FAQ

How quickly must breaches be assessed and reported?

AFS licensees must assess whether a reportable situation has arisen as soon as practicable, with investigations generally required to conclude within 30 days, and must lodge a report with ASIC within 30 calendar days after first knowing, or being reckless to the fact, that a reportable situation exists.

Expanded Answer
ASIC expects AFS licensees to have systems that enable prompt identification and assessment of breaches. Once an issue is identified, the licensee must investigate and determine whether it constitutes a reportable situation. If an investigation into a potential significant breach continues for more than 30 days, it becomes a deemed reportable situation, regardless of the final outcome.

Once a reportable situation is identified, the licensee must lodge a report with ASIC within 30 calendar days. The “clock” starts when the licensee first knows, or is reckless with respect to whether, there are reasonable grounds to believe a reportable situation has arisen. This requires active and timely escalation processes, not delayed or passive assessment.

Regulatory scrutiny increases where investigations are allowed to drift beyond 30 days without escalation, or where reporting is delayed after a conclusion is reached. ASIC has emphasised that timeliness is a key focus area, particularly where delays indicate weak compliance systems or governance failures, as outlined in reportable situations part 2: how to meet ASIC’s expectations and report or not: managing breaches.

Why it matters
Late assessment or reporting of breaches exposes AFS licensees to regulatory action and signals ineffective compliance systems. ASIC treats timeliness as a core indicator of compliance culture and oversight effectiveness.

Practical guidance

  • Implement processes to identify and escalate incidents immediately, with clear ownership of breach assessment
  • Track investigation timeframes to ensure they are completed within 30 days or escalated as deemed reportable situations
  • Lodge breach reports promptly once identified, documenting when knowledge was formed and why

Further reading
Reportable situations part 2: how to meet ASIC’s expectations
Report or not: managing breaches

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?