ASIC expects AFS licensees to lodge reportable situations through the Regulatory Portal by creating a report, categorising the breach, linking it to relevant obligations, and updating the report over time. The process is a lifecycle obligation requiring ongoing updates, investigation tracking, and final remediation outcomes.
Expanded Answer
ASIC expects AFS licensees to report significant breaches and likely breaches using the Reportable Situations regime via the Regulatory Portal. The obligation extends beyond initial notification. ASIC expects licensees to assess, report, investigate, and update reportable situations as they evolve, consistent with breach reporting obligations under the Corporations Act.
In practice, the process involves the following steps:
- Navigate to Reportable Situations in the Regulatory Portal
- Create a new reportable situation
- Describe the incident clearly, including facts and timing
- Categorise the breach type and affected services
- Link the issue to relevant legal obligations and licence conditions
- Submit the initial report within the required timeframes
- Provide ongoing updates as investigations progress
- Record remediation actions and client impact
- Submit final outcomes, including root cause and rectification
What’s changed
ASIC now treats breach reporting as a lifecycle process rather than a one-off lodgement. ASIC has ongoing visibility of the matter, including investigation progress and remediation. Regulatory risk increases where updates are delayed, breach significance is misclassified, or remediation is incomplete or poorly evidenced. For further context, see Reportable situations part 1: ASIC’s findings and why they matter and Reportable situations part 2: how to meet ASIC’s expectations.
Why it matters
Reportable situations are a core enforcement dataset for ASIC. Incomplete, late, or poorly managed reports can lead to regulatory scrutiny, enforcement action, and reputational risk, particularly where systemic issues or client harm are involved.
Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call.
Practical guidance
- Assess breach significance early and document the basis for reportability decisions.
- Update reportable situations promptly as investigations and remediation progress.
- Track remediation outcomes and root causes to demonstrate effective resolution and prevent recurrence.
Further reading
Reportable situations part 1: ASIC’s findings and why they matter
Reportable situations part 2: how to meet ASIC’s expectations