Compliance means following the laws, regulations, standards and your own policies so your organisation can operate within its legal and ethical obligations. It is fundamentally about managing risk, as Business, not filling out paperwork. We see this play out constantly in our work with Brisbane small businesses, where compliance usually gets treated as an afterthought until something goes wrong with data, finances or a regulator comes knocking.
TL;DR:
- Directors remain responsible, including sole directors; assign a named person to manage obligations, because outsourcing IT or commissioning an audit does not transfer that duty.
- APP 11 requires businesses to take reasonable steps to protect personal information and dispose of it when no longer needed, yet businesses often overlook disposal.
- Start with tested backups, multifactor authentication on email and finance accounts, and an owner for each control; verify restores quarterly instead of trusting success messages.
- Review obligations at least twice a year as laws and business operations change; train staff by role and keep policies short enough to follow.
Table of Contents
- What compliance actually covers
- Why compliance matters more than businesses think
- Who is actually responsible for compliance
- Key laws and standards worth knowing
- Building a compliance programme that actually works
- What we see when we walk into a new client site
- Where small business owners should actually start
- How we help Brisbane businesses get compliance sorted
- FAQ
- Sources
What compliance actually covers
Compliance is not one document sitting in a drawer. It is a set of moving parts: the laws and regulations that apply to your industry, internal policies that translate those laws into rules your team follows, procedures that explain how the rules get carried out day to day, controls that stop things going wrong, monitoring that checks the controls are working, and training so staff actually know what is expected of them.

Each business will have a different mix depending on what it does. A medical practice has health privacy obligations supported by robust record retention and access controls. A retailer deals with consumer law. Every business handling personal information has to think about the Australian Privacy Principles.
The practical skill is mapping each obligation to something concrete, not leaving it as an abstract legal requirement. Here is what that mapping looks like in practice:
- Privacy obligation under the APPs maps to a written privacy policy and access controls on customer data
- Workplace health and safety law maps to induction training and incident reporting procedures
- Financial reporting obligations map to record keeping systems and reconciliation schedules
- Consumer law obligations map to clear refund policies and accurate advertising review
Why compliance matters more than businesses think
Non compliance has real teeth. Directors can face personal liability, fines, loss of licences and reputational damage that outlasts any single incident. Operationally, a breach often means weeks spent on recovery instead of running the business.
On the other side, a working compliance programme makes audits faster, builds customer trust and gives you a paper trail showing you took reasonable steps when something does go wrong. That paper trail matters more than people expect.
The mistake we see constantly: business owners think a single audit, or a single security tool, equals compliance. It does not. Business.gov.au is clear that an effective programme is an active set of policies and training, not a static document you file once a year.
A missed detail with real consequences: under APP 11, businesses must take reasonable steps to protect personal information and properly dispose of it when it is no longer needed. Plenty of businesses we work with have never actioned that second half.
- Fines, director liability and licence loss are the hard costs of getting this wrong
- Reputational damage and client churn often outlast the actual incident
- A documented compliance programme speeds up audits and demonstrates due diligence
- Treating a single tool or one audit as “done” is the most common failure we see
Who is actually responsible for compliance
Directors carry legal responsibility for making sure a company meets its obligations. ASIC’s guidance on director duties is direct about this: directors must act with care and diligence, stay informed, keep proper records and avoid insolvent trading. Sole directors are not exempt. Many small business owners assume being the only person on the company register means these duties are optional. They are not, and that misunderstanding is one we encounter regularly.
Below the director level, responsibility splits into oversight and execution. Management assigns tasks and checks they are happening. Staff follow the procedures that have been written for them. In a business of 10 to 50 people, that often means one person, sometimes the office manager or finance lead, wears the compliance officer hat alongside their main job. That is fine, as long as the responsibility is clearly assigned rather than assumed.
- Directors hold ultimate legal responsibility, even as a sole director
- Management sets and monitors controls; staff execute the day to day procedures
- SMEs should formally assign compliance ownership, even if it is a part-time role
- Outsourcing IT or running an audit does not transfer legal responsibility away from the business
Key laws and standards worth knowing
You do not need a law degree to get the basics right. A handful of references cover most of what applies to small and medium businesses.
The Corporations Act sets out director duties, covered in detail by ASIC’s roadmap for directors. The practical check: are records being kept, and would you be comfortable showing them to an administrator if asked?
The Privacy Act and the Australian Privacy Principles govern how personal information is collected, used and stored. OAIC’s guidance requires reasonable steps to protect that information and to destroy or de-identify it once it is no longer needed. The check: do you have an up to date privacy policy, and can you actually restore the data you are supposed to be protecting?
