Regulatory Ripples and Cultural Tsunamis

“The reality is that we are seeing stories like [Shield and First Guardian] over and over in our investigations into suspected misconduct in financial services. Stories of shameless sales tactics designed to convince honest and hard-working Australians to transfer their superannuation savings into complex and risky schemes … Stories that end with that nest egg diminished or completely dissipated. Stories that say something needs to change.”

Joe Longo, 30 July 2025


In his address to the Financial Services Council on 30 July 2025, ASIC Chair Joe Longo effectively and emphatically declared that the days of plausible deniability, delegation without oversight, and box-ticking compliance are over. This isn’t posturing. ASIC is broadening its enforcement approach from punishing bad actors to interrogating the cultures that enable them. Commissioner Longo’s message is clear: system-level problems require a whole-of-system response. Gatekeepers must do more than simply comply with regulations; they must lead with integrity and embed compliance into their operations, not just their reporting. 

“You can go your own way, Go your own way”  – Fleetwood Mac


ASIC’s Shift: From Enforcement to Cultural Scrutiny

Every time ASIC delivers a speech, financial services firms scramble. Risk committees convene, compliance sends memos, consultants send “calls to action.” But little changes.

Joe Longo’s recent address at the FSC Summit followed the usual script—naming names, listing failures, and warning of consequences. But underneath the familiar tone is a less comfortable truth: we don’t have a regulation problem. We have a leadership problem.

ASIC’s enforcement posture isn’t about catching bad actors after the fact anymore. It’s about rooting out cultures that let misconduct take hold in the first place. It’s about expecting more of gatekeepers and recognising our collective interest in maintaining trust in Australia’s superannuation system.

we have to raise the standards for gatekeepers. ..The vast majority of people … rely heavily on professionals in this system to manage their money well. Yet for those people caught up in the Shield and First Guardian matters, this system did not serve them well at all.

— Joe Longo, 30 July 2025

That’s not a shot across the bow. That’s a change in engagement rules. 

In our view, Longo’s recognition of “a system-level problem” that requires raised standards and a “whole of system response” signals a shift from reactive enforcement to pre-emptive cultural and structural scrutiny. By admitting that “regulation isn’t [ASIC’s] first response, or the only answer”, Longo is telling the industry to stop waiting for regulation before taking obligations and duties seriously.

But here’s the challenge no one likes to acknowledge: most firms don’t know what “seriously” actually looks like.

The reality is that most licensees don’t have the time, money, inclination, courage or headcount to turn their whole compliance model around.

So, let’s get real.


Compliance Is Now a Culture Test

“It appears to us that we need higher standards for the key gatekeepers in the system – the research houses, financial advisers, super trustees and responsible entities”

— Joe Longo, 30 July 2025

Firms still treat culture as HR’s domain and compliance as legal’s problem. But ASIC’s message is clear: poor culture is a compliance risk. Ignorance or inertia isn’t a defence. Nor is good intent.

Most licensees are small, stretched, and led by practitioners wearing multiple hats. When ASIC says raise standards, many hear: “spend more, hire more, stress more.”

But that’s not the ask.

ASIC may have “doubled the number of new financial advice-related investigations“, but this shouldn’t concern a competent Licensee. ASIC isn’t looking for gold-plated policies and procedures. They’re looking for evidence that compliance is real.

That it shapes decisions.

That it guides incentives.

That it’s part of how you work, not just something you outsource once a year.


Compliance Doesn’t Have to Be Expensive. But It Does Have to Be Intentional. 

You don’t need a Deloitte budget to show ASIC you’re serious. Smart, resource-conscious firms are doing more with less by making compliance intentional, not ornamental:

  • Reframed Compliance Reviews: They’ve ditched the once-a-year audit for shorter, focused file reviews more regularly — using unconflicted service providers guided with structured checklists and broad industry exposure. Early detection, quicker responses and more credible insights.
  • Reusing the Right Tools: They use connected tools – like [complye] – for broader oversight and sharper insights. The same platform for ASIC obligations, risk reduction, APL Management and remediation. One source of truth to support multiple outcomes. This saves money and tells a clearer story when ASIC knocks.
  • Tying Culture to KPIs: Staff incentives aren’t just revenue-based. They include compliance performance—like advice quality scores, training completion, and client file health. That’s culture alignment without extra cost.
  • Reflect rather than react. Instead of opinion shopping and catastrophising, they engage trusted sources and act with deliberation — operationalising requirements properly, consistently, and with clear expectations.

These aren’t heroic actions. But they’re credible. And ASIC is watching.


From Ticking Boxes to Proving Intent

ASIC has signalled that it’s “doing a range of work over the next year to further uplift standards across the industry” and “taking enforcement action … to hold people to account”. This should be enough to prompt Licensees to review their current compliance arrangements. The cut-price “half-arsed” audit you grudgingly paid for each year might have been enough five years ago. It isn’t now. 

ASIC’s new posture demands that obligations are met and that compliance frameworks are real, not rhetorical.

If you’re still responding to ASIC’s public statements like it’s 2017, you’ve missed the signal.

Hear Longo’s remarks about gatekeeper failures and inadequate standards and apply them more broadly. In my mind, ASIC’s comments about gatekeeper failures and bad actors are equally applicable to advisers and licensees who justify questionable practices as “within the rules.” Those that present “personal advice” disguised as “general advice” or treat unsophisticated, retail clients as “wholesale clients” because they own their home. And those who justify conflicted recommendations based on “client preferences.” 

