AFS licensees must assess whether a reportable situation has arisen as soon as practicable, with investigations generally required to conclude within 30 days, and must lodge a report with ASIC within 30 calendar days after first knowing, or being reckless to the fact, that a reportable situation exists.
Expanded Answer
ASIC expects AFS licensees to have systems that enable prompt identification and assessment of breaches. Once an issue is identified, the licensee must investigate and determine whether it constitutes a reportable situation. If an investigation into a potential significant breach continues for more than 30 days, it becomes a deemed reportable situation, regardless of the final outcome.
Once a reportable situation is identified, the licensee must lodge a report with ASIC within 30 calendar days. The “clock” starts when the licensee first knows, or is reckless with respect to whether, there are reasonable grounds to believe a reportable situation has arisen. This requires active and timely escalation processes, not delayed or passive assessment.
Regulatory scrutiny increases where investigations are allowed to drift beyond 30 days without escalation, or where reporting is delayed after a conclusion is reached. ASIC has emphasised that timeliness is a key focus area, particularly where delays indicate weak compliance systems or governance failures, as outlined in reportable situations part 2: how to meet ASIC’s expectations and report or not: managing breaches.
Why it matters
Late assessment or reporting of breaches exposes AFS licensees to regulatory action and signals ineffective compliance systems. ASIC treats timeliness as a core indicator of compliance culture and oversight effectiveness.
Practical guidance
- Implement processes to identify and escalate incidents immediately, with clear ownership of breach assessment
- Track investigation timeframes to ensure they are completed within 30 days or escalated as deemed reportable situations
- Lodge breach reports promptly once identified, documenting when knowledge was formed and why
Further reading
Reportable situations part 2: how to meet ASIC’s expectations
Report or not: managing breaches