ASIC Regulatory Guide 221 – Facilitating Digital Financial Services Disclosures (December 2025)

“We encourage providers to consider a range of options for presenting their disclosures, including more innovative digital options, and to adopt a format that will facilitate consumer engagement and an understanding of the financial product offered.”

RG 221.43

RG 221 marks a clear regulatory shift: ASIC now explicitly permits digital disclosure formats, removes outdated consent barriers, and enables a ‘publish and notify’ model without needing confirmation of receipt. This creates immediate operational flexibility for licensees, particularly in advice, client communication, and technology design.


The image depicts the major changes in RG 221.

Advice is Moving Forward

“You know it’s all the same, another time and place. Repeating history and you’re getting sick of it …  these things will change. Can you feel it now?”

Taylor Swift

This isn’t just a cultural moment; it’s a clear regulatory one. RG 221 gives licensees, advisers and product issuers explicit permission to modernise: disclosures no longer need to be pushed or received, consent isn’t a legal booby trap, and innovative formats are actively supported. This creates immediate operational flexibility for licensees, particularly in advice, client communication, and technology design. For the first time, digital-first advice models have a regulatory framework to build on.

RG221 “Facilitating digital financial services disclosure” sets out ASIC’s current regulatory approach to the digital delivery of financial services disclosures required under Parts 7.7 and 7.9 of the Corporations Act 2001. The guide replaces earlier versions and reflects ASIC’s acknowledgment that digital disclosure can improve regulatory and consumer outcomes, provided statutory disclosures are preserved.

We’ve repeatedly insisted that the Corporations Act provides flexibility, facilitates innovation and generally accommodates digital disclosure. RG221 confirms it.

However, while RG 221 is a welcome development, it’s important not to overstate its novelty. The guide provides practical clarity and operational flexibility, but it does not eliminate all regulatory uncertainty. Interpretive grey zones remain — particularly in how courts or AFCA may assess digital disclosures in complex or disputed scenarios. Practitioners should treat RG 221 as enabling, not exhaustive.

Equally, framing this shift as a binary choice between digital innovation and paper-based stagnation oversimplifies the terrain. Hybrid models, where digital and physical disclosures coexist to accommodate client preference and accessibility needs, will remain relevant. Innovation should be measured not by the medium alone, but by the clarity, effectiveness, and suitability of the disclosure for the intended audience. Pragmatically, ASIC has addressed industry apprehension by providing targeted relief addressing technical or procedural barriers, through ASIC Corporations (Electronic Disclosure) Instrument 2025/447.

“Parts 7.7 and 7.9 of the Corporations Act permit a wide range of financial services disclosures to be delivered digitally.”

RG 221.10

The most significant relief is the “publish and notify” method, which explicitly allows advisers, trustees, and product issuers to satisfy disclosure obligations by making disclosures available digitally and notifying clients of their availability, without requiring confirmation of receipt.

“We have given relief enabling providers to satisfy particular disclosure obligations by making disclosures available digitally and notifying the client that the disclosure is available … subject to certain conditions.”

RG 221.20-21

You may have had other things distracting you last year, but don’t overlook RG221 and its capacity to transform your business. The truth is that RG 221 matters because it:

  • Clarifies how disclosure obligations can be met without the direct production of physical documents.
  • Resolves uncertainty around client consent, confirmation, and formatting.
  • Actively supports interactive and multimedia disclosure formats.
  • Highlights risks around privacy, cybersecurity, and accessibility.

Now, RG221 does not dilute your overarching obligations or current duties, including the requirement that disclosures are “clear, concise and effective”, or that AFS licensees act “efficiently, honestly and fairly”.  It does, however, confirm that you don’t have to embrace deforestation to do so.

RG 221 has immediate consequences for licensees and compliance teams. It affects disclosure systems, client communication, record-keeping, and the move away from paper. If management or advisers are reluctant to depart from comfortable traditions and advice norms, you can encourage them to innovate by highlighting that failing to align digital disclosure practices with RG 221 may impede growth and expose them to regulatory, enforcement, and remediation risks.

Licensees and Advisers love prescription, so let’s start with the rules.


Commandment 1: Design for Consumer Understanding

“The disclosure can potentially incorporate a range of digital features such as video, audio, interactive menu features… and animation.”

RG 221.44

Digital disclosure should prioritise client comprehension and decision usefulness, not your administrative convenience. Content structure, navigation and sequencing should support how consumers read and engage digitally.

Key Considerations and Implications

  • You should be able to explain how the disclosure design supports understanding for the intended audience and channel.
  • Where disclosures are layered or non-linear, you should ensure consumers can readily locate key information without undue effort.
  • Innovation is regulator-endorsed, not merely tolerated.
  • The format choice must not compromise clarity or completeness.

