Logo

Australia's 2026 Regulatory Calendar for Software Buyers

  1. Nabeel Al Nassir

  2. August 4, 2026

  3. 5 Min read

pixbit solutions

Updated 28 September 2026

Australia's 2026–27 compliance calendar changes what regulated businesses need from their software. Reformed AML/CTF obligations started for existing reporting entities on 31 March 2026 and for lawyers, accountants and real estate agents on 1 July 2026. APRA's CPS 230 contract deadline fell on 1 July 2026. Privacy Act automated-decision disclosures start on 10 December 2026, and most Scams Prevention Framework obligations apply from 31 March 2027.

Australia's 2026–27 Regulatory Calendar

DateRegulationWho's AffectedWhat Software Must Do
1 Jul 2025 (in force)CPS 230 Operational Risk Management commences (APRA)APRA-regulated banks, insurers and superannuation trusteesMap critical operations, set tolerance levels, manage material service providers and test business continuity.
1 Nov 2025 (in force)Aged Care Act 2024 and Support at Home commenceRegistered aged care providersSupport new service agreements, care plans, Support at Home budgets and quality standards evidence.
10 Nov 2025 (in force)NDIA provider portals move to myID and RAMRegistered NDIS providers and their staffMap staff access to myID identity strength and RAM authorisations.
31 Mar 2026Reformed AML/CTF obligations commence (AUSTRAC)Existing reporting entities, including banks, remitters and virtual asset providersUpdate customer due diligence, AML/CTF program and reporting workflows to the reformed rules.
1 Jul 2026AML/CTF Tranche 2 commences (AUSTRAC)Lawyers, accountants, trust and company service providers, real estate professionals, and dealers in precious metals and stones providing designated servicesCustomer due diligence, beneficial ownership, risk assessment, monitoring, suspicious matter reporting, audit logging and record retention.
1 Jul 2026CPS 230 deadline for pre-existing service provider contracts (APRA)APRA-regulated entities and their material service providersContract terms, incident notification, continuity testing and exit arrangements that meet CPS 230.
1 Jul 2026Mandatory climate reporting: Group 2 beginsEntities in the second reporting cohort (Group 1 began with financial years starting 1 Jan 2025)Collect, govern and retain climate-related data with audit trails.
1 Jul 2026AFCA becomes the dispute scheme for scam complaintsBanks, telcos and digital platforms regulated under the Scams Prevention FrameworkPrepare complaint handling and evidence retention for AFCA.
29 Jul 2026AUSTRAC enrolment deadline for Tranche 2 entitiesBusinesses newly regulated from 1 July 2026Record regulatory status, designated services and compliance officer details.
1 Sep 2026Scams Prevention Framework: AFCA membership requiredBanks, telcos and digital platforms providing regulated servicesMembership is an organisational step; case records must be ready to support complaints.
10 Dec 2026Privacy Act automated-decision disclosures (APP 1.7–1.9)Organisations covered by the Privacy ActRecord which systems use personal information to make significant decisions so privacy policies can disclose them. The OAIC must also register the Children's Online Privacy Code by this date.
31 Mar 2027Scams Prevention Framework: most obligations applyRegulated banks, telcos and digital platformsScam prevention, detection, disruption, reporting and response, with evidence for each.
1 Jul 2027Mandatory climate reporting: Group 3 beginsEntities in the third reporting cohortExtend climate data collection and reporting to the new cohort.

AML/CTF Tranche 2: The Biggest Software Change of 2026

Among all Australian regulatory changes arriving in 2026, AUSTRAC's AML/CTF Tranche 2 reforms are likely to have the broadest impact on commercial software. Rather than introducing entirely new compliance concepts, the reforms extend Australia's existing Anti-Money Laundering and Counter-Terrorism Financing regime to industries that have historically operated outside it. For many professional services firms, this is the first time customer onboarding, identity verification, risk assessment, transaction monitoring and regulatory reporting have become part of day-to-day operations.

