ASIC's 2026–27 Regulatory Agenda: What Boards and Businesses Should Expect
Australia's corporate regulator has set out its agenda for the year ahead, with a clear emphasis on earlier detection of risk, stronger accountability and more targeted enforcement.
ASIC's 2026–27 Corporate Plan, released in August 2026, identifies priorities spanning consumer protection, professional conduct, financial reporting, operational resilience, private markets and emerging technology. At the same time, ASIC has committed to reducing unnecessary regulatory friction for businesses seeking to comply.
ASIC Chair Sarah Court has described the regulator's intended direction as becoming "easier to deal with" for those doing the right thing and "harder to avoid" for those who are not.
Behind that formulation is a broader strategy: identify emerging risks earlier, respond more selectively and impose stronger consequences where serious misconduct is identified.
For boards, executives and regulated businesses, the practical implication is that regulatory preparedness increasingly begins before ASIC makes contact.
What Boards and Businesses Should Take From ASIC's Agenda
Several themes deserve particular attention:
- Earlier detection: ASIC intends to make greater use of data and intelligence to identify emerging risks and potential misconduct sooner.
- Governance and accountability: Directors, auditors and other gatekeepers remain firmly within ASIC's focus.
- Reliable information: Financial reporting, valuations and disclosure remain central to market integrity.
- Private markets: Private credit and other private-market activities are attracting greater regulatory scrutiny.
- Cyber and AI: Technology, operational resilience and responsible AI use are increasingly governance issues.
- Enforcement remains active: Regulatory simplification should not be mistaken for reduced scrutiny.
A Regulator Seeking to Intervene Earlier
ASIC's current strategy rests on three broad themes: becoming more responsive, investing in earlier detection and prevention, and setting clearer expectations supported by targeted intervention and stronger consequences.
The emphasis on early detection is significant.
ASIC has said it is modernising how it triages reports of misconduct and combining those reports with other intelligence to identify patterns and move higher-priority matters more quickly to regulatory and enforcement teams.
That changes how organisations should think about regulatory risk.
Compliance should not begin when a regulator requests information. The quality of an organisation's governance, records, escalation processes and controls before that point may materially affect its ability to respond.
ASIC's five strategic priorities for 2026–27 broadly focus on consumer and small-business outcomes; professional conduct and reliable information; retirement outcomes; resilient and innovative operations; and integrity and confidence across Australia's public and private markets.
Directors and Professional Accountability Remain Firmly in Focus
ASIC's agenda places continuing emphasis on directors, auditors, financial reporting and the reliability of information used in corporate decision-making.
For boards, this reinforces an important distinction between receiving information and exercising effective oversight.
Relevant questions include whether financial and compliance controls are operating effectively, whether significant risks reach the board promptly, whether conflicts are identified and managed, whether management assumptions receive appropriate challenge and whether important decisions are supported by reliable information.
ASIC has also continued to identify corporate governance and directors' duties as areas of regulatory concern. Earlier in 2026 it reported a significant volume of misconduct reports involving corporate governance issues and referred to active investigations concerning governance failures and directors' duties.
The quality of the process through which a decision is made may therefore become important long after the decision itself.
Reliable Information and Private Markets Are Under Greater Scrutiny
Reliable financial and business information is another recurring theme.
ASIC's 2026 enforcement priorities include financial reporting misconduct, including failures to lodge required financial reports. The regulator has emphasised that reliable information is increasingly important as private-credit funds, superannuation funds and other entities holding unlisted assets assume a greater role in Australia's financial system.
Private credit is also a specific enforcement priority.
For private equity firms, private-credit providers, fund managers, family offices and businesses raising private capital, the direction of regulatory attention is important.
Reduced public disclosure should not be mistaken for reduced regulatory expectations.
Organisations should consider whether valuations are robust, conflicts are properly managed, investor information is clear and not misleading, liquidity assumptions are realistic and governance arrangements remain appropriate as investment structures grow in size and complexity.
ASIC's focus on private markets reflects a broader proposition: where significant capital is being raised and deployed, regulators will increasingly expect the systems supporting valuations, disclosure and governance to keep pace.
