“A licensee must report breaches committed by the licensee and by its representatives, as this term is defined in the Corporations Act and the National Credit Act”
— Robert Ludlum, “The Bland Clarification” (or RG78.33)
Learn more about Breach Reporting. Talk to our compliance experts today.
Welcome to the new breach reporting regime
September had all the thrills and escalating tension of a Ludlum thriller but, instead of dramatic resolution, delivered an ambiguous and unsatisfying denouement. ASIC’s facilitative approach to the October reforms is greatly appreciated, but most AFSLs may have preferred earlier clarification to deferred enforcement.
In any event, 5 October 2021 saw the commencement of a new breach reporting regime; a reconsecration of what earlier inquiries dubbed the cornerstone of financial services regulation.
We’ve no doubt you’re across the new requirements but, as a refresher, our compliance experts will address four common questions:
The Grand Design

What are an AFSL’s core obligations?
If you are an Australian Financial Services Licensee, your “core obligations” are listed under s912A of the Corporations Act, and include obligations to:
• do all things necessary to ensure that the financial services covered by your licence are provided efficiently, honestly and fairly;
- have in place adequate arrangements for the management of conflicts of interest;
- comply with the conditions of your licence;
- take reasonable steps to ensure that your representatives comply with the financial services laws;
- if you are the operator of an Australian passport fund, or a person with responsibilities in relation to an Australian passport fund, comply with the law of each host economy for the fund;
- comply with the ASIC reference checking and information sharing protocol;
- have adequate resources to provide the financial services covered by your licence and to carry out supervisory arrangements (unless you are a body regulated by APRA);
- be competent to provide the financial services;
- have trained and competent representatives;
- have a dispute resolution system for retail clients (that complies with ASIC Standards and requirements and includes AFCA membership);
- have adequate risk management systems (unless you are a body regulated by APRA);
- have compensation arrangements in accordance with s912B; and
- comply with any other obligations prescribed by Corporations Regulations, including the requirement to cooperate with AFCA.
What are Reportable Situations?
An AFSL is required to notify ASIC if there are reasonable grounds to believe that a “reportable situation” has occurred or is likely to occur.
A “reportable situation” includes circumstances where:
- the licensee or a representative has breached a “core obligation” (one or more of the licensee obligations under s912A and 912B) and the breach is significant;
- the licensee or a representative is no longer able to comply with a core obligation and the breach, if it occurs, will be significant;
- the licensee’s investigation into a reportable situation continues past 30 days;
- the licensee or a representative has engaged in conduct constituting gross negligence; and
- the licensee or a representative has committed a serious fraud.
This is a clear and clearly defined list, so you’re probably wondering what the fuss is about? Well, stay with me, and I’ll show you why October brought joy to lawyers and IT Professionals while depressing everyone else.
The challenge lies in the fact that “reportable situations” are like regulatory Matryoshka Dolls, containing a multitude of complications. For example, “breaches or likely breaches of core obligations” include:
- investigations that take more than 30 days;
- Deemed significant breaches; and
- Other breaches that are significant.
“Deemed significant breaches” include, inter alia, breaches that constitute the commission of an offence punishable by a penalty that may include imprisonment, breaches of a civil penalty provision, breaches that contravene s1041H(1) of the Corporations Act or s12DA(1) of the Australian Securities and Investments Commission Act 2001 (ASIC Act) (misleading or deceptive conduct) and breaches that result, or are likely to result, in material loss or damage.
Understanding what the civil penalty provisions are, and which breaches will be deemed significant, is where the complexity emerges.

How has ASIC’s interpretation evolved since commencement?
While the legislative framework has remained largely unchanged, ASIC’s expectations regarding how licensees operationalise breach reporting have evolved significantly.
In particular, ASIC now places far less reliance on subjective or qualitative assessments of “significance”. Licensees are expected to apply structured, repeatable decision frameworks that can be evidenced and consistently applied across the business. Informal or undocumented reasoning is unlikely to withstand regulatory scrutiny.
There is also a heightened focus on timeliness. The 30-day investigation trigger is no longer treated as a soft threshold. ASIC expects licensees to have systems and workflows in place that actively monitor investigation timeframes, escalate delays, and ensure reporting obligations are met without deferral.
Finally, ASIC expects a more mature approach to root cause analysis and remediation. It is no longer sufficient to identify and report a breach in isolation. Licensees are expected to:
- identify underlying systemic issues;
- assess whether similar conduct has occurred elsewhere in the business; and
- implement and track remediation actions to completion.
In practice, this means breach reporting is no longer a discrete compliance activity. It is a core component of a licensee’s risk management framework and must be supported by appropriate systems, governance, and oversight.
What are the ‘civil penalty provisions’?
