“Previously, we didn’t have these obligations. None of our incidents were ever considered for reportability.”
— Head of Compliance and Conduct, “State of Financial Services Breach Reporting in Australia”, Gadens/Coredata 2022
This article is the fourth and final part of our Breach Reporting series clarifying the operation of the breach reporting regime by exploring:
- How to identify a ‘significant breach of a core obligation’ and being ‘unable to comply with a core obligation’ (Part 1),
- The obligation to report ‘reportable investigations’, ‘gross negligence and serious fraud’ and reporting other licensees (Part 2).
- The obligation to commence investigations, notify affected clients and conduct remediation (Part 3).
- Reporting to ASIC and connected publication (Part 4).
Reportable situations
We covered reportable situations in Part 1, 2 and 3 of the series. In this article we’ll cover:
- Reporting to ASIC, and
- The publication of reportable situations.
Reporting to ASIC
Licensees must lodge a report in relation to a reportable situation with ASIC in accordance with section 912DAA of the Corporations Act.
A failure to lodge a report is a reportable situation.
Reports to ASIC must be lodged with ASIC in writing in the prescribed form within 30 days after the licensee first knows that, or is reckless with respect to whether, there are reasonable grounds to believe a reportable situation has arisen.
We unpacked the meaning of ‘knowledge’ and ‘recklessness’ in Part 3 of this series.
From an operational perspective this means that as licensees manage potential breaches, licensees must be conscious that the obligation to report to ASIC may be triggered when they identify that there is a substantial possibility that a reportable situation exists. Once the obligation to report to ASIC is triggered, licensees are subject to a 30-day timeframe to do so.
The prescribed form
Licensees must lodge a report on a reportable situation via the prescribed form on the ASIC Regulatory Portal. The prescribed form asks licensees a series of questions about the nature of what is to be reported. The prescribed form requires that licensees provide the following information:
- The date the reportable situation arose and the date licensees first knew that there were reasonable grounds to believe that a reportable situation had arisen,
- The nature of the reportable situation (which type),
- A description of the reportable situation,
- Why the breach is significant,
- How the reportable situation was identified,
- How long the breach lasted,
- If an authorised representative or credit representative is involved, that representative’s details,
- Whether and how the reportable situation has been rectified,
- Whether and when affected clients have been compensated, and
- Any steps that have been or will be taken to ensure future compliance with the relevant obligation.
ASIC will confirm their receipt of a report and ask for more information if necessary.
The ASIC Regulatory Portal also provides licensees with the ability to track the status of submitted reportable situation transactions reports and correspond with ASIC online about submitted reportable situations.
ASIC must publish information
ASIC must, for each financial year, publish information on reportable situations that are lodged with ASIC or APRA in accordance with section 912DAD of the Corporations Act.
Section 912DAD specifies that the information must:
- Be published within 4 months after the end of the financial year,
- Be published on ASIC’s website, and
- Include information prescribed by regulations.
At the time of writing there are no regulations prescribing the information ASIC must include in its publication of reportable situation data.
On 10 August 2022, ASIC issued Media Release 22-214MR which states that ASIC’s first report due to be published in October 2022, will contain high level insights into trends observed across the reports lodged by licenses.
ASIC will not name licensees nor refer to the nature or number of reports lodged by specific licensees in the 2022 publication.
Media Release 22-214MR provides that ASIC will reconsider its approach to the publication of reportable situations early in 2023, and that it is likely that ASIC will commence licensee-level granular public reporting in 2024.
This concludes our Breach Reporting series. We hope you have found the information useful.
Please contact us if you have any questions about incidents and breaches.