Quick Answer:
Most of the regulatory compliance changes Australian businesses were told to prepare for have already commenced. Mandatory climate reporting began for the largest entities on 1 January 2025 and extended to mid-sized entities on 1 July 2026. Intentional wage underpayment became a criminal offence on 1 January 2025. The right to disconnect reached small business employers on 26 August 2025. APRA’s CPS 230 commenced on 1 July 2025. A statutory right to sue for serious invasion of privacy commenced on 10 June 2025. The practical question is no longer how to prepare. It is whether your risk management framework, policies and training records already reflect obligations that are in force today.
In this guide
- Regulatory compliance changes already commenced
- Climate and sustainability reporting
- Wage compliance is now a criminal matter
- The right to disconnect now covers every employer
- Psychosocial hazards are a work health and safety duty
- Privacy: a new right to sue, and a code still coming
- CPS 230, and why it matters even if APRA does not regulate you
- Regulatory compliance changes still ahead
- The workforce shifts driving these changes
- Building a framework that absorbs regulatory compliance changes
- A 90-day catch-up plan
- Where this leaves your risk management framework
- Frequently asked questions
Australian businesses have spent two years being told to get ready for a wave of regulatory compliance changes.
That wave has now broken. Climate reporting, criminal wage underpayment, the right to disconnect, psychosocial hazard duties and a new privacy tort are all law, not proposals.
These regulatory compliance changes matter because the language of preparation is comfortable. It suggests there is still time.
For every obligation on this page, there is not. The gap that opens up is not a gap between an organisation and a future requirement.
It is a gap between an organisation and a current one, and that is the kind a regulator can act on. Closing it is risk management work, not a compliance project with an end date.
This guide covers the regulatory compliance changes that apply at the Commonwealth level and under the model work health and safety laws. Some duties differ by state and territory, and by industry. Dates and thresholds below were checked against the responsible regulator in August 2026.
Regulatory Compliance Changes That Have Already Commenced
Seven regulatory compliance changes have taken effect since the start of 2025. Each creates a documentation or evidence obligation, which is where most organisations are exposed.
The table below is the fastest way to check whether any of them now capture you.
| Change | In force from | Who it captures | What it demands in practice |
|---|---|---|---|
| Mandatory climate-related financial disclosure (Group 1) | Financial years starting 1 Jan 2025 | Largest entities, and NGER-registered corporations in a group above the NGER threshold. Registered schemes, superannuation entities and retail CCIVs are not in Group 1 | A sustainability report covering governance, strategy, risk management and metrics |
| Criminal offence for intentional underpayment | 1 January 2025 | All national system employers | Evidence that pay decisions were deliberate and correct, not just that errors were fixed |
| Right to disconnect (employers with 15 or more employees) | 26 August 2024 | Non-small-business employers | A position on out-of-hours contact, and awareness that adverse action protections apply |
| CPS 230 Operational Risk Management | 1 July 2025 | APRA-regulated banking, insurance and superannuation entities | Critical operations mapped, tolerances set, material service providers registered |
| Statutory tort for serious invasion of privacy | 10 June 2025 | Individuals and entities broadly, not only APP entities | Exposure to a direct court action by an individual, separate from the Privacy Act |
| Right to disconnect (small business employers) | 26 August 2025 | Employers with fewer than 15 employees | The same duty, now with no size exemption remaining |
| Mandatory climate-related financial disclosure (Group 2) | Financial years starting 1 July 2026 | Two of: revenue $200m or more, gross assets $500m or more, 250 or more employees. Also all NGER registered corporations, and asset owners with $5 billion or more in assets | First reports lodged in 2027, so the data collection has to be running now |
The pattern worth noticing
Four of these seven items are evidence obligations rather than activity obligations. They do not ask whether you did something. They ask whether you can show, at a specific past date, what you did and why. An organisation can be doing the right thing and still fail, because the record was never kept.
Climate And Sustainability Reporting
The most administratively demanding of the recent regulatory compliance changes is mandatory climate-related financial disclosure, now part of the Corporations Act.
It is administered by ASIC and the reporting content is set by the Australian accounting standard AASB S2. It is phased in by size, in three groups.
