ASIC does not publish one fixed list of ACL policies and procedures for every business.
What ASIC does expect is that you have adequate arrangements to meet your licence obligations and to ensure that your representatives are adequately trained and competent to engage in the credit activities they are authorised to perform. The exact policy set will depend on the nature, scale and complexity of your business.
For many ACL holders, that means documented policies covering governance, compliance monitoring, reportable situations and breach reporting, complaints and IDR, credit representative supervision, training, conflicts, record keeping, outsourcing oversight, disclosure, and any business-specific controls relevant to the credit activities being carried on.