The Cash Recovery Brief

Is Your Debt Collection Software Compliant? 25 Questions to Ask Under ACCC and ASIC Guidance

20 September 2026 · 12 min read · For CFOs, finance leaders and business owners

Buying debt collection software does not outsource your legal responsibilities. If a tool contacts your customers in your name, you are still the one answering for what it says, when it says it and how it treats them. This guide sets out 25 practical questions to put to any vendor, organised around the ACCC and ASIC debt collection guideline and the privacy and recording rules that sit alongside it. Use it as a due-diligence checklist before you sign.

What "compliant" means for debt collection software

Last reviewed: September 2026. Rules and guidance change, particularly in privacy. This article is general information, not legal advice.

There is no single rulebook or certificate that makes a product "compliant". Compliance comes from three layers working together:

  1. 1.The law. This includes the Australian Consumer Law and the ASIC Act (which prohibit misleading or deceptive conduct and unconscionable conduct), state and territory fair trading laws, the Privacy Act 1988, and laws on recording calls and sending electronic messages.
  2. 2.Regulator guidance. The joint ACCC and ASIC debt collection guideline (ASIC Regulatory Guide 96) explains how the regulators view fair collection conduct. It does not have legal force by itself, and following it does not guarantee you will avoid enforcement action, but it is the benchmark most Australian collectors measure themselves against.
  3. 3.Your own contracts and policies. Your payment terms, customer agreements and internal collection policy set what you have promised customers and what you will not do.

Does the guideline apply to business debts?

The guideline says it was developed with particular reference to collecting debts from individual debtors, and that many of the laws and principles it discusses are also relevant to collecting corporate, business and, in particular, small business debts. In practice that means:

  • Treat it as your baseline even when your customers are businesses. Many of your debtor contacts are individuals (sole traders, directors, accounts staff), and small business owners are often treated much like consumers.
  • Some legal provisions are consumer-specific, and others, such as those on misleading and unconscionable conduct, can apply in commercial dealings.
  • Get legal advice on which rules apply to your customer mix.
  • Responsibility stays with you: the guideline notes that when a creditor uses an agent to collect, the creditor as principal will generally be liable for the agent's conduct within that agent's authority, even if the agent breaks an agreement about how collection should be done. How that applies to a software vendor acting on your behalf is a question for your lawyer.

Questions 1-4: contact hours and frequency

  1. 1.How does the platform decide when a call, SMS or email can go out? Look for rules based on the debtor's local time zone, not yours. The guideline treats weekday phone calls between 7:30am and 9pm and weekend calls between 9am and 9pm as reasonable times, and recommends no contact on national public holidays. Workplace contact should fall in the debtor's working hours, or 9am to 5pm on weekdays if unknown. Some states add their own rules.
  2. 2.How does it count contact frequency? Look for counting per account, with voicemails, SMS and emails as separate contacts. The guideline recommends no more than three actual contacts a week and ten a month, and only when necessary, with a reasonable gap so the customer can respond.
  3. 3.How does it handle unanswered calls? Look for limits on attempted contact too. Repeated redialling, including automatic dialler queues, can amount to undue harassment.
  4. 4.Can I set stricter rules than the defaults, per customer or segment? Look for configurable caps, quiet periods and channel preferences.

Questions 5-8: identity, disclosure and AI

  1. 1.How does the platform confirm it is speaking to the right person before discussing the debt? Look for identity verification before any detail is disclosed, every time.
  2. 2.What does the platform say at the start of contact? Look for who is calling, on whose behalf and why, followed by basic details of the debt and contact details.
  3. 3.What do voicemails, SMS and emails reveal to someone who is not the intended recipient? Look for wording that does not disclose a debt to third parties, and care with shared inboxes and reception lines.
  4. 4.If AI is speaking, is that made clear, and can the customer reach a human at any time? Look for upfront disclosure and an easy path to a person. Disclosure is best practice; ask your lawyer whether any specific obligation applies to you.

Questions 9-12: disputes, hardship and representation

  1. 1.What happens the moment a customer disputes the debt? Look for an automatic pause of collection activity on the disputed amount, handover to a person, and clear rules for when contact can resume.
  2. 2.Does the system ever ask the customer to prove they do not owe the money? Look for a firm no. The guideline treats implying that a debtor must disprove liability as misleading.
  3. 3.How does it respond when a customer says they cannot pay? Look for a route to a person, realistic payment options, and no pressure to take on further debt or access superannuation to pay.
  4. 4.Can it honour "do not contact me by this channel" and route contact to a nominated representative? In business collections, the debtor's accountant or bookkeeper is often the right contact.

Questions 13-16: accuracy of what is said, and payment plans

  1. 1.How does it make sure amounts are right and payments are reflected? Look for frequent ledger sync, handling of part-payments, credit notes and reversals, and no reminders for amounts already paid.
  2. 2.What is it allowed to say about the consequences of non-payment? Look for controls that stop threats you cannot, will not or have no instructions to carry out, including implying court or solicitor involvement that does not exist.
  3. 3.Who approves scripts, templates and automatically generated messages, and can I see every version? Look for versioned templates, consistent wording across channels, and no false urgency.
  4. 4.Are agreed plans documented and confirmed in writing, and does routine chasing stop while the customer keeps to the plan? Contact during a plan should be limited to defaults, requests, or genuine alternative offers.

