WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

A letter arrives from ASIC. It asks how you identified a particular obligation, who owns it, what controls sit behind it, and when those controls were last tested. You have thirty days.

Most Australian organisations can eventually assemble that answer. The problem is the word eventually. Three people spend a fortnight reconstructing from email, policy documents and memory something that should have taken an afternoon to export.

ISO 37301:2021 exists to close that gap. It is the international standard for compliance management systems, it is certifiable, and it applies to any organisation carrying regulatory, contractual or voluntary obligations. Nathan ISO Consulting implements it for Australian businesses operating in regulated environments, with the deepest concentration of our work in financial services.

Can you answer the four questions a regulator will ask?

Every regulatory enquiry we have watched play out resolves into the same four questions. A compliance management system is, in practical terms, the machinery that answers them quickly.

Which obligations apply to us?

Harder than it sounds. A mid-sized licensee typically carries obligations from primary legislation, regulations, licence conditions, regulatory guidance, industry codes, contractual terms and internal policy commitments. Very few organisations hold all of these in one place. ISO 37301 requires a compliance obligations register, and building it is the single largest piece of work in the whole project.

Who owns each one?

If the answer is "Compliance", you have a problem. Regulators expect obligations to be owned by people who actually perform the activity, with the compliance function providing oversight rather than substituting for accountability. A register with a single owner named against two hundred obligations tells an inspector that the business is not engaged with its own requirements.

What controls satisfy them?

This is where most registers break. An obligation is listed, a policy is referenced, and nothing connects the two to an actual control operating in a process. The test we apply is simple: pick an obligation at random and trace it to a control, then to evidence the control operated in the last reporting period. If that path breaks, you have a list, not a system.

How do you know the controls are working?

Through a compliance monitoring program with defined scope, frequency and methodology, agreed at board level and executed on schedule rather than after something goes wrong. Monitoring is the requirement organisations most often defer, and it is the one that turns a register from documentation into assurance.

ISO 37301, ISO 37001 or ISO 19600?

Three numbers get confused, and one of them no longer exists as a certification target.

ISO 19600 was guidance. It described good compliance practice but could not be certified against, which limited its usefulness for organisations wanting to demonstrate something to a third party. ISO 37301:2021 replaced it with a requirements standard that certification bodies can audit.

ISO 37001 is a different animal. It deals specifically with anti-bribery management systems, and it sits alongside rather than underneath ISO 37301. Organisations with genuine bribery and corruption exposure, typically those operating in higher-risk jurisdictions or sectors, sometimes hold both. The two integrate cleanly because they share the harmonised structure.

If a provider offers you certification to ISO 19600, that tells you something useful about the provider.

The regulators your obligations register has to cover

Australia distributes regulatory oversight widely, and organisations of any size answer to several bodies simultaneously. That fragmentation is exactly why a register beats a policy library.

RegulatorRemitWhat it looks for
ASICFinancial services and credit licensing, markets, corporate conductSection 912A licence obligations, the reportable situations regime, internal dispute resolution under RG 271
APRAPrudential supervision of banks, insurers and superannuation fundsRisk management frameworks, CPS 220, CPS 230 operational risk, CPS 234 information security
AUSTRACAnti-money laundering and counter-terrorism financingAML/CTF program, customer due diligence, transaction and suspicious matter reporting
ACCCCompetition and consumer protectionAustralian Consumer Law compliance, unfair contract terms, product safety, competition compliance programs
OAICPrivacy and freedom of informationAustralian Privacy Principles and Notifiable Data Breaches obligations
Fair Work OmbudsmanWorkplace relationsAward and agreement compliance, record keeping, wage compliance
ATOTaxationTax governance frameworks and justified trust reviews for larger taxpayers
Sector regulatorsAHPRA, ASQA, TEQSA, TGA and state licensing authoritiesSector licensing and conduct obligations, generally with their own audit regimes

Why financial services adopt first

Obligation density is the reason. A licensee carries general obligations under section 912A of the Corporations Act, including providing services efficiently, honestly and fairly and maintaining adequate risk management systems. Those are deliberately broad, and demonstrating them requires structure rather than assertion.

Layered on top sits the reportable situations regime, where the practical difficulty is rarely the report itself but having a system that reliably surfaces an incident, assesses it against the threshold, and documents the assessment whether or not it results in a report. The decision not to report is the one you will be asked to justify.

Internal dispute resolution under RG 271 generates complaints data, which is a compliance signal that most systems fail to ingest. The Financial Accountability Regime places accountability obligations on directors and senior executives, and accountability maps only hold up if a system underneath them shows the accountable person had visibility of what they are accountable for. AUSTRAC obligations sit somewhat apart with their own program requirements, and reforms have extended the regime to professions that have never had to think about it.

What we build, and the order we build it in

First Scope

Which legal entities, jurisdictions, licences and activities are in scope, and which regulators attach to each. One to two weeks, and it prevents an expensive discovery in month three.

