CASE INSIGHTS

Australian Securities and Investments Commission v Westpac Banking Corporation (Omnibus) [2022] FCA 515

1. Executive Summary

In Australian Securities and Investments Commission v Westpac Banking Corporation (Omnibus) [2022] FCA 515, Beach J imposed pecuniary penalties totalling $113 million on Westpac Banking Corporation and several subsidiaries across six regulatory proceedings.

The proceedings concerned distinct but recurring failures in Westpac’s financial services operations:

  1. dealing incorrectly with accounts held by deregistered companies;
  2. deducting insurance fees from superannuation accounts and paying conflicted remuneration;
  3. charging financial advice fees after customers had died;
  4. making misleading representations when selling customer debts;
  5. charging contribution fees without adequate disclosure; and
  6. issuing duplicate general insurance policies or policies without customer consent.

The Court found or declared contraventions of provisions including:

  • ss 912A, 962P, 963K and 1041H of the Corporations Act 2001 (Cth); and
  • ss 12CB, 12DA, 12DB, 12DI and 12DM of the Australian Securities and Investments Commission Act 2001 (Cth).

The judgment is particularly significant for its treatment of the obligation to provide financial services efficiently, honestly and fairly under s 912A(1)(a). Beach J confirmed that:

  • dishonesty in the criminal or traditional sense is not required;
  • the standard is assessed objectively; and
  • s 912A(1)(a) is itself a substantive statutory obligation and does not depend on proving a separate breach of another legal duty.

The common theme was not isolated employee error. The misconduct arose from deficient systems, fragmented information, inadequate records, ineffective escalation and failures to act promptly after problems became known.


2. Citation and Context

Case: Australian Securities and Investments Commission v Westpac Banking Corporation (Omnibus)
Neutral citation: [2022] FCA 515
Court: Federal Court of Australia
Judge: Beach J
Date of judgment: 22 April 2022
Reasons certified: 6 May 2022
Proceedings: VID 704, VID 705, VID 707, NSD 1239, NSD 1240 and NSD 1241 of 2021
Procedural posture: Agreed facts and admissions, declarations, civil penalties, compliance orders and costs.

The Court dealt with the six proceedings separately but issued omnibus reasons explaining the legal principles and penalties applied across them. Each matter was founded on a detailed statement of agreed facts under s 191 of the Evidence Act 1995 (Cth).

Beach J did not apply an overarching “meta-totality” adjustment across all six proceedings. Totality was considered within each proceeding, rather than by reducing the combined penalties merely because all matters involved entities within the Westpac group.


3. Summary of the Six Proceedings

ProceedingConductPrincipal respondent or respondentsPenalty
VID 704 of 2021Accounts of deregistered companiesWestpac$20 million
VID 705 of 2021Insurance in superannuation and conflicted remunerationBT Funds Management Ltd$20 million
VID 707 of 2021Advice fees charged after customers’ deathsWestpac and seven related entities$40 million
NSD 1239 of 2021Misleading representations in debt salesWestpac$12 million
NSD 1240 of 2021Undisclosed contribution feesWestpac, Securitor and Magnitude$6 million
NSD 1241 of 2021Duplicate and non-consensual insurance policiesWestpac$15 million
Total$113 million

4. Deregistered Company Accounts — $20 Million

Westpac did not have adequate processes to identify when companies holding bank accounts had been deregistered or to manage those accounts consistently with the statutory consequences of deregistration.

Under s 601AD of the Corporations Act, a company ceases to exist on deregistration. Relevant property may vest in ASIC or the Commonwealth. Despite this, Westpac continued to treat some accounts as if the deregistered companies remained legally capable of operating them.

The failures included:

  • permitting withdrawals or transfers from affected accounts;
  • charging fees;
  • allowing funds to remain subject to ordinary account processes;
  • failing to identify legal changes in ownership of the account property; and
  • lacking an effective operational process to respond to deregistration data.

The Court imposed a $20 million penalty for Westpac’s contravention of s 912A.

Compliance significance

Entity-status data must be treated as a legal control input. A customer’s deregistration, death, insolvency or change of trustee is not merely a customer-record update; it may alter legal ownership, authority and the institution’s ability to transact.


5. Insurance in Superannuation — $20 Million

BT Funds Management deducted insurance premiums and related fees from superannuation accounts in circumstances involving defective or inadequate disclosure. It also paid more than $6 million in conflicted remuneration to financial advisers or advice licensees over the relevant period.

The contraventions included false or misleading representations under s 12DB of the ASIC Act and payment of conflicted remuneration contrary to s 963K of the Corporations Act.

Beach J imposed a single $20 million penalty, reflecting:

  • the number of affected members;
  • the prolonged nature of the conduct;
  • the amount of conflicted remuneration;
  • the need for general and specific deterrence; and
  • the size and resources of the Westpac group.

The Court stated that the penalty would have been substantially higher but for remediation, corrective action and significant cooperation with ASIC.

Compliance significance

Superannuation trustees must reconcile:

  • product disclosures;
  • member consent;
  • fee deduction logic;
  • adviser-payment arrangements;
  • conflicted remuneration restrictions; and
  • actual system outputs.

