1. Executive Summary
In Australian Securities and Investments Commission v Mercer Superannuation (Australia) Limited [2026] FCA 832, the Federal Court imposed total pecuniary penalties of $10.3 million on Mercer Superannuation (Australia) Limited (MSAL) for systemic failures under the reportable situations regime, failures to report eight investigations on time or at all, and failures to take reasonable steps to ensure reports lodged with ASIC were not materially false or misleading. MSAL was also ordered to pay ASIC’s agreed costs of $1.2 million.
The proceeding was resolved on a statement of agreed facts and admissions. Button J accepted the parties’ proposed declarations and penalties, divided as follows:
| Contravention category | Penalty |
| Inadequate systems: ss 912A(1)(a) and 912A(5A) | $4,062,500 |
| Fifteen reporting contraventions: ss 912DAA(1) and 912DAA(7) | $5,300,000 |
| Three misleading-report contraventions: s 1308(5) | $937,500 |
| Total | $10,300,000 |
The central governance lesson is that breach reporting is not merely a legal reporting process. It is part of the operational infrastructure required to provide licensed financial services efficiently, honestly and fairly.
The Court treated MSAL’s inability to identify when an investigation commenced, track the 30-day investigation period and trigger reporting deadlines as a serious systems failure. The judgment also confirms that:
- an “investigation” is determined objectively by what the licensee is doing, not by an internal label or committee referral;
- a prolonged investigation can itself become reportable before the underlying breach question is resolved;
- a concluded investigation that finds no significant breach may create a separate reportable situation;
- voluntary update reports lodged with ASIC can attract liability under s 1308(5); and
- outsourced personnel, systems and compliance functions do not transfer the licensee’s statutory responsibility.
For Australian financial services licensees, the decision requires a joined-up breach reporting framework connecting incident intake, investigation commencement, legal assessment, reporting deadlines, data quality, remediation and board oversight.
2. Citation and Context
Case: Australian Securities and Investments Commission v Mercer Superannuation (Australia) Limited [2026] FCA 832
Court: Federal Court of Australia
Judge: Button J
Judgment date: 26 June 2026
File: VID 1039 of 2025
Hearing: 3 June 2026
Procedural basis: Statement of agreed facts and admissions filed 21 May 2026; joint submissions on liability and relief.
MSAL was the trustee of the Mercer Super Trust and held both an Australian financial services licence and a registrable superannuation entity licence. During the relevant period, from 1 October 2021 to 30 September 2024, its compliance staff and systems were supplied by its parent, Mercer (Australia) Pty Ltd, under a services arrangement. The Court emphasised that MSAL nevertheless remained solely responsible for its obligations as licensee: at [9].
The current reportable situations regime commenced on 1 October 2021. It was a significant change from the former breach reporting framework and was intended to give ASIC visibility of prolonged investigations and incentivise licensees to prioritise them: at [11]–[17].
3. Procedural Posture
ASIC commenced civil penalty proceedings alleging failures relating to:
- the design and operation of MSAL’s reportable situations systems;
- the reporting of eight investigations; and
- the accuracy of reports submitted to ASIC.
MSAL admitted the contraventions. The parties initially proposed a single $10.3 million penalty. At the Court’s prompting, they allocated the proposed amount across the three contravention categories: at [4].
The Court remained responsible for determining whether the agreed facts established the contraventions and whether the proposed penalties were within an appropriate range. Button J applied the principles governing agreed civil penalties from Commonwealth v Director, Fair Work Building Industry Inspectorate [2015] HCA 46.
4. Material Facts, Issues and Outcome
Systems failure
MSAL used a governance, risk and compliance database called “Scout”, supplemented at different times by spreadsheets, triage meetings and manual reviews.
The system could not reliably record:
- when an investigation commenced;
- the date 30 days after commencement;
- when the investigation itself became reportable;
- the reporting deadline; or
- when a concluded investigation generated a further reporting obligation.
