“These are not endorsements, but are provided as examples of culture, system design, and leadership choices that show how firms can move beyond compliance.” – AFCA, Systemic Issues Insights Report, Edition 8, p. 3.
AFCA’s latest Systemic Issues Insights Report reinforces the clear message that documented frameworks are not enough. Across banking, insurance, advice and superannuation, AFCA found that systemic issues often arose where firms had policies, procedures and governance frameworks in place. Those frameworks simply didn’t operate effectively in practice.
For licensees, the practical challenge isn’t simply understanding AFCA’s markers of excellence. It is embedding them into everyday operations: monitoring, escalation, complaint handling, breach assessment, remediation and governance reporting.
That is where Assured Support’s progressive focus on compliance infrastructure, operationalised by [complye], demonstrates expertise and relevance. We help firms interpret regulatory expectations, assess operational gaps and design practical compliance frameworks. [complye] then provides the operational infrastructure to record, monitor, evidence and report on those frameworks in practice.
This distinction is operationally significant. AFCA’s report isn’t a software procurement guide. It’s an operational risk and governance report; any credible analysis must practically reconcile regulatory insights and operational requirements to identify the systems and disciplines needed to make those requirements work in practice.
AFCA’s message: frameworks are not enough
“Good consumer outcomes depend on operational systems capable of identifying emerging issues early and supporting timely intervention before consumer detriment expands.”- AFCA, Systemic Issues Insights Report, Edition 8, p. 6
A recurring theme in AFCA’s report is that systemic issues often emerge even where formal policies and procedures exist. Generally, the problem was not a failure to recognise obligations, but a failure to operationalise and monitor them effectively.
Instead of negligence or intent, the operational controls, monitoring mechanisms, or escalation pathways simply didn’t work as intended.
That’s an important distinction. A policy may describe the right outcome, but a firm still needs systems that test whether that outcome is being delivered consistently and the capacity to tell if the system is working as intended. A complaints framework may reflect ASIC Regulatory Guide 271, but it still needs monitoring to identify ageing complaints, poor-quality responses, and recurring themes. A breach framework may exist, but it still needs a reliable pathway for incidents to be assessed, escalated, remediated and reported where required.
AFCA’s markers of excellence should be interpreted as operational expectations rather than aspirational goals. They point to the practical machinery firms need to convert documented obligations into consistent outcomes.
For boards and accountable persons, the key governance question is no longer whether frameworks exist, but whether management can demonstrate they are operating effectively through reliable evidence and oversight.
What the markers of excellence require in practice
“Quality assurance, exception reporting and thematic reviews can assist firms to identify where operational practices may diverge from documented intent.” – AFCA, Systemic Issues Insights Report, Edition 8, p. 9.
AFCA has articulated expectations that Licensees demonstrate clear operational controls, monitoring frameworks, thematic reviews, escalation pathways and management reporting. They also emphasise complaint trend analysis, governance oversight, transparent remediation, third-party oversight, operational change assurance and better embedding of vulnerability considerations across customer touchpoints.
Taken together, these expectations require licensees to be able to answer practical questions:
- Are obligations reflected in operational workflows, not just policy documents?
- Can the firm identify when actual outcomes differ from policy intent?
- Are complaints analysed as indicators of broader operational risk?
- Are incidents assessed consistently for breaches, remediation, and systemic-issue implications?
- Can management and boards see where processes are deteriorating?
- Are remediation actions tracked through to completion?
- Is there evidence that the framework is operating in practice?
The reality is that these questions are practically impossible to answer honestly when compliance information is dispersed across spreadsheets, inboxes, meeting papers, file notes, and disconnected registers.
The operational gap for licensees
“The systemic issue arose because execution was inconsistent, controls were weak or frontline practices diverged from documented intent.” – AFCA, Systemic Issues Insights Report, Edition 8, p. 9.
The gap for many licensees isn’t awareness. Most firms understand their broad compliance obligations. The hard task is operationalisation. The harder task is embedding compliance into operational culture and accountability.
Operationalisation means translating obligations into repeatable processes, assigning ownership, monitoring performance, identifying exceptions, escalating issues and retaining evidence. It also means ensuring that compliance does not depend on informal knowledge held by a single person or team.
