Skip to main content
    Astris Law S IconAstris Law

    Regulatory and Compliance Lawyer Brisbane

    Regulatory & Compliance - Astris Law Brisbane commercial law firm
    ← Back to Regulatory & Compliance

    Summary

    Astris Law helps Australian businesses and regulated professionals manage compliance, respond to investigations and defend enforcement action across ASIC, ACCC, AUSTRAC, the NDIS Quality and Safeguards Commission, AHPRA, the Office of the Health Ombudsman, WorkCover Queensland and WHS regulators. The practice covers corporate and financial services regulation, ACL compliance, AFSL and ACL licensing, breach reporting and AFCA disputes, privacy and data protection under the Privacy Act and Notifiable Data Breaches scheme, and AML/CTF program design, reporting and enforcement defence under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. We also advise NDIS providers and platforms on registration and mandatory registration reforms, and defend health practitioners and other professionals in disciplinary proceedings.

    Overview

    Australian businesses and professionals now operate under overlapping regulatory regimes that move from proactive compliance into investigation and enforcement without warning. Astris Law advises on the full field: ASIC, ACCC and AUSTRAC for corporate, financial services, credit and consumer issues; the NDIS Quality and Safeguards Commission, AHPRA and the Office of the Health Ombudsman for care and health professionals; WorkCover Queensland and WHS regulators for workplace safety and premium disputes; and the Privacy Act and Notifiable Data Breaches scheme for data protection and breach response. We treat each regime as part of the same operational risk picture so that advice on one area does not create exposure in another.

    Our work also includes AML/CTF compliance under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. The regime has applied to financial services, gambling and bullion dealers since 2006 and from 2026 Tranche 2 extends it to lawyers, accountants, real estate agents, trust and company service providers, precious metals and stones dealers, property developers, business brokers and other designated services. Whether you are an established reporting entity or a new entrant, we build AML/CTF programs that are practical, defensible and proportionate to your risk profile.

    How We Help

    Astris Law assists Brisbane directors, business owners and regulated professionals facing regulatory investigations, enforcement action and compliance obligations. When a regulator comes knocking through a compulsory notice, dawn raid, infringement notice or show cause letter, the response you give in the first days and weeks shapes the entire matter. We provide immediate, strategic advice that protects your position from the outset.

    Our corporate and financial regulatory work covers ASIC, ACCC and AUSTRAC investigations and enforcement under the Corporations Act 2001, the Australian Securities and Investments Commission Act 2001, the Competition and Consumer Act 2010 and the Australian Consumer Law. We advise on AFSL and ACL licensing, design and review compliance programs, manage breach reporting and design and distribution obligations, and defend enforcement proceedings. For Brisbane businesses in financial services, we also handle AFCA complaints and external dispute resolution matters.

    Astris Law is one of a small number of Australian law firms with a dedicated AML/CTF compliance practice. We advise reporting entities on every aspect of their obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, from initial AUSTRAC registration and AML/CTF program development through to enforcement defence and remediation. From 2026, Tranche 2 extends the regime to lawyers, accountants, real estate agents, trust and company service providers, precious metals and stones dealers, property developers, business brokers and other designated services.

    Privacy is now part of the same regulatory picture. We advise on Privacy Act compliance, Australian Privacy Principles, privacy policies, collection notices, data breach response and the Notifiable Data Breaches scheme, and help clients manage regulator engagement with the Office of the Australian Information Commissioner.

    Regulated care and health businesses face their own regulators. We act for NDIS providers and platforms on registration, audits and NDIS Commission compliance actions, including mandatory registration reforms from 2026 through to 2030, and for providers responding to compliance notices, infringement notices and banning orders. For registered health practitioners, AHPRA notifications, Health Ombudsman complaints and show cause processes are handled through our Disciplinary Law practice.

    Regulatory exposure does not stop at the corporate regulators. WorkCover Queensland investigations and work health and safety enforcement are handled with our Administrative Law & WHS practice, so the same firm covers the corporate, care, safety, privacy and professional dimensions of a regulatory problem.

