The draft was developed with input from the Advisory Group on Corporate Governance, chaired by former RBA Governor Dr Philip Lowe. This body was established following the October 2025 recommendations of an Independent Review Panel, which replaced the former ASX Corporate Governance Council.
ASX describes the draft as representing "evolution, not redesign" of the Principles. It retains the eight core Principles and the now familiar 'if not, why not' reporting framework. The focus is on simplification, modernisation and the removal of duplication with legislative requirements that have overtaken earlier editions of the Principles.
That characterisation is fair as far as it goes. But for governance professionals navigating increasingly complex regulatory and operating environments, the question is whether evolution is sufficient. This article examines five themes that warrant close attention from listed company stakeholders during the consultation period.
Consensus failures on diversity and inclusion: pragmatism or missed opportunity?
One of the notable aspects of the consultation paper is its candid acknowledgment that the former Corporate Governance Council was unable to reach consensus on a range of diversity and inclusion reforms, notwithstanding extensive consultation involving over 100 submissions during 2024–2025.
The result is a 5th Edition that maintains the existing 30% gender target for boards of S&P/ASX 300 entities, moves board diversity from Principle 1 to Principle 2 (Recommendation 2.3), and introduces disclosure about how diversity is incorporated into board succession planning, but proposes no additional numerical targets for other diversity characteristics or mandatory disclosure of diversity characteristics for individual directors. Workforce diversity is demoted to explanatory material in Principle 3, with reliance placed on the Workplace Gender Equality Act 2012 and associated instruments for companies with more than 500 employees.
The consultation paper frames this restraint as providing listed entities with “flexibility to determine how best to achieve diversity of thought, experience and perspectives". That is a defensible position, but one that requires some context.
The global retreat from Diversity, Equity and Inclusion (DEI) programmes (exemplified by executive orders in the United States and the conspicuous withdrawal of corporate commitments to diversity targets) has created a political environment in which any governance body proposing expanded diversity obligations faces accusations of regulatory overreach. In the Australian context, there is a legitimate question about whether prescriptive targets for characteristics beyond gender risk creating compliance burdens disproportionate to their governance benefit, particularly for smaller listed entities.
Yet the inability to reach consensus should not be mistaken for the absence of a problem – indeed it may be more symptomatic of one. Gender diversity on ASX 300 boards has risen from 38% to 73% between 2019 and 2025, which is a material achievement driven in no small part by the specificity of earlier recommendations. The principles-based alternative which is now adopted for other diversity characteristics essentially leaves it to individual boards how (and whether) to pursue diversity objectives. This approach risks producing precisely the kind of performative disclosure that the 'if not, why not' framework was designed to avoid.
The most likely practical implication is that diversity governance will increasingly be shaped by investor expectations and proxy adviser frameworks, rather than by the Principles themselves. The 5th Edition, in this area, follows rather than leads.
Geopolitical context and the return to basics: appropriate recalibration or wilful blindness?
The draft 5th Edition has been developed during a period of unprecedented geopolitical complexity: intensifying great-power competition, supply chain fragmentation, sanctions proliferation and the emergence of economic statecraft as a first-order business risk. Australian listed companies (particularly those in the resources, technology and financial services sectors) confront operating environments in which geopolitical miscalculation can give rise to material (and in some cases existential) risk.
Against this backdrop, the decision to pursue simplification and remove duplication is understandable as an administrative exercise. The removal of nine recommendations that now do little but replicate legislative requirements (including those relating to whistleblower policies, anti-bribery, poll voting, electronic communications and sustainability reporting) represents sensible housekeeping.
However, the broader orientation of the draft raises a different concern: that, by removing specific measures and replacing them with generic recommendations about "material risks", the Principles will retreat to a level of abstraction that may not serve boards well.
For example, the explanatory material to Recommendation 7.2 references "digital disruption, cyber-resilience, data governance, climate change, biodiversity, worker underpayments and third-party risk management". However, these appear as examples in a list, not as governance priorities warranting specific board attention. Other risks that have come to the fore in recent years, such as supply chain resilience, sanctions compliance, geopolitical risk management or sovereign risk assessment, are noticeably absent. The rationale within the Principles (that these matters are captured by the generic obligation to manage "material risks") assumes that boards already possess the frameworks and expertise to identify and govern these risks. That assumption may be warranted for the largest ASX-listed entities but is questionable for the broader population of approximately 1,800 listed companies.
The Principles’ 'return to basics' is defensible as a regulatory philosophy, particularly if one takes the view that listed company boards are already weighed down by excessive regulation. But there is a risk that, by the time the 5th Edition takes effect (for financial years commencing from 1 July 2027), the governance challenges facing listed companies will have evolved beyond what such a stripped-back framework can meaningfully address.
Emerging governance issues: AI, cyber and algorithmic decision-making
Perhaps the most striking omission in the draft 5th Edition is the treatment (or rather, non-treatment) of artificial intelligence, algorithmic decision-making and cyber security governance.
AI receives only one substantive mention in the entire draft, in the explanatory material to Principle 1, regarding the chair's role, where it notes that "AI can be used to summarise information in board packs and highlight key issues in the board papers" but "is not a substitute for a director exercising their own judgment and inquiry". Recommendation 2.2's explanatory materials list "technology" among potential areas of board expertise. That is the extent of the guidance.
