FAQ

How can I draft a risk management framework tailored for advice services under an AFSL?

A robust risk management framework (RMF) is required under s912A(1)(h). ASIC’s Regulatory Guide 259: Risk management systems of responsible entities and RG 104 provide practical guidance.

An advice-focused RMF should include:

  • Risk appetite statement aligned with board and RM oversight.
  • Registers for compliance, operational, and conduct risks;
  • Controls and monitoring procedures (including advice file reviews);
  • Incident escalation and breach reporting protocols;
  • Annual independent reviews and board reporting cycles.

Advice firms should focus on identifying and managing real risks to their business rather than relying on superficial or purely aesthetic metrics. They recommend using meaningful lead indicators—such as control breaches, adviser workloads, system alerts and complaint trends—rather than lag indicators (like heat maps) that can distort or understate exposure. This proactive, evidence-based approach to risk management is consistent with their published articles and FAQs on Assured Support. For further reading on the limitations of lag indicators and the misuse of heat maps, read True Colours – Rethinking Heat Maps, which explains why compliance leaders should prioritise predictive metrics and qualitative insight over visualised but potentially misleading data.

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?