How to Respond to an ASIC Notice: A Practical Step-by-Step Guide for Licensees

While I nodded, nearly napping, suddenly there came a tapping,
As of some one gently rapping, rapping at my chamber door. “
“'Tis some visitor,” I muttered, “tapping at my chamber door—
Only this, and nothing more.

The Australian Securities and Investments Commission (ASIC) plays a critical role in overseeing financial services and markets, ensuring that Licensees comply with their regulatory obligations. One of the ways ASIC exercises its powers is by issuing notices, which require Licensees to provide specific information or take particular actions. These notices can be complex and may be issued for various reasons, ranging from routine compliance checks to investigations into potential breaches of legislation.

For Australian Financial Services (AFS) Licensees, understanding how to manage ASIC notices is crucial to ensuring compliance and avoiding significant penalties, including substantial fines, legal action, enforceable undertakings, or even suspension or cancellation of a financial services license.

Receiving an ASIC notice can be a daunting experience for Australian Financial Services Licensees (AFSLs) and Australian Credit Licensees (ACLs). These notices often signal regulatory scrutiny and, if mishandled, can lead to severe penalties, reputational damage, and increased regulatory oversight. Understanding how to respond appropriately is crucial for mitigating risks and maintaining compliance.

This guide draws on our practical experience to provide a structured, step-by-step approach to responding effectively to ASIC notices. It outlines key types of notices, legal obligations, real-world pitfalls, and best-practice response strategies.

What is an ASIC Notice?

ASIC notices are formal communications issued by the regulator to collect information, seek clarifications, or require specific actions from financial service licensees. They are typically issued under various provisions of the Corporations Act 2001 or the Australian Securities and Investments Commission Act 2001. Whether as a blunt instrument or surgical tool, ASIC uses these notices to ensure Licensees adhere to legal and regulatory obligations and maintain proper governance structures and practices.

ASIC has a range of powers that enable it to issue different notices, each serving a distinct purpose and it’s important to appreciate their differences. These notices can require Licensees to provide documents, answer questions, allow inspections of records, or even take corrective actions.

In a highly regulated environment, it’s critically important that Licensees (and the advisers on whom they rely) understand the specific nature of each type of Notice and respond accordingly.


Types of ASIC Notices

To enhance clarity and comprehension, the following table summarises the different types of ASIC notices and their purposes:

Type of NoticePurpose
Section 19Summons to appear for an examination when ASIC suspects non-compliance.
Section 30Requires a business to provide ASIC with certain documents for investigation or regulatory inquiry. .
Section 33Requires a company to provide ASIC access to specified documents.
Section 48Requires individuals (e.g., directors or senior managers) to provide reasonable assistance, attend interviews and answer questions.
Section 1317DACInfringement Notices are issued when ASIC believes a company has committed a breach. Companies may accept or challenge these notices, but ignoring them can escalate enforcement action.
Information RequestsASIC frequently requests information to assess compliance. These are often precursors to formal investigations.

The Fine Print

Section 19 Notices (Summons for Appear for Examination)

Under Section 19 of the ASIC Act 2001, ASIC has the authority to issue notices that compel companies or individuals to produce documents or provide information as part of its broader regulatory functions. This Notice is a powerful regulatory tool often preceding civil or criminal proceedings. Practically, a Section 19 notice is issued when ASIC investigators have compelling grounds to suspect misconduct or significant contraventions of the financial services or credit laws by an individual or entity.

ASIC can issue a section 19 notice when it suspects or believes that the person has information related to a matter it is investigating under its regulatory and enforcement functions, including misconduct and market misconduct. Specifically, it enables ASIC to:

  1. Compel Individuals to Appear – ASIC can require a person to attend an examination before a specified ASIC officer.
  2. Compel the Giving of Evidence – People must answer questions under oath or affirmation.
  3. Require the Production of Documents – ASIC can demand that the person bring specific documents relevant to its investigation.

Although anyone examined under a s19 Notice will be interviewed in private, they must answer all questions, even if the answers might be self-incriminating.

Although the information they provide might expose them to criminal liability, it cannot be used against them in criminal proceedings (except in proceedings related to false statements or non-compliance with the notice).

