ASIC Enforcement Trends 2025

ASIC Enforcement Trends: What You Need to Know for 2025

In a world where regulatory scrutiny is tightening, are you prepared for ASIC’s next move?

As we look towards 2025, the Australian Securities and Investments Commission (ASIC) is signalling a robust and ambitious enforcement agenda. For financial services businesses, staying ahead of these enforcement trends is critical. Whether you’re a licensee or an adviser, the message is clear: compliance isn’t optional, and scrutiny is only increasing under ASIC’s enforcement focus.

The ASIC Corporate Plan 2024-25 outlines the Australian Securities and Investments Commission’s (ASIC) strategic approach over the next four years (2024-2028). It addresses significant shifts in Australia’s financial landscape, focusing on consumer protection, market integrity, climate risk, and technological innovation. The plan sets out ASIC’s vision to be a “modern, confident, and ambitious regulator” as it navigates challenges like inflation, demographic shifts, and increasing cyber risks.

Key Observations

Strategic Priorities for 2024-2025

ASIC’s five main strategic priorities for the period include:

  1. Consumer Protection
  2. Greenwashing
  3. Better Retirement Outcomes 
  4. Technology and Operational Resilience 
  5. Reportable Situations
  6. Protection of Small Business

Of course, ASIC has also declared its intention to focus on consistency and transparency across markets, developing a licensing regime for buy now pay later providers and payment providers, targeting gatekeeper misconduct and implementing the Financial Accountability Regime and payment providers, but those topics will be explored elsewhere. 

1. Continued Focus on Consumer Protection for Financially Vulnerable Consumers

“We will also continue to act against systemic non-compliance by large financial institutions that results in widespread consumer harm.” ASIC Corporate Plan 2024-5, page 16

ASIC has always focused intensely on consumer protection, but this has intensified in recent years. In its 2024-2025 Corporate Plan, ASIC reiterated its focus on consumer protection and recommitted to addressing:

  • Predatory lending and financial hardship assistance
  • Product Design and Distribution
  • Insurance claims handling 
  • Dispute resolution

One of the ongoing enforcement priorities for 2025 is to deal fairly with and protect vulnerable consumers, especially from high-cost credit, predatory lending, misleading conduct and misconduct in superannuation and insurance. ASIC is also focused on the Design and Distribution Obligations (DDO) and the reasonable steps that Issuers and Distributors take to ensure their products reach the appropriate customers.

24-200MR ASIC calls on product issuers to review distribution practices

In light of the Senate Economics Committee’s criticism of ASIC’s performance as a regulator, anticipate both increased activity and more media releases and a shift towards more proactive, risk-based enforcement.

What to do: If you’re a licensee or adviser, now is the time to:

  • Review your website. 
  • Review your product selection and distribution frameworks. Pay particular attention to how the Licensee selects products for inclusion on its APL and critically examine the process followed for unlisted assets. 
  • Ensure that products are designed or distributed under the DDO regime
  • Review and update your compliance framework (particularly in respect of emerging risks) given ASIC’s declaration that “[ASIC is] committed to pursuing high penalties and sentences through the courts.”.
  •  Engage regulatory support and consider using technology to monitor compliance.
  • Engage regulatory consultants to review your IDR framework and compliance with RG271. 

But consumer protection is just one piece of the puzzle; ASIC’s focus extends to other critical areas as well enduring priorities including climate change and ESG promotion.

2. Greenwashing and Sustainable Finance

“We will undertake ongoing surveillance activity and take enforcement action, where necessary, to prevent harms from greenwashing and other sustainable finance-related misconduct.”       ASIC Corporate Plan 2024-5, page 18

With climate concerns gaining traction globally, ASIC is sharpening its enforcement focus on greenwashing—the practice of making false or misleading claims about the sustainability of financial products. In 2024, ASIC ramped up its actions against firms doing this and, for 2025, ASIC has indicated it will scrutinise claims more aggressively, focusing on whether businesses have a reasonable basis for such statements. It’s not all bad. In addition to focusing on climate-related financial disclosures and greenwashing, ASIC will support businesses in transitioning towards net-zero emissions, promote fair carbon markets, and ensure appropriate climate-related disclosures.

Key initiatives include:

  • Mandatory climate-related financial disclosures
  • Surveillance and enforcement actions to prevent greenwashing 

“We will establish a new team that will develop regulatory guidance, assess applications for relief and supervise compliance with the new obligations.” (p. 18)

What to do: If you’re offering sustainable finance products or promoting environmentally friendly business models or investments, ensure that verifiable data backs your marketing and disclosures. Misleading consumers can lead to significant penalties and reputational damage.

Those focus on ensuring that consumers are neither misled or disadvantaged underpins ASIC’s focus on retirement outcomes. 