Under the Corporations Act, the civil penalty provisions include, but are not limited to, contraventions of s798H (Complying with market integrity rules), s901E (Complying with derivative transaction rules), s912A (General Obligations), s912D (Breach reporting), s922M (Offences relating to investigations by a monitoring body), s941A (Obligation on AFSL to provide a retail client with FSG) s941B (FSG Provision by Authorised Representative), s946A (SoA provision), s952E (Giving defective Disclosure Documents (SoA and FSG)), s952H (Failing to ensure Authorised Representatives give disclosure documents), s961Q (the essential advice duties including s961B (Best Interests Duty), s961G (Appropriateness) 961H (Warning about incomplete/inaccurate information) and s961J (Client priority)), s962G (Requirement to give an FDS), s962P (charging fees after OFA terminated), s962S (Deducting fees without consent), s962U (Failure to process variation or withdrawal of consent), s962V (Failure to notify provider of ceased consent), s963F to 963K (Conflicted remuneration), s963N (Rebates on conflicted remuneration), s964A (Asset based shelf space), s964D (Asset based fees on borrowed amounts), s964E (Authorised Representative charging asset based fees on borrowed amounts), s965 (Anti-avoidance), s981B (Failure to pay money into account), s981C (Account management obligations), s1012A and s1012B and s1012C (Obligation to provide a PDS), s1017BA (Obligation to make a superannuation fund dashboard publicly available), s1017BB (Obligation of Superannuation Trustees to make investment asset information available), s1021E (Prepare a defective disclosure document), s1021G (Licensee failure to ensure Authorised Representatives provide disclosure documents), s1041A (Market manipulation), s1041B (False trading), s1041C (Market rigging), s1041D (Dissemination of information about illegal transactions), s1041E (False and misleading statements), s1041F (Inducing persons to deal), s1041G (Dishonest Conduct), s1041H (Misleading and Deceptive Conduct) and s1101AC (Obligation to comply with enforceable code provisions). For completeness, it also includes contraventions of s12DA (Misleading and Deceptive Conduct – ASIC Act).
For completeness, please appreciate that civil penalty provisions are also included in the Australian National Registry of Emissions Units Act 2011, Banking Act 1959, Carbon Credits (Carbon Farming Initiative) Act 2011, Financial Sector (Collection of Data) Act 2001, Financial Sector (Shareholdings) Act 1998, Financial Sector (Transfer and Restructure) Act 1999, Insurance Acquisitions and Takeovers Act 1991, Insurance Act 1973, Insurance Contracts Act 1984, Life Insurance Act 1995, Retirement Savings Accounts Act 1997, Superannuation Industry (Supervision) Act 1993, and the Superannuation (Resolution of Complaints) Act 1993.
How are civil penalty provisions applied in practice?
While the list of civil penalty provisions is extensive, the practical challenge for licensees is not identifying the provisions themselves, but mapping real-world conduct to those provisions in a consistent and defensible way.
In practice, many reportable situations arise from advice-related breaches, particularly those involving the “essential advice duties” under s961B (best interests duty), s961G (appropriateness), s961H (warnings) and s961J (client priority). Where these obligations are not met, the breach will often enliven civil penalty provisions under s961K, s961L or s961Q, depending on whether the failure sits with the adviser or the licensee.
Importantly, these breaches are frequently identified through file reviews, audit findings, or complaints rather than deliberate misconduct. As a result, licensees must ensure that their review and monitoring programs are calibrated not only to detect errors, but to assess whether those errors constitute contraventions of civil penalty provisions.
This requires a structured approach to breach classification, including:
- clear mapping between common failure types and relevant legislative provisions;
- consistent documentation of the reasoning applied; and
- escalation protocols where uncertainty exists.
Without this structure, there is a heightened risk of under-reporting or inconsistent reporting outcomes across similar scenarios.
What are the relevant ‘civil penalty provisions’?
“While ASIC had published draft guidance on the regime, Anderson said it was incredibly complex and that it would be difficult for small licensees to understand what was reportable and what was not reportable.”
— “Clarity needed on civil penalty exemptions for breach reporting”, Money Management, 21 June 2021
Thankfully, the regulations modified this list to remove some penalties that are “not taken to be significant if contravened”.
In effect, these regulations create a smaller subset of reportable civil penalty provisions that includes, but is not limited to, contraventions of:
- s961K (financial services licensees responsible for breaches of the essential advice duties including s961B (Best Interests Duty), s961G (Appropriateness), 961H (Warning about incomplete/inaccurate information) and s961J (Client priority)),
- s961L (licensee to ensure compliance with s961B, s961G, s961H and s961J)
- s961Q (the authorised representative is required to comply with the essential advice duties including s961B, s961G, s961H and s961J),
- s962P (charging fees after OFA terminated),
- s963F to 963K (Conflicted remuneration),
- s963N (Rebates on conflicted remuneration),
- s964A (Platform provider must not accept asset based shelf space),
- s964D (Licensees must not charge asset based fees on borrowed amounts),
- s964E (Authorised Representative must not charge asset based fees on borrowed amounts),
- s965 (Anti-avoidance),
- s1041H (Misleading and Deceptive Conduct) and
- s12DA (Misleading and Deceptive Conduct – ASIC Act).