    Common Situations

    • ASIC has issued a compulsory notice requiring your company to produce documents or attend an examination
    • Your business has received an infringement notice or show cause letter from a regulator and you need to respond within a tight deadline
    • You need to design or overhaul your compliance program to meet current ASIC or ACCC expectations
    • A customer complaint has escalated to an AFCA determination or an ACCC investigation into misleading conduct
    • Your AFSL or ACL licence is subject to conditions, variation or cancellation and you need to make submissions to ASIC
    • You have identified an internal compliance breach and need advice on breach reporting obligations and remediation
    • Your business is a reporting entity and AUSTRAC has commenced an investigation or issued an infringement notice
    • You need an AML/CTF program developed, reviewed or remediated to meet current AUSTRAC expectations
    • Your business provides designated services and needs to prepare for Tranche 2 AML/CTF obligations from 2026
    • The NDIS Commission has issued a compliance notice, infringement notice or banning order, or your provider registration is caught by the mandatory registration reforms
    • AHPRA or the Health Ombudsman has notified you of a complaint or investigation touching your registration or practice
    • WorkCover Queensland or a WHS regulator is investigating a workplace incident, claim or premium declaration involving your business
    • You suspect or have confirmed a data breach involving personal information and need advice on Notifiable Data Breaches obligations

    Why Astris Law

    As a boutique Brisbane firm, Astris Law provides the direct principal access and responsiveness that regulatory matters demand: you are not passed between departments or delegated to juniors during a crisis.

    What We Can Do

    ASIC investigations, infringement notices and enforceable undertakings
    Australian Consumer Law compliance, unfair practices and product recalls
    ACCC investigations, competition law and merger clearance
    AFSL and ACL licensing, compliance programs and breach reporting
    AML/CTF program development, review and remediation
    AUSTRAC registration, reporting entity obligations and ongoing compliance
    Suspicious matter reports, threshold transaction reports and IFTI obligations
    AUSTRAC investigations, infringement notices and enforcement responses
    Tranche 2 readiness and onboarding for new reporting entities
    Regulatory investigations, dawn raids and enforcement responses
    NDIS provider and platform registration, audits and mandatory registration reform advice
    NDIS Commission investigations, compliance actions, banning orders and enforcement responses
    WorkCover Queensland and WHS regulator investigations, notices and enforcement
    Professional conduct and disciplinary regulators, including AHPRA and health complaints bodies
    Privacy Act compliance, Australian Privacy Principles and Notifiable Data Breaches response
    Compliance program design, review and remediation
    Industry code compliance, external dispute resolution and AFCA matters

    Our Special Interests

    Responding to ASIC, ACCC and AUSTRAC investigations
    Implementing compliance frameworks and breach reporting systems
    Managing product recalls, consumer remediation and class actions
    Navigating multi-regulator oversight and coordinated investigations
    Designing risk-based AML/CTF programs for complex business models
    Preparing Tranche 2 entities for AML/CTF obligations from 2026
    Guiding NDIS providers and platforms through the mandatory registration reforms
    Privacy Act compliance, data breach response and OAIC engagement

    Key Legislation & Frameworks

    Corporations Act 2001 (Cth)Australian Consumer LawCompetition and Consumer Act 2010ASIC Act 2001Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)AML/CTF RulesNational Consumer Credit Protection Act 2009Treasury Laws Amendment (Design and Distribution) ActNational Disability Insurance Scheme Act 2013 (Cth)Health Practitioner Regulation National Law (Qld)Workers' Compensation and Rehabilitation Act 2003 (Qld)Work Health and Safety Act 2011 (Qld)Privacy Act 1988 (Cth)

    Frequently Asked Questions

    What should I do if ASIC is investigating my business?

    If ASIC is investigating your business, you should immediately seek legal advice. ASIC has broad investigative powers including the ability to compel attendance, production of documents and examination under oath. You have rights including legal professional privilege and the privilege against self-incrimination in certain circumstances. Early legal engagement can help manage the investigation and negotiate outcomes such as enforceable undertakings.

    What is the Australian Consumer Law and how does it affect my business?

