Regulatory and Compliance Lawyer Brisbane

Summary
Astris Law helps Australian businesses and regulated professionals manage compliance, respond to investigations and defend enforcement action across ASIC, ACCC, AUSTRAC, the NDIS Quality and Safeguards Commission, AHPRA, the Office of the Health Ombudsman, WorkCover Queensland and WHS regulators. The practice covers corporate and financial services regulation, ACL compliance, AFSL and ACL licensing, breach reporting and AFCA disputes, privacy and data protection under the Privacy Act and Notifiable Data Breaches scheme, and AML/CTF program design, reporting and enforcement defence under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. We also advise NDIS providers and platforms on registration and mandatory registration reforms, and defend health practitioners and other professionals in disciplinary proceedings.
Overview
Australian businesses and professionals now operate under overlapping regulatory regimes that move from proactive compliance into investigation and enforcement without warning. Astris Law advises on the full field: ASIC, ACCC and AUSTRAC for corporate, financial services, credit and consumer issues; the NDIS Quality and Safeguards Commission, AHPRA and the Office of the Health Ombudsman for care and health professionals; WorkCover Queensland and WHS regulators for workplace safety and premium disputes; and the Privacy Act and Notifiable Data Breaches scheme for data protection and breach response. We treat each regime as part of the same operational risk picture so that advice on one area does not create exposure in another.
Our work also includes AML/CTF compliance under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. The regime has applied to financial services, gambling and bullion dealers since 2006 and from 2026 Tranche 2 extends it to lawyers, accountants, real estate agents, trust and company service providers, precious metals and stones dealers, property developers, business brokers and other designated services. Whether you are an established reporting entity or a new entrant, we build AML/CTF programs that are practical, defensible and proportionate to your risk profile.
How We Help
Astris Law assists Brisbane directors, business owners and regulated professionals facing regulatory investigations, enforcement action and compliance obligations. When a regulator comes knocking through a compulsory notice, dawn raid, infringement notice or show cause letter, the response you give in the first days and weeks shapes the entire matter. We provide immediate, strategic advice that protects your position from the outset.
Our corporate and financial regulatory work covers ASIC, ACCC and AUSTRAC investigations and enforcement under the Corporations Act 2001, the Australian Securities and Investments Commission Act 2001, the Competition and Consumer Act 2010 and the Australian Consumer Law. We advise on AFSL and ACL licensing, design and review compliance programs, manage breach reporting and design and distribution obligations, and defend enforcement proceedings. For Brisbane businesses in financial services, we also handle AFCA complaints and external dispute resolution matters.
Astris Law is one of a small number of Australian law firms with a dedicated AML/CTF compliance practice. We advise reporting entities on every aspect of their obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, from initial AUSTRAC registration and AML/CTF program development through to enforcement defence and remediation. From 2026, Tranche 2 extends the regime to lawyers, accountants, real estate agents, trust and company service providers, precious metals and stones dealers, property developers, business brokers and other designated services.
Privacy is now part of the same regulatory picture. We advise on Privacy Act compliance, Australian Privacy Principles, privacy policies, collection notices, data breach response and the Notifiable Data Breaches scheme, and help clients manage regulator engagement with the Office of the Australian Information Commissioner.
Regulated care and health businesses face their own regulators. We act for NDIS providers and platforms on registration, audits and NDIS Commission compliance actions, including mandatory registration reforms from 2026 through to 2030, and for providers responding to compliance notices, infringement notices and banning orders. For registered health practitioners, AHPRA notifications, Health Ombudsman complaints and show cause processes are handled through our Disciplinary Law practice.
Regulatory exposure does not stop at the corporate regulators. WorkCover Queensland investigations and work health and safety enforcement are handled with our Administrative Law & WHS practice, so the same firm covers the corporate, care, safety, privacy and professional dimensions of a regulatory problem.
