What do Courts expect of Directors after ASIC v Bekier?

After ASIC v Bekier (Liability Judgment) [2026] FCA 196, directors should expect courts to examine whether they actively interrogated risk, challenged management assumptions, and ensured material issues were clearly escalated, properly understood, and subjected to meaningful oversight. The Federal Court reinforced that directors can’t passively rely on management, information overload, deficient reporting, or AI-generated summaries once warning signs emerge. Directors’ accountability remains personal because boards control the information they receive, the questions they ask, and the risks they prioritise. Although the proceeding arose from AML/CTF and casino suitability issues, the governance principles emerging from Bekier extend well beyond financial crime and apply broadly to organisations operating in regulated, high-risk, or reputationally sensitive environments.

What Bekier Means for Boards and Executives

The Federal Court’s decision in Australian Securities and Investments Commission v Bekier (Liability Judgment) [2026] FCA 196 is already emerging as one of the most significant recent Australian governance decisions.

Although the proceeding arose from AML/CTF failures, junket operations, China UnionPay arrangements, and concerns about the suitability of The Star Entertainment Group as a casino operator, the broader significance of the judgment lies elsewhere.

At its core, Bekier is a case about organisational governance.

It examines how information moves through large organisations, how risks are escalated, how boards oversee management, and where reliance on reporting systems becomes unreasonable.

The decision reinforces a principle Australian courts have repeatedly emphasised: directors are entitled to rely on management and formal reporting structures, but not passively.

Once risks become persistent, inadequately explained, commercially sensitive, or potentially material, directors are expected to engage actively, interrogate assumptions, and ensure escalation processes are functioning effectively.

That principle is not confined to casinos or financial crime.

It applies to any regulated or high-risk organisation where boards depend heavily on management reporting, control functions, and escalation systems to identify emerging risk.


What the Case Actually Decided

Justice Lee examined whether former directors and officers of The Star breached their statutory duty of care and diligence under section 180(1) of the Corporations Act 2001 (Cth) between November 2016 and March 2020.

ASIC alleged that The Star’s governance and oversight failures extended across its AML/CTF risk management systems, junket operations, China UnionPay arrangements, broader reputational and regulatory exposures, and its ongoing casino suitability obligations.

The Court found breaches against former CEO and Managing Director Matthias Bekier and former Chief Legal and Risk Officer Paula Martin. However, ASIC was unsuccessful in significant parts of its case against the non-executive directors.

Importantly, the judgment doesn’t reject reliance on management reporting systems. Nor does it impose an unrealistic expectation that directors personally investigate every operational issue inside a complex organisation.

Instead, the Court reinforced a more established governance principle: directors may rely on management only to the extent risks are being properly escalated, clearly explained, and meaningfully understood.

That distinction matters.

The issue is rarely whether some information technically existed somewhere within the organisation. The issue is whether material risks were effectively escalated and rigorously interrogated to support effective oversight.


Governance Failures Rarely Begin With a Single Decision

One of the more important aspects of the judgment is the Court’s focus on organisational failure over time.

Rather than searching for a single catastrophic decision, Justice Lee examined how information was identified, escalated, framed, understood, and acted upon across several years.

That reflects how most governance failures actually develop.

Large organisations rarely fail because of one isolated error. Failures more commonly emerge through cumulative weaknesses in:

  • reporting structures
  • escalation pathways
  • accountability mechanisms
  • challenge processes
  • prioritisation of risk information

The Court’s reasoning is important because governance failures are often less obvious in real time, than they appear with hindsight.

Information inside complex organisations is frequently fragmented, commercially contested, incomplete, or spread across multiple reporting channels. Courts recognise that reality.

The relevant question, therefore, is not whether directors possessed perfect information. The question is whether the available information, viewed objectively and in context, was serious enough to require further inquiry, clearer escalation, or closer oversight.

That is the broader governance significance of Bekier.

At its heart, this is a case about how governance operates inside large organisations.

It’s about how information moves through an organisation. It’s about escalation. It’s about accountability. It’s about whether boards and executives receive risk information in a form that allows them to properly understand and respond to emerging threats.

And importantly, it’s also about where reliance on management ends.


Directors Can’t Be Passive Consumers of Information

A central governance principle reinforced in the judgment is that boards control the quality of the information they receive.

In discussing board reporting and information flow, Justice Lee referred to the established principle from ASIC v Healey that “A board can control the information it receives.”

That observation carries practical significance well beyond litigation.

Boards are not passive recipients of management reporting. If information is unclear, excessively dense, fragmented, poorly prioritised, or incapable of supporting informed oversight, directors are expected to require better reporting.

This has become increasingly important as organisations produce larger board packs, more dashboards, and more layered committee reporting.

Overdisclosure and excessive reporting doesn’t necessarily improve governance.

In practice, information overload can make it harder to identify genuinely material risks because everything is presented as important.

