There’s a strange fiction in financial services that responsibility can be compartmentalised.
You’ll see it in the way some licensees treat Responsible Managers (RMs) as compliance clerks—technocrats who tick boxes but have no strategic say. You’ll see it again in boards or governing bodies that rely on risk reports but don’t interrogate the systems they describe.
But the fiction is fading. Through guidance and enforcement, ASIC is steadily reminding the sector that leadership is a shared endeavour within regulated entities. And a shared liability.
In theory, the RM ensures compliance with ASIC’s expectations under RG 105. Directors and officers ensure broader governance and compliance under the Corporations Act. In practice, their roles converge. Sometimes productively. Often problematically.
What does ASIC expect of Licensee Leadership?
Let’s be clear. ASIC’s expectations of licensees aren’t new. The obligation to maintain adequate resources, competent representatives, and effective compliance arrangements has long existed under section 912A.
What’s changed is ASIC’s appetite to enforce those obligations. The regulator no longer accepts form over substance.
In that context, the RM role, once seen as a box-ticking requirement, is being reinterpreted as a frontline of accountability. If you oversee the systems that ensure compliance, you cannot claim ignorance when those systems fail. But those same systems are also a responsibility of directors and officers. They shape culture, allocate resources, and determine whether compliance has influence or merely access.
When those systems fail, ASIC doesn’t choose between culpable parties. It widens the lens.
How do RMs and Directors divide accountability for compliance?
They don’t, or at least not cleanly. In smaller licensees, Directors are often Responsible Managers and Responsible Managers Directors; so the formal separation of responsibilities is a fiction that serves no purpose. In larger licensees, roles, responsibilities and position descriptions are often used to demarcate and manage responsibilities, but again, in reality, they remain collectively responsible for the licensee’s compliance.
Both Directors and Responsible Managers are responsible for ensuring the Licensee complies with the law. Directors (and officers) have statutory duties, while Responsible Managers are licensing constructs designed to evidence and ensure organisational competence and compliance. Both cohorts are responsible, within their respective roles, for ensuring the licensee’s systems achieve compliance, and they are collectively accountable for the outcomes of their decisions, acts and omissions. In practice, exposure turns on explicit and implicit authority, the capacity to influence or direct, and access to information and resources. ASIC’s expectation that RMs play a significant role in the business and influence, or are routinely relied on by, directors and officers is an effective way to restrict accountability arbitrage.
Accountability in practice.
Any discussion of accountability needs to acknowledge both nuances and practicalities. While the s912A obligations sit with the licensee, ASIC assesses organisational competence through named Responsible Managers. Where an RM has the authority and opportunity to influence systems and decisions, they cannot rely on reporting lines to avoid scrutiny. In that sense, RMs are collectively answerable for how the licensed services are run, and individual exposure follows their actual influence and involvement, particularly where they are also officers.
Who is an officer?
Under s9AD of the Corporations Act, although an officer usually refers to a director or secretary of the corporation, it can also include anyone who makes, or participates in making, decisions that affect the whole or a substantial part of the business, or who has the capacity to significantly affect the licensee’s financial standing, or is someone in accordance with whose instructions the directors are accustomed to act.
This legal category overlaps with ASIC’s model for a Responsible Manager, but serves a different legal purpose. Officers owe statutory duties of care and diligence, good faith and proper purpose, and must not misuse their position or information. It can be confusing. A Director is always an officer; a Director need not be a Responsible Manager. An officer need not be either a Director or a Responsible Manager. A Responsible Manager may be an officer if they wield that level of influence; in that case, their exposure tracks their authority and access to information.
Why have Responsible Managers if we already have officers?
Because the roles do different jobs. An officer is a statutory governance concept for the whole entity; a Responsible Manager (RM) is an ASIC licensing construct that evidences organisational competence for the specific services authorised on the licence and keeps day-to-day influence with identifiable, senior people.
In theory, ASIC could have set service-specific and operational-proximity tests for nominated officers; in practice, “officer” is a broad governance category that varies by entity form. The RM framework focuses on a person’s role and responsibilities rather than their legal status. It provides ASIC service line granularity, explicit competence standards, and change notification levers, without conflating corporate law duties with licensing competence or allowing licensees to park accountability with nominal directors.
However, a key reason why ASIC created the RM role was to accommodate diversity, recognising the highly variable “nature, scale and complexity” of the regulated population. The financial services sector includes a wide range of entities from sole advisers and fintech start-ups to global investment banks and superannuation trustees. These businesses vary significantly in structure, staffing, and governance, and the RM is a context-specific role that acknowledges this reality.
In practice, responsibilities cluster into three areas. RMs design, maintain and monitor the compliance system, identify issues and escalate, and provide timely advice to the governing body. Directors and officers set risk appetite, ensure resources and competence, challenge reports, and manage conflicts, conduct and systemic risk. Together they shape culture, define escalation thresholds, ensure direct access between RMs and the governing body, and demonstrate substance over form through documented challenge, breach triage and remediation metrics.
Do Credit Licensees have RMs?
Credit licensees face similar expectations; ASIC uses Responsible Managers in the credit regime to evidence organisational competence alongside the general conduct obligations. The shared accountability logic is the same: operational leaders who influence day-to-day credit activities must be identifiable, competent, and connected to decision-making, while directors and officers resource, challenge, and oversee the system.