This is where systemic risk can emerge. If complaints are handled individually without thematic review, recurring issues may be missed. If incidents are recorded inconsistently, breach assessments may be delayed or incomplete. If remediation actions are not tracked centrally, firms may struggle to demonstrate that corrective action was completed. If management reporting focuses on the existence of policies rather than the performance of controls, issues may only become visible after consumer harm has already occurred.
AFCA’s report reinforces that operational evidence is now central to compliance credibility.
This operational gap becomes particularly evident during complaint escalations, breach investigations, remediation reviews, and AFCA dispute resolution processes, where the quality of evidence is often tested retrospectively.
How We help firms assess and uplift their frameworks
“Effective governance depends on active oversight of how policies operate in practice.” – AFCA, Systemic Issues Insights Report, Edition 8, p. 9
Assured Support’s role is to help licensees interpret regulatory expectations and convert them into practical compliance arrangements. That includes assessing whether governance, monitoring, complaint handling, breach management and remediation frameworks are operating effectively, not merely whether they exist.
This involves looking at the design of the framework, the quality of implementation, the evidence available to support decisions and the visibility provided to management and boards. It also involves identifying where firms need clearer controls, better escalation pathways, stronger monitoring, more reliable reporting or improved records of decision-making.
In this context, the value of advice isn’t limited to explaining what the rules require. It is helping licensees build an operating model that can withstand scrutiny when something goes wrong.
How [complye] supports operational execution and evidence
“Several systemic issues investigations this period involved issues arising from system configuration logic, automated processing pathways, platform capacity constraints or operational processes performed by third-party administrators.” – AFCA, Systemic Issues Insights Report, Edition 8, p. 7.
[complye] supports the operational side of this model. It provides a structured environment for governance records, monitoring programs, incidents, breach assessments, remediation actions, attestations, regulatory change and reporting.
This helps licensees move away from fragmented compliance administration and toward a more consistent, evidence-based model. Obligations can be linked to controls. Monitoring activity can be recorded. Incidents can be assessed. Remediation can be assigned and tracked. Governance reporting can be supported by structured records rather than being reconstructed after the event.
That doesn’t mean that [complye] replaces executive accountability, business judgment or sound operational discipline. Nor does it replace primary business systems such as claims platforms, advice production systems, loan administration platforms or customer relationship management tools. Its value lies in demonstrating the compliance infrastructure that links those components: the oversight, monitoring, escalation, evidence, and reporting layer.
AFCA markers and operational requirements
“Markers of excellence” include “clear operational controls,” “monitoring frameworks,” “regular thematic reviews,” “escalation pathways”, and “management reporting.” – AFCA, Systemic Issues Insights Report, Edition 8, p. 9
Before looking at individual markers of excellence, boards and senior executives should recognise what AFCA’s report signals more broadly. The report reflects a growing expectation that firms be able to demonstrate not only that governance frameworks exist, but also that those frameworks operate effectively in practice and produce consistent customer outcomes.
That shifts the focus of compliance oversight. Increasingly, accountability turns on whether firms can identify emerging issues early, monitor operational performance, escalate concerns consistently, and evidence the actions taken in response. Complaint trends, remediation delays, breach assessment quality and operational monitoring are no longer peripheral compliance activities; they are becoming central indicators of governance effectiveness.
For many licensees, this creates a practical challenge. Policies and procedures may be well-documented, but operational evidence is often fragmented across spreadsheets, inboxes, meeting papers, and disconnected systems. When issues arise, firms can struggle to demonstrate how decisions were made, whether escalation thresholds were applied consistently, and whether remediation actions were completed and appropriately monitored.
“Complaints frequently provide the first indication of broader operational issues.” – AFCA, Systemic Issues Insights Report, Edition 8, p. 11.
