Preparing for A Compliance Review Key Considerations

Preparing for A Compliance Review: Key Considerations

Preparing for A Compliance Review Key Considerations

Are you confident that your compliance framework can withstand the scrutiny of a formal review? If not, it’s time to prepare meticulously to minimise regulatory risk and meet your obligations.

 

As a sophisticated and enthusiastic supporter of the arts, I obviously enjoy going to the theatre. I’ve seen some shocking performances, but I’ve never seen a single commercial performance where the director, performers and crew simply turn up and “wing it”.

They certainly don’t invite critics to review their show without knowing what they have to do or anticipating how the audience will react.

They’re professionals; they prepare.

So why don’t Responsible Managers, Executives and advisers properly prepare before they’re reviewed?

Unless they want to bomb, Responsible Managers and Licensee Executives should meticulously prepare for their Compliance Reviews to ensure they minimise their Regulatory Risk and satisfy their Regulatory Obligations

Whether I, an auditor, or ASIC are reviewing your compliance, don’t leave the outcome entirely to chance. She may be crazy, but remember Nancy Pelosi’s eloquent advice: “Organize, don’t agonise.”

It’s great advice from a day-to-day business perspective, but it’s especially true when preparing for compliance reviews.

Professional Planner recently highlighted that ASIC’s regulatory focus is on small licensees. Small licensees (from boutique to mid-size businesses) should prepare for some unwanted regulatory attention, such as a Notice, visit or Review. 

In my view, ASIC and other regulatory bodies generally recognise that compliance reviews are integral to a Licensee’s overall risk management framework. I’ll go further and suggest that whether it’s a compulsory statutory audit, external consultant audit, or internal review, these evaluations help Licensees identify issues, assist in recalibration of their processes, and underpin their continuous improvement. 

External reviews can be incredibly valuable. Effectively preparing for a compliance review can make the difference between a smooth, successful process and costly setbacks. Here’s how AFS and AC licensees can confidently prepare for their next compliance review.

1. Review and Update Compliance Policies and Procedures

Before any compliance review, ensure that your compliance policies and procedures are current. Regulatory requirements evolve, and so should your compliance framework. Regularly updating your compliance policies not only helps to satisfy your regulatory obligations but strengthens your overall compliance risk management. 

Outdated policies can lead to unnecessary complications during the review process. By regularly updating your procedures, you show auditors that you’re actively managing compliance and reduce the need for oversight, intervention or other action. I want to be clear about one thing: it’s great to have policies, but they need to be integrated and accessible to your staff (any effective review will test whether policies are actually understood and followed). 

There’s a series of cases starting with NSG and Financial Circle that clearly demonstrate that a robust compliance framework is essential for meeting regulatory obligations and avoiding costly penalties. Nor are these cases outliers, as the recent actions against FX OpenAU, Lanterne Fund Services and Guildfords Funds Management demonstrate. AFS Licensees (and AC Licensees) are expected to have compliance arrangements that satisfy their regulatory obligations. By learning from such examples, Responsible Managers and Licensees should be motivated to better tailor their compliance strategies to meet evolving regulatory demands.

Key Actions:

  • Schedule regular reviews of all compliance policies.
  • Benchmark your procedures against current industry standards and regulatory requirements.
  • Ensure that policies are clearly communicated to all relevant staff and are readily accessible)
  • Check that your policies are current and approved.
  • Sign up for our regulatory updates that use real-world examples to provide invaluable insights.

The fact that you haven’t seen a media release about [REDACTED] demonstrates how proactive policy updating and regular internal audits can prevent regulatory penalties. 

2. Conduct Internal Audits Before the Review

Imagine stepping onto a stage, the spotlight glaring, with no script, no rehearsal, and no idea what comes next. Sounds like a recipe for disaster, right? Yet, this is exactly what some Responsible Managers and Licensee Executives do when they face a compliance review unprepared. 