Section 30 Notices (Production of Documents)

ASIC is empowered under Section 30 of the ASIC Act 2001 to issue a notice requiring a corporate body or registered scheme to provide ASIC with access to certain documents. These notices often pertain to an investigation or regulatory inquiry into the Licensee’s operations and activities; they are typically issued to confirm compliance with record-keeping and disclosure obligations, licence obligations, and client communications. If the Notice requires the production of sensitive or legally privileged documents, seek legal advice to confirm your compliance obligations. Similar Notices can be issued to auditors (s30A), to registered liquidators (s30B) and about financial products (s31) or financial services (s32A)

Section 33 Notices (Inspection of Documents)

A Section 33 Notice under the Australian Securities and Investments Commission Act 2001 (ASIC Act) allows ASIC to inspect and copy books (documents) without taking possession of them. Unlike Section 30 notices, Section 33 notices generally do not involve document production but allow ASIC to inspect the documents in situ. These Notices are typically used when ASIC wants real-time access to records without disrupting business operations or when seizing documents under Section 30 might not be necessary or practical.

Section 48 Notices (Examination of Persons)

Under Section 48 of the ASIC Act 2001, ASIC can issue notices requiring individuals, including company officers, directors, senior managers or employees, to attend interviews and answer questions. ASIC uses these notices as an exploratory tool to obtain assistance and general information rather than to secure testimony, so the interviews aren’t under oath.

Like in an S19 interview, respondents must answer all questions. However, suppose the information they provide might expose them to criminal liability. In that case, it cannot be used against them in criminal proceedings (except in proceedings related to false statements or non-compliance with the notice).

Section 1317DAE Infringement Notice

1317DAC of the Corporations Act 2001 allows ASIC to issue an infringement notice for civil penalty breaches of financial services laws, offering a financial penalty as an alternative to ASIC commencing civil proceedings. Generally, an Infringement Notice is issued when ASIC reasonably believes a company or individual has contravened specific provisions of the financial services laws by engaging in financial services misconduct, market misconduct or breaches of the Directors’ Duties. For example, Notices can be issued for a failure to comply with disclosure obligations, Misleading or deceptive conduct in financial services, contravention of consumer credit laws or breach of financial product advice requirements. These Notices are not issued for criminal matters, and although paying the penalty avoids further regulatory action, they do not equate to an admission or finding of liability. 

Section 1317DAE specifies the required contents of an infringement notice, such as the date of issuance and the name and address of the entity to whom it is issued.

Informal Information Requests

In addition to formal notices, ASIC may issue informal information requests to Licensees as part of its routine regulatory oversight. These requests are not legally binding like statutory notices but are often a precursor to more formal investigative actions. Informal information requests allow ASIC to gather insights into a company’s operations, compliance frameworks, and risk management practices. These requests may arise due to routine compliance monitoring, Industry-wide reviews or preliminary inquiries before issuing formal notices. Although these requests do not carry the same legal obligations as statutory notices, Licensees should treat them seriously because failing to respond appropriately to an informal request may result in ASIC escalating its approach, including issuing formal notices under statutory provisions such as Section 19, Section 30, or Section 33 of the ASIC Act 2001.


Notices, Responses and Legal Obligations

Considerations for Authorised Representatives

If an Authorised Representative is personally served with an ASIC notice, they must carefully review the document to determine whether they can disclose its existence to their Licensee. Many Authorised Representative Agreements require representatives to notify their Licensee of any regulatory contact or issues. However, some ASIC notices contain confidentiality provisions that may restrict disclosure to the Licensee or other parties.

Before taking any action, the representative should verify the terms of their agreement and assess whether the notice imposes any legal restrictions on sharing information. Seeking legal or compliance advice is crucial to ensure they comply with their contractual obligations and the notice’s requirements. If the notice permits disclosure, notifying the Licensee promptly ensures they can provide necessary support and guidance on regulatory obligations. However, if disclosure is restricted, the representative must strictly adhere to those requirements to avoid potential penalties or enforcement action.

General Considerations

Ignoring or mishandling an ASIC notice can lead to fines, licence suspensions, or criminal charges. Key obligations include:

  • Timely response: Most notices have strict deadlines, often within 14–28 days.
  • Accuracy and completeness: Providing misleading information is a criminal offence. Information must not be altered or destroyed once a notice is received.
  • Confidentiality: The notice’s existence, nature, and scope must be kept strictly confidential. Licensees must ensure that information is not disclosed to unauthorised parties. Breaching confidentiality may result in regulatory consequences, including financial penalties, enforceable undertakings, licence suspension or cancellation, and potential criminal prosecution.
  • Legal and compliance consultation: Licensees should engage legal or compliance experts to ensure they fully understand their obligations and rights when responding to an ASIC notice. Sharing the Notice with these professionals is permitted and is often essential. 
  • Accessibility of records: Ensure records stored offshore or in cloud services can be retrieved quickly to comply with ASIC demands.

