What Two 2025 Compliance Surveys Reveal (and How AFSLs Should Respond)
“These are the days that try men’s souls”
Thomas Paine
Thomas Paine might not have initially been speaking to Responsible Managers and Licensees, but his observation is apt (if insufficiently inclusive). Right now, AFS licensees face a confronting reality – compliance spending is falling even as the regulatory burden surges. Worse still, these trends are widespread, publicly recognised and systemic.
Holley Nethercote (HN) analysed 208 AFSL and ACL licensees, most of whom are already compliance-engaged.
PwC surveyed 73 senior executives from large and mid-tier Australian companies to assess how regulatory complexity reshapes operations.
ASIC identified that the responsible entities (REs) of a combined total of nearly $1 trillion in managed investments failed to maintain adequate compliance plans.
These reports expose the growing disconnect between regulatory expectations and current practice.
They provide a clear signal of where ASIC is likely to direct its scrutiny—and a unique opportunity for licensees to demonstrate leadership by acting ahead of enforcement.
Complexity is no longer a nuisance; it is a tax on growth. 56% of executives report negative impacts on every major growth driver, with 93% pointing to technology adoption as the hardest hit. Compliance fatigue now reaches senior leadership: 94% say complexity diverts their focus from strategy.
Six Chronic Weaknesses Exposed
Amid ongoing discussion about the costs of the year-old Compensation Scheme of Last Resort, it’s important to remember that, ultimately, the main driver of the cost of the scheme is flawed business models leading to consumer complaints.
Shail Singh, Lead Ombudsman, Investments and Advice – 30 March 2025
Weakness
Data Highlights
ASIC Lens
Immediate Actions
1.Under‑Resourcing
40 % of licensees spend <$100k on internal compliance staff (up from 29 % in 2024). PwC shows 70% of firms rely on external advisers for core compliance work.
Adequate resources duty under s912A(1)(d) Corporations Act 2001 (Cth).
• Benchmark budget vs peer group. • Document how spend aligns with risk profile. •Engage independent experts.
2. Mid‑Sized “Missing Middle”
> 40 % of licensees with 16–50 reps have no monitoring & supervision policy.
Only 53% maintain whole‑of‑staff training plans. Nearly 70% cite poor data quality as a barrier to compliance.
Competency duty s912A(1)(f).
• Build role‑based CPD matrix. • Remediate data quality issues. • Track effectiveness, not attendance.
ASIC’s Likely Response
Minimum Benchmarks – ASIC will likely issue public guidance outlining minimum expectations for compliance resourcing and committee oversight. This may include thresholds for staffing, budget, and frequency of compliance committee meetings, particularly for high-risk licensees.
Targeted Surveillance – Expect focused supervisory programs targeting licensees with 16–50 representatives. These may involve structured thematic reviews, governance diagnostics, and compulsory remediation plans for those falling below expected standards.
AI & Technology Governance – ASIC is anticipated to introduce “compliance-by-design” expectations consistent with PwC’s framework. This could take the form of an Information Sheet or Regulatory Guide, mandating that licensees embed AI governance policies, perform risk assessments, and maintain accountability through board-level reporting.
Conflicts Reviews – ASIC may launch industry-wide thematic reviews to assess how effectively licensees identify, log, disclose, and manage conflicts of interest. Particular attention will be paid to firms reporting no conflicts or maintaining dormant registers.
Conduct & Culture Sweeps—Surveillance activity will likely intensify around compliance with the “efficiently, honestly and fairly” obligation (s 912A(1)(a)). ASIC may revisit culture-focused reviews, assessing tone from the top, accountability structures, and issue escalation protocols.
Capability Audits – ASIC may initiate audits to test whether CPD programs, staff training, and compliance skill levels meet expectations. Licensees could be asked to produce training matrices, evidence of role-specific capability plans, and data quality governance protocols.
A Compliance‑By‑Design Roadmap
Compliance‑by‑design means embedding control requirements up‑front, not patching them after launch. Use the following roadmap to turn survey insights into a strategic advantage:
1. Map Your Compliance Ecosystem
Catalogue every compliance activity and owner.
Visualise inter‑dependencies—risk, audit, legal, IT.
Establish a cross-functional forum to track regulatory change.
2. Revisit Strategy & Structure
Define a three-year vision for compliance maturity (remember: 92% of firms plan to be ‘leading’ or ‘mature’ by 2028).
Align compliance structure with business strategy and product roadmaps.
Give Compliance Leaders a genuine seat at the table.
3. Invest In Data, Tech & AI
Agree on a target architecture for compliance tech and data.
Pilot AI use cases (breach triage, policy mapping), supported by a Responsible AI framework.
