Implementing an Effective Compliance Management Framework in Energy Retail

Twitter
LinkedIn
Facebook

Energy retail is one of the most highly regulated sectors in Australia. Retailers must navigate a web of national and state laws, industry codes, and licence conditions – all enforced by multiple regulators – making compliance a complex task​. An effective compliance management framework is therefore essential to avoid legal penalties and reputational damage; in fact, failing to comply can cost millions in fines or worse, result in loss to consumers and severely harm an organisation’s reputation​.

To assist businesses in managing these obligations, international standards like ISO 37301:2021 (Compliance Management Systems) and its predecessor AS ISO 19600:2015 (Compliance Management Guidelines) provide structured guidance. This article explains how energy retailers can apply these standards in practice, with a focus on governance, risk assessment, policies and procedures, monitoring, and continuous improvement. It offers practical insights and best practices for compliance officers and executives in the energy retail industry, addressing sector-specific challenges and strategies to overcome them.

Understanding ISO 37301 and AS ISO 19600 in the Energy Retail Context

ISO 37301 is the leading international standard for compliance management systems, published in 2021 to replace ISO 19600​. The earlier ISO 19600:2014 was a set of guidelines for establishing and maintaining a compliance program, whereas ISO 37301 provides formal requirements and is certifiable (organisations can be audited and certified against it)​. In practical terms, ISO 37301 is more prescriptive: it outlines specific elements that a compliance management system (CMS) must include – enabling independent assurance that boards and companies have carried out due diligence, implemented necessary controls, and established oversight and monitoring processes​ (nimonik.com). By contrast, ISO 19600 offered recommendations and flexibility, but no certification.

One key improvement in ISO 37301 is the stronger emphasis on a risk-based approach to compliance. The standard requires organisations to identify, assess, and prioritize their compliance risks, going beyond ISO 19600’s softer recommendation to merely consider risk​. In essence, compliance management under ISO 37301 aligns with broader risk management principles (as per ISO 31000 guidelines) to ensure companies focus their efforts on the most significant compliance obligations and threats​. This risk focus is crucial in energy retail, where businesses must manage obligations ranging from consumer protection and pricing regulations to safety and environmental rules. As one commentator noted, effective compliance goes beyond ticking off legal requirements – it involves meeting the needs and expectations of stakeholders and making sound, risk-informed choices about priorities​ (logicmanager.com). Adopting a risk-based compliance framework (as advocated by ISO 37301) helps energy retailers standardise their approach to governance and better integrate compliance into decision-making​ (logicmanager.com).

Another focal point of ISO 37301 is organizational culture and context. The standard explicitly calls for considering both internal and external context when developing a CMS, including the organisation’s culture, values and the expectations of stakeholders​. It recognizes that energy companies operate within a broader socio-political environment and that a strong culture of compliance is the cornerstone of effective implementation​. In fact, ISO 37301 places ethical culture “at the heart of the new standard,” requiring promotion of values and responsibility so that everyone knows their compliance duties​. This focus on culture is highly relevant to energy retailers, where front-line staff (e.g. sales agents, customer service teams, field technicians) must consistently do the right thing in interactions with customers and market participants.

It’s worth noting that AS ISO 19600:2015 was the Australian adoption of ISO 19600, and Australian regulators have begun referencing the new standard. The Australian Energy Regulator (AER), for example, now expects energy companies to establish compliance policies, systems and procedures “in a manner and form consistent with AS ISO 37301:2023”​ (aer.gov.au). This means energy retailers are encouraged (and arguably required) to align their compliance management frameworks with the principles of ISO 37301. In the sections below, we outline a structured approach to compliance implementation – governance, risk assessment, policies and procedures, monitoring, and continuous improvement – and illustrate how these elements can be applied in an energy retail business in line with ISO 37301 (and the legacy guidance from ISO 19600).