Questions 17-22: records, privacy, recording and security

  1. 1.What is logged for every account? Look for the time, date, channel, content and outcome of every contact and attempted contact, plus payments and commitments.
  2. 2.Can I export a complete history for any account quickly? Look for an export you can hand to a lawyer, a regulator or an external dispute resolution body within days, not weeks.
  3. 3.What personal information is collected, where is it stored, and does any of it go overseas? Look for a plain-English answer aligned with the Australian Privacy Principles. Even B2B collection involves personal information about directors and accounts staff. The small business exemption still exists for now, but a second tranche of reforms is under consultation, so do not build your process around it.
  4. 4.How are calls recorded, what notice is given, and how are state and territory differences handled? Look for notice at the start of each call and a conservative approach across jurisdictions. Be wary of "recorded for training purposes" when recordings may also be used as evidence.
  5. 5.What is the security and data breach process, and what independent evidence exists? Look for documented incident response and assurance you can review, with scope and dates. A logo on a website is not evidence.
  6. 6.Will the vendor help us describe automated processing accurately in our privacy policy? Transparency obligations about certain automated decisions under the first tranche of Privacy Act reforms are due to start on 10 December 2026, so check with your privacy adviser.

Questions 23-25: governance and contract

  1. 1.Who is accountable for compliance on the vendor's side, and how are staff and mediators trained? Look for a named function, a compliance program, regular training and testing.
  2. 2.How are customer complaints handled, and how quickly do they reach a person? Look for an internal complaints path with escalation to someone with authority to resolve the matter.
  3. 3.What will the contract say about indemnities, audit rights and incident notification? Look for the right to audit or review call samples, prompt notice of incidents, and clear allocation of responsibility. Have a lawyer review this.

Red flags in vendor answers

  • "We're fully compliant" with no detail on how.
  • Recovery guarantees, or pressure tactics presented as best practice.
  • No dispute pause, or automation that keeps contacting a disputing customer.
  • Scripts you cannot see, or a "black box" AI with no controls.
  • Incomplete logs, or logs that omit attempted contacts and message content.
  • Certification claims without proof, such as badges with no scope, date or report.
  • Recording notices that say "training purposes" only, when calls will also be used as evidence.

Your own controls

Even with the right vendor, accountability stays with you. Build these into your process:

  • Write a short collection policy covering hours, frequency, tone, disputes, hardship and escalation.
  • Review scripts and templates with a lawyer before they go live, and after any change.
  • Sample real calls and messages every month, and read the disputes.
  • Set the escalation trigger, including which accounts never go to automation (key customers, disputes, vulnerable customers).
  • Keep the paperwork strong with clear terms, credit applications and accurate invoices.
  • Review quarterly, because privacy and guidance keep moving.

Sources

  • ACCC and ASIC, Debt collection guideline: for collectors and creditors (April 2021), also published as ASIC Regulatory Guide 96.
  • Office of the Australian Information Commissioner, Australian Privacy Principles guidelines (oaic.gov.au).

Where Chasyr fits

Chasyr is designed around the idea that the most compliant collection is one that resolves the issue early and fairly. The intended design is compliant outreach by SMS and email, AI voice calls within permitted contact hours, and handover to trained Australian mediators for disputed or sensitive accounts, following the SETTLE Method, our negotiation and mediation approach. We are not claiming certifications or regulatory endorsements. Chasyr is in development, with public launch in Australia planned for Q4 2026. You should expect any vendor, including us, to answer the 25 questions above in writing.

Compliance in debt collection software is not a badge you buy; it is a set of mechanisms you can see, test and evidence. Put these 25 questions to every vendor in writing, have counsel review the answers against the way you actually collect, and revisit them each quarter as privacy rules move.

Frequently asked questions

Is debt collection software legal in Australia?
Using software to contact customers is not unlawful in itself. What matters is how it contacts them: hours, frequency, accuracy of statements, handling of disputes and privacy all matter. Confirm which rules apply to your customers with a lawyer.
Does the ACCC and ASIC guideline apply to business-to-business debts?
The guideline was developed with individual debtors in mind but says many of its laws and principles are relevant to corporate and small business debts too. It is sensible to use it as a baseline, and to get advice on how the law applies to your customers.
Can AI make debt collection calls in Australia?
We are not aware of a blanket ban, but the same rules on hours, identification, accuracy, privacy and recording apply. Being clear that the customer is speaking to AI, and offering a person on request, is best practice. Ask your lawyer to confirm.
Do I have to tell customers that calls are recorded?
Recording laws vary by state and territory, so the conservative approach is to notify every person at the start of each call. Avoid describing recordings as "for training purposes" only if they may also be used as evidence.
Who is liable if my software vendor gets it wrong?
Responsibility for conduct on your behalf generally stays with you, and the guideline treats creditors as liable for their agents' conduct. Contract terms with the vendor can allocate some risk, but they do not remove your exposure. Take legal advice.

Part of Debt Collection Software Australia: The Complete Guide for Business Leaders.

Keep reading

This article is general information only and is not legal, financial, tax or accounting advice. Regulatory references are described as alignment objectives, not certifications or endorsements. Obtain advice from a qualified lawyer or accountant before acting. Chasyr is in closed alpha with a public launch targeted for Q4 2026.