“Consequence management .. requires the application of direct and proportionate consequences to hold individuals to account when issues emerge and are not properly addressed. ” — APRA Information Paper “Self-assessments of Governance, accountability and culture”, 22 May 2019
Key insight: Consequence management is not punishment. It’s evidence that accountability operates when standards are missed.
Consequence management is the process a Licensee uses to respond when conduct, supervision, systems or controls fall short of expected standards.
It’s not limited to discipline. It includes remediation, retraining, closer supervision, remuneration consequences, role changes, escalation, termination, reporting and governance review. The purpose is not to punish every error. The purpose is to ensure that failures are addressed fairly, consistently, and proportionately, and that the Licensee can evidence its decisions.
For AFSL and ACL holders, consequence management is a practical accountability control. It shows whether the business takes misconduct seriously, whether managers are accountable for issues that occur under their supervision, and whether recurring compliance failures are treated as governance problems rather than isolated mistakes.
Since the introduction of the reportable situations regime, consequence management can no longer be treated as a general cultural aspiration. It is now closely connected to incident assessment, breach investigation, root cause analysis, remediation and regulatory reporting. A Licensee that identifies a significant failure must consider not only whether the issue is reportable, but also what the failure says about supervision, accountability and the effectiveness of its controls.
Consequence Management
“And .. what it also found … is that there was a lack of [Consequence Management] policy application by the business where advisers admitted to or were found to be non-compliant or breached the Westpac code of conduct? Yes.” — Mr Hodge’s examination of Mr Hartzer, Westpac CEO, Royal Commission transcript, 22 November 2018 P-6847
Consequence management should reflect the nature, scale and complexity of the Licensee’s business and its risk appetite. A small advice licensee doesn’t need a bank-style disciplinary architecture, but it does need clear triggers, decision rights, escalation pathways, documentation standards and evidence that similar conduct is treated consistently.
APRA’s 2019 work gave the industry a clear formulation of a broader regulatory expectation: consequence management should be consistently applied and should impose direct and proportionate consequences for misconduct and improperly managed compliance failures.
In this respect, a licensee’s consequence management policy is a critical component of your organisational culture; it embeds accountability and promotes an unambiguous statement of individuals’ responsibility. If it’s also consistently applied, it will significantly reduce both the incidence and impact of non-compliance.
Start with your risk appetite and build a conceptual framework to explain when you’ll take remedial actions – fixing the problem – and when you’ll take administrative actions – addressing the conduct and the cause.
Review your remuneration framework at the same time and eliminate any inconsistencies you identify.
Clearly define your expectations and remember that the responses you propose for failures need not be mutually exclusive.
The appropriate consequence will depend on the nature of the failure, the client impact, the conduct involved and whether the issue is isolated, recurring or systemic. The table below provides a practical guide, but each decision should be assessed on its facts and supported by evidence.
| Failure identified | Primary response type | Remedial response | Consequence response | Escalation / governance consideration |
|---|---|---|---|---|
| Poor advice file | Remedial | Correct advice, repair the file, remediate the client if required | Coaching, increased supervision, higher audit frequency | Consider whether the issue is isolated or part of an adviser quality trend |
| Repeated recordkeeping failure | Remedial and administrative | Reconstruct evidence, improve workflow, clarify file note standards | Performance warning, role restriction, mandatory training | Consider whether poor records affect the Licensee’s ability to evidence services, advice or supervision |
| Systemic process failure | Governance and remedial | Redesign process, uplift controls, review affected clients | Manager accountability, revised delegations, governance reporting | Consider breach assessment, client impact, root cause analysis and board or committee reporting |
| Misconduct or dishonesty | Administrative / disciplinary | Protect clients, stop further harm, assess affected files, consider remediation | Suspension, termination, removal of authority, ASIC reference check consequences | Consider reportable situation obligations, ASIC notification, AFCA exposure and client communications |
| Poor supervision | Governance and administrative | Review affected representatives, files and clients; correct supervision process | RM or manager accountability, revised delegations, supervision uplift | Consider whether governance reporting, RM review, or broader control redesign is required |
| Client loss, damage or inconvenience | Restorative remedial | Apologise, refund fees or commissions, compensate, correct the client position | Coaching, warning or other action depending on cause | Consider whether the harm is isolated, recurring, systemic or reportable |
| Recurring or systemic compliance failure | Governance / disciplinary | Investigate root cause, review impacted clients, redesign controls | Management accountability, formal remediation plan, possible disciplinary action | Consider breach reporting, board reporting, external review and regulatory engagement |
In an advice business, you might conceive of your framework to look like this:

It’s disappointing that few of the entities surveyed by APRA have an effective way to identify and consistently respond to incidents, breaches, and contraventions.