Common Situations
- ASIC has issued a compulsory notice requiring your company to produce documents or attend an examination
- Your business has received an infringement notice or show cause letter from a regulator and you need to respond within a tight deadline
- You need to design or overhaul your compliance program to meet current ASIC or ACCC expectations
- A customer complaint has escalated to an AFCA determination or an ACCC investigation into misleading conduct
- Your AFSL or ACL licence is subject to conditions, variation or cancellation and you need to make submissions to ASIC
- You have identified an internal compliance breach and need advice on breach reporting obligations and remediation
- Your business is a reporting entity and AUSTRAC has commenced an investigation or issued an infringement notice
- You need an AML/CTF program developed, reviewed or remediated to meet current AUSTRAC expectations
- Your business provides designated services and needs to prepare for Tranche 2 AML/CTF obligations from 2026
- The NDIS Commission has issued a compliance notice, infringement notice or banning order, or your provider registration is caught by the mandatory registration reforms
- AHPRA or the Health Ombudsman has notified you of a complaint or investigation touching your registration or practice
- WorkCover Queensland or a WHS regulator is investigating a workplace incident, claim or premium declaration involving your business
- You suspect or have confirmed a data breach involving personal information and need advice on Notifiable Data Breaches obligations
Why Astris Law
As a boutique Brisbane firm, Astris Law provides the direct principal access and responsiveness that regulatory matters demand: you are not passed between departments or delegated to juniors during a crisis.
What We Can Do
Our Special Interests
Key Legislation & Frameworks
Frequently Asked Questions
What should I do if ASIC is investigating my business?
If ASIC is investigating your business, you should immediately seek legal advice. ASIC has broad investigative powers including the ability to compel attendance, production of documents and examination under oath. You have rights including legal professional privilege and the privilege against self-incrimination in certain circumstances. Early legal engagement can help manage the investigation and negotiate outcomes such as enforceable undertakings.
What is the Australian Consumer Law and how does it affect my business?
The Australian Consumer Law (ACL), contained in Schedule 2 of the Competition and Consumer Act 2010, applies to all businesses operating in Australia. It prohibits misleading or deceptive conduct, unconscionable conduct and unfair contract terms. It provides consumer guarantees for goods and services and gives the ACCC enforcement powers including product recalls, infringement notices and court-ordered penalties.
Do I need an AFSL or ACL for my business in Australia?
You need an Australian Financial Services Licence (AFSL) if you provide financial services including dealing in financial products, providing financial advice or operating a financial market. You need an Australian Credit Licence (ACL) if you engage in credit activities. Exemptions may apply, and authorised representative arrangements can provide an alternative to holding your own licence.
What is an AML/CTF program and do I need one in Australia?
An AML/CTF program is a compliance framework required under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) for all reporting entities. It must include customer identification procedures, ongoing customer due diligence, transaction monitoring and suspicious matter reporting processes. If your business provides designated services including financial services, gambling, bullion dealing or (from 2026) professional services under Tranche 2, you are required to have an AML/CTF program registered with AUSTRAC.
What is Tranche 2 AML and when does it start in Australia?
Tranche 2 extends Australia's AML/CTF regime to lawyers, accountants, real estate agents, trust and company service providers (TCSPs), precious metals and stones dealers, property developers, business brokers and other designated service providers. These entities will become reporting entities for the first time, requiring AML/CTF programs, AUSTRAC registration and ongoing compliance frameworks from 2026.
What is an enforceable undertaking from ASIC?
An enforceable undertaking is a written agreement between ASIC and a person or company in which the entity commits to taking specific actions to address compliance concerns. It is an alternative to court proceedings and is legally binding. Breaching an enforceable undertaking allows ASIC to seek court orders enforcing compliance. Negotiating an EU can be a favourable outcome compared to civil penalty proceedings.
What penalties apply for breaching Australian Consumer Law?
Penalties for breaching the Australian Consumer Law can be severe. For bodies corporate, the maximum civil penalty is the greater of $50 million, three times the benefit obtained or 30% of turnover. For individuals, the maximum is $2.5 million. The ACCC can also seek injunctions, disqualification orders, adverse publicity orders and community service orders.
What should I do if the NDIS Commission takes compliance action against my business?
The NDIS Quality and Safeguards Commission can issue compliance notices, infringement notices, enforceable undertakings and banning orders, and its compliance actions are listed on a public register that participants, competitors and insurers can search. Operating without registration where registration is required is now a criminal matter and civil penalties for serious misconduct reach $15 million. If the Commission is looking at your business, the sequence of what you do next matters more than the notice itself: obtain legal advice before responding, preserve documents and treat any registration or renewal application in light of your compliance history.
