complex, AFSLs need greater visibility across operational risks, data governance, vendor management and incident response processes.
Cybersecurity isn’t just an IT issue. Operational resilience isn’t just a risk management issue. Outsourcing responsibility does not outsource accountability.
These topics are now critical governance issues.
ASIC continues to emphasise cyber resilience, third-party risk, outsourcing oversight and operational continuity. As firms become increasingly dependent on technology providers, cloud platforms, external administrators, and specialist vendors, operational risk becomes more interconnected and harder to manage.
Key areas requiring ongoing attention include:
- Cybersecurity controls
- Data governance
- Outsourcing due diligence
- Vendor oversight
- Incident response capability
- Business continuity and disaster recovery
- AI and automation governance
Many firms have invested heavily in risk frameworks but comparatively little in the infrastructure needed to operationalise them. The next phase of maturity will involve connecting compliance, risk and operational resilience into a unified operating model rather than managing them through separate functions and disconnected systems.
The most effective directors are not industry specialists. They’re consequence specialists.
Their role isn’t to understand every technology platform, cyber threat or outsourced service arrangement in detail.
Their role is to understand what happens when those things fail.
Operational resilience begins when boards stop asking whether a control exists and start asking what happens when it doesn’t.
The firms likely to perform best over the next 18 months will be those that treat resilience as an enterprise capability embedded across governance, risk, technology and compliance functions rather than as a collection of isolated obligations.
3. Client outcomes will be the defining advice metric
Priority: High
For advice licensees, advice quality remains a critical regulatory focus.
However, the conversation is increasingly shifting from adviser competence alone to client outcomes and supervisory effectiveness.
ASIC’s enforcement priorities continue to place consumers at the centre of regulatory decision-making.
In fact, one of the clearest themes across ASIC’s recent messaging is a growing emphasis on outcomes rather than process. This is a profound reorientation for licensees that, historically, often assessed compliance by asking: “Have we complied with the law?”
Increasingly, ASIC, APRA and AFCA appear to be asking a different question: “Did clients achieve a fair and reasonable outcome?”
They’re not abandoning statutory compliance in favour of purely subjective outcomes, but they are assessing compliance from a broader perspective.
We need to recognise that technical compliance and good client outcomes aren’t always the same thing.
It’s entirely possible for advice to satisfy every process step while still delivering a poor client experience or a suboptimal outcome. Licensees seem reluctant to act, but regulators are increasingly willing to examine that gap.
Those businesses that continue to treat compliance as a legal exercise rather than an outcomes or strategic discipline will find themselves increasingly exposed.
This shift is already underway, and its implications will be significant.
Areas likely to remain under scrutiny include:
- Misleading conduct
- Complaints handling
- Remediation programs
- Vulnerable customer protections
- Distribution practices
- Marketing and disclosure standards
The firms best positioned to navigate this environment will be those that treat complaints and incidents as strategic intelligence rather than administrative obligations.
How Exposed Are You?
Before reading further, ask yourself:
- Can management demonstrate that key controls are operating effectively today?
- Would the board identify an emerging conduct issue before it became a breach report?
- Are complaints, incidents and remediation activities being used as risk indicators or simply recorded and filed?
- Is compliance evidence spread across spreadsheets, emails and disconnected systems?
- Can you demonstrate that products continue to deliver appropriate outcomes after approval?
If any of these questions are difficult to answer confidently, you’re already facing one or more of the challenges shaping the next generation of AFSL supervision and governance.
4. The Shift in Supervision
Priority: High
While advice quality will always remain a core regulatory focus, the emerging challenge isn’t adviser competence or conduct risk alone. It’s supervisory effectiveness.
In an evolving market, advice licensees continue to face increasing pressure from adviser shortages, rising client demand and growing expectations around best-interest obligations, file quality and client outcomes.
Traditional supervision models were designed for a different environment. Reviewing files months after advice has been delivered often identifies problems too late to prevent consumer harm or systemic issues.
Most supervision programs are still built around proving compliance to regulators rather than improving outcomes and preventing consumer harm.
You might not care now, but if supervision only identifies issues after advice has been delivered, clients have already borne the risk. The industry’s longstanding and almost complete reliance on retrospective file reviews will ultimately be viewed as one of the least effective control mechanisms ever adopted at scale.
A more mature governance model is starting to emerge.
Leading firms are increasingly using workflow management, monitoring systems and structured supervision frameworks to identify patterns before they become widespread compliance failures. Complaints, incidents and remediation activities are no longer merely operational records. They are becoming leading indicators of conduct risk.
The strongest supervision frameworks will not simply review advice after the fact. They will identify emerging risks before they become systemic issues.
Those Licensees that can effectively monitor and analyse this information will be better positioned to identify issues before regulatory intervention becomes necessary.
The future of supervision is unlikely to be defined by larger audit samples; it will be defined by earlier intervention.
For AFSLs, this means moving beyond the question of whether obligations have technically been met and focusing on whether consumer outcomes are fair, reasonable and defensible.
Over the next 18 months, we anticipate that AFSLs will move away from retrospective supervision and towards risk-based monitoring frameworks supported by technology, workflow automation and integrated compliance systems.
5. Product Governance and Private Market Exposure
Priority: Medium–High
Private credit, private markets and alternative investment structures continue to attract regulatory attention.
That attention is only likely to intensify as retail exposure increases and market complexity grows.
