“This presence of an automatic reportable situation has led to a large volume of .. breaches being reported to ASIC that have little or no intelligence value. This reporting involves a cost for licensees with little regulatory benefit” — Explanatory Statement ASIC Corporations and Credit (Amendment) Instrument 2023/589
Rethinking Breach Reporting
On Thursday, 19 October 2023 ASIC announced modifications to the Reportable situations regime (breach reporting) and to Licensees’ obligations.
The key changes made by the Amendment Instrument include the insertion of new significance thresholds in section 7 that make minor amendments of section 912D of the Corporations Act and section 50A of the Credit Act. Section 7 also inserts new subsections 912D(4A) and 912D(4B) of the Corporations Act and subsections 50A(4A) and 50A(4B) of the Credit Act (the new significance thresholds). These new significance thresholds are intended to provide greater clarity and certainty for licensees in determining whether a reportable situation has occurred.
You may be wondering why these changes were made by legislative instrument rather than by primary legislation. It’s because Treasury consider that the subject matter and policy implemented by Instrument are
more appropriate than primary legislation because of the flexibility it provides:
“the instrument provides administrative relief in circumstances where strict compliance with the primary legislation produces anomalous outcomes that are inconsistent with the intent of the primary law.”
Overview
The key changes made by the Amendment Instrument relate to the new significance thresholds that have been inserted into the Corporations Act and Credit Act. These new thresholds modify reportable situations deemed ‘significant’ breaches under paragraphs 912D(4)(b) and 912D(4)(c) of the Corporations Act and paragraph 50A(4)(d) of the Credit Act and false and misleading representations under 1041H(1) of the Corporations Act and subsections 12DA(1) and 12DB(1) of the Australian Securities and Investment Commissions Act 2001.
The new significance thresholds are based on a two-tiered approach that takes into account the potential harm caused by the breach and the licensee’s response to the breach.
- The first tier applies to breaches that have caused, or have the potential to cause, significant consumer harm, financial loss, or damage to the licensee’s reputation.
- The second tier applies to breaches that do not meet the first tier but are still considered significant due to the licensee’s response to the breach, such as a failure to take reasonable steps to prevent the breach from occurring or to mitigate its impact.
Overall, the key changes made by the Amendment Instrument are intended to reduce the regulatory burden for licensees arising from reportable situation reports that offer limited or no regulatory intelligence value for ASIC and meet certain criteria.
New Significance Thresholds
In previous articles, we’ve explored the issue of significance in some detail.
This instrument modifies the significance thresholds to exempt a breach (that would otherwise be significant constituted) from being deemed ‘significant’ and therefore reportable if certain conditions are met.
In effect, ASIC’s modifications to the reportable situations regime entail the exclusion of specific breaches that apply when the breach meets certain criteria:
- The breach does not give rise to, and is unlikely to give rise to, any other reportable situation. The underlying circumstances in relation to the breach must have only given rise, and only be likely to give rise, to a single reportable situation under paragraph 912D(1)(a) of the Corporations Act (and 50A(1)(a) of the Credit Act). The paper confirms that a single reportable situation can exist even if conduct has given rise to a single contravention of multiple provisions. The condition that there be only a single reportable situation means that the underlying circumstances must not give rise, and be unlikely to give rise, to another reportable situation. Likewise, a licensee cannot fail to report a contravention that has given rise, or would be likely to give rise, to another reportable situation. For example, think about a Licensees failure to maintain adequate capital or hold adequate insurance, these failures would lead to cascading failures and would therefore still be reportable.
- Only one person is impacted or, if it relates to a jointly held financial product, credit product, consumer lease, mortgage, or guarantee, it affects those joint holders. Reasonably enough, where the breach relates to misleading and deceptive publications, this exemption will not apply even if only one consumer raises a concern.
- The breach does not result in, and is unlikely to result in, any financial loss or damage to any person, regardless of whether remediation is required. Any assessment of damage includes immediate or future financial loss or damage and, in the case of misleading or deceptive representations, extends to loss or damage to a person other than the consumer that was misled or deceived. To be clear, financial loss or damage exists irrespective of whether the loss or damage has been, will, or may be, remediated.

Extended Reporting Timeframe
Licensees also benefit from an extended reporting timeframe.
You now have up to 90 days (previously 30 days) from the time they become aware, or are reckless with respect to whether there are reasonable grounds to believe, that a reportable situation has occurred. This extension applies when the reportable situation has underlying circumstances that are the same as, or substantially similar to, those of a previously reported reportable situation.
However, You must lodge their reports within 30 days after the licensee first knows that, or is reckless with respect to whether, there are reasonable grounds to believe that a reportable situation has arisen under subsection 912DAA(3) of the Corporations Act or subsection 50B(4) of the National Consumer Credit Protection Act 2009 (Credit Act) (timeframe obligations).
It’s such an important point that it bears repeating. Licensees have up to 90 days to report “related reportable situations” to ASIC. For example, if you identify a contravention that has followed from or because of a previously reported breach, you have 90 days to report the breach and this starts from when you first know that a related reportable situation has arisen. All other reportable situations must be reported within 30 days.
Remember that the Corporations Act and ASIC Act provide ASIC with a range of enforcement powers, including the ability to take legal action against licensees who breach their obligations. These enforcement powers may include fines, penalties, and other sanctions. Additionally, failure to comply with reporting obligations may also result in reputation damage and business disruption.
Enough already?
Regulatory change fatigue may be a real thing but these changes should be welcomed by an industry that has struggled to resist a fear-driven response to report and over-report.
Simply, these changes should reassure responsible licensees because they exclude the automatic reporting of certain breaches, injects reasonableness into any discussion of whether a contravention significant and reportable and provide licensees with an extended reporting timeframe of up to 90 days for reportable situations with underlying circumstances similar to previous ones. However, new significant issues still need to be reported within 30 days.
For reasons of speed and flexibility, ASIC used ASIC Corporations and Credit (Amendment) Instrument 2023/589 to enact these modifications, and these changes became effective from 20 October 2023. These modifications will streamline reporting requirements while ensuring that only significant breaches, that meet specific criteria, are reported to ASIC.

If you are a Licensee, make sure that you are aware of these changes and ensure that you adjust your reporting processes to operationalise these refinements. If you need help, reach out to us.