The reforms arrived in two steps. On 31 March 2026, the reformed obligations began for businesses that were already reporting entities, such as banks, remitters and virtual asset providers. On 1 July 2026, newly regulated entities followed, including legal practices, accounting firms, trust and company service providers, real estate professionals involved in designated transactions, and dealers in precious stones and metals. Businesses newly regulated from 1 July had until 29 July 2026 to enrol with AUSTRAC. The legislation applies to businesses, but putting it into practice almost always depends on software.

This changes procurement priorities for organisations buying new systems.

Client relationship platforms, onboarding portals, document management systems, payment platforms and internal administration software increasingly need compliance features that were not considered when they were bought. Identity verification, beneficial ownership capture, politically exposed person (PEP) screening, sanctions screening, customer risk scoring, record retention, audit logging and suspicious matter reporting are becoming functional requirements rather than optional extensions. For identity verification specifically, our myID digital identity integration guide covers how Australian software connects to the government's digital identity system.

The shift also affects organisations replacing legacy systems.

Many professional firms have run separate compliance tools alongside practice management software. Under Tranche 2, integrating compliance into operational workflows usually works better than keeping disconnected systems that need duplicate data entry and manual reconciliation. Every additional manual process increases the chance of inconsistent records and extra work during a regulatory review.

Software architecture therefore becomes part of compliance planning.

Applications that treat customer onboarding as a single form submission may need redesigning to handle ongoing customer due diligence, periodic reviews, document refresh cycles, beneficial ownership updates and risk reassessment over time. These capabilities need to run alongside existing business workflows rather than interrupt them. Real estate agencies feel this sharply, because Tranche 2 now sits on top of state-based trust accounting and licensing rules.

For software buyers, the question is no longer only whether a platform can manage clients or transactions. It is whether the system can produce the evidence needed to show compliance during an AUSTRAC review while remaining usable for operational teams.

Our AML/CTF Tranche 2 software requirements guide covers customer due diligence, monitoring, suspicious matter reporting and recordkeeping in more technical depth.

Privacy Act × AML/CTF: The Collision Most Buyers Miss

One of the easiest mistakes Australian software buyers can make is treating the Privacy Act reforms and AML/CTF Tranche 2 as separate compliance projects. In practice they often affect the same customer records, the same onboarding workflows and the same data architecture decisions.

AML/CTF obligations require organisations to collect and verify identity information, assess customer risk, monitor ongoing relationships, retain records and keep evidence for regulatory review. The Privacy and Other Legislation Amendment Act 2024 adds new transparency duties. From 10 December 2026, APP 1.7 to 1.9 require privacy policies to disclose the kinds of personal information used, and the kinds of decisions made, when a computer program uses personal information to make decisions that could significantly affect a person's rights or interests. Many businesses will therefore need to collect more customer information for compliance purposes and, at the same time, explain more clearly how automated processes use it.

This creates architectural tension rather than a simple checklist.

An onboarding workflow built only for AML requirements may capture the necessary identification documents, beneficial ownership details and risk indicators, yet still fall short on the new disclosure duty if the organisation cannot say which automated risk scores or screening rules affect customers. Conversely, a privacy-first design that minimises collection may not keep enough evidence to meet AUSTRAC recordkeeping obligations.

The intersection matters most for organisations automating workflows.

Risk scoring engines, identity verification services, sanctions screening, fraud detection models and customer segmentation increasingly process personal information automatically. Under the amended Privacy Act, organisations need an accurate inventory of those automated processes and the decisions they feed, so the privacy policy can describe them correctly.

For software buyers, this means compliance architecture should be designed once rather than retrofitted twice.

Identity verification, consent management, audit logging, document retention, access controls and reporting should sit inside one governed data model rather than being built separately by different teams. Applications that split compliance across disconnected systems create duplication and make regulatory evidence harder to produce later.

