Are you turning compliance into strategic capability?
As usual, the annual Australian Institute of Company Directors (AICD) Essential Director Update at the ICC Sydney on 21 October was a great pulse check on the macro themes driving effective governance for Australian businesses.
Keynote talks by Penny Bingham-Hall (NED, Fortescue) and Bruce Cowley (NED, Australian Retirement Trust), were followed by a panel led by Paul Merrill (Head of Content, AICD) with Penny, Bruce, and Donna-Maree Vinci (NED, NGM Group).
Most of the themes discussed have been in progress for a while and are largely driven by market dynamics (you can check out my 2024 EDU and 2023 EDU posts for more).
These interconnected themes are reshaping director responsibilities.
Climate, AI, data, and cyber governance have moved from a nice to have – to core strategic priorities through stakeholder expectations and backstopped by regulators. This requires effective and high performing boards.
“The director’s role is now foresight as well as oversight. Don’t get stuck in a bubble of thinking that what’s worked well in the past will continue to work well in the future.”
Bruce Cowley quoting Naomi Edwards, AICD Chair
Expectations have changed.
Expectations to Opportunity
It’s clear that talent, customers, investors, and regulators – and the community more broadly – have higher expectations of companies and leaders than they have in the past.
Regulators aren’t first movers. They typically respond to market failures, emerging risks, and established practices to protect system stability when there’s enough consensus and expectation on minimum standards that need to be baselined and enforced.
The shift has been happening for a while and it shouldn’t come as a surprise.
The reality is diverse stakeholder groups increasingly expect businesses to do the right thing by people and the planet… AND still achieve traditional business performance outcomes.
With this change in expectations, the risk profile has changed. Not just reputational risk but material financial risk. A higher bar of what good business looks like.
These requirements need to be embedded in strategy and core business with the CEO, CFO, COO, and ultimately the board being accountable.
The only real decision is how to respond to these expectations… and legal requirements.
Waste time and energy resisting these changes and treat them as a compliance burden…
Or take it as an opportunity to innovate, do better business, and transform compliance into strategic advantage.
To rapidly transition to more regenerative ways of living and doing business.
What are the themes?
4 Core Themes
The focus of these themes are on business performance and governance at the board level, with directors being ultimately accountable.
But they’re just as relevant – maybe more so – for leaders and teams throughout the organisation. The people who need to deliver on these requirements by designing and building process, systems, and organisational capability to make them a reality.
Climate Governance & Mandatory Reporting
Penny opened with a powerful message: we’ve moved “from morality to materiality” in climate governance. Australia’s mandatory climate-related financial reporting regime is now live.
In case you’re not already familiar, there’s a phased rollout of the mandatory reporting. There are some other requirements and some exceptions, but here’s a brief summary of how it’s being rolled out.
Group 1
Mandatory reporting for Group 1 companies started from 1 January this year. These are companies (or the Australian reporting entities of multinationals) who match at least two of these three criteria: $500m+ revenue, $1b+ assets, 500+ employees – roughly equivalent to the ASX 200.
A lot of these companies have been doing voluntary disclosures over the last 10-15 years, but now they need to comply with the AASB S2/ASRS standard and formally declare their methods and assumptions to ASIC as the regulator.
From next year, Group 1 companies will also be required to formally report on Scope 3 (value-chain emissions). If you have Group 1 customers, even if you aren’t required to report, you’ll probably be asked for at least some basic data. If you haven’t already.
The cascade is already happening.
Group 2 & Group 3
Group 2 companies ($200m+ revenue, $500m+ assets, 250+ employees) start reporting from 1 July 2026. If you’re in Group 2, you’ve got eight months to make sure you’re ready.
Group 3 companies ($50m+ revenue, $25m+ assets, 100+ employees) start reporting from 1 July 2027. If you’re in Group 3 you’ve got 20 months and a great opportunity to do a dry run next year.
There’s a high likelihood your supply chain will ask you for basic climate data before your reporting period officially starts.
This means immediate action is needed.
Phased Increase in Requirements
Another aspect of the phased rollout is that the company’s sustainability report for the first year only requires disclosure of Scope 1 and 2 emissions but from year two forward, Scope 3 is also required.
For the first three years, directors give a qualified “reasonable steps” declaration. From year four, this shifts to the standard directors’ declaration of compliance under the Corporations Act and AASB S2.
ASIC has said they’ll take a pragmatic, supportive approach early – prioritising guidance to help entities get compliant with the new sustainability reporting rather than jumping straight to heavy penalties. As long as they believe you’re acting in good-faith.
I think this is a sensible phasing in of mandatory climate reporting. It recognises this is a fundamental change in the disclosures required. It’s about transparency and risk. For now, it doesn’t even require businesses to set targets and deliver on them.
It’s expected the market will do the heavy lifting as supply chains, investors, lenders, and insurers increasingly demand credible transition plans with measurable targets.
The direction is clear… companies will face growing pressure to publish and deliver credible emissions-reduction and transition targets as part of good governance and access to capital.
The transition has started. Are you ready?
Organisational Transition Planning
This isn’t just an environmental issue — it’s strategic business transformation. The work is about integrating climate action into core business strategy, risk management, and long-term value creation.
Penny framed the board’s role in organisational transition planning through six practical questions:
- Has your board reviewed a comprehensive assessment of how climate-related risks and opportunities may impact the organisation’s business model, strategy, and financial position?
- Does your board have the capability and confidence to critically assess climate-related advice and assumptions from management or advisers?
- Has your organisation engaged in meaningful consultation with key stakeholders – including vulnerable or underrepresented groups – and does the transition plan include strategies for ongoing engagement?
