1. What are the key compliance obligations for Australian financial advice providers?
Under section 912A(1) of the Corporations Act 2001 (Cth), Australian Financial Services Licensees (AFSLs) must:
- Act efficiently, honestly and fairly in providing financial services.
- Maintain adequate arrangements for managing conflicts of interest.
- Ensure representatives are competent and adequately trained.
- Have adequate risk management systems.
- Comply with financial services laws and ensure representatives do the same.
These obligations are complemented by the 12 ethical standards set out in the Financial Planners and Advisers Code of Ethics 2019, which impose duties to act with integrity, fairness, competence, and diligence.
ASIC elaborates on these duties in Regulatory Guide 104: Licensing – Meeting the general obligations, which outlines ASIC’s expectations for governance, compliance monitoring, and internal dispute resolution (IDR).
2. What are the steps to obtain an AFSL for providing financial advice, and what documentation is required?
Applying for an AFSL involves demonstrating to ASIC that the applicant can meet the general obligations of licensees under section 912A. The process includes:
- Determining authorisations required (e.g., personal advice, dealing, or custodial services).
- Preparing core documents, including:
- Business description and financial statements;
- Compliance and risk management framework;
- Responsible Manager (RM) qualifications and experience;
- Proof of adequate financial resources (RG 166);
- Dispute resolution arrangements (RG 271).
- Lodging the application via ASIC’s AFS Licensing Portal.
ASIC’s Regulatory Guide 1: AFS Licensing Kit provides detailed procedural guidance. Most firms also engage compliance specialists (such as Assured Support) to prepare documentation consistent with ASIC’s licensing expectations.
Consider Is self-licensing a reasonable option for me? and Thinking about self-licensing?.
Assess your readiness for self-licensing using this tool.
3. What recent ASIC enforcement actions in financial advice should compliance teams learn from?
Beyond ‘fees for no service’, Beyond ‘fees for no service’, ASIC’s recent actions emphasise cyber security and resilience, outsourcing governance, SMSF advice quality, and APL/research independence. Key matters and lessons include:
- Cyber Security & Cyber Resilience – RI Advice and Beyond. The Federal Court in ASIC v RI Advice confirmed inadequate cyber risk management breaches s912A(1)(a) and 912A(1)(h). ASIC summarises the implications for AFS licensees and boards in its cyber pages (see Court finds RI Advice failed to adequately manage cybersecurity risks, the judgment orders and What a Federal Court ruling on cybersecurity means for AFS licensees). ASIC has since pursued further cyber matters (e.g., 2025 cyber enforcement action) and reinforces good practice via its Cyber Resilience Hub. Lesson: Treat cyber as a standing operational risk program with board reporting, control testing, incident playbooks and third-party/vendor controls mapped to s912A obligations.
- Outsourcing and offshoring – governance gaps. ASIC’s 2025 review warns of offshore outsourcing risks (supervision, data security, continuity) and points licensees back to RG 104, RG 259 and related guidance (ASIC flags risks in offshore outsourcing). Lesson: maintain a documented outsourcing framework—due diligence, contractual controls (service levels, audit/attestation rights), performance/KRI dashboards, resilience testing, and exit/transition plans. Note RG 104 expectations and, where appropriate, supplement your arrangements with risk-systems guidance in RG 259 (for REs).
- Research & APL management (post‑Dixon, and in light of Shield). ASIC expects a reasonable investigation (s961B) that is not constrained by an APL where client needs require broader consideration (see Acting in the client’s best interests and RG 175). Conflicts governance is being updated (CP 385 – proposed updates to RG 181); research controls continue to be framed by RG 79 and RG 264. Lesson: uplift APL governance (entry/exit criteria, liquidity/complexity screens, independent research, conflicts registers), and document where advice considers products outside the APL to meet client needs.
- SMSF advice quality – Dixon and SMSF guidance. The Court imposed a $7.2m penalty on Dixon Advisory for best-interest and appropriate-advice failures (22-256MR). ASIC’s SMSF advice expectations are captured in INFO 274 Tips for giving SMSF advice. Lesson: evidence cost‑benefit analysis, client capability and risks (liquidity, diversification, leverage, trustee obligations), and avoid conflicted, vertically‑integrated flows. Apply INFO 274 and its case-study attachment; note ASIC’s 8 Dec 2022 update.
