How Consultants Help Higher Education Providers Meet Government Regulations

📕
Free planner
Download the Threshold Standards Map

— a one-page cross-reference from each Threshold Standard to the HESA, ESOS, privacy and WHS obligations that touch it, drawn from our TEQSA registration and governance work with private providers. Get the map

A wall chart mapping overlapping regulatory obligations, illustrating consultants government regulations higher education providers must coordinate
Updated: 2026-09-20

Consultants government regulations higher education providers rely on do one thing that matters above all others: they hold the whole regulatory map in view at once, so that a decision made to satisfy TEQSA does not breach the Higher Education Support Act, the ESOS Act, the Privacy Act, work health and safety law or a state statute. TEQSA is the regulator most providers think about. It is one of at least seven, and the others do not coordinate with it.

This article sets out the regulatory obligations that sit around TEQSA registration, where they overlap or pull in different directions, and what a good adviser does to keep a provider on the right side of all of them. It draws on fifteen years of TEQSA work with private providers, most of whom discovered the second and third regulators the hard way.

The map beyond TEQSA

The TEQSA Act and the Threshold Standards govern registration, accreditation and the quality of higher education. The Higher Education Support Act 2003 governs FEE-HELP approval, the conditions attached to it, tuition assurance, the information a provider must publish to students and the data it must report through the Tertiary Collection of Student Information, known as TCSI. The ESOS Act and the National Code 2018 govern every aspect of enrolling international students, from agents and written agreements to course progress and the Tuition Protection Service.

Then there is the law that applies to any organisation but bites harder on an education provider. The Privacy Act governs student records, which are among the most sensitive a business can hold. Work health and safety law applies to campuses, laboratories, placements and, since the pandemic, home-based work. Consumer law governs marketing claims and refund terms, and state law adds working with children checks where students are under eighteen, tenancy and building rules for premises, and in some states additional registration for particular fields. The interactions are described in the overlapping and conflicting requirements of other regulatory bodies.

Where the regulators disagree

The difficulty is not that there are many obligations. It is that they are written by different agencies for different purposes and they sometimes point in different directions. TEQSA's Standard 1.3 expects early intervention where a student is not progressing; the National Code prescribes a specific course progress and intervention process for international students with its own reporting consequences in PRISMS. The two must be reconciled in a single policy, or staff will follow one and breach the other.

FEE-HELP creates similar tension. The Higher Education Support Act's census date rules, its requirement to publish a schedule of fees and its tuition assurance obligations all constrain what a provider can promise a student, while Standard 7.2 expects the provider's information to be accurate and complete for every student regardless of funding. A refund policy drafted for TEQSA and a census date policy drafted for the Department can contradict each other on the same page of the student handbook. In my experience assessors from either agency read the other's requirements more carefully than providers expect.

What consultants government regulations higher education providers hire actually do

The first job is the map itself: a register of every obligation, the instrument it comes from, the internal owner, the reporting cycle and the evidence of compliance. Most providers have a TEQSA compliance calendar. Far fewer have one that also holds TCSI reporting dates, PRISMS deadlines, privacy breach notification timeframes, WHS audit cycles and state licence renewals. A good adviser builds that register and, more importantly, gets the governing body to adopt it and review it, so that Standard 6.2's requirement for corporate monitoring of legal compliance is met with a document the board actually uses.

The second job is reconciliation. Where two instruments touch the same process, the adviser drafts one policy that satisfies both and shows the mapping. The third is sequencing. FEE-HELP approval cannot precede registration, CRICOS cannot precede registration, and an allocation of international student places cannot precede CRICOS, so the adviser's calendar keeps a board from signing agent agreements or promising loans before the authority exists. Our step-by-step compliance guide for private providers follows that sequence.

What advisers cannot and should not do

A consultant cannot be the compliance function. The obligations belong to the provider, and every regulator on the map expects to see the provider's own governing body monitoring them. The non-delegation principle that applies to a TEQSA application applies just as strongly to a privacy breach or a WHS incident: the board must know, decide and record. An adviser who is the only person in the organisation who understands the map has made the provider dependent, not compliant.

Nor should a single adviser claim expertise in all of it. My firm's work is TEQSA, HESA and ESOS; for privacy, employment and WHS we tell providers to engage specialists and we coordinate with them. A provider choosing advisers should ask what each one does not do, and be suspicious of an answer that covers everything. A broader survey of the profession is in TEQSA higher education consultants: a comprehensive guide.

My advice on keeping the map current

Appoint one person inside the provider who owns the register, report it to the governing body quarterly, and update it whenever a regulator publishes a change. Treat every new activity, from a new campus to a new agent to a new online platform, as a trigger to ask which instruments it touches. And remember that TEQSA's material change rules run on a fourteen-day clock, that TCSI runs on its own reporting calendar, and that the Privacy Act's breach notification runs on another. The provider that knows all three is the one that never has to explain to one regulator why it was busy with a different one.

Free download

Download the Threshold Standards Map

— a one-page cross-reference from each Threshold Standard to the HESA, ESOS, privacy and WHS obligations that touch it, drawn from our TEQSA registration and governance work with private providers. Get the map

Keep reading — free

Want the full article?

Enter your email for free access to the rest of this guide and our TEQSA resource library.

Frequently asked questions

Which regulators does a private higher education provider answer to?

TEQSA under the TEQSA Act; the Department of Education under the Higher Education Support Act for FEE-HELP and TCSI reporting; the Department and Home Affairs under the ESOS Act for international students; plus privacy, consumer, work health and safety and relevant state law.

Does TEQSA check compliance with other laws?

Standard 6.2 requires the governing body to monitor compliance with legislation generally, and TEQSA's fit and proper person assessment considers false or misleading information given to any regulator. Material breaches of other laws can therefore affect registration.

Can one consultant handle all of a provider's regulatory obligations?

No single adviser credibly covers TEQSA, HESA, ESOS, privacy, employment and WHS law. A good adviser coordinates the map, reconciles overlapping requirements and tells the provider where a specialist is needed.

What is TCSI?

The Tertiary Collection of Student Information, the Department of Education's reporting system through which providers submit student, course and HELP loan data. Timely and accurate reporting is a condition of FEE-HELP approval.

BM
Dr Brendan MoloneyCEO, Darlo Higher Education

Dr Brendan Moloney is CEO of Darlo Higher Education, Australia's largest specialist TEQSA consultancy. He holds a PhD from the University of Melbourne, is a Cambridge University Press author on governance in higher education, and has advised private providers on registration and course accreditation for more than fifteen years.

Not sure where to start? Talk to us.

A short conversation tells you where you stand and what it takes — no cost, no obligation.

Talk to us →