(Regulatory) Fear and advice risk

(Regulatory) Fear and advice risk

“There is considerable fear of non-compliance in the industry, This has resulted in a compliance-driven approach across the industry where the tolerance for regulatory risk is very low.”

— Michelle Levy, Professional Planner, 6 June 2022

“Fear is the mind-killer.
Fear is the little-death that brings total obliteration.
I will face my fear.
I will permit it to pass over me and through me.
And when it has gone past, I will turn the inner eye to see its path.
Where the fear has gone there will be nothing. Only I will remain.”

— Paul Muad’dib CFP, Dune Financial Advisory

The psychology of regulatory fear

“Dread Risk (noun). a low-probability, high-consequence event ”

— Gerd Gigerenzer

In risk management, there’s a concept called ‘dread risk’ that describes low-probability risks whose potential impact is so profound that they routinely cause people to make poor decisions. Gigerenzer highlighted “September 11” as a dread risk; while the immediate risk of copycat events was small, Americans chose driving instead of flying, and this irrational choice led to numbers of road deaths that vastly exceeded the number of September 11 air passenger deaths.

For financial advisers and licensees, ‘regulatory action’ is their dread risk; a mind-killer that leads them to embrace conservatism, passivity, formalism and risk-aversion. 

As a rule, professional and ethical advisers don’t get banned. Competent and honest businesses don’t have their licenses cancelled. In compliance, a small and isolated error seldom leads to a catastrophic outcome. Despite what your Compliance Team may assert, an unsigned FSG receipt, for example, is a trivial issue (if not an entirely insignificant one). A Statement of Advice does not have to have 40+ pages to comply with the law. 

Unfortunately, for a variety of reasons, our dread of regulatory action has blinded us to the reality that, in the absence of systemic issues, recurring failures or egregious misconduct, the likelihood of regulatory intervention is quite low. Even with the heightened level of transparency created by mandatory industry reporting of complaints, breaches and adviser misconduct, the likelihood of regulatory action for competent and ethical participants will still remain moderately-low. Hopefully, Ms Levy’s observation in this respect will be reflected in the findings of the Advice Quality Review she leads. 

Make no mistake, there are consequences – and significant consequences at that – for non-compliance, but it’s only profound and fundamental failures that attract these sanctions. In reality, competent and ethical businesses avoid, or mitigate, these risks by investing in compliance arrangements that focus on substantive concerns – clients, competency, culture and consistency – rather than theoretical risks. Advisers don’t get banned, or licenses cancelled, for trivial reasons. 

Don’t buy into the myth of a “once-off”.

Whether they want to admit it or not, most (but maybe not all) regulatory action is the reasonable (but unreasonably slow) response to intentional ignorance, incompetence, or intentional failures. 

Our data shows that advisers are, as a general rule, getting better.

Despite the increasing compliance burden, they are getting better at reconciling their professional obligations and their commercial interests. Deliberately, and effectively, they’ve subsumed formal legal requirements intent within organic advice processes that focus on engagement, understanding and consent. Licensees, on the other hand, have generally been slower to retreat from legalism. 

I appreciate that many advisers (and licensees) find that it’s a scary environment to operate in, but their anxiety is not because of the regulatory framework but their inability to properly assess their regulatory risk. Licensees that invest in compliance, engage appropriate experts, embrace comparison and avoid the alarmism peddled by conflicted parties, make informed decisions and consequently demonstrate little of their peers’ timidity. Those that see more, and embrace systems, information and appropriate controls have little real cause for concern. There may be seemingly disproportionate penalties for non-compliance, but don’t allow the common tendency to over-estimate the likelihood and impact of regulatory and legal risks to push you from prudence to paralysis.

You can never run a risk-free advice business. But, if you’re taking reasonable steps to comply with the law, getting appropriate advice, regularly testing your arrangements and assumptions, and conducting your business efficiently, honestly and fairly, then you’re probably over-estimating your risk of regulatory sanction. Businesses, and people, that make real and legitimate efforts to comply with the law are seldom the object of ASIC’s general deterrence efforts. They’re never the object of specific deterrence.

Don’t succumb to irrational regulatory fear, regardless of how persuasively it’s peddled. If you’re already focused on avoiding recklessness, misconduct, negligence or fraud, then you’re already effectively managing regulatory risks to your business and your reputation. 


An edited version of this article was first published in Professional Planner on 14 July 2022 as “Don’t buy into the compliance failure myth

Your Call to Action

We can’t assuage all your fears, but we recommend that you move beyond them; dismiss legalistic approaches that don’t explicitly legislative intent and first principles and sideline advice that doesn’t explicitly consider your people, your compliance arrangements and your culture. More critically consider the compliance advice your lawyers, compliance people and advisers provide you. Make your own informed decisions based on your knowledge, your risk appetite and your understanding of the law. 

Engage experts, but don’t automatically substitute their judgment for yours. 

If you’re looking for practical steps to better assess and manage fear, here are five things you should immediately do.

  1. Review your Risk Appetite.
  2. Audit your SoA template. Before assessing the customer experience, differentiate between law, regulatory policy, licensee policy and habit.
  3. Review your framework for clarity and engagement.
  4. Reframe your Compliance Manual. Explain don’t restate.
  5. Engage people that understand your business, compliance arrangements and risk appetite.

Have you subscribed?

Keep exploring

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?