Governance and Leadership in Compliance

Governance is the foundation of an effective compliance management framework. In practical terms, this starts with a strong “tone from the top” – the board and executives must demonstrate a clear commitment to compliance and embed it into the company’s governance structures. Under ISO 37301, leadership and commitment are explicit requirements: top management and governing bodies should ensure compliance objectives are established, necessary resources provided, and responsibilities assigned. Energy retailers should formalise governance arrangements for compliance, for example by defining the roles of the Board, a compliance committee, and a dedicated compliance manager or officer.

In the energy retail sector, leading practice is to give the Board ultimate responsibility for the compliance program, while management and specialist staff handle day-to-day implementation. The Board may charter a Compliance Committee (often a subcommittee of the Board or executive leadership) to oversee implementation of the compliance program, review key risks, and monitor controls and remedial actions​. Meanwhile, management is tasked with developing and operationalising compliance policies and procedures, and the appointed Compliance Manager (or Compliance Officer) coordinates these efforts​. A clear delineation ensures that compliance is driven from the top but managed by capable personnel with proper oversight.

It is also advisable to appoint a dedicated compliance officer or manager to administer the compliance management system. According to guidance on ISO 37301, an organisation should have a person responsible for making sure the CMS is implemented, functional and maintained​ (pecb.com). In an energy retailer, this role would involve coordinating compliance risk assessments, monitoring regulatory developments, reporting to the executive team and Board, and fostering a culture of compliance across the business. Importantly, the compliance function must have sufficient authority and independence – typically, the compliance manager should have direct access to senior management and the Board (for example, via the compliance committee) to escalate issues.

Leadership commitment also means building a strong compliance culture. Management should communicate that compliance is a core value and “everyone knows their responsibilities and roles” in upholding obligations​ (nimonik.com). Practical steps include integrating compliance objectives into the company’s strategic plans, code of conduct and performance metrics. Many energy retailers incorporate compliance KPIs for managers and staff, and regularly discuss compliance performance in executive and board meetings. Training (addressed further below) at onboarding and periodically reinforces the message that “compliance with all Applicable Law is a key requirement for all employees”​. By embedding compliance into governance and culture, energy retailers create an environment where adhering to laws and ethical standards is the norm, not an afterthought.

Compliance Risk Assessment in the Energy Retail Sector

At the heart of ISO 37301 is a risk-based approach – effective compliance management requires identifying and assessing compliance obligations and risks. For energy retailers, this process is critical given the breadth of obligations under instruments like the National Energy Retail Law and Rules, state-specific regulations (e.g. Victoria’s Energy Retail Code of Practice), consumer protection laws, privacy legislation, and so on. A structured risk assessment ensures the company understands what it must comply with and the potential impact of non-compliance.

The first step is to identify all compliance obligations relevant to the business. AS ISO 19600 guidelines advised organisations to “systematically identify [their] compliance obligations and the implications of those on [their] activities, products and services”, with the level of documentation proportionate to the organisation’s size and complexity​. In practice, energy retailers should maintain an obligations register listing all legal and regulatory requirements, license conditions, industry codes, and internal standards that apply to their operations. Having a comprehensive obligations register (often managed with the help of compliance software such as Compliance Quarter’s own Titan or databases) is a best practice to ensure nothing slips through the cracks.

Once obligations are identified, assess the compliance risks – essentially, determine the likelihood and consequence of non-compliance with each obligation or category of obligation. ISO 37301 mandates a formal compliance risk assessment process, whereas the old ISO 19600 only recommended it​. In an energy retail context, this means evaluating scenarios such as breaches of customer billing accuracy requirements, wrongful disconnections, marketing misconduct, data privacy breaches, health and safety incidents, etc., and rating their risk levels. Many energy companies align this with their enterprise risk management framework, using the methodology of ISO 31000 for consistency​. The compliance risk assessment should consider not only legal penalties, but also customer harm, reputational damage, and operational impact that could result from each type of breach.

