Quick Answer:
The compliance risks in Australia that changed in 2026 are led by two that both commenced on 1 July 2026: Payday Super, which requires employers to pay superannuation at the same time as salary and wages, and AML/CTF Tranche 2, which brings lawyers, accountants, conveyancers, real estate professionals and precious metals dealers under AUSTRAC regulation for the first time. Alongside those sit criminal liability for intentional wage underpayment, the first civil penalty handed down under the Privacy Act, an enforceable positive duty to prevent sexual harassment, and mandatory climate reporting expanding to more entities. The common thread is that obligations have moved from reactive to preventative, and from civil to criminal.
In this guide
- What changed on 1 July 2026
- What compliance risks are and why they matter
- 1. Payday Super and payroll accuracy
- 2. Wage underpayment as a criminal offence
- 3. Privacy and cyber security
- 4. AML/CTF Tranche 2
- 5. Climate and sustainability reporting
- 6. Workplace behaviour and the positive duty
- 7. Psychosocial hazards
- 8. AI, technology and digital obligations
- Penalties, enforcement and director liability
- Compliance risks in Australia by industry
- A 6-step roadmap
- What is coming next
- Frequently asked questions
Compliance in Australia changed shape in 2026, and it changed on a specific date.
Two significant reforms commenced on 1 July, one affecting every employer in the country and one bringing five professions under financial crime regulation for the first time.
This guide covers the compliance risks in Australia that matter now, what each one actually requires, and what a business should be able to produce if asked.
Every figure is sourced to a regulator or a decided case, and linked.
This guide covers federal obligations. Work health and safety duties vary between states and territories, and Victoria operates under separate legislation. Confirm your position with the relevant regulator.
What Changed On 1 July 2026
If you read nothing else, read this table. Both of these are in force now, not proposed.
| Change | Who it affects | What it requires |
|---|---|---|
| Payday Super | Every employer in Australia | Superannuation must be paid at the same time as salary and wages rather than quarterly. The guarantee is calculated as 12% of qualifying earnings, a new term bringing together ordinary time earnings and other payments |
| AML/CTF Tranche 2 | Legal professionals, accountants, conveyancers, real estate professionals, and dealers in precious metals, stones and products | New AUSTRAC obligations for designated services: enrolment, an AML/CTF programme, customer due diligence, and reporting |
Why these two together are a bigger shift than they look
Payday Super converts a quarterly reconciliation into a per-pay-cycle obligation, which means a payroll error that used to be caught and corrected within a quarter is now visible immediately and repeatedly. Tranche 2 brings five professions into a regime none of them has operated under before. AUSTRAC puts the cost of financial crime in Australia at up to $82 billion a year, which is the reason the scope widened.
What Compliance Risks Are And Why They Matter
A compliance risk is the exposure created when an organisation does not meet a legal or regulatory obligation. It is distinct from the underlying operational risk, and the difference matters.
Most compliance risks in Australia are not failures of intent, they are failures of evidence.
| Operational risk | Compliance risk | |
|---|---|---|
| What it is | Something goes wrong in the work | An obligation is not met, and cannot be shown to have been met |
| How it surfaces | An incident, a loss, a failure | An audit, a complaint, a regulator request, a claim |
| What reduces it | Better controls and processes | The same controls, plus the evidence that they operated |
| Why it is missed | It is visible | It is invisible until someone asks, and by then the record either exists or it does not |
That last row is the whole problem. Most Australian businesses are more compliant than they can prove.
The work is happening, the records are partial, and the gap only appears at the point it cannot be closed. Structuring that record is covered in audit-ready risk management.
1. Payday Super And Payroll Accuracy
From 1 July 2026 superannuation must be paid at the same time as salary and wages.
The Australian Taxation Office describes the guarantee as 12% of qualifying earnings, which is a new term bringing together ordinary time earnings and other payments.
| What changed | What it means in practice |
|---|---|
| Timing moved from quarterly to each payday | There is no longer a quarter in which to notice and correct an error before it is reportable |
| A new earnings base, qualifying earnings | Existing payroll configurations that were correct against ordinary time earnings may not be correct against the new base |
| Payment deadlines are tied to the pay event | Late payment is measured per pay cycle, so a single misconfiguration repeats every cycle rather than once a quarter |
Why this is a compliance risk and not just a payroll change
A quarterly obligation forgives a configuration error for up to three months. A per-payday obligation does not. The same underlying mistake now produces a repeated failure with a record attached to each one, and the remediation is proportionally larger by the time it is found.
2. Wage Underpayment As A Criminal Offence
Intentional underpayment of wages became a criminal offence from 1 January 2025. The Fair Work Ombudsman states that prosecution can result in monetary fines, prison time, or both.
