“When you’re down and troubled
And you need some love and care
And nothing, nothing is going right
Close your eyes and think of me”
— Either asic.gov.au or Carole King (“You’ve got a friend”)
Recently, Sean Graham, our Managing Director, and Victoria Whitty, Easton’s Head of Advice Governance, co-presented a webinar addressing the new breach regime for a select group of Licensee representatives.
Focusing on the commercial and operational requirements, the presentation stepped though the regulatory requirements to provide a practical roadmap for managing change.
They addressed Treasury’s draft regulations and answered practical questions for businesses apprehensive about the changes and their potential impact.
Although we’ll address some of the key questions in this article, we’d recommend that you enrol in future webinars to really benefit from the expertise and insight of the presenters.
“We want to reward good performers with nudges, not grudges. We want to train ASIC’s radar on harmful misconduct, not on harm-free process breaches.”
— ASIC Deputy Chair Karen Chester “Regulation for recovery: when pilots become enduring practice.” ASIC Deputy Chair Karen Chester, AFR Business Summit 10 March 2021.
I’ve been told that I have to report every compliance issue to ASIC. Is that true?
No. As we discussed previously, the new breach regime introduces a ‘deemed significant’ test to provide certainty to regulated participants and ensure they promptly report breaches to ASIC. Under the new breach regime, a contravention of a core 912A or 912B obligation will be deemed to be significant if it involves:
- the commission of an offence punishable by a sentence of 12 months or more;
- a contravention of a civil penalty;
- misleading or deceptive conduct in relation to financial products or services; or
- a contravention that is likely to result in material loss or damage to a retail client.
This all seems reasonable, until you consider whether your representatives’ have the knowledge to identify contraventions that are offences involving dishonesty or punishable by a custodial sentence of 12 months or more.
Incidents or breaches that fall within these parameters need to be reported to ASIC, but that doesn’t mean that every incident, infringement or contravention is reportable.
If the contravention isn’t ‘deemed significant’ and automatically notified to ASIC, then the Licensee needs to consider the following elements to determine whether ASIC need to be notified:
- the number and/or frequency of similar breaches;
- the impact of the breach or likely breach on the licensee’s ability to provide financial services covered by the licence;
- the extent to which the breach or likely breach indicates that the licensee’s arrangements to ensure compliance with those obligations are inadequate; and
- any other matters prescribed by regulations.
So, critical failures and anticipated failures of core obligations will need to be reported to ASIC in the prescribed timeframes, but unless it’s otherwise deemed by you to be significant, it’s simply recorded and managed in accordance with your Incident Management Policy.
So, although contraventions of non-core obligation may, depending on context, be significant and reportable they will not need to be reported unless you determine that they are otherwise significant in accordance with s912D(5)
The … Association seems worked up about the civil penalty provisions. What are they?
The civil penalty regime covers a wider range of provisions in financial services laws, including:
- the general obligations of Australian financial services licensees;
- the obligation to lodge breach reports with ASIC;
- the disclosure requirements in Chapter 7;
- the general obligations of credit licensees;
- the duty to act in utmost good faith and provide a key facts sheet; and
- other provisions of the Corporations Act and Credit Act.
One of the consequences of the Hayne Royal Commission, was Parliament’s concerted effort to reconcile the penalty provisions for a range of laws and introduce a more consistent, expanded and stronger penalty regime.
There’s been a lot of focus on the need for harsher criminal sanctions and more significant civil penalties to provide credible deterrents to prevent misconduct including:
- increased penalties for criminal offences;
- Increased pecuniary penalties for criminal offences;
- Increased civil penalties for infringements and contraventions; and
- Broadening the scope of the civil penalty regime.
If we set aside custodial sentences, administrative orders and pecuniary penalties, you’ll see a significant increase in the financial consequences for the misconduct of individuals and corporate entities.
We covered these changes in a previous article, but it’s important to recognise that the maximum civil penalties under the Corporations Act have both increased and been extended beyond those listed in Schedule 3.
TIP: This suggests that investing in the competency and capability of your compliance team should be one of your immediate priorities.
How do I know what the Civil Penalty provisions are?
Before we begin, we’re not in a position to provide you with a comprehensive list covering all of the financial services laws but buckle up, because the range of relevant civil penalty provisions is expansive. For Advisers, the civil penalty provisions under the Corporations Act alone include (but are not limited to):
- s798H Complying with market integrity rules
- s901E Complying with derivative transaction rules
- s912A General Obligations
- s912D breach reporting
- s922M Offences relating to investigations by a monitoring body
- s941B and C – FSG Provision
- s946A – SoA production (s1317)
- s952E – Giving defective disclosure documents (SoA and FSG)
- s952H – Licensees failure to ensure Authorised Representatives provide disclosure documents.
- s961Q covers the essential advice duties
- s962G Requirement to give an FDS
- s962P Receiving fees after OFA terminated
- s962S – FDS provision
- s962S Deducting fees without consent,
- s962U Failure to process variation or withdrawal of consent
- s962V Failure to notify provider of ceased consent
- s963(F-K) Conflicted remuneration
- s963N Rebates on conflicted remuneration
- s963P rebates on conflicted remuneration
- s964A Asset based shelf space
- s964D Charging asset based fees on borrowed amounts
- s964E Authorised Representative charging asset based fees on borrowed amounts
- s965 Anti-avoidance
- s981B Failure to pay money into account
- s981C Account management obligations
- 1012A(5) Obligation to give a Product Disclosure Statement
- 1012B(6) Obligation to give a Product Disclosure Statement related to product issue
- 1012C(11) Obligation to give a Product Disclosure Statement related to sale of products
- 1012E(8) Small scale offerings of managed investments
- s1017BA Obligation to make a superannuation fund dashboard publicly available
- s1017BB Obligation of Superannuation Trustees to make investment asset information available
- s1021E Preparation of defective disclosure documents
- s1021G Failing to give disclosure documents
- s1041A Market manipulation (also an offence)
- s1041B False trading and market rigging (also an offence)
- s1041C Artificially maintaining prices
- s1041D Sharing information about illegal transactions (also an offence)
- s1041E False and misleading statements (also an offence)
- s1041F Inducing persons to deal (also an offence)
- 1041G Dishonest Conduct (also an offence).
- s1041H Misleading and Deceptive Conduct
- s1101AC Obligation to comply with enforceable code provisions.
TIP: There’s clearly a need to immediately invest in the competency and capability of your compliance team.
TIP2: If you want to investigate these penalty provisions further, look at s1311, s1317E and Schedule 3 and the Treasury Laws Amendment (Strengthening Corporate and Financial Sector Penalties) Act 2019 or ask your lawyer for a definitive list of relevant provisions (we haven’t even addressed the ASIC Act, the National Consumer Credit Protection Act or the Insurance Contracts Act.)
Interestingly, it’s the Amendment that significantly increases the penalties. It also defines Part 7.7A civil penalty provisions as:
- s961K(1) and (2) financial services licensee responsible for breach of certain best interests duties;
- s961L financial services licensee to ensure compliance with certain best interests duties;
- s961Q(1) authorised representative responsible for breach of certain best interests duties;
- s962P charging ongoing fee after termination of ongoing fee arrangement;
- s962S(1) fee recipient must give fee disclosure statement;
- s963E(1) and (2) financial services licensee must not accept conflicted remuneration;
- s963F financial services licensee must ensure representatives do not accept conflicted remuneration;
- s963G(1) authorised representative must not accept conflicted remuneration;
- s963J employer must not pay employees conflicted remuneration;
- s963K financial product issuer or seller must not give conflicted remuneration to financial services licensee or representative;
- s964A(1) platform operator must not accept volume-based shelf-space fees;
- s964D(1) and (2) financial services licensee must not charge asset-based fees on borrowed amounts; and
- s965 (anti-avoidance of Part 7.7A provisions).
Is there any Flexibility?
The civil penalty provisions is a long list but, in their Exposure Draft issued 10 March 2021, Treasury have indicated that the following civil penalty provisions “are not taken to be significant if contravened”:
- 941A(3) Obligation of a Licensee to give a FSG to a retail client;
- 941B(4) Obligation of an Authorised Representative to give a FSG to a retail client;
- 1012A(5) Obligation to give a Product Disclosure Statement;
- 1012B(6) Obligation to give a Product Disclosure Statement related to product issue;
- 1012C(11) Obligation to give a Product Disclosure Statement related to sale of products; and
- 1012E(8) Small scale offerings of managed investments.
So although contraventions of these provisions may, depending on context, be significant and reportable they will not necessarily need to be reported unless you determine that they are significant in accordance with s912D(5).
Exposure Draft
What are the Criteria against which Breaches need to be Assessed?
Section 912D provides the specific detail but, broadly, you need to consider:
Frequency. The greater the number or frequency of similar breaches, the more likely the new breach will be significant, as repetitive breaches may indicate a systemic issue.
Effect on the provision of financial services. When the impact of a breach would impair a Licensee from continuing to provide financial services, this would be considered a significant breach. For instance, a breach of the minimum financial requirements of a Licensee’s licence conditions would be considered a significant breach, as this would impair its ability or capacity to continue to provide financial services.
Indication of inadequate controls. Where a breach indicates broad inadequacies in arrangements to ensure compliance, this would be considered a significant breach.
Certain identifying questions to determine whether the breach is significant may include the length of time to discover the breach, and to what extent existing compliance arrangements helped to identify the breach.
Actual or Potential Financial loss to clients. If a breach results in financial losses for clients of the Licensee, this could indicate a significant breach.
How does the Act define “loss or damage”?
The Act doesn’t provide a definition but the Explanatory Memorandum (11.30) states that 11.30 ‘Loss or damage’ in the context of the deemed significance test has its ordinary meaning, which is extensive. The term includes financial and non-financial loss or damage.
Explanatory Memorandum
Won’t ASIC be overwhelmed by these new reporting requirements?
This is the second most commonly expressed fear about the new requirements; the first being that reporting (and ASIC’s publication of breach data) will destroy businesses’ reputations and public confidence in the advice profession.
We’re not convinced that either fear will be realised and we’re reassured that Treasury are taking a practical approach to the changes.
“For example, if ASIC is receiving a large number of largely unproblematic breach reports for minor, technical or inadvertent breaches of civil penalty provisions, and those breaches would not otherwise be significant, the Government may decide that the regulatory burden imposed outweighs the benefit of receiving those reports. ”
— FINANCIAL SECTOR REFORM (HAYNE ROYAL COMMISSION RESPONSE) BILL 2020 CORPORATIONS (FEES) AMENDMENT (HAYNE ROYAL COMMISSION RESPONSE) BILL 2020
What should I do right now?
Although the changes may not require a heightened sense of apprehension, it’s inarguable that if you’re intending to comply with these requirements you have to start now.
Start by mapping the requirements against your current processes, but take the opportunity to consider whether your systems and current compliance resources will be adequate to meet these heightened standards.
If you need help, let us know.