It seems like only yesterday that we offered the FSC our constructively critical feedback on its Green Paper. The FSC responded positively, and the ensuing dialogue signalled a remarkable willingness to engage beyond its membership.
In fact, the Financial Services Council’s recent White Paper on the Future of Advice Licensing represents a significant improvement on its original Green Paper.
It was pleasing to see the FSC respond so positively to our critical analysis of the Green Paper. The White Paper abandons tiered licensing, rejects practising certificates and accepts that licensee size is not a reliable proxy for risk.
Those are important corrections, and it’s gratifying to have been heard.
The FSC has moved from structural reform towards stronger supervision of the existing licensing framework. Its central conclusion is that Australia does not need to replace the AFSL framework. It needs to supervise it more effectively.
We wholeheartedly agree.
However, the White Paper also introduces significant new proposals concerning ASIC levies, professional indemnity insurance and financial requirements. These matters deserve broader consultation before policy positions are adopted that could profoundly affect the licensed community.
It’s still problematic that the paper continues to concentrate on licensees as entities. It gives less attention to the directors, controllers, executives and responsible managers whose decisions determine whether a licensee’s compliance arrangements work.
Has the FSC abandoned size-based licensing?
Largely, and thankfully, yes.
The Green Paper contemplated tiered licensing based on size, risk profile and service scope. We argued that this relied on an unstable and quixotic assumption: that larger licensees generally possess better compliance capability and present less risk.
Experience has repeatedly proven the opposite.
The White Paper now acknowledges:
“The consultation response was clear: size alone is not a reliable indicator of the probability of misconduct, governance failure or consumer detriment.
Large licensees may have more advisers and arguably therefore a larger potential scale of harm if something goes wrong. They may also have more complex distribution networks, more layered management structures and more dispersed authorised representative models. However, larger licensees typically have more mature governance frameworks, dedicated compliance teams, internal audit capability, product governance processes, breach reporting infrastructure, technology investment and extensive professional indemnity arrangements. Those features can significantly reduce risk.
Small licensees may have fewer advisers and closer day-to-day oversight. In some cases, a small principal-led licensee may have direct visibility of every advice file, client relationship and business decision. That can be a strength. However, smaller licensees may also have fewer internal controls, limited compliance capacity, weaker financial resilience, heavier reliance on external providers, less sophisticated cyber and operational systems, and less experience managing complaints, remediation or regulatory engagement.”
This is more balanced than the Green Paper. However, it still assumes capabilities rather than testing them.
Size does not equal capability[1].
A large licensee may have a mature governance framework, dedicated compliance teams and sophisticated systems. It may also have more profound conflicts, more complex reporting lines and greater commercial pressure to tolerate profitable misconduct.
A compliance function is not effective merely because it exists[2]. Its effectiveness depends on whether it receives reliable information, asks the right questions[3], escalates concerns and has sufficient authority to require management action.
That was a central lesson from ASIC’s Report 515 and the Financial Services Royal Commission. Large institutions frequently possessed policies, committees, compliance teams and internal audit functions. Their failures often arose because those arrangements were compromised by commercial priorities, weak escalation, fragmented responsibility, negligence, recklessness, ignorance or management inaction.
Our original response argued that:
“Internal compliance functions were sometimes compromised by commercial pressures or conflicts of interest.”
The FSC’s bias towards institutional and corporate licensees aside, the appropriate distinction isn’t between large and small licensees but between capable and incapable licensees, and between systems that operate effectively and systems that merely exist.
What does InterPrac tell us about scale?
Although there are many other relevant examples, ASIC’s proceedings against InterPrac Financial Planning illustrate the weakness in treating size, infrastructure or access to compliance resources as evidence of capability.
InterPrac was not a micro-licensee. It had hundreds of advisers and was part of the ASX-listed Sequoia Financial Group. Sequoia’s 2024 annual report said 70 advisers joined its AFSL during the year and 56 departed. Industry reporting indicated that InterPrac still had approximately 230 advisers during 2025.
ASIC alleges that InterPrac failed to take reasonable steps to ensure that certain authorised representatives complied with the best interests obligations and failed to maintain adequate risk-management systems. These allegations haven’t been determined by the Court, and InterPrac is entitled to contest them, but the case illustrates the weakness in the FSC’s reasoning.
InterPrac’s alleged problem wasn’t the absence of scale or access to compliance infrastructure. ASIC’s case is that the licensee failed to use its information, authority and systems effectively despite repeated indicators of serious risk.
