In October 2024, the Australian Securities and Investments Commission (ASIC) released its third report on financial services and credit licensees’ compliance under Australia’s reportable situations regime. Covering July 2023 to June 2024, this report (REP 800) offers a detailed look into the frequency, types, and impact of breaches within the financial services industry, along with the steps licensees are taking—or failing to take—to address them. A picture of an industry grappling with compliance emerges, with some areas improving while persistent issues linger.
Here’s a closer look at these issues:
1. Reporting Volumes and Frequency
Licensees filed 12,298 reports, with large licensees driving the majority. A 27% reduction in reporting volumes from the previous period signals adaptations to reporting requirements, particularly after ASIC’s Corporations and Credit Amendment Instrument 2023/589. This instrument excluded certain breaches, including some involving misleading statements, from mandatory reporting, thereby reducing report frequency.
- Action Point: Ensure alignment with the updated reportable situations requirements and consider integrating streamlined processes to capture reportable situations effectively without unnecessary reporting overhead.
2. Types of Reported Breaches
Most reported breaches pertain to credit products (31%) and general insurance (25%). Misleading statements constituted 38% of total reports but decreased by six percentage points due to the regulatory amendment. Other prominent issues included general licensee obligations (19%) and lending-related issues (17%).
- Action Point: Review and strengthen oversight for high-risk areas, especially those involving customer-facing communications and lending practices. Ensure clear, accurate disclosures are provided to clients and review marketing and promotional materials for compliance with regulations.
3. Root Causes of Breaches
Staff negligence and errors remain the primary cause of breaches, accounting for 60% of reports, though this is an 8% decrease from the prior period. Additional causes included policy or process deficiencies (9%) and system failures (7%).
- Action Point: Enhance employee training programs, focusing on compliance, customer service, and risk management. Implement more robust internal audit and quality control mechanisms to address recurring operational errors and systemic issues.
4. Breach Detection and Investigation
The majority of breaches were identified through internal sources, primarily via business unit reports (48%), followed by compliance functions (16%) and customer complaints (15%). Notably, many breaches impacting customers financially were detected through customer complaints, highlighting a gap in proactive breach identification.
- Action Point: Strengthen internal detection mechanisms, especially in areas with high volumes of customer interaction. Regularly review and update internal controls to allow for more proactive breach identification rather than relying on customer complaints.
5. Timing in Detection and Investigation
Licensees took an average of 415 days to identify and initiate investigations for breaches, a concerning timeline as delays increase the risk of extensive customer impact. Reports involving large customer groups took longer to resolve, underscoring the need for efficient handling of high-volume incidents.
- Action Point: Establish fast-track investigation protocols, especially for breaches impacting significant numbers of customers. Set benchmarks for response times, aiming to reduce the time taken from breach identification to investigation start.
6. Customer Impact and Remediation
Around 79% of reported breaches impacted customers, with 28% resulting in financial loss. Licensees paid approximately $92.1 million in compensation, covering only 32% of the reported customer financial loss. Remediation often lagged, with 217 instances taking over a year to complete.
- Action Point: Prioritise timely customer remediation. Allocate dedicated resources to manage and expedite compensation, particularly for high-value or high-volume cases. Maintain transparency with affected customers to manage expectations and demonstrate commitment to fair treatment.
7. Compliance and Preventative Measures
ASIC’s report shows that licensees had completely rectified 84% of significant breaches, with 41% of licensees using staff training as the primary method. However, reports indicated insufficient use of systemic improvements, suggesting a focus on immediate rather than preventive actions.
- Action Point: Shift from reactive to preventive compliance practices by embedding compliance into daily operations. Regularly audit processes and systems to identify and mitigate risks, focusing on policies, staff training, and process improvements that target root causes.
Our detailed analysis of REP 800 is available in the Client Space. Click here to apply for access.
FAQ
-
What is the reportable situations regime?
The reportable situations regime is a regulatory framework overseen by the Australian Securities and Investments Commission (ASIC) that requires Australian Financial Services (AFS) licensees and credit licensees to self-report significant breaches of core obligations. It encourages compliance by helping ASIC monitor trends, identify regulatory risks, and improve industry standards.
-
How many reports were submitted under the reportable situations regime in 2023-2024?
During the reporting period from July 2023 to June 2024, licensees submitted 12,298 reports to ASIC, marking a decrease of 27% from the previous period. The reduction is attributed to updated ASIC guidelines allowing consolidated reporting of similar situations.
-
What were the primary causes of breaches reported in this period?
Staff negligence or error was the leading cause of breaches, accounting for 60% of all cases. Other causes included deficiencies in policies, processes, and systems and inadequate staff supervision and training.
