Maintaining compliance with ASIC’s reportable situations regime is not just about meeting a 30-day deadline. It requires a structured, repeatable process that ensures issues are identified early, assessed consistently and escalated appropriately.
Many Licensees struggle not with the law itself, but with operationalising it. The solution is to treat breach reporting as a defined lifecycle, not an isolated event. This framework applies to both AFSL and ACL Licensees.
The Reportable Situations Framework
A practical way for AFSL and Credit Licensees to approach ASIC breach reporting is through an eight-stage framework:
1. Identification
Incidents should be captured from multiple sources, including complaints, monitoring activities, adviser supervision and staff escalation. A centralised incident register with clear ownership is critical.
- Incident captured through complaints, monitoring, audit or staff escalation
- Incident recorded in central register with owner and date
How this is typically implemented in practice
Leading Licensees centralise incident capture to ensure all incidents, breaches, near misses and complaints are recorded, timestamped and assigned for action within a single workflow.
2. Investigation
Once identified, the issue must be properly understood. This involves gathering relevant facts, determining client impact and identifying whether the issue is systemic or isolated.
- Relevant facts and documents gathered
- Client impact assessed
- Root cause identified (systemic or isolated).
3. Significance Assessment
Not every incident is reportable. Licensees must assess whether a matter constitutes a “reportable situation” by considering factors such as breach significance, client detriment, frequency and control failures.
- Breach (or likely breach) of a core obligation identified
- Frequency or pattern of similar incidents considered
- Client detriment assessed (financial or non-financial)
- Control weaknesses identified
Where most licensees struggle
Significance assessments are often applied inconsistently across teams, particularly where judgment is required. Without a structured decision framework, similar issues can lead to different outcomes, creating regulatory risk.
4. Reporting Decision
A documented decision framework aligned to ASIC Regulatory Guide 78 helps ensure consistency. Borderline matters should be escalated, and all decisions should be clearly recorded.
- Decision framework applied (aligned to RG 78)
- Rationale documented clearly
- Borderline matters escalated
5. Lodgement
Where required, reports must be lodged with ASIC within statutory timeframes (generally 30 calendar days). Submissions should be complete, accurate and supported by internal records.
- Reportable situation confirmed
- ASIC notification prepared and lodged within the required timeframe
- Supporting documentation retained
6. Remediation
Affected clients must be identified and remediated promptly. This includes calculating loss, implementing corrective actions and tracking outcomes.
- Affected clients identified
- Loss or detriment calculated
- Remediation completed and tracked
Operational reality
Without structured workflows, remediation tracking becomes fragmented and difficult to evidence. Linking incidents, actions and outcomes is critical to demonstrating a clear audit trail.
7. Governance and Oversight
Breach data should be reported to senior management and the board, with a focus on trends, recurring issues and systemic weaknesses.
- Incident reported to senior management and/or board
- Trends and recurring issues analysed
8. Continuous Improvement
Each incident should feed back into the compliance framework. Policies, controls and training should be updated to prevent recurrence and strengthen the control environment.
- Policies and procedures were updated where required
- Controls strengthened to prevent recurrence
- Training updated based on incident learnings
Key question:
If ASIC reviewed this matter, could you clearly demonstrate how you identified, assessed and responded to it?
If the answer is no, your process needs strengthening
From framework to operating model
The difference between compliant and non-compliant licensees is not knowledge, but execution. Embedding this framework into day-to-day systems, workflows and reporting is what enables consistent, defensible outcomes.
Licensees who rely on manual processes often struggle to demonstrate consistent breach assessment and reporting. Implementing a structured framework, supported by a platform like complye, can significantly improve both compliance outcomes and auditability.
Maintaining consistent reportable situations assessments requires structured operational workflows, defensible investigation records and clear remediation governance.
Many licensees now use dedicated compliance infrastructure platforms such as [complyᵉ] to centralise incident management, document investigation decisions, maintain escalation records and track remediation activities through to resolution.
Moving forward
ASIC expects more than timely reporting. It expects evidence of a system that can identify, assess and respond to issues consistently.
If you are unsure whether your breach reporting process would withstand ASIC scrutiny, the issue is rarely the law itself. It is how the framework operates in practice.
Assured Support works with Licensees to design, implement and run breach reporting frameworks that are consistent, defensible and aligned to ASIC expectations. This includes embedding structured processes, oversight and, where appropriate, platforms like complye to ensure incidents are identified, assessed and reported correctly.
If you would like to discuss your current approach with one of our experts, click here.
If you enjoyed this article, you might also like:
- Reportable Situations (Part 1): ASIC’s Findings and Why They Matter
- Reportable Situations (Part 2): How to Meet (and Exceed) ASIC’s Expectations
- Is This a Reportable Situation? A Practical Decision Tree for Licensees
Frequently Asked Questions
A reportable situation is a breach (or likely breach) of a core obligation that meets significance thresholds under the Corporations Act and ASIC RG 78. This includes systemic issues, significant client detriment, or repeated breaches.
AFSL licensees must lodge a reportable situation with ASIC within 30 calendar days after they first know, or are reckless with respect to whether, there are reasonable grounds to believe a reportable situation has arisen.
Most issues arise from inconsistent significance assessments, fragmented systems, and lack of a structured decision framework—rather than misunderstanding the law itself.
ASIC expects evidence of a consistent, repeatable system that identifies, assesses, reports, and remediates incidents, supported by clear documentation and governance oversight.
Implement a centralised incident register, standardised assessment criteria aligned to RG 78, and workflows that link incidents to decisions, remediation, and reporting outcomes.