ASIC’s Record $830 Million Enforcement Year: What Queensland Directors and Business Owners Must Know

Key Takeaways

  • ASIC secured a record $830 million in civil penalties for the 2025-26 financial year — the highest in its history.
  • The regulator recorded 25 criminal convictions, with 21 custodial sentences including 11 individuals imprisoned.
  • ASIC launched more than 250 investigations and filed 32 new civil proceedings in 2025-26.
  • $644 million is being paid back to Australians through remediation and refunds connected to ASIC enforcement action.
  • The enforcement trend is unmistakable: ASIC is acting faster, targeting systemic failures, and pursuing criminal outcomes at record rates — and Queensland directors are not immune.

On 20 July 2026, ASIC confirmed what many in the legal and commercial community had sensed for some time: we are living through the most active enforcement period in Australian corporate regulatory history. ASIC secured court orders totalling $830 million in civil penalties for the 2025-26 financial year, up from already record levels in prior years. Alongside that, 25 criminal convictions were recorded against individuals, with 21 custodial sentences imposed.

This is not abstract financial services news. For Queensland directors, business owners, and company advisors, it represents a significant shift in the regulatory environment in which businesses now operate — and the personal risks that flow from it.

If ASIC’s enforcement priorities have you concerned about your exposure as a director, our insolvency lawyers Brisbane advise directors, creditors, and companies navigating ASIC investigations, insolvent trading claims, and director liability. Call Boss Lawyers on 1300 267 711.


This is general information only and is not legal advice. You should obtain professional advice specific to your circumstances.

What ASIC Achieved in 2025-26: The Numbers

According to ASIC media release 26-162MR (published 20 July 2026), the regulator’s enforcement and regulatory figures for the 2025-26 financial year include:

  • $830 million in civil penalties imposed by courts (comprising $350 million in the first half and $480 million in the second half of the financial year)
  • $643.5 million to be delivered back to tens of thousands of Australians through remediation, refunds, and payments connected to ASIC’s work
  • More than 250 investigations launched
  • 32 new civil proceedings filed and 18 new criminal prosecutions commenced
  • 25 criminal convictions recorded — comprising 21 custodial sentences (including 11 individuals sentenced to imprisonment) and four non-custodial sentences
  • $12 million in infringement notices issued and $137,315 in criminal fines

ASIC Chair Sarah Court described the enforcement posture plainly: “Our enforcement work is focused on misconduct that causes real harm and we are delivering results, forcing change, strengthening accountability, and returning money to consumers and investors.”

Who Was Targeted — and Why It Matters Beyond Financial Services

The major civil penalties secured in 2025-26 include:

  • Union Standard International Group — $300 million (record) for contracts for difference misconduct affecting retail investors
  • HSBC Bank Australia — $35 million for scam protection failures
  • Macquarie Securities — $35 million for systemic short sale misreporting and inaccurate market data
  • Westpac — $26 million for widespread failures in responding to customer hardship requests
  • Walker Stores (Snaffle) — $33.5 million for unlawful credit practices overcharging consumers nearly $20 million
  • Mercer Super — $10.3 million for systemic reporting failures including failure to notify ASIC of significant breaches

While several of these cases involve large financial institutions, the pattern they reveal — and ASIC’s stated enforcement priorities — has direct implications for smaller operators, company directors, and Queensland-based businesses. ASIC is not limiting its focus to the big banks. It is pursuing systemic failures, misleading conduct, governance breakdowns, and failures to notify or report wherever they occur.

The Criminal Enforcement Trend: 25 Convictions in One Year

The criminal outcomes in 2025-26 are particularly significant. ASIC recorded 25 criminal convictions for the financial year, with 21 involving custodial sentences. Notable outcomes include:

  • Rodney Forrest — resentenced to five years and three months imprisonment by the Full Federal Court for a $3 million insider trading scheme involving Platinum Asset Management shares
  • Anthony Torre — sentenced to six years in prison for fraud involving misappropriation of superannuation funds
  • Remedy Housing officials (Brent Smith, Mahmoud Khodr, and Fue Mano) — sentenced to lengthy imprisonment for dishonesty offences

The message from the courts is consistent: where directors and officers cause serious harm through dishonest conduct, imprisonment is on the table. This follows the record 25 criminal convictions figure for FY2025-26, which the regulator has described as representing an “uplift” in criminal outcomes.

What This Means for Queensland Directors: Five Practical Implications

Queensland directors and business owners should read the 2025-26 ASIC enforcement results through a practical lens. Here is what the record enforcement year reveals about how regulators are operating in 2026.

1. Systemic Failures Are the Primary Target

ASIC Chair Court specifically mentioned “serious failures in systems, governance and conduct” as the focus of enforcement. This means that isolated or one-off errors are less likely to attract attention than patterns of non-compliance, inadequate oversight, or failures in governance processes. For directors, this reinforces the importance of having documented systems for compliance, board oversight, and breach reporting — not just good intentions.

2. Reporting Failures Are Pursued Aggressively

The Mercer Super outcome ($10.3 million) for failing to report significant breaches to ASIC is a warning to all companies with reporting obligations. Under the Corporations Act, companies holding an AFSL, registered managed investment schemes, and publicly listed companies have mandatory breach reporting obligations. The failure to report is itself a serious offence, separate from the underlying breach. Queensland-based companies in financial services, funds management, or with listed entities should review their breach identification and reporting processes immediately.