According to ASIC’s Concise Statement, InterPrac allegedly:
- identified a significant spike in business volumes;
- found serious deficiencies in advice files;
- imposed pre-vetting requirements but failed to enforce them;
- had access to information about product flows and adviser revenue;
- identified concerns about lead generators and concentrated product recommendations;
- placed Shield and First Guardian on hold but failed to monitor compliance with that direction;
- received information about substantial payments connected to the products; and
- continued relationships with the relevant representatives despite those warning signs.
ASIC alleges that approximately 6,843 retail clients invested about $677 million in Shield and First Guardian on the advice of the relevant representatives.
The allegations concern the use of information and the exercise of authority. They don’t suggest that InterPrac simply needed more compliance staff.
This supports our original criticism of the FSC’s perspective. The FSC’s analysis tends to exclude management from any discussion of accountability. It discusses the capabilities of “the licensee” without adequately examining who received the information, who had authority to intervene, what decisions they made and why effective action was not taken.
Where is management accountability?
It’s important to appreciate that a licensee is a legal entity, and not a real person. It doesn’t read compliance reports, approve products or decide whether to retain a profitable representative.
People do, or don’t do, those things.
The Corporations Act properly places responsibility on the licensee for the financial services provided under its licence. However, effective regulation also requires attention to the individuals who control the licensee and make its decisions.
That’s why the FSC should focus less on size and presumed capability, and more on whether each licensee is genuinely capable and resilient. The better regulatory response would be a practical capability assessment that tests how the licensee operates, rather than inferring competence from its adviser numbers, resources or organisational structure.
In our view, that assessment should examine where control sits, how authority is exercised and whether management acts effectively when risks emerge. It should consider:
- who controls compliance resources;
- who approves representatives and business models;
- who receives monitoring and complaint information;
- who can impose or remove conditions;
- who decides whether misconduct is investigated;
- who approves remediation;
- who manages conflicts involving senior personnel; and
- what consequences follow when management fails to act.
The White Paper supports greater visibility of responsible managers. That’s potentially useful, but visibility alone isn’t enough. Responsible managers shouldn’t become convenient substitutes for the directors and executives who hold the real authority.
ASIC, and the FSC, must consider the entire management chain. Accountability should follow practical authority, access to information and resources and real decision-making responsibility.
Is phoenixing the problem, or is management accountability missing?
The FSC repeatedly identifies phoenixing as a significant licensing risk. The concern is legitimate, but the evidence provided is limited.
The White Paper describes advisers or key persons with poor compliance histories leaving one entity and re-emerging through another licensee structure. It says consultation participants identified examples of advisers removed or reported for compliance concerns who later obtained a licence elsewhere. It does not quantify those cases or establish how frequently the new entities caused consumer harm.
The description also extends beyond conventional phoenixing. An adviser changing licensees or a former manager joining another business isn’t necessarily phoenix activity. The relevant question is not simply whether a person was associated with a failed licensee. It is what responsibility they held, what they knew, what authority they possessed and what they did in response.
We know that ASIC already closely (and perhaps obsessively) scrutinises new licence applications and any variations. The licensing test covers organisational competence, financial resources, risk-management systems, officers, controllers, responsible managers and other fit-and-proper persons.
ASIC’s 2025 licensing report records that 290 new AFS licences were granted during 2024–25. It also records applications that were not accepted, were withdrawn or produced additional regulatory outcomes. ASIC says 42% of approved AFS licence applications attracted at least one additional regulatory outcome.
Obtaining a new advice licence is not a routine change of corporate name.
In our experience, the more credible risk is that management responsibility is poorly identified. A failed corporate licensee can disappear while the individuals who designed its business model, controlled its resources or ignored warning signs continue elsewhere. Unless ASIC establishes their responsibility and, where justified, takes action against them personally, preventing the failed company from reapplying achieves little.
This exposes the same weakness evident throughout the FSC’s analysis. Legal accountability is repeatedly attributed to “the licensee”, an entity that can be wound up, sold or replaced. Much less attention is given to the directors, executives, controllers and responsible managers whose decisions determine whether the licensee’s systems work.
If phoenixing is a material concern, the response should focus on management continuity. ASIC should be able to identify the current and historical associations of directors, controllers, responsible managers and other influential people. Licensing applications should require disclosure of their roles in failed or sanctioned businesses, the responsibilities they held and the actions they took when problems emerged.
The issue is not that ASIC lacks a licensing gateway. It is whether responsibility for past failure is identified before the same people are permitted to re-enter through a different structure.
Would independent review provide better assurance?
The FSC recommends that ASIC meet every advice licensee twice each year: once as part of an annual licence renewal and again through an additional supervisory review.