Do APRA-regulated entities have RMs?
For banks, insurers and superannuation trustees, APRA’s governance and risk standards place clear accountability on boards, directors and accountable or responsible persons.
Two concepts matter here:
- accountable or responsible persons with defined accountability for material functions, subject to fit and proper requirements
- board and executive oversight to set risk appetite, ensure capability and resources, and challenge and track remediation
The principle is the same as AFSLs. Responsibility can be divided by role, but accountability for outcomes is collective and follows authority, influence and access to information.
When systems fail, ASIC doesn’t pick a single culprit; it widens the lens to whoever had influence and failed to act.
What should Directors and officers do beyond approving policy?
Directors often assume governance is an abstract function. Policy-setting, not oversight. But in financial services, that distinction collapses. Governance without consequence is branding.
ASIC has made this clear. It expects directors and officers to understand and challenge the risk environment. Not just receive reports, but interrogate them.
If an RM flags systemic issues and directors and officers do not act, the liability is shared. If the RM remains silent while failures fester, directors and officers may escape blame, but the profession suffers.
Where do RM obligations and director duties converge?
The overlap between Responsible Managers and Directors is not just structural. It is behavioural.
Both roles are bound by duties to act diligently. To prevent misconduct. To promote a culture that values compliance.
Here’s where things get complicated. In many advice businesses, the same person holds both roles. This is not inherently problematic. Dual roles can streamline communication and accountability. But they can also concentrate risk, particularly when duties conflict.
For example, business growth targets push for more activity. The RM insists on additional controls and more effective risk management. The director wants to execute on the strategy. Both are compelled to ensure the business is sustainable, but their priorities conflict.
Who wins?
In most firms, culture answers that question.
Why doesn’t compliance culture respect org charts?
You can restructure your reporting lines. Retitle your RM. Rename your compliance committee. But none of that matters if cultural norms remain unchanged.
The problem isn’t that roles are overlapping. It’s that responsibility that is disowned. Directors defer to Compliance. Compliance defers to Operations. Everyone assumes someone else will intervene.
ASIC doesn’t accept that excuse.
REP 515 was blunt. Effective oversight was the exception, not the rule. Systems flagged issues that no one escalated. Or worse, that everyone rationalised.
That’s not a policy gap. That’s a collapse in leadership.
What creates the illusion of compliance control in AFSLs?
There’s comfort in believing that compliance risk sits neatly in someone else’s portfolio. But compliance is an ecosystem. When RMs, directors, and officers operate in silos or conflate accountability with activity, the system fails.
In many recent failures, RMs signed off on systems they didn’t shape. Directors and officers received reports they didn’t understand. Problems were “known” but not “owned.”
This is where the illusion of control becomes dangerous. You might have a policy for managing conflicts. But if everyone is conflicted and no one says no, the policy is just wallpaper.
What does shared accountability look like in an AFSL?
If we accept that RMs and Directors are jointly accountable for compliance and conduct, the solution is not to divide roles further. It is to clarify the conditions for shared success.
Mutual visibility. RMs should attend governing meetings. Directors should understand RM reports.
Clear escalation pathways. Systemic issues should never fall into the void between RM and directors and officers.
Independence with connection. RMs need independence from conflicted business units, and connection to the licensee’s decision-making.
Aligned KPIs. If the RM is rewarded for compliance and the Director is rewarded for revenue, misalignment is inevitable.
What’s the bottom line on accountability in a Licensee?
In advice, leadership is not a title. It is a posture. Regulators are now looking for evidence that leadership is exercised where it matters. In setting culture. In intervening early. In backing compliance when it counts.
The RM-Director divide may be administratively convenient, but in practice, it is a fiction.
Accountability doesn’t rest with the function with the fewest lawyers. It rests with those with the greatest capacity to act.
The profession will be stronger when RMs and Directors stop thinking in terms of lines of defence and start acting as co-stewards of trust.
For help understanding your AFSL obligations or fostering a culture of compliance and trust, contact Assured Support today.
If you enjoyed this article, you might also like:
- Governance Essentials for AFS Licensees: A Practical Guide
- Managing an AFSL: Compliance, liability and risk.
- The tenacity of RG146: Competency and Responsible Managers
Frequently Asked Questions
Who is ultimately responsible for AFSL compliance?
The licensee bears the s912A obligations. Practically, accountability is shared across directors, officers and Responsible Managers because exposure follows authority, influence and access to information, not just titles.
What does RG 105 actually require?
RG 105 explains how an AFS licensee demonstrates organisational competence, commonly through nominated Responsible Managers with appropriate knowledge and skills. It doesn’t make an RM the sole owner of compliance.
How is “officer” defined for accountability?
Section 9 defines “officer” broadly, including people who make major decisions or can significantly affect a corporation’s financial standing. ASIC v King confirms a person need not hold a formal title to be an “officer”.
Do credit licensees have Responsible Managers?
Yes. Under RG 206, organisational competence for credit licensees is often evidenced via named responsible managers.
How does FAR change accountability for APRA-regulated entities?
FAR imposes clear accountability on ‘accountable persons’: in force for banks from 15 Mar 2024 and for insurers/super from 15 Mar 2025, jointly administered by APRA and ASIC.