What is ASIC RG 271?
ASIC Regulatory Guide 271 (RG 271), Internal dispute resolution, sets standards and requirements for how financial firms identify, record, investigate and respond to complaints.
For AFS licensees, one of the most important RG 271 risks arises before the complaint-handling process formally begins.
The client doesn’t need to say “I want to make a complaint.”
They don’t need to demand compensation. They don’t need to put the complaint in writing. And the matter does not cease to be a complaint merely because an adviser or staff member resolves it quickly.
A complaint is an expression of dissatisfaction made to or about a firm, related to its products, services, staff or complaint handling, where a response or resolution is explicitly or implicitly expected or legally required.
That means effective RG 271 compliance starts with the ability of advisers, representatives and other frontline staff to recognise dissatisfaction when they encounter it and get it into the IDR system.
Key insight: The most sophisticated complaints process in the world is ineffective if complaints never enter it.
Once a complaint has been identified, the firm must then record it appropriately, manage the applicable response timeframe, investigate it fairly, communicate the outcome, consider any broader or systemic implications and meet its ASIC reporting obligations.
Related compliance guides
RG 271 does not operate in isolation. Once a complaint is identified, it may also affect ASIC reporting, breach assessment and the licensee’s broader compliance obligations.
ASIC IDR data reporting
Understand what complaint data must be reported to ASIC, the reporting periods and how to structure your complaints register for reliable submissions.
Read our guide to ASIC IDR data reporting
Reportable situations and RG 78
A complaint may reveal conduct or a control failure that also requires assessment under the breach-reporting regime.
Read our guide to reportable situations and RG 78
Section 912A obligations for AFS licensees
Weak complaint handling can indicate broader deficiencies in supervision, compliance arrangements, resources or the way financial services are provided.
Review the section 912A obligations
ASIC Regulatory Portal
Understand which ASIC portal is used for regulatory submissions and how the different ASIC systems fit together.
Read our guide to ASIC portals
What counts as a complaint under RG 271?
Complaint identification should be treated as a control in its own right.
A complaint isn’t confined to formal correspondence or serious disputes. Broadly, an expression of dissatisfaction made to or about the organisation can constitute a complaint where a response or resolution is explicitly or implicitly expected.
That can include dissatisfaction about:
- financial advice;
- fees or charges;
- delays;
- administration;
- service;
- communications;
- products;
- claims;
- staff or representatives;
- previous complaint handling; or
- an outcome the client believes is unfair.
The practical question isn’t: “Did the client make a formal complaint?”
It’s “Has the client expressed dissatisfaction in circumstances where they reasonably expect us to do something about it?”
That’s a much broader test.
What does a complaint look like in practice?
Many complaints don’t initially look like complaints.
A client might say:
- “Nobody ever explained that fee to me.”
- “I’m disappointed that this has taken three weeks.”
- “That isn’t what my adviser told me.”
- “I don’t think I should have to pay for this.”
- “Why was my portfolio changed without anyone talking to me?”
- “I’ve asked about this three times and nobody has fixed it.”
Each communication needs to be assessed on its substance and context.
The fact that the client hasn’t used the word complaint isn’t determinative, nor should staff assume that dissatisfaction is merely “feedback” because the matter seems minor.
You may have an RG 271 capture problem if your CRM contains “client concerns”, fee disputes, repeated service requests or adviser-resolved issues that do not appear in your complaints register.
Do verbal complaints count?
Yes.
A complaint doesn’t ordinarily have to arrive through a designated complaints email address or online form.
Potential complaints can arise through:
- telephone calls;
- client meetings;
- emails;
- letters;
- adviser file notes;
- reception or service interactions;
- online communications;
- complaints made to representatives; and
- relevant social media interactions.
This creates a practical challenge for licensees because the compliance team can’t identify complaints it never sees.
Frontline staff therefore need to understand both what a complaint looks like and what they must do when they receive one.
Five common complaint-identification failures
1. “The client didn’t call it a complaint”
That isn’t the relevant test. Look at the substance of the communication and whether the client expects a response or resolution.
2. “The adviser fixed it immediately”
Quick resolution may affect the written-response requirements. It doesn’t retrospectively mean that no complaint existed.
3. “The client hasn’t asked for compensation”
A demand for compensation isn’t a prerequisite to a complaint. Many legitimate complaints concern communication, delay, service or process.
4. “It wasn’t serious”
Severity and complaint classification are different questions. A relatively minor expression of dissatisfaction may still need to be captured through the IDR framework.
