Mackay Chapman Regulatory Roundup September 2026

9 September 2026
Regulation

Welcome to our regulatory roundup, bringing together key developments across Australia’s regulatory landscape.

This month’s developments point to a familiar theme: regulators are becoming more active in identifying risk, testing compliance frameworks and intervening where they believe controls are not working.

ASIC is signalling continued scrutiny of managed investments and financial markets. APRA has imposed licence conditions over persistent risk management failures. AUSTRAC is taking direct action against AML/CTF compliance failures and using industry-wide data to identify potential mortgage fraud. And the ATO continues to pursue deliberate tax fraud through criminal enforcement.

For regulated businesses, advisers, managers and other professionals, the direction is clear. Governance, compliance systems and the ability to identify and respond to risk are receiving increasingly close attention.

ASIC signals more scrutiny and enforcement

ASIC has released its Corporate Plan for 2026–27, setting out its priorities under new Chair Sarah Court.

For advisers, fund managers, responsible entities and other regulated businesses, the message is fairly clear: expect more scrutiny and continued enforcement.

ASIC says it wants to be easier to deal with for businesses seeking to comply with the law, while making it harder for those causing harm to avoid regulatory attention.

Managed investment schemes will receive increased supervision, while ASIC will continue its focus on market integrity across both public and private markets. That is particularly relevant given the regulator’s increasing attention to private credit, investment governance and risks to investors.

Artificial intelligence will also receive greater scrutiny, including how it is used by financial institutions and the potential for AI-driven manipulation, deepfakes and misinformation to affect investors and financial markets.

At the same time, ASIC says it wants to reduce unnecessary regulatory burden through simpler guidance, better digital services and more efficient licensing processes.

But simpler interaction with the regulator should not be mistaken for a lighter enforcement approach.

ASIC has made clear that it intends to continue using its supervisory and enforcement powers where it identifies serious misconduct or emerging risks. For regulated businesses, governance, disclosure, licensing and the effectiveness of compliance systems are likely to remain firmly under the microscope.

ATO 

Four sentenced over $10.7 million tax fraud scheme

Four people have been sentenced for their roles in a $10.7 million tax fraud and money laundering scheme involving labour hire and payroll companies linked to the building and construction industry.

The sentences follow Operation Bordelon, a joint investigation involving the ATO and Australian Federal Police.

The scheme operated between July 2018 and July 2020 and involved PAYG withholding amounts from labour hire services being diverted rather than remitted to the ATO. Funds were transferred to companies controlled by other syndicate members, relatives and associates, as well as offshore.

The case demonstrates the increasingly coordinated approach being taken to suspected tax fraud, particularly where corporate structures, related entities and movement of funds are used to conceal conduct.

For directors and businesses operating through complex group or labour hire arrangements, transactions that may attract regulatory scrutiny are unlikely to be considered solely as tax compliance issues. Serious cases can involve financial crime investigations, proceeds of crime issues and criminal prosecution.

Operation Protego convictions continue

The ATO has announced another four sentencing outcomes under Operation Protego, its large-scale investigation into GST fraud.

The four individuals were sentenced in July and August after fraudulently obtaining more than $500,000 through illegitimate GST claims.

The conduct involved registering ABNs, creating fake businesses and lodging false business activity statements to obtain GST refunds.

As at 30 June 2026, 178 people had been convicted through Operation Protego, while the ATO had applied compliance treatment to more than 57,000 alleged offenders.

The scale of the operation is a reminder of the ATO’s increasing ability to identify patterns across large volumes of data and pursue conduct well beyond an individual transaction or taxpayer.

Where the ATO identifies deliberate fraud rather than an error or ordinary compliance issue, criminal investigation, prosecution, debt recovery and penalties are all available.

APRA 

Persistent compliance failures lead to licence conditions

APRA has imposed licence conditions on Bendigo and Adelaide Bank following findings of longstanding and pervasive weaknesses in the bank’s non-financial risk management framework.

The action followed an independent root cause analysis required by APRA in December 2025.

That review identified material weaknesses across governance, accountability, compliance management, risk oversight and the bank’s understanding of its regulatory obligations, material risks and key controls.

Importantly, APRA said the weaknesses had persisted despite several years of remediation activity.