This is a remarkable understatement of the governance challenge increasingly posed by AI. By the time reporting against the 5th Edition commences, AI will be embedded in credit decisions, trading algorithms, customer interactions, workforce management and regulatory compliance processes across virtually every sector. The real governance challenge is how boards should oversee algorithmic systems that make or materially influence decisions with legal, financial and reputational consequences, not simply whether directors should read their own board papers.
Cyber security presents a similar gap. "Cyber-resilience" appears in a list of examples in the explanatory material to Recommendation 7.2 (alongside such things as biodiversity and worker underpayments) without any recommendation as to board-level governance structures, reporting protocols or competency requirements. For an entity that has experienced a material data breach (and the frequency of such events continues to accelerate), the absence of specific governance guidance is conspicuous.
The counterargument, of course, is that the future is inherently unpredictable, that the Principles should remain technology-neutral and principles-based. But there is a meaningful distinction between prescription and relevant. A recommendation that boards should satisfy themselves as to the adequacy of their oversight of AI deployment and cyber security governance, without mandating specific structures, would still be consistent with the “less is more” / “if not, why not” philosophy, while signalling the centrality of these issues to contemporary governance.
The interface with mandatory regulation: should the Principles lead or lag?
The removal of nine recommendations on the basis of legislative duplication raises a fundamental question about the role of the Principles in Australia's governance architecture.
Historically, the Principles have served a dual function: providing a compliance framework for entities below the threshold of mandatory regulation, and signalling governance expectations in relation to emerging issues that may subsequently crystallise into legislation. They have operated as both floor and early warning system.
The 5th Edition explicitly repositions the Principles as complementary to, rather than anticipatory of, legislative requirements. Consultation Question 2 asks whether further recommendations with "substantial overlap with other regulatory disclosure and reporting obligations" could be removed. This is an invitation to further narrow the Principles, positioning them to address “matters not yet regulated by statute”.
This approach reduces compliance burden, avoids inconsistency between voluntary and mandatory frameworks, and respects the primacy of Parliament and regulators as the appropriate bodies to impose binding obligations. The removal of recommendations duplicating Part 9.4AAA (whistleblower protections), section 295A (CEO/CFO declarations) and Chapter 2M (sustainability reporting) of the Corporations Act 2001 (Cth) recognises that the governance landscape has moved on since the 4th edition was published.
But the risk in this approach is that the Principles lose their anticipatory function. If the framework only addresses matters already regulated, it becomes descriptive rather than normative: a restatement of existing law rather than a guide to best practice. The most valuable contributions of earlier editions were precisely those recommendations that ran ahead of legislation.
For the 5th Edition to remain relevant, it should retain the ambition to identify governance challenges before they become legislative mandates. The areas identified above, such as AI governance, cyber security oversight, and algorithmic accountability, are precisely the kinds of topics on which a forward-looking principles framework could provide meaningful guidance without duplicating existing law.
Effectiveness under organisational stress: the missing chapter?
History has proven that corporate governance frameworks are tested most not in calm conditions but in crisis.
The 5th Edition contains several elements relevant to organisational stress, such as the new Recommendation 8.2 regarding malus and clawback mechanisms, culture monitoring provisions including detection of material breaches, discussion of the deputy chair or senior independent director as a governance safeguard, and a reference to "crisis management and business continuity processes" in the explanatory material to Recommendation 7.2.
These are useful but fragmentary. What is absent is any integrated guidance on governance during periods of acute organisational stress, such as an investigation into management conduct, a material data breach requiring real-time disclosure decisions, a contested takeover, a regulatory enforcement action or a liquidity crisis.
The continuous disclosure policy in Recommendation 5.1 addresses rapid escalation of price-sensitive information but does not contemplate the governance architecture required when the board itself is operating under conditions of uncertainty, conflict or time pressure. The board performance evaluation framework in Recommendation 1.3 is also periodic and retrospective: it does not address the distinct challenge of board effectiveness during live crises. There is no recommended protocol for governance when the chair is conflicted, when information asymmetries exist between executive and non-executive directors, or when external advisers must be engaged at pace.
Crisis governance necessarily varies by circumstance, so it is inherently difficult to adopt a prescriptive approach. However, a recommendation that boards should establish and periodically test protocols for decision-making under conditions of organisational stress would fill a genuine gap. The M&A context alone (where boards are required to make fundamental decisions based on incomplete information and under significant time pressure) is illustrative of the inadequacy of governance frameworks designed exclusively for steady-state operations.
Evolution is necessary – but is it sufficient?
The draft 5th Edition of the Principles represents a positive step towards “governance housekeeping”. The simplification of the framework, the reinforcement of the 'if not, why not' approach and the removal of regulatory duplication are each individually sensible and (alongside the maintenance of the fundamental ‘if not, why not’ approach) will likely be welcomed by those who argue listed companies are already subject to excessive regulatory burdens. ASX and the Advisory Group are to be commended for delivering a cleaner, more accessible document that should overall reduce compliance costs.
However, it is also arguable that governance frameworks serve listed companies (and society at large) best when they are slightly uncomfortable: when they push boards to confront challenges they might otherwise defer. The 5th Edition, in its understandable pursuit of simplicity and consensus, risks producing a document that is unimpeachable in principle but lacking in substance.
In our view, the areas warranting constructive challenge are clear: the treatment of AI and cyber governance, the absence of crisis governance guidance, and the question of whether the Principles should aspire to lead governance practice rather than merely codify it.
Consultation over the 5th Edition of the Principles closes on 14 September 2026. The opportunity to shape a framework that will govern Australian listed companies through to the end of this decade should not be missed.