How To Respond

Receiving an ASIC notice can be a significant event for any AFS Licensee. It can signal an ongoing investigation, routine compliance check, or request additional information. Regardless of the circumstances, responding appropriately to ASIC notices is essential to ensuring the sustainability of the business and preserving its reputation.

Receiving an ASIC notice can signal an ongoing investigation, a routine compliance check, or a request for additional information. Regardless of the circumstances, responding appropriately to ASIC notices is essential to maintaining regulatory compliance and protecting the business’s reputation.

Respond Promptly and Thoroughly

Licensees must respond to ASIC notices in a timely and comprehensive manner. The notice typically specifies a deadline by which the requested information or documents must be provided. Failure to meet the deadline can result in serious consequences, including potential penalties or further regulatory action.

If you are unsure about the scope of the notice, it is advisable to contact ASIC directly for clarification. ASIC is often willing to clarify what is required, and engaging with the regulator early can demonstrate your commitment to compliance.

It is also important to note that Licensees may have grounds to dispute or challenge specific ASIC notices. If a Licensee believes a notice is overly broad, unjustified, or lacks sufficient legal basis, they may seek clarification or engage legal counsel to respond formally. Licensees should know their rights and consider engaging regulatory experts to navigate potential disputes effectively.


Your Response Checklist

1. Review the notice carefully 

  • Identify the Relevant Entity named in the Notice. Determining the correct entity or person subject to an ASIC notice is essential. The notice may mistakenly identify an entity you are not responsible for or fail to specify the correct entity. In both cases, the validity of the notice may be affected. Correctly identifying the relevant entity or person ensures you only provide the legally required information. This step is crucial for Licensees operating under multiple subsidiaries or affiliated companies.
  • Assess the Validity of the Notice: Before responding, Licensees should evaluate whether the notice is legally issued under the appropriate legislative authority. It’s often wise to seek legal advice at this stage, which can help you determine whether the notice is enforceable or if there are grounds for challenging it.
  • Confirm the Scope: Each notice will specify the nature of the information or documentation required. Reviewing this scope ensures that only the necessary and relevant information is provided, helping avoid unnecessary disclosures or legal complications. If the scope is too broad or imprecise, it must be addressed before considering production. 
  • Confirm the time frame for your response: ASIC notices have strict deadlines. It is crucial to assess the response timeline and, if necessary, request an extension to gather and verify the required information.

2. Review Your Internal Records and Processes

Review your internal records and processes before responding to an ASIC notice. This includes ensuring that all requested documents are accurate, complete, and up to date. If the notice pertains to specific compliance or risk management practices, check that your policies align with the latest regulatory requirements.

For documents stored offshore or in cloud environments, ensure you can access and retrieve them promptly. ASIC’s ability to request information stored internationally or in cloud systems means Licensees must ensure their records are organised and retrievable, regardless of their physical location.

3. Consult Legal and Compliance Experts

Given the potential complexity of ASIC notices, licensees often seek legal and compliance advice before responding. Legal experts can help interpret the notice, identify any areas of concern, and assist in drafting an accurate and legally compliant response. A compliance professional can also help review your internal policies and procedures to ensure they align with the requested information.

Legal advisors can also help determine whether the notice raises any sensitive issues that require additional care in how the information is presented to ASIC.

4. Maintain Transparency and Open Communication

ASIC expects Licensees to respond to notices transparently. If you cannot meet the requirements within the specified timeframe, it is essential to inform ASIC as soon as possible and request an extension if necessary. Clear communication can help maintain a cooperative relationship with the regulator and demonstrate your commitment to resolving any issues.

5. Prepare for Further Scrutiny

Responding to an ASIC notice may not always result in the matter’s conclusion. ASIC may conduct further investigations, request additional documents, or issue further notices. Licensees should be prepared for additional scrutiny and consistently maintain high compliance standards.

6. Implement Compliance Improvements

If ASIC identifies weaknesses during their review, Licensees should immediately update their compliance frameworks to align with regulatory expectations. Strengthening internal monitoring and reporting processes is essential to ensure ongoing adherence to compliance obligations. Additionally, providing comprehensive training to staff on regulatory requirements helps reinforce a culture of compliance and reduces the risk of future breaches.

7. Monitor for Further Regulatory Action

After submitting a response to ASIC, Licensees must remain vigilant for any follow-up queries or inspections. Keeping key stakeholders, including directors and compliance officers, informed throughout the process is crucial. The response process should serve as an opportunity to strengthen compliance practices, ensuring that lessons learned are implemented effectively.