Practical Steps

  • Establish proportionate testing of digital disclosures for comprehension and navigation;
  • Test innovative disclosures against comprehension and accessibility benchmarks.
  • Assess accessibility across devices and assistive technologies;
  • Review disclosure design to ensure risks, costs and limitations are given appropriate prominence;
  • Maintain alternative delivery options for clients who cannot reasonably access digital disclosures.

Working Example: Statements of Advice and the “Cover” Requirement

A critical historical obstacle to digital innovation for advisers was the assumption that a Statement of Advice (SOA) must have required information presented “on the cover”. This assumption stems from paper-based disclosure concepts and creates uncertainty for digital-only or interactive SOAs that lack a physical cover page.

RG 221.52–RG 221.55 clarify that such paper-based concepts should not be applied rigidly to digital disclosure. In a digital context, references to a “cover” should be understood as referring to the beginning or initial presentation layer of the disclosure, rather than a physical first page.

For advisers and licensees, this means that:

  • an SOA delivered digitally does not need to replicate a traditional cover page;
  • required information should be presented prominently at the start of the digital SOA, such as on an opening screen, landing page, or initial section;
  • layered or interactive formats may be used, provided key information is clearly signposted and readily accessible; and
  • compliance assessment should focus on prominence, clarity and accessibility, not on adherence to paper-document conventions.

This clarification removes a significant practical barrier to digital SOA design and supports the use of innovative formats that may better engage clients while still satisfying statutory disclosure outcomes.


Commandment 2: Make Clear, Concise and Effective Disclosures

Digital formats must meet clear, concise, and effective requirements through design, layering, and navigation, not merely through word reduction. Don’t ignore this obligation and reintroduce the complexity, redundancy and obfuscation for which Statements of Advice are known.

Considerations and Implications

  • “Concise” can be achieved by structural design (e.g. layering and signposting) rather than simply removing material information.
  • Test whether key risks, costs, limitations and rights remain clear in the chosen digital format.

Commandment 3: Prioritise Key Information

Design matters; don’t simply digitise poor-quality documents and expect better results. Focus on improving client engagement and understanding. Design choices, interactivity or navigation pathways must not obscure key risks, costs and limitations.

Considerations and Implications

  • Avoid design patterns that divert attention away from adverse information (e.g. burying fees or risks behind optional links).
  • Where information is layered, ensure the pathway to material information is obvious and not overly complex.

Commandment 4: Guarantee Ongoing Accessibility

Consumers must be able to reasonably access disclosures during the relevant decision period, including where content is delivered via portals or websites.

“A provider can use the publish and notify method even if it has not first secured client agreement. [but] The client may elect… not to receive relevant communications by the electronic means.”

RG 221.23-24

Considerations and Implications

  • This is not a requirement to prove a consumer accessed or read the disclosure. It is simply a requirement to design and operate delivery so that access is reasonably available.
  • Initial onboarding processes may be simplified, but Opt-out mechanisms must be clear, functional, and monitored.
  • Ensure that the information is available and accessible across common devices and settings (e.g., mobile, low-bandwidth) and that links and portals are and remain functional.
  • Where practicable, monitor access failure (e.g., hard bounces, repeated delivery failures, broken links), and have escalation pathways to provide disclosure by another permitted method.
  • Where publish-and-notify is used, ensure disclosures remain available for an appropriate period and are not withdrawn before consumers can reasonably access them.

Practical Steps

  • Document a formal publish and notify framework approved by Compliance and senior management;
  • Define which disclosure types and products may rely on publish and notify.
  • Establish standard notification content, including access instructions, opt-out mechanisms, and legitimacy messaging;
  • Implement controls to monitor and enforce the seven-day opt-out period.
  • Define escalation and re-notification requirements where delivery methods or formats change.

A defensible compliance position requires that RG 221.12 be applied together with RG 221.24, which is the operative provision governing client consent where publish-and-notify or inferred nomination is relied upon.

RG 221.24 provides that: “The client may elect, by a means reasonably specified in the notice, not to receive relevant communications by the electronic means.”

This provision is critical. It makes clear that client consent in the RG 221 framework is not binary or one-off, but is instead:

  • ongoing;
  • revocable at any time; and
  • capable of being exercised by practical and straightforward means.

RG 221.27 must be read together with RG 221.24. RG 221.27 provides an alternative pathway, under which: “the provider could decide to secure the client’s agreement to the publish and notify method.”

RG 221.27 clarifies that, where a provider wishes to rely on publish and notify immediately, or wishes to reduce reliance on inferred nomination and opt-out mechanics, it may instead obtain positive client agreement (for example, during onboarding).

