“In every interaction that takes place in our professional and personal lives we have boundaries that we sort of trust the other person not to breach. ” — Jesse Armstrong, Anonymous
What’s happened?
ASIC’s breach reporting regime has continued to evolve since Regulatory Guide 78 (RG 78) was substantially updated in 2023. The framework is now more structured, more prescriptive and more nuanced than many licensees appreciate.
Since the original RG 78 update, ASIC has also issued ASIC Corporations and Credit (Breach Reporting—Reportable Situations) Instrument 2024/620, which modifies aspects of the deemed significance framework for both AFS and credit licensees.
For licensees, the challenge is no longer simply identifying breaches. It is understanding:
For licensees, the challenge is no longer simply identifying breaches. It is understanding:
- what constitutes a “reportable situation”
- when significance is deemed by operation of law
- when relief may apply
- and how ASIC expects incidents to be investigated, escalated and reported.
What is a “reportable situation”?
For AFS licensees, section 912D of the Corporations Act requires reporting where there is:
- a significant breach of a core obligation
- a likely significant breach of a core obligation
- an investigation that continues for more than 60 days into whether there is a significant breach
- the outcome of such an investigation where another reportable situation is identified
- serious fraud
- gross negligence
- certain other prescribed situations.
For credit licensees, equivalent obligations arise under section 50A of the National Consumer Credit Protection Act.
Importantly, not every breach is reportable. Whether reporting is required depends on the statutory framework, including:
- whether the obligation breached is a “core obligation”
- whether the breach is significant
- whether the breach is deemed significant
- and whether any statutory relief applies.
What is a “core obligation”?
For AFS licensees, “core obligations” include:
- obligations under section 912A
- obligations under Chapter 7 of the Corporations Act
- obligations under client money reporting rules
- certain obligations prescribed by regulation.
For credit licensees, core obligations are defined in section 50A(3) of the Credit Act and include:
- the general conduct obligations in section 47
- obligations under key provisions of the Credit Act and National Credit Code
- certain prescribed connected obligations.
Whether a matter is reportable depends first on whether the obligation breached is a “core obligation” for the purposes of the regime.
Significant breaches vs deemed significant breaches
One of the most misunderstood aspects of the regime is the distinction between:
- breaches that are significant under the ordinary significance test, and
- breaches that are deemed significant by operation of law.
Ordinary significance
Under section 912D(5), relevant factors include:
- the number or frequency of similar breaches
- the impact of the breach on the licensee’s ability to provide financial services
- whether the breach indicates inadequate compliance arrangements
- other prescribed matters.
These factors require judgment and contextual assessment.
Deemed significance
Other breaches are automatically taken to be significant under section 912D(4).
This includes:
- contraventions of certain civil penalty provisions
- breaches causing material loss or damage
- conduct prescribed by regulation.
Importantly, this means some breaches bypass the ordinary significance analysis entirely.
However, deemed significance is no longer absolute.
ASIC Instrument 2024/620: what changed?
ASIC Corporations and Credit (Breach Reporting—Reportable Situations) Instrument 2024/620 introduced several important modifications to the regime.
Among other things, the Instrument:
- extends the reportable investigation threshold from 30 days to 60 days
- modifies aspects of the deemed significance framework
- provides limited relief for certain low-impact contraventions
- clarifies interaction with APRA dual-reporting arrangements.
Most importantly, the Instrument inserts notional sections 912D(4A) and (4AA), which provide that some breaches otherwise deemed significant are not taken to be significant if strict statutory conditions are met.
For example, relief may apply where:
- no more than 10 clients are affected
- total financial loss or damage does not exceed $1,000
- the breach is rectified within the prescribed period
- there are no materially similar reportable situations within the relevant timeframe
- and all other statutory conditions are satisfied.
This does not create a broad discretion not to report. The relief provisions are narrow and highly conditional.
What does this mean in practice?
ASIC’s expectations remain clear:
- incidents should be identified early
- investigations should commence promptly
- root causes should be understood
- remediation should occur quickly
- and reportable situations should be lodged within the statutory timeframe.
The regulator continues to focus heavily on:
- delayed breach identification
- weak escalation frameworks
- poor root cause analysis
- inadequate remediation governance
- and inconsistent significance assessments.
The practical reality is that many substantive advice and conduct failures will still be reportable, particularly where:
- multiple clients are affected
- there is systemic misconduct
- client loss is material
- or compliance weaknesses are evident.
Final thoughts
The breach reporting regime is no longer a simple “breach/no breach” exercise. It is now a structured legal framework requiring:
- careful classification
- defensible significance analysis
- documented reasoning
- and strong incident governance.
Licensees should ensure their breach reporting frameworks are aligned not only with the Corporations Act and Credit Act, but also with:
- current RG 78 guidance
- ASIC Instrument 2024/620
- and evolving ASIC supervisory expectations.