In effect, certain minor, technical, or administrative breaches are not automatically presumed to be significant. However, this should not be interpreted as a safe harbour.
In practice, ASIC expects licensees to assess these breaches in their full context. Factors such as frequency, volume, duration, client impact, and the presence of systemic issues may elevate an otherwise minor breach into a significant and reportable one.
For example, repeated failures to provide disclosure documents, deficiencies in record keeping, or process-driven errors may indicate broader control weaknesses. Where this is the case, the issue is unlikely to be viewed in isolation and may instead be characterised as a systemic failure to comply with core obligations.
Accordingly, licensees should avoid treating “technical” breaches as inherently low risk. The appropriate focus is on whether the conduct reflects an isolated error or a breakdown in systems, controls, or supervision. It is this distinction that will ultimately determine whether a matter is reportable.
Complexity abounds and context is King.
It’s important to consider these contraventions broadly. For example, if the audit report identifies that an adviser breached the ‘best interest duty’ then that failure could be a contravention of a civil penalty provision under s961K, s961L or 961Q depending on the circumstances.
A practical decision framework: Is this reportable?
When a potential breach is identified, licensees should apply a structured assessment rather than relying on instinct or isolated judgement. The following framework can be used to guide that process:
1. Has a core obligation been breached (or is it likely to be breached)?
Start by mapping the conduct to a specific obligation under s912A or related provisions. If no obligation is engaged, the matter is unlikely to be reportable.
2. Does the conduct involve a civil penalty provision or deemed significance trigger?
If the breach involves a civil penalty provision, misleading or deceptive conduct, gross negligence, or serious fraud, it will generally be reportable regardless of materiality.
3. Is the breach significant in context?
If not automatically deemed significant, assess:
- the number or frequency of similar breaches;
- the impact on clients (actual or potential loss);
- the duration of the conduct; and
- whether the issue indicates a failure of systems, controls, or supervision.
Isolated, low-impact errors may not be significant, but patterns or systemic issues will generally be.
4. Has the investigation exceeded, or is it likely to exceed, 30 days?
If an investigation into a potential reportable situation continues beyond 30 days, this alone becomes a reportable situation.
5. Is there evidence of a broader systemic issue?
Consider whether the issue extends beyond the individual instance. If similar conduct may exist elsewhere in the business, escalation and reporting are more likely to be required.
6. Can the decision be clearly evidenced?
Regardless of outcome, document:
- the obligation considered;
- the reasoning applied; and
- the conclusion reached.
If the rationale cannot be clearly articulated and supported, the decision is unlikely to withstand regulatory scrutiny.
Applying this framework consistently helps ensure that similar matters are treated consistently and reduces the risk of under-reporting or delayed reporting.
Final Thoughts
Breach reporting isn’t difficult because of the rules. It’s difficult because applying them consistently, evidencing decisions, and managing investigations in real time requires the right structure around your business.
That’s where we help.
Our [complye] platform supports your compliance infrastructure by embedding breach-reporting logic directly into your workflows, providing consistency, auditability, and control across every stage of the process. And where complexity goes beyond systems, our Governance and Licensee Support team works alongside you to interpret obligations, pressure-test decisions, and strengthen your overall compliance framework.
If you want to move from reactive compliance to a structured, defensible approach, get in touch and we’ll show you how it works in practice.
If you enjoyed this, we recommend that you read:
How can AFSL holders meet ASIC notification obligations and avoid administrative breaches?
Why do record-keeping failures turn minor advice issues into reportable breaches?
FSC Standard 31 and the Rise of Platform Oversight
Frequently Asked Questions
A reportable situation arises where there are reasonable grounds to believe a significant breach or likely breach of a core obligation has occurred, or where specific triggers apply such as civil penalty breaches, gross negligence, serious fraud, or investigations exceeding 30 days.
No. Only breaches that are significant or deemed significant need to be reported. However, seemingly minor breaches may become reportable when viewed in context, particularly where they are repeated, systemic, or result in client impact.
Significance is assessed based on factors such as frequency, duration, client impact, and whether the issue reflects a failure in systems, controls, or supervision. Some breaches are automatically deemed significant, including those involving civil penalty provisions.
If an investigation into a potential reportable situation continues for more than 30 days, the matter itself becomes reportable, regardless of whether the breach has been conclusively determined.
Licensees should apply a structured and consistent framework to identify, assess, and document breaches. This includes mapping conduct to obligations, assessing significance in context, monitoring investigation timeframes, and maintaining clear records to support all decisions.