A good compliance risk assessment process is iterative and ongoing. The compliance committee should ensure that appropriate risk assessments, audits, and reviews are conducted regularly​, and whenever there are significant changes (such as new regulatory requirements or business activities). ISO 37301 likewise requires that organisations “consider both internal and external context”​ and re-evaluate compliance risks in light of changes. In practice, energy retailers often re-assess compliance risks annually (at minimum), and on an ad-hoc basis when major regulatory changes occur (for instance, if a new rule affecting hardship customers is introduced, or a new product line is launched). The outcome of risk assessments should be documented – usually as a risk register with rankings – and used to prioritise where to focus compliance efforts and resources.

By taking a risk-based approach, energy retailers can allocate their compliance resources efficiently, focusing on high-risk obligations (for example, those with severe penalties or that impact customers’ well-being) while not neglecting lower-risk areas. This approach is supported by research and practice: a risk-based compliance program helps organisations “prioritize compliance concerns and add context to compliance obligations”, essentially asking “what can go wrong if we don’t meet this requirement?”​. Answering that question guides the design of controls and mitigation strategies in the next step of the framework.

Policies, Procedures and Controls for Compliance

With governance in place and risks identified, the next component is developing robust policies, procedures and controls to address compliance obligations. These are the tools by which an organisation translates requirements into day-to-day practice. ISO 37301 expects organisations to establish and implement effective controls as part of operating the CMS​. For an energy retailer, this typically involves a suite of compliance documents and processes, such as a compliance policy, detailed procedures for complying with specific regulations, work instructions for staff, and internal controls built into IT systems (e.g. billing system checks).

Start by establishing a high-level Compliance Policy that articulates the business’s commitment to compliance and outlines the framework (often referencing the ISO standards as guiding principles). Many energy retailers, when applying for licences or authorisations, submit a Compliance Policy that aligns with AS ISO 19600/ISO 37301.

Documented procedures should be created for operational areas to ensure compliance is integrated into each business process. For instance, there should be standard operating procedures for customer onboarding (to ensure valid explicit informed consent is obtained, as required by retail rules), for handling customer complaints and hardship cases (to meet regulatory guidelines), for performing disconnections (to comply with notice requirements and life support customer protections), and so on. The goal is to ensure that for every significant obligation identified in the risk assessment, there is at least one control or procedure in place that addresses it.

A good practice is to integrate compliance controls into business systems to the extent possible. Instead of relying solely on manual adherence, energy retailers use system rules and automated flags. For example, a billing system might automatically prevent an invoice from being issued if it doesn’t meet pricing regulations, or a CRM system might have mandatory fields and workflows to ensure a cooling-off period is offered after a door-to-door sale. Such built-in controls act as “hard guards” against breaches.

Training and communication are also critical tools in this phase. Policies and procedures only work if staff are aware of them and know how to follow them. Compliance training should be provided to all relevant employees and contractors – both at induction and through regular refreshers. Ongoing training can be tailored to roles (e.g. specialised training for billing specialists on accuracy obligations, or for field technicians on safety compliance). It’s also useful to maintain easy access to compliance resources, such as an intranet site or compliance portal where the latest procedures and guidelines are available.

Additionally, internal communication from leadership reinforcing compliance expectations (e.g. periodic messages from the CEO about the importance of ethical conduct, or team briefings on compliance updates) will keep the topic front-of-mind. Creating a culture where employees feel comfortable asking questions or raising concerns about compliance is important – this can be aided by having clear reporting channels (even anonymous whistleblower channels) as required under the standards​.

Energy retailers should not overlook third-party compliance as part of their framework. Many retailers rely on third parties for sales (marketing agencies, brokers), service delivery, or IT systems. ISO 37301 adds specific requirements for managing third-party compliance risks​. Retailers should conduct due diligence on partners and ensure contracts include compliance obligations. For example, if using an outsourced call centre for telesales, the retailer must ensure that the call scripts and practices comply with energy marketing rules and consumer law. Some companies have a Third-Party Management Policy as part of their CMS. Clearly communicating your compliance expectations to contractors and monitoring their adherence protects the retailer from downstream risks.