- Shield Master Fund – platform/trustee and adviser oversight. ASIC halted offers (24‑018MR), obtained asset‑preservation orders (24‑129MR) and continued investor updates (24‑265MR). In 2025, ASIC announced Macquarie admissions and remediation for affected members (25‑215MR) and commenced proceedings against Equity Trustees over due diligence failings (25‑176MR). Lesson: strengthen platform due diligence, trustee/adviser supervision, and product research—especially for illiquid, complex or property-linked funds.
For practical lessons across these themes, start with RG 104, ASIC’s Cyber resilience materials, RG 175, RG 79 and Assured Support’s guidance on cyber governance for AFSLs.
4. How can advice firms implement effective AML/CTF procedures relevant to their advice business?
Financial advisers are reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). They must develop and maintain an AML/CTF program that includes:
- Customer identification and verification (KYC) processes;
- Ongoing customer due diligence;
- Suspicious matter and threshold transaction reporting to AUSTRAC;
- Staff training and periodic independent review.
AUSTRAC’s AML/CTF Programs and Compliance Guidance provides detailed implementation advice. For advice firms, this often involves embedding AML checks into onboarding workflows and file reviews.
5. What should a compliance checklist for ongoing advice reporting and disclosure duties include?
An effective compliance checklist for advice businesses should align with Part 7.7A of the Corporations Act 2001 and ASIC’s Regulatory Guide 175: Licensing – Financial product advisers: Conduct and disclosure. It should include:
- Best interests duty (s961B) and appropriate advice (s961G);
- Ongoing fee arrangements and consents (INFO 256);
- Record-keeping obligations (notional s912G (ASIC Instrument 2024/508 extends CO 14/923) and Code of Ethics Standard 8);
- Client file review cycles (minimum annual for high-risk clients);
- Training and CPD tracking;
- Reportable situations regime. Notify ASIC within 30 calendar days of determining a reportable situation (see RG 78 and Div 3 of Pt 7.6));
- Internal dispute resolution (IDR) tracking (RG 271);
- Complaints and remediation logs.
6. How do I appoint and document Responsible Managers for an advice-focused AFSL?
Responsible Managers (RMs) are individuals demonstrating the licensee’s organisational competence under s912A(1)(e). ASIC’s Regulatory Guide 105: Licensing – Organisational competence outlines five acceptable RM options based on qualifications and experience. RMs must be actively involved in the day-to-day management of the financial services business, understand their duties and obligations under the Corporations Act, and contribute meaningfully to compliance oversight and decision-making. Licensees should periodically review the ongoing appropriateness of each RM—particularly where the nature, scale or complexity of the business changes—to ensure the competence framework remains adequate and aligned with ASIC’s expectations.
To appoint Responsible Managers:
- Ensure each RM’s qualifications and experience align with authorised advice activities;
- Maintain position descriptions, fit and proper assessments, and succession plans;
- Document oversight mechanisms (e.g., compliance committee participation, supervision logs);
- Update ASIC if RMs change or responsibilities are restructured.
7. What minimum financial resources does ASIC expect of advice licensees?
Under Regulatory Guide 166: Licensing – Financial requirements, advice licensees must maintain sufficient financial resources to meet obligations and ensure the orderly wind-down of business. ASIC generally expects:
- Positive net assets and solvency;
- Cash buffer to meet short-term commitments;
- Contingency plans for liquidity events;
- Documentation supporting financial viability assessments (often included in annual compliance attestations).
Many advice businesses rely on Option 1 under RG 166, which requires maintaining ongoing access to liquid capital equal to or exceeding 20% of projected three-month expenses. This liquidity buffer helps ensure that the business can continue meeting operational commitments even under stressed conditions and is a practical indicator of solvency and prudence.
ASIC may impose additional financial conditions (e.g., external audit requirements) for higher-risk advice models or licensees with custodial functions.
8. How can I draft a risk management framework tailored for advice services under an AFSL?
A robust risk management framework (RMF) is required under s912A(1)(h). ASIC’s Regulatory Guide 259: Risk management systems of responsible entities and RG 104 provide practical guidance.
