Legal development

Financial Services Snapshots

Abstract digital wave visualisation with glowing cyan and teal light particles on a dark background, representing digital data flow and connectivity.

    Financial Markets

    ASIC reminds AFS licensees of strict DDO obligations associated with high risk products

    In its August Market Integrity Update, ASIC reinforced that AFS licensees offering high-risk or complex products to retail clients have strict DDO obligations and must maintain effective product governance arrangements, including ensuring that products are only distributed to consumers in appropriately defined target markets.

    The warning comes following ASIC's surveillance of nine licensees offering short-dated exchange-traded options, futures and fractional share products. ASIC identified weaknesses in:

    • target market determinations;
    • onboarding;
    • client monitoring;
    • disclosure; and
    • client asset arrangements.

    Given the complexity and high risk of exchange-traded options and futures, ASIC encourages licensees to narrowly define their target markets and maintain effective distribution arrangements.

    See: Market Integrity Update

    Banking

    AUSTRAC uncovers coordinated mortgage fraud across major lenders

    On 19 August 2026, AUSTRAC announced that its Fintel Alliance had uncovered coordinated mortgage fraud and systemic weaknesses across Australia's lending sector.

    A joint analysis of data from 10 major Australian banks identified potentially hundreds of millions of dollars in suspected fraudulent loans, mostly linked to properties in Sydney.

    Recurring warning signs include falsified or misleading documents and repeated use of mortgage brokers, accountants and law firms across multiple applications.

    AUSTRAC has urged mortgage lenders to examine their loan books for signs of fraud, report suspicious activity and strengthen controls to prevent and detect mortgage fraud of this nature.

    See: Media Release

    Superannuation

    APRA to strengthen superannuation investment governance

    On 19 August 2026, APRA announced plans to strengthen superannuation investment governance alongside the Government's proposed compensation scheme for superannuation members who suffer significant losses because trustees have failed to meet their obligations.

    Under the proposal, APRA would set capital requirements for trustees offering higher-risk investment options and consult on the framework's detailed design after the relevant legislation is finalised.

    APRA intends to consult on the detailed design of the framework once the Government has finalised the relevant legislation. A first round of consultation is expected to commence in September.

    See: Media Release

    Other

    ASIC warns against scammers impersonating ASIC staff in email phishing

    On 17 August 2026, ASIC issued a warning that scammers are targeting personnel of market operators and financial businesses by impersonating ASIC staff in email spear-phishing scams.

    ASIC warns the financial services industry to treat unexpected ASIC emails and requests with caution and to verify communications through official ASIC channels before responding, opening links or attachments, or providing information.

    Appropriate staff awareness and internal controls should be maintained.

    See: Media release

    ASIC provides insight on new director ID requirements

    On 24 August 2026, ASIC announced that companies and directors should prepare for new requirements commencing on 1 July 2027. From that date, companies will need to provide director IDs to ASIC through company reporting processes, including annual reviews and notifications of changes to director details.

    ASIC encourages companies and directors to check that company details are up to date, confirm all current directors are correctly recorded, update incorrect names, addresses or contact details, and compare ASIC records with ABRS records.

    Directors can review and update their director ID details through the ABRS Manage your director ID service.

    ASIC will provide further guidance before 1 July 2027.

    See: Media Release

    ASIC withdraws financial reporting relief for uncontactable members

    On 25 August 2026, ASIC announced that it has withdrawn financial reporting relief for uncontactable members. The change follows ASIC's consultation on the proposal to withdraw the relief on 5 June 2026.

    The instrument, ASIC Corporations (Uncontactable Members) Instrument 2016/187 (Instrument 2016/187) was due to expire on 1 October 2026.

    ASIC assessed that Instrument 2016/187 was no longer being used because amendments to the Corporations Act now provide similar relief. Specifically:

    • section 110JA provides relief from sending certain documents, including annual reports, where a member is uncontactable; and
    • section 110F(4A) addresses situations where there is no current address for sending documents in an elected manner.

    Entities not covered by the Corporations Act relief may need to seek individual relief from ASIC under ASIC Regulatory Guide 43. Affected entities should review their reporting and member-contact processes.

    See: Media Release, Instrument 2016/187, Consultation Paper

    APRA-ASIC Industry Roundtables on AI risks

    On 27 August 2026, APRA and ASIC published key insights from nine industry roundtables on preparedness and resilience for frontier AI risks.

    The regulators warned that awareness of frontier AI risks must now translate into practical action, testing and measurable resilience outcomes. APRA and ASIC expect entities to demonstrate that their governance processes, key decision-making arrangements, escalation authority, recovery priorities and communication strategies can operate at the speed required by emerging frontier AI threats.

    The key message was that the industry must move from awareness to action by demonstrating practical implementation, testing and measurable resilience outcomes.

    Key themes included:

    • Strengthening cyber fundamentals;
    • Establishing effective governance and escalation arrangements;
    • Managing defensive AI carefully;
    • Understanding shared third party dependencies; and
    • Improving industry collaboration.

    Entities should assess whether their existing controls and response arrangements are effective in practice, including through appropriate testing and assurance.

    See: Media Release

    Authors: Jonathan Gordon, Partner; Corey McHattan, Partner; Samantha Carroll, Partner; Hong-Viet Nguyen, Partner; Deuchar Allen, Lawyer and Charlotte Ekins, Graduate.

    The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
    Readers should take legal advice before applying it to specific issues or transactions.