In summary, well-crafted policies and procedures operationalise the compliance requirements, and ongoing training and communication ensure that the workforce and partners understand and implement these controls in their daily activities. This builds the first and second lines of defence for compliance within the organisation.

Monitoring, Reporting and Assurance

No compliance management framework is complete without mechanisms to monitor compliance, report on performance, and provide assurance that the controls in place are effective. Both ISO 19600 and ISO 37301 stress the importance of performance evaluation and continuous checking of the CMS. In fact, ISO 37301 requires organisations to establish a compliance performance evaluation process – including monitoring and measuring compliance, analysing results, and taking corrective actions​- whereas ISO 19600 had only suggested periodically evaluating the system’s effectiveness.

For energy retailers, monitoring can take several forms:

  • Regular compliance reporting: Business units or process owners should report on compliance metrics and any incidents. For instance, a retail operations team might report the number of disconnections carried out and any that were in breach of rules, or the compliance team might track how many customer complaints were resolved within regulated timeframes. These reports should be reviewed by the Compliance Manager and elevated to the Compliance Committee and Board in a structured manner. In practice, many retailers require immediate escalation of any material breach (significant non-compliance) and provide summary compliance reports at each Board meeting. This ensures senior leaders have visibility and can take action on serious issues.
  • Compliance audits and inspections: The retailer’s compliance function (or internal audit team) should conduct periodic audits to test whether obligations are being met and controls are working. This might involve sample testing of billing accuracy, reviewing customer account changes for proper consent, or auditing field work orders for safety compliance. The concept of “three lines of defence” is useful here: operational management is the first line (owning and managing risks), the compliance/internal audit function is the second/third line providing independent check. Regulators themselves may also conduct audits – the AER periodically audits retailers’ compliance with things like hardship program obligations or life support customer processes. A robust internal audit program can preempt regulatory audits and ensure the company is prepared.
  • Automated monitoring: Where possible, use technology to continuously monitor compliance. Modern compliance management systems (CMS software) can track key obligations and send alerts. Energy retailers are increasingly using RegTech solutions – for example, some use automated tools to monitor regulatory changes or to track that all required compliance tasks (like submitting reports to regulators) are completed on time. In fact, Compliance Quarter’s own platform (the Compliance HUB) and tools are designed for this purpose.. Such tools can streamline tracking of obligations, centralise incident reporting, and provide dashboards for oversight, saving an organisation time and energy in managing compliance data. Compliance technology can also facilitate incident management – logging any compliance breaches or near-misses and tracking remediation actions to closure.
  • Issue and incident management: When a compliance breach or incident occurs, the framework should ensure it is promptly identified, reported, investigated, and corrected. This is part of monitoring too – encouraging staff to speak up about problems (through internal reporting channels or whistleblower mechanisms) so that issues surface. ISO 37301 puts weight on having effective reporting channels and whistleblowing processes to detect issues early​ (nimonik.com). Energy retailers should have clear procedures for staff to report compliance concerns (e.g. an anonymous hotline for reporting misconduct, or a policy that all staff must report any observed breach to the Compliance Manager). Once reported, incidents should be logged and investigated. If a breach is confirmed, the retailer may need to self-report to regulators (energy laws often require reporting material breaches “as soon as practicable”) and take remedial actions such as compensating customers or fixing system errors. The Compliance Committee and Board should also receive reports on such incidents and the status of corrective actions.

The outcomes of monitoring activities – whether from routine reporting or audits – should be analyzed to identify trends and areas for improvement. For instance, if internal audits find recurring issues with a certain process (say, delays in refunding customer security deposits beyond regulated timeframes), that should trigger management to strengthen controls or provide additional training in that area.

Robust monitoring and reporting not only help catch compliance issues but also demonstrate to external stakeholders (regulators, auditors, even the public) that the retailer has its compliance risks under control. In an environment where regulators like the AER and Essential Services Commission are actively enforcing rules, being on top of your compliance status is critical. Businesses that can show a strong monitoring regime may even gain some trust or leeway from regulators. As one ACCC review noted in a different context, having a “robust compliance management system” can streamline regulatory oversight and provide incentives for businesses through reduced scrutiny​ (accc.gov.au). In short, “what gets measured gets managed” applies to compliance – so energy retailers should rigorously measure their compliance performance.