    The Australian Consumer Law (ACL), contained in Schedule 2 of the Competition and Consumer Act 2010, applies to all businesses operating in Australia. It prohibits misleading or deceptive conduct, unconscionable conduct and unfair contract terms. It provides consumer guarantees for goods and services and gives the ACCC enforcement powers including product recalls, infringement notices and court-ordered penalties.

    Do I need an AFSL or ACL for my business in Australia?

    You need an Australian Financial Services Licence (AFSL) if you provide financial services including dealing in financial products, providing financial advice or operating a financial market. You need an Australian Credit Licence (ACL) if you engage in credit activities. Exemptions may apply, and authorised representative arrangements can provide an alternative to holding your own licence.

    What is an AML/CTF program and do I need one in Australia?

    An AML/CTF program is a compliance framework required under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) for all reporting entities. It must include customer identification procedures, ongoing customer due diligence, transaction monitoring and suspicious matter reporting processes. If your business provides designated services including financial services, gambling, bullion dealing or (from 2026) professional services under Tranche 2, you are required to have an AML/CTF program registered with AUSTRAC.

    What is Tranche 2 AML and when does it start in Australia?

    Tranche 2 extends Australia's AML/CTF regime to lawyers, accountants, real estate agents, trust and company service providers (TCSPs), precious metals and stones dealers, property developers, business brokers and other designated service providers. These entities will become reporting entities for the first time, requiring AML/CTF programs, AUSTRAC registration and ongoing compliance frameworks from 2026.

    What is an enforceable undertaking from ASIC?

    An enforceable undertaking is a written agreement between ASIC and a person or company in which the entity commits to taking specific actions to address compliance concerns. It is an alternative to court proceedings and is legally binding. Breaching an enforceable undertaking allows ASIC to seek court orders enforcing compliance. Negotiating an EU can be a favourable outcome compared to civil penalty proceedings.

    What penalties apply for breaching Australian Consumer Law?

    Penalties for breaching the Australian Consumer Law can be severe. For bodies corporate, the maximum civil penalty is the greater of $50 million, three times the benefit obtained or 30% of turnover. For individuals, the maximum is $2.5 million. The ACCC can also seek injunctions, disqualification orders, adverse publicity orders and community service orders.

    What should I do if the NDIS Commission takes compliance action against my business?

    The NDIS Quality and Safeguards Commission can issue compliance notices, infringement notices, enforceable undertakings and banning orders, and its compliance actions are listed on a public register that participants, competitors and insurers can search. Operating without registration where registration is required is now a criminal matter and civil penalties for serious misconduct reach $15 million. If the Commission is looking at your business, the sequence of what you do next matters more than the notice itself: obtain legal advice before responding, preserve documents and treat any registration or renewal application in light of your compliance history.

    What should I do if I receive an AHPRA notification or Health Ombudsman complaint?

    AHPRA notifications proceed through a staged process under the Health Practitioner Regulation National Law: assessment, possible immediate action on your registration, investigation and in serious cases referral to a tribunal. Deadlines to respond are short and what you say in your first response shapes the entire matter. Obtain legal advice before responding, notify your professional indemnity insurer and do not contact the notifier. Astris Law handles these matters through its Disciplinary Law practice, which defends health practitioners and other regulated professionals.

    What should I do if WorkCover Queensland or a WHS regulator is investigating my business?

    WorkCover Queensland and Workplace Health and Safety Queensland have broad powers to require documents, enter workplaces and interview staff following a workplace incident or in connection with a claim or premium declaration. What you say and produce during the investigation forms the evidentiary foundation of any later prosecution or claim dispute, so legal advice at the investigation stage is critical. Astris Law handles these investigations with its Administrative Law & WHS practice, including WHS prosecution defence across all offence categories.

    What are my obligations if my business has a data breach?

    If your business is subject to the Privacy Act 1988 and there are reasonable grounds to believe an eligible data breach has occurred, the Notifiable Data Breaches scheme requires you to notify affected individuals and the Office of the Australian Information Commissioner. The assessment must be made within 30 days of becoming aware of the suspected breach. Prompt legal advice helps you contain the breach, determine notification obligations, manage communications and reduce the risk of regulatory action.