This would be expensive. It may also produce more regulatory contact without materially improving ASIC’s understanding of whether the licensee’s arrangements work.
A better model may already exist in the reformed AML/CTF framework.
In case you missed it, reporting entities must arrange an independent evaluation of their AML/CTF programs at least once every three years. The frequency must otherwise reflect the nature, size and complexity of the business.
The evaluation is not confined to confirming that policies exist. It must examine the risk assessment, evaluate the design of the policies and test whether the entity has appropriately identified, assessed, managed and mitigated its risks.
The evaluator must provide a written report to the governing body and relevant senior management. The entity must consider adverse findings, update its arrangements where required and maintain evidence of its response. AUSTRAC’s independent-evaluation guidance explains the model.
A comparable obligation for advice licensees could be more effective than recurring administrative engagement with ASIC. At least once every three years, each licensee could be required to commission an independent evaluation of the design and operating effectiveness of its compliance, supervision and governance arrangements.
The review should examine:
- governance and management accountability;
- organisational competence and responsible-manager involvement;
- supervision of advisers and corporate authorised representatives;
- advice monitoring and remediation;
- structural and commercial conflicts of interest;
- product governance and approved product arrangements;
- complaints and reportable situations;
- client acquisition, referral and lead-generation arrangements;
- outsourcing and third-party dependencies;
- financial resources and PI insurance;
- the reliability of compliance reporting to the board; and
- whether previous findings have been effectively remediated.
Independence is critical.
The reviewer should not have designed, implemented or maintained the arrangements being reviewed. Nor should the licensee’s routine compliance provider review its own work. The reviewer must have direct access to records, staff and governing-body members and be free to determine the scope, testing and findings.
This is particularly important for conflicts of interest. Internal compliance teams operate within the organisations they assess. They may report through executives responsible for the relevant business line, depend on management for resources or have participated in approving the arrangements under review.
Familiarity, hierarchy and commercial pressure can narrow the questions asked or discourage escalation. An independent reviewer is better placed to identify conflicts that have been normalised, rationalised or omitted from internal reporting.
The report should be provided directly to the licensee’s board and made available to ASIC. Material findings should require a documented remediation plan, accountable owners, completion dates and independent verification of closure. Serious or systemic findings should trigger immediate notification.
A triennial review should not, and would not, prevent earlier ASIC intervention. Licensees should continue to provide annual attestations and structured information about material changes. Complaints, reportable situations, adviser movement, management turnover, PI deterioration or significant business-model changes should trigger targeted supervision.
This returns us to our original criticism of the Green Paper. Compliance effectiveness depends on governance, culture, accountability and the quality of independent challenge, not licensee size.
External compliance can provide the objectivity that internal teams sometimes lack. However, external compliance support and independent assurance perform different roles. A licensee may use an external provider for routine compliance support, but the periodic evaluation should be conducted by someone who did not design or maintain the arrangements under review.
A short ASIC meeting may establish that a licensee can describe its arrangements. Independent testing is more likely to establish whether those arrangements are properly designed, operating effectively and producing reliable information for management and the board.
Does the Financial Advisers Register need to be expanded?
The FSC proposes expanding the Financial Advisers Register to provide greater visibility of licensees, corporate authorised representatives, trading names and responsible managers.
Greater transparency is sensible. Creating substantial new reporting infrastructure may not be necessary.
ASIC already holds much of this information across the Financial Advisers Register and its other professional and corporate registers. A properly designed linkage could allow consumers and regulators to see:
- an adviser’s present and former authorisations;
- the relevant corporate authorised representative;
- the ultimate AFS licensee;
- trading names and related entities;
- responsible managers and relevant historical associations; and
- disciplinary and banning information.
The principal weakness is not necessarily the absence of information, but ASIC’s presentation of that information.
The existing interface is difficult to search, navigate and interpret. Relationships between advisers, corporate authorised representatives and ultimate licensees are not always clear. Users may need to conduct several searches across different ASIC systems before understanding the relevant structure.
That is unacceptable for a register intended to help consumers verify the status and history of a financial adviser.
Information is not meaningfully public if ordinary consumers cannot find it, understand it or connect it to the entities responsible for the advice business.
Before imposing additional reporting obligations, ASIC should identify what information it already holds, connect the relevant records and redesign the public interface. Any genuine information gaps could then be addressed through targeted amendments.
The objective should not be a larger register. It should be a usable one.
Should accountability extend beyond licensees?
Many failures identified by the FSC may not require another register or regulatory layer. A more practical response would be to require institutional participants to act on credible information about misconduct.
