This TEQSA compliance guide sets out what a registered private provider has to do, year in and year out, to stay compliant between registration and renewal: lodge the annual data returns, notify material changes within fourteen days, review the risk register, run course and governance reviews on schedule, keep an evidence index current, and prepare a self-assurance report the governing body can honestly sign. Registration is a licence to operate for a period. Compliance is the record that earns the next one.
The guide is organised as a calendar and a set of roles, because in fifteen years of TEQSA registration and renewal work I have found that providers who fail at compliance rarely fail from ignorance of the Standards. They fail because nobody owned the calendar.
Step one: understand what compliance means to TEQSA
TEQSA does not conduct audits in the sense that ASQA does. It regulates through assessments at registration, accreditation and renewal, through compliance assessments where risk indicates, through requests for further information, and through the annual data it collects. Between those points it relies on the provider to govern itself, and the Threshold Standards are written in the present tense to make that expectation explicit. A provider "has" a governing body, "monitors" outcomes, "addresses" breaches. Compliance is those verbs being true on any day TEQSA chooses to look.
The move from Confirmed Evidence Tables to self-assurance sharpened this. TEQSA now asks the provider to say which standards it meets and to point to the evidence, rather than filling in a table. That raises the evidentiary bar, because a self-assurance statement the evidence does not support is a false statement to the regulator. It also means the compliance work of years two, three and four is what the renewal application in year five is made of.
Step two: assign the roles
A compliance calendar without owners is a list. Before anything else, decide who holds each of four roles. The company secretary or compliance manager owns the calendar, the register of obligations and the evidence index. The CEO owns material change notifications and the relationship with TEQSA.
The two chairs hold the rest. The chair of the academic board owns the academic quality cycle: course reviews, integrity reporting, assessment moderation. The chair of the governing body owns the risk register, the governance reviews and the self-assurance report.
The non-delegation principle applies to every one of those. A consultant can build the calendar and draft the reports. The governing bodies remain responsible for compliance, and the record must show them deciding, not receiving. Our article on common TEQSA compliance mistakes lists what happens when that separation is lost.
Step three: build the annual calendar
The calendar has fixed dates and cyclical dates. The fixed dates are the ones TEQSA sets. Annual provider data is collected through the Commonwealth's higher education data collection and TEQSA's own information requests, on dates published each year; the compliance manager should carry those dates forward as soon as they are announced. CRICOS providers add their PRISMS reporting obligations under the ESOS Act and the National Code. Financial statements have their own statutory dates.
The cyclical dates are the ones the provider sets for itself and the Standards assume. Risk register review by the governing body at least annually. Academic integrity reporting to the academic board each semester. Assessment moderation each teaching period. Annual course monitoring for every course, and a comprehensive review of each course at least every seven years under Standard 5.3.
Then the governance items. An independent review of the governing body and of academic governance, which TEQSA expects at renewal and which is easier to do in the year before than the month before. Put each on the calendar with an owner and a date, and minute completion.
Step four: watch the fourteen-day clock
Section 29 of the TEQSA Act requires a provider to notify TEQSA of a material change no later than fourteen days after it would reasonably be expected to have become aware of it. TEQSA's material change notification policy lists the categories: ownership and major shareholding changes, a new CEO, incidents significantly affecting student safety, matters bearing on good standing, significant revenue changes, new third-party delivery arrangements, failures of control over third parties, and major course changes including notable reductions in duration.
In my experience the clock is missed not because providers hide things but because nobody recognised the event as material. A parent company restructure, a major agent contract, a decision to run a course in two thirds of its accredited duration: each is a notification, and each has been missed by a provider that would have notified had it thought to ask. The compliance manager should hold a standing question at every executive meeting: has anything happened that TEQSA would want to know about? Our article on what triggers TEQSA scrutiny under material change goes through the categories in detail.
Step five: keep the risk register alive
Standard 6.2 requires risk management, and TEQSA's renewal guide lists a risk register, policy and procedures among the mandatory evidence. A register created for registration and never touched is worse than useless, because it shows a governing body that adopted a control and then ignored it. The register should be reviewed by the governing body at least annually and by management more often, and every review should change something: a rating, a control, a new risk, a closed one.
The risks that matter to TEQSA are the ones that bear on the Standards: financial viability, student attrition, staffing gaps, third-party delivery, academic integrity including generative AI, and any concentration of revenue in one market or agent. A register that lists cyber-security and workplace health and safety but not attrition or integrity has been copied from a different kind of organisation.
Each risk should carry a control, an owner and an indicator the governing body can actually watch. Attrition above a stated threshold, a course running below the enrolment its budget assumed, a third-party partner late with its reporting: these are the signals that tell a board something is moving before TEQSA's annual data tells the regulator. A register built that way does the monitoring Standard 6.2 describes, and its review minutes become evidence without any extra effort.
Step six: run the academic quality cycle
This is the part of the TEQSA compliance guide that lives with the academic board, and it is the part TEQSA reads most closely at renewal. Each teaching period: moderation of assessment, review of grade distributions, integrity reporting. Each year: annual course monitoring against outcomes data, benchmarking where available, and a report to the governing body on academic quality. Each course, on the seven-year cycle: a comprehensive review with external referencing, findings, an action plan and a board resolution.
