6 Compliance Deadlines Hitting Australian SMEs in Late 2026 (and How to Stay Ahead)

Late 2026 is bringing several important compliance dates for Australian small and medium-sized businesses.
Some changes apply broadly to companies. Others only affect particular industries, such as accounting, legal, conveyancing and real estate businesses. The key is to understand which obligations apply to your business, record the relevant dates and allow enough time to prepare.
Here are six compliance deadlines and changes to have on your radar.
1. AML/CTF obligations began on 1 July 2026
Australia’s anti-money laundering and counter-terrorism financing reforms expanded the regulated sector from 1 July 2026.
The new obligations affect businesses that provide certain designated services, including some:
- Accountants and accounting practices
- Lawyers and legal practices
- Conveyancers
- Real estate professionals
- Trust and company service providers
- Dealers in precious metals and stones
Being in one of these professions does not automatically mean every service is covered. The question is whether your business provides a designated service under the reforms. For example, this may include assisting with certain property transactions or the creation, restructuring or transfer of companies, trusts or other legal arrangements.
Businesses providing covered services must generally have processes for:
- Customer identification and verification
- Beneficial ownership checks
- Risk assessment
- Ongoing customer due diligence
- Suspicious matter reporting
- Record-keeping
- Staff training
- AML/CTF governance and oversight
The formal enrolment deadline is generally within 28 days of starting to provide a designated service. For businesses that started on 1 July 2026, the typical enrolment date was 29 July 2026. However, AUSTRAC expected businesses to be operationally ready from 1 July, not simply enrolled by the later date.
The AUSTRAC Tranche 2 factsheet explains the obligations in more detail.
What to do now
If your business may be covered:
- Confirm which of your services are designated services.
- Check your AUSTRAC enrolment status.
- Complete a documented money laundering and terrorism financing risk assessment.
- Prepare or update your AML/CTF program.
- Appoint a responsible compliance officer.
- Review your customer onboarding and verification process.
- Check that your record-keeping is secure and privacy-conscious.
The OAIC’s AML/CTF privacy guidance also highlights an important point: businesses should not retain full copies of identity documents for AML/CTF record-keeping unless another law requires it.

2. Privacy reform consultation closes on 18 September 2026
On 31 August 2026, the Australian Government released an exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026.
The proposed reforms include stronger privacy protections and changes relating to emerging technologies, personal information and data security.
One proposal that has attracted particular attention is a potential 72-hour deadline for notifying the OAIC of an eligible data breach. The proposal would also require notification to affected individuals at the same time where practicable.
This is not yet a current legal requirement. The exposure draft remains subject to consultation and further consideration. Businesses should not treat the proposed 72-hour period as enacted law unless and until the legislation is passed and commenced.
Public submissions on the exposure draft close on 18 September 2026. Businesses that handle significant amounts of personal information, use automated systems or are concerned about practical implementation may wish to review the materials.
You can read the Attorney-General’s Department consultation information and the exposure draft legislation.
What to do now
Even though the 72-hour proposal is not currently law, it is a useful prompt to test your data breach response process.
Check whether your business can:
- Identify a suspected breach quickly
- Contain unauthorised access
- Escalate the issue to the right decision-maker
- Assess whether personal information is affected
- Record what happened and what was done
- Notify the OAIC and affected people when required
- Manage communications with customers and suppliers
A breach response plan that depends on one person knowing what to do is not a reliable plan. Make sure responsibilities, contact details and escalation steps are documented.
3. Automated decision-making disclosures begin on 10 December 2026
From 10 December 2026, new privacy transparency requirements will apply to many organisations covered by the Australian Privacy Principles.
The requirements relate to the use of a computer program to make, or substantially and directly assist with, a decision that could significantly affect an individual’s rights or interests.
This may include automated systems used for decisions involving:
- Access to services
- Applications or eligibility
- Risk scoring
- Identity verification
- Fraud detection
- Customer prioritisation
- Credit or payment decisions
The term “computer program” is broad. It can include artificial intelligence, machine learning, automated scoring tools and traditional rule-based systems.
Where the requirements apply, an organisation’s privacy policy will need to describe, at a high level:
- The types of personal information used
- The kinds of decisions made solely by computer programs
- The kinds of decisions substantially and directly shaped by computer programs
This does not mean every business using software will need to disclose every automated workflow. The focus is on automated decision-making involving personal information and decisions that could significantly affect individuals.
The OAIC’s APP 1 guidance provides further information.
What to do now
Create a simple register of systems that use personal information to make or support decisions.
For each system, record:
- What the system does
- What personal information it uses
- Whether a human reviews the outcome
- Who is affected by the decision
- Whether the decision could significantly affect a person
- Which privacy policy wording may be required
Do not assume that a system is outside scope simply because a staff member clicks “approve” at the end. A computer program may still be substantially and directly influencing the outcome.
4. ASIC annual review fees are due according to your company’s review date
There is no single national ASIC annual review date for all companies.
Your company’s annual review date is generally linked to the anniversary of its registration. ASIC sends an annual statement around that time. The statement includes:
- Your annual review date
- The annual review fee
- Company details held by ASIC
- Payment instructions
The annual review fee is usually due within two months after the annual review date, or by the date shown on the annual statement.
For 2026–27, ASIC lists the annual fee for a standard proprietary company as $342. A special-purpose proprietary company fee is listed as $70. Fees can change, so check the amount shown on your statement or ASIC’s current fee information.
At the annual review, your company should:
- Pay the annual review fee.
- Check company details and update anything incorrect.
- Pass the required solvency resolution.
If the fee is paid late, additional fees may apply. ASIC may also take steps towards deregistration if a company does not meet its obligations.
Read ASIC’s company annual review guidance and current company fees.
What to do now
Find your company’s ASIC annual review date and add these reminders to your calendar:
- One month before the review date
- The review date
- The fee due date, usually two months after the review date
- A director review of company details
- The solvency resolution deadline