5. “It’s just negative feedback”
Sometimes it is, but relying on labels such as feedback, service issue, query or client concern can cause complaints to disappear outside the complaints framework.
The substance of the interaction should determine how it is treated.
How should an AFS licensee identify complaints?
Complaint identification should be embedded into normal business processes rather than left to individual judgement without guidance.
A practical identification process might require staff to ask:
| Question | Why it matters |
| Has the client expressed dissatisfaction? | Establishes the first element of the complaint test. |
| Is it about the firm, its people, products or services? | Helps determine whether it falls within the firm’s IDR framework. |
| Does the client expect a response or action? | A response can be expected implicitly, not only expressly. |
| Has someone already resolved the issue? | Resolution does not necessarily remove the need to record the complaint. |
| Could another client be affected by the same issue? | May indicate a systemic issue or broader control failure. |
| Has the matter also created an incident or possible breach? | May require escalation outside the IDR process. |
The objective isn’t to turn every difficult conversation into a compliance event.
It is to stop genuine complaints being missed because employees apply an unduly narrow definition.
What should happen once a complaint is identified?
Identification should trigger a controlled process.
A useful workflow is:
Identify → Record → Acknowledge → Assess → Investigate → Respond → Escalate → Analyse → Report
Each stage serves a different purpose.
- Identify: Determine that an expression of dissatisfaction falls within the IDR framework.
- Record: Capture sufficient information about the complaint, including the complainant, subject matter, date received and relevant product, service or representative.
- Acknowledge: Acknowledge the complaint promptly in accordance with the applicable requirements.
- Assess: Identify the issues raised, applicable timeframe, potential consumer harm and any immediate action required.
- Investigate: Gather sufficient information to reach a fair and supportable conclusion.
- Respond: Communicate the outcome and reasons within the applicable maximum timeframe.
- Escalate: Provide AFCA information where required and escalate internal issues appropriately.
- Analyse: Ask whether the complaint reveals a broader problem.
- Report: Capture the information required for ASIC IDR data reporting.
How quickly must complaints be resolved under RG 271?
The applicable timeframe depends on the type of complaint.
For many financial-services complaints, RG 271 generally requires an IDR response within 30 calendar days, although different maximum timeframes apply to particular complaint categories, including superannuation complaints.
However, the deadline shouldn’t be treated as the primary complaint control. The deadline only works if the organisation knows when the complaint was received.
A complaint received by an adviser on Monday but entered into the complaints register the following Friday has not acquired a new starting date. The operational risk arose when the complaint was missed.
That’s why identification and timely registration matter so much.
Common maximum IDR timeframes
| Complaint type | General maximum timeframe |
| Most standard financial-services complaints | 30 calendar days |
| Most superannuation complaints | 45 calendar days |
| Certain superannuation death-benefit distribution complaints | 90 calendar days |
| Certain credit and hardship matters | Separate statutory requirements can apply |
The applicable timeframe should be identified when the complaint is first recorded.
What is the five-business-day IDR response exception?
Some complaints resolved to the complainant’s complete satisfaction within five business days may not require the usual written IDR response, provided the conditions for the exception are met.
That should not be confused with an exemption from complaint identification.
The sequence remains:
Complaint identified → complaint recorded → issue resolved quickly → determine whether written IDR response exception applies.
It should not be:
Issue resolved quickly → therefore it was never a complaint.
That distinction is particularly important for the integrity of the firm’s complaints data.
Do complaints resolved within five days still need to be recorded?
Do not use the five-business-day response rule as a mechanism for keeping complaints out of the register.
A firm needs sufficiently complete complaint records to:
- manage its IDR obligations;
- identify recurring problems;
- detect systemic issues;
- supervise representatives;
- produce reliable management information; and
- satisfy applicable ASIC IDR data reporting requirements.
If the register contains only complaints that became serious or contentious, it may substantially understate the firm’s actual complaint experience.
Why is complaint identification particularly important for advisers?
Advice businesses often operate through longstanding relationships.
That can make complaint identification harder.
A client may raise dissatisfaction conversationally with an adviser they have known for many years. The adviser may regard the issue as a service matter and resolve it immediately.
That can be good client service.
It can also create an IDR control gap if the complaint is never captured.
Licensees should therefore be particularly alert to complaints hidden in:
- adviser emails;
- meeting notes;
- CRM records;
- service requests;
- fee disputes;
- remediation records;
- incident registers; and
- conversations described as “client concerns”.
