“[Financial advisers are] just under 1.4 per cent of the complaints [AFCA] receive. The number of complaints we get is actually quite low with regard to financial advisers. ”
— Mr Locke, Australian Financial Complaints Authority, AFCA QoN07
A solution in need of a problem
One of the key components of the “new and improved” regulatory framework launching in October is an improved, and data heavy, approach to complaints. For those of you playing at home, the other components of this new better-integrated approach is Design and Distribution Obligations, Enhanced Breach Reporting and Reference Checking.
At first glance, ASIC Regulatory Guide 271 “Internal Dispute Resolution” seems to be little more than a more polished, slightly updated version of ASIC Regulatory Guide 165 “Licensing: Internal and external dispute resolution”. We understand that view, but don’t let the new labels distract you from recognising the substantive changes to ASIC’s expectations.
We’ll address the specific and significant changes introduced in RG271 but, before that, let’s consider the cost-benefit equation for advisers and small licensees.
AFCA acknowledge that less than 1.5% of the complaints referred to them relate to financial advisers and “financial advisers/planners” aren’t even in the top 10 financial firms complained about.
So why change requirements that are, for all intents and purposes, meeting the objectives desired by our legislators?
In our view, it’s partially designed to address Insurers’ misconduct and maladministration, but the introduction of enforceable paragraphs shows an intention to improve the transparency and comparability of licensees.
We’ve remarked before that data is the new oil, and RG271 (and the broader connected reforms) that ASIC are moving (aggressively) into the oil business.

RG271 is a big topic, and we’re only addressing key points, so if you don’t have time to read the whole article, you can use the following index to jump directly to the sections that interest you.
One. The expansive definition of complaints
Five. Management responsibility
The Australian Financial Complaints Authority
Complaints and Red October
“Mr. Praline: ‘Ello, I wish to register a complaint.
(The owner does not respond.)”
— Monty Python, “Dead Parrot” sketch
In our webinar, and our upcoming AFA session, we explore the detail of RG271 and its consequences, implications and operational aspects.
We don’t intend to simply repeat that content here, but we will highlight a few key elements including the significant departures from RG165 and the new obligations imposed by, and enforced by, ASIC.
For example, RG165 (at 165.59) certainly confirmed their expectation that AFSLs would adopt the Australian Standard (AS ISO 10002-2006) definition of complaint, meet the guiding principles of that Standard and inform their clients of their access to their IDR system, but RG271 is more prescriptive.
At RG271.17 ASIC note that “Many firms have addressed the foundational aspects of their IDR process. However, we consider more progress can be made in key areas, including:
a. achieving organisation-wide understanding of the definition of ‘complaint’ and the types of matters that must be dealt with in a firm’s IDR process;
b. increasing the capture, tracking, analysis and reporting of complaint data;
c. improving timeliness and efficiency;
d. enhancing the quality of written communications and IDR responses;
e. strengthening complaint management skills;
f. fostering organisation-wide accountability for complaint management; and
g. leveraging the power of technology and data analytics to improve both the IDR process and the products and services offered by financial firms.
As general principles, they are eminently reasonable but they are enforceable provisions and, as every bush lawyer recognises, the devil is in the detail.
In an environment of increasing statutory, regulatory and compliance costs, and in a period of profound regulatory change, operationalising and maintaining some of these new requirements may be beyond the internal capability of many Licensees and advisers. Without expert support, or a dedicated compliance platform, many businesses may find themselves unable to comply.
Five specific concerns about RG271
One. The expansive definition of complaints
“Firms should encourage complaints and make it easy for people to voice their concerns by developing an IDR system that is readily accessible and easy to use. Firms should proactively identify people who might need additional assistance.”
— ASIC RG 271 at 131
Lets start at the very beginning; a very good place to start.
RG271 makes a number of changes but the most obvious one is the most central component – what defines a complaint.
Enforceable paragraph RG271.27-29 departs from RG165 to require firms to satisfy the following complaint definition
“[An expression] of dissatisfaction made to or about an organization, related to its products, services, staff or the handling of a complaint, where a response or resolution is explicitly or implicitly expected or legally required.”
The new reference to AS/NZ 10002:2014, is a reasonably required update but the expansion of the definition to explicitly include “posts … on a social media channel or account owned or controlled by the financial firm that is the subject of the post, where the author is both identifiable and contactable” should prompt Licensees and advisers to review their social media and marketing strategies. ASIC also emphasise that, if one responds to a complaint made on social media, one must ensure that the consumer’s privacy is protected. Clearly, as Harvey Norman demonstrated, it’s better not to respond over social media but to handle the complaint through your Internal Dispute Resolution (IDR) processes.
