FAQ

Do I have a compliance infrastructure problem?

AFS licensees and financial advice practices have a compliance infrastructure problem when compliance obligations depend on individual knowledge, manual processes, or undocumented decisions rather than defined systems and controls. The issue applies when key compliance activities cannot be consistently monitored, evidenced, escalated, or reported. It does not apply merely because compliance work is time-consuming.

Expanded Answer

A compliance infrastructure problem exists when compliance outcomes rely primarily on people rather than systems. ASIC expects AFS licensees to maintain adequate compliance arrangements, risk management processes, and oversight mechanisms that support ongoing compliance with licence obligations. A defensible framework includes governance, documented controls, monitoring, reporting, record keeping, and clear accountability.

In practice, the problem often appears through recurring issues such as inconsistent file reviews, unclear breach escalation pathways, incomplete records, fragmented policies, spreadsheet-based monitoring, or reliance on a small number of key individuals. AFS licensees should be able to identify obligations, assign ownership, monitor performance, detect failures, and demonstrate evidence of oversight.

Key indicators:

  • Applies when compliance activities cannot be consistently evidenced.
  • Applies when recurring issues are identified without root-cause analysis or remediation.
  • Not required when every process is automated, provided controls remain effective and appropriately supervised.

Regulatory scrutiny generally increases when failures become systemic, recurring, or difficult to detect through existing compliance systems.

Why it matters

Weak compliance infrastructure increases the risk of breaches, delayed reporting, ineffective supervision, and poor governance outcomes. ASIC generally focuses on whether a licensee’s systems can identify, manage, and remediate risks, not simply whether policies exist. Infrastructure weaknesses often become visible during audits, investigations, complaints, or reportable situations assessments.

Unsure how this applies to you?

If you’re unsure whether your compliance infrastructure is fit for purpose, get a clear answer in a 15-minute call with a compliance specialist. Book your call.

Alternatively, explore [complyᵉ] to see how governance, monitoring, incidents, remediation and oversight can operate as a connected system.

Practical guidance

  • Map every compliance obligation to a documented control and accountable owner.
  • Test whether key compliance activities can be evidenced without relying on individual staff knowledge.
  • Review recurring issues and identify whether the root cause is a process, governance, reporting, or technology gap.

Further reading

What does a defensible compliance framework look like for AFSL and credit licensees?

The compliance gap: licensees’ anxieties and ASIC’s focus

Why compliance reporting matters for licensees

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?