The Payment Times Reporting Regulator held its Stakeholder Liaison Forum on 9 September 2026. The headline message for reporting entities is that identifying non-compliance remains the Regulator's priority, and that incorrect reporting may be treated as false or misleading reporting rather than as a technical error to be quietly corrected. The Regulator highlighted two areas entities have been often making calculation errors: the derivation of the 95th percentile payment time and the treatment of the invoice date. Given that false or misleading reporting carries a potential civil penalty exposure of up to 0.6% of total income, and that the Regulator continues to apply an escalating compliance approach to repeat non-compliance, accurate reporting is now a matter for boards and audit committees to take responsibility over as much as for finance operations. Below we set out a summary of the matters raised during the Forum and the practical next steps we recommend for all reporting entities.
Separately, we note the Regulator has begun writing to businesses and groups it believes have revenue above $100 million, requiring them to confirm whether the Payment Times Reporting obligations apply and, where they do, to prepare and lodge all outstanding reports within a set timeframe. Businesses should proactively assess whether they meet the reporting thresholds, rather than wait for a letter to arrive.
This was the most consequential clarification to come out of the Forum.
The Regulator confirmed that the 95th percentile payment time reported by an entity must be an actual payment time that appears in that entity's Small Business Trade Credit Payment (SBTCP) dataset. It cannot be an average of two adjacent values, and it cannot be an interpolated value sitting between two observed payment times. Put simply: if no small business trade credit payment in your dataset was made in 27 days, then 27 days cannot be your reported 95th percentile payment time.
The trap here is a practical one. The Regulator has published formula examples in its guidance material and in its worked example, and many entities, reasonably, have built their reporting processes directly on those formulas, or on the default percentile functions in Excel and similar tools, which interpolate by design. The Regulator was clear at the Forum that entities should not rely on those examples, because depending on the size and distribution of an entity's dataset they will not always return a value that actually exists in the data. Responsibility for arriving at the correct figure sits with the entity.
Where an entity has reported an averaged or interpolated figure, the Regulator's position is that the report is incorrect and should be revised.
The Regulator also reminded entities of the way individual payment times are to be calculated. The payment time for an invoice is:
Payment date – invoice date (or invoice receipt date, where applicable) + 1 day
The "+1 day" matters. The day the invoice is issued or received forms part of the payment time. The only exception is where payment is made on or before the invoice date or invoice receipt date, in which case the payment time is recorded as zero.
An entity that has calculated payment times as a simple date difference has understated every payment time in its dataset by one day. That error flows through to its reported metrics, its average and median payment times, and its percentile calculations. The Regulator confirmed that this will also be treated as false or misleading reporting.
False or misleading reporting is not treated as a minor administrative issue under the Payment Times Reporting framework. Civil penalty exposure for a reporting entity can potentially reach 0.6% of total income for the income year in which the contravention occurred, where a payment times report is false or misleading in a material particular. For an entity with $2 billion of total income, that is a theoretical maximum of $12 million, which was driven, potentially, by the methodology applied to a single field in a payment times report.
We also expect that the Regulator is seeking to ensure all entities are disclosing their reports based on the correct calculations to ensure that it is able to assess fairly and accurately which are in the slowest 20% of small business payers, and it may be prepared to issue penalties to ensure accurate reporting across all entities before it starts to issue slow small business payer directions.
There is also a reputational dimension. Reported data is published, so errors are visible to customers, suppliers and procurement teams, particularly where payment performance is referenced in tender processes or supplier negotiations.
The Forum featured Jane Christie, the new Payment Times Reporting Regulator, but also confirmed that the compliance approach has not changed.
The Regulator continues to apply an escalating approach to non-compliance. In practice, at first instance, a late lodgement will typically attract a notice of non-compliance. A second instance moves the entity up the escalation ladder, and the Regulator may then take action including issuing an infringement notice with penalties.
The key implication is that compliance history is cumulative. An entity that received a notice of non-compliance for a late report in an earlier period is not starting with a clean slate. A further late lodgement, or an incorrect report, may be met with a penalty rather than a warning.
This escalation risk is not limited to entities already in the system. As noted above, the Regulator has been contacting businesses and groups it considers may sit above the $100 million revenue threshold, asking them to confirm their reporting status and, where the rules do apply, allowing a fixed period to bring all overdue reports up to date. It is possible this exercise has been informed by data matching against tax return information held by the ATO.
The practical consequence is that entities which have not turned their mind to whether they are caught by the regime are increasingly likely to be identified. Where an entity concludes it has an unmet obligation, the timing of how that comes to light matters: an unprompted approach to the Regulator is far more likely to be handled as a first-instance matter, while a response to Regulator-initiated correspondence is being made under a timeframe the entity has no control over, and with escalation already a live possibility.
There remains no update on the slow small business payer direction. The Regulator advised that it is still analysing the data it holds.
The absence of an announcement should not be read as an absence of risk. The data analysis being undertaken by the Regulator is precisely the process that will identify candidate entities. Entities that expect to sit in the slowest-paying cohort have a window, of unknown duration, in which to act before decisions are made.
Review your data extraction process and calculation methodology, with particular attention to whether your 95th percentile output is an actual observed value in your Small Business Trade Credit Payment dataset or an interpolated figure produced by a formula or software function; whether your payment time calculation includes the invoice date / invoice receipt date (the “+1 day”) and correctly records zero for payments made on or before that date; and how invoice receipt date is captured where it differs from invoice date. Where you identify an error, revise the affected reports as soon as possible. Proactive correction is a materially better position than being identified by the Regulator as having lodged a false or misleading report.
Start by identifying the first financial year in which your business or group exceeded the $100 million threshold, as the obligation runs from that year onward. Trigger years are frequently missed, often where income crossed the threshold on the back of a strong year, or where an acquisition or restructure brought additional entities into a reporting group. Because the obligation is ongoing, missing the trigger year means every reporting period since has also been missed. Given the Regulator's letter campaign and its apparent use of ATO data to identify likely reporting entities, an unassessed position is unlikely to remain unnoticed. Where you identify unlodged or overdue reports, disclose to the Regulator without delay. The objective is to avoid being placed on or moved further up in the escalated compliance ladder, where infringement notices and penalties become live.
Model where your payment performance is likely to sit relative to your peers and the published data. If there is a realistic prospect you fall into the slowest-paying group, consider voluntary disclosure and engagement with the Regulator before decisions on slow small business payer directions are made. Engaging early with a credible remediation plan is a far stronger position than responding to a direction after the fact.
We support reporting entities across the Payment Times Reporting lifecycle, including:
If you would like to discuss what the Regulator's clarifications mean for your reporting, please contact your PwC engagement team or Sean Lee, Partner.
For more information, visit PwC’s main Payment Times Reporting webpage.
Sean Lee
Partner, Tax Reporting and Innovation, PwC Australia