Key database fields could also be overwritten when records were updated: at [23].
From May 2023 to approximately June 2024, MSAL stopped using its separate RG78 tracker and ceased weekly triage meetings. It also incorrectly treated an investigation as commencing only when an incident was considered by the Significant Incident Review Panel, rather than when fact-gathering first began: at [25].
External auditors raised concerns between March 2022 and April 2024 about incidents remaining open for more than 30 days and MSAL’s comparatively low reporting levels. Those concerns reached senior management and governance committees. The Court regarded MSAL’s continued reliance on the deficient system after receiving those warnings as a significant aggravating factor: at [28].
Eight investigations
The deficiencies contributed to failures involving eight incidents. Seven were never reported. One was reported late.
For seven investigations, two separate reporting obligations arose:
- when the investigation continued for more than 30 days under s 912D(1)(c); and
- when the investigation concluded without identifying a reportable significant breach under s 912D(1)(d).
That produced 14 contraventions. The late report for the eighth investigation produced the fifteenth contravention: at [70]–[71].
Some investigations lasted between at least 93 and 434 days: at [69].
Inaccurate ASIC reports
The detailed example concerned incident INC-0011906, involving failures to establish some employer-sponsored accounts correctly after the introduction of a new employer gateway.
Although fact-finding relevant to a possible significant breach commenced on 2 December 2022, MSAL recorded the investigation as commencing on 22 March 2023. The investigation had therefore continued for at least 140 days before MSAL lodged its first report on 21 April 2023: at [33]–[34].
Three subsequent reports were materially false or misleading because MSAL failed to consult or properly consider available internal information.
Examples included:
- reporting that the number of affected clients was “not known” when at least 231 affected members had already been identified;
- reporting approximately 50 affected clients despite records showing at least 231;
- reporting that an investigation was complete when 5,709 invalid member registration requests remained under consideration; and
- materially understating the number of affected clients and relevant instances.
ASIC accepted that MSAL did not deliberately attempt to mislead it. Liability arose because MSAL failed to take all reasonable steps to ensure accuracy: at [41]–[42], [78]–[80].
5. Contraventions
| Act | Section | Duty or prohibition | Conduct | Count | Finding | Pinpoint |
| Corporations Act 2001 (Cth) | 912A(1)(a), 912A(5A) | Do all things necessary to ensure licensed financial services are provided efficiently, honestly and fairly | Inadequate systems to identify, track and report reportable investigations | 1 sustained contravention | Admitted and declared | [21]–[28], [53]–[64] |
| Corporations Act 2001 (Cth) | 912DAA(1), 912DAA(7) | Report a reportable situation within the statutory period | One late report and failures to report seven investigations and their conclusions | 15 | Admitted and declared | [29]–[36], [65]–[73] |
| Corporations Act 2001 (Cth) | 1308(5) | Take all reasonable steps to ensure documents lodged with ASIC are not materially false or misleading | Three inaccurate ASIC update reports | 3 | Admitted and declared | [37]–[42], [74]–[82] |
The Court did not infer additional contraventions beyond those admitted and particularised.
6. Definitions and Legal Clarifications
Investigation
The Corporations Act does not define “investigation”. The Court adopted its ordinary meaning: a searching inquiry to ascertain facts.
An investigation may commence when personnel begin gathering information or applying human effort to determine whether a breach has occurred. It does not depend on:
- entry into a particular system;
- escalation to a committee;
- completion of preliminary fact-finding;
- a formal breach assessment; or
- the organisation’s internal terminology.
As the Explanatory Memorandum stated, quoted at [18]:
“The time at which an investigation commences is a matter of fact and is not a subjective determination by the licensee.”
Reportable investigation
An investigation into whether there has been, or may be, a significant breach becomes a reportable situation when it continues for more than 30 days.
