INSIGHT

Reading the regulatory horizon: key themes from ASIC and APRA's New Corporate Plans

By Kate Austin, Stephanie Malon, Penny Nikoloudis, Isabelle Guyot, Victoria Eastwood, Jillian Button, Emily Turnbull, Llon Riley, Andrew Burns, Julia Clemente, Daniel Taha, Zanna Dunstan, Nicola Holdsworth, Molly O'Brien, Glenn Cardinio, Esra Sporton, Katherine Polazzon, Joshua Fisher, Grace Collier, Thea Shields, Abi Thillainadarajah, Edward Ford
AI APRA ASIC Boards & NEDS Capital Markets Competition, Consumer & Regulatory Corporate Governance Cyber Data & Privacy Dealmakers & Investors Finance, Banking & Debt Capital Financial Services Foreign Investment Review Board (FIRB) General Counsel Insurance Risk & Compliance Superannuation

Introduction 20 min read

Each year, the Australian Securities and Investments Commission (ASIC) and Australian Prudential Regulation Authority (APRA) release their Corporate Plans, which identify the regulators' strategic priorities and projects. The plans provide an insight into where ASIC and APRA will direct their resources and enforcement and supervisory activity for the year ahead.

This year, key themes across ASIC and APRA's plans include a sharpened focus on cyber, AI and geopolitical risk, retirement outcomes and superannuation, climate-related and extreme weather risk to insurers, and continued attention to consumer, small business and investor protection and financial market integrity. Both regulators also place a strong emphasis on productivity. This reflects the Federal Government's Statement of Expectations and broader productivity agenda.

ASIC has reiterated its commitment to pursuing high penalties and sentences where necessary. APRA has confirmed it retains a strong appetite to increase the intensity of its supervision and take formal enforcement action where risks are material or there is a lack of cooperation.

In this Insight, we consider the key themes of the Corporate Plans and what they mean for regulated entities.

Key takeaways

  • Supervision and enforcement activity: ASIC's adoption of more ambitious annual KPIs for investigations and enforcement may drive an increase in both the volume and pace of enforcement activity in the year ahead. APRA continues to signal a willingness to escalate its supervisory response and pursue enforcement action, though we have not yet seen any material uptick in court-based enforcement from the regulator. Both regulators have emphasised that while supporting the productivity agenda remains a priority, they can administer regulatory oversight and supervision in a way that supports that objective.
  • Data, technology, AI and cyber: Regulated entities should expect ongoing scrutiny of their AI usage and cyber and operational resilience. APRA expects strong guardrails and governance around AI, with ASIC closely monitoring banks' AI usage. Cyber and operational resilience remains a top priority for both regulators. Regulated entities are expected to actively monitor evolving threats and strengthen board oversight. The regulators have flagged technology concentration risk from shared service providers, with APRA also pushing for stronger resilience against AI-enabled and quantum-enabled cyber threats.
  • Superannuation and retirement outcomes: ASIC and APRA have provided a roadmap of targeted focus areas within the ongoing themes of governance and risk management maturity, protecting superannuation savings, member services and retirement incomes. These include areas precipitated by the First Shield and Guardian collapses: unlisted asset valuations, investment governance reforms and the practices of platform trustees, lead generators and responsible entities. The regulators will also focus on advice fee deductions, use of complaints data, underperformance and retirement outcomes. Trustees and other regulated entities should carefully review their practices in these areas, noting that both regulators have strongly signalled that they are willing to move to direct supervisory and enforcement action where practices fall short.
  • Protecting consumers and small businesses: Buy now, pay later (BNPL) providers can expect assessment of their compliance with the National Consumer Credit Protection Act 2009 (NCCP Act), and non-bank lenders should be aware ASIC is investigating lending practices that can lead to poor outcomes for small businesses, including the use of unfair terms. With the Scams Prevention Framework (SPF) commencing on 31 March 2027, regulated entities should expect regulatory attention on scam prevention and response. Consistent with regulator's focus on consumer outcomes, insurers should also prepare for a redrafted General Insurance Code of Practice, which is being progressed by the Insurance Council of Australia and is expected to be lodged with ASIC in late October of this year.1
  • Financial market transparency, integrity and stability: ASIC is broadening its focus on market integrity, expanding its interest in insider trading, market manipulation and disclosure to market cleanliness, market-wide risks, professional conduct, and AI-driven risks. Private markets are now a permanent part of the regulatory agenda, with increasing focus on auditor misconduct. Reporting entities should expect ASIC to continue its 'pragmatic and proportionate' approach to supervising the mandatory climate reporting framework, including through the rollout of education and relief.

