Once more unto the breach (register), dear friends, once more

Once more unto the breach (register), dear friends, once more

Once more unto the breach (register), dear friends, once more

“Once more unto the breach, dear friends, once more” — William Shakespeare, Henry V, Act III, Scene I


Editor’s Note (2026)

This article was originally published in July 2018 during the Hayne Royal Commission. Since then, Australia’s breach reporting framework has changed substantially.

AFSL holders are now subject to the “reportable situations” regime introduced under the Financial Sector Reform (Hayne Royal Commission Response) Act 2020. The framework now includes mandatory investigation reporting, expanded deemed significant breaches, and revised reporting timeframes.

While the governance principles discussed in this article remain relevant, readers should interpret references to “significant breaches” and “10 business day reporting obligations” in their historical context.


How are compliance breaches identified, managed and reported?

Only time will tell whether the Hayne Royal Commission is all “sound and fury, signifying nothing“. At this point in time, the institutional licensees seem to be lurching between threatened litigation and PR disasters, while the smaller licensees (and many others) incredulously wonder how mandatory compliance requirements can be observed so flexibly (if observed at all) at the big end of town. 

Screenshot 2018-07-02 22.12.21.png

Our clients, in particular, question whether any other Licensee would be permitted to retain their AFSL if they handled breach reporting in the same way.

Despite the admissions made at the Royal Commission, ASIC value breach reporting and see it as “an important part of the regulatory framework”. ASIC like to be notified but they don’t take action on all matters reported to them. Instead, they consider the information in the breach report and use it to inform their decision about whether it is necessary or appropriate to take  further action. 

REMINDER: At the time this article was originally published, Licensees were generally required to notify ASIC in writing of any “significant” breach (or likely breach) of their licence conditions or compensation arrangements or the financial services laws, as soon as practicable, and in any event within 10 business days of becoming aware of the breach or likely breach.

Since October 2021, AFSL holders have instead been subject to the “reportable situations” regime under the Corporations Act. Licensees must generally lodge reportable situations with ASIC within 30 calendar days after first knowing, or being reckless with respect to whether, there are reasonable grounds to believe a reportable situation has arisen.

breach notification form


Timeliness

“Ms Orr also invited Commissioner Hayne to find that the Commonwealth Bank of Australia had breached its financial licence provisions, the Corporations Act by not reporting its fees for no service issues to ASIC for two years. The law requires all licence holders to report significant breaches to the regulator in 10 days.”

— Sarah Danckert, Sydney Morning Herald 27 April 2018

ASIC RG78
ASIC RG78

Even if these failures recede into the background in light of more dramatic contraventions, it has sparked a renewed focus on Incident Management and Breach reporting. 


What is Incident Management?

Let’s start with the basics.

If you’re a Licensee, or a representative of a Licensee, you probably understand the importance of recognising (and remediating) your contraventions of the laws, standards, policies or practices. Whether a contravention is an Incident or a Breach is a matter of legal judgment but, practically, the more profound the impact of the contravention, the more likely it’s a breach. It’s best not to leap to that conclusion at the outset though because formally recognising an incident as a breach has some important consequences. 

Licensees have statutory obligations to promptly report significant or repeated failures (breaches) to ASIC as soon as they become aware of them.

Unfortunately, not all Licensees deal with Incidents and Breaches in the same way.

In reality, problems will occur in any large, complex and diverse business. The Regulators understand this. They expect that incidents will occur and they expect, reasonably enough, that Licensees will identify and adequately manage them; not only to prevent their recurrence but also to use the experience to improve their business and the services they offer to their clients.

From a commercial perspective, the accurate identification and analysis of incidents provides you with a useful gauge of your performance and the effectiveness of your controls.

From a governance perspective, one of the most effective indicators of a Licensee’s ‘compliance culture’ is not the way they respond to incidents, but the way they proactively identify them. Competent Licensees can react to identified failures; Capable licensees search for them and ensure that their staff understand that everyone in their business is responsible for identifying and reporting incidents. (How they reward staff that identify and report incidents highlights their real values). 


Not all incidents are breaches

If you consider that an Incident is any failure of your internal controls, it’s easy to imagine that some failures are going to be more significant than others.

Isolated or one-off errors (that are quickly remediated) are less of a problem for your business than significant or recurring issues. These latter types of incidents or failures are commonly considered to be Breaches. 

Logically, not all failures are the same. In fact, the context, consequence and impact of the failures is critically important for determining your required response. 

It should not surprise any competent Licensee to learn that ASIC expect you to adequately respond to identified breaches (ASIC 15-003MR). 

What ‘failures of internal controls’ that amount to breaches is contextual in that it depends on the significance of the failure and it’s impact on your business and your clients.

This is clearly an over-simplification, but it’s reasonable that size of your business and the number of your clients will influence your assessment of whether the incident is a breach.