Just as no director would invite critics to a show without meticulous preparation, no financial services professional should approach a compliance review without a solid plan in place.

Let me reiterate. Don’t invite critics to the first dress rehearsal; prepare and prepare well. One of the most effective ways to prepare for an external compliance review is to conduct thorough internal compliance audits in advance. Compliance audits are essential for identifying gaps in your compliance framework and ensuring that your compliance risk is well-managed before the formal review. In simple terms, internal audits allow you to assess your compliance standing, identify gaps or weaknesses, and address them before the external reviewers identify them as red flags during the formal review.

This happens more frequently than you might imagine, but for obvious reasons, I won’t cite any specific example here. Suffice it to say that it’s the best way of identifying problems your team can’t or won’t identify. Depending on your timetable, you may not be able to resolve these problems, but it at least equips you to acknowledge them and explain your planned response. Don’t get caught flat-footed. 

Key Actions:

  • Perform internal audits on key compliance areas such as financial advice, client disclosures, and risk management.
  • Use audit findings to strengthen your compliance framework, making necessary updates or improvements.

3. Ensure Proper Documentation and Record-Keeping

We’ve often said that paperwork is a poor substitute for good processes, and that’s true, but effective documentation is still an essential element of a successful compliance review. Both Auditors and Regulators want to see evidence that your compliance arrangements are real and effective. Your records should be comprehensive, well-organized, and easily accessible to satisfy regulatory compliance standards. Proper documentation is a cornerstone of effective compliance risk management and is critical for passing any Regulatory Audits. Don’t underestimate how important this is: Disorganised or incomplete documentation can lead to delays and may raise concerns about your overall compliance culture.

Key Actions:

  • Review all documentation related to your compliance efforts, including training records, client communications, and policy updates.
  • Ensure critical documents, such as licenses, reports, and internal audits, are properly organised and available for review.

4. Educate and Train Your Team

Your team plays a crucial role in maintaining compliance. So, your staff should be familiar with compliance procedures and understand their role in ensuring regulatory adherence. Auditors may ask questions or require staff to demonstrate their knowledge of internal policies, so understanding and regular training are essential. One of my colleagues recounted asking Responsible Managers in a business some pretty basic questions about their compliance arrangements, only to watch those Managers struggle and bumble their way through the interview. These were executives intimately involved in ensuring the licensee’s compliance with the financial services laws. A cynical person might suggest that’s why that business is now neither licensed nor operational.

Key Actions:

  • Provide ongoing training programs for staff on relevant compliance issues.
  • Ensure employees understand key policies and their role in compliance to prepare them for interviews during the review process.

5. Evaluate Risk Management Practices

Risk management is a central focus of most compliance reviews. Auditors want to know that your business is effectively identifying, assessing, and mitigating risks as part of your overall risk management and compliance risk strategy. A robust compliance framework that integrates risk management practices is essential for meeting regulatory obligations. We’ve written extensively about risk management, including a Licensee’s need to embrace risk and the practical benefits of integrating risk and compliance. Your level of familiarity will depend on your specific roles and responsibilities. Still, a Responsible Manager should be able to confidently articulate the business’ approach and identify the key risks they face. Remember that proactively managing risks reduces the likelihood of compliance breaches and demonstrates a culture of compliance within your organisation.

Key Actions:

  • Regularly assess and update your risk management framework to ensure it is aligned with the latest regulatory expectations.
  • Document your risk assessments and mitigation strategies to provide evidence of your proactive risk management efforts and ensure the risk register is current.

With your documentation in order and risk management practices in shape, the next step is to ensure your team is well-prepared for any questions that may arise during the review.

6. Conduct Pre-Review Mock Audits

This may not be an option for all licensees, but larger licensees (or those with underlying issues) should consider the value of dress rehearsals. Although it may consume time and resources, a mock audit is a great way to prepare for a formal compliance review. This practice run can simulate the actual review process and help identify areas where your business may fall short. A mock audit allows your team to become familiar with the review process and allows you to make any necessary adjustments before the actual review. Unfortunately, running your mock audit too close to your actual audit may increase your apprehension, stress and sense of impending doom. I advise scheduling your mock audit 4-6 weeks before opening night. 

Key Actions:

  • Hire external experts to conduct a mock audit or assign internal compliance officers to lead the process.
  • Consider introducing role plays, i.e., questions asked of key management, advisers, and staff at all levels. 
  • Use the findings from the mock audit to fine-tune your procedures and address any gaps before the actual review.

The real value of mock audits is that they can simulate the pressure of a real review, minimising the likelihood of errors during the actual audit process. However, they have no value if your “auditors” are too concerned about their ongoing engagement to effectively probe and challenge you. One benefit of engaging us is that we’ll focus on telling you what you need to know rather than what you want to hear. 

Preparing for a compliance review requires thorough planning, attention to detail, and a proactive approach. By keeping your policy suite current, conducting internal audits, ensuring proper documentation, and maintaining a well-trained team, you’ll be well-positioned to confidently pass your next compliance review.

In my experience, most Licensees are confident that their compliance framework can withstand the scrutiny of a formal review. That’s great, but too often, that confidence is misplaced. I suspect that behind every ASIC Media Release and Enforcement Update was a confident adviser or Licensee who thought they could improvise their way to a standing ovation. 

My advice to you is to prepare, prepare, and prepare for your next compliance review. Misplaced confidence can be costly, especially when it comes to meeting your regulatory obligations. Ensure your compliance framework is robust, your compliance risk is well-managed, and your compliance policies are up-to-date before the curtain rises. If you need help, reach out to us. 

To further support your compliance Strategy, consider engaging a compliance consultancy that not only specialises in regulatory compliance and risk management but has the insights and experience to provide regulatory compliance support to AFSL and ACL businesses. They will not only help you meet your regulatory obligations but also ensure that your compliance framework is aligned with industry best practices and that your Compliance Risk is well-managed.

For more detailed guidance or assistance in preparing for your compliance review, please speak with our team or download our Compliance Review Checklist to ensure you’re fully prepared.

If you liked this, we recommend that you read:

Compliance 101: Reviews and Audits

How Best to Handle Your Review

Compliance 101: Approaches and Principles

The Compliance Audit: Ten “Red Flags” for Reviewers

Surviving “Red October”: A Quick Guide

 


Frequently Asked Questions

1. Why is preparing for a compliance review critical for financial services businesses?
Preparation ensures your compliance framework is robust, policies are current, and risks are managed effectively. Being proactive reduces regulatory risks, minimises potential penalties, and demonstrates a culture of compliance, giving your business a competitive edge during audits or reviews.


2. How can internal audits help in preparing for compliance reviews?
Internal audits identify gaps and weaknesses in your compliance framework before they are flagged during a formal review. They provide an opportunity to address potential issues, update policies, and ensure your team is ready for external scrutiny, ultimately reducing the risk of negative outcomes.


3. What role does proper documentation play in compliance reviews?
Proper documentation serves as evidence of your compliance efforts. Comprehensive, well-organised records demonstrate that your compliance policies are effective, accessible, and followed, reassuring auditors that your business meets regulatory obligations.


4. How can mock audits improve compliance review outcomes?
Mock audits simulate the review process, allowing your team to familiarise themselves with audit expectations and identify areas needing improvement. They reduce stress, improve preparedness, and help fine-tune procedures before the actual review, ensuring a smoother and more successful process.


5. Why is training staff important for compliance reviews?
Well-trained staff play a critical role in demonstrating compliance. Auditors may ask team members to explain policies or their roles in compliance processes. Regular training ensures employees understand their responsibilities and can confidently participate during reviews.

Keep exploring

Preparing for A Compliance Review: Key Considerations

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?