Connect data sources to create a single source of truth for compliance reporting.
4. Close The Capability Gap
Perform a talent‑gap analysis.
Use secondments and micro-credentials to build multidisciplinary skills.
Pair internal staff with external specialists to accelerate knowledge transfer.
Why Act Now?
These surveys reveal that even compliance-engaged licensees, those most likely to be proactive, well-resourced, and risk-aware, are struggling to maintain effective compliance arrangements. These licensees represent the upper tier of regulatory preparedness, yet the survey data shows a troubling decline in investment, monitoring rigour, and conflict oversight.
If the “best‑behaved” two per cent are showing cracks, ASIC will reasonably infer that the broader market, which may be less engaged or less resourced, faces even more significant challenges. This assumption raises the bar for all licensees and signals an elevated risk of intervention.
Inaction risks:
Enforcement: Downgrades to licence conditions, formal directions, civil penalties, or banning orders.
Reputation: Loss of trust from clients, advisers, and stakeholders; increased media scrutiny; and higher professional indemnity insurance premiums.
Operational Drag: Inefficient, reactive compliance efforts that escalate long-term costs and reduce agility.
Proactive licensees, by contrast, can position themselves as industry leaders. By addressing gaps early, they can demonstrate prudent stewardship, reduce the likelihood of intrusive regulatory scrutiny, and build reputational capital with ASIC and clients.
Assured Support: Your Independent Partner
Our consultants have delivered 22,000+ file reviews and supported 200+ licensees nationwide. We offer:
Compliance Resourcing Gap Analysis
Supervision Framework Design & Implementation
AI Risk‑Assessment Templates & Board Packs
Conflict‑Management Refresh Programs
Data‑Quality Diagnostics & Remediation (addressing the 70% reliability gap)
Role-Based CPD Frameworks & Effectiveness Reviews
Reach us at support@assuredsupport.com.au or visit www.assuredsupport.com.au for a confidential discussion.
Conclusion
Complexity is rising, budgets are shrinking, and ASIC is watching—but this isn’t just a risk to manage, it’s a leadership moment to seize.
The message from both surveys is clear: doing the bare minimum is no longer enough. ASIC has raised the bar, and licensees who want to maintain their reputation, influence and market position must also raise theirs. Compliance-by-design isn’t a theoretical model—it’s a competitive advantage. By embedding governance in product, advice and technology pipelines now, you future-proof your business against enforcement, enhance operational resilience and build trust with clients and regulators alike.
Those who act first will set the standard. Those who wait will be measured against it.
Use these insights to lead—before you’re forced to follow.
1. Why is compliance complexity considered a “tax on growth” for Australian financial firms?
Compliance complexity consumes resources and executive focus, with 90% of leaders citing increased regulatory burden. It impedes key growth drivers—especially technology adoption, where 93% report delays—leading to strategic stagnation and higher operational costs.
2. What are the biggest compliance weaknesses AFSLs need to address in 2025?
Six chronic issues include under-resourcing, lack of supervision frameworks, conflicts of interest blind spots, outdated technology governance, irregular monitoring, and capability/data gaps. Each links directly to ASIC’s core obligations under s 912A of the Corporations Act.
3. How is ASIC expected to respond to poor compliance practices?
ASIC is likely to raise minimum benchmarks, increase surveillance on mid-sized firms, issue AI governance guidance, and conduct thematic reviews on conflicts and conduct. Firms with weak practices may face formal directions, licence condition downgrades, or penalties.
4. What does ‘compliance-by-design’ mean, and why is it important now?
Compliance-by-design is the proactive integration of compliance controls into systems, products, and governance from the start. It ensures resilience, meets rising regulatory expectations, and positions firms as forward-thinking leaders in a changing compliance landscape.
5. How can AFSLs future-proof their compliance frameworks?
AFSLs should map their compliance ecosystem, align strategy with compliance maturity goals, invest in AI and data quality, close skill gaps, and adopt continuous monitoring. Independent advisors and structured training frameworks can accelerate transformation effectively.
Australia’s wholesale client test can treat wealth as a proxy for financial sophistication. We examine why the current thresholds are outdated and how the framework could better protect genuinely retail investors.
ASIC wants to be easier to deal with for businesses trying to comply — and harder to avoid for those causing harm. Here’s what ASIC’s 2026–27 Corporate Plan means for boards, Responsible Managers and compliance teams.
Leaving a financial advice licensee should be straightforward. Too often, ambiguity around compliance, client communications, records and authorisation gives the incumbent licensee leverage. Here’s how advisers can recognise it, reduce dependencies and prepare before they resign.
Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.
AS-Subscribe Form
"*" indicates required fields
We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.