One of the most common challenges for Licensees is determining whether an incident is actually reportable to ASIC. The legislation sets out the obligation, but in practice, the decision often sits in a grey area.
A simple decision framework can bring consistency and defensibility to that process. This framework applies to both AFSL and ACL Licensees.
Decision Tree for ASIC Reportable Situations
Step 1: Has an incident, error or operational failure occurred?
If no, no further action is required.
If yes, record the matter and proceed to assessment.
This step is intended to capture all relevant issues, not just clear breaches. In practice, this includes errors, process failures, control breakdowns, complaints and near misses. These are all potential precursors to a breach and should be assessed consistently.
Step 2: Does the breach relate to a core obligation?
Focus on whether the issue goes to the heart of how your business operates. Core obligations are failures that suggest the business is not doing, or has failed to do, something fundamental.
In practice, this includes situations where advice was not provided appropriately, key processes were not followed, controls failed, clients may have been impacted, or there are signs of operational strain such as service delays, increasing client complaints, or failures to respond to these issues.
If yes, continue.
Step 3: Is the breach significant?
Consider:
- repeated or similar issues (for example, the same error occurring more than once in a short period, or across multiple clients)
- any client impact or likely impact (including financial loss, incorrect advice, or delays that affect outcomes)
- missed or at-risk obligations (for example, deadlines not met, required actions not completed, or complaints not handled in time)
- indicators the problem is not isolated (for example, process gaps, unclear responsibilities, or controls not working as intended)
If the breach is significant, it is likely reportable.
Step 4: Is it part of a broader systemic issue?
Even if a single incident appears minor, repeated occurrences or signs that controls are not working (for example, the same error affecting multiple clients, recurring delays, or unresolved issues) may elevate it to a reportable situation.
Step 5: Does it trigger automatic reporting categories?
Certain matters are reportable without requiring a detailed significance assessment.
In practical terms, treat the matter as reportable if you have:
- commenced a formal investigation into suspected serious misconduct (for example, adviser misconduct, dishonest conduct, or material failures in advice)
- identified conduct that could reasonably be characterised as gross negligence or a serious failure of controls
- taken or are considering decisive action such as suspending or terminating an adviser or representative for cause
As a rule of thumb, if the issue is serious enough to trigger a formal investigation or disciplinary action, it is likely to fall within these categories and should be treated as reportable.
Step 6: Make and document the decision
Apply your internal decision framework aligned with ASIC Regulatory Guide 78, ensuring the same approach is consistently applied across similar matters.
Record the rationale clearly, including the key factors considered, supporting evidence, and why the matter was or was not assessed as reportable.
Step 7: Escalate where uncertain
Borderline matters should be escalated to compliance or legal specialists. Consistency is more important than speed at this stage.
Step 8: If reportable, lodge within the required timeframes
Once a reportable situation is confirmed, it must be lodged with ASIC within the required statutory timeframe (generally 30 calendar days). Ensure complete and accurate records are maintained.
Why this matters
ASIC expects Licensees to demonstrate not only that they report breaches, but that they apply a consistent and well-reasoned process in determining what is reportable.
A documented decision tree helps ensure:
- consistent assessments across the business
- defensible decisions under regulatory scrutiny
- timely escalation of genuine issues
From decision to defensible process
In practice, the difference between reactive breach reporting and a mature compliance function lies in the consistency of application. Licensees who rely on ad hoc judgment or informal escalation processes often struggle to demonstrate how decisions were reached.
Without centralised investigation workflows and defensible decision records, incident assessments can become inconsistent across teams, reviewers and reporting periods.
Platforms such as [complyᵉ] are increasingly being used by licensees to operationalise reportable situations frameworks through structured incident registers, investigation workflows, escalation pathways and remediation tracking.
Assured Support works with Licensees to design and implement decision frameworks that are applied consistently, documented clearly and aligned to ASIC expectations. Where appropriate, this includes embedding structured workflows and systems to support consistent assessment and reporting.
If you would like to discuss your current approach with one of our experts, you can arrange a time here.
If you liked this article, you might also like:
- Reportable Situations (Part 1): ASIC’s Findings and Why They Matter
- Reportable Situations (Part 2): How to Meet (and Exceed) ASIC’s Expectations
Frequently Asked Questions
An incident becomes reportable when it constitutes a “reportable situation” under ASIC RG 78, typically involving significant breaches or likely significant breaches of core obligations, or where automatic reporting triggers apply.
Significance is assessed based on factors such as frequency, client impact, extent of loss, and whether the issue indicates systemic control failures, as outlined in RG 78.
Yes. While not all near misses or minor errors are reportable, ASIC expects licensees to consistently capture and assess all incidents, as they may indicate emerging systemic issues.
These include commencing investigations into serious misconduct, identifying gross negligence, or taking disciplinary action such as adviser termination for cause—these must be reported regardless of significance.
ASIC expects licensees to demonstrate how decisions were made. Clear documentation provides evidence of a consistent, reasonable, and compliant decision-making process.