Diligent Logo
Diligent Logo
Products
arrow_drop_down
Solutions
arrow_drop_down
Resources
arrow_drop_down
Diligent AI

ASIC’s companies register is changing (CP 391): Here’s what to know

September 28, 2026
•
8 min read
April Skipp

April Skipp

Company Secretarial SME and Product Compliance Advisor

ASIC’s Consultation Paper 391 (CP 391), released 11 September 2026, proposes new rules for who can access information on the Australian companies register, and what they can see. It proposes a four-tier access model: General, company, business, and government, including who has access to new data types: Director IDs, service addresses and electronic addresses. Feedback closes 12 October 2026, and none of the proposals are final yet.

CP 391 sits at the end of a longer reform chain (more on that below). ASIC is now consulting the market, including the businesses, governance teams, and service providers that rely on register data every day, before finalising the proposals.

We’re flagging this now because the outcome will affect the data available to you, and about your directors and officeholders. Your voice matters in shaping it.

Whether you’re an existing Diligent Entities customer managing Australian subsidiaries today, or you’re evaluating entity management and registry-connected solutions for the region, this is worth understanding now. The data access ASIC lands on will shape due diligence, KYC, and compliance workflows in Australia for years to come.

How we got here

CP 391 is the latest step in a longer chain of Australian business register reform:

  • Modernising Business Registers (MBR) program (2018–2023) — the original plan to consolidate the Australian Business Register and ASIC’s 31 registers under the Australian Taxation Office, and introduce director ID.
  • Registry stabilisation and uplift consultation (opened December 2025) — a Treasury consultation covering director ID linkage, new ASIC registry powers, and unwinding leftover MBR-era legislation.
  • Treasury Laws Amendment (Business Registries Stabilisation and Uplift) Act 2026 — enacted July 2026, this is the legal basis that now enables the new data types and access powers CP 391 proposes.
  • RegistryConnect — ASIC’s ongoing registry technology-modernisation initiative.

What’s being proposed, in brief

  • New data types are being introduced: Director IDs, service addresses (an alternative to a home address for officeholders), and electronic addresses for companies and officeholders will be required to be submitted for the first time.
  • Some currently paid-only information will move to free access. For example, officeholder names and status, and director ID numbers.
  • Some personal information will be reduced across the general and paid tiers, for example, year of birth instead of full date of birth, and residential locality (state/country) instead of a full address.
  • Next annual review date will no longer be available on the general access tier.
  • Residential addresses will be protected once a service address is lodged. Where an officeholder hasn’t lodged a service address during the transition period, their residential address will become generally accessible as the default service address from 1 August 2028.
  • New “flags” will appear on company records, for example, whether a director ID has been confirmed or whether a company has an overdue annual review.
  • Access will sit across four proposed tiers: general (anyone), company (the company and its authorised representatives), business (verified liquidators, legal practitioners, journalists) and government.

Key dates

Feedback on CP 391 closes 12 October 2026. If adopted, new lodgement and access settings would start 1 July 2027, with full implementation, including the residential address changes, by 1 August 2028.

Note that the access restrictions are subject to a parliamentary process (scrutiny, disallowance, and sunsetting), so these dates could move.

Why this matters for your team

This consultation directly affects how you and your teams will search, verify, and rely on Australian company and officeholder data going forward, including how due diligence, KYC, and compliance workflows may need to adapt to narrower personal data (e.g. year of birth rather than full date of birth).

A few areas particularly worth your teams’ attention:

  • Whether the shift to year-of-birth and locality-only data is sufficient for your due diligence needs.
  • How officeholders you deal with should be advised about the service-address election, given the default risk to residential addresses from 1 August 2028.
  • Whether your organisation would fall into a “business access” category (e.g. legal practitioners) and what verification that might require of you.

Have your say

We’d encourage you to review the consultation paper and share it with your local compliance, legal, or company secretarial teams so they can consider making a submission.

This is the stage where feedback actually shapes the outcome. After the paper closes, ASIC moves into building the new settings into the register itself.

What Diligent is doing

We’re tracking this consultation closely and are already reviewing the likely technology impact on Diligent Entities and its integrations with the ASIC register.