The report must then be lodged within 30 days after the licensee first knows, or is reckless as to whether, reasonable grounds exist to believe the reportable situation has arisen. The Court described the practical effect as ordinarily requiring reporting within 60 days after the investigation begins: at [15].
Separate conclusion report
If the investigation later concludes that no reportable significant breach exists, that conclusion is itself a further reportable situation under s 912D(1)(d). A licensee must therefore track both:
- the duration trigger; and
- the conclusion trigger.
Voluntary reports
Section 1308(5) can apply to documents voluntarily submitted to ASIC. It is not confined to documents that legislation expressly requires to be lodged: at [76].
7. Key Legal Principles
7.1 Breach reporting systems form part of the efficiently, honestly and fairly obligation
Section 912A(1)(a) is not confined to customer-facing conduct. A deficient regulatory reporting system can have the necessary nexus with the licensed financial services.
Button J held that breach reporting supports the lawful provision of front-end services by giving ASIC visibility of potentially significant non-compliance and incentivising licensees to identify and address issues: at [60]–[62].
The Court stated at [53]:
“The provision does not impose a standard of perfection but a reasonable standard of performance.”
Operationally, the relevant standard depends on the licensee’s size, activities, resources, customer base and regulatory risk.
7.2 Internal classifications do not determine statutory commencement
A licence holder cannot postpone the statutory clock by treating early inquiries as “fact-finding”, “triage” or “preliminary assessment”.
The legal question is when the organisation first undertook a searching inquiry into whether a significant breach had occurred or might occur.
7.3 Reporting systems must be capable of calculating and preserving key dates
The judgment indicates that an adequate system should record, preserve and escalate at least:
- incident identification date;
- investigation commencement date;
- basis for that date;
- day 30;
- reportability trigger;
- statutory lodgement deadline;
- investigation conclusion date; and
- any separate s 912D(1)(d) obligation.
A database that depends on manual workarounds, permits key dates to be overwritten or does not produce reliable alerts creates material regulatory exposure.
7.4 Outsourcing does not reduce the licensee’s accountability
MSAL had no employees during the relevant period. Its parent supplied staff and systems. That did not alter MSAL’s legal responsibility.
Licensees using group or third-party service providers must maintain sufficient oversight, assurance, contractual rights, information access and escalation mechanisms to discharge their own statutory obligations.
7.5 ASIC reporting requires source-data reconciliation
The s 1308(5) findings demonstrate that reasonable steps require more than relying on an incident manager’s email, estimate or partial dataset.
Reports should be reconciled against authoritative records and reviewed for internal consistency before lodgement. The Court described the need for systems to be “joined up” so that important information is captured and not overlooked: at [83].
8. Orders, Penalties and Remedies
| Order or remedy | Legal basis | Amount or scope | Paragraphs |
| Declaration: inadequate systems | ss 912A(1)(a), 912A(5A) | Relevant period: 1 October 2021–30 September 2024 | Orders 1; [53]–[64] |
| Declaration: reporting failures | ss 912DAA(1), 912DAA(7) | 15 contraventions across eight incidents | Orders 2; [65]–[73] |
| Declaration: inaccurate reports | s 1308(5) | Three reports | Order 3; [74]–[82] |
| Pecuniary penalty | ss 1317E, 1317G | $10.3 million total | Order 4; [63], [72], [81]–[83] |
| Costs | Court order by agreement | $1.2 million | Order 5; [84] |
The Court treated deterrence as the primary, if not sole, purpose of civil penalties. The penalty must carry sufficient “sting” without being oppressive and must not be treated as a cost of doing business: at [43].
Although the parties proposed the s 1308(5) penalty jointly, Button J observed that, absent agreement, the Court might have imposed a somewhat higher amount: at [82].
9. Relevance for Licensees, Advisers and Responsible Managers
The decision materially increases the importance of investigation governance.