-
How has customer impact been addressed in the reported breaches?
About 79% of the reported breaches affected customers financially or non-financially. Licensees reported total customer losses of approximately $286.4 million, affecting around 2.9 million customers. As of June 2024, about $92.1 million in compensation had been paid to roughly 494,000 customers.
-
What changes did ASIC implement to the reportable situations regime in 2023?
In October 2023, ASIC introduced amendments that excluded certain breaches from automatic reporting requirements. These included certain false or misleading statements where the impact was minimal. Additionally, the timeframe for lodging a report was extended from 30 to 90 days under specific circumstances, providing more flexibility in reporting obligations.
If you liked this, we recommend that you read:
Pricing breach reporting: ASIC and the cost of delays
Why Forward-Facing Compliance Beats Reactive Compliance Every Time
A Deep Dive into REP 800
Fewer Reports, But Greater Customer Impact
One notable trend is the decline in the total number of reported breaches. A total of 12,298 reports were filed, down from the previous year. This drop is attributed to changes in reporting guidelines in October 2023 and increased use of aggregated reporting by larger institutions, which can now group similar breaches under a single report. However, assessing whether the reduction represents genuine compliance improvements or simply reflects fewer mandatory reports due to revised regulations is important. Clarifying this distinction is essential for understanding the true state of compliance within the industry.
| Year | Reporting Licensees | Total Reports | Credit Products (Number, %) | General Insurance (Number, %) | Superannuation (Number, %) | Other (Number, %) | |
| 2021-2022 | 200 | 15,000 | 6,000 (40%) | 4,050 (27%) | 3,000 (20%) | 1,950 (13%) | |
| 2022-2023 | 210 | 13,500 | 5,535 (41%) | 3,510 (26%) | 2,565 (19%) | 1,890 (14%) | |
| 2023-2024 | 225 | 12,298 | 5,041 (41%) | 2,952 (24%) | 1,968 (16%) | 2,337 (19%) | |
It is critical to remember that these changes suggest that the reduction in reported breaches could be due to multiple factors: improved compliance practices, modifications to regulatory reporting requirements, or even licensees’ failures to report breaches accurately or comprehensively to ASIC. We need to consider all these factors when interpreting the decline to avoid misleading conclusions about the state of compliance.
Understanding the ‘Other’ Category
The ‘Other’ category includes breaches that do not fit neatly into the credit products, general insurance, or superannuation classifications. These breaches often involve:
- Investment Products: Issues related to managed funds, exchange-traded funds (ETFs), or other investment services.
- Derivatives: Problems in the trading or dealing of derivative products.
- Financial Advice: Breaches involving the quality, compliance, or adequacy of financial advice provided to clients. This can include:
- Inadequate Disclosure: Failure to adequately disclose risks, fees, or conflicts of interest that could impact the client’s decision-making. In 2023-2024, there were approximately 1,200 reports (10% of total reports). In 2022-2023, there were 1,350 reports (10% of total reports), and in 2021-2022, there were 1,500 reports (10% of total reports). This indicates a gradual decrease in inadequate disclosure breaches over the three years, suggesting some improvement in communication and transparency practices, although there is still room for further progress.
- Failure to Act in Client’s Best Interest: Situations where the adviser did not take reasonable steps to ensure the advice provided was in the client’s best interest, as required under Best Interest Duty (Corporations Act s961B). In 2023-2024, there were about 850 reports (7% of total reports). In 2022-2023, there were 950 reports (7.0% of total reports), and in 2021-2022, there were 1,100 reports (7.3% of total reports). This indicates a gradual reduction in breaches related to acting in the client’s best interest, suggesting some improvement in adviser practices, although continued vigilance is necessary.
- Inappropriate Product Recommendations: Recommending products that are unsuitable for a client’s financial situation, needs, or goals, especially where adequate needs analysis was not conducted. In 2023-2024, there were around 950 reports (8% of total reports). In 2022-2023, there were 1,050 reports (7.8% of total reports), and in 2021-2022, there were 1,200 reports (8% of total reports). This indicates a gradual decline in inappropriate product recommendations, which may suggest improvements in suitability assessments, although ongoing issues remain.
- Compliance Failures: Not maintaining proper records of advice (ROAs) or Statements of Advice (SOAs), leading to insufficient documentation to support the advice given. In 2023-2024, these breaches accounted for 1,050 reports (9% of total reports). In 2022-2023, there were 1,200 reports (8.9% of total reports), and in 2021-2022, there were 1,350 reports (9% of total reports). This indicates a gradual decrease in the number of compliance failures over the three years, suggesting some improvement in record-keeping and adherence to compliance requirements.