Scams Prevention Framework: 31 March 2027 Is the Date That Matters

While AML/CTF governs how organisations know their customers, the Scams Prevention Framework (SPF) governs how regulated businesses stop scams reaching customers through their systems. It goes beyond traditional fraud monitoring into customer protection, scam detection and coordination across organisations.

The Scams Prevention Framework Act 2025 names banking, telecommunications and digital platforms as the first regulated sectors, and the government formally designated those sectors in May 2026. Two dates have already passed: AFCA became the dispute resolution scheme for scam complaints on 1 July 2026, and regulated entities had to be AFCA members from 1 September 2026. Most obligations to prevent, detect, disrupt, report and respond to scams apply from 31 March 2027, under sector codes that Treasury released as exposure drafts on 28 May 2026.

From a developer's point of view, the SPF is less about a single feature and more about operational capability.

Platforms need ways to identify suspicious activity, escalate potential scam events, retain evidence, support investigations, warn affected users and show that reasonable controls were operating when an incident occurred. These capabilities usually span authentication systems, transaction monitoring, messaging tools, customer service platforms and internal case management.

What makes the SPF unusual is that it sits where fraud, cybersecurity, customer experience and regulation meet.

A scam warning shown to a customer, an account restriction triggered by suspicious behaviour, a complaint investigation and a regulator-ready audit trail may all depend on the same underlying event data. Organisations that treat these as separate departmental systems often struggle to reconstruct what actually happened during a scam incident.

Buyers evaluating platforms before March 2027 should therefore ask different questions than they would of a traditional fraud tool. Can the system link customer interactions, authentication events, payment activity and investigation outcomes into one case record? Can evidence be retained for AFCA complaints? Can operational teams show which controls were active at the time of an incident? These questions become pressing as SPF obligations move from exposure drafts into daily operations.

CPS 230: Operational Resilience Becomes a Software Procurement Issue

While the AML/CTF reforms mainly affect customer-facing processes, APRA Prudential Standard CPS 230 is about how regulated financial institutions keep operating when systems, suppliers or critical business services fail. The standard commenced on 1 July 2025. Contracts with service providers that existed before then had to comply by the earlier of their next renewal or 1 July 2026, so that deadline has now passed.

The standard applies directly to APRA-regulated banks, insurers and superannuation trustees, but its effect reaches further. Any software vendor delivering a critical service to an APRA-regulated customer becomes part of that customer's operational resilience obligations.

This changes how software is evaluated.

Procurement used to focus on functionality, delivery timelines and commercial terms. Under CPS 230, regulated organisations also need to understand how vendors manage operational risk, business continuity, incident response, subcontractors, disaster recovery and service restoration. These questions are no longer reserved for enterprise procurement teams; they are part of regulatory compliance.

For software architecture, resilience becomes a measurable capability rather than an infrastructure preference.

Applications supporting critical operations should produce detailed audit logs, document their service dependencies, support disaster recovery planning, state recovery objectives where appropriate, and provide monitoring that shows availability during incidents. Vendor documentation becomes as important as the application, because regulated organisations need evidence that outsourced technology can keep critical services running.

For software buyers, CPS 230 is less about buying a resilient application than choosing a technology partner that can support operational resilience across the whole software lifecycle.

Climate Reporting: Group 2 Began on 1 July 2026

Mandatory climate-related financial disclosure is being phased in by cohort under the Corporations Act and the AASB S2 standard. Group 1 began with financial years starting on or after 1 January 2025, Group 2 began on 1 July 2026, and Group 3 begins on 1 July 2027.

For software, the challenge is data governance more than calculation. Emissions data, energy use, supplier information and climate risk assessments often sit in spreadsheets spread across operations, finance and facilities teams. Reporting entities need that data collected consistently, with clear ownership, version history and an audit trail that assurance providers can follow. Systems that already hold operational data, such as facility management, fleet and procurement platforms, are often the right place to capture it at source rather than rebuilding it at year end.

Digital Health and My Health Record Interoperability

Healthcare organisations face a different kind of regulatory challenge. Rather than financial crime or operational resilience, Australian digital health policy centres on secure information sharing, clinical interoperability and consistent patient records across the health system.