Group 1 began with financial years starting on or after 1 January 2025. Group 2 began with financial years starting on or after 1 July 2026, which has now passed. Group 3 follows from 1 July 2027. An entity falls into a group by meeting at least two of three criteria.
| Group | Financial years starting | Revenue | Gross assets | Employees |
|---|---|---|---|---|
| Group 1 | 1 Jan 2025 to 30 Jun 2026 | $500m or more | $1bn or more | 500 or more |
| Group 2 | 1 Jul 2026 to 30 Jun 2027 | $200m or more | $500m or more | 250 or more |
| Group 3 | On or from 1 Jul 2027 | $50m or more | $25m or more | 100 or more |
Two of the three criteria must be met. Separate tests apply alongside the size criteria. National Greenhouse and Energy Reporting scheme registered corporations are captured from Group 1.
Asset owners, meaning registered schemes, registrable superannuation entities and retail CCIVs with $5 billion or more in assets, are captured from Group 2 rather than Group 1.
Check your position against ASIC’s guidance on who must prepare a sustainability report rather than assuming, because the employee count test catches organisations whose revenue would not. The thresholds above are set out in Table 2 of ASIC Regulatory Guide 280.
If your organisation falls within scope, the sustainability report must disclose climate-related risks and opportunities, report on governance and oversight processes, identify how climate risks affect financial performance, and track and report greenhouse gas emissions.
Those four are the substance of AASB S2, and three of them are governance questions rather than environmental ones.
The part that surprises boards is that this is a governance obligation before it is an environmental one.
The standard asks how climate risk is overseen, who is accountable, and how it feeds into strategy and risk management.
Those are questions about your risk register, your governance structure and your board papers. An organisation with no documented process for identifying and escalating climate risk to the board cannot answer them, regardless of its actual emissions.
This is why enterprise risk management and ESG reporting are converging rather than running in parallel.
Scope 3 emissions reporting is not required in an entity’s first reporting year and becomes mandatory from the second.
That relief is narrower than it sounds, because Scope 3 depends on supplier data, and suppliers take time to organise. The first year is the year to build that pipeline.
If you sit below every threshold, you are still affected indirectly. Reporting entities have to understand their value chain, which means larger customers will start asking smaller suppliers for emissions and governance information.
Being unable to answer becomes a commercial problem well before it becomes a legal one.
ESG reporting and workforce compliance are closer than they look.
The social component of ESG covers workforce practices, safety performance, training and conduct, which means the same governance records support both your ESG reporting and your work health and safety obligations.
Organisations that treat ESG as a separate reporting exercise usually end up collecting the same evidence twice. See GRC and ESG reporting for how the two fit together.
Wage Compliance Is Now A Criminal Matter
From 1 January 2025, intentionally underpaying an employee’s wages or entitlements can be a criminal offence under the Fair Work Act.
For most Australian employers this is the workforce compliance obligation with the sharpest consequence attached.
This is the single largest of the workforce-related regulatory compliance changes in a decade, and it is frequently underestimated because most employers know they are not deliberately underpaying anyone.
The offence turns on intent. Honest mistakes are not captured, and the Fair Work Ombudsman has been explicit about that.
The difficulty is evidentiary rather than moral. Intent is inferred from records.
An organisation that was told about a classification problem, recorded the advice, and did not act on it for eighteen months is in a materially different position from one that found the same problem during a scheduled audit and corrected it.
What actually changes your exposure
Not whether errors occur. Whether there is a documented process that finds them, a record of what was found, and evidence of what happened next. That is a risk management artefact, not a payroll one.
A protection exists for smaller employers. The Voluntary Small Business Wage Compliance Code means a small business employer’s conduct cannot be referred for possible criminal prosecution where the Fair Work Ombudsman is satisfied the code was complied with in relation to that underpayment.
Larger employers can enter cooperation agreements. Both routes reward organisations that self-identify and disclose, and both depend on records.
For most Australian employers the practical work is unglamorous. Confirm which award or agreement applies to each role, confirm classifications are current after any role change, and put a scheduled review in place with a named owner.
Award coverage errors and stale classifications after promotions are the two most common sources of systemic underpayment, and both are documentation failures rather than payroll failures.
The Right To Disconnect Now Covers Every Employer
The right to disconnect allows an employee to refuse to monitor, read or respond to contact, or attempted contact, outside their working hours, unless that refusal is unreasonable.