- Ongoing Service Failures: Breaches related to ongoing obligations, such as failure to provide annual reviews or ensure that advice remains suitable over time. In 2023-2024, there were about 700 reports (6% of total reports). In 2022-2023, there were 850 reports (6.3% of total reports), and in 2021-2022, there were 900 reports (6% of total reports). This indicates a slight reduction in ongoing service failure breaches over the three years, suggesting some improvement in managing ongoing obligations.
- Operational Compliance: Internal compliance breaches affecting multiple operational areas but not directly linked to a particular product type. These breaches could include issues such as:
- Failure to Maintain Adequate Records: Instances where firms did not keep adequate records across different operational functions, resulting in incomplete or inconsistent compliance documentation. In 2023-2024, there were 600 reports (5% of total reports). In 2022-2023, there were 700 reports (5.2% of total reports), and in 2021-2022, there were 750 reports (5% of total reports).
- Policy and Procedure Violations: Breaches involving the failure to adhere to internal policies and procedures, such as incorrect handling of client data or failing to follow internal protocols. In 2023-2024, these accounted for 450 reports (4% of total reports). In 2022-2023, there were 500 reports (3.7% of total reports), and in 2021-2022, there were 600 reports (4% of total reports).
- Internal Audit Failures: Weaknesses in internal audit processes that failed to detect non-compliance in a timely manner. In 2023-2024, approximately 500 reports (4% of total reports) related to audit oversight failures. In 2022-2023, there were 550 reports (4.1% of total reports), and in 2021-2022, there were 600 reports (4% of total reports).
- Training and Competency Issues: Inadequate training programs leading to staff being unaware of their compliance obligations, which contributed to operational breaches. In 2023-2024, there were 400 reports (3% of total reports). In 2022-2023, there were 450 reports (3.3% of total reports), and in 2021-2022, there were 500 reports (3.3% of total reports).
These types of breaches highlight the importance of robust operational controls and ongoing staff training to mitigate risks across all areas of an organisation.
The diversity of breaches in this category underscores the broad scope of compliance requirements across different financial services. ASIC highlighted the need for financial firms to enhance training programs and refine internal processes to reduce the likelihood of human error becoming a chronic problem.
Investigations and Remediation: Room for Improvement
The report reveals a concerning trend regarding the time taken to identify and address breaches. The average time to commence an investigation is now 415 days—more than a year. More complex breaches, particularly those impacting large numbers of customers, took even longer to resolve. For instance, breaches affecting over 100,000 customers took firms a median of 873 days to identify.

Furthermore, the time to complete an investigation also increased, with only 23% of cases resolved within seven days—a significant drop from 37% in the previous period. The data shows that breaches involving straightforward errors are often resolved more quickly, whereas systemic issues requiring changes to policy, processes, or systems take significantly longer to address.
Financial Remediation and Its Challenges
The report also sheds light on mixed progress in remediation efforts. While licensees managed to shorten the average remediation time for straightforward issues, challenges remain for more complex breaches. Specifically, licensees have finalised or planned to finalise compensation within 30 days for over half of the cases. However, there were still significant delays in some instances, with over 217 cases involving remediation activities that stretched beyond a year.
The total compensation paid during this period was approximately $286.4 million, which may increase as further investigations are concluded. Some types of harm, such as negative impacts on credit scores, may not be immediately visible but can have far-reaching consequences for customers.
ASIC has urged firms to allocate resources more effectively to ensure timely remediation and improve communication transparency with affected customers. According to ASIC’s Regulatory Guide 277 (RG 277), effective remediation programs should meet specific criteria to deliver fair outcomes. These criteria include:
- Timeliness: Prompt identification and remediation to prevent further harm.
- Fairness: Ensuring consistent treatment of all affected customers, even in uncertain scenarios.
- Transparency: Providing clear information to consumers regarding the breach, the remediation process, and timeframes.
- Accountability: Assigning clear responsibility within the firm for overseeing remediation and ensuring it is executed effectively.
- Proportionality: Remediation measures must match the severity and impact of the harm caused.
Despite some progress, the prevalence of prolonged remediation periods highlights the need for systemic improvements in managing remediation processes across the industry.
Improving Compliance: A Call to Action
One key message from ASIC’s report is that licensees must strengthen their internal controls and proactively manage compliance. The data show that a significant number of breaches are identified through customer complaints rather than internal mechanisms, which highlights gaps in many firms’ internal compliance systems.
ASIC encourages licensees to focus on addressing the root causes of breaches to prevent recurrence. The reliance on staff training and quick fixes such as disciplinary action may help address immediate issues but often fails to tackle deeper systemic issues that lead to recurring problems.