Continuous Improvement of the Compliance Program

A hallmark of both ISO 19600 and ISO 37301 is the concept of continuous improvement – the compliance management framework should evolve and improve over time. Energy retail markets and regulations do not stand still; new laws emerge, regulatory priorities shift, and businesses themselves change. Thus, an effective compliance program is not a one-off project but an ongoing cycle of planning, implementing, checking, and refining (closely mirroring the Plan-Do-Check-Act cycle in ISO management system standards).

To ensure continuous improvement, energy retailers should conduct regular reviews of their compliance management framework. ISO 37301 requires top management to review the CMS at planned intervals, evaluating performance and identifying opportunities for enhancement​ (nimonik.com). In practice, this might take the form of an annual compliance management review presented to the Board or Audit Committee. Such a review would consider: Have there been significant compliance incidents this year? What do the audit findings and compliance reports indicate about control weaknesses? Are there emerging regulatory risks (for example, forthcoming changes to the energy code or new consumer protection mandates) that we need to prepare for? Based on this, the compliance program for the next period can be adjusted – perhaps introducing new controls, updating policies, or increasing training in certain areas.

Lessons learned from compliance breaches or near-misses are especially valuable. Each incident should lead to asking: how can we prevent this in future? The answers might involve updating a procedure, upgrading a system, or even redesigning a business process. This implies a feedback loop where after mitigating known risks, the residual risk is watched and further actions are taken if needed.

Energy retailers should also stay abreast of regulatory changes and industry best practices as part of continuous improvement. Compliance officers often subscribe to regulator newsletters, participate in industry forums, or consult external experts to keep updated​. When rules change – for example, amendments to the National Energy Retail Rules – the compliance framework must be agile enough to incorporate those changes quickly (by updating the obligations register, altering processes, and briefing staff). A living compliance program will have a mechanism to incorporate regulatory updates on an ongoing basis.

Regular policy and procedure updates are another aspect of improvement. A policy may be slated for review every two years, but interim updates should be made if needed. Similarly, compliance training content should be refreshed periodically to include any new requirements or lessons from incidents.

Finally, continuous improvement is aided by maintaining proper documentation and reporting on compliance activities, because this documentation allows analysis over time. Tracking metrics year over year can show whether compliance performance is improving (e.g. reduction in number of breaches, faster response times to issues, etc.).

In summary, energy retailers should treat their compliance management system as a dynamic system – always looking for ways to strengthen it. By regularly reviewing performance, learning from mistakes, updating the framework, and adapting to change, retailers can ensure their compliance program remains effective and resilient in the face of new challenges.

Challenges Specific to the Energy Retail Sector and Strategies to Address Them

Implementing a compliance management framework in an energy retail business comes with unique challenges. Below we discuss some of these challenges and strategies (best practices) for compliance officers and executives to address them:

