When Good Advice Cannot Be Proven: System Failures During a Regulatory Review

When people think of system failures, they usually imagine servers crashing, software outages or cyberattacks preventing access to client files.  In regulatory reviews, however, the most serious failures often occur while every system appears to be working perfectly. 

The software works. The documents exist. The client received the advice. At least that’s what everyone believes until someone actually asks to see the file.

Most advisers reading this article will recognise the situation immediately: “I know the document exists… I just need five minutes to find it.” 

In our experience reviewing over 24,000 advice files, we regularly encounter advisers who believe they have everything required to support their recommendations. However, as the review progresses, it becomes apparent that key information has been captured across multiple systems, retained outside the primary advice record, or relies on electronic evidence that cannot be substantiated.

The issue is rarely that the work wasn’t completed. The issue is that the work cannot be demonstrated. For advisers and licensees, this distinction is important.

A regulatory review does not simply assess whether appropriate advice was provided. It assesses whether the advice can be substantiated through complete, reliable and contemporaneous records.

Where the evidence cannot be produced, the advice itself becomes increasingly difficult to defend.


The Real Problem: A Compliance System is Only as Good as the Evidence It Produces

Advice practices continue to invest heavily in technology. Client relationship management systems, document management platforms, workflow software and automated compliance tools have significantly improved efficiency and strengthened compliance processes. However, technology should support compliance rather than become a substitute for it.

One of the most common assumptions we encounter during file reviews is that because something has been recorded by the system, it can therefore be demonstrated. Unfortunately, this is not always the case.

A system may record that an adviser completed a task, issued a disclosure document or held a client meeting. It may even record the date and time that an activity occurred.

What it may not demonstrate is:

  • what information was actually provided to the client;
  • which version of the document was issued;
  • how the recommendation was explained;
  • what alternatives were considered; or
  • whether the client genuinely understood the advice.

A regulatory review generally requires more than confirmation that an event occurred: it requires evidence that supports what actually happened.

Technology is an excellent servant but a terrible witness.


Client Records Across Multiple Systems

Many practices use a client relationship management system as the central repository for client records. Ideally, it should represent a single source of truth for the advice process.

In some practices, however, the primary advice system contains only part of the picture, while the remainder of the information is spread across shared drives, email folders, local desktops and external hard drives. There may also be an exchange of information over text or other social media accounts.

At first glance, the client file appears complete. Statements of Advice, Fact Finds and Authorities to Proceed have all been uploaded. The adviser is confident the review will proceed smoothly.

However, as the reviewer begins examining the file, a different picture emerges. The supporting research referred to in the advice cannot be located in the client file. File notes documenting important discussions with the client have been saved to a shared network drive rather than uploaded to the CRM system. Alternative strategy analysis exists, but only within an adviser-specific folder. Email correspondence explaining key decisions remains in Outlook. Insurance calculations have been retained locally. Product comparisons are stored somewhere on the shared drive.

When questions are raised, the adviser is usually able to locate most of the documents.

The difficulty is that they are produced progressively throughout the review rather than forming part of a complete and contemporaneous advice record.

On paper, every document exists. In practice, finding them can feel less like reviewing an advice file and more like participating in a corporate treasure hunt. The advice itself may have been entirely appropriate, but the evidence supporting it is fragmented.

One reviewer summed it up perfectly:

“The advice isn’t missing. It’s just hiding in Outlook.”

From a regulatory perspective, this creates unnecessary risk. A reviewer should not need to search multiple systems, folders or email accounts to piece together the advice process. The client file should present a complete record of the advice provided and the basis on which recommendations were made.


System-Generated Compliance Records

Another issue commonly encountered is reliance on system-generated compliance records. Many advice businesses use software that automatically records when a Financial Services Guide (FSG), Product Disclosure Statement (PDS) or other regulatory document has been provided to a client. These records are valuable; however, during a review, the system record alone may not always answer the questions being asked.

Can the actual FSG be produced?

Can the PDS still be located?

Can the actual version relied upon be reproduced, or does the system simply record that “a” PDS was issued?

Can the system demonstrate that the client received the documents before implementing the recommendation?