ASIC’s Report 800 reinforces the practical importance of consequence management. Reportable situations are not only disclosure events. They are indicators of whether a Licensee can identify issues, investigate them, understand their cause, assess client impact and take appropriate corrective action. Consequence management should therefore be considered as part of the post-incident response, not after the governance process has finished.
To be clear, consequence management is not a complete solution; monitoring, supervision and remediation are equally, if not more, important. Consequence management is, however, an effective and efficient way to both manage regulatory risk and maintain a good corporate ‘culture’. Properly applied, it may also help you better manage your reputation and your resources.
Where an incident may be reportable, consequence management should not sit outside the breach process. The breach assessment should identify what happened, who was involved, whether the conduct was isolated or systemic, what controls failed, whether clients were affected, and whether the Licensee’s response should include supervision, training, remuneration, role or disciplinary consequences.
What should Licensees do?
A Licensee should be able to show that its consequence management framework:
- identifies the trigger for review;
- distinguishes remediation from accountability;
- assesses seriousness, intent, recurrence and client impact;
- considers supervision and management responsibility;
- links to breach reporting, complaints and remediation processes;
- defines who can make each decision;
- records the reasons for the outcome;
- tests whether similar cases are treated consistently; and
- reports material themes to Responsible Managers, the board or compliance committee.
Management’s role
“Is there proper accountability as demonstrated by discipline for managers under whose watch misconduct occurred? Is the application of discipline consistent? Is there an incentive program for good compliance and ethical behavior? Can the company point to specific examples of actions taken (promotions or awards denied) as a result of compliance and ethics considerations?” — U.S. Department of Justice, Criminal Division, Fraud Section “Evaluation of Corporate Compliance Programs”
Consequence management is not only about the framework for responding to incidents – consequences must be clear, cascaded and enforced. APRA did not find this to be the case. Instead, consequences were found to be inconsistently applied throughout the businesses. The business’ willingness to insist on accountability varied depending on the seniority, role or influence of the offending party.
This is the core of APRA’s call for Licensees to enhance their consequence management framework.
While APRA found that senior executives had clarity about their roles and responsibilities, the clarity they had was not shared by those at lower levels. If you are in any management role, it is incumbent on you to gain clarity about your role and responsibilities and communicate these (and the Licensee’s expectations) in a manner that ensures that understanding and accountability cascade throughout the business.
It’s easy to see Consequence Management as a compliance obligation, but it’s a key indicator of corporate culture; it improves your retention and recruitment of ethical staff, enhances your reputation and brand and ensures your business’ alignment with community expectations.
It’s also a practical point of focus given ASIC’s continuing emphasis on breach reporting, consumer harm, governance failures and the adequacy of licensee supervision.
Consequence management fails when it only moves downward. If the only person ever held accountable is the adviser, broker, paraplanner or administrator closest to the incident, the framework is incomplete. Licensees should ask what the manager knew, what they should have known, what supervision was in place, whether warning signs were ignored, and whether business settings contributed to the failure.
Why does Consequence Management matter?
Consequence management matters because regulators do not assess culture by what a policy says. They assess it by what happens when something goes wrong.
A Licensee that repeatedly identifies advice defects, supervision failures, missed service obligations, complaints, fee issues or poor recordkeeping but does not take proportionate action is sending a clear signal. The signal is that compliance obligations are negotiable. That is dangerous.