  • Regulatory Complexity and Change: Energy retailers operate under a patchwork of federal and state regulations, with multiple regulators (AER, state commissions, ACCC) overseeing different aspects​. Keeping track of varied obligations – from pricing and billing rules to marketing standards – can be difficult, and frequent regulatory changes add to the burden. Strategy: Maintain a comprehensive obligations register and assign owners for monitoring regulatory updates​. Many retailers use subscription services or regulatory monitoring tools to get alerts on rule changes. Build flexibility into policies so they can be quickly updated. Also, engage in industry consultations so you have early awareness of upcoming changes. A robust CMS aligned with ISO 37301 inherently prepares the business to adapt to new laws by emphasizing context and continual re-assessment of obligations​ (nimonik.com).
  • Protecting Vulnerable Customers: A major focus area in recent years has been ensuring fair treatment of customers in vulnerable circumstances (e.g. those on hardship plans, life support equipment, or experiencing difficulty paying). Regulators have taken enforcement action for breaches like wrongful disconnections, failure to register life support customers, and aggressive sales to vulnerable groups​. These incidents not only lead to fines but can seriously damage a retailer’s reputation given energy is an essential service. Strategy: Develop targeted compliance controls for customer protection obligations. For example, implement system safeguards that prevent disconnection of a customer flagged as having life support equipment unless special approval is obtained. Train customer service staff extensively on hardship program requirements and how to identify and support vulnerable customers. Regularly audit your processes for disconnections and reminder notices to ensure they strictly follow the rule timelines. Emphasise a customer-centric culture as part of compliance – employees should understand the spirit behind these rules (protecting those in need) so that they are motivated to comply, not just because the rule says so but because it’s the right thing to do.
  • Data Management and Billing Accuracy: Energy retailers handle large volumes of customer data (e.g. meter readings, billing information) and must comply with accuracy and privacy requirements. Billing errors or delays, in particular, are a common source of customer complaints and can lead to compliance breaches (such as not billing a customer on time or applying incorrect rates contrary to regulatory price caps). Strategy: Invest in reliable billing systems and conduct routine data quality checks. Use automated validations in the billing process to flag anomalies (for instance, if a bill is exceptionally high/low it gets reviewed before sending). Keep a close eye on the accuracy of standing offer and market offer pricing disclosures – the ACCC’s Electricity Retail Code and general consumer law demand that advertised prices and discounts aren’t misleading. Implement privacy compliance measures as well, ensuring customer data is secured and used in line with the Privacy Act. A strong IT control environment and periodic IT audits (including cybersecurity, given the rise of data breaches) form part of compliance assurance in this area.
  • Multiple Jurisdiction Operations: If an energy retailer operates across different Australian states or territories, it may have to deal with different regulatory regimes – for example, Victoria has its own Energy Retail Code and licensing, whereas other states follow the national framework under the AER. Additionally, some requirements (like concession schemes or state-based rebates) differ. Strategy: Clearly map out obligations by jurisdiction. It might be prudent to maintain separate compliance matrices for each jurisdiction and ensure local teams are aware of the specific rules. Harmonise processes where possible to meet the highest standard across jurisdictions, to avoid confusion. Also, maintain open communication with each regulator – for instance, engage with both the AER and the Victorian ESC to understand their expectations. Many retailers appoint a dedicated compliance resource or advisor for Victoria versus other states given the differences. Ensuring your CMS considers territorial variables (as ISO 37301 suggests​ (nimonik.com)) will help manage this complexity.
  • Embedding Compliance into Organisational Culture: Creating a compliance-oriented culture can be challenging, especially in a sales-driven environment where there may be pressure to meet targets. Frontline employees or contractors might be tempted to cut corners (e.g. misrepresent a plan to close a sale) if compliance is seen as secondary. Strategy: Reinforce “tone from the top” continuously – leadership should consistently message that no sales goal justifies a breach. Include compliance criteria in performance evaluations and incentive structures (for example, sales commissions could be clawed back if mis-selling is discovered). Encourage a speak-up culture: staff should feel safe to report issues. Celebrate compliance achievements (like completing a year with zero major breaches or successfully passing an audit) to show that compliance is valued. According to the new ISO standard, making compliance everyone’s responsibility and promoting an ethical culture are critical to success​ (nimonik.com), so invest in awareness campaigns and leadership example-setting.
  • Resource Constraints and Expertise: Particularly for smaller or newer energy retailers, dedicating sufficient resources (people, technology, budget) to compliance can be tough. Compliance requirements can seem overwhelming without experienced staff or established systems. Strategy: Leverage technology and external expertise to augment your capabilities. As noted, tools like Compliance Quarter’s Compliance HUB and related software can systematise a lot of compliance tracking​ easing the burden on a small team. Consider engaging compliance consultants or legal advisors (like Compliance Quarter or similar specialists) for periodic reviews or to build out your framework – they can bring industry best practices and updates that you might not catch while occupied with daily operations. Also, prioritize your efforts using the risk-based approach: ensure high-risk areas are resourced first. Over time, as the company grows, invest in expanding the in-house compliance team. Remember that regulators will look at whether your compliance arrangements are adequate for the size and scale of your business; demonstrating that you have thought about this and sought appropriate tools/support can go a long way.