Bekier reinforces that governance quality is not measured by the volume of reporting provided to directors. It’s measured by whether boards can identify material risks, understand their significance, and respond appropriately.

That transforms reporting design into both a governance issue and a legal risk issue.


Reliance on Management Has Limits

One of the more important governance principles reinforced in the judgment is that directors are not expected to personally investigate every operational issue inside a complex organisation.

Boards are entitled to rely on executives, legal teams, compliance functions, and risk frameworks. Complex organisations could not operate otherwise.

But that reliance is conditional.

Once risks become persistent, cumulative, inadequately explained, or commercially sensitive, directors are expected to ask questions, test assumptions, and ensure that escalation systems are functioning properly.

The Court’s reasoning is particularly significant for modern legal, risk, and compliance functions.

In many organisations, these functions no longer operate merely as technical advisers. They are increasingly treated as formal control functions with escalation responsibilities.

Where material risks are identified, courts expect clear escalation in a form that conveys seriousness to decision-makers.

Disclosure alone is not enough.

A buried email chain, an overloaded dashboard, an ambiguous committee paper, or a fragmented reporting pathway may not provide meaningful protection for management, officers, or directors if material risks are not properly understood.


AI Doesn’t Sideline Judgment

One of the more notable observations in the judgment concerned the use of AI in governance processes.

Justice Lee acknowledged that directors increasingly use artificial intelligence tools to navigate large volumes of board material:

“directors are now commonly making use of artificial intelligence to assist them in navigating material provided by management. … There isn’t anything inherently objectionable in obtaining such assistance, but … Proper collective governance requires transparency about how information is being reduced and relied upon …. The use of technology may assist comprehension, but it can’t displace judgment.” [1956]

The judgment does not suggest that directors or management should avoid using AI. However, it reinforces that accountability for governance decisions remains personal, including where AI tools are used to assist reporting, analysis, or decision-making processes.

AI-generated summaries, analytical tools, and reporting systems may assist comprehension and efficiency, but they cannot replace informed human judgment.

For organisations integrating generative AI into governance or compliance frameworks, this creates several practical implications:

  • transparency around how information is generated and summarised
  • validation and review processes for AI-generated content
  • clear accountability for decisions based on AI-assisted reporting
  • safeguards against loss of nuance, context, or escalation detail

The broader point is straightforward: technology may improve governance processes, but it doesn’t dilute directors’ duties.


Culture Still Matters

The judgment also highlights a more difficult governance issue.

In many organisations, material risks are not completely invisible. Instead, they become normalised, commercially tolerated, fragmented across reporting lines, or insufficiently challenged.

That’s why governance effectiveness can’t be measured solely by the existence of board packs, committee structures, escalation frameworks, dashboards, or formal policies. These mechanisms may support oversight, but they don’t guarantee that material risks will be recognised, challenged, or escalated effectively.

Good governance ultimately depends on organisational willingness to confront inconvenient risks before external intervention forces the issue.

This is particularly important where personal interests, corporate arrangements or commercially significant activities create pressure against escalation or challenge.

Strong governance, therefore, requires more than formal reporting structures. It requires a culture in which control functions can effectively escalate concerns and boards are willing to interrogate uncomfortable information.


Responsibility Depends on Role

Another important aspect of the judgment is the Court’s role-specific analysis.

Justice Lee did not apply a generic governance standard detached from organisational reality. Instead, the Court examined the responsibilities associated with each role.

For Mr Bekier, organisational oversight and board escalation responsibilities were central to the analysis, given his roles as CEO and Managing Director.

For Ms Martin, the analysis reflected her responsibilities as Company Secretary, General Counsel, and later Chief Legal and Risk Officer.

That aspect of the judgment is significant for modern governance structures.

As legal, compliance, and risk functions assume greater operational responsibility within organisations, expectations surrounding escalation and intervention become correspondingly higher.

Where material issues are identified or anticipated, courts expect effective escalation and meaningful advocacy from these legal, compliance, and risk functions.


Practical Lessons for Boards and Executives

Several practical lessons emerge from the decision.

1. Governance failures are usually cumulative

Organisations should avoid treating recurring compliance or operational issues as isolated incidents where patterns suggest systemic risk.

Repeated breaches appearing across multiple dashboards or committees may require aggregation and escalation at the board level.

2. Reporting quality matters more than reporting volume

Boards require clear, prioritised, and actionable reporting.

Larger board packs and more dashboards don’t necessarily improve oversight if material issues become obscured by volume.

3. Escalation frameworks should be tested regularly

Organisations should periodically assess whether escalation thresholds remain effective as reporting complexity increases.

This includes testing whether management, legal, compliance, and risk teams consistently escalate issues and in a form that conveys seriousness.

4. Documentation should assume later scrutiny

Board papers, committee minutes, escalation records, and reporting structures may later be examined closely during regulatory investigations or litigation.