Read together, RG 221.24 and RG 221.27 establish a dual consent architecture:

  • RG 221.24 preserves client autonomy through an ongoing opt-out right where agreement has not been expressly obtained; and
  • RG 221.27 permits providers to rely on an express agreement pathway where appropriate, without removing the client’s ability to change delivery preferences later.

Accordingly:

  • the absence of express prior consent does not equate to client indifference.
  • reliance on inferred nomination is always conditional on the client retaining an effective right to opt out under RG 221.24; and
  • securing agreement under RG 221.27 is a risk-reducing option, not a mechanism to lock clients into digital delivery.

In practice, RG 221.24 serves as the primary consent safeguard, while RG 221.27 serves as a compliance-enhancing alternative when certainty is required. Together, they confirm that client consent under RG 221 is dynamic, preference-driven, and revisitable, not fixed at a single point in time.


Commandment 5: Respect Client Preferences

“We have given relief from the requirement for a provider to be reasonably satisfied that the client has received the relevant PDS, FSG or SOA.”

RG 221.37

“A provider… is not required to use a mechanism to track whether a client has accessed the disclosure.”

RG 221.38

Where digital delivery is used, your clients must retain meaningful ability to opt out or change delivery preferences.

Considerations and Implications

  • Opt-out mechanisms should be easy to use and processed promptly, with systems that prevent further delivery when a client has opted out.
  • Even when express consent is obtained for digital delivery, you should still treat preferences as revocable and manage change requests.

Practical Steps

  • Establish proportionate processes to periodically prompt clients to confirm or update key contact details, particularly where digital-only disclosure is relied upon;
  • Monitor for reasonable indicators that an electronic address may no longer be reliable (e.g. hard bounce-backs, repeated delivery failures, prolonged non-engagement in circumstances where engagement would ordinarily be expected);
  • Define escalation and alternative delivery steps where such indicators arise;
  • Ensure advisers and frontline staff are trained to recognise and respond to risks to contact detail reliability.

Commandment 6: Monitor, Record and Track Disclosures

“We consider that Pts 7.7 and 7.9 operate to allow a provider to have more than one PDS for a financial product, more than one FSG for a financial service or more than one SOA for a single instance of advice provided that each version satisfies the requirements.”

RG 221.58

Despite this, record keeping continues to matter. You must be able to demonstrate what disclosure was made available, when it was available, and which version applied to the client.

Considerations and Implications

  • RG221 permits multiple versions, forms, and formats of regulated documents, but this increases version-attribution risk (proving precisely what they received at what time). You should implement unique identifiers, effective dates, and defined applicability for each version.
  • Record-keeping should evidence publication/availability and notifications, without requiring proof of client access.
  • Although Read-receipt tracking is not mandatory under publish and notify, you remain exposed if delivery failures are otherwise evident.
  • Version control and record-keeping become critical compliance functions.
  • Each version must independently satisfy statutory requirements.

Practical Steps

  • Implement a controlled repository for all disclosure versions, including digital-only and channel-specific formats;
  • Assign unique identifiers and defined applicability (e.g. channel, client type, device) to each version;
  • Maintain a controlled repository of all disclosure versions and availability dates.
  • Record publication, amendment, and withdrawal dates for each version;
  • Ensure advisers and relevant staff are trained to understand which disclosure versions apply in which contexts;
  • Prevent overwriting or informal modification of disclosures without traceability and audit logs.

RG 221.58 permits more than one version of a disclosure document to exist at the same time, provided each version independently satisfies the relevant disclosure requirements. While this flexibility is intended to support innovation across channels and devices, it also introduces material governance, evidentiary and conduct risk for licensees and advisers.

The existence of multiple disclosure versions elevates risk in several ways:

  • Version attribution risk – providers must be able to demonstrate which version of a disclosure applied to a particular client at a particular time;
  • Substantive inconsistency risk – differences in wording, sequencing or emphasis across versions may give rise to allegations that one version was misleading or less clear;
  • Governance and sign-off risk – multiple versions increase the complexity of compliance approval, change management and quality assurance processes; and
  • Adviser usage risk – advisers may inadvertently rely on an incorrect or inappropriate version, or be unable to evidence which version was used.

RG 221.58 does not reduce disclosure accountability. Instead, it shifts the compliance focus from maintaining a single document to managing multiple compliant versions in a controlled and auditable manner.

For advisers and licensees, the practical implication is that innovation in disclosure formats must be accompanied by stronger version control, training, and record-keeping. Failure to manage version-attribution risk may undermine reliance on RG 221 and expose providers to AFCA findings or regulatory action.


Commandment 7: Manage Technology, Cyber and Fraud Risk

“Providers will need to identify and manage the relevant technological risks, such as fraud, scams and identity theft.”

RG 221.4

Your decision to use digital disclosure systems must not expose your clients to unreasonable cyber, phishing or impersonation risks.