An advice-focused RMF should include:
- Risk appetite statement aligned with board and RM oversight.
- Registers for compliance, operational, and conduct risks;
- Controls and monitoring procedures (including advice file reviews);
- Incident escalation and breach reporting protocols;
- Annual independent reviews and board reporting cycles.
Advice firms should focus on identifying and managing real risks to their business rather than relying on superficial or purely aesthetic metrics. They recommend using meaningful lead indicators—such as control breaches, adviser workloads, system alerts and complaint trends—rather than lag indicators (like heat maps) that can distort or understate exposure. This proactive, evidence-based approach to risk management is consistent with their published articles and FAQs on Assured Support. For further reading on the limitations of lag indicators and the misuse of heat maps, read True Colours – Rethinking Heat Maps, which explains why compliance leaders should prioritise predictive metrics and qualitative insight over visualised but potentially misleading data.
9. What are common ASIC licence conditions for financial advice firms, and how can they comply?
Typical licence conditions include:
- Maintaining adequate competence and resources (s912A);
- Annual compliance attestation signed by RMs or directors;
- Key Person requirements, ensuring that nominated key individuals remain actively engaged and that ASIC is notified of changes impacting continuity of control or management;
- Minimum capital requirements, maintaining solvency and liquidity levels consistent with ASIC’s Regulatory Guide 166;
- Notification obligations (changes to control, RMs, or authorised representatives);
- Record-keeping (minimum seven years);
- Breach reporting within 30 days of discovery (s912D).
ASIC’s Regulatory Guide 104 provides detailed expectations. Regular internal audits, file testing, and training help ensure compliance.
10. What is the latest ASIC guidance on adviser training and competency standards?
ASIC’s adviser competency standards are detailed in Regulatory Guide 146: Licensing – Training of financial product advisers, supplemented by FASEA’s education framework and Continuing Professional Development Standard 2018. Advisers must:
- Meet minimum degree qualifications and professional year requirements;
- Adhere to the Financial Planners and Advisers Code of Ethics (Standards 10 and 12), requiring ongoing competence and ethical cooperation;
- Maintain annual CPD plans and logs, with evidence of structured learning.
ASIC continues to emphasise that training should be linked to demonstrable competence in advice processes, not merely CPD hours.
11. How can I create an annual compliance certificate checklist for a financial advice business?
An annual compliance certificate is a concise but comprehensive summary that demonstrates the AFSL holder’s ongoing adherence to licence obligations under s912A and ASIC’s Regulatory Guide 104. A well-designed checklist should include:
- Confirmation of solvency, capital adequacy, and financial viability (RG 166);
- Review of Responsible Managers’ competence and engagement (RG 105);
- Annual risk management framework review and cyber resilience testing;
- Conflicts of interest register updates (RG 181);
- Adviser registration, training, and CPD compliance (RG 146, FASEA Standards 10–12);
- AML/CTF compliance and reporting (AUSTRAC);
- Breach reporting log and remedial actions (RG 78);
- Summary of internal audit findings and governance attestations.
Many licensees use this certification as both an internal assurance tool and evidence for ASIC’s targeted surveillance reviews.
12. What are ASIC’s key reporting deadlines affecting advice licensees?
Advice licensees must manage a complex array of reporting obligations. The key deadlines include:
- Breach reporting: Within 30 calendar days of determining a reportable situation (s912D; RG 78);
- Financial statements and auditor’s report: Lodged annually within 3–4 months of the financial year-end (RG 166);
- Updated register of financial advisers: Ongoing obligations to maintain details on ASIC’s Financial Adviser Register;
- Dispute resolution data: Six-monthly reporting to ASIC (periods Jan–Jun; Jul–Dec) with submission windows in Jan–Feb and Jul–Aug underRG 271;
- AUSTRAC reporting: Threshold, suspicious matter, and annual compliance reports.
Failure to meet these deadlines can lead to civil penalties or licence variations. Many firms use compliance calendars or governance dashboards to track recurring obligations. licence variations. Many firms use compliance calendars or governance dashboards to track recurring obligations.
