“Assured Support .. have taken to calling the October period ‘Red October’, such is the alarming congestion of reforms to hit the industry.”
— Tahn Sharpe, Professional Planner, 20 August 2021
Brace yourself
Ever had a throw-away line become a thing repeated back to you and credited to ASIC?
Welcome to “Red October”.
We just wanted to make the point that October is a critical month for Licensees and Advisers and more than a little preparation is needed to deal with a significant amount of regulatory reform. In this article we’ll briefly address the new requirements that you should already be contemplating and implementing – Reference Checking, Breaches, Complaints and Design and Distribution.
That’s not the entire list (there’s hawking, add-on insurance sales and a new duty to take reasonable care) but they’re the heaviest burdens and if you need help, reach out to us. We can help.

You’ll be pleased to know that even though they expect Licensees to have these reforms under control, ASIC recognises that “there will be a period of transition as industry finalises implementation of additional compliance measures”
We recommend that you read 21-213MR but we’ll summarise the four key reforms below:
- Reference Checking
- Breaches
- Design and Distribution Obligations
- Complaints
Reference Checking
“From 1 October 2021, licensees must comply, as an obligation under their licence, with the ASIC Reference checking and information sharing protocol.”
— ASIC Corporations and Credit (Reference checking and information sharing protocol) Instrument 2021/429
Commencement Date: 1 October 2021
Summary:
- Compliance with ASIC Instrument (2021/429) is mandatory from 1 October 2021;
- It’s a licence condition and subject to breach reporting requirements;
- Recruiting licensees must request a reference about the prospective representative from the referee licensee(s);
- The referee licensee(s) must then share information with the recruiting licensee about the prospective representative by giving a reference.
- Recruiting Licensees must seek written consent from a prospective representative to request a reference and if consent is given – request a reference from the referee licensee(s) in accordance with the ASIC protocol.
- The referee licensee(s) must then share information with the recruiting licensee about the prospective representative by giving a reference.
ASIC Instrument
Reference Template – Adviser
Reference Template – Credit
HB322
Red Flags:
- It’s a licence condition so contraventions are ‘deemed significant’ breaches.
- As long as they are factual, accurate and complete your reference checking responses are protected by the defence of ‘qualified privilege’ but it’s important to appreciate that it does not apply to any information you share that you are not obliged to give.
- If a prospective representative refuses to provide consent, you can still employ or authorise them BUT carefully consider how you’ll be able to demonstrate that you complied with your licensee obligations.
Related Content:
New Breach Regime
“Financial supervision is increasingly driven by data, with regulators requiring data of greater granularity and at a greater frequency.”
— Institute of International Finance, March 2016
Commencement Date: 1 October 2021
Summary:
The key features of the amendments to the breach reporting regime for financial services licensees include:
- the introduction of two new significance tests.
- an expansion of the kinds of situations that need to be reported by licensees to ASIC (which are referred to as ‘reportable situations’) to include:
- investigations into whether a significant breach has occurred or will occur if the investigation continues for more than 30 days, and the outcomes of those investigations;
- conduct that constitutes gross negligence or serious fraud;
- conduct that amounts to misleading or deceptive conduct under the financial services law; and
- serious compliance concerns about individual financial advisers operating under another licence;
- requiring licensees to lodge breach reports with ASIC in the prescribed form, and within 30 calendar days after the licensee first knows that, or is reckless with respect to whether there are reasonable grounds to believe, a reportable situation has arisen; and
- requiring ASIC to publish data about breach reports on its website.
RG78
Red Flags:
- At the risk of over-simplification, the new regime requires Licensees to report serious compliance concerns they have about any Licensee or financial adviser engaged by another Licensee. Reporting Licensees have the benefit of qualified privilege against defamation and breach of confidence actions for ‘good faith’ reporting but operationalising this requirement may prove challenging.
- A Licensee is required to notify ASIC within 30 days if there are reasonable grounds to believe that a “reportable situation” has occurred or is likely to occur.
- the licensee or a representative has breached a “core obligation” (one or more of the licensee obligations under s912A and 912B) and the breach is significant;
- the licensee or a representative is no longer able to comply with a core obligation and the breach, if it occurs, will be significant;
- the licensee’s investigation into a reportable situation continues past 30 days;
- the licensee or a representative has engaged in conduct constituting gross negligence; and
- the licensee or a representative has committed a serious fraud.
- Essentially, a breach of a core 912A or 912B obligation will be deemed to be significant if it involves:
- the commission of an offence punishable by a sentence of 12 months or more (or three months or more for offences involving dishonesty),
- a contravention of a civil penalty;
- misleading or deceptive conduct in relation to financial products or services; or
- a contravention that is likely to result in material loss or damage to a retail client.
- The challenge is that the civil penalty regime covers a wider range of provisions in financial services laws, including:
- the general obligations of Australian financial services licensees;
- the obligation to lodge breach reports with ASIC;
- the disclosure requirements in Chapter 7;
- the general obligations of credit licensees;
Related Content:
Our “New Breach Regime” webinar
Confession, repentance and testimony: The new breaches regime
In the new breach regime, what are ‘reportable situations’?
