Assurance audits used to be a tick-the-box exercise. They are not anymore. With the Australian Energy Regulator (AER) refreshing its Compliance Procedures and Guidelines and releasing an updated Practice Guide for Compliance Audits last year energy retailers in Australia are operating in a sharper, more evidence-driven assurance environment than at any point in the National Energy Retail Law’s history.
This post explains, in plain English, what an assurance audit looks like under the current settings, where the AER is looking hardest in 2025/26, and how Australian energy retailers can prepare without burning out their compliance teams.
What is an assurance audit, in the AER’s words?
An assurance audit is an independent review of an authorised retailer’s compliance policies, procedures and systems and a sample of their operation in practice. The AER may either carry out a compliance audit itself or, more commonly, require a retailer to carry one out, in accordance with the Compliance Procedures and Guidelines and the Practice Guide for Compliance Audits.
The audit answers three questions:
- Does the retailer have policies, procedures and systems that, on paper, comply with the National Energy Retail Law, the Rules and any conditions of their authorisation?
- Are those policies, procedures and systems actually being followed in day-to-day operations?
- Where the answer to either is “no”, what has the retailer done about it?
The deliverable is an assurance report rated against AER expectations and signed off by an independent auditor. It is, increasingly, the document that boards, investors and regulators read first.
What changed with the February 2025 Practice Guide
The AER’s 2025 Practice Guide sharpens a few things that retailers can feel in the way audits are now being scoped and delivered:
- Independence is taken more seriously. The expectation that the auditor is independent of the compliance function being audited is now stated more clearly, with practical guidance on what independence looks like for in-house and outsourced compliance teams.
- Sampling and evidence are front and centre. The Practice Guide leans into testing of actual records (billing, hardship interactions, life support flags, marketing scripts) rather than relying on what the policy says the retailer does.
- Root-cause analysis matters. A finding is not closed by a procedure update alone. The AER wants to see why a control failed and what systemic change has been made.
- Findings are rated. Audits should clearly state the significance of each finding so the AER (and the retailer’s own board) can prioritise remediation.
For practical purposes, the bar for an “acceptable” assurance audit report has lifted. A short narrative confirming compliance is no longer sufficient; the audit should evidence its conclusions.
Where the AER is looking in 2025/26
The AER’s 2025–26 Compliance and Enforcement Priorities tell every authorised retailer exactly where the spotlight is. The headline themes are:
- Customers experiencing vulnerability and hardship. The AER expects hardship policies to be applied consistently, payment plans to reflect capacity to pay, and benefits to continue when a hardship customer leaves the retailer.
- Life support customers. Registration, de-energisation safeguards and ongoing verification remain a perennial focus, with serious detriment treated as an enforcement issue, not a paperwork one.
- Customers affected by family violence. The AER continues to monitor compliance with the family violence protections in the Rules.
- Explicit informed consent (EIC) and marketing conduct. Long-standing focus areas that continue to surface in assurance audits and compliance reports.
Two further changes loom in the audit horizon for 2026:
- From July 2026, retailers will need to provide more information about concessions and rebates more regularly. Expect this to be a topic in next year’s audits.
- From December 2026, hardship customers should pay no more than their deemed better offer, where one is available. Audits commissioned after this date will reasonably test the controls that make this real for customers.
Where most retailers come unstuck
From our experience supporting Australian retailers and embedded networks through assurance engagements, the common shortfalls are not exotic. They are mundane and operational:
- Policy documents that say one thing while the contact centre script says another.
- Hardship procedures that lack triage criteria, so similar customers receive materially different outcomes.
- Life support registers that do not reconcile cleanly to the metering and billing systems.
- Marketing compliance frameworks that have not kept pace with new digital channels.
- Issue registers that capture incidents but never close the loop with a root cause and a control change.
None of these are fatal. All of them are detectable by an honest assurance audit and fixable in weeks, not quarters, with the right scoping.
How to prepare without overwhelming your team
The temptation, after reading the Practice Guide, is to scope an “everything” audit. We would gently push the other way. The retailers we see succeeding in 2026 take a different approach:
- Pick the topics that matter most. Use the AER’s stated priorities and your own incident data. A focused review of five topics, well evidenced, will tell you more than a thinly spread review of fifteen.
- Test against the system, not the policy. Pull samples from billing, complaints, hardship and life support records. If the audit cannot reconcile to source systems, it has not really tested compliance.
- Document root causes, not just controls. A finding closed without a clear cause will reappear in the next audit.
- Brief the board early. Assurance reports should not be a surprise. The conversation with the board is easier when they have seen the scope, the criteria and the early observations.
- Close the loop in your AER compliance reporting. The same controls that pass an assurance audit are the ones that produce reliable quarterly and half-yearly reports.
How Compliance Quarter helps
Compliance Quarter has supported energy retailers and embedded networks through assurance engagements ranging from authorisation readiness through to mature post-incident reviews. Where it helps, we now offer assurance work on a defined-scope, fixed-price basis through our fixed-price services.
- Assurance Audit (up to five topics) for authorised retailers wanting an AER-aligned independent review with a board-ready report.
- Policy and Procedure Set for retailers and exempt sellers needing a complete, current compliance suite.
- Exempt Seller Starter Pack for embedded networks and exempt sellers establishing operations.
If you are about to seek a new retail authorisation, or if your last assurance audit predates the February 2025 Practice Guide, this is the year to bring your assurance program up to the current line. We are happy to scope a focused engagement that does that without consuming your operational team.
Frequently asked questions
How often does the AER require an assurance audit?
There is no fixed cadence in the Law. The AER can require an audit at any time, and authorisation conditions may also mandate periodic audits. Many retailers run an independent assurance review annually as part of good governance.
Who can act as the independent auditor?
The Practice Guide expects the auditor to be functionally independent of the compliance activities under review. That can be an external firm or, in some cases, an internal audit function that does not report into the compliance team.
What is the difference between an assurance audit and a compliance audit?
In practice the terms are used interchangeably. The AER’s Practice Guide governs both. “Assurance audit” tends to be the language used by boards and auditors; “compliance audit” tends to be the AER’s term.
How long does an assurance audit take?
A focused five-topic audit typically runs four to six weeks from scoping to final report. Broader programmatic audits can take three to six months depending on the size of the retailer.
What does the AER do with the audit report?
For audits the AER has required, the report is provided to the AER and informs its supervisory and enforcement activity. For voluntary assurance audits, the report stays with the retailer and is typically used by the board, the executive and, where relevant, in regulatory engagement.
Talk to us about your next audit
If you are scoping your next assurance audit, refreshing your policies for 2026, or simply want a second opinion on where the AER is most likely to push next, contact Compliance Quarter or call (02) 8001 6664. We will come back to you with a fixed scope, a clear timeline and a quote inside one business day.