13. How should firms document adequate resources and competence to deliver compliant financial advice?
ASIC expects licensees to have and demonstrate adequate human, technological, and financial resources to deliver compliant advice. Under RG 104 and s912A(1)(d)–(f), firms should document:
- Staffing levels, qualifications, and professional designations;
- Adviser-to-client ratios and supervision structures;
- Core system capabilities (CRM, advice generation, cyber security controls);
- Training and professional development programs;
- Business continuity and succession planning;
- Oversight by Responsible Managers and compliance committees.
Licensees should also prepare an annual resource sufficiency assessment—a self-review showing that current capacity aligns with business growth, complexity, and emerging risks. For practical governance principles and examples of how licensees can structure oversight, risk management, and resource planning, see Governance Essentials for AFS Licensees – A Practical Guide, which outlines key governance controls, reporting structures, and decision-making responsibilities for maintaining an effective AFSL framework.
14. What should a sample dispute resolution policy for financial advice licensees include?
Under s912A(1)(g) and ASIC’s RG 271: Internal Dispute Resolution, AFSL holders must maintain an IDR system that is free, fair, and timely. A compliant policy should include:
- Precise definitions of complaints and complainants;
- Timeframes for acknowledgement (within 24 hours) and resolution (within 30 days);
- Procedures for escalation, documentation, and analysis of recurring issues;
- Obligations to refer unresolved complaints to AFCA;
- Root-cause analysis and remedial processes to prevent recurrence.
Best practice is to integrate complaint analytics into compliance reporting, identifying early warning indicators for systemic issues. For additional practical insights on complaint handling, escalation and reporting, see Assured Support’s Complaints FAQ, which guides establishing effective complaint management processes and meeting ASIC’s RG 271 expectations.
15. What triggers ASIC audits or enforcement actions for advice non-compliance?
ASIC commonly initiates surveillance, audits, or enforcement actions in response to:
- High complaint volumes or AFCA determinations against the firm;
- Breach reports indicating poor remediation or recurring control failures;
- Evidence of systemic fee-for-no-service or conflicted advice practices;
- Misleading disclosure or non-compliance with consent and FDS obligations;
- Cyber incidents or outsourcing failures exposing client data;
- Whistleblower reports or media coverage suggesting misconduct.
ASIC prioritises firms that demonstrate a weak culture, poor remediation history, or inadequate governance. Proactive monitoring and transparent reporting to ASIC can significantly reduce enforcement risks. For context, our Reportable Situations Part 1 – ASIC’s Findings and Why They Matter summarises ASIC’s key observations about reportable situation data, common failings, and practical steps licensees can take to strengthen breach identification, escalation, and reporting frameworks.
16. What are the key ASIC guidance updates for financial advice compliance in 2025?
Key updates in 2025 include:
- Cyber resilience and AI/technology governance: Updated ASIC expectations following RI Advice, FIIG action and Fortnum Wealth, highlighting board-level accountability.
- Outsourcing and offshoring oversight: New ASIC focus on due diligence and resilience testing for overseas service providers.
- Conflicts management review: Consultation Paper 385 proposes revised RG 181: Licensing – Managing conflicts of interest.
- Adviser registration reforms: Enhanced obligations under the Financial Sector Reform (Hayne Royal Commission Response) Act.
- Professional standards: Transition of the Financial Adviser Code of Ethics to the Treasury portfolio, maintaining core obligations under s921E.
- ASIC enforcement trends: Continuing focus on culture, governance, and cyber resilience, with thematic enforcement across advice quality, conflicted remuneration, and record keeping. For insights and practical preparation tips, see Assured Support’s ASIC Enforcement Trends – What You Need to Know for 2025, which summarises ASIC’s priorities, recent cases, and what licensees should expect during surveillance and enforcement activity.
17. What are the differences between personal advice and general advice obligations under the Corporations Act?
Under s766B(3) of the Corporations Act, personal advice is given where the adviser has considered one or more of the client’s objectives, financial situation, or needs, or where a reasonable person might expect those matters to be considered. General advice, by contrast, does not consider any of these individual circumstances.