A disclosure document cannot cure a system that deducts or distributes amounts on a different basis.


6. Advice Fees Charged After Death — $40 Million

The largest individual proceeding concerned advice fees deducted from customer accounts after Westpac or related entities had been notified that the customer had died.

The advice could not be provided to the deceased customer, yet fees continued to be deducted, accepted, retained or remitted.

The respondents included:

  • Westpac;
  • Securitor Financial Group;
  • Magnitude Group;
  • Advance Asset Management;
  • Asgard Capital Management;
  • BT Funds Management;
  • BT Funds Management No. 2; and
  • BT Portfolio Services.

The admitted contraventions included:

  • accepting payment where there were reasonable grounds to believe services could not be supplied, contrary to s 12DI(3) of the ASIC Act;
  • unconscionable conduct under s 12CB;
  • prohibited ongoing fee arrangements under s 962P;
  • failure to comply with financial services laws under s 912A(1)(c); and
  • failures to provide services efficiently, honestly and fairly under s 912A(1)(a).

Penalties

RespondentPenalty
Westpac$15.95 million
Securitor$7.6 million
Magnitude$4.45 million
Advance Asset Management$100,000
Asgard Capital Management$1.8 million
BT Funds Management$7.2 million
BT Portfolio Services$2.9 million
BT Funds Management No. 2No pecuniary penalty sought
Total$40 million

Westpac admitted 4,324 contraventions of s 12DI(3), involving approximately $812,735 and the estates of 575 customers. It also admitted 1,212 contraventions of s 962P, involving approximately $301,928 and 179 estates. Securitor and Magnitude admitted to thousands of additional instances affecting the estates of hundreds of deceased customers.

The orders recorded that the advice licensees lacked systems capable of:

  • preventing advice fees from continuing after notification of death; and
  • refunding fees back to the date of death.

Compliance significance

A notification of death must create an immediate, group-wide control event. It should stop:

  • ongoing advice fees;
  • service charges dependent on the customer being alive;
  • commissions or remittances to advisers; and
  • automated renewal or consent assumptions.

The control must operate across trustees, platform administrators, advice licensees and product issuers, not merely within the entity that first receives the notification.


7. Misleading Debt Sales — $12 Million

Westpac sold written-off customer debts to third-party debt purchasers while providing inaccurate information about the interest rates applicable to those debts.

The conduct affected 16,535 customers with Westpac-branded cards and loans and St George-group cards, including Bank of Melbourne and BankSA products.

The misleading information affected both:

  • debt purchasers, who acquired debts using incorrect contractual information; and
  • customers, who were later pursued or had balances adjusted on an incorrect basis.

Westpac remediated approximately $17.72 million in customer loss and damage. During the penalty period, it had sold affected debts with a face value exceeding $83.6 million and received approximately $19.87 million from debt purchasers.

The Court imposed a $12 million penalty.

Compliance significance

Data supplied during debt sale is a regulated customer outcome, not merely a commercial warranty between seller and purchaser. Institutions require controls over:

  • contractual interest rates;
  • balance calculations;
  • product migrations;
  • data lineage;
  • reconciliation between source systems and sale files; and
  • post-sale customer corrections.

8. Undisclosed Contribution Fees — $6 Million

Westpac, Securitor and Magnitude charged contribution fees in connection with investment and superannuation products without ensuring that the fees had been adequately disclosed in statements of advice or other required documents.

The defendants admitted failures to maintain systems and processes that would:

  • prevent fees being charged where they should not have been charged;
  • prevent advisers or licensees retaining improperly charged fees;
  • ensure contribution fees were disclosed;
  • retain adequate disclosure records;
  • train staff properly; and
  • align application and fee-loading processes with the disclosure documents.

The exact number of affected clients could not be readily determined because adequate disclosure records had not been retained.

The Court imposed penalties of $2 million on each respondent, totalling $6 million.

Compliance significance

Poor records do not reduce regulatory exposure. In this case, inadequate recordkeeping prevented the defendants from readily determining how many clients had been improperly charged.

Fee governance therefore requires proof of:

  1. the legal basis for the fee;
  2. the disclosure made to the customer;
  3. any required consent;
  4. the system instruction implementing the fee; and
  5. the amount actually deducted.

9. Duplicate and Non-Consensual General Insurance — $15 Million

Westpac distributed general insurance policies in two problematic categories.

Duplicate policies

Approximately 3,899 customers were issued home, contents or landlord insurance policies where an existing policy already covered the same risk address for an overlapping period. Premiums were collected on both policies and renewal documents continued to issue.

The admitted contraventions included:

  • misleading or deceptive conduct;
  • false or misleading representations;
  • failures under ss 912A(1)(a), (c) and (ca); and
  • misleading conduct under s 1041H of the Corporations Act.

Policies issued without consent

A further 329 customers were issued policies without consenting to the relevant insurance.

The admitted contraventions included ss 12DA, 12DB and 12DM of the ASIC Act and ss 912A(1)(c) and 1041H of the Corporations Act.

The Court imposed an aggregate $15 million penalty and made compliance orders extending beyond the immediate duplicate-policy and non-consent issues.

