Every August, the Australian Securities and Investments Commission publishes a corporate plan. On the surface it is a compliance document, required under the Public Governance, Performance and Accountability Act 2013. In practice it is one of the clearest signals a regulated business gets about where the regulator’s attention, and its enforcement resources, are heading over the next four years.
With ASIC’s latest plan hot off the press this month, we thought it was the perfect opportunity to step back and take the long view: to line the newest edition up against those that came before it and see just how much the regulator’s priorities, language and posture have shifted over a decade.
So we pulled three of them off the shelf (2016, 2021 and 2026) and read them side by side. Ten years apart at the bookends, five years between each. What emerges is a changing idea of what ASIC is for, written each time in the language of whichever crisis or inquiry had most recently reshaped the environment. Each plan is very much a product of its moment.
The three moments
It helps to remember what each plan was written into.
The 2016 plan (covering 2016–17 to 2019–20) was Greg Medcraft’s, and it landed less than a decade after the 2008 global financial crisis. The GFC is never far from the surface. The plan opens on the language of trust, confidence and “gatekeepers,” and it reads as a document still processing the lesson that markets can break and that the public’s faith in the financial system is fragile and hard-won.
The 2021 plan (2021–22 to 2024–25) was Joseph Longo’s first as Chair, written roughly eighteen months into COVID-19 and, more importantly for its character, two years after the Hayne Banking Royal Commission handed down its final report in February 2019. The Commission’s findings run right through the document: in its emphasis on misconduct, on the Financial Accountability Regime, on design and distribution obligations, and on ASIC’s re-cast identity as “a strong and targeted law enforcement agency” and “an active litigator.”
The 2026 plan (2026–27 to 2029–30) is Sarah Court’s first, and it reflects a regulator operating in a genuinely new risk landscape (artificial intelligence, cyber and operational resilience, private markets and private credit, digital assets) and one that, after years of rebuilding its enforcement capability, is visibly more confident. Court came to the chair as ASIC’s deputy and a career litigator, having overseen what the government described as some of the agency’s strongest enforcement results on record. That self-assurance shows.
The language: from “trust and confidence” to “harder to avoid”
The most striking shift over ten years is tone.
The 2016 plan is earnest and almost academic. Its central vocabulary is trust, confidence, culture, gatekeepers and behaviour. Medcraft’s message dwells on “human behaviour drivers” such as financial literacy, behavioural biases, incentives and deterrence, and frames ASIC’s role as understanding why people and firms act as they do. There is a diagnostic, social-science quality to it. The recurring promise is to “detect, understand and respond.”
By 2021, the register has hardened. Longo’s message is built around the language of misconduct, disruption, deterrence and enforcement. ASIC “will remain an active litigator against misconduct” and will “use our full suite of tools and powers to address wrongdoing.” Where 2016 wanted to understand behaviour, 2021 wants to identify, disrupt and deter it. This is the vocabulary of a post-Royal-Commission regulator that had been publicly criticised for being too soft.
By 2026, the language shifts again, this time toward balance and confidence. Court’s framing is that ASIC will be “easier to deal with for those trying to comply with the law, while being harder to avoid for those causing harm.” The plan repeatedly insists it does not have to “choose between strong regulation and growth”; it can and must have both. Words like productivity, growth, innovation and resilience now sit alongside enforcement. This is the language of a regulator that no longer feels it has to prove it can bite, and can therefore afford to talk about being a partner to well-behaved business.
Areas of focus: what each plan actually points at
The headline priorities tell their own story.
2016 organised itself around five “long-term challenges”: aligning conduct with trust and confidence; digital disruption and cyber resilience; structural change (led by the growth of superannuation); complexity driven by financial innovation; and globalisation. Notably, cyber is present but framed abstractly, as “digital disruption and cyber resilience,” an emerging theme rather than a live threat.
