A robust risk management framework (RMF) is required under s912A(1)(h). ASIC’s Regulatory Guide 259: Risk management systems of responsible entities and RG 104 provide practical guidance.
An advice-focused RMF should include:
- Risk appetite statement aligned with board and RM oversight.
- Registers for compliance, operational, and conduct risks;
- Controls and monitoring procedures (including advice file reviews);
- Incident escalation and breach reporting protocols;
- Annual independent reviews and board reporting cycles.
Advice firms should focus on identifying and managing real risks to their business rather than relying on superficial or purely aesthetic metrics. They recommend using meaningful lead indicators—such as control breaches, adviser workloads, system alerts and complaint trends—rather than lag indicators (like heat maps) that can distort or understate exposure. This proactive, evidence-based approach to risk management is consistent with their published articles and FAQs on Assured Support. For further reading on the limitations of lag indicators and the misuse of heat maps, read True Colours – Rethinking Heat Maps, which explains why compliance leaders should prioritise predictive metrics and qualitative insight over visualised but potentially misleading data.