Strategic priorities

ASIC's Corporate Plan covers 2026-30 and identifies five strategic priorities:

  • improving consumer and small business outcomes;
  • strengthening professional conduct and improving access to reliable financial and business information;
  • supporting better retirement outcomes and superannuation member services;
  • supporting effective, resilient and innovative operations; and
  • driving integrity, transparency and confidence across markets.

In her foreword, ASIC Chair Sarah Court frames ASIC's the regulator's work around four themes: supporting better financial outcomes for all Australians, driving productivity, enhancing innovation, and building resilience.

APRA's Corporate Plan covers 2026-27 and is now built around three strategic objectives (down from four last year):

  • maintaining financial safety and stability;
  • 'getting the balance right' to deliver its financial safety and stability objectives without 'undue cost' to industry; and
  • improving organisational effectiveness.

Under its first objective, APRA is prioritising five prudential outcomes for the year:

  • strengthening operational resilience in response to cyber and AI risks;
  • strengthening resilience to geopolitical risks;
  • ensuring the system is prepared for severe stress;
  • improving outcomes for superannuation members; and
  • preparing for a new payments role.

Common themes across both plans continue from last year, but with some notable evolutions:

  • Cyber and AI risk: ASIC has elevated AI use to a dedicated focus area this year, while APRA has flagged a deeper supervisory focus on cyber and AI resilience.
  • Geopolitical risk: Both ASIC and APRA have elevated this to a standalone, explicitly named priority;
  • Retirement outcomes and superannuation: This remains a continuing joint priority for both ASIC and APRA.
  • Payments reform: Both regulators have made a firmer joint commitment, with APRA developing a prudential framework for large stored-value facility providers and working with ASIC on joint guidance.
  • Productivity: This has emerged as an explicit cross-regulator theme this year, reflecting the Federal Government's Statement of Expectations, with ASIC notably committing to concrete KPIs, including faster licensing and investigation timeframes.

Supervisory and enforcement approach

ASIC: ASIC remains committed to pursuing high penalties and sentences through the courts so that breaking the law has a material impact and achieves deterrence. Its enduring enforcement priorities target:

  • misconduct damaging market integrity, including insider trading, continuous disclosure breaches and market manipulation;
  • misconduct impacting First Nations peoples;
  • misconduct involving a high risk of significant consumer harm, particularly conduct targeting financially vulnerable consumers;
  • systemic compliance failures by large financial institutions resulting in widespread consumer harm;
  • new or emerging conduct risks within the financial system; and
  • governance and directors’ duties failures.

ASIC also puts more rigour around its enforcement ambitions through the adoption of annual KPIs to:

  • refer at least 70% of reported alleged misconduct to the Regulatory Triage Committee within 60 days;
  • commence a formal investigation within 50 days of accepting a referral;
  • reach first action or finalisation within 12 months of commencing an investigation;
  • refer at least 25 people or companies to the Commonwealth Director of Public Prosecutions for criminal prosecution; and
  • commence at least 30 civil proceedings.

Additionally, ASIC will undertake risk-based supervision. This includes enhanced oversight of financial institutions with the greatest potential to impact consumers, and monitoring Australian financial markets trading in real time and post-trade to protect market integrity.

APRA: In its Corporate Plan, APRA states that it 'retains a strong appetite to increase the intensity of its supervision to address inadequate practices, and to take formal enforcement action against entities or individuals, particularly where risks are material or there is a lack of cooperation.' This is reflected in APRA's commitments in relation to the five prudential outcomes it is prioritising for the year under its strategic objective of maintaining financial safety and stability.

