Make them happy: Five ways to manage Compliance

Make them happy: Five ways to manage Compliance

Make them happy: Five ways to manage Compliance

“Clap along if you know what happiness is to you (Because I’m happy)”

— Pharrell Williams, Compliance and Risk Manager

Have you subscribed?

Happy Business, Happy Life

It’s easy to get caught up in the day-to-day with so many competing priorities; client meetings, file notes, keeping up with Continuing Professional Development and legislative change. It’s a lot to manage.

In fact, running an advice practice or an AFSL can seem like a very thankless job.

As a Practice/Compliance Manager (and we’ll add to this group other related roles such as responsible manager, advice business owner and advice manager), there’s a lot of crucial but often invisible work that’s essential to the running of an advice business.

Our job is to make your job easier so here are some key takeaways from talking with our clients – advisers, practices, and licensees – around how you can minimise the friction, aggravation and unrest too often associated with “Compliance”.

You may, as an adviser, think this article isn’t for you but remember the famous proverb “Happy compliance, happy life” (or something similar).


1. Read and understand Licensee policies

It may surprise you to learn that most adviser errors could have been simply solved or avoided if the adviser had taken the time to carefully read their Licensee’s policies.

Even if you plan to do so when things get a little quieter, we recommend that you prioritise the following policies if they fall within your current activities:

  • When to use an SoA/RoA;
  • Gearing/margin lending;
  • SMSF policies & checklists.

It’s important to remember that your Licensee often designs these policies to reflect their scope and scale, the conditions of their professional indemnity insurance policy and their risk appetite – so it’s often dangerous to presume that your Licensee’s policy will be the same as your last Licensee’s policies or simply reflect the law. Your Licensee may choose to exceed the legislative requirements in order to fulfil their obligations under their AFSL.

You’ll make your licensee happy, and your compliance staff even happier, if you take the time to read and understand their policies. There’s an even more immediate benefit for you, these documents often contain checklists and tools to make your advice process both more compliant and more commercial. And if they don’t, reach out to us to rewrite them.


2. Take great file notes

We’ve said it before, and we’ll say it again, great file-notes are simply invaluable.

Detailed file-notes that are contemporaneous records of the clients’ own words, and focus on how the client felt, thought, and behaved, are immeasurably more valuable than a record of the compliance obligations that were executed in a meeting.

File notes (including audio and video records) can be incorporated, or referenced, in SoAs to demonstrate connection, intimacy and understanding. More prosaically, they provide context for advice recommendations and comfort for you in the event of a client complaint.

Keeping good file-notes is challenging, but not impossible, when we’re already time-poor but there are workable strategies you can use. Some advisers use dictation software or dictation recordings that are sent away for transcription (subject of course to Licensee approval and data protection considerations).

The real trick here is to do file notes thoroughly and effectively so that they change from becoming a burden to a key piece of information in getting to know clients.


3. Be consistent with your record-keeping

There is nothing quite like the panic of preparing for an upcoming audit and wondering where the relevant documents are. Thankfully, this fear can be avoided with some basic housekeeping.

Have a file name convention in your business:

  • This should be easy to understand and documented so that anyone who works with you will be able to follow it;
  • For example “SurnameFirst-DDMMYYYY-DocType-Author” or “SmithJ-12092021-SOA-Nadia”;
  • This makes it much easier to find key information not just for your business, but for your auditors and regulators.

Tips for consistent document storage:

  • Have one source of truth, because looking through multiple sources of information makes it hard to put an accurate picture of a client file together;
  • If you are currently bound to separate systems, consistently use your separate systems, document which systems store what information and stick to it;
  • Even an adviser who knows their client well can take considerable time to find information that is a year or more old if they are searching across multiple systems, so you can begin to imagine how tough it is for your Practice/Compliance Manager to help you when they may never have met your clients.

Keep filing up-to-date:

  • Have a regular process that ensures your documents are stored in a timely manner so that you aren’t sifting through piles of paperwork or folders of electronic documents trying to figure out what belongs where.

When ASIC, AFCA or another organisation requests access to your client file following a complaint or random review, it is not going to be any easier then than now to do an implementation checklist and collect, collate and structure all relevant documents.

In fact, it may well be very hard to retrospectively generate any documentation that may be missing such as supporting research.


4. Create a culture of cybersecurity awareness

The RI Advice case and the more recent Optus and Medibank Private data breaches, highlight the need to build a strong cybersecurity culture in your business. It not only reassures current and prospective clients but strengthens the relationship of trust that is critical to any ongoing advice relationship.

Tips for creating a better cybersecurity culture are:

  • Engage a cybersecurity expert if you can, or a good IT firm who can give you advice and suggestions relevant for your business;
  • Ask our Licensee for help;
  • Consider taking out cybersecurity insurance;
  • Have regular catch-ups with your team to talk about examples of what phishing scams, irregularities and attachments in emails and other methods that hackers may try to use to attack your business;
  • Ask a central person in your business like your Practice/Compliance Manager to collate queries and potential issues to formulate an overall view of the cybersecurity risks in your business so that your business can isolate any patterns or systemic vulnerabilities to be fixed and improved.

5. Ask questions

Although Sean might occasionally disagree with this assertion, there are no stupid questions.

You operate in a complicated and frequently changing regulatory environment, where errors (and unintended consequences) can attract significant penalties. Traditionally, many advisers deal with compliance issues (or Compliance generally) by living by the mantra that “it’s easier to ask for forgiveness than to get permission” and we understand the legacy issues that created that impression.

We can’t eradicate cultural assumptions overnight, so we’ll suggest an alternative mantra that will improve your life and make your compliance manager happy – “measure twice, cut one”. You may cynically suggest that it only makes your life easier because it will make your compliance manager happy, but taking the time to check your assumptions, biases and understanding BEFORE you commit to a profound course of action (instead of after) will, I assure you, make you less anxious over time.

I cannot stress this enough. If in doubt, and particularly when you are unreasonably confident, seek the insight of your colleagues, external contacts, your Licensee, and your external compliance team at help@assuredsupport.com.au

Have you subscribed?

Keep exploring

Make them happy: Five ways to manage Compliance

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?