Key differences include:
| Obligation | Personal Advice | General Advice |
| Best Interests Duty (s961B) | Yes | No |
| Appropriate Advice (s961G) | Yes | No |
| Statement of Advice (SOA) | Required for retail clients | Not required |
| Conflicted Remuneration Prohibitions | Apply | Apply |
| Disclosure Requirements | Detailed, tailored | General disclaimers |
Advisers must ensure all communications accurately reflect whether advice is personal or general. ASIC has prosecuted cases where “general” advice presentations contained implicit personal recommendations. For a deeper exploration of general advice concepts, practical examples, and the associated compliance risks, see Assured Support’s General Advice article, which outlines how to communicate within the general advice framework while avoiding inadvertent personal advice.
18. How should licensees document adviser training and continuing professional development (CPD)?
Under the Continuing Professional Development Standard 2018 and ASIC’s RG 146, each adviser must maintain a structured CPD plan. Licensees should document:
- Annual CPD plans with measurable learning objectives;
- Evidence of training provider quality and course content;
- Training logs capturing completion dates and hours;
- Verification of technical, regulatory, and ethical competencies;
- Internal reviews confirming that training aligns with the adviser’s authorisations and business strategy.
ASIC encourages firms to integrate CPD tracking within HR or CRM systems for audit readiness and professional development oversight.
19. What should be included in a compliance checklist for financial advice obligations under an AFSL?
A comprehensive AFSL compliance checklist should encompass:
- Governance and ethics: FASEA Code of Ethics, conflict management, cultural indicators;
- Advice quality: File reviews, SOA/ROA testing, APL governance, research independence;
- Financial controls: Capital adequacy, liquidity management, and contingency funding;
- Operational resilience: Cyber security, business continuity, outsourcing risk oversight;
- Reporting and disclosure: FDS, consent renewals, breach reporting;
- People and capability: Fit and proper assessments, RM reviews, CPD logs;
- Client experience: Complaints management, client surveys, and remediation tracking.
Firms should revisit this checklist quarterly to reflect regulatory developments and ASIC’s evolving enforcement focus. This question can also be interpreted as asking what obligations should be addressed in an advice review checklist, which evaluates the quality, suitability, and compliance of client advice files. A high-level checklist should cover:
- FSG provision – verifying that clients have received a current Financial Services Guide;
- Data gathering and fact finding – ensuring information is sufficient, current, and relevant to client objectives;
- Research and analysis – documenting comparisons, product investigations, and due diligence, particularly around APL and product selection;
- TMD consideration – confirming the adviser considered the Target Market Determination for recommended products under RG 274 and Pt 7.8A obligations;
- SoA/ROA production – checking clarity, disclosure accuracy, and consistency with the best interests duty;
- Compliance with the Code of Ethics – particularly Standards 2 (best interests), 5 (appropriateness), 6 (long-term interests), and 7 (fair remuneration);
- Record keeping and disclosure – ensuring all communications, consents, and FDS requirements are documented. For further guidance, refer to A Practical Guide to High-Level File Reviews for Licensees and Advisers.
20. What are the steps to prepare for an ASIC compliance audit focused on financial advice?
Preparation for an ASIC audit requires proactive governance and robust documentation. Key steps include:
- Pre-audit readiness review – Assess compliance with s912A obligations and ASIC guidance (RG 104, RG 105, RG 166).
- Update risk registers and control evidence – Ensure risk assessments include cyber, outsourcing, APL, and SMSF advice risks.
- Maintain complete client files – Verify that all SOAs, FDSs, and consent renewals are accurate and accessible.
- Conduct internal file audits – Benchmark advice quality against FASEA ethical standards and best interest duty.
- Brief Responsible Managers and key staff – Ensure they understand their duties and can explain compliance systems.
- Rectify known issues early – Document remediation plans and progress.
- Engage with ASIC cooperatively – Transparency and prompt response can mitigate enforcement outcomes.
Effective preparation turns an ASIC audit into an opportunity to demonstrate professionalism and governance maturity rather than a source of regulatory risk. For practical strategies on managing ASIC notices, responses and engagement, refer to Assured Support’s How to Respond to an ASIC Notice – A Practical Step-by-Step Guide for Licensees and Preparing for a Compliance Review both of which outline structured preparation, communication and evidence management to help licensees respond confidently and efficiently.