It began for employers with 15 or more employees on 26 August 2024 and extended to small business employers on 26 August 2025. No size exemption remains.
Contact from a third party such as a client is included. That catches professional services, property, recruitment and any industry where client contact routinely runs past close of business.
Whether a refusal is unreasonable depends on factors including the reason for the contact, how it is made and how disruptive it is, whether the employee is compensated for being available, the nature of their role and level of responsibility, and their personal circumstances including caring responsibilities.
An on-call allowance changes the analysis. A general expectation of availability, unpaid and undocumented, does not.
The compliance risk is rarely the contact itself. It is the response to a refusal.
Adverse action protections apply, so a manager who treats an employee less favourably after they decline out-of-hours contact creates a general protections exposure.
That is a training and culture problem, and the evidence a business needs is the record that managers were trained.
Psychosocial Hazards Are A Work Health And Safety Duty
Under the model work health and safety (WHS) laws, employers must manage risks to psychological health with the same rigour applied to physical health.
This is not new in principle, and it is no longer new in regulation either. It is in force across Australian jurisdictions, with some variation in how each state and territory has implemented it.
Hazards that must be identified and controlled include excessive workload, bullying and harassment, poor organisational change management, low role clarity, low job control, poor support, inadequate reward and recognition, and exposure to traumatic events or occupational violence.
Two things about this duty are commonly missed. The first is the hierarchy of control.
Regulation 36 requires elimination so far as is reasonably practicable, and only then substitution, isolation and engineering controls, with administrative controls and personal protective equipment last. Applied to psychosocial risk, that means an employee assistance program is an administrative control at the bottom of the hierarchy.
It supports people experiencing harm. It does not reduce the workload causing it, and a regulator will ask what was done higher up.
The second is that the duty extends to remote and hybrid arrangements. Your WHS duty of care does not stop at the office door, and hybrid arrangements do not dilute it.
See Safe Work Australia’s guidance on psychosocial hazards for the current model framework.
| Psychosocial hazard | What it looks like in practice | A control higher than an employee assistance programme |
|---|---|---|
| 1. Excessive workload | Sustained overtime, unfilled vacancies absorbed by the team, deadlines set without capacity checks | Reduce or redistribute the demand, resource the vacancy, change the deadline. Elimination or substitution, not support |
| 2. Low role clarity | Employees unsure who decides, overlapping responsibilities after a restructure | Documented role statements and a decision-rights map. An administrative control, but a targeted one |
| 3. Poor organisational change management | Restructures announced without consultation, repeated changes of direction | A consultation process with recorded steps, and a change impact assessment before announcement |
| 4. Bullying and harassment | Repeated unreasonable behaviour, or a single serious incident | Behavioural standards enforced consistently, with investigation records that show consistency |
| 5. Low job control | No say over how or when work is done, rigid monitoring of remote staff | Give discretion where the work allows it, and review monitoring against what it is actually for |
| 6. Exposure to traumatic events or occupational violence | Client aggression, distressing content, lone work | Design the exposure out where possible, then physical and procedural controls, then support |
The question that exposes most organisations
Where in your risk register is workload recorded as a hazard, with a control, an owner and a review date? In most registers it appears nowhere, because it is treated as a management issue rather than a safety one. That is the gap.
Privacy: A New Right To Sue, And A Code Still Coming
A statutory tort for serious invasions of privacy commenced on 10 June 2025.
It gives individuals a direct avenue to seek redress in the courts, and it is broader in application than the Privacy Act itself, extending to individuals and entities that are not Australian Privacy Principle entities.
The Office of the Australian Information Commissioner does not administer it. That is the significant part. An organisation can now face a privacy claim brought by a person directly, without a regulator deciding to act.
Of all the recent regulatory compliance changes, this one most alters the risk calculation for employee data.
Surveillance, monitoring of remote workers, handling of health information in return-to-work matters and disclosure during workplace investigations all become areas where an individual has a route that did not previously exist.
Civil penalties under the Privacy Act for serious or repeated interference with privacy are tiered and substantial.
Because the figures are indexed and the tiers were restructured, confirm the current amounts with the Office of the Australian Information Commissioner rather than relying on a number quoted in an article, including this one.