Responsible managers and compliance executives should not assume that a breach reporting framework is adequate merely because:
- incidents are entered into a GRC system;
- a breach committee meets periodically;
- business units are responsible for investigations;
- a manual tracker exists;
- an external service provider operates the process; or
- reports are eventually lodged.
The licensee must be able to demonstrate that the framework works reliably in practice.
Boards and risk committees should receive metrics addressing:
- investigations open for 20, 25 and 30 days;
- matters without a confirmed commencement date;
- overdue legal assessments;
- reports due within the next 10 business days;
- investigations concluded without a significant breach;
- discrepancies between GRC data and ASIC reports;
- repeat incidents and systemic themes;
- ageing remediation; and
- control exceptions or manual overrides.
External audit warnings and assurance findings require tracked remediation, accountable owners and closure testing. Merely noting an audit issue may aggravate exposure if the deficient process continues.
10. Risk Management and Compliance Recommendations
| Audience | Control type | Legal rationale | Risk indicator | Practical control |
| Board and risk committee | Governance | Oversight of ss 912A and 912DAA compliance | Repeat audit findings; low reporting volumes | Quarterly breach reporting assurance dashboard and overdue-action escalation |
| Compliance | Preventative | Correctly identify investigation commencement | Reliance on committee dates or internal labels | Statutory investigation definition embedded in procedures and training |
| Compliance operations | Detective | Track 30-day and lodgement deadlines | Missing or overwritten dates | Locked date fields, automated alerts and exception reports |
| Legal | Preventative | Ensure consistent reportability assessments | Divergent business and compliance interpretations | Legal review protocol for disputed commencement dates |
| Data and technology | Preventative | Preserve reliable statutory records | Manual spreadsheets and duplicate datasets | Single source of truth with audit logs and immutable trigger dates |
| Regulatory reporting | Detective | Avoid materially false or misleading reports | Estimates inconsistent with case records | Pre-lodgement reconciliation and independent reviewer sign-off |
| Business units | Preventative | Escalate fact-gathering promptly | Investigations conducted outside GRC workflow | Mandatory notification when information gathering begins |
| Internal audit | Detective | Test design and operating effectiveness | Known deficiencies remain unresolved | Periodic sample testing from incident detection to ASIC lodgement |
| Executive management | Corrective | Ensure timely remediation | Actions repeatedly extended | Formal issue acceptance and escalation thresholds |
| Outsourcing owner | Governance | Licensee retains responsibility | Provider controls not independently tested | Contractual control standards, assurance rights and service-level reporting |
11. Regulatory Trends
The judgment reflects judicial acceptance that regulatory reporting controls are integral to the provision of financial services, not a peripheral administrative obligation.
It also reinforces a broader enforcement focus on:
- systems and controls;
- data integrity;
- regulator visibility;
- prolonged investigations;
- governance responses to known deficiencies; and
- the accuracy of information supplied to ASIC.
The decision is particularly significant because Button J noted that there had been limited specific judicial consideration of the obligation to report prolonged investigations: at [16].
12. Recommended Next Steps
Licensees should undertake a targeted review of their reportable situations framework.
Priority actions are:
- Reconstruct the legal definition of “investigation” in procedures, training and system rules.
- Test whether current systems identify the true factual commencement date rather than a formal escalation date.
- Review open and recently closed investigations for missed ss 912D(1)(c) and 912D(1)(d) reports.
- Validate all statutory date fields, alerts, access controls and audit trails.
- Introduce independent pre-lodgement review of ASIC reports against authoritative source data.
- Escalate unresolved audit findings concerning breach reporting to the board or relevant committee.
- Test outsourced or group-provided compliance functions against the licensee’s own legal obligations.
- Establish recurring assurance over the end-to-end process.
Any retrospective review should be legally privileged where appropriate and should include a documented approach to potential corrective reporting, breach assessment, remediation and engagement with ASIC.
Reviewer note: This analysis is suitable for internal legal and compliance review, but final positions should be confirmed against the complete source material and current law.