Incidents (and potential breaches) include, but aren’t limited to:

  • Failure(s) to produce Statements of Advice or provide Financial Services Guides;
  • A contravention of an applicable law, regulatory requirements, or a licence condition;
  • Charging clients for services that aren’t provided; 
  • An inability to meet, or continue to meet a licence condition;
  • Misrepresentation of a products benefits or features;
  • A breakdown of a key control, system or process;
  • Signing a document on behalf of your client (without legal authority); 
  • A recurring event, or combination of events, that considered together indicate a systemic internal control failure;
  • A breach of contractual arrangements (including client agreements, outsourced service providers, mandates, guidelines);
  • Failures of your Internal Dispute Resolution processes; 
  • Failure to notify ASIC of significant breaches; and
  • Representative misconduct such as breaches of their Best Interest Duty.

Identifying a ‘significant’ breach

“I shall not today attempt further to define the kinds of material I understand to be embraced… [b]ut I know it when I see it …””

— Justice Potter Stewart, 1964

In some respects, anyone asked to define ‘significance’ is forced to either admit that “it depends” or else mirror Justice Stewart’s legal definition of pornography and assert that they’ll recognise it when they see it.

As unsatisfying as this response may be, it’s less an equivocation than a recognition that ‘significance’ is a subjective and contextual determination. 

Consequence and regularity are important factors for you to consider. We’d add that when you’re assessing significance you should also explicitly consider:

  • Frequency or similarity. As a general rule, the larger the number of similar failures, the more likely the new failure will be significant. Appreciate that frequent or as repetitive failures suggest systemic issues.
  • The impact of the breach on your organisational competence. If the failure impairs, or is likely to impair, your capacity to provide financial services, it’s likely to be a significant breach. For example, your failure to meet your financial requirements indicates an in ability to continue to provide financial services.
  • The adequacy of your controls. A failure to effectively monitor and supervise your representatives, for example, would generally be considered a significant breach because it indicates the inadequacy of your compliance arrangements. The fact that CBA took two-years to determine whether their Fee-for-Service issues were significant, should have been enough to indicate they were – the length of time it takes to discover and resolve breaches highlights the effectiveness of the Licensee’s compliance arrangements.
  • The actual or potential financial loss to clients. If a breach results in financial losses for clients of the Licensee, this could indicate a significant breach. The larger the losses (either individually or in aggregate) the more likely the incident is a significant breach.

What Changed After the Hayne Reforms?

When this article was originally published in 2018, the financial services industry was still reacting to the evidence emerging from the Hayne Royal Commission. At that time, breach reporting obligations were primarily framed around whether a Licensee had identified a “significant breach” and whether it had been reported to ASIC within the required timeframe.

Since then, the legal and regulatory landscape has changed substantially.

The Financial Sector Reform (Hayne Royal Commission Response) Act 2020 fundamentally expanded Australia’s breach reporting framework and introduced what is now commonly referred to as the “reportable situations regime”. While many of the governance principles discussed throughout this article remain relevant, the operational and regulatory expectations imposed on AFSL holders are now materially more prescriptive.

From “Significant Breaches” to “Reportable Situations”

The modern framework is broader than the historical breach reporting regime.

Today, Licensees are no longer merely assessing whether a contravention is “significant” in the ordinary sense. Instead, the Corporations Act now identifies a range of circumstances that automatically become reportable situations, including certain civil penalty breaches, misleading conduct offences, serious fraud and conduct involving gross negligence.

Importantly, the regime also captures likely contraventions, systemic issues and failures that may indicate deficiencies within a Licensee’s supervision, monitoring or compliance arrangements.

This shift reflects a broader regulatory expectation that Licensees proactively identify emerging risk patterns rather than waiting for harm to crystallise before escalating concerns.

Mandatory Investigation Reporting

One of the most significant post-Hayne reforms was the introduction of mandatory investigation reporting obligations.

Under the current regime, a Licensee may be required to report not only confirmed breaches, but also investigations into potential reportable situations where those investigations continue for more than 30 days.

This change has had profound operational consequences for Licensees.

Historically, some organisations treated breach investigations as relatively informal compliance exercises. That is no longer realistic. The duration, governance, escalation and documentation of investigations are now themselves subject to regulatory scrutiny.

As a result, competent Licensees increasingly maintain:

  • formal incident triage frameworks;
  • documented breach assessment criteria;
  • investigation governance protocols;
  • escalation committees;
  • root cause analysis procedures; and
  • remediation tracking systems.

In practice, the quality of a Licensee’s investigation framework may now be as important as the underlying incident itself.

“Reasonable Grounds to Believe”

The current regime also places significant emphasis on when a Licensee first had “reasonable grounds to believe” a reportable situation had arisen.

This creates important governance implications.

