Australia is in the middle of its most concentrated regulatory overhaul in over a decade. The cost of complying with federal regulation has grown from $65 billion in 2013 to $160 billion today, which is roughly 5.8 per cent of GDP, according to the Australian Institute of Company Directors. That figure alone tells you the stakes have shifted. Board time spent on compliance has doubled from 24 per cent to 55 per cent in the same period. If you run a business here, you are not imagining the pressure — the data confirms it.
Disclosure: Some links on this page are affiliate links. If you make a purchase through them, Britwealth may earn a commission at no extra cost to you. We only include products and services that are relevant to the topic.
This article is general information only and does not constitute professional advice. For your specific situation, consult a qualified professional.
What makes this moment different is the sheer number of deadlines landing in a single year. The AML/CTF Tranche 2 expansion, mandatory cybersecurity standards for smart devices, a new merger control regime, climate disclosure requirements, and the CPS 230 contract remediation deadline all converge between March and July 2026. This is not a slow build — it is a regulatory wall. Here’s what you actually need to know.
What the 2026 regulatory wave means for your business
The central concept here is demonstrated compliance. Regulators no longer just ask whether you have a policy on paper. They want measurable, auditable evidence that controls are working in practice. That shift — from existence to proof — is what makes this wave different from previous ones.
What I tend to notice is that businesses treat each new regulation as a standalone project. That approach breaks down when five major frameworks land in the same year. The smarter move is to look for the overlaps — and there are plenty.
What changes when you get compliance wrong
The financial exposure is not theoretical. AUSTRAC has already signalled it will increase its focus on individual accountability, including joining individuals to enforcement proceedings. ASIC is bringing stepping stone liability claims against directors for breaches of their duties. The enforcement trend is moving toward personal liability, not just corporate fines.
Consider the AML/CTF Tranche 2 expansion. Australia was first put on notice about its failure to extend anti-money laundering obligations to lawyers, accountants, and real estate agents in 2005. The legislation finally passed in November 2024. That is nearly twenty years of known gap. Now approximately 90,000 entities must enrol with AUSTRAC by 31 March 2026 and be fully compliant by 1 July 2026. Miss that window and you are not just late — you are operating outside a regime that has been two decades in the making.
The same pattern applies to the new mandatory ransomware payment reporting under the Cyber Security Act 2024. Organisations must report within 72 hours, including payment details, the nature of the attack, vulnerabilities exploited, and business impact. That is a tight window, and the data you submit must be accurate. Regulators are not accepting rough estimates.
Where businesses get caught out
Treating AML/CTF enrolment as the final step
Enrolling with AUSTRAC by 31 March is only the beginning. By 1 July, you need a full AML program, beneficial ownership verification processes, and reporting procedures in place. I have seen businesses treat the enrolment date as the compliance date. It is not. The gap between March and July is three months to build an entire compliance framework from scratch. For a firm starting from a low baseline, that is tight.
Assuming existing contracts are fine under CPS 230
APRA’s CPS 230 framework requires service provider mapping beyond spreadsheets. The contract remediation deadline is 1 July 2026. If your third-party agreements were written before this framework existed, they almost certainly do not meet the new requirements. Remediation means reviewing every contract, identifying gaps, and renegotiating terms. That process takes months, not weeks.
Ignoring the cumulative merger test
From 1 April 2026, a deal can trigger notification based on combined party size and transaction value, even where either measure alone falls below the threshold. This catches the creeping acquisition problem — serial small purchases that cumulatively reshape markets. If your growth strategy involves multiple small acquisitions, you need to map them as a single portfolio, not as isolated transactions.
Treating climate disclosure as a reporting exercise
Climate reporting requirements expand from July 2026 for Group 2 entities, with increasing assurance expectations over time. The mistake is treating this like an annual report you can prepare in a week. Regulators expect climate data managed with the same rigour as financial data, including audit readiness and traceability. That means systems, not spreadsheets.