The Australian Digital Health Agency (ADHA) runs My Health Record and continues to expand interoperability work around it, which makes system integration a growing consideration for healthcare software buyers. Hospitals, specialist clinics, allied health providers, diagnostic services and their software vendors are increasingly expected to design systems that exchange information accurately while maintaining appropriate privacy, security and clinical governance.

This makes interoperability an architectural decision rather than simply an integration project.

Clinical software regularly interacts with electronic medical record systems, diagnostic platforms, referral networks, appointment scheduling, patient portals, identity services and government digital health infrastructure. Every additional connection raises the importance of consistent data models, secure authentication, auditability and standards-based information exchange.

Unlike ordinary application integrations, healthcare interoperability directly affects clinical work. Delayed pathology results, incomplete referral information, duplicate patient records or inconsistent medication histories create inefficiency and extra administration. Software needs to exchange information reliably while keeping the audit trails and access controls expected across Australian healthcare.

Organisations replacing clinical systems should evaluate interoperability alongside functional requirements rather than leaving integration to a later phase.

NDIS and Aged Care: Identity and Service Model Changes

Two care sectors have also changed what their software has to do. The Aged Care Act 2024 commenced on 1 November 2025 alongside the Support at Home program, which replaced Home Care Packages. Providers have had to update service agreements, care plans, budget management and quality standards evidence, and many older care management systems were built around the previous package model.

In disability services, the NDIA moved its provider portals to myID and the Relationship Authorisation Manager (RAM) from 10 November 2025. Provider software now has to reflect who in the business is authorised to act, at what identity strength, and keep that aligned with its own user roles. For providers delivering both NDIS and aged care services, one platform that handles rostering, worker records, claiming and compliance evidence across both schemes avoids running two parallel systems.

What's Next, but Not Yet Designated

Australia's regulatory calendar does not end with the obligations that have confirmed dates. Several sectors could come within existing frameworks over time, which makes them watch-items for organisations making software investments now.

The most closely watched is the possible expansion of the Scams Prevention Framework beyond banking, telecommunications and digital platforms. The Act allows further sectors to be designated later, and two are discussed most often.

The first is superannuation. Super funds handle a large volume of digital member interactions, account changes, identity checks and payment instructions, all of which attract sophisticated scam activity. If SPF obligations extend to this sector, software supporting member services, authentication, fraud detection, payment approvals and member communications would need further governance and monitoring capability.

The second is digital asset and cryptocurrency exchanges. These providers already operate under AUSTRAC registration and AML/CTF obligations. Future inclusion in the SPF would add another operational layer around transaction monitoring, customer warnings, account intervention, evidence retention and coordinated fraud response.

For now, these sectors should be treated as possible future policy rather than confirmed deadlines.

Organisations planning long-term platform investments can benefit from compliance architecture flexible enough to take on additional regulatory workflows without major redevelopment. Identity management, event logging, audit trails, notification engines, investigation workflows and configurable governance controls adapt to new regulation far more easily than point solutions built around a single obligation.

The practical lesson for software buyers is straightforward: build for adaptability where possible, but prioritise confirmed deadlines over anticipated ones.