A Licensee’s reporting obligations are no longer determined solely by when a final conclusion is reached. Regulators will increasingly examine:

  • when the incident was first identified;
  • how quickly it was escalated internally;
  • whether warning signs were ignored;
  • whether investigations progressed appropriately; and
  • whether contemporaneous records support the Licensee’s decision-making.

Poor documentation, delayed escalation or inadequate supervision may themselves become indicators of broader compliance failure.

ASIC’s Expectations Have Changed

ASIC’s expectations regarding breach governance and operational resilience are materially higher than they were before the Hayne Royal Commission.

The regulator now expects Licensees to demonstrate that they can:

  • identify incidents promptly;
  • assess reportability consistently;
  • investigate issues competently;
  • remediate affected clients effectively;
  • identify systemic causes;
  • strengthen internal controls; and
  • maintain clear evidence supporting their decisions.

Importantly, ASIC increasingly treats weak breach governance as evidence of broader organisational incompetence rather than isolated procedural failure.

Delayed escalation, recurring control failures, poor supervision frameworks and inadequate remediation processes may all indicate deeper governance deficiencies within the business.

Modern Examples of Reportable Situations

While traditional advice failures remain relevant, contemporary reportable situations increasingly arise from issues such as:

  • fee consent and ongoing fee arrangement failures;
  • Design and Distribution Obligations (DDO) breaches;
  • cyber incidents and operational resilience failures;
  • misleading marketing or disclosure practices;
  • AML/CTF compliance failures;
  • record-keeping deficiencies;
  • inappropriate superannuation switching strategies;
  • systemic advice process deficiencies;
  • remediation calculation errors; and
  • failures in monitoring outsourced service providers.

These examples reinforce an important point: modern breach reporting is no longer confined to adviser misconduct alone. Increasingly, it reflects the effectiveness of a Licensee’s entire governance, risk and operational framework.

The Central Principle Remains Unchanged

Despite the legislative reforms and increased regulatory scrutiny, the central governance principle discussed throughout this article remains remarkably consistent.

Regulators do not expect perfection.

They do, however, increasingly expect evidence that Licensees:

  • identify problems early;
  • escalate them appropriately;
  • investigate them competently;
  • remediate them effectively; and
  • learn from them systematically.

In 2026, the quality of a Licensee’s incident management and breach governance framework is no longer merely a compliance issue. It is increasingly treated as evidence of organisational competence, operational resilience and leadership effectiveness.

download rg78 Breach Reporting

If you liked this article, you may like:

Forget ‘Culture’. Let’s talk about consequences

Money for nothing (and the tricks are fees)

Trust, culture and enforcement


Frequently Asked Questions

What is a “reportable situation” under the current AFSL regime?

A reportable situation is a matter that an AFSL holder may be legally required to report to ASIC under the Corporations Act. This includes certain significant breaches, likely breaches, investigations that continue beyond prescribed timeframes, and conduct involving serious fraud, gross negligence or particular civil penalty provisions.

The regime extends beyond traditional “significant breaches” and focuses heavily on whether a Licensee’s systems, supervision and governance arrangements are functioning effectively.

How long does a Licensee have to report a reportable situation to ASIC?

Under the current regime, AFSL holders generally have 30 calendar days to lodge a report with ASIC after first knowing, or being reckless with respect to whether, there are reasonable grounds to believe a reportable situation has arisen.

This replaced the historical “10 business day significant breach” reporting framework discussed during the Hayne Royal Commission period.

Does every compliance incident need to be reported to ASIC?

No.

Not every incident or control failure will be reportable. However, all incidents should generally be assessed through a documented incident management framework to determine:
– whether the issue is systemic;
– whether clients suffered loss or detriment;
– whether the issue reflects inadequate supervision or controls; and
– whether the matter meets the statutory threshold for reportability.

Repeated minor incidents may collectively become reportable if they indicate broader control weaknesses.

What happens if a Licensee delays investigating or escalating an incident?

Delays can create significant regulatory risk.

ASIC increasingly examines:
– when the issue was first identified;
– how quickly it was escalated internally;
– whether investigations were appropriately managed; and
– whether the Licensee maintained adequate records supporting its decisions.

Poor escalation practices, weak documentation or prolonged investigations may themselves become indicators of governance failure.

Why is breach governance now considered a leadership issue rather than just a compliance issue?

Modern breach governance reflects far more than technical compliance.

ASIC increasingly treats a Licensee’s incident management framework as evidence of organisational competence, operational resilience and leadership effectiveness. The way an organisation identifies, escalates, investigates and remediates issues provides regulators with insight into the quality of its governance culture, supervision arrangements and risk management capability.

Strong breach governance is now considered a core component of sustainable financial services operations rather than merely an administrative obligation.

Keep exploring

Once more unto the breach (register), dear friends, once more

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?