You may have already considered Holley Nethercote’s 2025 Compliance Trends Survey, which captures responses from 208 AFS and ACL Licensees.
Despite its weaknesses, it still offers insights into the current state of compliance in Australia’s financial services sector.
We’d like to provide context and strategic insight to help you anticipate and adapt to ASIC’s likely focus areas.
In summary, HN’s 2025 Compliance Trends Survey highlights concerning developments across the financial services sector, including declining investment in compliance, inadequate monitoring frameworks, and widespread misunderstandings of core obligations, signalling emerging systemic risks.
In our view, it is unlikely that no one at ASIC has read the coverage or the report. Although the survey represents only around 2% of AFS Licensees, its findings may carry significant regulatory weight due to the “compliance-aware paradox.” Being engaged enough to participate voluntarily, survey participants are likely to be more compliance-conscious than the broader licensee population. As such, the insights derived may understate the extent of industry-wide risks. Since these concerning trends are present in compliance-engaged licensees, they may indicate more severe issues in the broader population, including businesses like yours.
This paradox underscores the survey’s value as an early warning signal for regulators and a strategic guide for proactive Licensees.
As tempting as it may be to dismiss the survey as unrepresentative, it is a public document that has been widely covered and shared. It is also broadly consistent with PwC’s 2025 Global Compliance Survey.
If you’d like to purchase a copy of the Holley Nethercote report, it’s available from their site. Click here to purchase it.
KEY FINDINGS AND REGULATORY IMPLICATIONS
The Compliance Resourcing Gap
The most striking development is a consistent and measurable contraction in both internal and external compliance investment. Across all firm sizes:
- 40% of respondents now spend less than $100,000 annually on internal compliance staff, compared to 29% in 2024.
- External spending on compliance fell even more steeply, with 57% of licensees spending under $50,000 annually, up from 39% the year prior.
This reduction in financial commitment occurs despite increasing regulatory obligations, greater market scrutiny, and the emergence of new risks such as cybercrime and AI misuse. It also contradicts the direction of ASIC’s recent communications, which emphasise robust, well-resourced compliance functions as the cornerstone of licensee obligations.
Implication: ASIC is likely to assess the presence and adequacy of compliance functions. Licensees with minimal budgets may face heightened scrutiny or be required to demonstrate how their low-cost model ensures adherence to s912A obligations. Regulatory actions may include benchmarking exercises. Expect updated guidance on minimum compliance resourcing standards, potentially accompanied by mandatory third-party reviews for high-risk or under-resourced firms.
The Mid-Sized Licensee Blind Spot
Licensees with 16–50 authorised representatives represent a disproportionately risky segment. The survey identifies them as a ‘missing middle’—organisations too large for direct oversight yet too small to implement robust enterprise-level compliance programs. Key weaknesses include:
- Over 40% do not have documented monitoring and supervision policies.
- These licensees are the least likely to use checklists or conduct file reviews supplemented with interviews or system audits.
Despite being licensed under the same regime as larger firms, mid-sized licensees often lack the necessary sophistication or infrastructure to detect or respond to emerging compliance risks. They also exhibit weaker engagement with compliance consultants and less frequent reviews.
Implication: ASIC is expected to develop tailored supervision models for this cohort. We anticipate focused regulatory projects, including direct outreach, thematic surveillance, and compliance capability assessments. Licensees in this category should pre-empt regulatory attention by strengthening governance structures, resourcing, and documentation practices.
Conflict Management: Persistent Gaps
A disturbing insight from the survey is that over half of all respondents—across both retail and wholesale sectors—claim to have no conflicts of interest. This assertion contradicts ASIC’s foundational assumption that conflicts exist in all financial services businesses and must be actively managed.
- 54% of licensees believe they are conflict-free.
- While over 90% report having a conflicts policy or register, these are often dormant, with minimal entries or outdated disclosures.
This suggests a profound cultural or educational gap in understanding what constitutes a conflict under s912A(1)(aa) and related guidance. It raises concerns not only about disclosure failures but also about the meaningful implementation of conflict management frameworks.
Implication: ASIC will likely prioritise conflict management in future surveillance and enforcement activity. Guidance may be updated to include detailed expectations on conflict identification, logging, resolution, and disclosure. Inadequate or absent conflict registers may be seen as evidence of systemic governance failure.
Technology Governance: Rapid Adoption, Limited Oversight
The use of AI and automation tools is increasing at a faster rate than the establishment of proper governance arrangements. Survey data shows:
- AI’s use for minute-taking rose from 10% in 2024 to 46% in 2025.
- Over 50% now use AI to record client or internal meetings.
Despite this growth, few respondents have embedded technology governance policies or conducted risk assessments of the tools. This leaves gaps in record-keeping, privacy management, auditability, and fairness, especially in light of the potential for AI-driven decisions to affect consumers.
Implication: ASIC is expected to issue guidance (possibly through an Information Sheet or RG update) outlining governance expectations for AI and RegTech solutions. This may include mandatory risk assessments, board-level oversight, and audit trails. Licensees using AI without clear governance structures may face enforcement risk if client outcomes are compromised.
Monitoring and Supervision Weaknesses
One of the clearest indicators of systemic vulnerability is the inconsistent application of monitoring and supervision programs:
- 30% of respondents reported having no monitoring and supervision policy.
- A large proportion conducts internal reviews only every two years or less.
- Reviews often focus narrowly on file audits without broader thematic assessments or root cause analysis.
This limited scope undermines the licensee’s ability to identify misconduct, breaches, or risks proactively. The data shows that firms in the 16–50 rep category perform especially poorly, with some not conducting any form of documented supervision.