3. Improving Retirement Outcomes

“We will take action to target misconduct in the superannuation sector, with a particular focus on member experience, including superannuation trustees’ provision of services to members, and harms arising from complaints handling and claims handling.” ASIC Corporate Plan 2024-5, page. 19

The ASIC Corporate Plan 2024-25 addresses retirement outcomes as one of ASIC’s strategic priorities signalling the regulator’s focus on improving outcomes for consumers planning for or already in retirement, with particular attention on ensuring that superannuation trustees comply with their obligations and that member services are enhanced. ASIC’s decision to protect and improve retirement experiences should consider:

  • Improved Services for Superannuation Fund Members: ASIC is monitoring how trustees provide services to their members, particularly regarding complaints and claims handling. ASIC is committed to addressing misconduct in the superannuation sector that negatively affects members.
  • Retirement Income Covenant: ASIC is focusing on the implementation of the retirement income covenant, which requires trustees to have strategies to improve members’ retirement outcomes. This involves ensuring trustees comply with regulatory obligations to provide better retirement planning and services.
  • Targeted Enforcement on Superannuation Misconduct: ASIC will take enforcement action against trustees who engage in conduct that results in the inappropriate erosion of superannuation balances (e.g., switching models or poor advice) and those failing to provide adequate services to members.
  • Surveillance and Review of Member Services: ASIC is undertaking a multi-year project to review compliance with laws related to trustee administration practices and services, such as death-benefit claims handling.

What to do: If you are a Trustee, or act for a Superannuation Fund, you should:

  • Develop comprehensive retirement strategies that align with the Retirement Income Covenant to improve retirement outcomes (including the provision of considered advice) 
  • Enhance Member Services and Client Support with an immediate focus on complaints and claims handling processes: 
  • Prioritise regulatory compliance by engaging Compliance Consultants to review your processes to ensure compliance with all relevant Guides, Standards and regulations (, particularly in the areas of advice quality, superannuation switching models, and the retirement income covenant).
  • Prevent inappropriate erosion of superannuation balances by avoiding practices that do not objectively serve clients or members interests. 
  • Ensure fair and efficient handling of death benefits by getting external confirmation that your claims handling processes meet legal requirements and industry standards.
  • Focus on client education and clear communication and help clients/members make informed decisions regarding their retirement planning. 

4. Technology and Operational Resilience Amid Emerging Conduct Risks

“We will continue to monitor how retail financial services and credit entities use AI and advanced data analytics. We will also assess their risk management and governance processes.” ASIC Corporate Plan 2024-5, page 20

ASIC is stepping up its focus on technology and operational resilience as the financial services industry becomes more reliant on technology. Ensuring that the financial system, markets and institutions are robust enough to handle technological disruptions and cyber threats is critical.​ ASIC has clarified that operational resilience and the ability to manage technological risks will be scrutinised in 2025. This includes assessing market participants’ responses to cyber incidents, outages, and data breaches. Interestingly, ASIC will also review how investment managers and financial advisers manage the risks of using offshore service providers.

ASIC’s focus on cybersecurity and technological risk is heightened due to the rapid adoption of AI and rising incidents of scams and data breaches. Key initiatives include:

  • Disrupting technology-enabled scams
  • Monitoring the use of AI in financial services
  • Enhancing cyber resilience across the industry

What to do

  • Strengthen your cybersecurity frameworks and ensure your technology infrastructure is resilient. 
  • Don’t exclusively rely on your Licensee’s arrangements but consider your own obligations, duties and risks.
  • Conduct regular testing and audits to identify vulnerabilities before they become regulatory issues.
  • Review your outsourcing arrangements and update your Privacy Policy.

5. Reportable Situations Regime and Market Integrity

“We will continue to conduct a targeted surveillance of licensees with low numbers of reportable situations and, where appropriate, take enforcement action.” ASIC Corporate Plan 2024-5, page 22

Introduced in 2021, the reportable situations regime remains a crucial concern for ASIC. Surprisingly, 89% of licensees failed to report under this regime in 2023, a figure that has triggered targeted surveillance by the regulator​. ASIC will likely enforce compliance more rigorously in 2025, mainly for licensees who need to report breaches as expected.

ASIC expressed concerns about under-reporting by some licensees, particularly those with low numbers of reportable situations. ASIC is actively monitoring and conducting targeted surveillance on licensees who may not be fulfilling their breach reporting and continuous disclosure obligations.

Key Actions ASIC Will Take:

  • Targeted Surveillance: ASIC will conduct surveillance on licensees with suspiciously low numbers of reportable situations and take enforcement action where appropriate.
  • Framework Development: ASIC plans to develop a framework for ongoing publication of the information it receives from breach reports, making the process more transparent and encouraging industry-wide compliance.