The academic board's minutes are the evidence. They should show the board asking questions, requesting follow-up and declining to approve where the case was thin. A board that receives every report and approves every recommendation without recorded discussion will be read as a board that is not governing, whatever its terms of reference say. Our article on aligning with the national higher education standards sets out the quality cycle in more detail.
Step seven: review the governance
TEQSA's renewal of registration guide makes independent reviews of the governing body and of academic governance against Domain 6, with an action plan, mandatory at renewal. Providers that leave those to the renewal year get a review that finds problems they have no time to fix. Providers that review governance in the middle of the registration period get a review, an action plan, and two years of minutes showing the plan being delivered.
The review should be genuinely independent. A review by the provider's own consultant, or by a friend of the chair, will be read as such. And the action plan should be owned by the governing body, tracked in its minutes, and reported on in the self-assurance report as evidence of Standard 6.1 and 6.3 operating.
Step eight: keep the evidence index current
An evidence index is a document that maps each Threshold Standard to the records that show it being met, with the location of each record and the date it was last updated. It is the backbone of a self-assurance report and it is the tool that turns compliance from a scramble into a routine. Build it once at registration, then update it as a standing task each quarter: new minutes, new reviews, new policies, new data.
The test of a good index is whether a stranger could use it to find the evidence for Standard 1.3 in ten minutes. In my experience most providers have the evidence and cannot find it. The index fixes that, and it also exposes gaps early, which is its real value. Our guide to preparing re-registration evidence explains how to structure it against the renewal guide.
Step nine: write the self-assurance report as you go
TEQSA's renewal application requires a self-assurance report of no more than ten pages with an evidence index, and the application must be lodged at least 180 calendar days before registration ends. Ten pages is not much, which is precisely the point. The report has to say what the provider has done, what it found, what it changed, and where the evidence is. It cannot say that in ten pages unless the work has been done and indexed over the whole period.
I advise clients to draft a section of the self-assurance report each year, at the point the governing body considers the annual compliance report. By the renewal year the document exists in draft, the governing body has seen it evolve, and the assessor reads a report that describes a living system rather than a reconstruction. That approach also protects the governing body, because it will be signing a report whose claims it has watched being earned.
Step ten: prepare for renewal from year one
Registration runs for up to seven years, and TEQSA's initial registrations policy contemplates five years with capacity to extend. Renewal is risk-based: TEQSA does not require evidence against every standard, and it weighs compliance history, annual data and the strength of evidence in deciding how deeply to look. A provider with a clean history, timely notifications, stable data and a strong evidence index will face a lighter assessment than one that has drawn conditions or RFIs.
That is the practical reason for this whole guide. Every step above builds the compliance history TEQSA will read when it decides how to assess the renewal. The fastest renewal is the one where the record already answers the questions, and the record is built one calendar entry at a time.
Where private providers go wrong
The failures I see fall into three groups. The first is ownership: a calendar nobody holds, a register nobody reviews, notifications nobody makes because nobody knew they should. The second is separation: academic quality handled by the faculty, compliance by administration, risk by the board, with no report joining them. The third is reconstruction: two years of work done in the six months before renewal, producing evidence that is dated the same month and reads that way.
Each is fixable, and each is cheaper to fix in year two than in year five. A private provider that assigns the roles, holds the calendar, keeps the index and lets its governing bodies govern will find that compliance is not a burden layered on the business. It is the business, run in a way that can be shown.
What this TEQSA compliance guide comes down to
Compliance is a record of operation. TEQSA reads that record at renewal, and it reads it in the meantime whenever a material change, a complaint or a data anomaly gives it reason. The provider that can point to the minutes, the reviews, the notifications and the index has nothing to reconstruct. The provider that cannot will spend its renewal year explaining, and that is the most expensive year in the sector.
Download the Darlo Re-registration Evidence Index Template
— a standard-by-standard index with owners, review dates and record locations, drawn from our TEQSA registration and governance work with private providers. Get the template
Want the full article?
Enter your email for free access to the rest of this guide and our TEQSA resource library.
Frequently asked questions
How often does TEQSA check on a registered provider?
TEQSA collects provider data annually, responds to material change notifications and complaints, and may conduct a compliance assessment where risk indicates. Formal assessment otherwise occurs at course accreditation, renewal of accreditation and renewal of registration.
What must be notified to TEQSA as a material change?
Under section 29 of the TEQSA Act, events that significantly affect the provider's ability to meet the Threshold Standards or that require a National Register update, notified within fourteen days of the provider reasonably becoming aware. TEQSA's policy lists ownership, CEO, safety, good standing, revenue, third-party delivery and major course changes.
When must a renewal of registration application be lodged?
At least 180 calendar days before the current registration period ends, with a self-assurance report of no more than ten pages, an evidence index, independent governance reviews and risk management evidence.
What is an evidence index?
A document mapping each Threshold Standard to the records showing it is met, with the location and currency of each record. It underpins the self-assurance report and should be updated continuously rather than assembled before renewal.
Dr Brendan Moloney is CEO of Darlo Higher Education, Australia's largest specialist TEQSA consultancy. He holds a PhD from the University of Melbourne, is a Cambridge University Press author on governance in higher education, and has advised private providers on registration and course accreditation for more than fifteen years.