3. Consumer Protection and Scam Failings Are Under the Microscope

The HSBC outcome ($35 million for scam protection failures) signals that ASIC is holding businesses accountable for how they protect customers from third-party fraud. While this is primarily a financial services issue, any business that takes consumer payments, operates a digital platform, or has customer-facing financial operations should consider its scam risk governance. The Westpac outcome ($26 million for hardship failures) reinforces that customer vulnerability obligations are being enforced strictly.

4. The Director Lens: Personal Liability Follows Corporate Failures

When a company faces ASIC enforcement action, directors are often simultaneously under scrutiny. ASIC’s enforcement model targets companies and the individuals who were responsible for the relevant governance or conduct failures. Under sections 180-184 of the Corporations Act, directors owe duties of care, good faith, and honest conduct. Where corporate failures can be traced to inadequate director oversight — whether through passive acceptance, wilful blindness, or active dishonesty — ASIC has demonstrated a willingness to pursue individual enforcement action alongside the corporate penalty.

5. ASIC Has More Resources and Is Using Them

The 250+ new investigations launched in 2025-26, combined with 32 new civil proceedings and 18 new criminal prosecutions, shows a regulator operating at peak capacity. ASIC has described this as part of a sustained enforcement commitment, not a one-year spike. Queensland directors should assume that the enforcement environment in 2026-27 will be at least as active.

The Governance Checklist: Six Things Queensland Directors Should Review Now

Against this backdrop, directors of Queensland companies — whether large or small — should consider the following governance review:

  1. Board oversight of compliance systems: Can your board demonstrate that it actively monitors the company’s compliance with its legal obligations? Are there documented board papers, minutes, and escalation processes?
  2. Breach reporting processes: If your company has statutory reporting obligations (AFSL, ASX listing, superannuation), do you have a process for identifying, escalating, and reporting significant breaches within required timeframes?
  3. Director duties review: Have your directors completed a review of their obligations under ss 180-184 of the Corporations Act in the last 12 months? The criminal end of s 184 (dishonest use of position or information) carries penalties of up to five years imprisonment and/or 2,000 penalty units.
  4. Consumer-facing obligations: If your business deals with consumers, are your sales representations, pricing practices, and complaint handling processes compliant with the Australian Consumer Law?
  5. Financial reporting and disclosure: If you are a public or listed company, are your continuous disclosure and financial reporting obligations being met? The Macquarie Securities ($35 million) and Electro Optic Systems ($4 million) outcomes demonstrate the consequences of disclosure failures.
  6. Personal protection: Do directors have adequate D&O insurance, and have they verified that the policy covers both civil and criminal proceedings? As ASIC’s criminal enforcement escalates, the distinction matters.

When to Seek Legal Advice

Directors and companies should seek legal advice promptly in any of the following circumstances:

  • Receipt of an ASIC investigation notice, compulsory examination summons (section 19), or document production requirement
  • Identification of a potential breach of the Corporations Act or ASIC Act that may trigger mandatory reporting obligations
  • Any ASIC contact — including informal inquiries — relating to company conduct, financial reporting, or director behaviour
  • Discovery of potential misconduct by another director or officer of the company
  • Any situation in which a director’s personal conduct is under internal or external scrutiny

Early legal advice is critical. The window to manage an ASIC investigation — or to avoid it escalating to formal proceedings — is always narrower than it appears.

Frequently Asked Questions

Can ASIC investigate small private companies in Queensland?
Yes. ASIC has jurisdiction over all companies registered under the Corporations Act 2001 (Cth), regardless of size or revenue. While large financial services firms attract the highest profile enforcement action, ASIC investigates director misconduct, insolvent trading, creditor-defeating dispositions, and governance failures across companies of all sizes.

What triggers an ASIC investigation?
ASIC investigations are typically triggered by complaints from creditors, investors, liquidators or administrators; compulsory reports from external administrators under section 533 of the Corporations Act; tip-offs from the public or other regulators; media reports; or ASIC’s own intelligence and market surveillance activities.

What is a section 19 examination?
A section 19 examination is a formal compulsory examination conducted by ASIC where the person summoned must answer questions under oath. Legal representation is permitted, but legal professional privilege protections are limited. Answers can be used in subsequent civil or criminal proceedings. If you receive a section 19 summons, you should obtain legal advice immediately.

Are directors personally liable when ASIC takes action against their company?
Directors can be pursued individually and separately from the company. ASIC may seek civil penalties against individual directors under sections 180-184 of the Corporations Act, or refer matters to the Commonwealth Director of Public Prosecutions (CDPP) for criminal prosecution. Resignation as a director does not necessarily end personal liability for conduct that occurred during the directorship.

How does the 2025-26 ASIC enforcement record affect D&O insurance?
The escalating penalty environment may affect D&O insurance premiums, coverage limits, and exclusions. Directors should review their policies with a broker to ensure coverage extends to ASIC investigation costs, civil penalties (where insurable), and criminal defence costs. Many policies have specific carve-outs for intentional or fraudulent conduct.


This is general information only and is not legal advice. You should obtain professional advice specific to your circumstances before taking any action in response to ASIC contact or regulatory matters.

Directors and officers under ASIC scrutiny frequently face concurrent commercial litigation — including creditor claims, insolvent trading actions, and shareholder disputes. Boss Lawyers provides strategic advice to directors navigating ASIC enforcement. Contact our commercial litigation lawyers Brisbane for a confidential consultation.

Mark Harley
Principal Solicitor, Boss Lawyers
17+ years experience in commercial litigation, director disputes, and corporate governance
Get a confidential consultation | 1300 267 711

Search
Recent Posts