Considerations and Implications

  • Notifications should help consumers recognise legitimate communications and avoid requests for sensitive information.
  • Controls should be proportionate to sensitivity, with stronger measures for private disclosures than for general disclosures.
  • Cybersecurity controls are part of disclosure compliance.
  • Privacy Act and APP compliance is mandatory, not ancillary.

Practical Steps

  • Standardise disclosure notification design so clients can recognise legitimate communications;
  • Embed clear warnings that disclosures will not require personal or financial information to be entered.
  • Integrate cybersecurity and phishing mitigation controls into disclosure-delivery frameworks.
  • Segregate security controls for generic versus private disclosures;
  • Align disclosure delivery controls with the licensee’s broader cyber and privacy risk frameworks.

Commandment 8: Improve Governance and Risk Management

RG221 facilitates innovation but doesn’t entirely remove the burden of compliance; innovation in disclosure increases, rather than reduces, the need for disciplined governance, oversight and accountability.

Considerations and Implications

  • Providers should embed digital disclosure into governance frameworks (approvals, change management, incidents, assurance) rather than treating it as a communications channel.
  • Roles and accountability should be clear across your Compliance, Legal, Technology, product teams and advisers.

Practical Steps

The effectiveness of your innovation strategy should be:

  • Overseen by senior management or a delegated risk committee;
  • Subject to periodic compliance assurance or internal audit review;
  • Updated following regulatory change, material incidents, or significant disclosure model changes.

Conclusion

RG 221 represents a material recalibration of ASIC’s disclosure guidance to reflect contemporary digital engagement. It removes procedural rigidity while reinforcing substantive disclosure quality, consumer protection, and governance expectations.

The guide indicates that ASIC will assess compliance based on outcomes, not form. Providers who adopt digital and innovative disclosures without equivalent investment in governance, accessibility, and risk controls may face heightened regulatory scrutiny.

RG 221 reflects a principles-based regulatory posture. RG221 emphatically demonstrates that ASIC prioritises disclosure outcomes, such as accessibility, comprehension, and fairness, over delivery mechanics. In fact, the publish-and-notify model signals ASIC’s acceptance that modern consumers engage with information asynchronously and digitally.

However, ASIC simultaneously increases expectations around:

  • Governance of digital systems
  • Record-keeping of disclosure versions;
  • Consumer accessibility and vulnerability considerations; and
  • Cyber and privacy risk mitigation.

By addressing these obstacles explicitly, ASIC is signalling that:

  • innovation risk should no longer be treated as a legal risk by default.
  • the primary regulatory question is whether the disclosure outcome is achieved, not whether the format resembles a traditional document; and
  • providers should reassess legacy disclosure design assumptions that may no longer be justified.

Don’t misinterpret RG221 as an additional compliance burden or new obligations. ASIC isn’t mandating innovation or requiring providers to adopt digital disclosure; it’s simply removing the legal disincentives that previously constrained businesses trying to innovate. For Licensees and advisers, RG 221 is both an enabler and a compliance test. Those who align disclosure strategies with its principles can confidently improve business efficiency and modernise client engagement.

RG 221 gives you permission to modernise, but confidence comes from getting it right.

Assured Support helps licensees and advisers translate RG 221 into defensible, practical disclosure frameworks, from publish-and-notify models and digital SOA design to governance, record-keeping and cyber controls.

If you want to innovate without guessing where the compliance edges are, we’ll help you design digital disclosures that are regulator-ready, audit-proof and built to scale.

If you enjoyed this article, you might also like:


Frequently Asked Questions

What is ASIC RG 221?

ASIC’s Regulatory Guide 221 explains how financial services disclosure obligations under Parts 7.7 and 7.9 of the Corporations Act 2001 can be met through digital delivery, including innovative formats, provided the disclosures remain clear, concise, and effective.

Can disclosures be delivered digitally without client consent?

Yes. Under the “publish-and-notify” model in RG 221, providers can make disclosures available digitally and notify clients without needing confirmation of receipt, subject to conditions and opt-out provisions.

Do digital disclosures need a traditional cover page?

No. RG 221 clarifies that concepts like an SOA “cover” should be interpreted for digital formats based on prominence at the start, not paper conventions.

What ongoing rights do clients have under RG 221?

Clients always retain the right to opt out of electronic delivery; consent is ongoing, revocable, and not a one-off tick box under RG 221’s dual consent framework.

Does digital disclosure reduce compliance obligations?

No. While RG 221 enables digital delivery, providers must still ensure disclosures are clear, effective, accessible, and fully traceable, including version control and governance oversight.

Keep exploring

ASIC Regulatory Guide 221 – Facilitating Digital Financial Services Disclosures (December 2025)

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?