FAQ

How do you assess whether a breach is reportable?

ASIC expects AFS licensees to assess reportability by determining whether there are reasonable grounds to believe a reportable situation has arisen, including significant breaches or likely breaches of core obligations, assessed by reference to impact, frequency, and systemic nature.

Expanded Answer
Under the reportable situations regime, ASIC requires AFS licensees to identify and assess whether a breach, or likely breach, meets the threshold for reporting. This includes breaches of key obligations such as providing financial services efficiently, honestly and fairly, as well as situations involving misconduct, gross negligence, or serious compliance failures. The assessment must be based on whether there are reasonable grounds to believe the situation is reportable.

In practice, licensees assess reportability by considering significance factors. These include the number and frequency of similar breaches, the impact on clients (including financial loss or disadvantage), the extent to which the breach indicates systemic issues, and how long the issue remained undetected. Breaches that are isolated and minor may not be reportable, but repeated or systemic issues are more likely to meet the threshold. Timeliness is critical, with strict timeframes applying once reportability is determined.

Regulatory scrutiny increases where licensees delay assessments, apply inconsistent thresholds, or fail to identify systemic issues. ASIC expects a structured and documented assessment process, with clear rationale for decisions. For practical guidance, see Reportable situations part 2: how to meet ASIC’s expectations and Report or not: managing breaches.

Why it matters
Failure to correctly assess and report breaches exposes licensees to civil penalties and heightened regulatory scrutiny. ASIC enforcement increasingly focuses on delays, under-reporting, and poor breach assessment frameworks.

Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call.

Practical guidance

  • Apply a structured assessment framework that tests each breach against significance factors such as impact, frequency, and systemic nature.
  • Document the rationale for reportability decisions, including why a matter is or is not considered reportable.
  • Escalate and assess breaches promptly to meet statutory timeframes and avoid delayed reporting risk.

Further reading
Breach reporting for ACLs: a definitive guide
Why compliance reporting matters for licensees

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?