As additional inquiries may arise, it is essential to thoroughly document all communications and submissions to ASIC. Maintaining clear and organised records will help Licensees promptly respond to further regulatory actions. By proactively monitoring for regulatory follow-ups, organisations can mitigate risks and reinforce a culture of compliance, reducing the likelihood of future scrutiny.


How to Challenge an ASIC Notice

ASIC notices can be challenged; however, Licensees should only consider doing so if solid legal or procedural grounds exist. Challenging a notice without valid justification can escalate regulatory scrutiny and lead to reputational damage. Before taking action, assess whether the notice is overly broad, based on incorrect assumptions, or lacks sufficient legal foundation. Engaging legal and compliance experts early in the process ensures that any challenge is appropriately framed and supported by relevant laws and regulatory provisions. In cases where a challenge is warranted, Licensees should follow the prescribed procedures for requesting modifications, seeking clarifications, or pursuing judicial review. However, in most cases, cooperating with ASIC and providing a well-prepared response is the best course of action to mitigate risks and maintain regulatory goodwill.

1. Review the Notice Carefully

Carefully examine the notice to determine its scope, legal basis, and any potential grounds for objection. Ensure the notice has been correctly addressed to the relevant entity and falls within ASIC’s regulatory powers. If the request is overly broad or vague, it may be possible to challenge its scope.

2. Seek Legal Advice

It is essential to formally engage a lawyer with expertise and practical experience in regulatory matters. Briefing brilliant generalists or experienced commercial litigators leads to generally sub-optimal outcomes. Legal counsel can assess whether the notice is legally valid, determine the best course of action, and advise on the potential consequences of non-compliance or challenge.

3. Request Clarification or Modification

If the notice appears too broad, burdensome, or unclear, Licensees can engage with ASIC to seek further clarification or negotiate a narrower scope. ASIC may also be willing to extend deadlines if reasonable justifications are provided.

4. Formally Object in Writing

Where valid grounds exist, Licensees should submit a formal written objection to ASIC, clearly outlining the legal and procedural reasons for challenging the notice. This response should be carefully structured and supported by relevant legal arguments and evidence.

5. Apply for Judicial Review

Licensees may seek judicial review if an ASIC notice is deemed unlawful or unreasonable and informal objections are unsuccessful. This legal process involves challenging the notice in court, requiring strong legal representation and evidence to support the case.

6. Ensure Compliance with Partial Requirements

If only part of the notice is disputed, licensees should comply with the undisputed sections to demonstrate good faith. This approach helps maintain credibility with ASIC while resolving contested matters separately.


Risk Management: Best Practices for Licensees

Licensees should adopt proactive risk management practices to mitigate the risks associated with ASIC notices. This includes regularly auditing internal processes, ensuring proper record-keeping, and maintaining strong governance structures. By doing so, Licensees can reduce the likelihood of regulatory issues arising and be better prepared to respond to ASIC’s requests.

1. Regular Audits and Compliance Reviews

Regular audits and compliance reviews can help identify potential gaps in your operations before ASIC does. These reviews should assess your internal controls, policies, and practices against the latest regulatory requirements and industry best practices. If any deficiencies are identified, corrective actions should be taken immediately.

2. Clear Record-Keeping and Documentation

Licensees must maintain accurate, organised, and complete records of all business activities. This includes financial transactions, client communications, advice documents, and risk management reports. Proper record-keeping is crucial for responding to ASIC notices and ensures that your business complies with ongoing regulatory obligations.

3. Training and Education

Regular staff training is crucial, particularly in compliance, legal, and risk management roles. This ensures that your team is equipped to handle ASIC notices effectively and is aware of the latest regulatory developments. Training should also include understanding the importance of record-keeping and compliance with relevant financial services laws.


Knowledge is Power

ASIC notices are a crucial part of the regulatory landscape for Australian Financial Services Licensees. While these notices can be daunting, understanding the types and how to respond appropriately can help ensure Licensees remain compliant and avoid further scrutiny. Licensees can effectively navigate the complexities of ASIC notices by maintaining strong record-keeping practices, engaging with legal and compliance experts, and fostering a culture of transparency and proactive risk management.

Licensees should consider conducting regular internal compliance reviews to safeguard against compliance risks. These reviews help identify potential gaps, ensure adherence to regulatory requirements, and demonstrate a proactive approach to risk management. Establishing an internal review process can improve response readiness, enhance governance frameworks, and ultimately reduce the risk of regulatory penalties.

The key takeaway for licensees is that being prepared and responsive is essential. Proactively managing compliance and swift, well-informed action when receiving an ASIC notice will help safeguard your business’s reputation and regulatory standing.