The comparison below illustrates how AFCA’s markers of excellence translate into practical operational expectations and how compliance infrastructure such as [complye] can help firms strengthen the governance, monitoring, and evidence frameworks needed to support them in practice.
| AFCA marker of excellence | Operational requirement for firms | Our position | Alignment |
| Clear operational controls that support consistent implementation of policies across teams and customer cohorts | Firms need controls that translate policies into repeatable workflows and consistent staff practices. | Assured Support can help design or uplift the control framework. [complye] supports structured workflows, registers, monitoring programs, incident records and remediation tracking. | Strong alignment |
| Monitoring frameworks capable of identifying deviations between policy intent and operational outcomes | Firms need monitoring that tests whether documented processes are producing intended outcomes. | Assured Support can help define monitoring scope, frequency and review methodology. [complye] supports monitoring programs, review records, issue capture and reporting. | Strong alignment |
| Regular thematic reviews of consumer outcomes to test whether frameworks are functioning as intended | Firms need to identify patterns across complaints, incidents, reviews and remediation activity. | Assured Support can help interpret themes and identify systemic risk indicators. [complye] can centralise relevant data for thematic review. | Strong alignment, dependent on configuration |
| Escalation pathways that enable emerging issues to be identified and addressed early | Firms need clear thresholds and accountability for escalation. | Assured Support can help define escalation criteria. [complye] supports structured issue management, breach assessment, action assignment and governance reporting. | Strong alignment |
| Management reporting that identifies where processes are not operating as intended | Boards and senior managers need visibility of operational performance, not just policy existence. | Assured Support can help determine what reporting is meaningful. [complye] supports structured compliance records and reporting for oversight forums. | Strong alignment |
| Complaint management frameworks aligned with ASIC Regulatory Guide 271 | Firms need complaint workflows that support timeliness, quality, escalation and accurate records. | Assured Support can assess RG 271 alignment and complaint process design. [complye] can support complaint handling workflows, visibility and reporting where configured to do so. | Strong alignment in principle |
| Systems capable of monitoring complaint ageing and identifying potential timeframe breaches early | Firms need visibility of open complaints, ageing matters and potential breaches. | Assured Support can help design complaint ageing controls and reporting. [complye] can support workflow visibility and reporting, with effectiveness dependent on configuration. | Partial to strong alignment |
| Thematic analysis of complaints to identify emerging operational issues and systemic risks | Complaint data must be analysed as a source of operational insight. | Assured Support can help identify themes, root causes and systemic issue implications. [complye] can support categorisation, review and escalation of complaint-related issues. | Partial to strong alignment |
| Transparent remediation frameworks that explain the issue and corrective steps taken | Firms need to record the issue, affected cohort, decision-making, actions and completion evidence. | Assured Support can help design remediation methodology and governance. [complye] supports remediation tracking, investigation records, breach lifecycle management and follow-up actions. | Strong alignment |
| Governance oversight of outsourced providers and administrator systems | Firms remain accountable for outsourced outcomes and need visibility of third-party performance risks. | Assured Support can help assess oversight frameworks and accountability arrangements. [complye] can support registers, obligations, incidents, actions and reporting relating to outsourced providers. | Partial alignment |
| Governance over structured workflows and automated assessment tools | Firms need oversight of automated or pathway-driven processes, including escalation and review. | Assured Support can help assess governance, assurance and review expectations. [complye] can evidence governance activities, incidents, reviews and remediation relating to automated workflows. | Partial alignment |
| Operational systems that identify vulnerability indicators and support consistent handling across customer touchpoints | Firms need vulnerability considerations embedded in operational processes, not just policies or training. | Assured Support can help assess vulnerability frameworks and escalation pathways. [complye] can support policies, controls, training records, incidents and actions, but customer-level vulnerability workflow functionality depends on configuration and integration. | Development opportunity |
| Post-implementation monitoring and review following system migrations or operational change | Firms need change governance, testing, post-implementation review and evidence of operational impacts. | Assured Support can help design assurance and review programs. [complye] can document change governance, incidents, remediation and assurance activity. | Partial alignment |
| Evidence that frameworks operate in practice, not just that policies exist | Firms need defensible records showing monitoring, escalation, decisions and remediation. | Assured Support helps determine what evidence should exist. [complye] helps maintain structured records that show oversight and action in practice. | Strong alignment |
From documented compliance to operationally evidenced compliance
“The effectiveness of consumer protection frameworks increasingly depends on how operational systems, oversight mechanisms and responses to vulnerability function in practice.” AFCA, Systemic Issues Insights Report, Edition 8, p. 7.