Read the room. Relying on a lack of enforcement as proof of adequacy is a dangerous game. Legal doesn’t mean ethical. And ASIC’s tolerance for self-interested interpretations, passivity and “management ignorance” is gone.

“We didn’t know” is not a defence. It’s an admission.


The Real Risk Isn’t ASIC. It’s Irrelevance.

Too many firms still think compliance is about staying off ASIC’s radar. That mindset is dangerous and lazy. The real threat isn’t getting caught. It’s losing the trust of your clients. It’s falling behind the expectations of regulators, peers, and the public. As Commissioner Longo has stated, “just because you aren’t the bad actor, that doesn’t mean the behaviour of bad actors won’t impact you“. 

Licensees need to rethink their strategies for sustainability in this new world. Building Trust is the goal. Culture is the framework. Compliance is the evidence.

Longo’s speech makes it clear: ASIC’s enforcement will be thorough, deliberate,  and increasingly data-driven. That’s not a threat. That’s a promise of greater efficiency and increased accountability.

So the days of box-ticking audits and well-intentioned amateurism are over.

If your compliance is still ad-hoc, paper-based, inflexible, or “off-the-shelf,” you’re not just exposed—you’re irrelevant.


Don’t Wait for ASIC to Define “Enough”

If you’re thinking of waiting for a new ASIC regulatory guide to tell you how to be a better gatekeeper, or to define what “good” looks like, you’re behind.

Longo’s speech signals a shift. The future of compliance isn’t about ticking every box. It’s about proving—on your own terms — that you’re actively “doing the right thing”, that your systems are fit for purpose, your culture supports good outcomes, and your governance isn’t theatre. 

Most compliance consultants look backwards, but we’ve never been conventional.

Rather than waiting for the next ASIC crackdown—or clumsily reacting to it— our clients have embedded real compliance into their operations:

  • Dynamic Frameworks: Instead of Word documents and a PDF library, they’ve embraced adaptive systems that evolve with regulatory expectations. Build living systems, not static policies
  • Real-Time Oversight: They don’t wait for annual audits but engage experts and use tools that provide live insights into representative conduct, product suitability, and advice file quality. Embrace ongoing review of conduct, not annual box-ticking.
  • Cultural Integration: They don’t pretend that the “tone from the top” is anywhere near enough. They consult, reiterate expectations and model conduct. They build compliance into KPIs, incentives, training, and governance. They recognise that compliance is about culture, not just reporting. Say and Do. 
  • Conflict avoidant. No business is entirely without conflicts (or perceived conflicts), but these businesses have read the writing on the wall and stripped out, or actively mitigated, conflicted arrangements. They avoid conflicts instead of relying on disclosure. They anticipated that ASIC would endorse and operationalise Charlie Munger’s famous observation: ‘Show me the incentives and I’ll show you the outcome.’ 
  • Digital Support: They use regulatory technology, like [complye], that supports, not replaces, human judgment. They respect expertise as much as efficiency. 

ASIC is watching AI adoption closely, and so should you.


You are your own arch-enemy.

ASIC isn’t out to kill advice or punish ambition. It’s doing what a regulator should do, insisting on trust, fairness, and integrity in a system that too often forgets them.

If you’re still treating ASIC as an adversary and compliance as an obstacle, you’re playing the wrong game.

We have doubled the number of new financial advice-related investigations commenced since last year, and almost doubled the number of new investment management investigations.

Compliance isn’t your enemy. ASIC isn’t your enemy. Ambiguity is. Inaction is. Conservatism is. Complacency is.

So stop waiting for the next speech to wake up. The better play? Make compliance your differentiator. Make culture your asset. Lead, don’t react.

The question to answer isn’t “Will we comply?” — it’s “Am I ready to lead?”

You can go your own way. Just don’t wait for ASIC to hand you the map.

For expert guidance, contact Assured Support today.

If you enjoyed this, we recommend that you read:

ASIC Enforcement Trends: What You Need To Know For 2025

Why Compliance Isn’t Enough: Reconciling Law With Ethical Principles And ASIC’s Expectations

Reportable Situations (Part 1): ASIC’s Findings And Why They Matter


Frequently Asked Questions

1. What key change has ASIC Chair Joe Longo signalled for financial services compliance?

Joe Longo has emphasised shifting ASIC’s enforcement from reactive punishment of bad actors to proactive scrutiny of organisational cultures, expecting integrity and genuine compliance integration into business operations.

2. Why is compliance now considered a ‘culture test’ by ASIC?

ASIC recognises poor organisational culture as a root cause of compliance failures. Firms must demonstrate compliance as integral to their culture rather than isolated to legal or HR departments.

3. How can financial advisers practically embed compliance without significant cost increases?

Firms can use frequent, focused compliance reviews, integrated compliance tools, culture-linked KPIs, and real-time oversight technologies to embed compliance effectively without significantly increasing budgets.

4. What are the practical risks for firms continuing traditional box-ticking compliance methods?

Firms relying on traditional, superficial compliance methods risk regulatory action, reputational damage, client trust loss, and eventual irrelevance in an evolving regulatory landscape focused on proactive cultural scrutiny.

5. How should financial services firms respond to ASIC’s shift towards cultural scrutiny?

Firms should proactively adopt dynamic compliance frameworks, integrate compliance into their operational culture, actively mitigate conflicts, and use technology to ensure continuous oversight, thereby making compliance a competitive differentiator.

Keep exploring

Regulatory Ripples and Cultural Tsunamis

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?