Given that complaints about the handling of insurance claims (e.g. excessive delays or unreasonable information requests) dominate AFCA’s leaderboard, it’s not surprising that these fall within the scope of the expanded definition. What is more surprising is that operational matters unconnected to the provision of financial services are also encompassed. RG271.32 specifically includes complaints about a matter that is the subject of an existing remediation program or about the remediation program itself (e.g. delays, lack of communication).
This might be less problematic but for the emphasis on remediation at the heart of the new breach reporting regime.
TIP:
- Review your complaints policy.
- Review your social media and marketing policy (and your social media activity)
- Consider whether you’ll permit consumer to comment on your website or page (and whether they can do so anonymously)
- Train your IDR/EDR staff.
- Train your non-IDR/EDR staff in the new requirements.
Two. Outsourcing
In the old RG165, ASIC addressed outsourcing by noting (at 165.73) that “a financial service provider, credit provider, credit service provider or unlicensed COI lender that outsources its IDR procedures to a third party service provider remains responsible for ensuring that its IDR procedures comply with the requirements in this regulatory guide.” In contrast, RG271 expands on the licensee’s responsibility and, in enforceable paragraph 271.48 state that
“Firms that outsource part, or all, of their IDR process must:
(a) have measures in place to ensure that due skill and care is taken in choosing suitable service providers;
(b) monitor the ongoing performance of service providers; and
(c) appropriately deal with any actions by service providers that breach service level agreements or fall short of their obligations under this regulatory guide.
You may consider it a subtle change but it will require Licensees to demonstrate more active engagement and better due diligence. Based on our data, few licensees currently manage outsourcing arrangements at the level required by ASIC. If Licensees fail to manage their key outsourcing relationships effectively, how will they manage an outsourced facility that they consider less critical than their unmanaged IT and planning software relationships? While this change might seem to benefit the usual suspects, the difficulty of managing lawyers should guide more licensees to regtech providers and advice specialists.
It’s also worth thinking about the new section on remedies. At 271.61 ASIC recommends that “Firms should consider a broad range of possible remedies when attempting to resolve complaints including:
(a) an explanation of the circumstances giving rise to the complaint;
(b) an apology;
(c) provision of assistance and support;
(d) a refund or waiver of a fee or charge;
(e) a goodwill payment;
(f) a payment of compensation;
(g) a waiver of a debt;
(h) replacing damaged or lost property;
(i) correcting incorrect or out-of-date records;
(j) repairing physical damage to property;
(k) changing the terms of a contract;
(l) ceasing legal or other action that may cause detriment; and
(m) undertaking to set in place improvements to systems, procedures or products.
TIP:
- Review your Outsourcing policy.
- Undertake due diligence of the provider before their appointment.
- Negotiate and document service standards and KPI. Ensure that any standards/KPI can be easily monitored and confirmed by you.
- Schedule the regular review of this arrangement.
Three. Tighter time-frames.
“A financial firm should acknowledge receipt of each complaint promptly. We expect that firms will acknowledge the complaint within 24 hours (or one business day) of receiving it, or as soon as practicable.”
In addition to that enforceable paragraph, RG271 also requires financial firms to “provide an IDR response to a complainant no later than 30 calendar days after receiving the complaint.
However, in some cases different timeframes apply, ASIC expect this standard to be met UNLESS
- the resolution is particularly complex (ie more than 6 years ago and requiring reconstruction); and/or
- circumstances beyond your control prevent you meeting that timeframe.
Unfortunately for licensees, the recalcitrance of your authorised representative (or former authorised representative) is not an acceptable reason for a failure to respond within 30 days.
Even in those rare circumstances, where the universe conspires to sabotage your compliance with this timeframe, you need to provide the complainant with a written notice that includes:
- the reasons for the delay
- their right to complain to AFCA if they are dissatisfied; and
- the contact details for AFCA.
“We recognise that applying this definition may result in increased administrative burdens and compliance costs in relation to capturing and maintaining records of minor expressions of dissatisfaction. Therefore, where a complaint or dispute (except for a complaint or dispute relating to hardship, a declined insurance claim, or the value of an insurance claim) is resolved to the customer’s complete satisfaction by the end of the fifth business day after the complaint or dispute was received, you will not be required to apply the full IDR process”
— ASIC Regulatory Guide 165 at 165.77
Unfortunately, RG271 erodes some of the flexibility provided by 165. In contrast to its predecessor, enforceable paragraph RG271.71 confirms that while there’s no need to provide an IDR response if the complaint is closed by the fifth business day after receipt. If the complaint is resolved to the complainant’s satisfaction or if you’ve explained/apologised why the firm can take no further action, it’s not the general exemption you may have expected.