Building a compliance framework that survives the year
Map your regulatory footprint first
Before you can comply with anything, you need to know which frameworks apply to your business. A law firm handling property transactions is now under AML/CTF, may have smart devices in the office subject to cybersecurity standards, and likely has third-party contracts that fall under CPS 230. One business, three frameworks. Map them together, not separately. The JustAnswer Business Law service can help you identify which regulations apply to your specific operations without committing to a full legal retainer.
Build evidence systems, not policy documents
Regulators now expect you to demonstrate control performance at any point in time. That means centralised, auditable data and reduced reliance on manual processes. If your compliance evidence lives in email threads and local spreadsheets, you have a gap. The shift is from “do you have a policy?” to “show me it worked on Tuesday.”
Remediate third-party contracts early
The CPS 230 deadline is 1 July 2026. Start now. Identify every service provider, map the criticality of each relationship, and compare existing contract terms against the new requirements. Where terms fall short, begin renegotiation. This is not a task you can rush in June.
Prepare for the privacy tort
Recent updates introduce a statutory tort for serious invasions of privacy. Misuse of personal data, intrusion on privacy, and reckless handling of sensitive information are now direct litigation risks. Data minimisation and stronger governance practices reduce exposure. If you collect customer data, you need a defensible reason for holding it.
→ Scroll right to see all columns
| Regulation | Effective Date | Key Action Required |
|---|---|---|
| AML/CTF Tranche 2 enrolment | 31 March 2026 | Enrol with AUSTRAC; implement AML program by 1 July |
| Cyber Security Act (smart devices) | 4 March 2026 | No default passwords; vulnerability reporting; software support periods |
| Mandatory merger control (cumulative test) | 1 April 2026 | Notify based on combined size and transaction value |
| CPS 230 contract remediation | 1 July 2026 | Remediate all third-party contracts to meet APRA standards |
| Climate disclosure (Group 2) | July 2026 | Report with same rigour as financial data; audit-ready |
| Ransomware payment reporting | In effect | Report within 72 hours with full details |
Automated decision-making transparency
From December 2026, transparency requirements for automated decision-making take effect. If your business uses algorithms to make decisions about customers — pricing, credit, eligibility, hiring — you need to document how those decisions are made and be able to explain them. This is an emerging area, and the requirements are likely to tighten further.
Frequently asked questions
Do I need to register with AUSTRAC if I am a sole trader accountant? ▾
What happens if I miss the CPS 230 contract remediation deadline? ▾
Does the cybersecurity standard apply to products I already sell? ▾
Can I be held personally liable for a compliance failure? ▾
What counts as a creeping acquisition under the new merger test? ▾
Do I need a lawyer to set up my AML program? ▾
Why treating compliance as a one-off project will cost you more
The Productivity Commission has warned that regulatory complexity is becoming a significant brake on productivity growth. The government has responded with plans to cut compliance costs and streamline regulation, including a tell-us-once principle. But those reforms will take years to implement. In the meantime, the 2026 deadlines are fixed.
The businesses that come out ahead are the ones that treat compliance as an operational system, not a project with an end date. That means building evidence management into daily workflows, not pulling reports together when a regulator asks. It means mapping third-party risk continuously, not once a year. And it means recognising that demonstrated compliance is now the baseline, not a differentiator.
Remember: this article is general information only. For advice on your specific situation, speak to a qualified professional.
If this was useful, you might also want to read Essential Tips for Overcoming Australian Bureaucratic Hurdles.
Sources and Further Reading
Australian Businesses Battling Against Global Competitors — Explores how regulatory burden affects competitiveness and what businesses can do to stay agile.
Sustainable Success: How Australian Businesses Can Thrive in a Green Economy — Covers climate disclosure requirements and the business case for early compliance.
Australian Institute of Company Directors (2026). Research: $160bn and counting – resetting the regulatory balance. 🔗
Corrs Chambers Westgarth (2025). Emerging trends in the Australian regulatory environment. 🔗
Productivity Commission (2025). Resilient Economy Inquiry – Interim Report. 🔗
Australian Prudential Regulation Authority. CPS 230 Operational Risk Management. 🔗