The licence conditions require Bendigo Bank to undertake a comprehensive rectification program, engage an independent assurer and provide board attestation as part of that work. APRA will also retain the bank’s existing $50 million operational risk capital add-on until it is satisfied that the underlying prudential concerns have been addressed.

The action is significant beyond Bendigo Bank.

Regulators are increasingly looking not only at whether an organisation has policies, remediation programs or compliance frameworks in place, but whether those systems are actually working.

For boards and senior management, repeated control failures or remediation programs that do not produce sustainable improvement can ultimately result in direct regulatory intervention.

AUSTRAC 

AUSTRAC suspends Cryptolink registration

AUSTRAC has suspended Cryptolink Pty Ltd’s registration for three months over ongoing concerns about its compliance with anti-money laundering and counter-terrorism financing obligations.

Cryptolink operates a network of 96 cryptocurrency ATMs across Australia, all of which must remain offline during the suspension.

AUSTRAC had previously accepted an enforceable undertaking from Cryptolink in October 2025 after identifying alleged AML/CTF breaches, including late threshold transaction reporting and weaknesses in its risk assessments.

Although Cryptolink met the conditions of that undertaking, AUSTRAC said it subsequently failed to meet basic reporting obligations, particularly threshold transaction reporting, and failed to respond to a request for information.

The escalation from an enforceable undertaking to suspension is important.

It demonstrates that remediation does not end regulatory scrutiny. Where further compliance failures emerge, AUSTRAC can escalate its response and directly restrict a business’s ability to operate.

That is particularly relevant as Australia’s AML/CTF regime expands and more businesses come within AUSTRAC’s regulatory perimeter.

Mortgage fraud findings put intermediaries in focus

AUSTRAC’s Fintel Alliance has identified coordinated mortgage fraud and systemic weaknesses across Australia’s lending sector following analysis involving 10 major Australian banks.

Operation Claw identified potentially hundreds of millions of dollars in suspected fraudulent loans, mostly linked to properties in Sydney.

The suspected conduct included inflated incomes, misrepresented employment and fabricated or unverifiable business activity used to support loan applications. AUSTRAC also identified cases involving offshore or third-party funds being used to complete settlements and make mortgage repayments.

Of particular interest for professional advisers and intermediaries, recurring warning signs included falsified or misleading documents and the repeated use of particular mortgage brokers, accountants and law firms across multiple loan applications.

That does not establish wrongdoing by those intermediaries. However, it demonstrates the extent to which regulators and financial institutions can now identify recurring patterns across transactions, organisations and professional networks.

Names of individuals and entities potentially involved in submitting false documents have been provided to regulators and law enforcement agencies, including ASIC, the ATO and Tax Practitioners Board.

AUSTRAC said the project did not identify evidence of widespread money laundering, but warned that the weaknesses it uncovered could be exploited for criminal purposes.

Lenders have been urged to review their mortgage books, strengthen fraud controls and report suspicious activity.

For brokers, accountants, advisers, lawyers and others involved in lending transactions, the broader message is also important. Where suspicious activity or recurring patterns emerge, regulatory scrutiny may extend beyond the borrower to the professionals and intermediaries involved in the transaction.

Regulatory scrutiny continues to increase

Taken together, these developments show regulators taking an increasingly proactive approach.

ASIC is strengthening supervision and signalling continued enforcement. APRA is intervening where remediation has failed to address persistent control weaknesses. AUSTRAC is combining financial intelligence across institutions to identify patterns that may not be visible in individual transactions. And the ATO continues to pursue serious non-compliance through coordinated investigations and criminal prosecutions.

For businesses and professionals having policies and procedures on paper is no longer enough.

Regulators increasingly expect businesses to be able to demonstrate that their governance, risk and compliance systems work in practice, that identified problems are actually addressed and that emerging risks are escalated and managed early.

Where deficiencies are identified, early advice and remediation can be important before regulatory scrutiny develops into investigation or enforcement action.

The contents of this update do not constitute legal advice, are not intended to be a substitute for legal advice, and should not be relied upon as such. They are designed and intended as general information in summary form, current at publication, for general informational purposes only. You should seek legal or other professional advice concerning any particular legal matters you or your organisation may have.