These questions become particularly relevant when disclosure documents have subsequently been updated or replaced (which is very likely to happen over the seven years during which records are kept). Several years after advice has been provided, the system may continue to show that an FSG or PDS was issued. However, if the underlying document has not been retained, it may be impossible to establish exactly what information the client received.

The distinction is subtle but important.

A system record demonstrates that an activity occurred. It may not show the substance underlying that activity. Or, to put it another way, the system may confidently tell you that an FSG was issued. When asked which FSG, however, the silence can be deafening.

Technology can assist in evidencing compliance, but it should not be the only evidence available.


Electronic References and Broken Hyperlinks

Electronic disclosure has become increasingly common throughout the advice industry. Statements of Advice and research papers frequently include hyperlinks directing clients to Product Disclosure Statements, Target Market Determinations and other disclosure material published online.

There are clear benefits to this approach

  • Documents remain shorter;
  • Clients are directed to the latest information; and
  • Advisers avoid reproducing lengthy disclosure material.

However, hyperlinks create an often-overlooked compliance risk.

Websites and URLs change.

Providers redesign webpages.

Documents are archived, replaced or relocated.

Anyone who has ever clicked a five-year-old hyperlink already knows how this story ends.

404 – Page Not Found.

During a regulatory review, broken hyperlinks can make it difficult to establish exactly what disclosure material was available to the client when the recommendation was made. Even where the webpage remains accessible, it may display a newer version of the document than the one relied upon at the time.

The advice may still be appropriate; the evidence supporting it has simply deteriorated over time.


Version Control and Document Integrity

Advice documents naturally evolve throughout the advice process.

Statements of Advice are amended following peer review. File notes are updated. Research papers change. Recommendations are refined.

The challenge arises when there is uncertainty about which version forms part of the official advice record.

Reviewers occasionally encounter:

  • Final SoA.docx
  • Final SoA v2.docx
  • Final SoA FINAL.docx
  • Final SoA FINAL FINAL.docx

…and everyone’s personal favourite:

Final SoA FINAL FINAL Use This One.docx

While amusing, poor version control creates genuine regulatory risk. Reviewers need confidence that the document on file is the document presented to the client.

Good document management is not simply about retaining information. It is about preserving confidence in that information.


Business Continuity and Record Retention

Technology will continue to evolve. Software will change. Staff will leave. Shared drives will be restructured. Emails will be archived.

Businesses often discover just how much knowledge sat with one adviser immediately after that adviser leaves. It usually starts with someone asking:

“Does anyone know where Chris saved his file notes?”

Business continuity is not simply about recovering from disasters. It is about ensuring that complete advice records remain accessible years after the advice was provided.

A robust record retention framework should not rely on individual advisers remembering where documents have been stored. It should rely on documented processes that allow anyone within the business to locate the evidence required to support the advice.


What ASIC, AFCA or an External Reviewer Would Likely Examine

Reviewers are generally not looking for perfection, nor are they trying to increase their email count by requesting additional information. They simply need sufficient evidence to understand what occurred.

Questions commonly include:

  • Can the advice process be understood from the file alone?
  • Can supporting evidence be readily located?
  • Can key regulatory obligations be substantiated?
  • Is there evidence explaining why the recommendation was appropriate?
  • Can the documents relied upon at the time be produced?
  • Is there a clear audit trail?
  • Does the advice record stand on its own?

Where documentation is fragmented, incomplete or inconsistent, additional scrutiny often follows.

The advice itself may never be the issue. The evidence often is.


What Does a Defensible Advice File Look Like?

Documentation AreaExpected Evidence
Client fileSingle source of truth for all advice documentation
Advice documentsFinal executed versions with clear version control
File notesContemporaneous records of discussions and decisions
Supporting researchLinked to recommendations and retained on file
Regulatory disclosuresEvidence of the actual documents and versions provided
Electronic referencesWorking links or retained copies where appropriate
Email correspondenceMaterial client instructions retained
Alternative strategiesClearly documented and considered
Record retentionAccessible regardless of staff or system changes

A reviewer should be able to understand not only what advice was provided, but why it was appropriate and how it was supported.

If an independent reviewer needs to ask, “Where would I find that?”, there is probably an opportunity to strengthen the file.