Second The obligations register

The heavy lift, and typically four to eight weeks. Every applicable obligation identified, sourced back to its instrument, allocated to a named owner in the business, and mapped to the activity it governs. We build this from your licences, legislation, regulatory guidance, contracts and codes rather than from a sector template.

Third Compliance risk assessment

Obligations assessed for likelihood and consequence of non-compliance, producing a prioritisation your board will accept and your monitoring program can act on. Two to three weeks.

Fourth Control mapping and design

Existing controls mapped against obligations, gaps identified, new controls designed with the business rather than for it. Three to five weeks, and this is where the register stops being a list.

Fifth Governance, culture and reporting

Compliance policy, board and committee reporting, speak-up arrangements, role-based training and competence. Three to four weeks.

Sixth Monitoring and breach handling

The compliance monitoring plan, testing methodology, incident and breach framework, and corrective action process. Two to four weeks.

Seventh Audit and certification

Full internal audit against ISO 37301, findings closed, documented management review, then Stage 1 and Stage 2 with a JAS-ANZ accredited body. We attend both audits and close out findings ourselves. Five to eight weeks.

What makes our approach different

We allocate obligations to the business, not to Compliance

It creates friction during implementation and it is the single most important structural decision in the project. A register owned entirely by the compliance function fails its first regulatory test.

We document the decision not to report

Most frameworks document breaches that were reported. We document the assessment either way, because that is the record you need when a regulator disagrees with a threshold judgement made eighteen months ago.

We build the monitoring plan before certification, not after

A compliance management system with no monitoring evidence will pass a generous Stage 2 audit and fail its first surveillance. We would rather run the monitoring cycle before you certify.

We integrate rather than duplicate

If you already run CPS 230 machinery, an ISO 27001 system or an enterprise risk framework, the governance, audit and review structures exist. We extend them so evidence is produced once and used several times.

We stay for regulatory change

An obligations register is accurate on the day it is signed off and degrades from there. Ongoing maintenance is part of what we do rather than a renewal conversation.

Sectors and locations

Our compliance work concentrates in Sydney and Melbourne, where banking, insurance, superannuation and wealth management cluster, with substantial activity in Brisbane and Perth. Canberra work is weighted toward government suppliers and contracted service providers carrying flow-down obligations.

Beyond financial services we work with legal, accounting and professional services firms newly captured by AML/CTF obligations, aged care and disability providers, registered training organisations and higher education providers, health services, gaming and licensed venues, and energy retailers. Those clients sit across every capital city and in regional centres including Newcastle, Wollongong, the Gold Coast, Geelong, Toowoomba and Townsville.

Delivery is largely remote. We attend in person for obligation workshops, board and audit committee sessions, and Stage 2.

FAQ'S

ISO 19600 was guidance and could not be certified. ISO 37301:2021 replaced it with a requirements standard a certification body can audit and certify against. Systems built to ISO 19600 carry across in substance but need restructuring to meet the certifiable format.

ISO 37301 covers compliance management across every obligation your organisation carries. ISO 37001 deals specifically with anti-bribery management systems. They share the harmonised structure and integrate well, and organisations with real corruption exposure sometimes hold both.

No Australian regulator requires it. Organisations adopt it because it provides a defensible structure for obligations that are legally mandatory, and because it demonstrates to regulators, boards and counterparties that compliance is systematic rather than dependent on particular individuals.

Not directly. Section 912A obligations remain legal requirements resting with the licensee. A certified system gives you the structure and evidence to demonstrate those obligations are being met, which is what ASIC asks to see during surveillance activity.

They overlap across governance, accountability and monitoring. CPS 220 addresses risk management and CPS 230 operational risk and continuity. ISO 37301 handles the obligations layer. Built together they produce one evidence set rather than three.

The standard requires a compliance function with defined authority and direct access to the governing body, without mandating a role title or headcount. Smaller organisations often combine it with risk or legal, provided the independence and access are genuine rather than nominal.

The compliance function maintains it, but individual obligations must be owned by accountable people in the business who perform the relevant activity. A register where every obligation is owned by Compliance signals to a regulator that the business is disengaged.

Typically 20 to 32 weeks. The obligations register drives the timeline and takes longer where multiple licences or jurisdictions are involved. Compressing this phase produces a register that fails at the first audit or the first regulatory enquiry.

Yes. All three follow the harmonised structure and share governance, risk assessment, internal audit and management review. Regulated organisations commonly hold two or three and run them as a single integrated system with combined audits.

With scope rather than with a program document. Which designated services you provide determines which obligations apply, and that determination shapes customer due diligence, reporting thresholds and the program itself. Getting it wrong makes everything downstream wrong.

There is no automatic reduction. Certification provides documented evidence of a systematic approach, which is relevant to how a regulator assesses culpability and remediation. Treat it as a mitigating factor rather than protection.

All of them. Compliance work concentrates in Sydney, Melbourne, Brisbane, Perth, Adelaide and Canberra, with delivery largely remote and on-site attendance for obligation workshops, board sessions and Stage 2 audits.

Send us your licence conditions

Your licence conditions and a list of the jurisdictions you operate in tell us the shape of the obligations register faster than any discovery call will.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance