CASE INSIGHTS

Australian Securities and Investments Commission v Mercer Superannuation (Australia) Limited [2026] FCA 832

1. Executive Summary

In Australian Securities and Investments Commission v Mercer Superannuation (Australia) Limited [2026] FCA 832, the Federal Court imposed total pecuniary penalties of $10.3 million on Mercer Superannuation (Australia) Limited (MSAL) for systemic failures under the reportable situations regime, failures to report eight investigations on time or at all, and failures to take reasonable steps to ensure reports lodged with ASIC were not materially false or misleading. MSAL was also ordered to pay ASIC’s agreed costs of $1.2 million.

The proceeding was resolved on a statement of agreed facts and admissions. Button J accepted the parties’ proposed declarations and penalties, divided as follows:

Contravention categoryPenalty
Inadequate systems: ss 912A(1)(a) and 912A(5A)$4,062,500
Fifteen reporting contraventions: ss 912DAA(1) and 912DAA(7)$5,300,000
Three misleading-report contraventions: s 1308(5)$937,500
Total$10,300,000

The central governance lesson is that breach reporting is not merely a legal reporting process. It is part of the operational infrastructure required to provide licensed financial services efficiently, honestly and fairly.

The Court treated MSAL’s inability to identify when an investigation commenced, track the 30-day investigation period and trigger reporting deadlines as a serious systems failure. The judgment also confirms that:

  • an “investigation” is determined objectively by what the licensee is doing, not by an internal label or committee referral;
  • a prolonged investigation can itself become reportable before the underlying breach question is resolved;
  • a concluded investigation that finds no significant breach may create a separate reportable situation;
  • voluntary update reports lodged with ASIC can attract liability under s 1308(5); and
  • outsourced personnel, systems and compliance functions do not transfer the licensee’s statutory responsibility.

For Australian financial services licensees, the decision requires a joined-up breach reporting framework connecting incident intake, investigation commencement, legal assessment, reporting deadlines, data quality, remediation and board oversight.


2. Citation and Context

Case: Australian Securities and Investments Commission v Mercer Superannuation (Australia) Limited [2026] FCA 832
Court: Federal Court of Australia
Judge: Button J
Judgment date: 26 June 2026
File: VID 1039 of 2025
Hearing: 3 June 2026
Procedural basis: Statement of agreed facts and admissions filed 21 May 2026; joint submissions on liability and relief.

MSAL was the trustee of the Mercer Super Trust and held both an Australian financial services licence and a registrable superannuation entity licence. During the relevant period, from 1 October 2021 to 30 September 2024, its compliance staff and systems were supplied by its parent, Mercer (Australia) Pty Ltd, under a services arrangement. The Court emphasised that MSAL nevertheless remained solely responsible for its obligations as licensee: at [9].

The current reportable situations regime commenced on 1 October 2021. It was a significant change from the former breach reporting framework and was intended to give ASIC visibility of prolonged investigations and incentivise licensees to prioritise them: at [11]–[17].


3. Procedural Posture

ASIC commenced civil penalty proceedings alleging failures relating to:

  1. the design and operation of MSAL’s reportable situations systems;
  2. the reporting of eight investigations; and
  3. the accuracy of reports submitted to ASIC.

MSAL admitted the contraventions. The parties initially proposed a single $10.3 million penalty. At the Court’s prompting, they allocated the proposed amount across the three contravention categories: at [4].

The Court remained responsible for determining whether the agreed facts established the contraventions and whether the proposed penalties were within an appropriate range. Button J applied the principles governing agreed civil penalties from Commonwealth v Director, Fair Work Building Industry Inspectorate [2015] HCA 46.


4. Material Facts, Issues and Outcome

Systems failure

MSAL used a governance, risk and compliance database called “Scout”, supplemented at different times by spreadsheets, triage meetings and manual reviews.

The system could not reliably record:

  • when an investigation commenced;
  • the date 30 days after commencement;
  • when the investigation itself became reportable;
  • the reporting deadline; or
  • when a concluded investigation generated a further reporting obligation.

Key database fields could also be overwritten when records were updated: at [23].

From May 2023 to approximately June 2024, MSAL stopped using its separate RG78 tracker and ceased weekly triage meetings. It also incorrectly treated an investigation as commencing only when an incident was considered by the Significant Incident Review Panel, rather than when fact-gathering first began: at [25].

External auditors raised concerns between March 2022 and April 2024 about incidents remaining open for more than 30 days and MSAL’s comparatively low reporting levels. Those concerns reached senior management and governance committees. The Court regarded MSAL’s continued reliance on the deficient system after receiving those warnings as a significant aggravating factor: at [28].

Eight investigations

The deficiencies contributed to failures involving eight incidents. Seven were never reported. One was reported late.

For seven investigations, two separate reporting obligations arose:

  1. when the investigation continued for more than 30 days under s 912D(1)(c); and
  2. when the investigation concluded without identifying a reportable significant breach under s 912D(1)(d).

That produced 14 contraventions. The late report for the eighth investigation produced the fifteenth contravention: at [70]–[71].

Some investigations lasted between at least 93 and 434 days: at [69].

Inaccurate ASIC reports

The detailed example concerned incident INC-0011906, involving failures to establish some employer-sponsored accounts correctly after the introduction of a new employer gateway.

Although fact-finding relevant to a possible significant breach commenced on 2 December 2022, MSAL recorded the investigation as commencing on 22 March 2023. The investigation had therefore continued for at least 140 days before MSAL lodged its first report on 21 April 2023: at [33]–[34].

Three subsequent reports were materially false or misleading because MSAL failed to consult or properly consider available internal information.

Examples included:

  • reporting that the number of affected clients was “not known” when at least 231 affected members had already been identified;
  • reporting approximately 50 affected clients despite records showing at least 231;
  • reporting that an investigation was complete when 5,709 invalid member registration requests remained under consideration; and
  • materially understating the number of affected clients and relevant instances.

ASIC accepted that MSAL did not deliberately attempt to mislead it. Liability arose because MSAL failed to take all reasonable steps to ensure accuracy: at [41]–[42], [78]–[80].


5. Contraventions

ActSectionDuty or prohibitionConductCountFindingPinpoint
Corporations Act 2001 (Cth)912A(1)(a), 912A(5A)Do all things necessary to ensure licensed financial services are provided efficiently, honestly and fairlyInadequate systems to identify, track and report reportable investigations1 sustained contraventionAdmitted and declared[21]–[28], [53]–[64]
Corporations Act 2001 (Cth)912DAA(1), 912DAA(7)Report a reportable situation within the statutory periodOne late report and failures to report seven investigations and their conclusions15Admitted and declared[29]–[36], [65]–[73]
Corporations Act 2001 (Cth)1308(5)Take all reasonable steps to ensure documents lodged with ASIC are not materially false or misleadingThree inaccurate ASIC update reports3Admitted and declared[37]–[42], [74]–[82]

The Court did not infer additional contraventions beyond those admitted and particularised.


6. Definitions and Legal Clarifications

Investigation

The Corporations Act does not define “investigation”. The Court adopted its ordinary meaning: a searching inquiry to ascertain facts.

An investigation may commence when personnel begin gathering information or applying human effort to determine whether a breach has occurred. It does not depend on:

  • entry into a particular system;
  • escalation to a committee;
  • completion of preliminary fact-finding;
  • a formal breach assessment; or
  • the organisation’s internal terminology.

As the Explanatory Memorandum stated, quoted at [18]:

“The time at which an investigation commences is a matter of fact and is not a subjective determination by the licensee.”

Reportable investigation

An investigation into whether there has been, or may be, a significant breach becomes a reportable situation when it continues for more than 30 days.

The report must then be lodged within 30 days after the licensee first knows, or is reckless as to whether, reasonable grounds exist to believe the reportable situation has arisen. The Court described the practical effect as ordinarily requiring reporting within 60 days after the investigation begins: at [15].

Separate conclusion report

If the investigation later concludes that no reportable significant breach exists, that conclusion is itself a further reportable situation under s 912D(1)(d). A licensee must therefore track both:

  • the duration trigger; and
  • the conclusion trigger.

Voluntary reports

Section 1308(5) can apply to documents voluntarily submitted to ASIC. It is not confined to documents that legislation expressly requires to be lodged: at [76].


7. Key Legal Principles

7.1 Breach reporting systems form part of the efficiently, honestly and fairly obligation

Section 912A(1)(a) is not confined to customer-facing conduct. A deficient regulatory reporting system can have the necessary nexus with the licensed financial services.

Button J held that breach reporting supports the lawful provision of front-end services by giving ASIC visibility of potentially significant non-compliance and incentivising licensees to identify and address issues: at [60]–[62].

The Court stated at [53]:

“The provision does not impose a standard of perfection but a reasonable standard of performance.”

Operationally, the relevant standard depends on the licensee’s size, activities, resources, customer base and regulatory risk.

7.2 Internal classifications do not determine statutory commencement

A licence holder cannot postpone the statutory clock by treating early inquiries as “fact-finding”, “triage” or “preliminary assessment”.

The legal question is when the organisation first undertook a searching inquiry into whether a significant breach had occurred or might occur.

7.3 Reporting systems must be capable of calculating and preserving key dates

The judgment indicates that an adequate system should record, preserve and escalate at least:

  • incident identification date;
  • investigation commencement date;
  • basis for that date;
  • day 30;
  • reportability trigger;
  • statutory lodgement deadline;
  • investigation conclusion date; and
  • any separate s 912D(1)(d) obligation.

A database that depends on manual workarounds, permits key dates to be overwritten or does not produce reliable alerts creates material regulatory exposure.

7.4 Outsourcing does not reduce the licensee’s accountability

MSAL had no employees during the relevant period. Its parent supplied staff and systems. That did not alter MSAL’s legal responsibility.

Licensees using group or third-party service providers must maintain sufficient oversight, assurance, contractual rights, information access and escalation mechanisms to discharge their own statutory obligations.

7.5 ASIC reporting requires source-data reconciliation

The s 1308(5) findings demonstrate that reasonable steps require more than relying on an incident manager’s email, estimate or partial dataset.

Reports should be reconciled against authoritative records and reviewed for internal consistency before lodgement. The Court described the need for systems to be “joined up” so that important information is captured and not overlooked: at [83].


8. Orders, Penalties and Remedies

Order or remedyLegal basisAmount or scopeParagraphs
Declaration: inadequate systemsss 912A(1)(a), 912A(5A)Relevant period: 1 October 2021–30 September 2024Orders 1; [53]–[64]
Declaration: reporting failuresss 912DAA(1), 912DAA(7)15 contraventions across eight incidentsOrders 2; [65]–[73]
Declaration: inaccurate reportss 1308(5)Three reportsOrder 3; [74]–[82]
Pecuniary penaltyss 1317E, 1317G$10.3 million totalOrder 4; [63], [72], [81]–[83]
CostsCourt order by agreement$1.2 millionOrder 5; [84]

The Court treated deterrence as the primary, if not sole, purpose of civil penalties. The penalty must carry sufficient “sting” without being oppressive and must not be treated as a cost of doing business: at [43].

Although the parties proposed the s 1308(5) penalty jointly, Button J observed that, absent agreement, the Court might have imposed a somewhat higher amount: at [82].


9. Relevance for Licensees, Advisers and Responsible Managers

The decision materially increases the importance of investigation governance.

Responsible managers and compliance executives should not assume that a breach reporting framework is adequate merely because:

  • incidents are entered into a GRC system;
  • a breach committee meets periodically;
  • business units are responsible for investigations;
  • a manual tracker exists;
  • an external service provider operates the process; or
  • reports are eventually lodged.

The licensee must be able to demonstrate that the framework works reliably in practice.

Boards and risk committees should receive metrics addressing:

  • investigations open for 20, 25 and 30 days;
  • matters without a confirmed commencement date;
  • overdue legal assessments;
  • reports due within the next 10 business days;
  • investigations concluded without a significant breach;
  • discrepancies between GRC data and ASIC reports;
  • repeat incidents and systemic themes;
  • ageing remediation; and
  • control exceptions or manual overrides.

External audit warnings and assurance findings require tracked remediation, accountable owners and closure testing. Merely noting an audit issue may aggravate exposure if the deficient process continues.


10. Risk Management and Compliance Recommendations

AudienceControl typeLegal rationaleRisk indicatorPractical control
Board and risk committeeGovernanceOversight of ss 912A and 912DAA complianceRepeat audit findings; low reporting volumesQuarterly breach reporting assurance dashboard and overdue-action escalation
CompliancePreventativeCorrectly identify investigation commencementReliance on committee dates or internal labelsStatutory investigation definition embedded in procedures and training
Compliance operationsDetectiveTrack 30-day and lodgement deadlinesMissing or overwritten datesLocked date fields, automated alerts and exception reports
LegalPreventativeEnsure consistent reportability assessmentsDivergent business and compliance interpretationsLegal review protocol for disputed commencement dates
Data and technologyPreventativePreserve reliable statutory recordsManual spreadsheets and duplicate datasetsSingle source of truth with audit logs and immutable trigger dates
Regulatory reportingDetectiveAvoid materially false or misleading reportsEstimates inconsistent with case recordsPre-lodgement reconciliation and independent reviewer sign-off
Business unitsPreventativeEscalate fact-gathering promptlyInvestigations conducted outside GRC workflowMandatory notification when information gathering begins
Internal auditDetectiveTest design and operating effectivenessKnown deficiencies remain unresolvedPeriodic sample testing from incident detection to ASIC lodgement
Executive managementCorrectiveEnsure timely remediationActions repeatedly extendedFormal issue acceptance and escalation thresholds
Outsourcing ownerGovernanceLicensee retains responsibilityProvider controls not independently testedContractual control standards, assurance rights and service-level reporting

11. Regulatory Trends

The judgment reflects judicial acceptance that regulatory reporting controls are integral to the provision of financial services, not a peripheral administrative obligation.

It also reinforces a broader enforcement focus on:

  • systems and controls;
  • data integrity;
  • regulator visibility;
  • prolonged investigations;
  • governance responses to known deficiencies; and
  • the accuracy of information supplied to ASIC.

The decision is particularly significant because Button J noted that there had been limited specific judicial consideration of the obligation to report prolonged investigations: at [16].


12. Recommended Next Steps

Licensees should undertake a targeted review of their reportable situations framework.

Priority actions are:

  1. Reconstruct the legal definition of “investigation” in procedures, training and system rules.
  2. Test whether current systems identify the true factual commencement date rather than a formal escalation date.
  3. Review open and recently closed investigations for missed ss 912D(1)(c) and 912D(1)(d) reports.
  4. Validate all statutory date fields, alerts, access controls and audit trails.
  5. Introduce independent pre-lodgement review of ASIC reports against authoritative source data.
  6. Escalate unresolved audit findings concerning breach reporting to the board or relevant committee.
  7. Test outsourced or group-provided compliance functions against the licensee’s own legal obligations.
  8. Establish recurring assurance over the end-to-end process.

Any retrospective review should be legally privileged where appropriate and should include a documented approach to potential corrective reporting, breach assessment, remediation and engagement with ASIC.

Reviewer note: This analysis is suitable for internal legal and compliance review, but final positions should be confirmed against the complete source material and current law.

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?