AFCA’s markers of excellence point toward a more mature model of compliance. The emphasis is no longer on the mere existence of policies, committees, registers, or procedures. The emphasis is on whether those arrangements work when tested against real customer outcomes.
That requires firms to maintain clear operational controls, reliable monitoring, timely escalation, meaningful reporting and defensible evidence. It also requires management and boards to understand whether the compliance framework is operating as intended.
Assured Support helps firms interpret those expectations and build practical frameworks for implementation. [complye] already supports the operational execution of those frameworks by providing a structured environment to record, monitor, evidence and report on compliance activity.
The result is a stronger compliance operating model: one that moves beyond documented compliance and toward operationally evidenced compliance.
Where evidence, escalation tracking and governance reporting are fragmented, [complye] can help centralise compliance records, monitoring activities and remediation oversight.
The following articles expand on the operational themes discussed above, including data-enabled supervision, complaint and incident signals, outsourcing accountability, compliance reporting and the practical deployment of [complye]
How does ASIC’s Interprac case show that manual compliance is broken?
From Samples to Signals: A Smarter Approach to AFSL Surveillance
Deploying [complye]: A Practical Framework For Successful Adoption
Frequently Asked Questions
AFCA’s markers of excellence describe the operational practices, governance behaviours and oversight mechanisms that help firms identify, escalate and remediate issues before they result in widespread customer harm or systemic failures. They are intended to reflect what effective complaint handling, monitoring, and governance look like in practice across financial services businesses.
Importantly, the markers are not limited to whether policies or frameworks exist on paper. AFCA’s report repeatedly reinforces the need for firms to demonstrate that controls operate effectively in day-to-day operations, that issues are identified early, and that management has meaningful visibility into emerging risks and customer outcomes.
Regulators, AFCA, and governance stakeholders increasingly expect firms to demonstrate not only that compliance frameworks exist but also that those frameworks are functioning effectively in practice. This means firms need reliable evidence showing how monitoring occurs, how incidents are escalated, how remediation decisions are made and how customer outcomes are assessed over time.
Operational evidence becomes particularly important when firms face complaints, breach investigations, remediation reviews or regulatory scrutiny. In many cases, the credibility of a compliance framework is assessed retrospectively through records, governance reporting, monitoring activities, and evidence of decision-making. Where documentation is fragmented or inconsistent, firms may struggle to demonstrate that obligations were managed effectively, even where policies were technically in place.
Firms can assess the effectiveness of compliance frameworks by examining whether operational controls consistently produce the intended outcomes in practice. This includes reviewing complaint trends, monitoring results, breach assessments, remediation activities, incident escalation pathways, and governance reporting to determine whether issues are being detected and addressed appropriately.
Effective frameworks should also provide visibility into recurring operational weaknesses, ageing issues, incomplete remediation actions and areas where customer outcomes differ from policy intent. Importantly, management and boards should be able to see not just whether policies exist, but whether monitoring, oversight and escalation mechanisms are actively functioning and supported by defensible operational evidence.
ASIC Regulatory Guide 271 establishes the minimum requirements for internal dispute resolution and complaint handling within Australian financial services businesses. It outlines expectations regarding complaint timeliness, fairness, accessibility, escalation processes, and written responses provided to customers.
AFCA’s report reinforces and extends the practical importance of those obligations by highlighting the operational behaviours firms should adopt to support effective complaint management. This includes monitoring complaint ageing, identifying recurring themes, conducting thematic analysis and ensuring complaints are treated as indicators of potential systemic risk rather than isolated customer interactions. Together, RG 271 and AFCA’s findings point toward a stronger expectation for active governance oversight of complaint frameworks.
Fragmented compliance records can create significant operational and governance risks by reducing visibility, weakening accountability, and making it harder for firms to consistently identify emerging issues. When incidents, complaints, remediation actions and governance records are dispersed across spreadsheets, inboxes, meeting papers and disconnected systems, firms may struggle to maintain a complete and reliable view of compliance activity.
This fragmentation can delay escalation, create inconsistent breach assessments, weaken evidence retention and make remediation tracking more difficult. It also limits the ability of management and boards to identify patterns across complaints, incidents or operational failures. In practice, this can result in issues only becoming visible after customer harm has occurred or after a matter has already escalated to AFCA or regulatory scrutiny.