What should I do if I receive an AHPRA notification or Health Ombudsman complaint?
AHPRA notifications proceed through a staged process under the Health Practitioner Regulation National Law: assessment, possible immediate action on your registration, investigation and in serious cases referral to a tribunal. Deadlines to respond are short and what you say in your first response shapes the entire matter. Obtain legal advice before responding, notify your professional indemnity insurer and do not contact the notifier. Astris Law handles these matters through its Disciplinary Law practice, which defends health practitioners and other regulated professionals.
What should I do if WorkCover Queensland or a WHS regulator is investigating my business?
WorkCover Queensland and Workplace Health and Safety Queensland have broad powers to require documents, enter workplaces and interview staff following a workplace incident or in connection with a claim or premium declaration. What you say and produce during the investigation forms the evidentiary foundation of any later prosecution or claim dispute, so legal advice at the investigation stage is critical. Astris Law handles these investigations with its Administrative Law & WHS practice, including WHS prosecution defence across all offence categories.
What are my obligations if my business has a data breach?
If your business is subject to the Privacy Act 1988 and there are reasonable grounds to believe an eligible data breach has occurred, the Notifiable Data Breaches scheme requires you to notify affected individuals and the Office of the Australian Information Commissioner. The assessment must be made within 30 days of becoming aware of the suspected breach. Prompt legal advice helps you contain the breach, determine notification obligations, manage communications and reduce the risk of regulatory action.
Resource Centres
Digital Assets Law in Australia: The Regulatory Map
How a single digital asset can sit inside the financial services licence regime, the anti-money laundering regime and the tax rules at once, and which regimes touch what you do.
NDIS Lawyer for Providers: The Resource Hub
One page collecting everything for NDIS provider businesses: the mandatory registration timetable, audit preparation, the enforcement pathway from show cause letter to banning order, and the service agreements underneath.
AHPRA Investigation: What Happens and What To Do at Each Stage
The staged process under the National Law: assessment, immediate action, investigation and tribunal referral, with timeframes and a first 48 hours checklist.
Insights & Publications
View all
45 Providers Struck Off One Register, a Final Deadline on the Other: Australia's Digital Asset Squeeze
14 September 2026
AUSTRAC has cancelled, suspended or refused to renew 45 remittance and virtual asset registrations in a year, and ASIC's final licensing window for digital asset businesses closes on 30 September 2026. The two announcements are one story: holding a place on an Australian register is no longer passive, at either end of the regime.
Read more
AHPRA Social Media Policy: The Rules for Practitioners and Practices
11 September 2026
Social media collapses the distance between a practitioner's professional obligations and their personal voice. Ahpra's social media guidance makes clear the National Law follows the account: advertising rules, testimonial prohibitions, confidentiality and professional conduct standards all apply online. What that means in practice, for the practice account and the personal one.
Read more
EV Charging Networks: The Regulatory Stack
7 September 2026
An EV charging network looks like hardware plus an app. Underneath it sits a stack of regulatory questions about retailing, metering and network services whose answers turn on the specific arrangement. The structure chosen at site one gets replicated across the network, for better or worse.
Read moreIndustries We Serve in Regulatory & Compliance
Banking, Private Equity & Venture Capital
Strategic legal counsel for banks, private equity firms and venture capital funds.
Fintech
Innovative legal solutions for payment platforms, neobanks and financial technology disruptors.
Crypto & Blockchain
Forward-thinking legal guidance for cryptocurrency exchanges, token projects and blockchain ventures.
Gambling
Dedicated legal counsel for casinos, online wagering operators and gaming technology providers.
Insurance
Legal services for insurers, brokers, underwriters and policyholders.
Health & Medical Services
Legal services for medical, dental and allied health practices, NDIS and aged care providers, hospitals and digital health companies.
Non-Profit & Charities
Legal services for charities, not-for-profits, associations and social enterprises.
Education & Training
Legal services for schools, universities, RTOs and EdTech companies.
Construction & Infrastructure
Legal support for construction contracts, infrastructure projects and building disputes in Queensland and Australia.
Need a regulatory & compliance lawyer? Talk to Astris Law.
We work directly with our clients on regulatory & compliance matters across Australia. No layers, no committees.