What to do

  • Review Internal Reporting Systems: Ensure that you have effective internal processes to detect and report breaches and schedule an external review to assess the adequacy of breach reporting procedures.
  • Enhance your Compliance Culture: ASIC’s scrutiny of low reporting suggests a need for licensees to foster a stronger compliance culture. This includes training staff on breach reporting obligations and establishing clear guidelines on what constitutes a reportable situation.
  • Prepare for Increased Transparency: The development of a framework for publishing reportable situations data will likely bring greater public scrutiny. Licensees should be prepared for their breach reporting practices to be visible and, therefore, must maintain accurate and timely reporting.

6. Protection of Small Businesses

“We will take enforcement action against financial services participants whose actions impact small businesses, including in relation to unfair contract terms and the promotion and supply of high-risk or unsuitable products.” ASIC Corporate Plan 2024-5, page 23

ASIC intends to take enforcement action against financial services participants whose actions negatively affect small businesses. The key focus areas include:

  • Unfair contract terms in financial services agreements
  • High-risk or unsuitable products targeting small businesses
  • Illegal phoenix activity, in collaboration with the Australian Taxation Office (ATO)

ASIC aims to safeguard small businesses financially vulnerable consumers from predatory financial practices and ensure they are not disproportionately affected by misconduct within the financial sector.

What to do: If your business works with small businesses:

  • Review and Amend Contracts to ensure they do not include any terms that could be deemed unfair under the relevant legislation. Eliminate clauses that may cause significant imbalance, are not necessary to protect legitimate interests, or could cause detriment to the other party.
  • Avoid promoting high-risk or unsuitable products and implement robust product governance frameworks to ensure that the promoted products are appropriate.
  • Provide regular training on compliance: to ensure that you (and your representatives) understand the specific financial risks that small businesses face (including predatory lending, unsuitable products, and unfair terms). 
  • Strengthen Due Diligence and Monitoring to ensure your internal compliance systems can detect and prevent misconduct, particularly in dealings with small businesses. Action: Conduct thorough due diligence on new and existing clients to detect potential signs of phoenix activity, and report any suspicious behaviour to relevant authorities.

ASIC’s enforcement priorities extend to specific industries that pose a high risk of financial harm to consumers. By focusing on these sectors, ASIC aims to mitigate widespread consumer harm and ensure compliance with regulatory obligations.

How to Stay Ahead of ASIC’s Enforcement Trends

As ASIC’s enforcement approach becomes more proactive and strategic, financial services businesses must focus on staying ahead of regulatory scrutiny. Here are some practical steps to ensure you remain compliant and out of ASIC’s crosshairs:

  • Enhance your risk and compliance frameworks to align with ASIC’s evolving priorities. Regularly review and update your compliance processes with an immediate focus on product governance, risk management, consumer protection, dispute resolution and reporting obligations. To stay ahead of ASIC’s enforcement trends, businesses must ensure their compliance frameworks are robust and aligned with regulatory obligations.
  • Leverage technology and regtech solutions like [complye] to improve monitoring and facilitate compliance in real-time. These tools can help automate reporting, track customer outcomes, and ensure adherence to DDO and reportable situations obligations.
  • Prepare for increased scrutiny on climate-related financial disclosures and adopt robust governance processes to avoid greenwashing allegations.
  • Invest in cyber resilience and ensure that AI technologies used by you to provide financial services satisfy your current obligations and anticipate ASIC’s evolving regulations.
  • Stay informed: ASIC’s priorities shift frequently, and keeping up with regulatory updates is essential. Engage with industry bodies, attend compliance briefings, and subscribe to ASIC’s news alerts.
  • Prepare for audits and surveillance: With ASIC increasing its surveillance activities, businesses should ensure they are always audit-ready. Conduct internal audits regularly to identify and fix any compliance gaps.
  • Get help. Effective risk management and regulatory support are critical for financial services businesses navigating the evolving landscape of financial services compliance.

ASIC’s enforcement trends for 2025 reflect a regulatory environment that prioritises consumer protection, transparency, and resilience. By understanding these trends and taking proactive steps to strengthen compliance, financial services businesses can avoid the pitfalls of regulatory action and build trust with consumers and the regulator. Legal and compliance professionals that represent Superannuation trustees should review their member services to ensure they align with ASIC’s focus on the financial system governance improving retirement outcomes.

Please speak with our team or read our 2025 Compliance Guide for more detailed insights on enhancing your compliance strategy.

 

If you liked this, we recommend that you read:

The Compliance Gap: Licensees’ anxieties and ASIC’s focus

An ASIC Enforcement and Regulatory Update

No future except risk management

Keep exploring

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?