Licensee Data is the New Oil

Licensee Data is the New Oil

Licensee Data is the New Oil

“Understanding variation is the key to success in quality and business.” — W. Edwards Deming

 

Subscribe

Time to mine, refine and reflect

“Firms should analyse .. data regularly ” — ASIC RG 271 “Internal dispute resolution”

 

While institutional licensees withered under increased (and increasing) regulatory and stakeholder expectations, others looked forward and others looked forward and anticipated how advice businesses need to evolve to prosper in the new regulatory regime.

We’ve written before about how, over the last six months, we’ve transformed OpenAFSL with the aim of improving the quality of the data available to the Licensees.

The new iteration is not only much more visually engaging, but the granularity and inter-connectivity means that users are better equipped to identify, and remediate, systemic issues, in a manner aligned to ASIC’s expectations.


Data + Insight

We have, at last count, reviewed over 11,000 client files using a consistent, qualitative and risk-based advice assurance process. What you might not appreciate is that we’ve also reviewed a large number of AFS Licensees to assess, among other things, their organisational design and their operational effectiveness.

We don’t need to reiterate the obligations imposed on them by 912A and the regulatory guides, but we want to share our view of Licensee compliance.

Licensee Issues.png

The larger the sector, the greater the number of issues identified.
These results vary according to the Licensee, State, experience and advice focus (as well as subject and scope).

We can talk you through the subtleties, variations and inconsistencies (in the context of training, breach, remediation and complaint data).

In our view, Licensees will be increasingly expected to be able to do the same – so take this opportunity to either review your current capabilities or talk to us about how we can help you.

I Need Better Data

We’ll continue to identify and manage preferences (ethics and conduct), but we’ll do it in a way that is even more intuitive and even more practical.

Unlike the mechanistic process routinely followed by most Licensees, OpenAFSL focuses on the client experience and creates a formal demarcation between formal and substantive compliance issues; our users are therefore better placed to consider matters in context and therefore better differentiate between intent, process and outcome.


Common Failures

Framework

  • Absence of a risk framework however stated/documented
  • Off the shelf framework with zero customisation. The issue with this, is that we see boutique licensee operating under risk frameworks designed for, or better suited, to a billion dollar vertically-integrated organisation. Which makes no sense and is also quite risky
  • Risks are not discussed during compliance or other meetings. Compliance meetings are about considering emerging compliance risks and to measure progress on existing compliance risks
  • Licensees cannot distinguish the difference between compliance and operational risk. This is an important distinction, as acceptance or risk levels relates to operational risk (the risk of economic loss resulting from inadequate or failed internal processes, people and systems or from external events) as compared to compliance risk. Operational risk includes legal, regulatory, fraud, business continuity and technology risks and also considers the impact to brand and reputation. In comparison, compliance risk is the risk of legal or regulatory sanctions, material financial loss or loss of reputation that you may incur as a result of its failure to comply with its compliance obligations. You would not be able to risk accept non-compliance with your regulatory obligations.
  • Regular external reviews are not conducted. This compromises the monitoring supervision requirements.

Activities

  • The regulated documents contain information regarding referrals and related content which is non-compliant with the FASEA Code of Ethics.
  • Regulated documents have omissions in relation to minimum legal drafting requirements or do not contain dates and version numbers, plus a register is not being maintained for the FSG’s.
  • Websites, social media pages and linkedin are non-compliant with RG 234 and RG 175 requirements. I.e. do not contain a general advice warning; AFSL numbers; Information in relation to Authorised Representatives does not align to information contained on the public Financial Adviser Register .
  • The Licensee does not have a documented research process.
  • Promotional material does not comply.

Technology

  • Licensees Privacy Policies do not comply because they:
    • Are not dated
    • Do not contain minimum drafting requirements per the Australian Privacy Principles
    • Contain blank fields
    • Are out-dated.
  • Licensees do not have an IT strategy in place to manage current and future needs.
  • Licensees have outdated contracts in place with outsourced IT providers, which do not adequately manage current cyber security considerations etc.
  • Licensee does not have a Notifiable Data Breach Plan in place
  • Data breaches are logged on the incidents register, however they have not been assessed and treated via the NDS requirements.

Governance

  • Licensees conduct Compliance Committee Meetings in accordance with legacy Institutional processes that do not suit the size and complexity of their business.
  • Licensees do monitor, discuss, table compliance considerations as part of meetings
  • Compliance Committee Meeting minutes are inadequate and potentially problematic if read out of context of the discussion.
  • Compliance Committee Actions are not regularly or adequately managed
  • Key risk registers are not being monitored or do not align to the live registers.

Pricing

If you exclude the advice review module from your system, you can obtain access to a reg-tech platform built by, and supported by, compliance experts.

For a relatively low licensing fee (based on user numbers) you’ll secure the data, systems, training and support the Regulators expect you already have.

Pricing is flexible and customised to your needs. From as little as $240 per user per month you can access a compliance platform that can free you from the burden of compliance.

Contact me if you have any questions or want to arrange a demonstration.