Notifiable data breach obligations are unchanged in structure. An eligible data breach must be assessed and, where serious harm is likely, notified to affected individuals and the Commissioner.
The practical control is a documented data breach assessment process with a named owner, because the 30-day assessment window is difficult to meet from a standing start.
Most organisations discover during a real data breach that nobody had agreed who makes the serious harm call.
CPS 230, And Why It Matters Even If APRA Does Not Regulate You
Prudential Standard CPS 230 Operational Risk Management commenced on 1 July 2025.
It applies to APRA-regulated banking, insurance and superannuation entities. It requires those entities to identify their critical operations, set tolerance levels for disruption, maintain a register of material service providers, and test business continuity against realistic scenarios.
Regulated entities had until the earlier of 1 July 2026 or the next renewal date to bring existing material service provider agreements into line, so that transition period has also now closed.
Regulatory compliance changes reach organisations indirectly as well as directly. If APRA does not regulate you, CPS 230 still reaches you through the supply chain.
A bank, insurer or superannuation fund that relies on your service has to assess and document you as part of its own operational risk obligations.
That flows down as due diligence questionnaires, contractual terms around notification and continuity, and requests for evidence of your controls.
Organisations that cannot produce a risk register, an incident history and a tested business continuity plan are increasingly being screened out at procurement rather than at contract.
The requirement is not yours, but the commercial consequence is.
Regulatory Compliance Changes Still Ahead
Two regulatory compliance changes remain forward-looking rather than in force. Both are worth diarising.
| What | When | Who it affects |
|---|---|---|
| Children’s Online Privacy Code | In place by 10 December 2026 | Online services likely to be accessed by children, including apps, games and websites, and services primarily concerned with children’s activities |
| Mandatory climate reporting, Group 3 | Financial years starting 1 July 2027 | Two of: revenue $50m or more, gross assets $25m or more, 100 or more employees |
The Children’s Online Privacy Code is an Australian Privacy Principle code developed by the Office of the Australian Information Commissioner.
It sets out how covered services must comply with the Australian Privacy Principles and adds requirements for handling children’s personal information.
If your organisation runs any service a child might plausibly use, this is the item to watch.
Group 3 climate reporting is the threshold that captures genuinely mid-sized Australian businesses.
At $50 million revenue or 100 employees, a large number of organisations that have treated climate disclosure as a big-company problem come into scope.
The lead time looks generous. It is not, because the first report needs a full year of collected data behind it.
Cyber risk deserves naming separately, because it is where the workforce shifts and the regulatory compliance changes meet. A hybrid workforce widens the cyber attack surface.
The statutory privacy tort gives an individual a route to act after a cyber incident. Notifiable data breach obligations require assessment within a fixed window.
And a cyber incident at a service provider is exactly the disruption CPS 230 asks regulated entities to plan for.
One cyber event can therefore trigger a privacy claim, a notification obligation and a contractual continuity failure at the same time.
That is why cyber belongs in the enterprise risk register rather than only on the information technology roadmap.
The Workforce Shifts Driving These Regulatory Compliance Changes
Regulatory compliance changes do not arrive in isolation. Four workforce shifts are changing where risk sits, and each interacts with the obligations above.
Workforce risk and regulatory risk are now the same conversation, which is why workforce planning belongs in the risk register rather than beside it.
Skills shortages and talent risk
Skills shortages persist across the compliance, cybersecurity and governance workforce, and specialist capability remains difficult to hire.
Where a skills shortage bites, workforce risk becomes compliance risk within a quarter. Where that capability is thin, organisations struggle to interpret regulatory requirements correctly, monitor compliance, investigate and respond quickly to incidents, and keep policies and controls current.
Leadership turnover compounds it. When experienced managers leave, corporate knowledge leaves with them, and where responsibilities were never documented, accountability becomes unclear at exactly the moment it matters.
The controls are ordinary: define risk and compliance responsibilities in writing, document key processes, cross-train where possible, deliver regular training on regulatory obligations and record who completed it, and hold a succession plan for critical roles.
A skills shortage in a compliance team is a risk register entry, not just a recruitment problem.
The test is simple. If your compliance or risk manager resigned tomorrow, is there a documented transition plan, or does the knowledge walk out with them?
Hybrid work and remote risk exposure
Hybrid and remote arrangements are now standard across much of the Australian workforce.