Periodic reconciliation between these sources and the complaints register can provide valuable assurance about whether complaints are actually being identified.
What should be recorded in the complaints register?
The precise information required will depend on the firm’s obligations and systems, but an effective record will usually capture information such as:
- date received;
- complainant;
- complaint channel;
- product or service involved;
- adviser, representative or business unit;
- nature of dissatisfaction;
- issues raised;
- relevant regulatory classification;
- applicable response deadline;
- investigation actions;
- outcome;
- remediation;
- date resolved;
- AFCA escalation;
- systemic-issue assessment; and
- applicable ASIC reporting fields.
Where possible, design the complaints register around the information required for ASIC IDR data reporting rather than trying to reconstruct that information six months later.
What must an IDR response contain?
A written IDR response should enable the complainant to understand what the firm decided, why it reached that decision and what the complainant can do next.
Depending on the circumstances, that will generally require clear treatment of:
- the issues raised;
- material findings;
- relevant facts;
- the firm’s decision;
- reasons for that decision;
- any remedy or corrective action; and
- AFCA rights where applicable.
Templates can improve consistency, but they shouldn’t be used to produce generic answers that fail to engage with the actual complaint.
What happens if the complaint cannot be resolved on time?
The maximum IDR response period should be treated as a genuine deadline.
Where the applicable requirements permit a delay notification, the firm needs to satisfy the relevant conditions and provide the prescribed information.
A difficult investigation isn’t, by itself, a reason to routinely extend complaint deadlines.
Deadline monitoring should therefore form part of the complaints workflow.
Useful controls include:
- automatic due dates;
- reminders before expiry;
- ageing reports;
- escalation thresholds; and
- management oversight of overdue or at-risk complaints.
How do complaints reveal systemic issues?
Individual complaint resolution answers: “What should we do for this client?”
Systemic-issue analysis asks: “Who else could be affected?”
That second question is one of the most valuable functions of an effective IDR system.
Examples may include:
- the same advice error across several clients;
- recurring fee errors;
- defective disclosure;
- incorrect template wording;
- repeated administration failures;
- a product configuration error;
- calculation defects;
- misleading communications;
- poor adviser practices;
- deficient supervision; or
- systems that repeatedly generate the same client outcome.
A complaint should therefore be assessed not only for its individual merits but for what it might reveal about the business.
When does a complaint become a breach-reporting issue?
A complaint and a reportable situation are not the same thing.
But a complaint may reveal conduct or a control failure that requires assessment under the reportable situations regime.
When that occurs, the complaint should be linked to the firm’s incident and breach-management process.
Relevant questions include:
- Has a legal or regulatory obligation potentially been breached?
- Could the issue affect other clients?
- Is there evidence of a systemic control failure?
- Is client remediation required?
- Does the matter satisfy the applicable reportable-situation tests?
- Has an investigation itself triggered a reporting obligation?
For more detail, see our guide to reportable situations and ASIC RG 78.
The distinction is important:
RG 271 determines how the complaint is handled. The breach-reporting framework determines whether the underlying conduct must also be reported to ASIC.
How does RG 271 interact with section 912A?
Complaint handling should not be viewed as an isolated compliance function.
For AFS licensees, the effectiveness of the IDR framework sits within the broader general obligations applying under section 912A of the Corporations Act.
Weak complaint identification may provide evidence of wider problems in areas such as:
- compliance arrangements;
- supervision;
- risk management;
- representative conduct;
- resources;
- competence; and
- the obligation to provide financial services efficiently, honestly and fairly.
This is why complaint trends can matter well beyond the complaints team.
See our practical guide to section 912A obligations for AFS licensees.
What IDR data must be reported to ASIC?
In-scope financial firms have an ongoing obligation to report IDR data to ASIC for each reporting period, including lodging a nil submission through the ASIC Regulatory Portal where no complaints were received or open during the period.
Good reporting starts at the point a complaint is identified.
If complaints are incompletely identified or poorly classified, the problem cannot be fixed simply by improving the final ASIC submission.
The reporting process should therefore connect frontline identification → complaints register → quality assurance → ASIC submission.
For reporting periods, fields, lodgement requirements and practical preparation, see our dedicated guide to ASIC IDR data reporting.
ASIC updated its IDR data reporting handbook in December 2025. The revised requirements apply to complaints open or received from 1 January 2026, with firms first reporting under the updated handbook in the July–August 2026 submission window.