Implication: ASIC will likely set clearer expectations around monitoring and supervision programs’ frequency, scope, and accountability. There may also be a stronger push toward continuous compliance models supported by technology, independent reviews, and board-level accountability.
Inconsistent Training and Capability Development
Despite legal obligations under s912A(f) to maintain and ensure that staff are competent to provide financial services, the survey reveals highly variable training practices:
- Only 53% of licensees have a formal training plan covering all staff.
- CPD requirements for Responsible Managers and compliance personnel range from 10 to 40 hours, with no consistency.
- Staff with high regulatory exposure (e.g., marketing, complaints handlers) are often excluded from structured learning.
This reflects a tick-box mentality and a reactive training culture, relying on ad hoc events rather than strategic capability building. Licensees are exposed to knowledge and conduct risks as regulatory requirements expand and technologies evolve.
Implication: ASIC should be expected to review training standards and may introduce formalised guidance on role-based capability plans. To demonstrate compliance, firms should consider implementing tiered CPD frameworks, training needs assessments, and regular effectiveness reviews.
ANTICIPATING ASIC’S STRATEGIC RESPONSE
Based on these findings, we expect ASIC to pursue the following regulatory strategies:
- Minimum Standards and Benchmarks
- Development of clear minimum expectations for compliance resourcing and governance.
- Consultation on standardising compliance committee operations and oversight frequency.
- Supervisory Programs for Mid-Sized Licensees
- Increased surveillance of licensees with 16–50 representatives.
- Targeted reviews of monitoring, supervision, and resource allocation.
- AI and Technology Governance Expectations
- Release of regulatory guidance on AI usage.
- Enhanced scrutiny of technology-related compliance failures.
- Conflicts of Interest Enforcement and Education
- Thematic reviews focused on conflict identification.
- Updated guidance and potential enforcement for misleading disclosures.
- Culture and Conduct Programs
- Reinforced messaging around the “Efficiently, Honestly and Fairly” obligation.
- Expanded use of culture-focused surveillance.
- Training and Capability Reviews
- Examination of training frameworks, CPD planning, and role-specific competencies.
- Promotion of better practice examples across the industry.
OUR RECOMMENDATIONS
To proactively respond to the trends and anticipated regulatory actions, licensees should:
- Conduct a compliance resource adequacy review.
- Update or implement monitoring and supervision frameworks.
- Perform a comprehensive review of conflict management policies and practices.
- Audit AI and technology governance, including risk assessments and controls.
- Strengthen training programs across all roles with regulatory obligations.
- Engage with external reviewers to independently validate compliance systems.
OUR VIEW
The 2025 Compliance Trends Survey and the PWC Global Survey reveal a shifting regulatory landscape marked by underinvestment, inconsistent compliance practices, and rapidly evolving risks.
Licensees should interpret these findings as a call to act to mitigate regulatory risk and embed stronger, more resilient compliance frameworks.
ASIC is expected to adopt a more assertive stance in response to these emerging trends. Proactive licensees will view this as an opportunity to lead, rather than lag, in meeting rising expectations.
CALL TO ACTION
The time to act is now. Waiting for regulatory intervention risks reputational damage, enforcement outcomes, and operational disruption. Rather than dismissing HN’s report, we recommend using this report as a roadmap to proactively assess your risk, close compliance gaps, and demonstrate a leadership mindset to ASIC and your clients.
- Start by benchmarking your current arrangements against the findings in this report or our Licensee Governance Index.
- Engage your Responsible Managers and Compliance Committee to review your supervision, conflict management, and training frameworks.
- Connect with us at Assured Support—Australia’s leading compliance consultancy—to help you diagnose, strengthen and future-proof your compliance framework.
Our expert team has conducted over 22,000 file reviews and supported over 200 licensees. We bring commercial, confident, and creative solutions grounded in real-world data and regulatory insight.
Please email us at support@assuredsupport.com.au or visit www.assuredsupport.com.au to schedule a confidential consultation.
Being proactive isn’t just good governance—it’s your best defence.
If you liked this we recommend that you read:
AI-Driven Compliance: Transforming Risk Management and Regulatory Oversight
Compliance 101: Approaches and principles
Why Forward-Facing Compliance Beats Reactive Compliance Every Time
Frequently Asked Questions
1. What is the 2025 Compliance Trends Survey, and why is it significant?
The 2025 Compliance Trends Survey, conducted by Holley Nethercote, captures responses from 208 AFS and ACL licensees, revealing critical gaps in compliance resourcing, monitoring, and conflict management. Despite covering only 2% of licensees, it offers valuable insight into systemic risks and helps forecast ASIC’s regulatory priorities.
2. How will ASIC likely respond to declining compliance budgets?
ASIC is expected to increase scrutiny on under-resourced licensees and may introduce minimum standards for compliance spending. Firms with minimal budgets could face benchmarking assessments or mandatory third-party reviews to ensure compliance with s912A obligations.
3. Why are mid-sized licensees (16–50 reps) a focus for regulatory oversight?
Mid-sized licensees often lack enterprise-grade compliance infrastructure yet are too large for direct oversight. The survey highlights their inadequate monitoring practices, making them a likely target for ASIC’s thematic reviews and tailored supervisory programs.
4. What are the risks of failing to manage conflicts of interest effectively?
Over 50% of licensees claim to have no conflicts of interest, a stance at odds with ASIC’s expectations. Failing to identify, disclose, and manage conflicts can lead to enforcement actions and may be interpreted as systemic governance failure.
5. How should licensees prepare for ASIC’s focus on AI and tech governance?
With AI adoption rising, ASIC is anticipated to release guidance on technology governance. Licensees should perform risk assessments, establish audit trails, and implement board-level oversight for any AI or RegTech solutions in use to avoid compliance breaches.