Back to all Insights
Market Insights Aug 27, 2026

Compliance Isn’t the Hard Part Anymore

Risk, Compliance, Governance and Legal

Australia’s financial crime landscape has entered a new phase. Regulatory expansion, rising scam activity and increasing data exposure mean the challenge is no longer whether organisations are compliant, but whether their controls actually work. The organisations performing best are those that design frameworks around real behaviour, manage friction deliberately and focus on execution rather than policy volume.

Insights were carefully collated after having moderated and led panel sessions across fraud, AML, scams, cyber risk and Digital ID (Digital Identity) at the Financial Crime & Fraud 2026 Forum, alongside regulators and senior leaders from the ACCC, global fund managers, including Morgan Stanley, superannuation leaders from Hostplus and Aware Super, and fintechs such as Coinbase and Raiz Invest.

What stood out was a clear alignment across very different organisations, risk profiles and business models. There was a shared recognition that compliance itself is no longer the challenge. The main challenge being tackled now is whether controls actually work in practice, with real people, under real commercial pressures.

Australia has moved well beyond a policy‑led phase that regulators are no longer asking whether obligations exist. Instead, they are asking whether outcomes are being achieved.

Regulatory Expansion is Already Reshaping Behaviour

AUSTRAC’s expansion of the AML regime into professional services, real estate and other professional services sectors had been framed as a future issue until now. In reality, it is already reshaping how organisations think about risk, resourcing and governance, and these new industries are grappling with how to prepare and deliver these requirements.

A consistent theme from the panels was that many emerging regulated industries are underestimating the operational lift and ongoing cost of AML. Leaders from investment management, banking, superannuation and platforms have lived through this cycle before. The lesson is well understood. Generic frameworks applied without regard to business models rarely stand up.

Risk does not present the same way across a global fund manager, a super fund, a crypto exchange or a professional services firm. Treating it as though it does produces controls that look compliant but fail under pressure.

One‑size AML Has Reached Its Limit

The idea that a single, standardised AML framework can be rolled across industries is quietly breaking down.

Transaction velocity, customer behaviour, typologies and new digital identity risk differ materially. Yet many organisations continue to rely on static, onboarding‑heavy models in environments where risk evolves continuously.

The shift underway is away from event‑based compliance and towards ongoing assessment. Continuous customer due diligence, behavioural monitoring and closer integration between fraud, AML and scam controls.

It is Often the Simple Things That Trip Organisations Up

One of the most practical insights from the conference was this: Most control failures start internally, not externally.

People optimise their work. That is reality. When controls are over‑engineered, poorly aligned to workflows or create needless friction with no obvious benefit, they will be bypassed. Not through malicious intent, but through practical adaptation to get the job done.

This is where internal fraud, corruption and control failure often take root. Workarounds, informal processes and control fatigue quietly erode even well‑designed frameworks. Complexity can create comfort on paper while increasing real operational risk.

The Purpose of These Frameworks Matters

The purpose of financial crime, AML and cyber risk frameworks is not perfect documentation, but protection - Protecting the business, customers or members.

One of the most celebrated observations from the panels came from a senior executive who described their role simply as managing friction.

Slowing activity where risk genuinely sits, and removing friction everywhere else. That balance keeps organisations solvent, avoids licence conditions and regulatory scrutiny, and supports commercial performance.

That framing resonated because it reflects reality. Risk and compliance professionals are trained to pursue precision, and perfection designed first within theoretical environments.

For most employees, however, compliance is only one part of how work gets done. If controls are seen as unnecessary friction or extra effort with no clear upside, they will be worked around.

Managing Friction is Now a Leadership Capability

The organisations performing to the highest levels are the ones deliberately managing (and removing) friction.

They engage stakeholders early and invest in education rather than constant and boring policy updates and procedures. Designing controls that align with how work actually happens, not how it "should" happen.

This is particularly important as fraud, scams and cyber risks continue to converge.

Both ASIC and the ACCC have noted that scams and fraud are increasing again for the first time since the lows of 2022.

At the same time, data protection featured heavily across discussions as a growing source of risk. The over‑collection of identity data, weak governance and poor handling of personal information now directly enable scams and fraud, not just privacy breaches.

Digital ID (Digital Identity) has real potential to reduce harm, but only where it genuinely limits the spread of sensitive data rather than creating new exposure points.

Where Good Frameworks Fail or Succeed

The organisations pulling ahead the ones that understand how people actually operate inside their businesses, not those with the most detailed policies or the most complex control maps.

They accept that employees will optimise their work. They design controls around that reality. They slow activity where risk genuinely concentrates and remove friction everywhere else. They prioritise clear ownership, accountability and judgement over sheer volume of controls.

Technology plays an important role, but only where governance keeps pace. Layered controls that combine behavioural indicators, data signals and frontline intervention consistently outperform single‑point solutions.

Ultimately, effectiveness comes down to execution within real operating models with new technology enabling judgement rather than replacing it.

Compliance may satisfy requirements. Execution and reality checks outside the theoretical protects the licence.

Get in Touch

Based in Melbourne and Sydney, Kaizen Recruitment specialises in financial services recruitment nationally across funds management, wealth management, superannuation, investment consulting, fintech and insurance. If you'd like to understand more about the current candidate landscape within funds management or what's driving talent decisions in the market right now, please fill in the form below and a member of our team will be in touch.

By sending this form, I agree to the Privacy Policy