  • Cyber and AI risk: Regulated entities should expect more frequent and deeper engagement from APRA on cyber and AI risks in supervisory interactions, with APRA expecting entities to be readily able to show how they are managing these risks.
  • Geopolitical risk: APRA will continue to strengthen resilience to geopolitical risks at both the entity and system level, with a focus on risks that could stem from international tensions such as trade disruptions, sanctions, grey-zone activities and conflicts.
  • Severe stress preparedness: APRA will increase its focus on contingency planning to ensure the financial system can continue to play its role in absorbing, rather than amplifying, the impact of any severe downturn or disruption.
  • Superannuation member outcomes: APRA will maintain strong regulatory oversight of superannuation trustees and aim to ensure trustees are conducting their affairs prudently and meeting the reasonable expectations of members, in line with the requirements of the Superannuation Industry (Supervision) Act 1993 (SIS Act) and APRA's prudential framework;
  • New payments role: In anticipation of APRA's new responsibilities for the prudential regulation of large stored-value facility (SVF) providers, APRA will develop and consult on a new prudential framework for large SVF providers and work with ASIC on joint guidance to support implementation.

Both regulators continue to frame enforcement and supervision as part of a genuine productivity agenda. APRA's Corporate Plan states that, in continuing to support productivity and 'getting the balance right', the plan includes 'additional actions to free up capital, streamline prudential requirements and remove duplicative reporting, without undermining safety standards'. Meanwhile, in her foreword to ASIC's Corporate Plan, ASIC Chair Court states that ASIC 'does not have to choose between strong regulation and growth' and can pursue both to address Australia's 'longstanding productivity challenges'.

Data, technology, AI and cyber

Technology risk remains a focal point for ASIC and APRA in this year's Corporate Plans.

Both regulators indicate a continued increased focus on how regulated entities use AI, manage cyber and operational resilience, and prepare for emerging technology risks such as frontier AI and quantum computing.

  • AI adoption: Neither regulator opposes AI adoption, but they do expect regulated entities to implement strong guardrails. APRA expects entities adopting AI to improve governance, risk management and board oversight. ASIC supports AI where it is safe, responsible, beneficial to business and does not compromise consumer outcomes. ASIC does, however, caution that weak controls can allow AI to amplify misleading financial information and consumer harm. Relatedly, ASIC specifically intends to monitor the growing use of AI by banks.
  • Cyber and operational resilience: As with previous years, cyber risk and operational resilience remains front of mind for both regulators. Technological, cyber and operational resilience is one of ASIC's focus areas. It will continue to articulate its expectations for entities in the financial system. APRA expects entities to actively monitor and adapt to evolving cyber threats, while also strengthening board oversight of technology and cyber risk. Entities should expect more frequent (and thorough) regulatory engagement here and be ready to show how they manage these risks.
  • Technology risks (both isolated and interconnected): Both regulators' plans flag growing operational and systemic risk arising from increased reliance on shared service providers and technology platforms. APRA plans to collect data on material service providers to improve its oversight of shared dependencies. Separately, APRA has identified frontier AI and the rise of quantum computing as posing greater and more sophisticated cyber threats. APRA will focus on ensuring entities have stronger resilience to AI-enabled cyber threats (and quantum computing) and has reiterated the Australian Signals Directorate’s recommendation that businesses should finalise their transition plans for post-quantum cryptography (and begin implementation by the end of 2028).

Internally, both regulators will continue to invest in data and AI. APRA is aiming to become an 'AI-enabled regulator', with plans to develop priority AI use cases. ASIC is developing its data and AI literacy and is enabling AI adoption to enhance its decision-making.

Superannuation and retirement outcomes

Superannuation and retirement remain a standalone focus area for both regulators. ASIC's top five strategic priorities include 'retirement incomes and superannuation member services', while APRA's top five priorities for financial safety and stability include 'improving outcomes for superannuation members'.

While superannuation trustees remain the key focus within these strategic priorities, there are important impacts on responsible entities of managed investment schemes, financial advisers and others within the ecosystem.