By anticipating these challenges and proactively implementing such strategies, energy retail executives and compliance officers can significantly strengthen their compliance management framework. The goal is to make compliance not a hindrance, but a built-in aspect of business excellence – leading to better outcomes for the company and its customers.

Conclusion

Implementing an effective compliance management framework in the energy retail sector is undeniably challenging, given the heavy regulation and public interest nature of energy services. However, by following a structured approach aligned with ISO 37301 and the guidance of AS ISO 19600, energy retailers can build a robust compliance program that not only meets legal requirements but also enhances governance and business integrity. Key elements include strong governance and leadership commitment, a thorough risk assessment process, well-designed policies and procedures (with training to support them), diligent monitoring and reporting, and a commitment to continuous improvement.

The practical examples and best practices discussed – from maintaining an obligations register and compliance risk register, to using compliance technology and fostering a compliance culture – are tools that compliance officers and executives can apply directly in their organisations. Importantly, the framework should be tailored to the specific context of the retailer: its size, the jurisdictions it operates in, and the particular risks it faces (for example, a retailer focusing on commercial industrial clients will have different emphases than one serving residential customers).

By embedding compliance into corporate DNA and treating it as an ongoing journey, energy retailers can not only avoid breaches but also gain strategic benefits. A company that “demonstrates commitment to an effective compliance management system” builds trust with regulators, customers, and business partners​. This trust and reputation for integrity can be a real differentiator. Moreover, a well-implemented compliance framework helps prevent costly incidents and service failures, contributing to smoother operations and customer satisfaction.

In conclusion, energy retail businesses should view the ISO 37301 standard and related guidelines as valuable blueprints for compliance success. By applying these in a practical, sector-specific way – and by continuously improving their compliance management – retailers will be well-equipped to navigate the regulatory landscape while upholding the highest standards of conduct. This not only keeps the business on the right side of the law but also aligns with the broader goal of treating customers fairly and maintaining confidence in the energy market. An effective compliance management framework is, ultimately, an investment in the company’s long-term sustainability and reputation.​

More to explorer

werribee park mansion

Victoria consults on lower prices for embedded network customers

The Victorian Government has opened consultation on proposed pricing reforms for embedded networks, following its announcement that it intends to require lower energy prices for households and small businesses in those networks. The consultation is relevant to residential and small commercial embedded network customers, embedded network operators, exempt sellers and suppliers, licensed retailers operating in embedded networks, owners corporations, retirement villages, caravan parks, shopping centres and providers of bundled energy-related services such as bulk hot water, centralised heating and cooling.

smartphone beside a magnifying glass

Energy Retailer Assurance Audits in 2026: An Australian Guide

Assurance audits used to be a tick-the-box exercise. They are not anymore. With the Australian Energy Regulator (AER) refreshing its Compliance Procedures and Guidelines and releasing an updated Practice Guide for Compliance Audits last year energy retailers in Australia are operating in a sharper, more evidence-driven assurance environment than at any point in the National Energy Retail Law’s history. This post explains, in plain English, what an assurance audit looks like under the current settings, where the AER is looking hardest in 2025/26, and

street road near green and yellow trees

Embracing the uncertainty of rapid advancement and adoption of general artificial intelligence for energy businesses

The way businesses and professionals interact with artificial intelligence has changed. Over the past two months, we have observed a shift across our client base and the broader regulatory and legal community that goes beyond curiosity or experimentation. Professionals who were previously sceptical are now actively engaging with AI tools. Those who were already experimenting are finding that the tools have become materially more capable than they were even six months ago.

Leave a Reply

Your email address will not be published. Required fields are marked *