Subscribe

“Understanding variation is the key to success in quality and business.” — W. Edwards Deming

 

Subscribe

Time to mine, refine and reflect

“Firms should analyse .. data regularly ” — ASIC RG 271 “Internal dispute resolution”

 

While institutional licensees withered under increased (and increasing) regulatory and stakeholder expectations, others looked forward and others looked forward and anticipated how advice businesses need to evolve to prosper in the new regulatory regime.

We’ve written before about how, over the last six months, we’ve transformed OpenAFSL with the aim of improving the quality of the data available to the Licensees.

The new iteration is not only much more visually engaging, but the granularity and inter-connectivity means that users are better equipped to identify, and remediate, systemic issues, in a manner aligned to ASIC’s expectations.


Data + Insight

We have, at last count, reviewed over 11,000 client files using a consistent, qualitative and risk-based advice assurance process. What you might not appreciate is that we’ve also reviewed a large number of AFS Licensees to assess, among other things, their organisational design and their operational effectiveness.

We don’t need to reiterate the obligations imposed on them by 912A and the regulatory guides, but we want to share our view of Licensee compliance.

Licensee Issues.png

The larger the sector, the greater the number of issues identified.
These results vary according to the Licensee, State, experience and advice focus (as well as subject and scope).

We can talk you through the subtleties, variations and inconsistencies (in the context of training, breach, remediation and complaint data).

In our view, Licensees will be increasingly expected to be able to do the same – so take this opportunity to either review your current capabilities or talk to us about how we can help you.

I Need Better Data

We’ll continue to identify and manage preferences (ethics and conduct), but we’ll do it in a way that is even more intuitive and even more practical.

Unlike the mechanistic process routinely followed by most Licensees, OpenAFSL focuses on the client experience and creates a formal demarcation between formal and substantive compliance issues; our users are therefore better placed to consider matters in context and therefore better differentiate between intent, process and outcome.


Common Failures

Framework

  • Absence of a risk framework however stated/documented
  • Off the shelf framework with zero customisation. The issue with this, is that we see boutique licensee operating under risk frameworks designed for, or better suited, to a billion dollar vertically-integrated organisation. Which makes no sense and is also quite risky
  • Risks are not discussed during compliance or other meetings. Compliance meetings are about considering emerging compliance risks and to measure progress on existing compliance risks
  • Licensees cannot distinguish the difference between compliance and operational risk. This is an important distinction, as acceptance or risk levels relates to operational risk (the risk of economic loss resulting from inadequate or failed internal processes, people and systems or from external events) as compared to compliance risk. Operational risk includes legal, regulatory, fraud, business continuity and technology risks and also considers the impact to brand and reputation. In comparison, compliance risk is the risk of legal or regulatory sanctions, material financial loss or loss of reputation that you may incur as a result of its failure to comply with its compliance obligations. You would not be able to risk accept non-compliance with your regulatory obligations.
  • Regular external reviews are not conducted. This compromises the monitoring supervision requirements.

Activities

  • The regulated documents contain information regarding referrals and related content which is non-compliant with the FASEA Code of Ethics.
  • Regulated documents have omissions in relation to minimum legal drafting requirements or do not contain dates and version numbers, plus a register is not being maintained for the FSG’s.
  • Websites, social media pages and linkedin are non-compliant with RG 234 and RG 175 requirements. I.e. do not contain a general advice warning; AFSL numbers; Information in relation to Authorised Representatives does not align to information contained on the public Financial Adviser Register .
  • The Licensee does not have a documented research process.
  • Promotional material does not comply.

Technology

  • Licensees Privacy Policies do not comply because they:
    • Are not dated
    • Do not contain minimum drafting requirements per the Australian Privacy Principles
    • Contain blank fields
    • Are out-dated.
  • Licensees do not have an IT strategy in place to manage current and future needs.
  • Licensees have outdated contracts in place with outsourced IT providers, which do not adequately manage current cyber security considerations etc.
  • Licensee does not have a Notifiable Data Breach Plan in place
  • Data breaches are logged on the incidents register, however they have not been assessed and treated via the NDS requirements.

Governance

  • Licensees conduct Compliance Committee Meetings in accordance with legacy Institutional processes that do not suit the size and complexity of their business.
  • Licensees do monitor, discuss, table compliance considerations as part of meetings
  • Compliance Committee Meeting minutes are inadequate and potentially problematic if read out of context of the discussion.
  • Compliance Committee Actions are not regularly or adequately managed
  • Key risk registers are not being monitored or do not align to the live registers.

Pricing

If you exclude the advice review module from your system, you can obtain access to a reg-tech platform built by, and supported by, compliance experts.

For a relatively low licensing fee (based on user numbers) you’ll secure the data, systems, training and support the Regulators expect you already have.

Pricing is flexible and customised to your needs. From as little as $240 per user per month you can access a compliance platform that can free you from the burden of compliance.

Contact me if you have any questions or want to arrange a demonstration.

Subscribe

Keep exploring

Licensee Data is the New Oil

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?