2021 reorganised around a cleaner set of external strategic priorities: promoting economic recovery (a COVID artefact); reducing consumer harm from poor product governance and scams “in a low-yield environment”; enhancing cyber resilience; and driving industry readiness for the wave of law reform flowing from the Royal Commission, including the Financial Accountability Regime, breach reporting, and design and distribution obligations. The through-line is implementing the Commission’s agenda.
2026 presents five strategic priorities: improving consumer and small business outcomes; strengthening professional conduct and access to reliable information; supporting better retirement and superannuation outcomes; supporting effective, resilient and innovative operations; and driving integrity, transparency and confidence across markets. Underneath sit focus areas that simply did not exist in comparable form a decade earlier: the impact of AI use, digital asset platforms, private credit practices including valuations and liquidity, mandatory climate reporting, and scam prevention and disruption as a first-order concern rather than a footnote.
Two structural moves are worth flagging. The first is that private markets and private credit have arrived as a headline preoccupation. The 2026 plan explicitly targets “changing risks, interconnectedness and supervision across private markets” and the distribution of private credit funds to retail clients. This reflects the migration of risk out of the well-lit public markets and into less transparent alternative investments, and it is arguably the single biggest new area of focus. The second is that AI appears on both sides of the ledger: as a risk ASIC must police (AI-driven market manipulation, deepfakes, unreliable financial information) and as a capability ASIC intends to use itself to regulate more effectively.
The risks identified
Read the risk framing closely and you can date each plan almost to the year.
In 2016 the shadow is the GFC. The plan states plainly that ASIC’s system “is not designed to eliminate market risk, prevent all wrongdoing, or ensure compensation for all investors who lose money,” a sober, almost defensive acknowledgement of the limits of regulation that reads as a direct lesson of 2008. Its economic environment section frets about household debt at record highs (186.9% of disposable income), property oversupply, soft commodity prices and global volatility. The animating concern is systemic fragility and the risk of another confidence-destroying shock.
In 2021 the shadow is the Royal Commission. The identified risks are overwhelmingly about conduct and consumer harm: poor product governance and design, scams, and the risk that firms fail to lift their standards to meet incoming reforms. The plan commits explicitly to working with government “to implement the law reforms responding to the Royal Commission.” Cyber has by now graduated to a standalone strategic priority. The animating concern is that the misconduct the Commission exposed might be allowed to persist.
In 2026 the concern is complexity, technology and interconnection. Its operating-environment analysis is the most sophisticated of the three. It warns that “operational risks are becoming increasingly system wide,” that reliance on shared service providers and platforms allows “disruptions to transmit rapidly across entities and sectors,” and that “uncertainty has become a structural feature” of a fragmented geopolitical and economic order. It names AI as transforming the environment, superannuation assets exceeding $4.5 trillion and consolidating into a handful of giant funds, climate-driven extreme weather pressuring insurance, and private credit as an opaque and growing risk. The animating concern is speed and contagion: in a digitised, interconnected system, harm now spreads faster than the regulator can see it.
How the plan is approached: from framework to focus
The three documents also differ in how they are built.
The 2016 plan is the most conceptual. It is heavy on the strategic architecture, the “detect, understand and respond” model, the “what good looks like” narrative for each sector, and the behavioural theory that underpins it all. It reads as a regulator explaining its philosophy.
The 2021 plan is more of a delivery plan. It splits neatly into external and internal priorities, ties itself tightly to the government’s Statement of Expectations and ASIC’s Statement of Intent, and organises its actions around discrete reform programs. It reads as a regulator executing an agenda largely set for it by others, namely the Commission and the Parliament.
The 2026 plan is the most operational and granular of the three. Under each of five priorities sit specific, named surveillance and enforcement activities: reviews of debt collectors, “disaster chasers,” buy-now-pay-later providers, separately managed accounts, private equity valuation practices, and wholesale broker preparedness for market shocks. It reads less like a philosophy and more like a work program from a regulator that knows exactly which doors it intends to knock on. There is also a new confidence in structure, including a “corporate plan on a page,” explicit budget forward estimates, and a clearer separation of the Chair’s executive authority from the Commission’s strategic role.
