Navigating regulatory change: practical compliance advice for MVNOs
Australia's consumer protection framework exists to keep the relationship between telco providers and their customers working for all. It helps ensure customers get clearer information and fairer treatment, while providers build trust in their brand.
But getting there isn't always simple. Telecommunications and consumer protection regulation in Australia is genuinely complex, and MVNOs face that complexity in three distinct ways.
Volume. There's a lot happening at once, driven by active regulator responses to industry issues. The Australian Communications and Media Authority (ACMA) and the Australian Competition and Consumer Commission (ACCC) are the two bodies whose rules and enforcement activity most directly affect telco providers, and both are currently working through a substantial agenda.
Breadth. Requirements touch nearly every part of the business, from sales and billing to network operations and customer service. Rules evolve in response to real events in the industry, and the common thread running through most of them is transparency: clearer information, better communication, and stronger protections for consumers.
Doability. Establishing compliance with new regulatory obligations requires early planning to meet compliance dates. For organisations without large, dedicated compliance teams, this can feel like a lot to manage. The good news is that effective compliance doesn't depend on size. It depends on a handful of practices that any MVNO can put in place, regardless of how many people are working on it.
Best practice approaches
Every organisation has its own unique set of requirements for compliance. However, there are a few principles leaders can follow to manage compliance risk, no matter the size or complexity of their organisation.
Reframe how compliance is seen internally
Culture is set from the top of an organisation, and compliance culture is no exception. When the board and senior leaders visibly and consistently support compliance, it reinforces its importance across the business and makes it easier for people to raise issues early, before they become bigger problems.
It also helps to shift the framing. Rather than treating compliance purely as a cost of doing business, consider it an opportunity. Clearer communication, better complaint handling, and stronger data practices are all part of a good customer experience. Seen this way, compliance can become an important part of how consumers perceive your brand.
Set responsibilities and lines of accountability
Legally, your organisation, and ultimately your board, carries accountability for compliance. But accountability at that level doesn't answer a more practical question: who actually owns compliance day to day? Who's responsible for monitoring it and driving change when something needs to shift?
Significant regulatory obligations and change initiatives tend to work best with named owners — individuals who are responsible for making sure requirements are understood and properly implemented. Those owners don't need to sit in a formal compliance role. What matters is that someone is clearly accountable, so nothing falls through the gaps between teams.
Embed compliance in regular operational conversations
Compliance works best as an ongoing conversation, not an occasional review. Many organisations find it helpful to make it a standing agenda item in regular operational meetings, which keeps it visible and current and makes it more likely that emerging issues get raised and addressed while they're still small.
Implement a system for monitoring, triaging and operationalising regulatory updates
Early warning matters. Horizon scanning gives you visibility of new regulatory requirements or enforcement priorities before they land, so you're responding on your own terms rather than reacting under pressure.
Once you're aware of a change, the next step is impact assessment. Does it affect what you do? Who else in the business, or in your partner network, needs to act on it? Part of this is understanding your notification obligations. It's worth knowing which incidents or issues may need to be escalated internally, and whether they trigger any reporting requirements to regulators, such as eligible data breaches under privacy legislation.
Practical tips
Alongside these foundations, a few practical habits can help you stay ahead of regulatory change rather than reacting to it.
Read the regulator's priorities for the year
Each year, ACMA publishes its , setting out where it will concentrate its efforts to improve consumer protection over the year ahead. These priorities don't limit ACMA's usual compliance, monitoring and enforcement activity, but they do give a clear signal of where attention is likely to fall. It's worth reading the document and thinking through whether any of the priority areas touch your operations, products, services, or the way you engage with customers.
Consider the Three Lines of Defence model
The Three Lines of Defence (3LoD) model is a for managing risk. It works by creating clear separation between the people managing compliance obligations day to day and the people providing oversight and assurance. The three lines are:
- The business (Line 1), which is accountable for managing compliance in its everyday operations
- Risk management (Line 2), which provides oversight and challenge to the first line
- Internal audit (Line 3), which performs independent assurance over the whole system
Which team or individual performs each of these roles will differ from one organisation to the next, and that's fine. What matters is that all three functions exist somewhere: someone managing risk, someone overseeing and challenging that management, and someone auditing the results.
An alternative approach some organisations prefer is a RACI framework, which names individuals as Responsible, Accountable, Consulted, or Informed for each obligation.
Sign up for regulatory alerts and industry news
Many organisations build an early warning system by subscribing to alerts from , and other relevant bodies. It's also worth following , which tracks legislative, regulatory, compliance and enforcement developments across the telco industry.
If in doubt, ask
If you're unsure how a requirement applies to your business, ask. Many regulators encourage early engagement where businesses are uncertain how particular requirements apply rather than to investigate and remediate after an issue has occurred, and reaching out early is rarely held against you.Your ºÚÁÏ³Ô¹Ï Wholesale account team is also available as a sounding board. We work across the MVNO market and can often help identify issues and considerations that may be relevant to your business.
Useful resources
Here are a few external guides worth bookmarking if you want to build out your compliance approach further:
- (Australian Government Department of Finance) — guidance and examples for embedding risk management into everyday business activities.
- — templates, guidance and key principles for designing and running a compliance program, tailored to organisations of different sizes and levels of complexity.
- — written for the financial services industry, but its foundational principles on governance, accountability and risk management apply well beyond that sector.