Key areas of focus within these strategic priorities include:

Investment governance
  • Valuation: APRA will require selected large trustees to appoint an independent party to review their valuation governance practices, focussing on unlisted assets. APRA has warned that trustees will be held to account for timely remediation of any material risks identified. ASIC will also consider valuation practices as part of its targeted reviews of financial reports and audits.
  • Investment governance reforms: APRA plans to consult with industry on capital requirements to support the trustee compensation reforms proposed by the Government for higher risk investment options. The regulator is also developing its own reform package to lift investment governance standards across the industry. These will apply to all trustees, but are expected to have the most impact on platform trustees (see our Insight).
  • Platform trustee supervision: APRA has signalled it will supervise platform trustees more intensely, including to ensure entities subject to enforcement action take appropriate remedial action.
Retirement outcomes

APRA will focus on retirement when conducting supervisory engagements relating to SPS 515 Strategic Planning and Member Outcomes, and plans to finalise its reporting requirements for the Retirement Reporting Framework the first half of 2026-27. ASIC will continue to monitor industry progress in implementing the retirement income covenant and share better practice examples.

Underperformance and 'sub-standard practices'

APRA has indicated it will focus on underperforming funds and funds with 'sub-standard practices', including in relation to expenditure. APRA has indicated it will work with the Government on potential future revisions to the performance test.

Fair and informed member services – use of complaints data

Within the key focus areas of fair and informed members services, ASIC is completing its review of how superannuation trustees identify and address systemic issues using complaints data.

Misconduct targeting superannuation savings – lead generation

Misconduct targeting superannuation savings remains a broad focus area for ASIC this year, with a special mention for its plans to identify and disrupt the models of AFS licensees that use high-risk lead-generation services.

Innovation in advice

ASIC has stated that 'innovation in advice' is a key focus area. While it is not entirely clear how far this focus extends, ASIC has called out the following two priorities:

  • Advice fee deductions: ASIC will review trustee oversight of advice-fee deductions and related assurance processes, building on Report 833, Safeguarding super: How well are platform trustees monitoring risks to retirement savings? It has warned it will take enforcement or other regulatory action if it identifies any poor conduct.

    Separately managed accounts (SMAs): ASIC has flagged it will continue surveillance of licensees recommending and offering SMAs, with a focus on governance, conflicts and consumer outcomes.
Managed investment scheme (MIS) oversight

MIS oversight is now a standalone focus area within ASIC's superannuation and retirement outcomes strategic priority. ASIC has flagged:

  • it will engage with industry bodies to develop and implement enhanced MIS standards, including by continuing to focus on the private credit sector, building on ASIC Report 823 Advancing Australia’s evolving capital markets: Discussion paper response report; and
  • it will increase its supervisory activity of MISs by introducing an annual risk-based surveillance program and enhancing its data capabilities to improve the visibility of MIS risks and use of collected data.

The Shield and First Guardian collapses have heavily informed this year's corporate plans from both regulators, so the focus areas will come as no surprise. However, the regulators have given trustees and other regulated entities within superannuation and retirement a roadmap of quite specific focus areas within the broader ongoing themes of governance and risk management maturity, member services and retirement incomes. All affected entities should carefully review their existing practices here, noting that both regulators have strongly signalled that they are willing to move to direct supervisory and enforcement action where practices fall short.

Protecting consumers and small businesses

Non-bank and BNPL lenders

A continuing area of strategic focus for ASIC is improving outcomes for both consumers and small businesses.

June 2026 marked one year since the NCCP Act was extended to apply the National Credit Code to BNPL contracts. This change meant all providers of BNPL products must now comply with obligations under the NCCP Act including those related to responsible lending, hardship, and reporting. ASIC has indicated that as part of its work to enhance consumer protections, it will assess compliance by BNPL providers with the legislation and identify insights into the impact of these laws.

For small businesses, following its launch of the refreshed Small Business Strategy last month, ASIC has enforced its commitment to 'taking targeted action against misconduct that harms small businesses' by including a proposal in its Corporate Plan to examine lending practices by non-bank lenders that can lead to poor outcomes for small businesses, including through the use of unfair terms. This follows several years of regulatory focus and action against banks over unfair terms in small business contracts.

ASIC has also indicated that it will continue focusing on debt collection. Building on the work over the past year, it will seek to minimise harm from debt collection by credit providers, debt buyers and contingent collectors acting on their behalf. Lenders can expect ongoing ASIC surveillance and engagement here, as well as a continuation of the enforcement proceedings seen during the past year against non-bank lenders engaging in misconduct in debt management and collection.  

Scams

Scams remain a top priority for ASIC, with scam prevention and disruption named as a specific focus area under ASIC's first strategic priority.

We expect ASIC's main focus in 2026-27 will be implementing the SPF. The framework is due to commence on 31 March 2027 and will introduce a regulatory regime aimed at requiring regulated entities to take steps to prevent, detect, disrupt, report and respond to scams.

Beyond the SPF, ASIC's other scam-related commitments for 2026-27 are to:

  • actively disrupt investment scams through takedowns of scam websites (noting equivalent obligations exist for SPF-regulated entities to prevent and respond to brand impersonation attempts);
  • collaborate and share information with domestic and international regulators, including the ACCC-led National Anti-Scam Centre; and
  • share information, online resources and warnings with consumers, including expanding its registers to include Australian Financial Services licensees' website addresses.

Together, these commitments signal that regulated entities, particularly those in the banking, telecommunications and digital platforms sectors that are now covered by the SPF, should expect sustained regulatory attention from ASIC on scam prevention and response over the coming year.

While APRA has not explicitly prioritised scams, it has called for regulated entities to strengthen their resilience to AI-enabled cyber threats and to maintain effective cyber controls as the threat environment evolves. As scam methodologies become more sophisticated and increasingly leverage AI, regulated entities should expect APRA's supervision of cyber risk governance, systems and controls to broadly align with ASIC's scam-prevention agenda.

Insurance

Insurance claims and service standards are again a focus area for ASIC within its strategic priority of 'improving customer and small business outcomes'. ASIC is continuing its review into whether life insurers are meeting their obligations when delivering services to customers who obtained policies directly or through financial advisers, in response to service issues being a major source of life insurance complaints.

In the general insurance sector, ASIC has identified 'disaster chasers' as an enforcement priority and has announced a review of businesses that provide consumer services related to home insurance claims, particularly in areas affected by natural disasters.

Citing its strategic objective of maintaining financial safety and stability, APRA has indicated that, as part of its review of industry implementation of Prudential Standard CPS 230 Operational Risk Management (CPS 230), general insurers can expect supervisory engagement focused on operational and technology risk management. This follows similar reviews recently undertaken in the superannuation and private health insurance sectors. APRA has stated that it will engage directly with entities regarding the findings of the review and, where appropriate, share broader insights with industry.

Financial market transparency, integrity and stability

Market integrity and the conduct of directors, officers and auditors

ASIC’s focus on market integrity continues in 2026–27, albeit with a slightly broader lens. Alongside its established focus on insider trading, market manipulation and disclosure, ASIC is expressly targeting:

  • 'market cleanliness' across public and private markets, together with changing risks, information disclosure, private credit practices and preparing for the new digital assets regime;
  • 'market-wide risks' across public and private equity, debt and derivatives markets, with a view to identifying emerging stress, excess leverage and risk-taking that may threaten orderly markets;
  • AI-driven manipulation and market integrity risks, including deepfakes and misinformation;
  • surveillance of wholesale private equity valuation practices, private credit liquidity and credit risk management, and continuing its scrutiny of private credit distribution to retail clients. ASIC has also said it will review transactions to assess the protection of confidential information, and enhance its annual, risk-based supervision and oversight of managed investment schemes; and
  • professional conduct, with an increased focus on holding directors and auditors to account and ensuring that valuations and auditing are high quality and timely. It will do this through targeted and thematic surveillance and by examining individual complaints received by audit firms, with associated action against auditors if required.

In parallel, ASIC is pairing this increased scrutiny with a more facilitative agenda. The agenda includes consulting on simplified fundraising settings to enhance the appeal of Australia’s capital markets and continuing work on tokenisation, innovation and competitive market infrastructure. 

This system-level focus is also reflected in APRA’s agenda. APRA plans to build on its first system-risk stress test by undertaking further work on risks arising from 'linkages between sectors' and their potential implications for financial stability. APRA is also increasing its scrutiny of valuation governance for unlisted assets (see section 6 above) and will increase its focus on business continuity planning, noting the continued escalation of cyber threats, including frontier AI. It is also jointly consulting (with ASIC) on proposed changes to the Financial Accountability Regime, seeking to reduce administrative burdens while maintaining strong accountability.