They improve engagement for many employees and they also increase cybersecurity exposure, reduce visibility over workplace behaviour, complicate the management of psychosocial hazards, and make policy application inconsistent.
WHS duties extend to the remote and hybrid work environment.
Reasonable steps include remote work risk assessments, ergonomic guidance, monitoring of workload and wellbeing, and making sure employees understand how to report a hazard or incident when they are not physically present to mention it to anyone.
Cybersecurity sits alongside it. Remote and hybrid access widens the cyber attack surface, and with the privacy tort now available to individuals, a breach involving employee data carries a route to redress that did not exist two years ago.
AI, automation and ethical governance
Artificial intelligence and automation now appear in recruitment, performance management, customer service and data analysis.
The risks are bias in automated decision-making, lack of transparency in outputs, privacy and cybersecurity exposure from the data used, and unclear accountability for decisions.
Recruitment is the sharpest case, because an automated screening tool that disadvantages a protected attribute creates discrimination exposure, and the organisation deploying it is accountable whether or not it built it.
The governance expectations are documented approval before implementation, a risk assessment covering the decision the tool influences, ongoing monitoring of outcomes rather than a single pre-deployment check, and a named accountable owner. A tool that no one owns is a tool no one is monitoring.
Culture, conduct and psychological safety
Culture and conduct risk have moved from a reputational concern to a regulated one, particularly through the positive duty to eliminate sexual harassment and the psychosocial hazard duties described above.
The controls are that codes of conduct are current, communicated through training and understood, reporting channels are accessible and genuinely confidential, whistleblower protections are understood by the people who might rely on them, and investigations are handled consistently and fairly.
Consistency of conduct handling is where organisations most often fail, and it is a culture signal as much as a process one.
Two similar conduct complaints handled differently, with no documented reason, is the pattern that turns a manageable incident into a systemic finding.
Conduct records are governance evidence, and an incident register that omits conduct matters is incomplete.
Building A Framework That Absorbs Regulatory Compliance Changes
Chasing each obligation separately is what makes regulatory compliance changes feel relentless.
The organisations that cope are not the ones with more compliance staff. They are the ones whose risk framework has somewhere to put a new obligation when it arrives.
Integrate compliance with enterprise risk management
Compliance obligations managed on a separate spreadsheet from enterprise risk will drift, because nothing forces the two to reconcile.
An integrated approach needs a documented risk management policy, a centralised risk register, clearly defined risk categories, assigned risk owners, and regular reporting to senior management and the board.
An enterprise risk management framework gives each new obligation a home. When a new duty appears, it becomes a risk with an owner and a control rather than a project with a deadline.
Boards carry this. Under an enterprise risk management (ERM) framework, the board is accountable for oversight of material risks, and every obligation on this page is now a material risk for someone.
Practical board-level governance means a standing risk item on the agenda, a register the board actually sees rather than a summary of it, and a named executive owner for each regulatory obligation.
Where ERM is mature, new obligations are absorbed. Where governance is thin, each one becomes a separate crisis.
Run scenarios rather than checklists
A checklist confirms a control exists. A scenario test confirms whether it works, which is why scenario planning has become a standard board expectation rather than an audit nicety.
Take a plausible event and walk it through: a significant data breach, a workplace misconduct allegation, a regulatory investigation, or a disruption to a critical service provider that tests your business continuity plan.
For each scenario, ask what controls are currently in place, who would be responsible for managing the response, how quickly you could access the relevant documentation, and how and when the board would be informed.
Run the scenario as a timed exercise rather than a discussion, because governance gaps show up in the delay, not in the intent.
The third question is usually the one that fails, and it fails quietly until the day it matters.
Strengthen governance and accountability
Good governance starts with documenting who owns each risk category, who monitors controls, who reports to the board and how often risks are reviewed.
Without that, ERM becomes a document rather than a practice. Then verify the operating layer underneath: that policies are current, that training is delivered, recorded and refreshed on a cycle, that incidents are investigated and closed, and that corrective actions are actually implemented rather than logged.
A policy management system that records which version of a policy each employee acknowledged, and when, is the difference between asserting that someone was informed and proving it.
