Reflections from the Insight Exchange with Star Compliance

When I hosted James Balbas from StarCompliance and Vito Giudice from Ascentium Consulting, one thing came through loud and clear — regulatory overlap isn’t the exception anymore. It’s just the environment we work in now.

Overlap is now a feature, not a bug

Vito made the point early that regimes like the Financial Accountability Regime are deliberately designed to cut across the traditional prudential/conduct divide.  Regulators aren’t working in separate lanes anymore and a recent example is Bank of Queensland, where AUSTRAC and APRA issued enforceable undertakings on the same day for related issues, a clear signal of where this is heading.

For Australian compliance teams, this means the days of managing obligations regulator-by-regulator, framework-by-framework, are numbered.

Conflicts of interest as a case study in fragmentation

Conflicts of interest are a good example of overlap in miniature. One conflict can touch the Corporations Act, APRA’s expectations under CPS 511, and your own code of conduct — and, as Vito pointed out, each of those regimes defines and manages conflicts a little differently. Add in outside business activities, gifts and hospitality, and personal account dealing, and you quickly see why so many organisations end up with conflicts recorded in email, in spreadsheets, and in GRC systems, with no single source of truth.

It’s a data problem before it’s a policy problem

James put it plainly: most policies are actually pretty good. The gap is rarely the paper — it’s getting the right information to the right person at the right time. That challenge existed before AI, but it becomes existential with AI, because the value of any AI capability depends entirely on the quality and connectedness of the data underneath it.

From “policy exists” to “effective compliance”

The most useful reframe from today’s discussion, courtesy of Vito, was this: you can’t claim effective compliance without assurance testing. Having a policy is the start. Testing the design and operating effectiveness of your controls — and having a genuine remediation plan for the gaps you find — is what separates a documented framework from a demonstrable one.

That distinction matters enormously when a regulator comes knocking. As Vito observed from his enforceable undertaking work, and as the Star Casino findings illustrated, regulators increasingly scrutinise information flow — whether the right issues were surfaced, escalated, and acted on, all the way to the board.

Culture is the multiplier

No safeguard means much without the culture behind it. James and Vito kept coming back to this: compliance needs a seat at the table, leaders need to visibly back it, and good behaviour needs to be rewarded — with the bad called out. The organisations with genuinely strong compliance cultures aren’t the ones with the thickest policy manual — they’re the ones where compliance isn’t seen as “big brother,” but as a trusted business partner.

Where to start

If your team’s weighing up a tech or automation upgrade, James’s advice was refreshingly down to earth: sort your data first. Bad data in, bad insight out. And keep the human decision at the centre of automation for now — the sensible model is automating the evaluation and surfacing of information, while the sign-off stays with a person, at least for the next 12–18 months.

Vito’s single piece of advice for any compliance team wanting to get ahead of this complexity was simpler still: formulate a clear strategy, get governing-body buy-in, and execute against it consistently. Everything else — consolidation, technology, testing regimes — follows from that.

Want to watch the replay? Members can access past sessions here.