Together, these indicate that private markets are now a permanent part of the regulatory agenda, with an increasing focus on auditor misconduct. Regulators are also adopting a clear cross-market lens, meaning that entity-specific conduct or governance issues may attract broader regulatory attention where they reveal linkages to counterparties, investors or the wider financial system.

Climate-related financial risk

a) Mandatory climate reporting

Implementing the mandatory climate reporting framework remains a key focus area for ASIC over the next five years. ASIC has reiterated that it will take a 'pragmatic and proportionate' approach to this reporting, consistent with its Regulatory Guide 280 Sustainability Reporting. This approach includes assisting entities with education and relief, and engaging with large audit firms on their methodologies. For example, ASIC has:

  1. released educational modules to help companies understand foundational concepts behind the sustainability reporting requirements; and
  2. continued to update its publicly available sustainability reporting and audit relief decisions register, summarising examples of situations where ASIC has exercised (or not exercised) its exemption and modification powers.

Further, ASIC has reviewed and released its initial observations for a subset of the first sustainability reports earlier this year. This is aimed at improving the quality, consistency and comparability of climate-related financial disclosures. ASIC will continue to review Group 1 (listed and unlisted) entities and share its final observations later this year.

This comes as the Australian Treasury has opened consultation on improving the efficiency of climate-related financial disclosures, in an effort to 'lower costs for businesses while still keeping reports high-quality, credible and comparable with other countries. The main proposals include:

  1. changing assurance rules to reduce compliance costs;
  2. providing clearer guidance on key terms and concepts; and
  3. reducing the burden of information requests across supply chains.

We expect that reporting entities will likely benefit from the foreshadowed changes, if implemented.

See our Insights on Regulatory Guide 280 Sustainability Reporting obligations here, observations on the first wave of Group 1 reporting here, and broader background on the climate-related financial disclosure regime here.

b) Greenwashing and associated governance failures

Greenwashing is no longer a stated enforcement priority for ASIC (noting it remains one for the ACCC in 2026-27). However, it remains a salient risk for entities, as ASIC continues to obtain successful outcomes in its regulatory actions against companies. Just last month, ASIC secured its fourth greenwashing civil penalty outcome: a $7.3 million penalty against Fiducian Investment Management Services Ltd for breaching its care and diligence duties and engaging in conduct liable to mislead the public.

Importantly, this was also ASIC's first outcome against the operator of a managed fund for failures in governance, compliance and oversight of ESG claims. In public comments about the case, ASIC Chair Court emphasised that the 'ESG claims must be backed by robust systems, oversight and governance" and that '[f]und managers and responsible entities must comply with their duties and ... cannot make sustainability claims that are not supported in practice'. This signals a broader approach by ASIC, linking greenwashing claims to the statutory duties of responsible entities and governance failures.

See our Insight published at the commencement of the proceeding.

c) Insurance risks

ASIC has included physical climate-related risks as an acute issue for the insurance sector over the short and long terms. This is especially relevant for those in areas considered to be 'high-risk', such as northern Australia, where the cost of insurance premiums have jumped following several years of extreme flooding. As noted above, ASIC has also identified ‘disaster chasers’ as a focus area within its strategic priority of improving consumer and small business outcomes. Although insurance remains a priority from last year, ASIC’s focus has shifted from a broader review of the accuracy and transparency of general insurers’ premium disclosures to a more direct assessment of claims-handling for disaster-affected consumers, including claims connected with physical climate risks.

Similarly, APRA has found that while Australia’s insurance industry remains broadly well-positioned, it continues to face structural and emerging challenges, including from climate-related risk. In particular, APRA has identified affordability and availability as being two aspects within general insurance that are already facing pressures as a result. This is consistent with APRA's previous report. This is already widening the protection gap, with fewer consumers able to obtain or afford general insurance. As a sub-sector with $144.4 billion in assets, this is likely to have significant flow on impacts for related industries.

Next steps

These Corporate Plans give a clear signal of where ASIC and APRA will focus their attention in the year ahead. If you'd like to discuss what this means for your organisation, or want help reviewing your practices against these priorities, get in touch with our team below.