Compliance is the work a business does to meet the laws, licence conditions and industry rules that apply to it, and to prove it has.
Also known as: regulatory compliance, compliance obligations
Key points
- Compliance covers licensing, disclosure, record keeping, training and conduct, not just paperwork filed once a year.
- In consumer lending the central framework is the NCCP Act, administered by ASIC.
- Anyone arranging consumer credit must hold or act under an Australian credit licence.
- Responsible lending obligations sit at the centre of day to day compliance for brokers and lenders.
- Getting it wrong can mean licence conditions, penalties, customer remediation or losing the right to write finance.
How compliance works
Compliance starts with knowing which rules bite. A finance business normally sits under credit law, corporations law, privacy law and anti-money laundering law at the same time, and each brings its own duties. The obligations are written into policies, then built into the way staff actually work.
The second half is evidence. Regulators expect records that show what was assessed, what was disclosed and when, which is why a credit guide is issued upfront and why files are kept for years. Monitoring, staff training and an audit trail turn intention into something you can demonstrate.
Compliance in Australian finance
Australian finance has several regulators with different jobs. ASIC oversees credit licensing and conduct, APRA sets prudential regulation for banks, insurers and super funds, AUSTRAC supervises anti-money laundering reporting, and the OAIC handles the Privacy Act.
Layered on top are duties such as the best interests duty for mortgage brokers, design and distribution obligations, and the rules on unfair contract terms. Most finance businesses map these into a single compliance calendar rather than treating them separately.
Who is responsible
Responsibility sits with the licensee and its directors, even where work is outsourced to authorised credit representatives, aggregators or referrers. A licensee has to supervise its representatives, keep them trained and act when something goes wrong.
In practice, compliance is shared. Front line staff follow process and document their reasoning, managers check the work, and a compliance function sets policy, runs monitoring and reports breaches to the regulator within the required time. Small brokerages often buy this support in rather than build it.
Not to be confused with
- Self-regulation
- self-regulation is industry set standards, compliance covers what the law and the regulator require
- Ethics
- ethics is about what a business should do, compliance is about what the rules oblige it to do
Frequently asked questions
What does compliance mean in business?
It means running the business so that it meets the laws, licence conditions and industry codes that apply to it, and keeping records that prove it. In finance that covers licensing, disclosure, lending conduct, privacy, anti-money laundering reporting, staff training and complaint handling.
Why is compliance important?
Because the consequences land on the business. Breaches can bring penalties, licence conditions, remediation costs and reputational damage, and lenders and aggregators check compliance history before they take someone on. Good compliance also protects customers, which is the point of the rules in the first place.
Who regulates compliance in Australian finance?
Several bodies share the work. ASIC covers credit licensing and conduct, APRA sets prudential standards for banks, insurers and super funds, AUSTRAC oversees anti-money laundering and counter-terrorism financing reporting, and the OAIC handles privacy. The ACCC deals with competition and consumer law issues.
What happens if a business is not compliant?
Outcomes range from a warning or extra licence conditions through to infringement notices, court penalties, banning orders for individuals and licence cancellation. Businesses are often required to remediate affected customers as well, which usually costs far more than the fix would have.
What is the difference between compliance and risk management?
Compliance asks whether the business is meeting its legal and licence obligations. Risk management is broader: it identifies anything that could damage the business, including credit, operational, technology and reputational risk. Compliance failure is one of the risks a risk framework is meant to catch.
Related terms
NCCP Act
The NCCP Act is Australia's National Consumer Credit Protection Act 2009, the law that licenses credit providers and brokers and sets responsible lending and disclosure rules for consumer credit.
Read definitionResponsible lending obligations
Responsible lending obligations are duties under the NCCP Act that require lenders and brokers to inquire into and verify a consumer's finances and not provide or suggest unsuitable credit.
Read definitionASIC
ASIC is the Australian Securities and Investments Commission, the regulator for companies, markets, financial services and consumer credit, which licenses providers, keeps public registers and enforces conduct laws.
Read definitionAustralian credit licence (ACL)
An Australian credit licence (ACL) is the authorisation from ASIC that a business needs to provide consumer credit or credit assistance under the National Consumer Credit Protection Act.
Read definitionAnti-money laundering (AML)
Anti-money laundering (AML) is the set of laws, controls and processes designed to stop criminals turning the proceeds of crime into apparently legitimate funds, enforced in Australia by AUSTRAC.
Read definitionBest interests duty
The best interests duty is a statutory obligation requiring financial advisers giving personal advice and mortgage brokers arranging credit to put the customer's interests first.
Read definitionGo deeper
Sources
This article is general information only and is not financial advice.