The Reportable Situations Framework: A Practical Approach to ASIC Breach Reporting

Maintaining compliance with ASIC’s reportable situations regime is not just about meeting a 30-day deadline. It requires a structured, repeatable process that ensures issues are identified early, assessed consistently and escalated appropriately.

Many Licensees struggle not with the law itself, but with operationalising it. The solution is to treat breach reporting as a defined lifecycle, not an isolated event. This framework applies to both AFSL and ACL Licensees.


The Reportable Situations Framework

A practical way for AFSL and Credit Licensees to approach ASIC breach reporting is through an eight-stage framework:

1. Identification

Incidents should be captured from multiple sources, including complaints, monitoring activities, adviser supervision and staff escalation. A centralised incident register with clear ownership is critical.

  • Incident captured through complaints, monitoring, audit or staff escalation
  • Incident recorded in central register with owner and date

How this is typically implemented in practice

Leading Licensees centralise incident capture to ensure all incidents, breaches, near misses and complaints are recorded, timestamped and assigned for action within a single workflow.

2. Investigation

Once identified, the issue must be properly understood. This involves gathering relevant facts, determining client impact and identifying whether the issue is systemic or isolated.

  • Relevant facts and documents gathered
  • Client impact assessed
  • Root cause identified (systemic or isolated). 

3. Significance Assessment

Not every incident is reportable. Licensees must assess whether a matter constitutes a “reportable situation” by considering factors such as breach significance, client detriment, frequency and control failures.

  • Breach (or likely breach) of a core obligation identified
  • Frequency or pattern of similar incidents considered
  • Client detriment assessed (financial or non-financial)
  • Control weaknesses identified

Where most licensees struggle

Significance assessments are often applied inconsistently across teams, particularly where judgment is required. Without a structured decision framework, similar issues can lead to different outcomes, creating regulatory risk.

4. Reporting Decision

A documented decision framework aligned to ASIC Regulatory Guide 78 helps ensure consistency. Borderline matters should be escalated, and all decisions should be clearly recorded.

  • Decision framework applied (aligned to RG 78)
  • Rationale documented clearly
  • Borderline matters escalated

5. Lodgement

Where required, reports must be lodged with ASIC within statutory timeframes (generally 30 calendar days). Submissions should be complete, accurate and supported by internal records.

  • Reportable situation confirmed
  • ASIC notification prepared and lodged within the required timeframe
  • Supporting documentation retained

6. Remediation

Affected clients must be identified and remediated promptly. This includes calculating loss, implementing corrective actions and tracking outcomes.

  • Affected clients identified
  • Loss or detriment calculated
  • Remediation completed and tracked

Operational reality

Without structured workflows, remediation tracking becomes fragmented and difficult to evidence. Linking incidents, actions and outcomes is critical to demonstrating a clear audit trail.

7. Governance and Oversight

Breach data should be reported to senior management and the board, with a focus on trends, recurring issues and systemic weaknesses.

  • Incident reported to senior management and/or board
  • Trends and recurring issues analysed

8. Continuous Improvement

Each incident should feed back into the compliance framework. Policies, controls and training should be updated to prevent recurrence and strengthen the control environment.

  • Policies and procedures were updated where required
  • Controls strengthened to prevent recurrence
  • Training updated based on incident learnings

Key question:

If ASIC reviewed this matter, could you clearly demonstrate how you identified, assessed and responded to it?

If the answer is no, your process needs strengthening


From framework to operating model

The difference between compliant and non-compliant licensees is not knowledge, but execution. Embedding this framework into day-to-day systems, workflows and reporting is what enables consistent, defensible outcomes.

Licensees who rely on manual processes often struggle to demonstrate consistent breach assessment and reporting. Implementing a structured framework, supported by a platform like complye, can significantly improve both compliance outcomes and auditability.

Maintaining consistent reportable situations assessments requires structured operational workflows, defensible investigation records and clear remediation governance.

Many licensees now use dedicated compliance infrastructure platforms such as [complyᵉ] to centralise incident management, document investigation decisions, maintain escalation records and track remediation activities through to resolution.


Moving forward

ASIC expects more than timely reporting. It expects evidence of a system that can identify, assess and respond to issues consistently.

If you are unsure whether your breach reporting process would withstand ASIC scrutiny, the issue is rarely the law itself. It is how the framework operates in practice.

Assured Support works with Licensees to design, implement and run breach reporting frameworks that are consistent, defensible and aligned to ASIC expectations. This includes embedding structured processes, oversight and, where appropriate, platforms like complye to ensure incidents are identified, assessed and reported correctly.

If you would like to discuss your current approach with one of our experts, click here.

If you enjoyed this article, you might also like:


Frequently Asked Questions

What is a reportable situation under ASIC rules?

A reportable situation is a breach (or likely breach) of a core obligation that meets significance thresholds under the Corporations Act and ASIC RG 78. This includes systemic issues, significant client detriment, or repeated breaches.

How long do AFSL licensees have to report breaches?

AFSL licensees must lodge a reportable situation with ASIC within 30 calendar days after they first know, or are reckless with respect to whether, there are reasonable grounds to believe a reportable situation has arisen.

Why do licensees struggle with breach reporting?

Most issues arise from inconsistent significance assessments, fragmented systems, and lack of a structured decision framework—rather than misunderstanding the law itself.

What does ASIC expect beyond timely reporting?

ASIC expects evidence of a consistent, repeatable system that identifies, assesses, reports, and remediates incidents, supported by clear documentation and governance oversight.

How can licensees improve audit readiness?

Implement a centralised incident register, standardised assessment criteria aligned to RG 78, and workflows that link incidents to decisions, remediation, and reporting outcomes.

Keep exploring

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?