Use technology for risk intelligence
Manual processes fail at the point where evidence is required. Software earns its place by maintaining a central risk register, tracking incidents, near misses and investigations, managing policy updates and acknowledgements, monitoring compliance tasks, and providing reporting for the board.
The value is not the automation. It is that the training record, the incident record and the policy acknowledgement are created as a by-product of doing the work, rather than reconstructed afterwards under audit pressure.
See implementing risk management software for how that transition typically runs.
Make it cross-functional
Every workforce and regulatory obligation on this page crosses departmental lines. Climate reporting needs finance and operations.
Wage compliance needs payroll, human resources and legal. The privacy tort needs information technology and human resources.
Psychosocial risk needs human resources and safety, and the controls sit with operational managers.
Where human resources, legal, information technology, finance, operations and executive leadership each hold a fragment, no one holds the picture.
Naming a single accountable owner per obligation, with a standing forum to reconcile, is the cheapest structural fix available.
| Obligation | Primary owner | Needs input from | The evidence a regulator or auditor asks for |
|---|---|---|---|
| Climate and sustainability reporting | Chief financial officer | Operations, procurement, company secretary | Board minutes showing climate risk oversight, and the data lineage behind the metrics |
| Wage compliance | Payroll | Human resources, legal | Award and classification review records, with dates and outcomes |
| Right to disconnect | Human resources | Operational managers | A documented position, and evidence managers were trained on it |
| Psychosocial hazards | Work health and safety | Human resources, operational managers | Register entries with hazard, control, owner and review date |
| Privacy and data breach response | Information technology | Human resources, legal | A documented assessment process, and the assessment record for any actual breach |
| Service provider continuity | Procurement | Information technology, finance | A register of material providers, and a tested continuity plan |
A 90-Day Catch-Up Plan For Regulatory Compliance Changes
If several of these regulatory compliance changes are new to you, the priority is not a transformation programme. It is establishing where you actually stand, in a form you could show someone.
| Weeks | Focus | What you should hold at the end |
|---|---|---|
| 1 to 2 | Scope. Work through the commencement table and mark each item as captures us, does not capture us, or unsure. Resolve every unsure against the regulator’s own guidance. | A one-page position on which obligations apply, with a reason recorded for each, ready for the board |
| 3 to 6 | Evidence. For each applicable obligation, find the document that would prove compliance. Policy, risk register entry, training record, incident record, board minute, contract clause. | A gap list naming what exists, what is out of date, and what does not exist |
| 7 to 10 | Fix the highest-consequence gaps first. Award and classification review, psychosocial hazards recorded in the register with owners, out-of-hours contact position, data breach response process. | Documented controls with named owners and review dates, not draft intentions |
| 11 to 13 | Report and embed. Take the position and the gap list to the board or executive so the regulatory compliance changes are on the record. Set review cycles so this does not need repeating from scratch. | Board awareness on the record, governance rhythm agreed, and standing review dates set |
Where to start if you only do one thing
The award and classification review. Intentional underpayment is the only item on this page carrying criminal exposure, the errors are usually systemic rather than isolated, and the protections available to employers reward those who find problems themselves.
Where This Leaves Your Risk Management Framework
None of the regulatory compliance changes on this page asks an Australian organisation to do something it has never done.
They ask it to prove things it may already be doing. Wage decisions, hazard controls, board oversight, training delivery, incident investigation and service provider continuity are all ordinary management activities.
What has changed is that each now has to leave a record.
That is why the response belongs in risk management rather than in a compliance project.
A compliance project ends. A risk management framework absorbs the next obligation without a new programme of work, because the register, the owners, the governance rhythm and the board reporting line already exist.
Organisations with mature risk management practices experienced the last two years as an update. Organisations without them experienced it as six separate emergencies.
The workforce dimension is what makes this different from earlier waves of regulation.
Wage compliance, the right to disconnect, psychosocial hazards, conduct and the governance of automated decisions are all workforce obligations.
They sit with human resources and operational managers, not with a central compliance function, which means training and communication are controls in their own right rather than support activities.
The single question to take to your next board meeting
If a regulator asked today which of these obligations apply to us, who owns each one, and where the evidence sits, how long would it take to answer? An organisation with governance in place answers in a meeting. One without it answers in a month, and the gap between those two is the risk.
