She said, “You think the devil has horns? Well, so did I
Marino “Devil in Disguise” 2026
But I was wrong, his hair is combed, and he wears a suit and tie
He’s nice, polite, he’ll catch you by surprise
A smile so bright, you’d never bat an eye”
Most compliance failures do not begin with misconduct. They begin with misplaced confidence.
Confidence that the framework is sound because the documents are in order. Confidence that a favourable report equates to effective governance. Confidence that a signed review settles the question.
That confidence is often misplaced.
Assurance and the Question of Evidence
Recently, I spoke with a licensee representative about a proposed acquisition. The target had commissioned an external licensee review in anticipation of the transaction. The report was unequivocal. The compliance framework was described as robust, current and complete. There was a manual. There were policies addressing breach reporting, conflict management, AML and supervision. Registers were maintained. The reviewer confirmed that the framework existed and signed off on it.
When the prospective purchaser undertook its own due diligence, the reassurance evaporated.
What it encountered was not the absence of infrastructure, but its hollowness. The manuals were generic and largely unadapted to the business model. Policies referred to processes that had never been implemented in practice. The monitoring program existed on paper but had not shaped supervision in any meaningful way. The documents were present, but they did not influence behaviour. This pattern is not unusual in our sector. Courts and regulators have repeatedly observed the same disconnection between policy and practice.
The external reviewer in this case had confirmed the existence without interrogating the operation. As far as I am aware, no files were sampled. No governance decisions were traced. No attempt was made to test whether policies altered conduct in practice.
The proposed acquisition did not proceed, and the transaction ultimately exposed a misplaced confidence in audit reports.
How We Have Come to Define Assurance
This episode isn’t simply a cautionary or apocryphal tale warning you against using other compliance experts. Instead, I’m exposing a more pervasive weakness in the way parts of our profession understand assurance. We have become comfortable equating structure with substance and documentation with discipline.
The distinction matters because ASIC does not regulate artefacts. It regulates conduct. The obligation under section 912A to take reasonable steps is not satisfied by assembling a library of policies. It is satisfied by designing and operating systems that meaningfully reduce the risk of client harm. A manual can describe that ambition. It cannot deliver it.
Documentation endures because it is visible and manageable. It can be indexed, version-controlled and presented neatly to an external party. Operational effectiveness is less convenient. It is revealed through judgment, adaptation and accountability, often in moments of discomfort. A review that confines itself to confirming the existence of documents inevitably privileges what is easy to display over what is difficult to evidence.
The Subtle Consequence of Checklist Thinking
Checklists sit quietly at the centre of this dynamic. In complex regulatory environments, they offer structure and discipline, and for that reason, they are widely relied upon. Difficulty arises when the checklist becomes the objective rather than the instrument. Organisations learn quickly what is being measured. If the inquiry stops at whether a breach policy exists, the energy of the system is directed toward drafting one. If it does not extend to how breaches are identified, assessed and escalated, those capabilities receive less attention. Over time, the methodology shapes the behaviour it purports to test.
In the proposed acquisition, the vendor-initiated review focused on presence rather than performance. The purchaser, by contrast, examined whether the framework could withstand scrutiny when tested. That divergence in approach exposed a credibility gap that could not be repaired through clarification or reassurance. One party had sought confirmation. The other sought assurance.
What a Thorough Review Actually Examines
A well-conducted compliance review is not an inventory exercise. It is an examination of translation. Policy must translate into behaviour. Governance must translate into accountability. Monitoring must translate into improved advice outcomes. Where that translation cannot be evidenced, the framework is descriptive rather than operational.
This is the philosophy that shapes our own licensee reviews. We do not begin by asking whether documents exist. We begin by asking how decisions are made, how risks are identified in context and how supervision responds when weaknesses emerge. Documentation is reviewed, but it is tested against lived practice. Files are examined. Escalations are traced. Governance forums are observed for evidence of challenge. The objective is not to confirm presence, but to assess performance.
Governance, Risk and Supervision in Practice
When auditors examine governance, they do not limit themselves to organisational charts or ASIC registers. They examine the quality of oversight. They read minutes not for attendance but for challenge. They trace breach reporting decisions to understand how judgment was exercised and documented. They consider whether accountability is demonstrable in practice or merely implied by title.
Risk assessment is approached with similar scepticism. A mature framework reflects the actual nature, scale and complexity of the business. It captures the risks arising from product design, adviser capability, client demographics, and remuneration structures. A register that mirrors statutory headings but fails to articulate operational exposure signals compliance by template rather than compliance by understanding. Effective risk management is grounded in context.
Monitoring and supervision often reveal whether a framework is alive. The lessons from REP 515 remain instructive because they demonstrated how frequently audit processes failed to identify poor advice. Effective reviewers, therefore, look beyond the existence of a monitoring schedule. They examine how files are selected, whether higher-risk advisers receive enhanced scrutiny, and whether findings lead to structural adjustments rather than incremental amendments. Supervision that consistently produces minor administrative observations without identifying substantive risk suggests reassurance rather than detection.
Where Frameworks Reveal Their True Character
Incident and complaint handling provide further insight. Registers may be complete, and classifications technically accurate, yet still fail to influence behaviour. Reviewers compare complaint themes with monitoring outcomes and breach decisions to test for coherence. They examine whether recurring issues trigger examination of root causes or whether remediation is confined to additional training that leaves underlying incentives intact. A framework that records incidents but does not learn from them is static.