If you found this helpful, we recommend that you read:

Responding to ASIC: s33 Notices and LIF

Fear, Surprise, and Ruthless Efficiency: ASIC’s Powers

Friend or Foe?: Dealing with Regulators

The Compliance Gap: Licensees’ Anxieties & ASIC’s Focus

Preparing for A Compliance Review: Key Considerations

Dear ASIC: How to respond to a regulatory notice


Frequently Asked Questions

1. What should I do if I receive an ASIC notice?

If you receive an ASIC notice, review it carefully to understand the type and the specific information requested. Then, ensure you respond within the stated deadline, verify the accuracy of your records, and seek legal or compliance advice if necessary. Engaging with ASIC proactively and transparently can help demonstrate your commitment to compliance and mitigate potential regulatory risks.

2. What are the most common types of ASIC notices?

ASIC issues several types of notices, including:

  • Section 19 Notices – Require Licensees to produce documents or information for investigations.
  • Section 30 Notices – Grant ASIC access to inspect specific documents.
  • Section 33 Notices – Request company information for compliance assessments.
  • Section 48 Notices – Require individuals to attend interviews under oath.
  • Section 139B Notices – Issued when ASIC suspects a contravention of financial services laws.
  • Section 1317DAE Infringement Notices: These are Issued when ASIC believes a breach has occurred. Understanding the type of notice received helps ensure an appropriate and timely response.

3. Can an ASIC notice be challenged?

Yes, ASIC notices can be challenged if they are overly broad, based on incorrect assumptions, or lack legal grounds. If you believe a notice is unjustified, seek legal advice to explore options such as requesting clarification, negotiating the scope, or formally objecting in writing. In extreme cases, judicial review may be pursued to challenge an ASIC notice in court.

4. What happens if I fail to respond to an ASIC notice?

Failing to respond to an ASIC notice can result in significant consequences, including fines, enforcement actions, or even suspension or cancellation of a financial services license. Providing inaccurate or incomplete information can also lead to penalties or criminal charges. Therefore, taking ASIC notices seriously and ensuring full compliance is essential to avoid regulatory repercussions.

5. How can my business prepare for ASIC compliance and notices?

To proactively manage ASIC compliance:

  • Conduct regular internal audits and compliance reviews.
  • Maintain accurate and up-to-date records.
  • Train employees on regulatory requirements and best practices.
  • Establish a structured response plan for regulatory inquiries.
  • Seek legal or compliance advice when necessary. By implementing these best practices, Licensees can reduce regulatory risks and ensure readiness for ASIC notices.

Regulatory Response Checklist

Step 1: Acknowledge and Review the Notice

  • Confirm receipt: Acknowledge the notice promptly.
  • Identify the type and scope: Determine whether it requires documents, explanations, or an appearance.
  • Assess deadlines: Note the submission timeframe and whether extensions are possible.

Step 2: Engage Legal and Compliance Experts

  • Consult and formally engage regulatory compliance professionals or lawyers to interpret the notice and assess risks.
  • Review ASIC Regulatory Guides relevant to the notice (e.g., RG 78 for breach reporting, RG 104 for compliance obligations, RG 98 for licensing requirements).

Step 3: Gather and Verify Information

  • Identify relevant documents and ensure accuracy.
  • Cross-check records with compliance logs and policies.
  • Verify access to offshore and cloud-based records to ensure compliance.
  • Document the process to demonstrate due diligence.

Step 4: Prepare a Clear and Compliant Response

  • Draft a structured response addressing each request point-by-point.
  • Provide all requested documents, ensuring they are unaltered and complete.
  • If clarification is needed, seek guidance from ASIC before submitting.

Step 5: Submit and Monitor Follow-Up Actions

  • Submit the response via the prescribed ASIC channel.
  • Keep records of all correspondence and submissions.
  • Prepare for potential follow-up inquiries or additional document requests.

Step 6: Implement Compliance Improvements

  • If ASIC identifies weaknesses, update compliance frameworks accordingly.
  • Strengthen internal monitoring and reporting processes.
  • Provide training to staff on compliance obligations.

Step 7: Monitor for Further Regulatory Action

  • Be prepared for follow-up queries or inspections.
  • Keep stakeholders, including directors and compliance officers, informed.
  • Learn from the experience to improve future compliance practices.
  • Submit the response via the prescribed ASIC channel.
  • Keep records of all correspondence and submissions.
  • Prepare for potential follow-up inquiries or additional document requests.

Keep exploring

How to Respond to an ASIC Notice: A Practical Step-by-Step Guide for Licensees

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?