A sound consequence management framework helps the Licensee show that:
- the issue was identified;
- the cause was investigated;
- the client impact was addressed;
- the representative, manager or business unit response was considered;
- the action taken was fair and proportionate;
- similar cases were treated consistently; and
- governance bodies received enough information to challenge management.
Why does this matter now?
The 2019 APRA and Royal Commission material remains relevant, but the regulatory environment has moved on. Consequence management now sits much closer to breach governance, reportable situations, remediation, operational risk and accountable management.
ASIC’s reportable situations regime requires AFS and credit licensees to identify, investigate and report certain significant breaches, long-running investigations, gross negligence, serious fraud and other prescribed conduct. RG 78 provides the current regulatory guidance for those breach reporting obligations.
ASIC’s Report 800 reinforces the practical point. Reportable situations are not merely disclosure events. They test whether a Licensee can identify issues, investigate them, assess client impact, understand root cause, remediate harm and take corrective action.
APRA’s CPS 230 and the Financial Accountability Regime point in the same direction, even where they do not apply directly to every Licensee. APRA-regulated entities must identify, assess and manage operational risks with effective internal controls, monitoring and remediation. That is a useful benchmark for all Licensees thinking about control failure, escalation and accountability.
The real test
Consequence management is not about finding someone to blame. It is about proving that accountability exists when standards are missed.
For Licensees, the issue is not whether a policy mentions culture, conduct or consequences. The issue is whether the business responds to failures in a way that is fair, proportionate, consistent and evidenced. When an adviser makes the same error repeatedly, when a manager ignores warning signs, when a control fails, or when a client is harmed, the Licensee should be able to show what happened, why it happened, who was accountable, what was fixed and what changed.
That matters because weak consequence management sends a dangerous message. It tells people that obligations are optional, that escalation is avoidable and that poor conduct can be absorbed as a cost of doing business. Strong consequence management sends the opposite message. It reinforces standards, protects clients, supports managers and gives directors confidence that problems are not merely being recorded, but addressed.
The best frameworks are not punitive. They are disciplined. They distinguish honest mistakes from misconduct, isolated errors from systemic failures, individual conduct from management responsibility, and remediation from accountability. They also leave a clear evidence trail.
Ultimately, consequence management is one of the clearest tests of a Licensee’s governance maturity. Not because it shows what the business says it values, but because it shows what the business is prepared to do when those values are tested.
Need to test whether your consequence management framework would stand up to ASIC scrutiny? Assured Support can review your incident, breach, supervision and accountability processes and help you build a practical framework that is fair, proportionate and evidence-based.
Book a 15-minute call with a compliance specialist.
Further reading
Frequently Asked Questions
Consequence management is the structured process a Licensee uses to decide what should happen after conduct, supervision, systems, or controls fail.
It’s not limited to punishment or disciplinary action. It includes the full range of responses a Licensee may need to take to address the issue, protect clients, correct the underlying cause and reinforce expected standards. That may include client remediation, file correction, retraining, closer supervision, changes to delegations, remuneration consequences, formal warnings, role changes, termination, breach reporting, or escalation to the board.
The key point is proportionality. Not every mistake requires disciplinary action. Equally, repeated failures, ignored warnings, client detriment, dishonesty, poor supervision or systemic control weaknesses should not be treated as minor administrative issues. A good consequence management framework helps the Licensee apply judgement consistently and provide evidence why a particular response was fair, reasonable and appropriate.
For AFSL and ACL holders, consequence management is part of the compliance infrastructure. It shows whether the business merely identifies issues or acts on them.
Unsure how this applies to you? Get a clear answer in a 15-minute call with a compliance specialist. Book your call.
No. Disciplinary action is only one possible consequence.
Consequence management is broader. It asks what response is required to address the issue, prevent recurrence and reinforce accountability. In some cases, the appropriate response may be coaching, retraining, process improvement or increased supervision. In others, it may require a formal warning, removal of authority, remuneration consequences, termination or regulatory reporting.
