Although frequently disproved by reality, the idea that Compliance is functionally independent of Licensee management is one of the most enduring myths of financial services. You didn’t need REP515 to recognise the ugly reality that internal Compliance functions are generally compromised, conflicted and, inevitably, ineffective.
Despite institutional failures, this myth remains a cornerstone of effective Licensee governance. It’s the mechanism by which consumer rights are defended, conflicts of interest are managed, standards are upheld, and confidence in financial services is maintained. It’s a fine idea, and a great principle, but how can it be achieved in non-institutional Licensees? Is “independent compliance” unachievable in small or medium AFSLs?
Clearly, smaller licensees often operate with leaner teams, flatter structures, and fewer resources. ASIC’s operational mantra of “nature, scale and complexity” recognises that proportionality is not only reasonable, but essential. But proportionality doesn’t legitimise inadequacy. Independence doesn’t become unnecessary simply because a licensee is small. Instead, it must be adapted, demonstrated, and embedded in practical ways that reflect the licensee’s scale and structure.
Why Independence Matters
Independence shouldn’t just be a regulatory expectation; it’s the practical safeguard that ensures compliance functions, audits, and reviews can operate without undue influence. It provides credibility to decision-making, protects clients, and reduces risks for licensees.
For AFSLs, s912A of the Corporations Act 2001 requires licensees to maintain adequate resources, systems, and arrangements. Independence isn’t explicitly required, but it sits squarely within this obligation and is entirely consistent with regulatory expectations of gatekeepers. The simple truth is that when independence is lacking, so too is the integrity of a licensee’s compliance framework. In my experience, while functional independence is critically important, it often aggravates the people it protects. My stance against double gearing, capitalisation of interest, and 100% LVRs led management to engage a Consultant to recommend my replacement with a more “commercial” compliance manager. Thankfully, the Consultant refused to write that recommendation, and the GFC killed the coup.
The Challenge for Smaller AFSLs
Unlike large institutions, smaller licensees can’t always establish fully separated compliance or risk teams or, in many cases, even a dedicated compliance resource. A director may also act as a Responsible Manager (RM), adviser, and compliance lead. Staff may wear multiple hats, and resources may not allow for dedicated oversight roles.
These structural realities create tension. On the one hand, independence must be real and demonstrable. On the other, the regulator and assessors should not expect the same scale of separation that exists in institutions with hundreds of staff.
The question then becomes: how can smaller AFSLs achieve independence in proportionate but credible ways? I know you’re expecting me to recommend outsourcing, and it can be the best option, but it can also be the worst option. Rest assured, there are a variety of solutions.
What Independence Looks Like
Even in smaller licensees, independence is achievable. It requires thoughtful design and an emphasis on function over form. Key indicators include:
- Clear Role Separation
- RMs should not be the sole reviewers of their own advice.
- In the right culture, independence can be achieved through peer review, rotating oversight, or external compliance support.
- Documented Processes
- Policies should explain how independence is preserved despite size constraints.
- Escalation procedures must provide an impartial pathway when issues involve senior staff or directors.
- Evidence of Challenge
- Minutes, compliance reports, or file review records should show that decisions are questioned, not simply endorsed.
- Use of External Support
- Independent file reviews, audits, or consultancy input are proportionate ways for smaller licensees to bring objectivity into their arrangements.
These practices demonstrate that independence is more than a theoretical construct; it is an operational discipline.
Proportionality vs. Inadequacy
For Responsible Managers and Compliance Staff, the line between proportionality and inadequacy is critical. Independence must never be symbolic or illusory. The following examples illustrate the distinction:
| Acceptable Proportionality | Inadequate Arrangements |
|---|---|
| Policies reference independence, but no practical steps are in place. | RM/Director self-reviews their own advice with no independent oversight. |
| The owner-operator uses an external compliance consultant to review advice files. | “Independent review” conducted by a close associate who is not impartial. |
| A small team rotates peer reviews, with findings recorded and followed up on. | No escalation path beyond the individual whose conduct is under review. |
| Regular external audits supplement limited internal resources. | Policies reference independence, but no practical steps exist. |
This distinction reflects both the regulator’s principle-based expectations and real-world insight: independence can be achieved in different ways, but it cannot be ignored or substituted with window-dressing.
Questions Auditors Should Ask
When reviewing a smaller AFSL, Auditors should look beyond the written policy and test the substance of independence to assess the Licensee’s compliance arrangements. Useful questions include:
- Is there a mechanism to ensure conduct is reviewed by someone not directly involved?
- Does the licensee have documentary evidence of independence, such as review reports or board minutes?
- Are independence arrangements scalable and adaptable to growth, or are they a means of avoiding scrutiny?
- How are conflicts involving directors or RMs escalated and resolved?
By applying these questions, auditors (and Compliance experts) can determine whether independence exists in substance or only in form.
Independence Is About Substance, Not Size
The reality is that, to ASIC’s relief, independence in smaller AFSLs will never look identical to independence in large institutions. Size might matter, but that does not absolve licensees from the obligation to try to minimise conflicts, compromises and apathy. Compliance demands creativity, transparency, and evidence.
Auditors should look beyond the organisational chart to identify practical arrangements that reflect the scale of the business, prevent self-review, provide credible oversight, and demonstrate real challenge. They also need to recognise that where arrangements collapse into self-policing, window-dressing or rubber-stamping, real independence is absent — and so is the Licensee’s compliance with the law.
Function Over Form
Independence remains one of the most reliable markers of an AFSL’s compliance culture and maturity. For smaller licensees, it is not about replicating the structures of larger firms, but rather about avoiding their weaknesses and ensuring that proportionality does not slide into inadequacy and ineffectiveness.
Practical steps, such as external review, peer oversight, documented processes, and clear escalation pathways, can help mitigate the challenges of limited resources and multiple roles. Look for substance, not size, and focus on whether your independent compliance function operates effectively in practice.
If you’ve learnt nothing else from the Royal Commission and recent regulatory actions, you must acknowledge that having an independent compliance function is not optional. It is the discipline that ensures your governance framework is credible, your compliance culture is authentic, and that your clients can trust the advice they receive.
If you enjoyed this article, you might also like:
- Managing an AFSL: Compliance, liability and risk.
- Risk Management 2.0 for a Small AFSL: Practical, Adaptive, and Intent-Led
- Governance Essentials for AFS Licensees: A Practical Guide
Frequently Asked Questions
Because independence ensures that compliance functions can operate without undue influence, it preserves the integrity of oversight and protects clients, licensees, and the financial services industry as a whole.
Through clear role separation, documented procedures, peer reviews, independent audits, and credible escalation pathways—all tailored to reflect their scale and structure.
While s912A doesn’t explicitly mention “independence,” it does require adequate systems and arrangements, under which functional independence is a consistent and expected regulatory standard.
Evidence of review challenge, documented decisions, escalation mechanisms, and the involvement of independent parties all signal genuine independence.
When independence is illusory, conflicted, or unsupported by practical safeguards—such as self-reviews, rubber-stamping, or lack of escalation—proportionality gives way to inadequacy and risk.