Organisations should maintain clear, defensible records that demonstrate how risks were identified, escalated, and considered.

5. AI-assisted governance requires safeguards

Where organisations use AI tools in governance or reporting processes, they should maintain transparency, validation mechanisms, and clear accountability for outputs relied upon by decision-makers.


Beyond Bekier: the emerging expectation of AI governance

If ASIC v Bekier highlights the importance of information flows, oversight, and inquiry, subsequent commentary by Chief Justice Andrew Bell suggests these obligations may become even more significant as artificial intelligence becomes embedded in corporate decision-making.

In his 2026 Harold Ford Memorial Lecture, Bell CJ observed that boards now face two related governance challenges: governing the organisation’s use of AI and governing with AI. The first concerns how AI is deployed within the business. The second concerns how directors themselves use AI tools when preparing for meetings, reviewing information, and making decisions.

Importantly, Bell CJ cautioned that directors cannot treat AI as a substitute for independent judgment. Existing duties under the Corporations Act continue to require directors to understand the information on which decisions are based, apply an enquiring mind, and exercise their own judgment. The apparent confidence of AI-generated outputs does not relieve directors of those responsibilities.

At the same time, Bell CJ raised a more challenging question. As AI systems become increasingly capable of identifying risks, analysing large volumes of information, and supporting decision-making, future disputes may not focus solely on whether directors relied too heavily on AI. In some circumstances, courts may be asked whether directors failed to use available AI tools that could reasonably have improved oversight, risk management, or decision-making.

This does not mean directors are under a duty to use AI. However, it reinforces a broader principle evident in Bekier: directors are expected to take reasonable steps to place themselves in a position to guide and monitor the company. As governance practices evolve, what is considered “reasonable” may evolve as well.

The practical lesson is that boards should not wait for AI-specific regulation before addressing these issues. Directors should understand how AI is being used within their organisations, establish appropriate governance frameworks, and ensure any use of AI supports, rather than replaces, informed and independent decision-making.


Final Observation

The significance of ASIC v Bekier extends well beyond casinos, junkets, or AML/CTF regulation.

The case is ultimately about how governance operates inside large and complex organisations.

Its broader lesson is that the quality of governance is tested through escalation, challenge, oversight, and decision-making under pressure, not by the mere existence of formal policies, committees, or reporting frameworks.

For boards, executives, legal teams, compliance leaders, and risk professionals, the practical question arising from the judgment is straightforward:

If a significant compliance, operational, reputational, financial crime, or conduct risk emerged today, would it be clearly escalated, rigorously challenged, and properly documented to withstand later scrutiny?

That is the fundamental governance question that Bekier forces organisations to confront.

The decision may also prove to be an early indicator of a broader shift in governance expectations. As organisations become increasingly reliant on data, technology, and artificial intelligence, courts are unlikely to lower the standard expected of directors. Rather, the central principles evident in Bekier, active oversight, informed inquiry, independent judgment, and effective information flows, are likely to become more important, not less.

Whether the issue is financial crime, cybersecurity, operational resilience, conduct risk, or the use of AI itself, directors will continue to be expected to place themselves in a position to guide and monitor the organisation, ask probing questions, and ensure significant risks reach the board in a form that permits meaningful scrutiny.

Bekier, therefore, should not be viewed simply as a casino case. It is a reminder that governance failures often arise not because information was unavailable, but because organisations failed to ensure the right information reached the right people at the right time. In an increasingly complex and technology-enabled environment, that lesson is only likely to grow in significance.

If you enjoyed this, we recommend that you read:

What does a defensible compliance framework look like for AFSL and credit licensees?

The three lines of defence: compliance miracle or mirage?

AI in financial advice: efficiency gains, compliance risks and cognitive costs


Frequently Asked Questions

What is the central governance lesson from ASIC v Bekier?

Boards may rely on management and reporting systems initially, but directors must actively challenge and investigate risks once warning signs become persistent, material, or insufficiently explained.

How did section 180(1) of the Corporations Act apply in Bekier?

The Court examined whether directors and officers exercised reasonable care and diligence in overseeing organisational risks, escalation processes, and governance responses.

Why are escalation frameworks so important?

Poor escalation can prevent boards from recognising cumulative risks early enough. Courts increasingly examine whether organisations escalated issues clearly, consistently, and in a decision-useful form.

Does ASIC v Bekier change expectations around AI-assisted governance?

The judgment reinforces that AI tools may assist reporting and analysis, but directors remain personally responsible for exercising informed judgment and oversight.

What governance records are likely to receive scrutiny during investigations?

Board papers, committee minutes, escalation logs, breach registers, risk reports, and evidence showing challenge and oversight are all likely to be examined closely.

Keep exploring

What do Courts expect of Directors after ASIC v Bekier?

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?