This distinction matters because Licensees can make two opposite mistakes. The first is treating every failure as misconduct, which creates fear, defensiveness and under-reporting. The second is treating serious or repeated failures as training issues, which weakens accountability and increases regulatory risk.
A mature framework separates remedial action from accountability action. Remediation fixes the client or control impact. Consequence management determines what should happen to the person, manager, business unit, or governance process associated with the failure.
Unsure how this applies to you? Get a clear answer in a 15-minute call with a compliance specialist. Book your call.
Consequence management matters because regulators assess culture and governance by how things go when something goes wrong.
Policies, training records, and committee minutes are useful, but they do not prove accountability on their own. The real test is whether the Licensee identifies failures, investigates causes, considers client impact, escalates appropriately, applies proportionate consequences and records the basis for its decisions.
For AFSL and ACL holders, this connects directly to supervision, breach management, complaints, remediation and governance reporting. If a Licensee repeatedly identifies poor advice, weak recordkeeping, missed service obligations, complaint themes or control failures but takes no meaningful action, the issue is no longer just the original failure. It becomes evidence of weak governance.
Consequence management also protects fairness. It helps ensure that similar issues are treated consistently, that senior people are not insulated from accountability, and that frontline staff are not blamed for failures caused by poor systems, unrealistic workloads, or inadequate supervision.
Unsure how this applies to you? Get a clear answer in a 15-minute call with a compliance specialist. Book your call.
Managers should not be automatically blamed for every failure by advisers or staff. Individual accountability still matters.
However, management accountability must be considered where the failure was foreseeable, repeated, ignored, poorly supervised or caused by weak business settings. A Licensee should ask what the manager knew, what they should have known, what controls were in place, whether warning signs were escalated, and whether the manager had the authority and resources needed to prevent or address the issue.
This is particularly important where the immediate failure lies with an adviser, broker, paraplanner, or administrator, but the root cause lies higher up in the business. For example, poor file quality may reflect individual carelessness. It may also reflect inadequate training, unrealistic turnaround times, weak review processes, poor technology, unclear accountability or a revenue model that rewards speed over quality.
A sound framework, therefore, looks both down and up. It considers the individual’s conduct, the supervisor’s role, the adequacy of the control environment, and whether senior management created or tolerated the conditions that enabled the failure.
Unsure how this applies to you? Get a clear answer in a 15-minute call with a compliance specialist. Book your call.
A consequence management framework should explain how the Licensee identifies, assesses, escalates, decides, records and monitors consequences when failures occur.
At a minimum, it should include clear triggers for review. These might include serious misconduct, repeated advice defects, breach events, substantiated complaints, missed remediation commitments, failure to follow policy, poor supervision, control breakdowns or conduct that creates client detriment.
It should also define decision rights. The framework should make clear who can decide coaching, supervision changes, warnings, remuneration consequences, suspension, termination, breach escalation and board reporting. This reduces the risk of inconsistent, informal or personality-driven decisions.
The framework should include proportionality criteria. Relevant factors include seriousness, client impact, intent, recurrence, prior warnings, cooperation, seniority, control failure, supervision failure, systemic risk and regulatory reporting implications.
Finally, the framework must require evidence. Each decision should record the issue, facts considered, root cause, people involved, options assessed, decision made, reasons, action owner, due date and governance forum notified. Without that evidence, the Licensee may struggle to show that accountability was applied fairly, consistently and effectively.
Unsure how this applies to you? Get a clear answer in a 15-minute call with a compliance specialist. Book your call.
Consequence management should be considered as part of the breach assessment and post-incident response. The Licensee should identify what happened, who was involved, whether clients were affected, whether the issue was isolated or systemic, which controls failed, and whether the response should include remediation, training, supervision, role changes, disciplinary action, or regulatory reporting.
The key point is that breach reporting and consequence management should not operate as separate processes. Breach reporting determines whether and how the matter must be reported. Consequence management determines which accountability measures and corrective actions are required.
Unsure how this applies to you? Get a clear answer in a 15-minute call with a compliance specialist. Book your call.