The Compliance Matrix: Red Pill or Blue Pill?

As 2025 hits its stride, so does ASIC. The regulator has shifted gears—from reacting to misconduct to actively disrupting it.

For firms out of step with community expectations or client outcomes, the message is clear: get your house in order.

So far this year, we’ve seen ten AFSLs either revoked or restricted. Advisers are facing bans, criminal charges, or FSCP sanctions. If you squint, it feels like a disciplinary round from the NRL.

But this isn’t sport. It’s financial services. And it begs the question: could any of this have been prevented?

Maybe not every case, but many could have been better managed (or avoided) if the right frameworks were in place. Not more tick-boxes. Not more policies gathering dust. But a meaningful compliance strategy that shines a light on blind spots and supports sound decisions.

Welcome to the Compliance Matrix.


Why a Matrix?

Think of the Matrix as a tool—not a spreadsheet. A Compliance Matrix helps you understand your risks in context: your business model, your clients, your scale, and your internal culture.

It’s not static. It’s dynamic. It evolves with your firm and with the shifting regulatory landscape. And it’s less about rules, more about rigour.

So, we ask again:

Blue pill or red pill?
Stay comfortable doing what’s always been done?
Or dive deep and confront your blind spots head-on?

“Unfortunately, no one can be told what The Matrix is.
You have to build it for yourself.”
— Morpheus, The (Compliance) Matrix


Context Is Everything

The risks facing a boutique advisory firm are not the same as those facing a scaled, national Licensee. Yet too many risk frameworks are borrowed, boilerplate, or built in isolation.

You can’t mitigate what you don’t understand. And you can’t learn from others’ mistakes if you don’t examine your own.


Dimensions of a Useful Risk Matrix

1. Size and Scale

How large is your firm? How dispersed? The bigger you are, the more you need structured oversight, distributed responsibilities, and systems that scale with your client base.

2. Business Model

Are you fee-for-service? Do you still receive legacy commissions? Is your advice conflicted by vertical integration or volume-based referrals?

3. Client Demographics

Different clients carry different risks:

  • Aged care clients: vulnerability and financial abuse
  • Retirees: suitability, switching advice, product bias
  • Wealth accumulators: under-documentation and service gaps

Tailoring Risk by Firm Type

Firm TypeKey RisksRemedies That Work
Boutique Smaller scale; Fee-for-service; Niche client base (HNW, SMSF); Limited in-house compliance team.Inconsistent recordkeeping, adviser discretion, over-reliance on key staffPeer reviews, compliance playbooks, ‘house views’, quarterly check-ins, centralised systems
Mid-Tier Broader scope of advice and services; Mixed income – fee-for-service and commissions etc.; Varied client base; Moderate compliance support – either via a dedicated in-house team, or varying levelsScaling issues, service failings, inconsistent advice, conflicted legacy clientsDefined advice process, regular reviews, clear opt-in models, external conflict checks
National/Scaled National identity and multiple locations; Scaled advice models; Potential vertical integration; Layered compliance and governance systems; Key staff in multiple locations (but not all).Fragmented oversight, brand risk, vertical integration, poor local supportIndependent reviews, location-based controls, CPD pathways, team uplift and due diligence

Compliance Failure in Practice: Dover

No discussion of systemic failure is complete without Dover.

When the Royal Commission turned its lens on Dover Financial Advisers in 2018, it uncovered a mess. Their infamous Client Protection Policy stripped clients of legal rights—while pretending to protect them.

The core issues?

  • Senior management knew the CPP was misleading.
  • Compliance oversight was non-existent for a 400+ adviser network.
  • Misconduct signals were ignored or dealt with superficially.

“Whoa. Déjà vu.”
— Neo, The (Compliance) Matrix

We’re unlikely to see another Dover. The industry has moved. Consumers are more informed. Licensees are more alert. But we’re not immune to complacency.


2025: ASIC Is Watching

ASIC’s 2025 enforcement priorities make one thing clear: they’re not easing off the accelerator. While the headline focuses may shift, adviser and AFSL conduct remains in the spotlight.

If you haven’t reviewed your compliance framework recently, you’re not ready.

Now is the time for firms to ask:

  • Are we aligned with ASIC’s enforcement focus?
  • Are our internal systems proactive or reactive?
  • Are we creating good outcomes—or just hoping to avoid enforcement?

How to Build Your Own Matrix

Forget static registers. A Compliance Matrix should live and breathe within your business. Here’s how to get started:

Baseline

  • Define your firm’s size, model, and demographic spread
  • Map service categories to compliance exposure
  • Review legacy revenue models

Quantitative Review

  • Segment high-risk clients
  • Track breach trends (rolling 12-month view)
  • Measure adviser supervision and file reviews

Qualitative Review

  • Run adviser culture surveys (anonymous)
  • Audit file notes for templated language or automation red flags
  • Risk-map with board and compliance leaders

Alignment and Oversight

  • Benchmark your framework against ASIC’s stated focus
  • Compare your breaches to real-world enforcement activity

Remediation and Education

  • Identify recurring non-compliance themes
  • Offer peer-led CPD on ethics and suitability
  • Link compliance performance to bonuses, KPIs, or recognition

So, What’s Next?

You can’t build trust with crossed fingers.

In 2025, the firms that lead will be the ones that see compliance as a strategic asset—not a sunk cost. They’ll treat governance as something to be embedded, not endured.

A well-built Compliance Matrix helps your firm:

  • Reduce operational risk
  • Spot cultural red flags
  • Align with regulatory focus
  • Improve client outcomes

If you’re ready to take a red-pill moment and design something that supports your business—not just ticks a box—we’re here to help.

See how we can help you build a better matrix →

If you enjoyed this article, we think you might also enjoy reading:

Everything You Know About Compliance Is Wrong

Risk Management 2.0 for a Small AFSL: Practical, Adaptive, and Intent-Led

ASIC Enforcement Trends: What You Need to Know for 2025


Frequently Asked Questions

1. What Is a Compliance Matrix and Why Should My Firm Use One?

A Compliance Matrix is a dynamic tool tailored to your business model, client demographics, and scale. It helps identify and mitigate risks by aligning your operations with current regulatory expectations and internal culture.

2. How Does ASIC’s 2025 Enforcement Focus Impact Licensees?

ASIC has shifted from reactive to proactive enforcement. Licensees must now demonstrate that their systems prevent misconduct, not just respond to it. A robust compliance framework is essential.

3. What Compliance Risks Do Different Firm Types Face?

Boutiques risk inconsistency and over-reliance on key staff; mid-tier firms may struggle with scaling and legacy conflicts; national firms often face fragmented oversight and governance gaps. Tailored strategies are essential for each.

4. How Can My Firm Start Building a Compliance Matrix?

Begin with a baseline of your firm’s model and risks, then conduct quantitative and qualitative reviews, align with ASIC’s focus, and embed remediation and education into your compliance culture.

5. What Lessons Can We Learn From Dover’s Collapse?

Dover’s failure shows the danger of ignoring systemic compliance flaws. Its misleading policies and weak oversight offer a cautionary tale about the risks of complacency and poor governance.

Keep exploring

The Compliance Matrix: Red Pill or Blue Pill?

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?