1510

New Financial Year, New Compliance Load: The FY27 Checklist for Collections Teams

8 July, 2026

New Financial Year, New Compliance Load: The FY27 Checklist for Collections Teams

Most compliance calendars mark 1 July as a formality. A new set of numbers, a new budget cycle, business as usual.

Not this year. Three regulatory clocks hit zero on the same date. CPS 230’s toughest requirements land for every remaining APRA-regulated entity. APRA’s targeted amendments to CPS 230 take effect for material service provider arrangements. And ASIC’s 2026 enforcement priorities, set back in November, are well underway, with hardship and vulnerable consumers named as a specific target.

None of this is a single big-bang deadline you can put in the diary and forget. It’s a stack. And for collections operations specifically, it’s a stack that lands directly on how you manage vendors, hardship cases, and the paper trail behind both.

Here’s what actually changed, what’s landing when, and what it means for your FY27 planning.

Key Takeaways

  • CPS 230’s full business continuity and scenario analysis requirements now apply to every APRA-regulated entity, including non-significant financial institutions that had until 1 July 2026 to catch up
  • APRA’s targeted amendments to CPS 230 and CPG 230 also commence 1 July 2026, with a refreshed Material Service Provider Register template
  • ASIC’s 2026 enforcement priorities include a new focus on misconduct exploiting consumers facing financial difficulty, including predatory credit practices, alongside a new focus on private credit
  • ASIC and APRA announced FAR simplification in June 2026, removing the Key Functions reporting requirement rather than adding to it, a genuine reduction in admin load
  • APRA’s new debt-to-income lending cap, active since February 2026, is reshaping how much high-leverage lending flows through the system, with knock-on effects for collections pipelines over time
  • ASIC has doubled its investigations and nearly doubled new Federal Court matters over the past year. The regulator’s enforcement appetite is not slowing down
  • None of this requires a bigger compliance team. It requires knowing which of these actually touches your operation and closing the gap before someone else finds it

 

Why This Financial Year Is Different

CPS 230 came into force on 1 July 2025. If you read the CPS 230 coverage at the time, or our own blog on the topic, you’ll remember the standard’s central idea: operational resilience isn’t optional, and boards are accountable for it in a way they weren’t before.

What didn’t get as much attention is the transition schedule. Significant financial institutions had to be compliant from day one. Everyone else, the non-SFIs, had a full year of runway on the business continuity and scenario analysis requirements specifically. That runway ends on 1 July 2026.

On top of that, APRA finalised targeted amendments to CPS 230 and CPG 230 on 30 April 2026, also commencing 1 July 2026. The amendments create limited exemptions from specific contractual requirements for arrangements with non-traditional service providers, government agencies, regulators, central banks, and financial market infrastructure providers, where bespoke contract terms aren’t realistically negotiable. Useful if it applies to you. Irrelevant if it doesn’t. Either way, the updated Material Service Provider Register template needs to be used for this year’s submission.

So this isn’t a single deadline. It’s the same date carrying three separate obligations for different parts of the regulated population. Worth checking which ones actually apply to your entity before assuming any of them, or none of them, do.

 

ASIC’s Enforcement Priorities Have a Collections-Shaped Target

ASIC set its 2026 enforcement priorities in November 2025, and they’ve had several months to start showing up in practice.

The enduring priorities are the same as always: misconduct that damages market integrity, systemic failures at large institutions, and conduct affecting financially vulnerable consumers. But the new priorities for 2026 sharpen the focus in ways that matter directly for collections. ASIC Commissioner Alan Kirkland has been explicit that lending and credit conduct causing foreseeable risk of financial hardship is a live enforcement target, not a background consideration.

Private credit is the other new addition. Australia’s private credit sector has grown past $200 billion, and ASIC has flagged it will pursue misconduct in that space without hesitation. If your organisation touches private credit lending or services private credit portfolios, that’s a new line of regulatory attention that wasn’t there a year ago.

The numbers behind these priorities are worth sitting with. ASIC doubled its investigations and nearly doubled new Federal Court matters over the past year. This is a regulator that’s demonstrably following through on its stated priorities, not just publishing them.

What This Looks Like in Practice

To illustrate, not as a real case: imagine a specialist lender’s collections team has an automated prioritisation model that scores overdue accounts for contact intensity. The model doesn’t know when a customer is in hardship until a hardship notice is formally lodged, so accounts get chased at full intensity right up to that point. Under ASIC’s current enforcement posture, that gap between what a system could reasonably flag and what it waits for is the kind of conduct question likely to draw scrutiny. The fix isn’t a bigger compliance team. It’s a model that can surface early hardship indicators, missed payment patterns, contact attempts, customer language, before the formal notice lands, with a documented reason for any change in contact intensity.

 

FAR Is Getting Simpler, Not Stricter

There’s a persistent assumption that every regulatory update adds weight. The Financial Accountability Regime changes ASIC and APRA announced on 16 June 2026 go the other way.

The regulators are proposing to remove the Key Functions reporting requirement from the FAR rules entirely, raise the materiality threshold for notifying changes in accountability, and stop requiring information on accountable persons’ direct reports in accountability maps. Roughly 4,500 accountable people across the industry are expected to see reduced reporting as a result, and updates to accountability maps should at least halve.

If your organisation had been tracking collections and enforcement as a distinct FAR Key Function with a named accountable person, that specific requirement is on track to disappear, not tighten. That doesn’t mean accountability for collections conduct goes away. FAR’s core obligations around honesty, care, and diligence for accountable persons remain fully in place. It means the administrative overhead of proving it through Key Functions reporting is being scaled back.

Worth flagging to whoever owns your FAR reporting: this is a genuine easing, not a trap dressed up as good news. ASIC and APRA are consulting through the rest of 2026 with implementation targeted by year end, so nothing changes on 1 July itself. But it’s worth knowing it’s coming so you don’t over-invest in a requirement that’s being wound back.

 

The DTI Cap Is a Slower-Moving Story Worth Watching

APRA activated its debt-to-income lending limit on 1 February 2026, capping the share of new mortgage lending banks can write at a DTI of six times income or higher to 20% across owner-occupied and investor lending separately.

This one isn’t a collections compliance obligation. It’s a macroprudential lever aimed at housing credit growth and investor leverage. But it’s relevant context for anyone planning collections capacity over FY27. APRA’s own reasoning is that high-DTI lending, particularly to investors, has been building from a low base as rates have eased and prices have risen. The cap is designed to slow that build before it becomes a stability risk.

The practical read for collections leaders: this is a lever pulled early, precisely so it doesn’t need to be pulled hard later. It’s not a signal that a wave of distressed accounts is coming. It’s a signal that regulators are watching leverage more closely than they were twelve months ago, which tends to mean closer scrutiny of how the back end, collections and hardship handling, holds up if conditions do turn.

 

What Does This Mean for You?

If you’re already CPS 230 compliant as a significant financial institution

Your obligations haven’t changed on 1 July, but the amended CPS 230 and CPG 230 language has. Check whether any of your material service providers fall into the newly exempted categories, and update your MSP Register using the new template regardless. Don’t assume last year’s submission format still works.

If you’re a smaller or non-significant entity

This is your deadline. Business continuity and scenario analysis requirements under CPS 230 now apply to you in full. If you’ve been treating 1 July 2026 as a soft target, it isn’t one anymore.

If you’re relying on a third-party collections platform or vendor

CPS 230’s contractual requirements for material service providers are your obligation to evidence, not your vendor’s to self-certify. Confirm your platform provider’s contracts, monitoring, and exit provisions are documented in a way your board can point to if APRA asks.

If your collections model runs on automated prioritisation or scoring

ASIC’s hardship-focused enforcement priority makes this the year to test whether your model can surface early hardship signals, not just formally lodged notices. Reactive compliance to a lodged hardship notice is table stakes. Proactive identification is where scrutiny is heading.

 

Not Every Change Adds Weight

None of these four developments are individually dramatic. A transition deadline landing on schedule. A modest exemption for edge-case vendors. A regulator sharpening an existing focus rather than inventing a new one. A simplification that reduces paperwork rather than adding it.

But stacked together on the same date, they say something clearer than any one of them does alone. The regulatory settings around collections and hardship in Australia aren’t static, and they’re not only getting heavier. Some genuinely get lighter. The organisations that do well out of FY27 will be the ones that read each change for what it actually is, rather than assuming every regulatory headline means more work.

If you want to work through what any of this means for your specific environment, or where 365 Collect fits into your operational control layer for the year ahead, we’re happy to have that conversation.

Get in touch with our team here.

 

FAQs

Does the 1 July 2026 CPS 230 deadline apply to us if we’re not a bank?

CPS 230 applies to all APRA-regulated entities, which includes banks, insurers, and superannuation trustees. Non-significant financial institutions across all three sectors had until 1 July 2026 to meet the business continuity and scenario analysis requirements specifically. If you’re APRA-regulated and haven’t confirmed your SFI status against this deadline, that’s the first thing to check.

What actually changed in the April 2026 CPS 230 amendments?

APRA created a limited exemption from specific contractual requirements for material arrangements with certain non-traditional service providers, government agencies, regulators, central banks, and financial market infrastructure operators, where standardised terms apply and bespoke negotiation isn’t realistic. It’s a narrow carve-out. All other CPS 230 obligations, including active risk management of those relationships, still apply.

Is the FAR simplification final?

Not yet. ASIC and APRA announced the proposed changes on 16 June 2026 and are consulting through the rest of the year, with implementation targeted by the end of 2026. Nothing changes automatically on 1 July. Treat it as a signal of direction rather than a rule already in force.

What does ASIC’s hardship enforcement priority actually mean for collections conduct?

It means ASIC is treating conduct that increases the risk of financial hardship, not just conduct after hardship is formally declared, as an enforcement target. For collections operations, that puts weight on early identification and consistent treatment, not just correct handling once a hardship notice is lodged.

Does the DTI cap mean more accounts will end up in collections?

Not directly, and not immediately. It’s a macroprudential tool aimed at slowing high-leverage lending growth before it becomes a stability risk, not a response to existing distress. The more relevant point for collections teams is what it signals: regulators are watching leverage and lending quality more closely than a year ago, and that tends to bring closer scrutiny of collections and hardship practices generally.

We’re a non-bank lender. Do any of these changes apply to us?

It depends on your licensing and structure. CPS 230 and FAR apply specifically to APRA-regulated entities. If you’re a credit licensee rather than an APRA-regulated entity, your direct obligations sit elsewhere, but ASIC’s enforcement priorities on hardship and consumer credit conduct apply regardless of whether APRA regulates you. Worth checking with your compliance advisor which specific instruments touch your licence type.

How does 365 Collect help?

365 Collect doesn’t make any organisation compliant with CPS 230, FAR, or ASIC’s enforcement priorities. That responsibility sits with the regulated entity. What the platform provides is the operational layer that supports it in practice: configurable workflow controls, a complete audit trail of case activity and communications, controlled suppression of activity for hardship or disputed cases, and visibility into planned versus actual collections activity. Built on Microsoft Dynamics 365, Dataverse, and the Power Platform, it’s designed to give collections teams and their boards something concrete to point to when a regulator asks how a decision was made and evidenced. If you’d like to talk through how that maps to your FY27 priorities, we’re happy to have that conversation.

This blog is intended as general guidance only and does not constitute legal or compliance advice. We recommend consulting your compliance team or legal advisors for advice specific to your organisation.

View All