- Is your organisation’s strategic ambition achievable, credible, and aligned with its purpose, and long-term business strategy?
- Are your governance structures, decision-making processes, and reporting lines appropriate to support delivery of the transition plan’s objectives?
- Are there defined processes in place to monitor progress, review the plan and respond to material developments or emerging risks?
Technical climate and environmental expertise is a critical component but it’s not actually the biggest challenge or most critical element.

Source: Governing for net zero: The board’s role in organisational transition planning. Penny Bingham-Hall. AICD EDU 2025
This requires building leadership capability, engagement with diverse stakeholder groups, and strategic design and innovation of governance structures with integrated processes, teams, and systems to put it in action.
These are the things we specialise in at Dynamic4.
AICD resources to help:
- Governing for net zero: The board’s role in organisational transition planning – covers the board’s role in understanding risks, building leadership capability, developing strategic ambition, and monitoring progress
- Director’s guide to mandatory climate reporting (Version 2) – practical guidance for directors overseeing their organisations’ disclosures under Australia’s mandatory climate reporting laws
AI Governance
The pace of change is accelerating – what seemed only possible a year ago has already been surpassed.
The key message for directors was don’t wait to be an AI expert before engaging. Start with personal experimentation but understand where and how AI is being used in your organisation. Is it part of a coherent enterprise strategy, or just individuals using it on their own devices?
Research shows directors and management often have little awareness of who, how, and why employees are using AI. The board’s role is to set risk appetite and approve policies without stifling innovation.
“Start small, go fast, and think big”
Penny Bingham-Hall quoting an AI expert
There’s understandable fear about machines replacing humans – and job losses are real.
This creates a crucial director responsibility to carefully navigate this transition while looking after people. It means developing clear policies, educating employees about appropriate use, and being clear about where accountability sits.
AICD resources to help:
- Directors’ Guide to AI Governance – covers roles and responsibilities, governance structures, principles and policies, and monitoring frameworks
- Effective board minutes and the use of AI: A joint statement – practical guidance on using AI for board administration
Data Governance & Cybersecurity
Penny’s closing theme brought everything together, data is at the centre of everything. Leaders who don’t use and share data – and take advantage of AI’s power – will get left behind.
But AI systems require data integrity – data that’s accurate, complete, consistent, and timely. Boards need to understand not only what data is strategically important, but who is responsible as the data steward.
Incomplete or outdated data can produce hallucinations in AI models – essentially automating stupidity.
The five principles from AICD’s Data Governance Foundations for Boards provide a helpful framework:
- Key organisational data is a strategic asset
- Define clear data governance accountability
- Manage the data lifecycle and effective risk management
- Empower a data-driven organisational culture
- Enable effective data incident response and recovery
On cybersecurity, the message is clear: cyber-attacks are a case of when, not if.
The best defence includes staying informed about vulnerabilities, agreeing risk appetite with appropriate controls, getting external assurance, and preparing through crisis management exercises.
The Essential Eight cybersecurity framework developed by the Australian Cyber Security Centre provides a good management tool for measuring organisational maturity.
Key risks to mitigate include legacy systems, third-party vendor vulnerabilities, and human error – which is still the top risk.
AICD resources to help:
- Data Governance Foundations for Boards – principles for treating data as a strategic asset
- Cyber Security Governance Principles (Version 2) – practical guidance on risk-based approach to security
Board Effectiveness
Bruce Cowley’s presentation focused on good governance under pressure – a timely reminder that even our most established practices need constant attention.
For directors, he posed these nine questions:
- How well structured is your skills matrix?
- Are you identifying existing skills and characteristics of your existing board members accurately?
- Have you articulated clearly enough what skills you need on the Board and are you using the matrix appropriately in succession planning and in developing training for Board members?
- Are your Board packs too long and how can they be shortened without reducing the presentation of all material information you need to make the best decisions?
- How can you use delegations and Committees more effectively to take the pressure off Board meetings?
- How confident are you that you have captured all strategic and material risks confronting your organisation?
- How nimble is your Board at responding to major issues when they arise?
- How well do you know the culture of your organisation? Are there cultural flaws lurking that could take things off the rails?
- If you’re contemplating a director role at a founder-led organisation, make sure you do comprehensive due diligence and ask yourself if taking on the role is worth the risk
AICD resources to help:
Let’s Collaborate
Dynamic4’s purpose is to help accelerate the transition to more regenerative ways of living and doing business.
We do this by working alongside leaders and their teams to help build internal capability that transforms complexity and compliance into confident strategic advantage through regenerative leadership, design, and innovation with a focus on purpose and wellbeing.
This results in business models, products, and services that are more regenerative. Solutions that customers and teams love, make money, do great things for people and our planet, and increase wellbeing.
Delivering real work while helping build internal capability.
We specialise in three integrated solution areas:
🌎 Climate reporting capability. Leverage compliance as a catalyst for faster, more reliable reporting, stronger leadership and team collaboration, new growth opportunities, and regenerative transformation that turns compliance into competitive advantage.
🚀 Leadership development. Resilient and engaged leaders and teams who are able to navigate complexity and creatively solve real-world problems, make better decisions, and build the relationships, workflows, rhythms, and habits for success.
🧩 Strategic design & innovation. Design and deliver solutions that drive business performance while creating meaningful value for all stakeholders – using a guided human-centred design and living systems approach that connects strategy with reality.
Keen to chat about how we can have fun collaborating to solve problems that matter? Book a free 15-minute discovery call.