5. Company changes must generally be reported to ASIC within 28 days
The annual review is not the only time your ASIC records should be checked.
Companies must generally notify ASIC of changes to company information within 28 days. This can include changes to:
- Registered office or business addresses
- Company officeholders
- Share structure
- Member or shareholder details
- Other information recorded on the companies register
Waiting until the annual review can result in late fees and inaccurate public records.
A practical control is to include ASIC notification in your internal change process. When a director, address, ownership structure or other company detail changes, assign someone responsibility for checking whether an ASIC lodgement is required.
ASIC’s changes to company details page provides further guidance.
6. Director IDs are already required, with new ASIC reporting from 1 July 2027
All company directors must have a director identification number, commonly called a director ID.
A director ID is:
- A unique 15-digit identifier
- Issued by the Australian Business Registry Services
- Held by the director permanently
- Used across companies and appointments
A person who plans to become a director must generally apply for a director ID before appointment. Existing directors who do not have one should apply now.
Director IDs are not currently recorded on the ASIC companies register. From 1 July 2027, companies will need to provide director IDs to ASIC through processes including annual reviews and notifications of director changes.
There is no separate director ID annual review deadline in late 2026. However, preparing now can make the transition easier.
Use the ASIC director ID guidance and the ABRS director ID service.
What to do now
- Confirm every current director has a director ID.
- Check that director names and details match across ASIC and ABRS records.
- Keep a secure internal record of director IDs.
- Make sure new directors apply before appointment.
- Review your process for notifying ASIC of director changes.
Your late-2026 compliance reset checklist
Before the end of 2026, consider whether your business has:
- Confirmed whether AML/CTF Tranche 2 obligations apply
- Enrolled with AUSTRAC where required
- Documented its AML/CTF risk assessment and program
- Reviewed identity-document retention practices
- Tested its data breach response process
- Reviewed privacy policy changes needed for automated decision-making
- Identified any systems using personal information for automated decisions
- Confirmed the next ASIC annual review date
- Paid any ASIC annual review fee by the due date
- Completed the required solvency resolution
- Updated ASIC records within the required timeframes
- Confirmed all directors hold a valid director ID
Compliance is easier to manage when it is treated as a business process rather than a last-minute response to a deadline. A simple compliance calendar, clear ownership and periodic reviews can help reduce missed obligations and avoidable costs.
Integrated Risk & Compliance helps Australian SMEs understand and manage risk, compliance and governance obligations in a practical way. If you are unsure which requirements apply to your business, we can help you identify the gaps and prioritise the next steps.
General information only: This article is not legal, financial or accounting advice. Compliance requirements can depend on your business structure, activities and circumstances. Seek professional advice about your specific situation. Current as at 10 September 2026.