Frequently Asked Questions
1. What are the biggest regulatory compliance changes facing Australian businesses right now?
Among the regulatory compliance changes now in force, the sharpest are criminal exposure for intentional wage underpayment, which commenced 1 January 2025, and psychosocial hazard duties under work health and safety law, because both apply to every employer regardless of size or industry. Mandatory climate reporting carries larger reporting burdens but reaches fewer organisations. The privacy tort, in force since 10 June 2025, creates a route for individuals to bring claims directly without a regulator being involved.
2. How should organisations prepare for mandatory climate and sustainability disclosures?
Start by confirming which group captures you, using the revenue, gross assets and employee thresholds, remembering that two of three must be met. Then treat it as a governance exercise first. Establish who oversees climate risk, how it enters the risk register, and how it reaches the board. Begin collecting emissions data early, including from suppliers, because Scope 3 becomes mandatory in the second reporting year and supplier data takes time to obtain.
3. Does the right to disconnect apply to small businesses?
Yes. It applied to employers with 15 or more employees from 26 August 2024 and extended to small business employers from 26 August 2025. No size exemption remains. It covers contact from third parties such as clients, not only from the employer.
4. What workforce changes create the highest compliance risk?
Role changes without a corresponding classification review, which is the most common source of systemic underpayment. Hybrid arrangements, because work health and safety duties extend to the home and psychosocial hazards are harder to observe. And the adoption of automated decision-making tools in recruitment and performance management, where accountability is often undefined.
5. How does CPS 230 affect a business that APRA does not regulate?
Through procurement. APRA-regulated entities must identify and assess material service providers as part of their own operational risk obligations, so suppliers face due diligence questionnaires, contractual notification and continuity terms, and requests for evidence of controls. Organisations that cannot produce a risk register, an incident history and a tested business continuity plan are increasingly screened out before contract stage.
6. What is the statutory tort for serious invasion of privacy?
A cause of action that commenced on 10 June 2025 allowing an individual to bring a claim in court for a serious invasion of their privacy. It is broader than the Privacy Act, extending to entities that are not Australian Privacy Principle entities, and the Office of the Australian Information Commissioner does not administer it. The practical effect is that a claim can proceed without a regulator deciding to act.
7. Are psychosocial hazard duties actually enforceable, or are they guidance?
They are enforceable duties under work health and safety law, not guidance. Employers must identify psychosocial hazards and control them applying the hierarchy of control, which means eliminating the hazard so far as is reasonably practicable before relying on administrative controls. An employee assistance program is an administrative control and will not, on its own, satisfy the duty where the underlying hazard could have been reduced.
8. How often should we review our risk register against regulatory compliance changes?
Quarterly as a baseline, and on event triggers rather than only on the calendar, with regulatory compliance changes tracked as one of those triggers. The model work health and safety regulations require review when a new hazard is identified, when a control is not effective, when a notifiable incident occurs, before a change at the workplace, or when a health and safety representative requests it. The commencement dates of new regulatory compliance changes should be treated the same way, which means a named owner tracking them rather than an annual sweep.
Sources
- ASIC, Who must prepare a sustainability report
- ASIC Regulatory Guide 280, Sustainability reporting, Table 2
- Fair Work Ombudsman, Criminalising wage underpayments and other issues
- Fair Work Ombudsman, Right to disconnect
- APRA, Prudential Standard CPS 230 Operational Risk Management
- OAIC, Statutory tort for serious invasions of privacy
- OAIC, Children’s Online Privacy Code
- Safe Work Australia, Psychosocial hazards
- Work Health and Safety Regulations 2011 (Cth), regulation 36, Hierarchy of control
Read more
- Risk management: the complete guide for Australian businesses
- 9 HR Compliance Areas Costing Australian Businesses In 2026 And Beyond
- Enterprise risk management framework
- How to build an effective risk management strategy
- Mastering risk management
- Continuous risk monitoring
- Policy management system
- GRC and ESG reporting
- Cultural risk management
- Implementing risk management software
- Psychological health and safety training in the workplace
Disclaimer: This article is general information, not legal advice. Commencement dates, thresholds and obligations described here were checked against the responsible regulator in August 2026 and can change. Requirements also vary between states and territories and by industry. Confirm your position with the relevant regulator or a qualified adviser before acting.
