Breach reporting: Investigations and reporting

Breach reporting: Investigations and reporting

Breach reporting: Investigations and reporting

“Nothing has such power to broaden the mind as the ability to investigate systematically and truly all that comes under thy observation in life.”

— Marcus Aurelius QC, Independent Commission Against Corruption

Have you subscribed?

The series continues

This article is Part 2 of our Breach Reporting series clarifying the operation of the breach reporting regime by exploring: 

  • How to identify a ‘significant breach of a core obligation’ and being ‘unable to comply with a core obligation’ (Part 1),
  • The obligation to report ‘reportable investigations’, ‘gross negligence and serious fraud’ and reporting other licensees (Part 2).
  • The obligation to commence investigations, notify affected clients and conduct remediation (Part 3).
  • Reporting to ASIC and connected publication (Part 4).

Reportable situations

In Part 1 of this series, we broke down the definition of a reportable situation into five (5) types.

The third type of reportable situation is our obligation to report certain investigations into previous, or anticipated, significant breaches.

Let’s start at the beginning.

Determining whether an investigation has commenced (or needs to commence) can logically only occur after you have identified a potential or likely significant breach of a core obligation. If you find a significant breach, or anticipate a significant breach, you’re expected to consider questions like:

1124 Breach Reporting

 

  • how was the significant breach identified?
  • why did the breach occur?
  • what is the impact of the breach?
  • are there broader consequences from, and implications of, the breach?
  • what rectification or remediation is required? and
  • what steps are needed to prevent the significant breach recurring?

These questions can’t always be answered immediately. Sometimes, properly identifying causes and quantifying effects takes time, and ASIC recognise this practical reality. Their guidance encourages AFS Licensees to take their time to investigate but to report the breach to ASIC if the investigation takes (or will take) thirty (30) or more days. It needs to be reported at the 30 calendar day mark, even if that investigation ultimately concludes there is no reportable breach. 

So, what constitutes an ‘investigation’?

Thankfully, in these circumstances, ‘investigation’ takes its ordinary meaning in this situation, which is: 

a searching inquiry in order to ascertain facts

The scope of the term investigation is broad and encompasses information gathering and, in ASIC’s words; ‘human effort applied by the licensee to determine whether a breach has occurred or will occur’. In simple terms, any effort beyond simply identifying and recording a breach (or anticipated breach) – such as analysing, considering or seeking advice – could be considered to be an investigation.

The Explanatory Memorandum provides that the intention of the term ‘investigation’ applies irrespective of how the licensee describes an investigation in its internal processes and ‘information gathering’ may include:

  • Communicating with representatives or staff of the licensee who may have been involved in the relevant conduct,
  • Communicating with potentially affected clients; or  
  • Seeking specialist or technical advice. 

A licensee is also considered to have conducted an investigation if it outsources the investigation, or if a related entity (such as a parent company) conducts the investigation. 

Please remember that an investigation that spans 30 days or more will be a reportable situation regardless of whether or not the subject of the investigation is ultimately established to be a significant breach of a core obligation. It’s the time taken to investigate an actual or anticipated breach of a significant obligation that triggers the reporting obligation.


Gross negligence and serious fraud

“And there is no difference, in principle, but only in degree”

— Lysander Spooner

The fourth type of reportable situation arises when a licensee or its representatives engage in conduct that constitutes gross negligence or serious fraud.

Let’s unpack these terms. Firstly, ‘gross negligence’ is undefined by the Corporations Act and the Explanatory Memorandum. It therefore takes its natural meaning, having regard to the common law, which is essentially: carelessness to an extreme degree, in breach of a duty of care.

We can turn to judicial decisions concerning gross negligence to further develop our understanding of the application of this key concept.

In the decision of GR Engineering Services Ltd v Investmet Ltd [2019] WASC 439, Tottle J held that Australian courts follow the approach of Mance J in the Hellespont Ardent case, in which his Lordship said:

Gross negligence is clearly intended to represent something more fundamental than failure to exercise proper skill and/or care constituting negligence. But, as a matter of ordinary language and general impression, the concept of gross negligence seems to me to be capable of embracing not only conduct undertaken with actual appreciation of the risks involved, but also serious disregard or indifference to an obvious risk

Serious fraud’ is defined by section 9 of the Corporations Act to mean an offence involving fraud or dishonesty, being an offence:

  • Against an Australian law or any other law; and
  • Punishable by imprisonment for life or for a period, or maximum period, of at least 3 months

An example of such an offence is a contravention of section 1041E of the Corporations Act. In essence, section 1041E prohibits persons from making false or misleading statements when:

  • The statements are likely to induce another person to acquire or dispose of a financial product, and
  • When the false or misleading statement was made, the person making the statement does not care whether the statement is true or false, or knows or ought reasonably to have known the statement is false or misleading.

In the event either gross negligence or serious fraud occurs, there is an obligation to lodge a report to ASIC.


Reporting other licensees

Next, we have reportable situation type 5, which is the obligation to report other licensees.

This obligation provides that a licensee (reporting licensee) must lodge a report to ASIC if:

  • There are reasonable grounds to believe that another licensee has, or is likely to significantly breach a core obligation or has engaged in gross negligence or serious fraud, and
  • The conduct of the other financial services licensee, its employees, directors, representatives or the employees and directors of its related body corporate, in carrying out their respective duties, forms part of the reportable situation, and
  • The individual provides personal advice to retail clients in relation to relevant financial products.

The reporting licensee must lodge a report within 30 days in the prescribed form if the above listed elements are satisfied. A copy of the report must be given to the other licensee.

The reporting licensee is not required to lodge a report if there are reasonable grounds to believe ASIC is aware of the reportable situation and all of the relevant information.

We note that the first threshold test of “reasonable grounds to believe”, constitutes a higher threshold than “reasonable grounds to suspect”.

In our view, this means that if there are facts or evidence that would lead a reasonable person in the shoes of the reporting licensee to be pretty sure that the conduct of another licensee or relevant person has, or is likely to, significantly breach a core obligation or has engaged in gross negligence or serious fraud, then this first test is satisfied.

We further note that the obligation to investigate under section 912EB of the Corporations Act, which is covered in the next part of this series, cannot be triggered by the conduct of another licensee alone.

We trust this provides some clarity regarding reportable situations type 3, 4 and 5. In the next part to this series we will analyse the obligation to commence an investigation, to notify affected clients, and to conduct remediation. We will also unpack the concepts of “knowledge” and “recklessness” under the breach reporting regime.

Have you subscribed?

Keep exploring

Breach reporting: Investigations and reporting

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?