New data fields and verification requirements will need to be built into how filings are pushed to ASIC and extracts are pulled back. Our aim is for your day-to-day experience of searching, filing, and extracting through Diligent Entities to stay familiar throughout.

Where changes do reach the surface — for example, if you need to elect a service address, or if a data field you’re used to seeing changes shape — we’ll tell you well ahead of time, separately from this post.

We'll keep you updated as the consultation progresses and as ASIC's settings become clearer.

Frequently asked questions

What is ASIC Consultation Paper 391 (CP 391)?

CP 391 is a consultation released by ASIC proposing changes to who can access information on the Australian companies register, and what information is visible at each access level. It covers new data types (director IDs, service addresses, electronic addresses), changes to which fields are free versus paid, reductions to some personal information shown publicly, and a new four-tier access model.

Are the CP 391 proposals final?

No. CP 391 sets out proposals only. ASIC is consulting with the market, including businesses, legal practitioners, and other regular users of register data, before finalising the settings. Feedback closes 12 October 2026, and any resulting access restrictions are still subject to parliamentary scrutiny, so details and dates could change.

What are the proposed access tiers under CP 391?

Four tiers are proposed: general access (available to anyone), company access (the company itself and its authorised representatives), business access (verified users such as liquidators, legal practitioners, and journalists), and government access.

How would my due diligence or KYC process be affected?

Some personal information visible today would be reduced under the proposals, for example, year of birth instead of full date of birth, and residential locality (state/country) instead of a full address. Teams that rely on more granular data for identity verification, KYC, or due diligence should assess whether the proposed fields will still meet their needs, and raise this in a submission if not.

What happens to officeholders’ residential addresses?

Under the proposal, a residential address is protected once an officeholder lodges a service address as an alternative. However, for officeholders who haven’t lodged a service address by the end of the transition period, their residential address would become generally accessible as the default service address from 1 August 2028.

What are the key dates for ASIC CP 391?

Feedback on CP 391 closes 12 October 2026. ASIC plans to publish a submissions report and draft legislative instrument by March 2027, build and test new registry services between November 2026 and June 2027, begin new lodgements and access settings from 1 July 2027, and reach full implementation, including the residential address changes, by 1 August 2028. These dates may shift, since the changes are subject to parliamentary review.

How can my organisation respond to the consultation?

Submissions can be sent directly to ASIC at consultation.registrydata@asic.gov.au before 5pm AEDT on 12 October 2026. Diligent customers who want to work with their customer success manager on a response are welcome to reach out.

Will this change how I use Diligent Entities to manage Australian companies?

Diligent is reviewing the technology impact of the proposed changes on our platform’s integration with the ASIC register now, ahead of any changes taking effect. Our goal is for day-to-day searching, filing, and extracting in Diligent Entities to remain familiar. If any change does require action on your part — such as electing a service address — we will communicate that separately and well in advance.

What came before ASIC CP 391?

CP 391 follows a longer reform chain: the Modernising Business Registers (MBR) program (2018–2023), abandoned in 2023; a Treasury consultation on registry stabilisation and uplift; and the Treasury Laws Amendment (Business Registries Stabilisation and Uplift) Act 2026, enacted in July 2026, which provides the legal basis for the changes CP 391 now proposes.

Explore More

Board members and the COO of a company discussing global entity management

Blog

· Feb 11, 2026

· 13 min read

How technology streamlines global entity management in an era of rising complexity

By Meghan Day

Discover how AI-powered entity management technology helps enterprises navigate regulatory complexity across 195 countries efficiently.

Guide

· Jul 9, 2026

· 1 min read

How AI is redefining legal entity management

Discover how AI-powered entity management tools boost efficiency, reduces risk and supports smarter decisions across legal, tax and compliance teams.

Close up of three people looking at financial data with graphs and charts.

Research

· May 28, 2026

· 1 min read

Global State of Legal Entity Compliance 2026 report

Discover the latest insights on legal entity compliance in the 2026 report, designed for governance leaders navigating complex mandates. Benefit from data-driven analysis and practitioner perspectives to transform your entity governance model, assess AI readiness, and prioritize strategic improvements. Download now to chart a practical path towards intelligent compliance.