    Resource Centres

    Digital Assets Law in Australia: The Regulatory Map

    How a single digital asset can sit inside the financial services licence regime, the anti-money laundering regime and the tax rules at once, and which regimes touch what you do.

    NDIS Lawyer for Providers: The Resource Hub

    One page collecting everything for NDIS provider businesses: the mandatory registration timetable, audit preparation, the enforcement pathway from show cause letter to banning order, and the service agreements underneath.

    AHPRA Investigation: What Happens and What To Do at Each Stage

    The staged process under the National Law: assessment, immediate action, investigation and tribunal referral, with timeframes and a first 48 hours checklist.

    Insights & Publications

    View all
    45 Providers Struck Off One Register, a Final Deadline on the Other: Australia's Digital Asset Squeeze - Astris Law legal insights
    Insights

    45 Providers Struck Off One Register, a Final Deadline on the Other: Australia's Digital Asset Squeeze

    14 September 2026

    AUSTRAC has cancelled, suspended or refused to renew 45 remittance and virtual asset registrations in a year, and ASIC's final licensing window for digital asset businesses closes on 30 September 2026. The two announcements are one story: holding a place on an Australian register is no longer passive, at either end of the regime.

    Read more
    AHPRA Social Media Policy: The Rules for Practitioners and Practices - Astris Law legal insights
    Insights

    AHPRA Social Media Policy: The Rules for Practitioners and Practices

    11 September 2026

    Social media collapses the distance between a practitioner's professional obligations and their personal voice. Ahpra's social media guidance makes clear the National Law follows the account: advertising rules, testimonial prohibitions, confidentiality and professional conduct standards all apply online. What that means in practice, for the practice account and the personal one.

    Read more
    EV Charging Networks: The Regulatory Stack - Astris Law legal insights
    Insights

    EV Charging Networks: The Regulatory Stack

    7 September 2026

    An EV charging network looks like hardware plus an app. Underneath it sits a stack of regulatory questions about retailing, metering and network services whose answers turn on the specific arrangement. The structure chosen at site one gets replicated across the network, for better or worse.

    Read more

    Industries We Serve in Regulatory & Compliance

    Banking, Private Equity & Venture Capital

    Strategic legal counsel for banks, private equity firms and venture capital funds.

    Fintech

    Innovative legal solutions for payment platforms, neobanks and financial technology disruptors.

    Crypto & Blockchain

    Forward-thinking legal guidance for cryptocurrency exchanges, token projects and blockchain ventures.

    Gambling

    Dedicated legal counsel for casinos, online wagering operators and gaming technology providers.

    Insurance

    Legal services for insurers, brokers, underwriters and policyholders.

    Health & Medical Services

    Legal services for medical, dental and allied health practices, NDIS and aged care providers, hospitals and digital health companies.

    Non-Profit & Charities

    Legal services for charities, not-for-profits, associations and social enterprises.

    Education & Training

    Legal services for schools, universities, RTOs and EdTech companies.

    Construction & Infrastructure

    Legal support for construction contracts, infrastructure projects and building disputes in Queensland and Australia.

    Discuss Your Situation

    Get a brief, no-obligation call to understand your options.

    Documents (optional)

    Drag & drop files here, or click to browse

    PDF, Word, photos or text — up to 25MB each, 5 files max

    Online enquiries do not create a solicitor-client relationship. Enquiries are subject to conflict checks, availability and onboarding. If you are unsure whether we may be acting for another party in your matter, please provide only your name and a general enquiry so we can complete conflict checks.

    I have read the and consent to Astris Law collecting and handling my personal information as it and the describe.

    (07) 3519 5616

    Need a regulatory & compliance lawyer? Talk to Astris Law.

    We work directly with our clients on regulatory & compliance matters across Australia. No layers, no committees.

    Other Practice Areas

    Anti Money-LaunderingDisciplinary Investigations & Professional MisconductAdministrative Law & WHS Investigations
    View all Regulatory & Compliance services →

    Cookies on by default ·Privacy