Australia's compliance index
Every Australian compliance rule, one index.
475+ cited explainers, 49 free tools, 399+ obligations and 38+ tracked deadlines — every claim links its source.
Federal + 8 states · Every regulator · Updated weekly · Free + open
Start here
Rules Mate suggests
Compliance Fingerprint
A structured assessment maps your business to its obligation set out of 399+ obligations across 179 regulators — with the thresholds you are about to cross.
AI compliance advisor
Cited answers grounded in the corpus — 399+ obligations, 234+ enforcement actions. Upload contracts, policies or notices. First question free.
Compliance calendar
38+ federal and state deadlines, filterable by industry and entity size — with an .ics subscription so nothing lands unannounced.
Free tools
Compliance tools
AML Tranche 2 scope checker
Are you a designated service provider under the 1 July 2026 reforms?
Privacy Act 2026 readiness
Score your privacy program against the APPs plus the 10 December 2026 reforms.
Payday Super readiness
Pre-1 July 2026 preparation check for the every-payday SG regime.
NDB notification timer
The OAIC data-breach notification clock, from suspicion to statement.
Penalty estimator
Maximum exposure by breach type across every Australian regulator.
Employee vs contractor
Indicative multi-factor check under the whole-of-relationship test (s 15AA).
Compliance calendar generator
A personalised list of every recurring federal and state deadline.
Essential Eight maturity
Score your cyber security maturity ML0–ML3 across ASD's eight strategies.
Browse the corpus
Every way into the corpus
Insights
475 long-form explainers, plain English, every claim cited.
Tools
49 free interactive compliance tools — scope checkers, timers, calculators.
Playbooks
15 industry obligation playbooks — every Act, section, form and source.
Compare
18 sortable state-by-state comparison tables — each cell sourced.
Act timelines
15 amendment histories — Royal Assent + commencement on every change.
Calendar
38+ deadlines, 35 industry calendars, .ics subscribe.
Checklists
5 interactive readiness checklists — Privacy, AML, Modern Slavery, SOCI, Directors.
Glossary
117 compliance terms defined — APP, NDB, CDD, SMR, TTR and more.
Acts & instruments
Commonwealth and state legislation with plain-English summaries.
Regulators
179+ federal and state regulators — scope, enforcement, guidance.
Obligations
399+ obligations — who, what, when, evidence and penalty.
Enforcement
234+ civil penalties, EUs, court judgments and infringements.
2026 compliance events
The big regimes in force or imminent
AML/CTF Tranche 2
90K new entities · 1 Jul 2026
Privacy Act 2026
Statutory tort live · ADM + Children's Code 10 Dec 2026
Payday Super
Per-pay SG · 1 Jul 2026
Director ID
Personal liability · $13.2K + criminal
Modern Slavery
≥$100M reporters · annual
Climate Disclosure
AASB S2 · Group 1 FY25 live
FAR (Financial Accountability)
Insurers + RSE · in force 15 Mar 2025
Closing Loopholes
Wage theft criminal · 1 Jan 2025
Cyber Security & SOCI
Multi-regulator incident clocks
Browse by topic
12 cross-cutting topic hubs
Financial services
109AFSL holders' obligations, Design and Distribution Obligations, Internal Dispute Resolution (RG 271), breach reporting, responsible lending, and product intervention powers.
Workplace & employment
80Fair Work obligations including modern award compliance, criminal wage theft, Payday Super, right to disconnect, psychosocial hazards, and the positive duty under the Sex Discrimination Act.
Tax & payroll
55ATO obligations across income tax, GST, FBT, payroll tax (state-by-state), Single Touch Payroll Phase 2, Payday Super, CARF crypto reporting, and tax practitioner regulation.
Directors & governance
50Director Identification Numbers, statutory directors' duties under the Corporations Act, insolvent trading safe harbour, continuous disclosure, and the Financial Accountability Regime.
Privacy & data protection
45Privacy Act 1988 obligations including APPs, NDB scheme, the 2024 amendments (statutory tort, enhanced penalties, doxxing offence), the 10 December 2026 commencements (ADM transparency, Children's Online Privacy Code), and the proposed removal of the small-business exemption (a future reform tranche, not yet law).
Cyber security
27Critical infrastructure reporting under SOCI, APRA CPS 234 information security, ASD Essential Eight, Right Fit For Risk for federal subcontractors, and the broader cyber compliance stack.
Industry-specific regulation
19Sector-specific compliance regimes: aged care, NDIS, RTOs, higher education, aviation, maritime, food safety, gambling and licensing.
WHS & worker safety
16Model WHS laws and state implementations covering primary duty of care, psychosocial hazards, silica exposure, incident notification, and industrial manslaughter regimes.
Climate & ESG
14Mandatory climate disclosures under AASB S2 (ASRS), NGER reporting, Safeguard Mechanism, Modern Slavery reporting, and greenwashing enforcement by ASIC and ACCC.
Anti-money laundering & CTF
13Australia's AML/CTF framework — designated services, AUSTRAC reporting, customer due diligence, and the 1 July 2026 Tranche 2 expansion to real estate, accountants, lawyers, conveyancers, TCSPs and precious metals dealers.
Tax practitioners + TASA reform
11Tax + BAS agents registration, Code of Conduct + 2024 Code Determination, breach reporting, supervision + arrangements. Substantial reforms post-PwC.