Standard 12 of the Financial Planners and Advisers Code of Ethics requires advisers, individually and in cooperation with their peers, to uphold and promote the profession’s ethical standards and hold each other accountable in the public interest.
The same principle should apply to institutions.
Product manufacturers, superannuation trustees, platform operators, insurers and investment managers often hold information capable of revealing harmful adviser or licensee conduct. Unusual transactions, recurring complaints, unexplained withdrawals, concentrated product flows, replacement activity and anomalous remuneration may provide early indications of misconduct.
These organisations should not be permitted to treat those indicators solely as another party’s compliance problem.
An institutional notification obligation should apply where a member has reasonable grounds to believe conduct may involve:
- serious consumer harm;
- dishonesty or fraud;
- systemic misconduct;
- significant unmanaged conflicts;
- deliberate avoidance of legal obligations; or
- a material failure by a licensee to supervise its representatives.
The obligation would require careful design. A requirement to report anything that might “damage the profession” would be too subjective. It could produce defensive reporting, duplicate existing breach-reporting obligations and expose people to allegations that have not been properly assessed, but properly designed, it would both clarify accountability and mitigate misconduct.
The framework should require reasonable grounds, documented assessment, confidentiality and procedural fairness. Existing statutory reports should continue to be made directly to ASIC. The industry mechanism should address credible concerns that reveal emerging risks but do not clearly satisfy an existing reporting threshold.
Most importantly, the obligation should extend to product manufacturers. Manufacturers benefit from adviser distribution and frequently have data across multiple licensees. Accountability should not end when the product enters a distribution channel.
Has the FSC overlooked its own Standard?
Although this proposal might appear too ambitious, implementation might be quite simple because the FSC may already possess part of the mechanism required to operationalise this change.
FSC Standard No. 1 states that members should report breaches in conduct or instances of unethical behaviour. It also requires full members to report breaches of FSC Standards to the FSC Secretariat and provide an annual board-supported certification of compliance.
The problem is that the obligation is not sufficiently developed.
The supporting compliance process focuses principally on each member’s own compliance with FSC Standards. It does not clearly require a member to notify the FSC or ASIC when information obtained through its business reveals serious misconduct by another licensee, adviser, distributor or product provider.
Before advocating further regulatory intervention, the FSC should consider strengthening its existing Standard. It could establish a defined obligation requiring members to act where they have reasonable grounds to believe conduct presents a serious risk of consumer harm or damages the integrity of the profession.
The strengthened Standard should specify reporting thresholds, timeframes, confidentiality protections, procedural fairness and its relationship with statutory breach reporting.
The FSC doesn’t need a new regulatory structure. It could begin by giving practical effect to an ethical obligation it already imposes on its members. That would test whether the industry is prepared to accept the accountability it recommends for others.
What about ASIC levies, PI insurance and financial requirements?
The White Paper introduces substantial proposals concerning ASIC supervisory levies, PI insurance and financial resilience.
These are legitimate policy questions. They were not, however, the central subjects of the Green Paper consultation.
A significant increase in the fixed licensee levy would disproportionately affect small licensees. It might discourage poorly resourced applicants, but it could also force capable and well-governed businesses to consolidate under larger licensees. That would be difficult to reconcile with the White Paper’s acceptance that size does not establish capability.
Higher PI limits may also create the appearance of stronger consumer protection without guaranteeing recoverability. The effectiveness of PI insurance depends on exclusions, deductibles, aggregation clauses, notification compliance, policy interpretation, insurer solvency and whether cover remains available after the licensee exits.
Similarly, financial-resource requirements require more than a nominal increase in capital. The proper question is whether the licensee has sufficient resources for its actual business model, including the capacity to supervise, investigate, remediate, pay policy excesses and manage an orderly exit.
These proposals require evidence, modelling and broad consultation. They should not become settled policy positions merely because they appear in a White Paper directed principally to advice licensing and supervision.
What should happen next?
The White Paper is a constructive correction. It accepts much of the feedback we directed at the Green Paper and moves the discussion in the right direction.
The AFSL framework should remain. Size should not determine regulatory treatment. ASIC should use risk indicators and better-connected information to identify where deeper supervision is required.
However, more meetings, higher levies and larger insurance policies will not solve failures of judgement and accountability.
The stronger reform program would:
- require independent evaluation of each licensee’s compliance, governance and supervisory arrangements at least every three years;
- retain annual attestations and event-driven ASIC supervision;
- connect and redesign ASIC’s existing public registers;
- identify the directors, controllers, executives and responsible managers associated with failed or high-risk licensees;
- attribute accountability according to practical authority and access to information;
- strengthen FSC Standard No. 1 to require members, including product manufacturers, to act on credible misconduct indicators; and
- subject new levy, PI and financial-resource proposals to broad consultation and evidence-based assessment.