Practical Considerations

Improving evidentiary standards does not necessarily require new technology. Often, it simply requires better discipline around existing processes.

Consider whether your practice:

  • stores all material supporting documents within the primary client file;
  • retains copies of the actual FSGs, PDSs and disclosure documents issued to clients;
  • periodically checks hyperlinks contained within advice documents and research papers;
  • has clear version control procedures;
  • captures material email correspondence within the client record; and
  • could produce a complete advice file if the adviser responsible was unavailable.

These are relatively simple controls. Collectively, they can make the difference between a file that is easy to defend and one that requires significant reconstruction under regulatory scrutiny.


Final Observation

Technology has transformed the way financial advice is delivered. It has improved efficiency, streamlined workflows and strengthened compliance processes.

However, technology alone cannot demonstrate compliance.

A client relationship management system is only as effective as the information retained within it. Automated workflows cannot replace contemporaneous evidence. System logs cannot always establish what information a client actually received. Broken hyperlinks, fragmented documentation and inconsistent version control can gradually erode the integrity of an otherwise well-prepared advice file.

The next time you review a client file, ask yourself one simple question:

If the adviser who prepared this file was on annual leave, could someone else explain and defend the advice using only the evidence on the file?

If the answer is no, the system hasn’t really failed. It has simply never been tested.

Regulatory reviews have a habit of revealing weaknesses that day-to-day operations never expose.

The true measure of a system is not how efficiently it records information, but how confidently it can reproduce the evidence when someone independent asks to see it.

For an independent test of your systems, contact Assured Support today. For Licensees and Advisers, your record-keeping is key to your compliance, so test your record-retrieval with us before it’s ASIC sniffing around.

Found this article useful? You can select Assured Support as a ‘preferred source’ in Google. This may help you see more of our articles in Google Top Stories, AI Mode and AI Overviews when our content is relevant to your search.

Further Reading


Frequently Asked Questions

Why can technically correct advice fail a review?

Advice can become difficult to defend when the evidence supporting it cannot be produced. Regulators and independent reviewers assess both the quality of the advice and the records that demonstrate how recommendations were developed, explained, and implemented.
If supporting research, file notes, disclosure documents or client instructions are fragmented across multiple systems, reconstructing the advice process may become difficult even where the underlying advice was appropriate.
Practices should periodically test whether an independent reviewer could understand and defend the file without relying on the original adviser.

Does a system audit log prove that a regulatory obligation has been met?

Not necessarily. An audit log may demonstrate that an activity (e.g. issuing a disclosure document) occurred, but it may not establish what was actually provided, which version was relied upon or whether the client received the information before implementation.
From a governance perspective, retaining the underlying document, along with evidence of delivery, generally provides a more complete evidentiary record than relying solely on system-generated events.

What should Responsible Managers and Licensees test when reviewing advice systems?

In addition to asking whether staff completed certain tasks, Responsible Managers should ask whether the evidence supporting the advice remains complete, accessible and reproducible.
Governance reviews should examine:
– document version control
– evidence retention
– centralisation of client records
– accessibility following staff departures
– completeness of audit trails
– dependency on individual advisers.
A control that cannot reliably reproduce evidence years later may warrant further review, even if day-to-day operations appear effective.

How can practices strengthen evidentiary quality without purchasing new software?

Many improvements involve discipline rather than technology. Practices can establish clear document retention and file-naming rules, capture material email correspondence within the client record, retain the exact disclosure documents issued, maintain version control procedures and periodically verify hyperlinks referenced in advice documents.
A useful exercise is to ask someone unfamiliar with the client to explain the advice using only the file. Any information they must retrieve elsewhere highlights an opportunity to strengthen the record.

Can automation replace good record-keeping?

Automation can improve consistency, but it cannot replace evidentiary judgement. Workflow software records activities efficiently, yet reviewers often need to understand the substance behind those activities: why recommendations were made, what alternatives were considered, and what information the client actually received.
Technology is most effective when it supports documented processes that preserve complete, contemporaneous and accessible evidence rather than simply recording task completion.

Keep exploring

When Good Advice Cannot Be Proven: System Failures During a Regulatory Review

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?