In the new breach regime, what are the ‘civil penalty provisions’?
In the new breach regime, what are the AFSL’s core obligations?
In the new breach regime, what are the ACL’s core obligations?
Design and Distribution Obligations
“One of the key sources of community and consumer frustration with the financial services sector is the divergence between what is promised and what is delivered over time.”
— Peter Kell (2018). “How financial services firms can act to meet community expectations through transparency and accountability”
Commencement Date: 5 October 2021
Summary:
The new product design and distribution regime per Pt 7.8A of the Corporations Act 2001 commending on 5 October 2021, will apply to issuers and distributors of financial products. For issuers the obligations apply to persons who must prepare a disclosure document under the Corporations Act (e.g. a responsible entity of a managed investment scheme, an insurer, a superannuation trustee, and an issuer of hybrid securities).

- Potentially, one of the most significant reforms of financial services since FSRA;
- Encompasses design, issue, distribution, intervention and enforcement;
- Requires a Product Issuer to prepare a Target Market Determination (TMD) for each product;
- Requires a Distributor to take reasonable steps to comply with the TMD;
- Requires a Distributor to track, record and escalate any breaches or complaints.
- It excludes:
- a MySuper product; or
- a margin lending facility; or
- a security that has been or will be issued under an employee share scheme; or
- a fully paid ordinary share in a company or a foreign company; or
- a financial product issued, or offered for regulated sale, by an exempt body or an exempt public authority; or
- a financial product of a kind prescribed by regulations.
RG274
Red Flags:
- Distributors are prohibited from distributing a product unless a current target market determination is in place and must take reasonable steps so that distribution is consistent with the most recent target market determination. How will you practically manage this?
- Distributors must maintain records
- Distributors must provide to offerors numbers of complaints about the product
- Distributors must notify a product’s offeror, and an offeror must notify ASIC, of a significant dealing.
- “The combination of civil and criminal penalties allows ASIC or the prosecutor (as the case may be) to take a proportional approach to enforcing the new obligations.” Penalties range between:
- 50-200 penalty units ($11,100- $44,000)
- Corporations ($55,500 – $222,000)
- 12 months – 5 years imprisonment
Related Content:
The new complaints regime
“[An expression] of dissatisfaction made to or about an organization, related to its products, services, staff or the handling of a complaint, where a response or resolution is explicitly or implicitly expected or legally required.”
— ASIC REGULATORY GUIDE 271, @271.27-29
Commencement Date: 5 October 2021
Summary:
- RG271 (which replaces RG165) becomes enforceable from 5 October 2021;
- Broad application with a new, more expansive definition:
- The introduction of enforceable paragraphs;
- The requirements are premised on data-driven and integrated IT solutions; and
- ASIC will publish data about complaints on its website.
RG271
RG165
Data Dictionary
Data Glossary
Red Flags:
- Establishing these requirements as enforceable paragraphs mean that non-compliance is a breach of a Licensee’s “core obligations”.
- Under the new penalty provisions, the maximum civil penalty for individuals is the greater of $1.11 million or three times the benefit obtained and detriment avoided.For corporate entities, the penalties can be ten times greater.
- In addition to referencing the new AS/NZ 10002:2014, the expanded definition explicitly includes “posts … on a social media channel or account owned or controlled by the financial firm that is the subject of the post, where the author is both identifiable and contactable”.
- You’ll need a public complaints policy that explains
- How consumers may lodge a complaint (e.g. online, by email, by phone and in person);
- The options available to assist complainants who might need additional help to lodge their complaint;
- Your key steps for dealing with complaints;
- Your response timeframes; and
- How they can access AFCA if their complaint is not resolved.
- You now have to acknowledge a complaint within 24 hours of one business day of receiving it, or as soon as is practicable.
- You must take into account the method used by the complainant to lodge their complaint and any preferences they may have expressed about communication methods (i.e. email, post or social media channels).
- Your people will have an obligation to proactively identify people who might need additional assistance.
- Your IDR Team need to be adequately resourced and appropriately authorised (with appropriate delegations) to resolve complaints.
- ASIC expect you to be able to demonstrate:
- an organisation-wide understanding of the definition of ‘complaint’ and the types of matters that must be dealt with in a firm’s IDR process;
- more effective capture, tracking, analysis and reporting of complaint data;
- improved timeliness and efficiency;
- enhanced quality of written communications and IDR responses;
- stronger complaint management skills;
- an organisation-wide accountability for complaint management; and
- leveraged technology and data analytics to improve both the IDR process and the products and services offered by financial firms.
- You will need to monitor key metrics for complaint management on an ongoing basis.
- You will need to record and report extensive information regarding complaints including
- the number of complaints received and closed;
- their nature;
- the time taken to acknowledge;
- the time taken to resolve;
- complaint outcomes;
- possible systemic issues; and
- the number of complaints escalated to AFCA.
Related Content:
Dispute resolution, compensation and moral hazards
The impact of complaints: New requirements, new challenges