The central issue isn’t the number of advisers operating under a licence. It’s whether the people responsible for that licence possess the necessary capability, use the information available to them and are held accountable when they fail to act.
Systems matter. Scale may help. Neither is a substitute for capable management, independent challenge and consequences. The solution isn’t more regulation, but more effective compliance built on openness, accountability and ethical leadership.
Found this article useful? You can select Assured Support as a ‘preferred source’ in Google. This may help you see more of our articles in Google Top Stories, AI Mode and AI Overviews when our content is relevant to your search.
Further reading
Frequently Asked Questions
Licence size may influence the scale of potential consumer harm, but it does not reliably predict whether a licensee has effective governance, supervision or compliance controls. Large licensees often have greater resources, dedicated compliance teams and sophisticated systems, yet regulatory action has repeatedly shown that these advantages do not necessarily prevent governance failures.
Conversely, smaller principal-led licensees may have fewer formal resources but stronger day-to-day oversight. The more meaningful question is whether a licensee can identify risks, escalate concerns, exercise authority and respond effectively when problems emerge.
A defensible licensing framework should assess actual capability rather than infer competence from organisational size or adviser numbers.
A financial services licence is held by a legal entity, but compliance decisions are made by people. Directors, executives, Responsible Managers and controllers determine whether compliance reports are acted upon, whether advisers are supervised effectively and whether misconduct is investigated or ignored.
Focusing only on the corporate licensee can obscure where real authority sits. A stronger regulatory approach would examine who received critical information, who had authority to intervene and whether those individuals exercised their responsibilities appropriately when risks emerged.
Assured Support argues that periodic independent reviews could provide deeper assurance than more frequent administrative meetings with ASIC. Drawing on Australia’s reformed AML/CTF framework, an independent review could assess whether governance, supervision, compliance monitoring and risk management arrangements are both well designed and operating effectively. Independent reviewers are also better placed to identify conflicts of interest and governance weaknesses that may not be apparent through routine internal reporting.
Such reviews would complement, rather than replace, ASIC’s existing supervisory and enforcement activities.
The allegations against InterPrac illustrate that access to compliance resources alone does not ensure effective oversight. According to ASIC’s allegations, the licensee identified multiple warning signs including file review deficiencies, concentrated product recommendations and concerns about lead generator, yet allegedly failed to use its information and authority effectively.
Although the proceedings are before the Court, the case demonstrates why regulators increasingly focus on how management responds to known risks rather than whether compliance systems simply exist on paper.
Assured Support’s analysis of the FSC White Paper concludes that Australia’s existing AFSL framework remains fundamentally sound but requires more effective supervision and stronger management accountability. Suggested reforms include independent reviews of governance and compliance arrangements, improved linkage of ASIC’s public registers, better identification of directors and Responsible Managers associated with failed licensees, greater transparency around management responsibility and broader consultation before introducing significant changes to ASIC levies, professional indemnity insurance or financial resource requirements.
Together, these measures aim to improve regulatory effectiveness without creating an entirely new licensing system.
[1] Westpac provides another warning against equating size with capability. In Westpac Securities Administration Ltd v ASIC [2021] HCA 3, the High Court unanimously held that Westpac’s superannuation rollover campaign provided personal advice despite being structured and presented as general advice. Westpac’s considerable legal, compliance and operational resources didn’t prevent the business from adopting a model that misunderstood, or failed to respect, a fundamental regulatory boundary. Scale provided infrastructure. It didn’t provide effective judgement or control.
[2] Nor is the problem confined to advice. In 2020, the Federal Court ordered Westpac to pay a record $1.3 billion penalty for more than 23 million AML/CTF contraventions. Westpac’s scale, specialist teams and sophisticated systems did not prevent extensive and prolonged compliance failures. Size supplied resources; it didn’t ensure that management deployed them effectively.
[3] Macquarie provides a more recent example. APRA imposed prudential overlays after material breaches exposed weaknesses in Macquarie Bank’s liquidity controls and operational-risk management, and a $500 million operational-risk capital overlay remains in place. Separately, Macquarie Investment Management admitted that it failed to place Shield on a watch list for heightened monitoring and committed to repay approximately 3,000 affected members. These were not failures caused by a lack of scale, specialist staff or technology. They were failures to ensure that available resources, information and controls produced effective action.