Skip to main content
Promotional banner for the pentest readiness checklist
Australia's MIS Reforms Expose Five Governance MythsRegulatory Obligations Management
5 min readFor GRC Leaders

Australia's MIS Reforms Expose Five Governance Myths

When two managed investment schemes collapsed in Australia, the investigations revealed a familiar pattern: governance frameworks that seemed adequate on paper but failed in practice. The Australian Treasury's consultation on MIS reforms, with submissions closing on 27 February 2026, dismantles several persistent myths about investment governance that extend far beyond Australia's borders.

These myths persist because they're comforting. They let boards check boxes without confronting hard questions about conflicts of interest, audit quality, or whether external oversight actually functions. The Shield Master Fund and First Guardian Master Fund collapses forced regulators to acknowledge what GRC professionals have long suspected: compliance theater doesn't prevent financial misconduct.

Myth 1: Generic Compliance Plans Are Sufficient If They Meet Minimum Requirements

Reality: Treasury's analysis found that responsible entities often used identical compliance plans across multiple schemes with different risk profiles and investment strategies. The Corporations Act currently requires only that plans be "adequate" without mandating scheme-specific procedures.

This approach treats compliance plans as regulatory paperwork rather than operational tools. When your compliance plan could apply equally to a property fund and an equity fund, it's not actually guiding risk management decisions. Treasury now proposes requiring detailed descriptions of each scheme's investment strategy and specific risk management processes.

The practical implication: your compliance framework must address the actual risks your organization faces, not theoretical risks that apply to your entire industry. If your SOC 2 system description could describe any SaaS company, you're writing for the auditor, not for your control environment.

Myth 2: Annual Compliance Audits Provide Meaningful Oversight

Reality: Australian law requires annual compliance plan audits by registered auditors but imposes no minimum qualitative standards for how those audits are conducted. Treasury identified this gap as a contributor to governance failures, noting that audits "may not provide the regulatory oversight expected."

This mirrors a broader problem in compliance auditing: the difference between checking whether controls exist and evaluating whether they work. An auditor can verify that you have a compliance committee without assessing whether that committee has the expertise, independence, or authority to challenge management.

Treasury proposes making existing audit and assurance standards mandatory for compliance plan auditors. For GRC leaders, the lesson is to impose your own quality standards rather than accepting minimum regulatory requirements. Your internal audit program should test control effectiveness, not just control documentation.

Myth 3: Compliance Committees Substitute for Board Independence

Reality: Current Australian rules allow responsible entities to skip having a majority of external directors if they establish a compliance committee instead. Treasury's proposal eliminates this option, requiring a majority of external directors on all responsible entity boards regardless of committee structure.

The rationale: compliance committees review and report, but boards make decisions. A committee composed of qualified members can identify conflicts of interest, but if the board majority has those same conflicts, the committee's findings get politely noted and quietly ignored.

This principle applies beyond investment schemes. Your data protection officer can flag privacy risks all day, but if your executive team's incentives favor growth over compliance, those risks remain unmitigated. Independent oversight requires decision-making authority, not just advisory capacity.

Myth 4: Related Party Transactions Are Acceptable With Disclosure and Approval

Reality: Australian law currently permits related party transactions if members approve them or if the transactions occur on arm's-length terms. Treasury now proposes prohibiting these transactions entirely for registered MIS, with limited exceptions for legitimate business needs.

This represents a fundamental shift from "disclose and approve" to "prohibit unless justified." The distinction matters because conflicts of interest aren't neutralized by disclosure. When your responsible entity invests scheme assets into companies controlled by board members, member approval doesn't eliminate the structural incentive to favor those investments regardless of merit.

GRC professionals face similar challenges with vendor relationships, particularly when procurement decisions involve companies where executives hold financial interests. Your conflict of interest policy should identify relationships that require prohibition, not just disclosure. Some conflicts can't be managed; they must be eliminated.

Myth 5: Minimum Capital Requirements Ensure Financial Stability

Reality: ASIC currently requires responsible entities to maintain AUD 150,000 in cash and either AUD 150,000 or AUD 10 million in net tangible assets under Instrument 2023/647. Treasury questions whether these thresholds adequately protect investors and whether the framework for setting requirements needs fundamental revision.

The consultation acknowledges that capital requirements involve trade-offs between investor protection and industry accessibility. Set them too low, and you allow undercapitalized entities to take on risk they can't absorb. Set them too high, and you restrict market entry to large established players.

This tension exists across regulated industries. Your cyber insurance policy has coverage limits that may or may not align with your actual risk exposure. Your professional liability insurance may meet regulatory minimums without covering the realistic costs of a data breach or compliance failure. Minimum requirements establish floors, not adequate protection levels.

What to Do Instead

Stop treating governance as a compliance exercise and start treating it as a control system. That means:

Make your compliance framework specific. Your risk register, control objectives, and compliance procedures should reflect your organization's actual operations. If your documentation could apply to any company in your sector, it won't guide decision-making when circumstances change.

Evaluate audit quality, not just audit completion. Whether you're managing SOC 2 readiness or preparing for ISO 27001 certification, assess whether your auditors test control effectiveness or simply verify documentation. Push back on auditors who treat walkthroughs as evidence of operating effectiveness.

Structure independence into decision rights. Advisory committees and oversight functions need authority to block decisions, not just raise concerns. Your privacy officer, compliance function, or risk committee should have escalation paths that bypass the executives they're monitoring.

Identify prohibitions, not just disclosures. Some conflicts of interest can't be managed through transparency. Determine which relationships, transactions, or arrangements create structural incentives that disclosure doesn't neutralize, then prohibit them.

Calibrate capital and resource requirements to actual risk. Regulatory minimums establish baselines. Your organization's risk profile, operational complexity, and potential impact scenarios should drive resource allocation decisions, not just compliance with minimum thresholds.

The Australian Treasury's proposals won't prevent every governance failure, but they acknowledge a fundamental truth: frameworks that allow organizations to check boxes while maintaining structural conflicts don't protect investors. The same principle applies whether you're governing a managed investment scheme, operating a SaaS platform, or managing third-party risk across a global supply chain.

Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide

You Might Also Like