Separately, maximum civil penalties increased from 27 February 2024.
For a non-small business employer, an underpayment penalty can be the greater of three times the value of the underpayment or the relevant penalty unit amount.
The distinction that matters
The criminal offence targets intentional conduct. Honest mistakes are treated differently, and the Fair Work Ombudsman has said so. What changes the risk profile is that the boundary between an error and an intentional act is drawn partly by what you did once you knew. A known underpayment that is not remediated is a different fact pattern from one that was found and fixed.
3. Privacy And Cyber Security
The Privacy Act stopped being theoretical in October 2025, when the Federal Court ordered Australian Clinical Labs to pay $5.8 million in civil penalties over the Medlab Pathology data breach.
It was the first civil penalty of its kind under the Act.
| Exposure | What it looks like |
|---|---|
| Serious or repeated interference with privacy | Penalties can reach the greater of a penalty unit amount, three times the benefit obtained, or 30% of adjusted turnover during the breach period |
| Notifiable data breaches | An obligation to assess and notify, with the notification itself causing reputational damage well before any regulatory outcome |
| Data held past its purpose | Old systems and spreadsheets holding personal information nobody has reviewed. This is the most common finding and the easiest to fix |
The turnover-linked penalty is the structural change. An exposure that scales with revenue grows with the business rather than being absorbed by it.
4. AML/CTF Tranche 2
From 1 July 2026, AUSTRAC regulates designated services commonly provided by five groups that have never been captured before.
- Legal professionals
- Accountants
- Conveyancers
- Real estate professionals
- Dealers in precious metals, stones and products
If you are in one of those groups, the obligations attach to the designated services you provide rather than to your profession as a whole, so the first question is which of your services are captured.
The core requirements are enrolment with AUSTRAC, an AML/CTF programme, customer due diligence, and reporting.
The trap for professional services firms
Most firms in these categories have strong client confidentiality practices and no financial crime programme, and the two are not the same thing. Knowing your client for relationship purposes is not customer due diligence in the regulatory sense, which has specified elements and a record requirement.
5. Climate And Sustainability Reporting
Entities required to prepare an annual financial report under Chapter 2M of the Corporations Act must also prepare a sustainability report if they meet one of the thresholds in section 292A. ASIC sets out three:
| Threshold | What it captures |
|---|---|
| Corporate size | Meeting two of three tests across consolidated revenue, consolidated gross assets, and employee numbers |
| Emissions | Being a registered corporation with reporting obligations under the National Greenhouse and Energy Reporting Act 2007 |
| Value of assets | Registered schemes, registrable superannuation entities and retail CCIVs above the asset threshold |
The report must contain climate-related financial information required under the Corporations Act and AASB S2 Climate-related disclosures, and it sits alongside the financial report, directors’ report and the auditor’s reports.
Check which threshold catches you, not whether you feel like a reporter
The three tests are independent. An organisation that does not meet the corporate size test can still be captured through emissions reporting or asset value. Several entities have discovered they are in scope through a threshold they were not watching. The reporting side of this is covered in ESG reporting and digital risk management.
6. Workplace Behaviour And The Positive Duty
The positive duty under the Sex Discrimination Act requires employers to take reasonable and proportionate measures to eliminate sexual harassment, sex discrimination and hostile workplace environments so far as possible.
The Australian Human Rights Commission has power to enforce compliance with it.
Preventative, not reactive
This is the change most often misread. The duty is not triggered by a complaint. It requires measures to be in place beforehand, which means “nobody has complained” is not evidence of compliance. It is closer to the opposite: an organisation with no complaints and no preventative measures has a duty it cannot demonstrate it has met.
What a reasonable and proportionate measure looks like depends on your size and circumstances, and the elements that recur are policy, training with completion records, a reporting route people will actually use, and consistent enforcement.
The exposure this creates is set out in the 11 types of workplace harassment that put a business at risk.
7. Psychosocial Hazards
Safe Work Australia treats psychosocial hazards under the same framework as physical ones, with the same hierarchy of control and the same duty.
High job demands, low control, poor support, conflict, isolation and exposure to traumatic content are recognised hazards.
The compliance risk is specific and it is a records problem more often than a practice problem.
Organisations are doing wellbeing work and are not documenting it as risk management, so the control set exists in a human resources programme rather than a risk register.
The control set that does not move a rating
An employee assistance programme, a wellbeing survey and resilience training all help people cope with pressure. None of them reduces the demand creating it, so the residual rating should not move. Applying the hierarchy honestly makes the gap visible, which is covered in psychosocial hazards at work.
8. AI, Technology And Digital Obligations
This is the least settled area on the list and the one where the compliance risk is easiest to create accidentally.
Australia does not have a single AI statute. What applies instead is existing law, reaching AI use through privacy, discrimination, work health and safety, consumer protection and record-keeping obligations.
| Where AI creates exposure | The obligation it runs into |
|---|---|
| Recruitment and workforce screening tools | Discrimination law. A tool that produces a disparate outcome creates exposure regardless of intent, and the vendor’s assurance is not your defence |
| Personal information entered into third-party tools | Privacy obligations, including where the data goes and how long it is held |
| Automated decisions affecting workers | Consultation and procedural fairness obligations, which do not disappear because a system produced the recommendation |
| Records generated or summarised by AI | Record-keeping accuracy. A summarised record that is wrong is still your record |
The practical control
Know where AI is being used in your organisation, including tools individuals adopted without asking. Most organisations cannot answer that question, and it is the first thing an assessment needs. Naming the uses is cheap. Discovering them after an incident is not.
Penalties, Enforcement And Director Liability
Three shifts have changed what the compliance risks in Australia actually cost, and they compound.
| Shift | What it means |
|---|---|
| From civil to criminal | Intentional wage underpayment now carries fines, prison time, or both. Compliance failure can reach a person rather than only a balance sheet |
| From fixed ceilings to scaled penalties | Underpayment penalties can scale to three times the underpayment. Privacy penalties can reach 30% of adjusted turnover. Exposure grows with the organisation |
| From reactive to preventative | The positive duty and the psychosocial duty both require measures in advance. Waiting for a complaint is not a compliant position |
Officers carry a personal due diligence duty for work health and safety, which is a positive obligation covering knowledge, resourcing, incident information and verification.
It is not discharged by delegation. Where that duty sits relative to managers and supervisors is set out in what supervisors and managers must consider.
Compliance Risks In Australia By Industry
The compliance risks in Australia that bite first differ by sector, and it is rarely the one an organisation is watching.
| Sector | The compliance risk that bites first |
|---|---|
| Professional services (legal, accounting, conveyancing) | AML/CTF Tranche 2 from 1 July 2026. A regime none of these firms has operated under, with a programme and due diligence records required |
| Real estate | Tranche 2, plus the volume problem. High transaction counts mean due diligence has to be systematic from the start rather than retrofitted |
| Aged care, disability and health | Overlapping regulators, worker screening, and psychosocial exposure among the highest of any sector |
| Construction and trades | Work health and safety duties across a contractor chain that does not transfer with the contract, plus wage compliance across awards |
| Retail and hospitality | Award interpretation and payroll accuracy, now compounded by Payday Super making errors visible each cycle rather than each quarter |
| Not-for-profit | The same duties as commercial entities with a fraction of the infrastructure, and volunteers who are workers for work health and safety purposes |
The pattern across all six is that the obligation is not new to the law, it is new to the organisation.
That is a resourcing problem before it is a legal one, and it is the same structural issue described in the five common governance, risk and compliance challenges.
A 6-Step Roadmap
| Step | What to do | What you should hold at the end |
|---|---|---|
| 1. Confirm what applies to you | Work through the eight compliance risks in Australia above against your operations, size and sector. Do not assume size gives an exemption | A written list of applicable obligations, confirmed rather than assumed |
| 2. Name an owner for each | Every obligation gets a person, not a department | A list where every line has a name against it |
| 3. Find the evidence gaps | For each obligation, ask what you would produce if asked today | The gaps, written down, ranked by consequence |
| 4. Fix the records before the practice | In most organisations the work is happening and the proof is not being kept | Completion records, acknowledgements and decision records with dates |
| 5. Set review on triggers | Not an annual cycle. Legislative change, an incident, a new service line, a new system | A review that fires on events |
| 6. Report it upward | Officers cannot exercise due diligence on information they do not receive | Compliance reported alongside financial results |
Step 4 is where most of the return sits. It is also the cheapest, because it does not require changing how anyone works.
The wider version of this sequence is set out in the seven steps good businesses take to mitigate the risk of non-compliance.
What Is Coming Next
Two things worth watching rather than acting on today.
- Further privacy reform: The Privacy Act has been reformed in stages, and further tranches have been flagged. The direction of travel is clear even where the detail is not settled
- Sustainability reporting expanding down the size curve: The thresholds phase in over time, so entities outside scope today should confirm which reporting period first captures them rather than assuming they remain outside
The honest position on the pipeline
Proposed reform is a poor basis for spending. The better use of attention is the compliance risks in Australia that are already in force, and the evidence trail behind them. An organisation that can produce its records on demand absorbs the next change far more cheaply than one that cannot.
Know what you could produce if asked today
Sentrient keeps policies, training completions, acknowledgements, incident records, risk registers and decision records in one place, so the evidence behind each obligation already exists rather than being assembled after a request arrives.
Explore the workplace compliance system | Book a free demonstration
Frequently Asked Questions
1. What are the main compliance risks in Australia in 2026?
Eight areas carry most of the exposure: Payday Super and payroll accuracy, criminal liability for intentional wage underpayment, privacy and cyber security, AML/CTF Tranche 2, climate and sustainability reporting, workplace behaviour under the positive duty, psychosocial hazards, and AI and digital obligations. Two of these commenced on 1 July 2026: Payday Super, which affects every employer, and Tranche 2, which affects five professions.
2. What is Payday Super and when does it start?
From 1 July 2026, employers must pay superannuation at the same time as salary and wages rather than quarterly. The Australian Taxation Office calculates the guarantee as 12% of qualifying earnings, a new term bringing together ordinary time earnings and other payments. The compliance significance is that a payroll misconfiguration that used to be caught within a quarter now repeats every pay cycle with a record attached to each one.
3. Who does AML/CTF Tranche 2 apply to?
From 1 July 2026 AUSTRAC regulates designated services commonly provided by legal professionals, accountants, conveyancers, real estate professionals, and dealers in precious metals, stones and products. The obligations attach to the designated services provided rather than to the profession as a whole, so the first step is identifying which of your services are captured. Core requirements are enrolment, an AML/CTF programme, customer due diligence and reporting.
4. Is underpaying wages a criminal offence in Australia?
Intentional underpayment became a criminal offence from 1 January 2025, and the Fair Work Ombudsman states prosecution can result in monetary fines, prison time, or both. Honest mistakes are treated differently from intentional conduct. Maximum civil penalties also increased from 27 February 2024, and for a non-small business employer an underpayment penalty can be the greater of three times the underpayment or the relevant penalty unit amount.
5. What are the penalties for a privacy breach in Australia?
For serious or repeated interference with privacy, penalties can reach the greater of a penalty unit amount, three times the benefit obtained, or 30% of the organisation’s adjusted turnover during the breach period. In October 2025 the Federal Court ordered Australian Clinical Labs to pay $5.8 million over the Medlab Pathology data breach, the first civil penalty of its kind under the Privacy Act.
6. Does my business have to report on climate?
You must prepare a sustainability report if you are required to prepare an annual financial report under Chapter 2M of the Corporations Act and meet one of three thresholds in section 292A: a corporate size test, an emissions test tied to National Greenhouse and Energy Reporting obligations, or a value of assets test for registered schemes, registrable superannuation entities and retail CCIVs. The tests are independent, so check all three rather than only the size one.
7. Do compliance obligations apply differently to small businesses?
Some administrative requirements and penalty thresholds differ for small business employers, and the underlying duties largely do not. The primary work health and safety duty applies to a business or undertaking of any size, and the positive duty under the Sex Discrimination Act applies to all employers. Payday Super applies to every employer. Confirm your specific position rather than assuming size provides an exemption.
8. What should we do first if we are behind?
Confirm in writing which obligations apply to you, then name an owner for each. Those two steps cost nothing and surface most of the problem. After that, work on evidence rather than practice: in most organisations the work is already happening and the records are partial, which is the gap that actually fails an audit.
Sources
- Australian Taxation Office – About Payday Super
- Australian Taxation Office – Payment deadlines for Payday Super
- AUSTRAC – Newly regulated businesses: get ready for the reforms
- AUSTRAC – Professional designated services
- Fair Work Ombudsman – Criminalising wage underpayments and other issues
- OAIC – Australian Clinical Labs ordered to pay penalties, a first for the Privacy Act
- OAIC – Civil penalties: serious or repeated interference with privacy
- Australian Human Rights Commission – The positive duty in the Sex Discrimination Act
- Australian Human Rights Commission – Positive duty: compliance and enforcement
- ASIC – Who must prepare a sustainability report?
- ASIC – Sustainability reporting
- Safe Work Australia – Psychosocial hazards
- Safe Work Australia – Duties under WHS laws
- SafeWork NSW – Due diligence
Read more
- The 7 steps to mitigate the risk of non-compliance
- Risk management: the complete Australian guide
- Audit-ready risk management
- Psychosocial hazards at work
- 5 common governance, risk and compliance challenges
Disclaimer: This article is general information, not legal advice. Australian compliance obligations change frequently, vary between states and territories, and depend on your circumstances. Confirm your obligations with the relevant regulator or a qualified adviser before acting.