How do firms lodge IDR information with ASIC?
ASIC regulatory submissions are increasingly managed through digital regulatory systems.
Firms should ensure appropriate users have access, permissions and processes for the relevant ASIC systems before a reporting deadline arises.
Our Guide to ASIC Portals explains the different ASIC systems, what they are used for and how to determine which portal is relevant.
This should form part of the firm’s reporting control environment rather than being left until the submission deadline.
What should boards and senior management monitor?
Complaint data is no longer solely an internal management metric. ASIC launched its public IDR data dashboard in March 2026, allowing users to examine complaints reported by individual financial firms. That increases the importance of accurate identification, classification and contextual interpretation of complaint data.
For this reason, a complaint dashboard should do more than count complaints.
Useful governance information includes:
| Measure | Question it answers |
| Complaint volume | Are complaints increasing or decreasing? |
| Complaint source | Where are complaints entering the business? |
| Product/service | What is generating dissatisfaction? |
| Adviser/representative | Are there concentrations requiring supervision? |
| Identification source | Are complaints reaching the register directly, or being found later? |
| Time to acknowledge | Are matters entering IDR promptly? |
| Time to resolve | Are deadlines being met? |
| Outcomes | How often are complaints upheld or partially upheld? |
| Remediation | What consumer harm is being identified? |
| AFCA escalation | Which matters leave IDR and why? |
| Systemic issues | What broader weaknesses are emerging? |
| Breach linkage | Which complaints also trigger incident or breach assessment? |
One particularly useful metric is Complaints discovered retrospectively rather than identified when received.
That directly tests the effectiveness of the complaint-identification framework.
Boards should interpret complaint volume alongside evidence about complaint capture. A low complaint count isn’t necessarily evidence of good client outcomes if assurance testing shows dissatisfaction is being recorded elsewhere but not entering IDR.
What controls should an AFS licensee have?
An effective RG 271 framework will commonly include:
- a broad and accurate complaint definition;
- practical examples for staff;
- mandatory complaint-identification training;
- a simple escalation process;
- central complaint recording;
- clear responsibility for classification;
- deadline controls;
- investigation standards;
- response quality assurance;
- ASIC reporting fields;
- systemic-issue assessment;
- integration with incident and breach reporting;
- management reporting; and
- periodic testing of complaint capture.
The final item is particularly important.
Do not only test complaints that entered the complaints register.
Test whether matters that should have entered the register were missed.
RG 271 complaint-identification checklist
Ask:
- Do our staff know the regulatory definition of a complaint?
- Do they understand that the word “complaint” does not need to be used?
- Do we capture verbal complaints?
- Do advisers know when dissatisfaction must be escalated?
- Do we distinguish complaints from ordinary enquiries using substance rather than labels?
- Are complaints resolved immediately still recorded appropriately?
- Do we monitor adviser emails and file notes for missed complaints?
- Do we reconcile service issues or incidents against the complaints register?
- Is the date the complaint was actually received recorded?
- Is the correct IDR deadline calculated from that date?
- Do we capture ASIC reporting information contemporaneously?
- Does every complaint receive a systemic-issue assessment?
- Are relevant complaints linked to incident and breach reporting?
- Does management know how many complaints were found retrospectively?
If the firm cannot answer these questions confidently, its main RG 271 vulnerability may arise before the formal IDR process even starts.
The practical test
The most important RG 271 question isn’t: “Can we resolve complaints within 30 days?”
It’s “Can we reliably recognise when a complaint has been made?”
Everything else depends on that.
A missed complaint can result in:
- an incorrect commencement date;
- a missed acknowledgement;
- an overdue IDR response;
- incomplete ASIC data;
- missed systemic issues;
- unrecognised remediation;
- an unassessed breach; and
- misleading management reporting.
The critical control chain is therefore Recognise → Record → Respond → Analyse → Escalate → Report.
Get the first step wrong and every downstream control becomes less reliable.
Need help testing your IDR framework?
A useful RG 271 review should test whether the framework works in practice, not merely whether the policy reproduces the regulatory requirements.
Assured Support can review:
- complaint-identification controls;
- IDR policies and procedures;
- staff and adviser training;
- complaints registers and workflows;
- response templates;
- deadline controls;
- ASIC IDR data reporting;
- systemic-issue processes;
- integration with reportable situations and RG 78;
- alignment with section 912A obligations; and
- governance and management reporting.
