Five reasons why your auditor got it wrong

Five reasons why your auditor got it wrong

Five reasons why your auditor got it wrong

“Never attribute to malice that which can be adequately explained by incompetence”

— Robert J Hanlon, “Hanlon’s Razor”

Learn more

A broken watch

You may offer us commiserations when you learn that we’ve reviewed over 7,413 advice files since 2015, but the reality is that we’ve gained a unique perspective from having provided advice, support and services to over 120 Australian Financial Services Licensees and over 1700 advisers.

Over the years we have also, from time to time, been engaged to provide a second-opinion on Licensees’ compliance arrangements and, in particular, their approach to monitoring and supervision.

As ASIC found in Report 515, compliance resources (particularly conflicted resources) don’t always get it right.

That said, most compliance professionals are skilled, competent and capable. The difficulty for most advisers (and many Licensees) is that it’s often incredibly difficult to determine whether you’re dealing with a compliance professional or someone who simply dresses the part. As declining margins and institutional fragmentation position compliance as ‘the new oil’, compliance is likely to be defined by the increasing supply of experts and the decreasing quality of their advice.

As an admission against interest, I want you to understand that Reviewers, like advisers, make mistakes.

In our experience, these mistakes are seldom the result of either malice or conscious bias but they are often fundamental, avoidable and easily addressed.

So without saying your Reviewer definitely got your review wrong, let’s look at five reasons why their report might be wrong.


  1. Flawed file selection

A common strategy adopted by some Reviewers, for either their convenience or for optimizing review efficiency, is to limit their consideration to advice provided in the last twelve months (and relevant supporting documents).

This seems sensible and a logical starting point, unless, or until, you realise that the foundation of your business – your ongoing clients – are likely to be excluded. Nor will the Reviewer properly consider situations where the recent advice is built on a series of documented interactions that occurred over a longer period.

They might, for example, review the ROA you’ve prepared (and confirm the existence of the underlying SOA) but they’ll seldom review the underlying SoA to determine the appropriateness of the ROA. This approach explains, but does not excuse, many errors because this approach increases the likelihood that a Reviewer could simply overlook, or dismiss as irrelevant, any documents that weren’t prepared or issued in the last twelve months. 

TIP:

  • Insist that an Ongoing Service file is reviewed.
  • Ask the Reviewer to consider how that file would be seen if a ‘five year look-back” was made.

2. Poor record keeping

It’s ironic that while Treasury proposes criminal penalties for advisers and licensees that don’t keep adequate records, most Reviewers don’t list, record and identify all the documents they review.

As AMP v McDonald highlighted, this approach can critically undermine the credibility of the review. While it may be reasonable to rely on your Reviewer’s expertise and capability, this vibe-based approach means that neither party can confirm the scope of the review or assert, with any certainty, that all relevant documents were considered. In my view, it makes reliance on the Reviewer’s conclusions less reasonable.

TIP:

  • Ask the Reviewer to confirm, in their report, what specific documents they considered (and what they dismissed as irrelevant).
  • Keep a record of the documents you made available to them.

3. Inadequate investigation

I once dealt with a bank-employed reviewer who failed files because the SoAs he reviewed did not contain mandated disclosures. The “missing” disclosures were contained in the SoA from page 6.

When this was highlighted, it was explained that his Bank included these disclosures in the first two pages. Since these SoAs were different, they obviously weren’t right, and he rightly marked the documents ‘non-compliant’. Consistent with the Peter Principle, he subsequently became Head of Advice Assurance at a large institution recently highlighted by Commissioner Hayne.

I may be an unreliable narrator, but this anecdote (whether real or apocryphal) should highlight another key problem.

Some Reviewers, particularly those that adopt a formalist approach to compliance, may simply not make the enquiries necessary to support their conclusions or reasonable inferences. This is most often seen in their approach to product replacement, their assessment of ‘best interests’ and their calculation of detriment.

I have, for example, peer-reviewed advice documents that contained clear and unambiguous statements that directly contradicted the Reviewer’s conclusions. In some cases, the statements were contained in the very documents referenced by the Reviewer. 

To be fair, even the most experienced and conscientious reviewer can make mistakes. The problem is not that a Reviewer makes a mistake, but rather that they do not take reasonable steps to confirm their conclusions before they assert them as facts.

We acknowledge this risk explicitly in our review process, and seek to mitigate it, by building a formal, evidence based appeals process into our review methodology. We also follow a substantive and objective approach to reviews. More importantly, we appreciate that our review will be more accurate if we start by trying to understand the advice rather than trying to demolish it.

Having great reviewers helps, but I’m sure they’d give more credit to the process I’ve designed than to their own ultra-competence, capability and exceptional inter-personal skills.

TIP:

  • Don’t react to adverse conclusions immediately but ask the Reviewer what they considered to reach that conclusion.
  • Alternatively, ask what they would have needed to see to come to a different conclusion.
  • Ask them why the issue they identified is important (and ask subsequent whys to test their knowledge).

4. Competency and Capability

In compliance circles, there’s often a great reluctance to attribute problems to a lack of competency and capability (beyond, obviously, adviser competence and capability).

The uncomfortable reality is that many Reviewers have a flawed and incomplete understanding of the law and a limited perspective of the advice industry. In some cases, neither their theoretical knowledge, nor practical understanding, is adequate for their role.

It’s often been remarked that most Licensees don’t really want competent compliance staff, but cynicism aside, it’s a reality that many compliance staff lack the qualifications, skill and education to properly assess the advice and process they are charged with reviewing.

In practical terms, their failure to understand the law means that they are often unable to recognise, and account for, matters that did not reconcile with either their limited experience or their mechanical review process. If they don’t understand an advisers’ processes, they are unable to contextualise the information they review, and this often leads to their erroneous conclusions. 

Compliance is, or at least should be seen as, a strategic management discipline but, in the absence of a formal qualification framework (or behavioural testing like that implemented by Macquarie) there’s no guarantee that your Reviewer has either the experience, competence or capability to do their job.

Don’t assume they aren’t competent, but don’t assume they are either. As a matter of professional courtesy, be amenable and respectful, but don’t be afraid to ask questions or respectfully challenge their reasoning and conclusions. If they respond with jargon, dissembling or vague references to ‘best practice’ then prepare yourself for your Licensee’s inevitable (and often pointless) internal review process.

TIP:

  • Do background research on your Reviewer before (but not during) your review. Don’t research them during the debrief. LinkedIn is a great resource.
  • All our team are highlighted on our site. Check them out.
  • Ask who will review, and validate, the Reviewer’s conclusions.
  • Identify escalation points.

5. Formalism

We take, quite deliberately, a qualitative, substantive and risk-based approach to compliance.

In simple terms, we consider advice in context and place as much emphasis on intent, outcome and process as on technical compliance. In our view, while the formal requirements are important, reviewers shouldn’t allow regulatory myopia to lead them to false conclusions.

Formal, or mechanistic approaches – box ticking – may be tremendously efficient from the provider’s perspective, but it’s sub-optimal by every other measure. Any review process that emphasises formal or technical compliance requirements over substantive elements misses the point.

To be clear, formal elements need to be identified and considered, but if they are not considered in context, or by reviewers with adequate skill and training, their conclusions are often unreliable and misleading.

TIP:

  • Insist your Reviewers follow a risk-based review methodology that appropriately incorporates construal elements into the review process. 
  • Ask the Reviewer to explain their methodology.
  • Consider whether the Reviewer simply identifies issues, or analyses and investigates them.

subscribe

Keep exploring

Five reasons why your auditor got it wrong

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?