Cyber, Operational Resilience and AI Are Governance Issues
ASIC's agenda also places technology and operational resilience firmly within the governance framework.
Its priorities include cyber and data resilience, crisis preparedness, operational risk, artificial intelligence and emerging technologies.
The Australian Government's 2026 Statement of Expectations similarly asks ASIC to support responsible innovation and adopt a targeted, proportionate regulatory approach while protecting consumers and market integrity. ASIC's corresponding Statement of Intent recognises the need to support sustainable economic growth and consider regulatory impacts on businesses and new market entrants.
For boards, cybersecurity and AI should therefore not be viewed solely as technology projects.
They can engage information security, privacy, confidential information, operational resilience, third-party risk, automated decision-making, consumer outcomes, record keeping and director oversight.
ASIC itself is also investing in data and intelligence capability.
The regulatory environment is therefore evolving on both sides: businesses are becoming more technologically sophisticated, and so is the regulator.
Easier to Deal With Does Not Mean Reduced Enforcement
ASIC has acknowledged concerns that some regulatory processes have been too slow, legalistic and difficult.
Its current direction includes greater responsiveness, simpler regulatory engagement and efforts to reduce unnecessary friction for businesses seeking to comply.
But ASIC has expressly rejected the proposition that this means weakening its enforcement posture.
The regulator's 2026 enforcement priorities include:
- misleading pricing practices;
- poor private-credit practices;
- financial reporting misconduct;
- insurer claims and complaint-handling failures; and
- continuing accountability work arising from the Shield and First Guardian Master Fund collapses.
Continuing priorities include insider trading, misconduct affecting consumers experiencing financial difficulty, unlawful practices seeking to evade small-business creditors, failures in superannuation member services and auditor misconduct.
ASIC also reported when announcing those priorities that it had doubled the number of new investigations and nearly doubled the number of new court matters during the preceding 12 months.
The intended distinction is increasingly clear:
less unnecessary friction for compliant activity, but earlier and stronger intervention where serious risk or misconduct is identified.
What Should Boards Be Doing Now?
For many organisations, the appropriate response is not another stand-alone compliance project.
The more useful exercise is to test whether existing governance systems can identify and escalate the risks ASIC is increasingly focused on.
1. What would the regulator see today?
Boards should understand how governance arrangements, financial reporting, compliance systems and internal records would appear if reviewed externally.
Board minutes, management reports, risk papers and internal communications can become important evidence of how decisions were made.
2. Do significant issues reach decision-makers early enough?
Escalation systems should ensure material financial, compliance, cyber, conduct and reputational concerns reach senior management and boards before they develop into larger problems.
3. Are controls operating or merely documented?
Policies alone do not demonstrate effectiveness.
Organisations should test whether personnel understand their responsibilities, whether controls work in practice and whether identified weaknesses are actually remediated.
4. Is technology changing the organisation's risk profile?
Boards should understand where AI, automation and data-intensive systems are being used, what information they process, who is accountable for them and how outputs are reviewed.
5. Is the organisation prepared for regulatory engagement?
Businesses should know who will manage a regulator enquiry, how potentially relevant records will be preserved, how privilege will be protected, who is authorised to communicate with ASIC and when the board should become involved.
Preparation before an investigation is generally more effective than designing the process after one has begun.
The Broader Direction
ASIC's 2026–27 agenda is not simply a call for more regulation.
The regulator is seeking to identify risk earlier, reduce unnecessary friction for compliant businesses and concentrate intervention where it considers the potential harm greater.
For boards and executives, that places renewed importance on sound governance, reliable information, effective controls and timely escalation.
The practical question is therefore not simply whether the organisation complies with the law today.
It is whether its systems are capable of identifying, escalating and responding to emerging problems before they develop into regulatory events.
How We Can Help
We advise boards, directors, executives and businesses on corporate governance, regulatory compliance, investigations and disputes.
We assist with governance frameworks, director and officer obligations, regulatory engagement, internal investigations, risk management and responses to actual or potential enforcement action.
This publication is current as at 24 September 2026 and is provided for general information only. It does not constitute legal, financial, investment or tax advice. Regulatory obligations and appropriate governance arrangements depend on the circumstances, activities and applicable legal framework of each organisation.