The signal from the Chair
If you read only the Chair’s foreword, you would still catch the drift of each decade.
Greg Medcraft (2016) signals a regulator focused on capability-building and understanding. His message is preoccupied with data: a new chief data officer, a data governance council, a behavioural insights team, and the additional government funding that would let ASIC run “more proactive surveillances.” The tone is that of an institution investing in its own intelligence, still finding its feet as a law-enforcement body.
Joseph Longo (2021) signals resolve and rehabilitation. His message is unambiguous that ASIC “will continue to be a strong and targeted law enforcement agency” and “an active litigator.” It is the voice of a Chair repositioning a regulator that had been found wanting, determined to demonstrate teeth while managing a heavy reform-implementation load.
Sarah Court (2026) signals confidence and balance. Her message leads not with enforcement but with productivity, growth and responsible innovation, and with the observation that “how we regulate is as important as what we regulate.” The enforcement posture is now taken as read; it is the settled foundation from which she can talk about being easier to deal with for the compliant. Given her own background as a litigator who spent five years rebuilding ASIC’s enforcement capability, this is a Chair speaking from strength rather than reaching for it, a regulator emboldened by a run of success in the courts and comfortable enough to lead with the carrot because everyone now knows about the stick.
A few other comparisons worth noting
Superannuation has moved from the wings to centre stage. In 2016 it was cited mainly as a driver of “structural change.” By 2026 it commands an entire strategic priority of its own, with $4.5 trillion in assets, an ageing population and 2.5 million Australians heading into retirement over the coming decade, plus a sharp new focus on high-risk lead generation and superannuation-switching misconduct.
Cyber’s promotion captures the decade in miniature. It appears in 2016 as one half of an abstract “digital disruption and cyber resilience” challenge, becomes a standalone strategic priority in 2021, and by 2026 is embedded across the plan. ASIC even commits to its own “multi-year cyber resilience program,” acknowledging that the regulator itself is a target.
The framing of business has also shifted. The 2016 and 2021 plans largely treat industry as a population to be surveilled and, where necessary, disciplined. The 2026 plan, without abandoning that stance, adds an explicit productivity-and-growth mandate handed down in a new Statement of Expectations, reflecting a broader political shift toward reducing regulatory burden. That tension, between protecting consumers and unlocking investment, is now stated openly as the central balance ASIC must strike.
And the regulator is simply bigger. ASIC’s total budgeted resources for 2026–27 sit near $688 million, up 7% year on year, with most costs recovered from industry under the industry funding model, a mechanism that barely featured in the 2016 framing. It is better funded and more explicitly resourced against named priorities than it was a decade ago.
What it means for regulated businesses
Read together, the three plans trace an arc. A regulator that in 2016 was still building the capability to understand, that by 2021 had been pushed to enforce, and that by 2026 is enforcing with confidence while being asked to enable growth.
For anyone operating in financial services, markets or consumer credit, the practical takeaways from the 2026 plan are clear. ASIC’s gaze has moved decisively toward private markets, private credit and alternative investments, toward the safe adoption of AI, toward operational and cyber resilience as systemic issues, and toward the protection of superannuation and retirement savings. It arrives at those targets as a regulator that no longer needs to prove it will litigate, because it already has.
The corporate plan has always been a signalling document. Ten years on, the signal is being sent by a more confident, better-resourced and more sharply targeted regulator than the one that wrote the 2016 edition in the aftermath of the financial crisis. Businesses that treat the plan as advance notice, rather than an annual formality, will be the ones best placed for the four years ahead.
PX Partners helps organisations interpret and respond to the regulatory environment. This article is general commentary based on ASIC’s published corporate plans and is not legal or compliance advice.