Compliance significance

Product systems must detect overlapping cover by reference to:

  • customer identity;
  • insured address;
  • risk type;
  • policy period; and
  • group-wide product holdings.

Consent must also be affirmatively evidenced. The absence of a cancellation request is not evidence that a customer agreed to acquire a policy.


10. Key Legal Principles

Efficiently, honestly and fairly is an independent standard

Beach J rejected an approach that isolates one word in the composite phrase. The obligation must be construed as a whole.

The Court confirmed:

“Section 912A(1)(a) does not require dishonesty in the traditional or criminal sense”: at [62].

It may be contravened without intentional wrongdoing. It also does not require proof of a separate statutory, fiduciary or common-law breach because the statutory standard is itself the source of the obligation: at [63].

Compliance culture is demonstrated by operation, not expenditure

In assessing penalty, the Court treated compliance culture as a concept extending beyond expensive systems or personnel with governance and compliance titles. The relevant inquiry is whether the controls were understood, used, enforced and capable of preventing or correcting the conduct: at [122].

Cooperation and remediation reduce, but do not remove, penalty

The Court gave weight to admissions, cooperation, remediation and system improvements. However, these matters did not displace the need for penalties capable of deterring a large financial institution and the broader market.

Group structures require end-to-end accountability

Several matters involved different entities performing separate roles:

  • adviser;
  • advice licensee;
  • trustee;
  • administrator;
  • product issuer; and
  • payment remitter.

The orders demonstrate that each entity remains accountable for its own statutory role. A fragmented operating model is not a defence where data and control failures produce unlawful customer outcomes.


11. Risk Management and Compliance Recommendations

AudienceControl typeLegal rationaleRisk indicatorPractical control
BoardGovernanceRepeated systemic failures can attract group-scale penaltiesSimilar incidents across products and entitiesEnterprise conduct-risk aggregation and board reporting
AFSL holdersPreventativeSection 912A requires functioning systemsFees continue after cessation eventsAutomated stop triggers for death, deregistration and account closure
Product governancePreventativeFees and policies require valid authority and disclosureProduct charged without matched disclosure or consentDisclosure-to-system reconciliation
Data governanceDetectiveIncorrect source data can create misleading conductDebt-sale or policy data differs across systemsData lineage, validation and exception reporting
Advice licenseesPreventativeFees cannot continue where services cannot be providedDeceased or disengaged clients remain billedClient-status checks before each fee cycle
Super trusteesGovernanceTrustee systems must control deductions and remunerationAdviser payments continue after service entitlement endsFee-authority and remuneration reconciliation
Insurance operationsDetectiveDuplicate cover may be misleading and unfairSame customer and address with overlapping policiesGroup-wide duplicate-policy detection
ComplianceDetectiveFormal policies are inadequate without testingHigh control completion but repeated customer harmOutcome-based control testing
Internal auditDetectiveInadequate records obstruct impact assessmentUnable to identify disclosure given to clientsRecord completeness and retrievability testing
RemediationCorrectiveSystemic failures require cohort reviewKnown issue extends beyond complainantsData-led population identification and interest methodology

12. Recommended Next Steps

Financial institutions should:

  1. create enterprise-wide triggers for death, deregistration, insolvency, disengagement and other events that affect legal authority or service entitlement;
  2. reconcile fee deductions against disclosure, consent and actual service delivery;
  3. test for duplicate products and overlapping insurance across brands and entities;
  4. establish authoritative data sources for rates, balances, customer status and contractual terms;
  5. ensure control failures identified in one entity are assessed across the broader corporate group;
  6. preserve evidence of disclosure and consent in a readily retrievable form;
  7. report customer harm and remediation metrics alongside control-operation metrics;
  8. assign accountable executives to cross-entity customer journeys;
  9. validate that remediation identifies the complete affected population; and
  10. assess whether recurring operational failures indicate a broader s 912A(1)(a) issue.

13. Orders and Remedies

ProceedingPrincipal relief
Deregistered companiesDeclarations, $20 million penalty and costs
Insurance in superannuationDeclarations, $20 million penalty and costs
Deceased customer feesDeclarations, penalties totalling $40 million and costs
Debt salesDeclarations, $12 million penalty and costs
Contribution feesDeclarations, $6 million penalties and costs
General insuranceDeclarations, $15 million penalty, compliance orders and costs

The combined pecuniary penalties were $113 million.


14. Broader impact

  • Signals ASIC’s continued focus on consumer protection in the financial services sector.
  • May lead to increased scrutiny of financial product offerings and fee practices across the industry.
  • Highlights the potential for significant penalties for breaches of financial services laws.
  • Demonstrates the courts’ willingness to enforce strict compliance with regulations governing financial services.

This case is particularly significant as it addresses key issues of misconduct in the financial services sector, emphasising the importance of aligning business practices with legal and ethical standards. The decision serves as a potent reminder of the severe consequences of unethical practices in the financial services industry and the need for ongoing vigilance to maintain compliant, ethical operations.

This analysis is suitable for internal legal and compliance review, but final positions should be confirmed against the complete reasons, the separate orders in each proceeding and current law.

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?