APRA and ASIC put FAR streamlining on the table

Fewer fields in a regulator-facing accountability map should not mean less clarity inside the business.

APRA and ASIC’s 2nd September 2026 proposal has outlined it will look to streamline the Financial Accountability Regime administration.

The risk-management implication is that firms must deliberately preserve decision rights, dependencies and escalation paths when a compliance artefact becomes simpler.

The 30-second take

APRA and ASIC propose removing prescribed key functions from the FAR Regulator Rules and no longer requiring direct reports in accountability maps.

The regulators estimate that about 4,500 accountable persons would be affected and map updates could be halved.

That will reduce administration, but it also may remove prompts that some firms have been relying on to keep accountability visible.

What happened

APRA opened its streamlining consultation on 31 August 2026, and APRA and ASIC announced the package publicly on 2 September. FAR has been operating for around 18 months. The agencies say the proposed changes respond to industry concerns about duplication and administrative burden while retaining the regime’s underlying accountability obligations.

The central proposals are to remove prescribed key functions from the regulator rules and to stop requiring information about an accountable person’s direct reports in accountability maps. The agencies estimate the first change would affect roughly 4,500 accountable persons. They also expect the changes could halve the number of map updates submitted to the regulators.

Submissions close on 2 October 2026. APRA and ASIC expect to settle final changes by the end of 2026, with implementation in early 2027. The consultation specifically asks whether the proposals could weaken accountability or create unintended consequences. That question should also be asked inside each affected organisation.

Why this matters for your business

Accountability maps serve two different purposes.

One is regulatory submission. The other is operational clarity: who decides, who advises, who executes, who monitors and who must act when an issue crosses business boundaries. The proposed reform changes the first purpose. It does not remove the second.

The risk is that firms treat a smaller submission requirement as permission to simplify their internal operating model. If direct-report relationships and key functions disappear from working maps without an alternative source of truth, leaders may lose visibility over shared processes, delegated authority and hand-offs between accountable persons.

That matters most during change and stress. A cyber incident may involve technology, operations, customer communications, legal and third-party providers. A product failure may move between design, distribution, complaints and remediation. A liquidity or data issue may begin deep in a process but require rapid executive escalation. Titles alone rarely explain who can stop activity, accept residual risk or resolve a conflict between functions.

The lesson extends beyond financial services. Any business can reduce a governance template while accidentally weakening the decisions the template made visible. A leaner committee paper, risk register or delegation schedule is useful only if the underlying authority and dependencies remain clear.

Where the risk can surface

The first failure pathway is silent deletion. A field is removed from the regulatory template, so the underlying information stops being maintained anywhere. Months later, a restructure or outsourcing decision leaves no current view of who owns a critical hand-off.

The second is false simplicity. One accountable person appears to own an outcome, while practical authority sits across several executives, committees or service providers. The map is neat, but the decision cannot be made quickly when tolerances are breached.

The third is version drift. Human-resources records, delegations, committee terms, process maps and FAR artefacts change at different times. A regulator may receive fewer updates, yet internal inconsistencies can grow unless one owner reconciles these records.

The fourth is assurance blindness. If second line and internal audit test only whether the required submission was made, they may miss whether actual decisions, escalations and hand-offs still match the stated accountability model.

What leaders should do now

The accountable executive for FAR should separate the regulatory map from the internal accountability architecture.

Decide which information can leave the external submission and which information must remain in an internal control record. Record the rationale before changing templates.

Business and risk owners should test important outcomes through real decision scenarios.

Choose a service disruption, customer-harm event, financial breach or supplier failure. Ask who notices it, who declares it material, who can stop the process, who informs the board and who confirms recovery. Any hesitation identifies a mapping gap that the streamlined rules will not solve.

Company secretariat and human resources should reconcile accountable-person statements, delegations, committee terms and role descriptions after every material restructure. The evidence should show the effective date, approver, affected dependencies and confirmation that hand-offs were understood.

Internal audit or an independent reviewer should examine whether map simplification removes useful control information. Their test should follow decisions across functions, not merely compare forms. Before the 2 October consultation deadline, firms should also provide APRA and ASIC with evidence of any unintended consequence that needs to be addressed in the final design.

Questions for your business

  • Which internal accountability information must we retain even if regulators no longer request it?
  • Can each critical incident be traced to a person with authority to decide and escalate?
  • Where do shared responsibilities create a gap between nominal ownership and practical control?
  • Who reconciles role statements, delegations, committees and process maps after change?
  • Will our assurance work test real decisions rather than the completeness of a template?

Use the Innovation of Risk to explore practical questions for accountability, decision rights and control evidence.

More from the Reading Room

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

When Fraud Syndicates Exploit Loan Processes: What Australia’s $600 Million Scam Reveals About Control Failures

NSW police allege a criminal syndicate defrauded banks of up to $600 million using false loan applications and insider help from accountants and money mules. This case uncovers how multi-party collusion exploits gaps in loan processes, demanding tighter fraud controls and cross-agency scrutiny.

APRA and ASIC put frontier AI, cyber and resilience on the board agenda

APRA and ASIC’s September 2026 superannuation roundtable summary shows why AI, cyber and supplier disruption should be tested as one compound event. Businesses need rehearsed authority to contain harm, operate through disruption and approve recovery.

APRA’s ING action is a blunt reminder: liquidity breaches are not just an internal issue

APRA’s 3 September 2026 action against ING Australia showed how a reported liquidity ratio near 160 per cent could conceal a materially lower position. Every business should govern critical metrics as controlled products with reproducible calculations, named ownership and escalation for uncertainty.