In fact, enforceable paragraph RG271.75, confirms that even if resolved within five days, you must provide a written IDR response if:
(a) the complainant requests a written response; or
(b) the complaint is about:
(i) hardship;
(ii) a declined insurance claim;
(iii) the value of an insurance claim; or
(iv) a decision of a superannuation trustee.
TIP:
- Review your IDR/EDR process to ensure visibility, analysis and comparability.
- Automate the escalation of slipped deadlines.
- Simplify the process for lodging (and managing) complaints
- Use a compliance platform or reg-tech solution.
- Review and update your Remediation and Consequence Management Framework
Four. Data.
In addition to being, behind Picard, the best officer on the USS Enterprise-D, Data is a critical component of RG271.
Before we get to Data, let’s start by acknowledging enforceable paragraph RG271.118 that requires “Boards [to] set clear accountabilities for complaints handling functions, including the management of systemic issues identified through consumer complaints.”
The reference to systemic issues was not an accident. In fact, it’s repeated throughout the Guide and, in particular, at RG271.120 where ASIC explicitly state that Financial firms must:
(a) encourage and enable staff to escalate possible systemic issues they identify from individual complaints;
(b) regularly analyse complaint data sets to identify systemic issues;
(c) promptly escalate possible systemic issues to appropriate areas within the firm for investigation and action; and
(d) report internally on the outcome of investigations, including actions taken, in a timely manner.
This leads us, inexorably, to considering organisational capacity and the use of compliance platforms (reg-tech).
We can show you how OpenAFSL satisfies this requirement but, in any event, it’s important to appreciate ASIC’s view (enforceable paragraph RG271.179) that “Firms must have an effective system for recording information about complaints. The system must enable firms to keep track of the progress of each complaint.”
In fact, ASIC’s expectations could not be clearer. “[ASIC] expect firms with large volumes of complaints to use specialised complaints software or to integrate complaint management data fields into existing customer relationship management systems.” The exhortation at 271.180 may be directed to firms “with large volumes of complaints” but, irrespective of the nature, scale and complexity of your business, ASIC expect that you “should analyse complaint data regularly [to]:
(a) monitor the performance of the IDR process;
(b) identify possible systemic issues and areas where product or service delivery improvements are required; and
(c) identify matters that are likely to need to be reported to ASIC under s912D of the Corporations Act.
It’s certainly a tighter expression than RG165’s general observation (page 46) that “Complaints or disputes handling data is a useful means of tracking compliance issues or risks. We may require you to produce complaints or disputes data in certain circumstances. You should, therefore, keep this data in an accessible form.” All complaints or disputes should be classified and then analysed to identify systemic, recurring and single incident problems and trends. This will help eliminate the underlying causes of complaints or disputes.
To do this, you need to be able to analyse complaints or disputes according to categories, such as source of complaint, type of complainant, subject of complaint, product, cost and outcome of complaint, and timeliness of response.
We appreciate that you may not have received many complaints (and admire your confidence that this won’t change for you) but you need to actively consider these requirements and how you will demonstrate compliance.
Even if you don’t outsource or use a compliance platform, remember that ASIC expect you to collect and analyse the following data at regular intervals:
(a) number of complaints received;
(b) number of complaints closed;
(c) nature of complaints (e.g. product and problem);
(d) time taken to acknowledge complaints;
(e) time taken to resolve or finalise complaints;
(f) complaint outcomes, including:
(i) number of complaints resolved;
(ii) number of complaints unresolved;
(iii) number of complaints abandoned/withdrawn; and
(iv) details of amounts paid to complainants to resolve complaints;
(g) possible systemic issues identified; and
(h) number of complaints escalated to AFCA.
TIP:
- Review your IT capability and/or use a compliance platform.
- Engage an expert to assist with metrics, measures and analytics.
- Choose relevant benchmarks.
Five. Management responsibility.
“Unless the number of complaints is very small, we would expect compliance audits to be undertaken at least annually. Where non-compliance with this regulatory guide is identified, appropriate action should be taken—such as performance feedback, re-training and enhanced supervision for complaints management staff and, where appropriate, rectification for the complainants adversely affected by the non-compliance.”