A particularly valuable test is to sample client correspondence, file notes and incident records and compare them against the complaints register.
That answers the question a policy review can’t.
Are you actually identifying your complaints?
Where complaint controls depend on recurring checks, evidence and accountable follow-up, consider whether [complye] can provide a more structured record of control operation and review.
Found this article useful? You can select Assured Support as a ‘preferred source’ in Google. This may help you see more of our articles in Google Top Stories, AI Mode and AI Overviews when our content is relevant to your search.
Further reading
Frequently Asked Questions
Yes. Complaint volume by itself does not establish that a firm has poor complaint handling; in some circumstances, a comparatively high number can reflect better identification and recording.
ASIC expressly cautions against interpreting high complaint numbers as necessarily indicating poor performance. A firm with effective staff training and robust IDR processes may capture more complaints than a comparable firm whose staff apply an unduly narrow definition.
That changes the governance question. Boards and Responsible Managers should not simply ask whether complaint numbers are rising. They should ask why. Relevant evidence includes complaint volumes relative to client numbers and products, identification channels, complaints discovered retrospectively, resolution outcomes and recurring issue categories.
Conversely, exceptionally low complaint numbers deserve scrutiny rather than automatic celebration. ASIC’s 2025 review of advice licensees specifically examined possible under-reporting and firms that
had never lodged IDR data.
The practical test is whether reported complaint volumes are credible when reconciled against actual client interactions.
No. Rapid resolution does not determine whether the communication was a complaint in the first place.
The relevant issue is whether the communication meets the complaint definition. ASIC currently defines a complaint by reference to an expression of dissatisfaction concerning the firm, its products, services, staff or complaint handling where a response or resolution is explicitly or implicitly expected or legally required.
This distinction matters because otherwise an adviser can inadvertently remove matters from the IDR system simply by being responsive. Good client service then creates bad regulatory data.
ASIC highlighted this precise misunderstanding in its 2025 review of advice licensees: some firms incorrectly believed that matters resolved immediately did not need to be reported. ASIC stated that expressions of dissatisfaction must be captured and included in IDR reporting regardless of severity or resolution time.
Licensees should therefore separate two decisions: Was this a complaint? and What response requirements now apply?
The strongest evidence comes from testing sources outside the complaints register against the register itself.
A review limited to registered complaints establishes how recorded complaints were handled. It does not establish whether the business reliably recognised complaints in the first place.
Useful testing populations include adviser emails, CRM notes, service requests, fee disputes, remediation records, incident registers and client correspondence. A sample can be assessed against the RG 271 complaint definition and then reconciled with the complaints register. The article correctly identifies this as a particularly valuable assurance exercise.
There is regulatory support for taking capture testing seriously. In an ASIC review of general insurers, one in six complaints in the sampled contact-centre records had not been identified and recorded.
For governance purposes, consider reporting a retrospective identification rate: the number of complaints discovered through assurance testing that were not recognised when received.
Start with the source data, not the submission file.
Reconcile the complaints register against potential complaint sources and confirm that complaints received during, or open at any time during, the reporting period are appropriately captured. Then test product and issue classifications, complaint identifiers, status, outcomes and other applicable reporting fields against ASIC’s current reporting handbook.
This is particularly important in 2026. ASIC’s updated IDR data reporting handbook applies to complaints open or received from 1 January 2026, with the updated requirements first used for the July–August 2026 reporting window.
Portal readiness should also be checked before the deadline. ASIC’s reporting process uses the ASIC Regulatory Portal, and even a firm with no complaints must lodge the required nil submission.
The practical control objective isn’t simply “Can we upload a valid file?” It is “Does that file accurately represent the complaints the business actually received?”
Not by itself. Technology can improve recording, deadlines, classification and evidence, but it cannot reliably capture complaints that staff never recognise or route into the system.
A complaints platform can support workflow controls such as mandatory fields, automated due dates, escalation alerts, reporting classifications and management dashboards. Those controls become valuable only after the organisation has identified the interaction as something that belongs within IDR.
That makes implementation partly a people-and-process problem. Licensees should test whether advisers and frontline employees recognise dissatisfaction across email, telephone calls, meetings, CRM entries and service interactions, and whether escalation into the central system is simple enough to occur consistently.
Technology can then provide an additional assurance layer by supporting reconciliation, exception reporting and evidence of review.
The distinction is between digitising the complaints register and improving the effectiveness of complaint capture. RG 271 control design needs both.