2026–27 Compliance Summary

DateRegulationWhat Software Must Do
1 Jul 2025CPS 230 commences (APRA)Operational resilience, service provider governance, continuity testing.
1 Nov 2025Aged Care Act 2024 and Support at HomeService agreements, care plans, budgets, quality evidence.
10 Nov 2025NDIA portals move to myID and RAMStaff identity strength and RAM authorisations mapped to app roles.
31 Mar 2026Reformed AML/CTF obligations for existing reporting entitiesUpdated due diligence, program and reporting workflows.
1 Jul 2026AML/CTF Tranche 2 (AUSTRAC)Identity verification, beneficial ownership, monitoring, SMRs, audit logging.
1 Jul 2026CPS 230 pre-existing contract deadlineCompliant contracts, incident notice, exit arrangements.
1 Jul 2026Climate reporting Group 2Governed climate data with audit trails.
1 Jul 2026AFCA dispute scheme for SPF complaintsComplaint handling and evidence retention.
29 Jul 2026AUSTRAC enrolment deadline (Tranche 2)Regulatory status and compliance officer records.
1 Sep 2026SPF: AFCA membership requiredCase records ready to support complaints.
10 Dec 2026Privacy Act APP 1.7–1.9Inventory of automated decisions using personal information.
31 Mar 2027SPF: most obligations applyPrevent, detect, disrupt, report and respond, with evidence.
1 Jul 2027Climate reporting Group 3Extend reporting to the third cohort.

Frequently Asked Questions

Which Australian regulations affect business software in 2026 and 2027?

The main ones are AML/CTF Tranche 2 (from 1 July 2026), APRA's CPS 230 (in force since 1 July 2025, with a 1 July 2026 contract deadline), the Privacy Act automated-decision disclosures (from 10 December 2026), the Scams Prevention Framework (most obligations from 31 March 2027) and mandatory climate reporting, which is being phased in by cohort.

When does AML/CTF Tranche 2 start affecting Australian professional services firms?

AUSTRAC's expanded AML/CTF obligations commenced on 1 July 2026 for designated services provided by lawyers, accountants, trust and company service providers, real estate professionals, and dealers in precious metals and stones. Businesses newly regulated from that date had until 29 July 2026 to enrol with AUSTRAC.

When does the Scams Prevention Framework start?

The Scams Prevention Framework Act 2025 is already law. Regulated banks, telcos and digital platforms had to join AFCA from 1 September 2026, and most obligations to prevent, detect, disrupt, report and respond to scams apply from 31 March 2027.

Does CPS 230 apply to my software vendor if I'm not APRA-regulated myself?

CPS 230 applies directly only to APRA-regulated entities. However, software vendors that support those entities' critical operations may need to show operational resilience, governance and service continuity, because their customers must meet CPS 230 through their service provider arrangements.

What's the difference between the Privacy Act reforms and AML/CTF Tranche 2 obligations?

The Privacy Act reforms, overseen by the OAIC, focus on how organisations handle personal information and, from 10 December 2026, on disclosing automated decisions that significantly affect people. AML/CTF Tranche 2, administered by AUSTRAC, focuses on customer identification, financial crime prevention, transaction monitoring and regulatory reporting.

Will superannuation funds and crypto exchanges be added to the Scams Prevention Framework?

No commencement dates have been announced for these sectors. The Act allows further sectors to be designated in future, so organisations in these industries should keep monitoring developments rather than assume immediate obligations.

Plan Your Software Around the Whole Calendar

Australia's 2026–27 compliance calendar is unusual because several unrelated reforms land within the same eighteen months. Organisations replacing or commissioning software in this period often find that AML/CTF, privacy, operational resilience, scam prevention and interoperability requirements overlap far more than expected once work begins.

Rather than assessing each regulation separately, it is usually more practical to map business processes against the full timeline before the software architecture is fixed. That lets compliance requirements go into one delivery programme instead of several retrofit projects over the following year.

Investment depends on how many of these frameworks apply and how much of the existing system can be extended, from a targeted compliance layer at the lower end to a new platform at the higher end. If your organisation is planning software that will operate under any of these frameworks, Pixbit scopes in a single discovery session.


Nabeel Al Nassir
Author
Nabeel Al Nassir

Digital Marketer

Share on

https://pixbitsolutions.com/au/blogs/au-2026-regulatory-calendar-software-buyers
Have an idea that needs to go mobile? Launch it with us!

Have an idea that needs to go mobile? Launch it with us!

Let's Talk
Contact Us

Have an idea ?

Let's make it happen

Tell us your business aspirations, and let's craft a custom solution that drives business growth, ensuring satisfaction and exceeding your goals with precision.

Let's Talk