— ASIC RG 271 at 271.189
Perhaps learning from the Royal Commission, ASIC’s focus on the Board’s responsibility to foster an appropriate culture of respect, helpfulness and accessibility (RG 271.130), is supplemented by more direct suggestions.
At RG271.128, ASIC state that Boards (if applicable), chief executives and senior management should be actively interested in, and support, effective complaint management by:
(a) having board and/or senior management oversight of the IDR process;
(b) providing adequate resources, including training and support to staff managing complaints;
(c) establishing and promoting a complaint management policy and procedure;
(d) implementing information technology (IT) systems and reporting procedures to ensure timely and effective complaint management and monitoring; and
(e) establishing clear roles and responsibilities for the management of complaints.
Their explicit responsibility for effective complaints management is a non-delegatable accountability and one that must be accurately reflected both in the firm’s governance activity and in the policies and procedures that constitute their governance/compliance framework.
If that wasn’t clear enough, enforceable paragraph RG271.183 requires “Financial firms [to] provide reports about complaints data regularly to senior management and the firm’s board (or equivalent) that detail:
(a) the number of complaints received;
(b) the number of complaints closed;
(c) the circumstances giving rise to complaints (e.g. products, services, and issues and reasons);
(d) the time taken to acknowledge complaints;
(e) the time taken to resolve or finalise complaints;
(f) complaint outcomes, including:
(i) the number of complaints resolved;
(ii) the number of complaints unresolved;
(iii) the number of complaints that were abandoned or withdrawn; and
(iv) details of amounts paid to complainants to resolve complaints;
(g) possible systemic issues identified;
(h) the underlying causes of complaints;
(i) complaint trends;
(j) the number of complaints escalated to AFCA; and
(k) recommendations for improving products or services.
TIP:
- Review your compliance framework to ensure visibility, analysis and comparability.
- Streamline reporting so that complaints data (or systemic issues) are appropriately prioritised.
- Review your IT capability and/or use a compliance platform.
- Review and update your Remediation and Consequence Management Framework
An aside: capability and culture
Culture and capability are important, but since we’ve already addressed five issues with RG271, we’ll deal with these topics as an aside.
In addition to the formal elements addressed above, ASIC’s focus on culture and capability needs to be properly appreciated.
ASIC expect that your staff will “treat complainants with respect, be helpful and adopt a user-friendly approach to complaint management” and “proactively identify people who might need additional assistance” (RG 130-131), but they also expect your IDR function be resourced so that it operates “fairly, effectively and efficiently” and have sufficient, and sufficiently capable staff, “to deal with complaints in a fair and effective manner within maximum IDR timeframes. This includes resourcing the IDR function to deal with intermittent spikes in complaint volumes.” (enforceable paragraphs 142 and 143).
In addition, ASIC expect that your IDR/EDR staff will have the knowledge, skill and experience to do their jobs. They define these core pre-requisites as:
(a) knowledge of this regulatory guide, consumer protection laws relating to financial products and services, AFCA approaches and relevant industry codes of practice;
(b) an understanding of the products and services offered by the financial firm;
(c) empathy, respect and courtesy;
(d) awareness of cultural differences and the ability to identify and assist complainants who need additional assistance;
(e) strong verbal and written communication skills; and
(f) analytical thinking and good judgement.
TIP:
- Review your IDR/EDR function and the team members’ formal and functional capabilities.
- Review/formalise financial delegations and responsibilities.
- Review, update or amend the job descriptions and performance/development plans.
- Assess whether the IDR/EDR team have the resources, materials and equipment they need.
- Engage HR to assess capability and/or address shortfalls.
The Australian Financial Complaints Authority
“I know you, you’re like this
When shit don’t go your way you needed me to fix it
And like me, I did”
— “You broke me first”, Tate McRae © BMG Rights Management
We initially, and perhaps unkindly, presented RG271 as a solution in need of a problem.
It’s clear that advisers and licensees receive complaints from retail clients, but at a far lower level than the complaints directed at Insurers, Trustees and Banks.
It’s also clear that, despite industry apprehension, AFCA is not inherently biased against financial planners. In our experience, neither FOS nor AFCA have acted in a demonstrably unfair manner. In fact, we’ve observed that they’re often reasonable and balanced in their approach.
We accept that advisers and licensees that are unsuccessful at AFCA have a different opinion, but it’s worth acknowledging that “for those matters that progressed to a final decision, 49% were in favour of the complainants and 51% in favour of the financial firms.”