The Competition and Consumer Act governs fair trading, advertising claims and consumer guarantees, and is the core reason business.gov.au recommends a formal compliance programme in the first place.
ASA 250, the auditing standard, clarifies that auditors consider compliance during a financial audit, but the responsibility for actual compliance sits with management, not the auditor.
- Corporations Act: check your record keeping would survive scrutiny
- Privacy Act and APPs: check your privacy policy is current and your backups are genuinely restorable
- Competition and Consumer Act: check advertising and refund practices against current rules
- ASA 250: understand that an audit is assurance, not a substitute for your own controls
Building a compliance programme that actually works
Most SMEs do not need a complex framework. They need a short, honest process that gets followed.
- List the obligations that actually apply to your business, not a generic checklist from the internet
- Write short, plain-language policies for each one, not twenty-page documents nobody reads
- Assign a named person to own each policy area
- Train staff on what matters to their role, not a once-a-year slideshow
- Test the controls: can you actually restore a backup, can you actually produce the records a director might need
- Log what you have done and review it at least twice a year, since obligations change as laws and your business change
On the technical side, this is where IT and compliance overlap directly. Verify backups by restoring them, not just checking a job completed. Turn on MFA across Microsoft 365. Patch on a schedule, not when someone remembers. Keep audit logs long enough to be useful, and restrict admin accounts to the people who actually need them. Our IT compliance checklist for Australian SMEs covers this in more detail.
Pro Tip: A backup job showing “success” every night tells you nothing. Test a full restore quarterly, or you won’t know it’s broken until you need it.
What we see when we walk into a new client site
Honestly, the pattern repeats across almost every new client. No MFA on admin accounts. Backups that have never been test-restored, so nobody actually knows if they work. Microsoft 365 tenants set up years ago with permissions nobody has reviewed since. Firmware on firewalls and switches that is years out of date.
We had a client who genuinely believed they were backed up because a green tick appeared in a dashboard every morning. Turns out, the backup software was saving to the wrong place, and nobody caught it for a long time. That is not an edge case, it is one of the most common findings we get in a sensitive data protection review.
- MFA, verified restores, patch cadence and access reviews fix most of what we find
- “Backed up” and “recoverable” are two different claims, and only one of them matters
- Retention and logging policies need to exist on paper, not just in someone’s head
Pro Tip: If nobody in your business can tell you the last time a backup was test-restored, assume it doesn’t work.
Where small business owners should actually start
Honestly, we see this a lot: owners want a compliance framework before they have fixed the basics. Start with backups you have actually tested, MFA on every account that touches email or finance, and a simple record of who owns what. Get those three right before worrying about frameworks. A short internal check, or a free assessment, will usually tell you more than another policy document will.
— Matt
How we help Brisbane businesses get compliance sorted
We handle the technical side of compliance so it stops being a guessing game. That covers managed IT support, backup and recovery, cyber security including advanced endpoint protection and firewall management, and risk assessment and compliance work tailored to Brisbane industries like financial services, healthcare and legal.
A free assessment gives you a plain list of gaps, which ones need fixing first, and a realistic sense of effort involved, no jargon, no inflated scope. If your Microsoft 365 environment or cloud setup needs attention alongside compliance, our Azure strategy and migration and cloud services teams work through that as part of the same conversation.
Get in touch through our contact page and we will walk you through what an assessment actually finds.
FAQ
What is the simple definition of compliance?
Compliance means following the laws, regulations, standards and internal policies that apply to your organisation, as the Cambridge Dictionary defines it at its simplest: obeying a law or rule. In a business context it extends to meeting industry standards and your own stated policies, not just legislation.
What is compliance in a job?
In a workplace, compliance means an employee follows the policies, procedures and legal obligations relevant to their role, such as privacy handling, workplace safety or financial record keeping. Responsibility for setting those rules sits with management and directors, while staff are expected to follow them day to day.
What are examples of compliance?
Common examples include privacy policies that meet the Australian Privacy Principles, workplace health and safety procedures, accurate financial reporting, and advertising practices that meet consumer law. Data security measures like verified backups and multi-factor authentication are increasingly treated as part of meeting privacy obligations.
What does compliance in a company mean?
For a company, compliance means directors and management have put in place policies, training and monitoring that meet legal obligations such as those under the Corporations Act and Privacy Act. ASIC guidance confirms directors carry legal responsibility for this, even in a small company with a sole director.
Sources
- Business
- Managing your director obligations | ASIC
- Guide to securing personal information | OAIC
- ASA 250 — Consideration of laws and regulations in an audit of a financial report