Australian Consumer Law + consumer protection
8Consumer guarantees, unfair contract terms (penalty regime from 9 November 2023), unconscionable conduct, product safety, misleading conduct + ACCC enforcement.
Browse by industry
Top industries
E-commerce & online retail
Online retailers and marketplaces. Captured by ACL, Privacy Act, and unfair contract terms regime.
Health practitioners
Registered health practitioners under the National Law.
Fintech (non-bank)
Non-bank financial technology businesses — neobanks, BNPL, payment processors, crypto exchanges.
Charities & not-for-profits
Registered charities and other NFPs subject to ACNC and state incorporated association regulation.
Construction (residential & commercial)
Builders, contractors, and subcontractors covered by the Building & Construction General On-site Award and high-risk WHS.
Mining & resources
Mining operations subject to state mining safety regimes, NGER, and royalty obligations.
Road transport & logistics
Heavy vehicle operators subject to Chain of Responsibility under HVNL.
Cafés & restaurants
Food service businesses covered by the Hospitality Industry (General) Award 2020 and food safety standards.
Software & SaaS
Tech companies — captured by Privacy Act, Online Safety Act, AI Voluntary Standard, and SOCI if critical-infrastructure-aligned.
Real estate agents
Selling agents, buyer's agents, and property developers involved in real estate transactions. From 1 July 2026 captured by AML/CTF Tranche 2 reforms.
What’s new
Latest insights
ISO 9001 quality management systems: what an Australian business actually has to implement
ISO 9001 for Australian businesses: what the standard requires, how it is adopted here as AS/NZS ISO 9001, what auditors check, cost drivers and the 2026 revision.
ISO 27001 implementation in Australia: scope, Statement of Applicability and the two-stage audit
A practical ISO 27001 implementation guide for Australian organisations: setting scope, risk treatment, the Statement of Applicability, Stage 1 and Stage 2 audits, and evidence.
ISO 45001 and the model WHS laws: how the OH&S management standard maps to Australian duties
How ISO 45001 maps to Australia's model WHS laws: what the standard adds, where the primary duty of care goes further, consultation duties, and why certification is not a defence.
ISO 14001 environmental management systems for Australian operations (and the 2026 edition)
ISO 14001 for Australian operations: the compliance obligations register, aspects and impacts, how it meets EPA general environmental duties, and the 2026 transition deadline.
ISO 31000 risk management: applying the standard to an Australian compliance program
ISO 31000 is guidance, not a certifiable standard. How to apply its principles, framework and process to an Australian compliance program that regulators will accept.
ISO 37301 compliance management systems: the standard for the compliance function itself
ISO 37301 sets certifiable requirements for a compliance management system: the obligations register, independence of the compliance function, culture, and Australian uses.
Coming up
Next compliance deadlines
SOCI CIRMP annual board attestation
Annual CIRMP attestation by board to Home Affairs.
NGER report due
Lodge NGER greenhouse + energy report for the 2025-26 reporting year via EERS.
NGER annual report due
NGER report for year ending 30 June 2026.
Silica standard becomes a binding WEL (0.05 mg/m³)
The 0.05 mg/m³ exposure standard for respirable crystalline silica becomes a legally binding Workplace Exposure Limit (WEL). A further cut to 0.025 mg/m³ is only proposed, not adopted.
Children's Online Privacy Code in force
OAIC Children's Code (binding) in force.
ADM transparency obligation in force
APP entities must disclose significant ADM use in privacy policy.
Recent guidance & changes
What’s shifted lately
- 28 Aug 2026ISO 22301 business continuity and APRA CPS 230: how the standard supports the prudential requirementHow ISO 22301 business continuity management supports APRA CPS 230: impact analysis, tolerance levels, testing, service providers, and where CPS 230 goes further.Cyber security
- 28 Aug 2026ISO 27701 privacy information management and the Australian Privacy ActISO/IEC 27701:2025 is now a standalone privacy management standard. How a PIMS maps to the Australian Privacy Principles, and what it does and does not satisfy.Privacy & data protection
- 28 Aug 2026Surveillance audits, non-conformances and keeping certification between recertification cyclesHow the three-year certification cycle works: surveillance audit scope, major vs minor non-conformances, root cause and corrective action, and suspension or withdrawal.Directors & governance
- 28 Aug 2026SOC 2 or ISO 27001: which security assurance artefact your customers actually wantSOC 2 is an attestation report; ISO 27001 is a certificate. How they differ in scope, evidence and renewal, and which Australian buyers ask for which.Cyber security
- 28 Aug 2026IRAP assessments and hosting Australian government data: the certification pathHow an IRAP assessment works, what an IRAP assessor can and cannot give you, and how the Hosting Certification Framework sits alongside it (checked August 2026).Cyber security
Weekly digest
Get the regulator changes that matter to your industry
Topic-filtered weekly digest. Subscribe to AML, privacy, climate, workplace, cyber, tax or directors — or all of them. Sources cited, no fluff.
Sourced live from
- legislation.gov.au
- ASIC
- AUSTRAC
- OAIC
- ACCC
- APRA
- ATO
- Fair Work Commission
- ASD
- NDIS Commission
- ACMA
- TGA
- State regulators ×8
Every claim links to its primary source. We summarise — we never republish full statutory text.
Part of the Mate Network