Underlying each of these domains is culture. Culture is not articulated in policy documents, yet it determines how those documents are applied when commercial pressure intensifies. Auditors infer cultural maturity by observing whether compliance staff can challenge senior advisers without consequence, whether dissent is documented rather than diluted, and whether leadership interrogates patterns rather than accepting convenient explanations. A framework may appear complete while a culture of avoidance renders it ineffective.
Firms that are surprised by adverse findings have often prepared for a different examination. They have ensured that documents are up to date, registers are populated, and policies are cross-referenced. They have not asked whether those artefacts shape behaviour in moments of tension. The difference between those exercises is subtle but decisive.
The proposed acquisition did not proceed because the purchaser lost confidence in the target’s governance credibility. If effectiveness has not been tested, assurance becomes assertion. If the framework is generic, engagement with risk is questionable. Trust deteriorates when scrutiny reveals superficiality.
Rebuilding Substance Before Scrutiny Arrives
If compliance hollowness is the risk, then methodology must change. Review programs need to shift from artefact audits to behavioural testing. Rather than beginning with document inventories, reviewers should begin with decision tracing. How was a recent breach classified? Why was a matter deemed not reportable? What risk signals were considered and which were dismissed? When reviews start with lived decisions and work backward to policy, the quality of translation becomes visible.
Incentives also require recalibration. External assurance has too often derived its reputational value from comfort rather than candour. When reviewers are implicitly rewarded for confirming robustness rather than detecting weakness, the system drifts toward affirmation. Mature organisations structure reviews so that credibility attaches to diagnostic truth. A review that surfaces difficult findings should enhance confidence, not diminish it.
Periodic adversarial testing is equally important. Escalation pathways and governance resilience should be stress-tested through deliberate challenges. Hypothetical but plausible scenarios can reveal whether cultural pressure suppresses dissent or whether systems respond proportionately. Such exercises expose fragility before it becomes public.
Boards also carry responsibility. Governance literacy must extend beyond reading minutes to interrogating them. Directors should be equipped to examine breach decisions, monitoring trends and complaint data for evidence of judgment quality rather than procedural completion. The tone set at the board level shapes the extent to which management engages with risk.
Finally, feedback loops must be embedded rather than assumed. Complaints, monitoring outcomes, and remuneration structures should be examined together through root-cause analysis. When systemic drivers are identified and addressed, compliance becomes dynamic. Without that integration, the same issues reappear under different headings.
Preparing for Scrutiny
Preparation for external scrutiny requires a deliberate shift in perspective. Leadership must look beyond the completion of artefacts and consider whether systems respond proportionately to emerging risk, whether higher-risk files withstand independent review, and whether governance forums evidence genuine debate. Escalation pathways should be tested rather than assumed. This work is rarely dramatic. It is disciplined, and it rests on intellectual honesty and a willingness to invite scrutiny before it is imposed.
The Difference Between Assurance and Illusion
There is nothing inherently wrong with maintaining comprehensive compliance documentation. It is an essential component of any well-governed licensee. The difficulty arises when documentation is treated as evidence of effectiveness rather than as a description of intent.
External auditors, regulators and increasingly sophisticated counterparties are not persuaded by the existence of policies alone. They are assessing whether governance arrangements withstand scrutiny without qualification or excuse, whether reasonable steps are demonstrable rather than asserted, and whether accountability is visible in decision-making.
Compliance is not about assembling a framework that appears complete. It is about building one that functions under pressure. That distinction is neither rhetorical nor cosmetic. It is the difference between assurance and illusion.
When the test eventually comes, as it invariably does, only one of those approaches survives.
If you are uncertain which category your arrangements fall into, that uncertainty is itself a signal. An independent review that traces decisions, tests supervision and examines governance culture will provide clarity long before a regulator, counterparty, or purchaser does.
At Assured Support, our licensee reviews are designed for that purpose. We test how your framework operates, not how it reads. If you would value an informed, candid assessment of your compliance arrangements, we’d welcome the conversation.
If you enjoyed this article, you might also like:
- How Accountability Obligations Are Shifting Toward Individual Advisers and Principals
- How does ASIC’s Interprac case show that manual compliance is broken?
- Systemic and Recurring Failures in Scaled Advice Businesses
Frequently Asked Questions
ASIC assesses whether an AFSL holder meets obligations under s912A of the Corporations Act, including providing services efficiently, honestly and fairly. This involves examining governance decisions, breach handling, supervision quality and whether monitoring systems operate effectively — not just whether policies exist.
Checklists confirm document presence but rarely test behavioural effectiveness. ASIC and courts focus on whether systems operate in practice, reduce risk and influence decision-making. A complete manual does not prove operational discipline.
REP 515 found that many licensees’ file review programs failed to detect poor advice. Monitoring existed formally but lacked risk-based selection and meaningful escalation, highlighting the gap between documentation and performance.
A robust review traces breach decisions, samples advice files, tests supervision quality, examines governance challenge in board minutes, and assesses whether monitoring outcomes drive systemic improvement.
Boards should interrogate breach decisions, monitor complaint trends, and examine whether governance discussions evidence challenge. Directors must assess judgment quality, not procedural completion.