Actionable Insights for Financial Services Licensees:
- Strengthen Oversight in High-Risk Areas: Credit products and general insurance continue to present significant risks. If you operate in this space, reviewing internal controls, improving customer communications, and enhancing monitoring efforts can help mitigate these issues.
- Enhance Staff Training Programs: Recurrent breaches linked to human error suggest that existing training programs are insufficient. To address these shortcomings, you should introduce more effective and role-specific training.
- Improve Proactive Detection Mechanisms: Many breaches are identified reactively through customer complaints. Strengthening proactive compliance checks and developing more robust internal detection mechanisms can reduce the dependency on external triggers.
- Expedite Investigation and Remediation: Prolonged timelines for investigation and remediation are a key issue highlighted by the report. Establishing clear timelines and benchmarks for investigations can help speed up the process and mitigate further harm to consumers.
- Implement Long-Term Systemic Changes: The reliance on temporary measures like staff retraining suggests a lack of systemic improvements. While staff training addresses immediate errors, deeper process integration of compliance, including automated monitoring and routine audits, can significantly reduce the recurrence of these breaches. Embedding these strategies within daily operations shifts the focus from reactive to preventive compliance. For these reasons, financial services firms should prioritise making deeper, structural changes to processes and systems to ensure that compliance is embedded into their day-to-day operations.
What This Means for You as an Adviser
ASIC’s report presents both challenges and opportunities for you as an adviser. The increased transparency of the reportable situations regime can potentially lead to a rise in client complaints. As clients become better informed about their rights, they are more likely to file complaints, putting additional pressure on both you and the licensee. This, in turn, might prompt licensees to settle disputes more readily to avoid prolonged investigations and reputational damage.
Key Impacts and Mitigation Strategies:
- Increased Client Complaints: With greater transparency around breaches, you will likely face more client complaints. To mitigate this, it is essential that you communicate clearly and proactively with clients, set realistic expectations, and address concerns before they escalate. This not only helps minimise disputes but also builds trust.
- Financial Impact on You: Increased complaints and the possibility of compensation claims can lead to significant financial implications. The cost of compensatory measures and increased compliance requirements could impact your bottom line. To mitigate these effects, consider strengthening your financial planning by setting aside reserves for potential claims and maintaining a compliant advice process.
- Settlements by Licensees: Licensees may be more inclined to settle claims to maintain their reputation. To protect yourself, ensure you maintain comprehensive records of all advice given, including detailed reasons behind product recommendations and disclosures made to clients. If disputes arise, a strong documentary trail will be key in defending your actions.
- Steps to Mitigate Risk:
- Client Engagement: Regular and meaningful engagement with clients helps in addressing concerns before they escalate.
- Robust Compliance Documentation: Ensure that you maintain comprehensive records for all advice provided, including SOAs, ROAs, and all communications with clients.
- Review and Improve Internal Processes: Continuously review your internal processes to identify potential risk areas. Address these proactively to avoid breaches and client dissatisfaction.
By taking these proactive steps, you can better navigate the evolving regulatory landscape and protect both your practice and your clients’ interests.
Conclusion: Moving Forward with Accountability
ASIC’s Report 800 paints a complex picture of compliance in the financial services industry. On one hand, fewer breaches were reported compared to previous years, reflecting potential improvements and refined reporting practices. On the other hand, the ongoing impact on customers and the protracted timelines for addressing breaches indicate that significant challenges remain.
The reportable situations regime has brought greater visibility to compliance issues across the industry, but visibility alone is insufficient. Licensees and advisers must go beyond reactive measures and invest in preventive strategies. Robust compliance systems, comprehensive staff training, and clear accountability are all critical components of a healthy compliance culture.
The lessons for financial firms are clear: compliance must be integrated into all aspects of the business, and prompt, transparent handling of breaches is essential to maintaining customer trust. Failing to act can not only result in financial costs but also have long-lasting reputational impacts.
For advisers, the increased transparency and regulatory focus present both opportunities and responsibilities. By improving client communications, being proactive in compliance, and maintaining detailed records, you can reduce the likelihood of breaches and strengthen relationships with your clients.
Ultimately, the role of financial services firms and advisers as stewards of trust is vital. Building and maintaining this trust will require sustained effort, ongoing vigilance, and a commitment to addressing both the symptoms and root causes of non-compliance.
ASIC’s report highlights the critical need for licensees to prioritise compliance and customer protection. If you are a financial services provider, consider reviewing your compliance strategy and implementing systemic improvements. Contact our compliance consultancy team today for tailored guidance on strengthening your compliance framework, protecting client interests, and building trust in your organisation.