Whether acting as product issuers, responsible entities, platform operators or advice providers, AFSLs should reassess the effectiveness of their product governance frameworks.
Areas requiring particular attention include:
- Distribution oversight
- Design and Distribution Obligations (DDO)
- Target Market Determinations (TMDs)
- Gatekeeper obligations
- Product due diligence
- Conflict management
- Valuation governance
- Liquidity monitoring
- Ongoing product monitoring
Historically, product governance has often focused heavily on approval processes.
The next phase of regulatory scrutiny is likely to focus on what happens after approval.
Licensees’ obsession with product approval governance has distracted their attention from a more important question: what happens after the product is approved?
Many firms have sophisticated approval processes but comparatively weak mechanisms for monitoring whether products continue to deliver suitable outcomes years later.
Product governance failures rarely occur at approval. They occur when firms stop paying attention after approval.
The critical question this focus on product governance poses will increasingly become How does the firm know the product continues to deliver appropriate outcomes?
Regulators are increasingly interested not only in how products are approved but also in how firms continue to monitor product suitability and consumer outcomes throughout the product lifecycle.
6. Compliance Technology Will Become Compliance Infrastructure
Priority: High
Perhaps the most significant shift over the next 18 months will be how AFSLs think about compliance itself.
For a long time, compliance technology has been viewed as a collection of tools for managing individual obligations or regulatory tasks.
That mindset is changing.
Regulatory complexity continues to grow. Governance expectations continue to expand. Reporting obligations continue to multiply.
At the same time, many compliance teams remain heavily dependent on spreadsheets, manual workflows and disconnected systems.
The mathematics of that model are becoming increasingly unfavourable.
The compliance profession may have passed the point where spreadsheet-based compliance management is professionally defensible.
It’s not because spreadsheets are inherently flawed, but because the complexity of modern regulatory obligations exceeds what manual oversight models can reliably manage.
At some point, licensees’ failure to modernise compliance infrastructure will itself become a governance issue.
Maintaining obligations registers, breach reporting, complaints oversight, supervision records and governance reporting across multiple spreadsheets may be manageable at a small scale, but it becomes increasingly fragile as businesses grow.
As compliance demands increase, manual approaches scale poorly. Visibility declines. Oversight becomes harder. Evidence becomes fragmented.
The firms responding most effectively are treating compliance infrastructure in the same way they treat financial systems, cybersecurity platforms, and operational risk frameworks: as a core business capability.
This doesn’t simply mean purchasing software.
It means creating a connected operating environment that links obligations, controls, incidents, complaints, breaches, supervision, audits and governance reporting into a single framework capable of supporting decision-making and demonstrating regulatory effectiveness.
The objective isn’t greater documentation.
The objective is greater defensibility.
Leading licensees are beginning to recognise that compliance is becoming a core operational capability and that capability requires infrastructure.
The AFSLs that outperform their peers will increasingly adopt compliance operating systems that integrate obligations, controls, incidents, complaints, breaches, supervisory activities, audits, and governance reporting into a single framework.
This shift is driven by a simple reality: regulatory complexity is outpacing what most manual compliance models can sustain.
Platforms such as [complye] reflect this broader evolution. Rather than treating compliance as a series of disconnected activities, modern compliance operating systems are helping firms build integrated, scalable, and defensible compliance environments that support both regulatory obligations and business growth.
The next generation of high-performing AFSLs will not view compliance as an administrative burden. They will view it as critical business infrastructure and a fundamental lever of business growth.
Looking Ahead
While no regulatory forecast is certain, the observations in this article are based on publicly observable regulatory themes, enforcement activity, surveillance priorities, and governance expectations evident across the Australian financial services sector.
Despite uncertainty, the direction of travel appears increasingly clear.
Across governance, cyber resilience, supervision, consumer protection and product oversight, regulators are placing greater emphasis on evidence, accountability and demonstrable effectiveness.
The common thread connecting all six trends is the shift from documented compliance to defensible compliance.
That shift changes the strategic challenge facing licensees.
Success will depend less on predicting individual regulatory developments and more on building the capability to respond when those developments occur.
The firms that succeed through 2027 are unlikely to be those with the largest compliance manuals.
They will be the firms that can demonstrate effective oversight, operational resilience, strong consumer outcomes and continuous control of their regulatory obligations.
In an increasingly complex environment, compliance is no longer merely a function.
It’s infrastructure. And infrastructure determines performance.
The firms that win won’t be those with the most policies, the most committees or the most reporting.They’ll be the firms that can prove their compliance frameworks actually work.
Further reading
If you enjoyed this, we recommend
Frequently Asked Questions
Defensible compliance is the ability to demonstrate that governance, supervision and compliance controls are operating effectively in practice. It focuses on evidence, accountability and outcomes rather than documentation alone.
Regulators increasingly want evidence that licensees can identify, escalate and address risks before they become systemic issues. Effective oversight is becoming as important as documented compliance frameworks.
Retrospective file reviews often identify problems after clients have already been affected. Many AFSLs are moving towards risk-based monitoring, workflow controls and earlier intervention models
Operational resilience is the ability to continue delivering services during disruption. It includes cyber security, outsourcing oversight, incident response, business continuity and technology governance.
Regulatory complexity is increasing faster than many manual compliance processes can sustainably support. Integrated compliance systems improve visibility, evidence collection, accountability and governance oversight.