Audits & Rectifications · E-Skills Insight

ASQA's Revised Monitoring Approach: How Regulatory Scrutiny May Begin

ASQA has revised its Regulatory Assessment and Monitoring Approach to support more varied and risk-based oversight. Scrutiny may now involve targeted evidence requests, site visits, performance assessments, financial-viability assessments or independent validation, not only a conventional announced audit.

ASQA has revised its Regulatory Assessment and Monitoring Approach, expanding the range of activities it may use to understand provider performance, investigate risk and respond to non-compliance.

The revised approach includes:

  • a wider range of regulatory activities;
  • four categories of performance assessment;
  • tiered pathways for compliance resolution;
  • targeted site visits;
  • specialised financial-viability assessments; and
  • independent student-assessment validation activities.

The practical implication is clear:

Regulatory scrutiny may begin in several different ways and may not always resemble a conventional announced audit.

Providers should therefore maintain continuing regulatory readiness rather than relying on a one-off audit-preparation exercise.

Performance monitoring is broader than an audit

ASQA describes performance assessment as one of the tools it uses to understand provider performance. In 2026, ASQA changed the way it conducts these assessments and introduced its revised Regulatory Assessment and Monitoring Approach.

Current performance-monitoring activities may include:

  • quality monitoring;
  • performance assessment;
  • compliance resolution;
  • complaint investigation;
  • student-assessment validation;
  • onsite performance visits; and
  • financial-viability specialist assessment.

The appropriate activity may depend on:

  • the nature and seriousness of the risk;
  • intelligence or complaints received;
  • the potential effect on students;
  • the provider's operating model;
  • previous regulatory history;
  • the quality of information available;
  • financial or operational concerns; and
  • whether rapid regulatory intervention is required.

1. Quality monitoring

Quality monitoring may be used to better understand an emerging issue, an identified sector risk or a particular aspect of provider performance.

A provider may be asked to supply targeted evidence concerning matters such as:

  • student outcomes;
  • training duration;
  • assessment practice;
  • trainer capacity;
  • course delivery;
  • complaints;
  • enrolment patterns;
  • third-party operations; or
  • governance and financial oversight.

A targeted request should not be treated as a routine administrative exercise. The evidence supplied may influence whether further regulatory activity is required.

Provider response considerations

Before responding, providers should:

  • identify precisely what ASQA is requesting;
  • nominate a responsible internal coordinator;
  • preserve original records;
  • reconcile information across systems;
  • check that submitted evidence is complete and internally consistent;
  • avoid creating retrospective records;
  • explain genuine anomalies;
  • distinguish current practice from previous practice; and
  • retain an exact copy of the submission.

2. Performance assessment

A performance assessment may examine whether the provider is achieving the required outcomes and complying with its regulatory obligations.

The scope may be broad or targeted. It may involve:

  • desktop review;
  • interviews;
  • student-file sampling;
  • assessment review;
  • trainer-file review;
  • governance evidence;
  • site attendance;
  • financial information;
  • student interviews;
  • system demonstrations; or
  • review of delivery across multiple locations.

Providers should not assume that the assessment scope will be limited to the documents initially requested. Issues identified during the assessment may lead to further enquiries.

3. Onsite performance visits

Site visits allow the regulator to compare documented arrangements with actual operations.

During a visit, ASQA may observe or review:

  • whether the premises are operating as represented;
  • student attendance;
  • class sizes;
  • trainers present;
  • facilities and equipment;
  • practical delivery;
  • student access to support;
  • records available onsite;
  • other entities operating from the premises; and
  • whether the provider exercises genuine control over delivery.

Providers with multiple campuses or shared facilities should ensure that each site can independently demonstrate that approved arrangements are being implemented.

A site should not depend on one compliance manager being present to explain every process. Staff should understand their roles and be able to locate relevant records.

4. Student-assessment validation

Independent validation may be used to determine whether students were assessed appropriately and whether competency outcomes are supported by sufficient evidence.

This may involve review of:

  • completed student assessments;
  • practical observation records;
  • assessor feedback;
  • authenticity controls;
  • reassessment;
  • recognition of prior learning;
  • third-party reports;
  • workplace evidence; and
  • the relationship between assessment evidence and the relevant training-product requirements.

Providers should ensure that retained assessment evidence allows an independent reviewer to understand:

  • what the student submitted or demonstrated;
  • what the assessor considered;
  • how the assessment decision was made;
  • what feedback was provided; and
  • whether all requirements were met.

5. Financial-viability specialist assessment

Financial viability is not solely an accounting issue. Financial weakness can affect:

  • staffing;
  • training resources;
  • student support;
  • premises;
  • course completion;
  • refunds and prepaid fees;
  • operational continuity; and
  • the provider's capacity to meet regulatory obligations.

ASQA's governance guidance expects governing persons to understand how the organisation's financial position, performance and cash flow are managed and monitored.

Providers should maintain reliable:

  • financial statements;
  • cash-flow forecasts;
  • budgets;
  • enrolment assumptions;
  • creditor and debtor information;
  • related-party transaction records;
  • prepaid-fee controls;
  • contingency plans; and
  • evidence of governing-person review.

6. Compliance resolution

Where non-compliance is identified, ASQA may use a pathway proportionate to the nature, seriousness and consequences of the issue.

Providers should not assume that every finding will result in an opportunity for informal rectification. Serious concerns involving students, qualification integrity, non-genuine operations or systemic risk may require stronger regulatory intervention.

Where rectification is permitted, a credible response should include:

  1. the cause of the problem;
  2. the extent of affected operations or students;
  3. immediate containment;
  4. correction of affected records or outcomes;
  5. systemic changes;
  6. responsibility and timeframes;
  7. evidence that changes were implemented; and
  8. monitoring to verify ongoing effectiveness.

Submitting a revised policy alone will rarely demonstrate that a systemic problem has been rectified.

Maintaining continuous regulatory readiness

Providers should maintain a standing assurance program covering:

  • governance;
  • risk;
  • student files;
  • training delivery;
  • assessment;
  • trainer and assessor capacity;
  • complaints;
  • certification;
  • third-party arrangements;
  • financial viability;
  • CRICOS operations, where applicable; and
  • corrective actions.

ASQA's Continuous Improvement Practice Guide refers to regular evaluation of operational functions and the use of a compliance calendar or assurance program to monitor obligations.

Questions for provider self-review

  • Could we respond to a targeted evidence request without creating new records?
  • Do our records reconcile across the SMS, LMS, timetables and student files?
  • Would an unannounced site visit reflect the operations described in our TAS?
  • Can an independent person follow our assessment decisions?
  • Do governing persons understand current financial and compliance risks?
  • Are previously identified issues demonstrably closed?
  • Can staff explain how the provider's systems work in practice?

Conclusion

The revised monitoring approach confirms that regulatory readiness must be embedded within normal operations.

The strongest protection is not an "audit folder". It is a provider-wide system that routinely produces accurate, consistent and traceable evidence.

E-Skills support

E-Skills Australia can assist with:

  • regulatory-readiness reviews;
  • internal audits;
  • evidence sampling;
  • onsite readiness;
  • mock interviews;
  • financial and operational risk review;
  • assessment-file review; and
  • rectification planning.

Arrange an independent regulatory-readiness review.