FAQ

How should an AFS licensee prepare for an ASIC or AUSTRAC review?

ASIC and AUSTRAC expect AFS licensees to maintain readily accessible, accurate, and complete records that evidence compliance with obligations, and to demonstrate that systems, controls, and governance are operating effectively, not just documented, when responding to a regulatory review.

Expanded Answer
ASIC and AUSTRAC reviews focus on whether a licensee can evidence compliance in practice. This includes demonstrating that advice processes, AML/CTF programs, breach reporting, and governance arrangements are implemented, monitored, and effective. Regulators typically request documents, data, and explanations that show how obligations are met and how risks are identified and managed.

In practice, preparation involves ensuring that key frameworks are current, internally consistent, and supported by evidence. This includes compliance policies, AML/CTF programs, breach registers, training records, file reviews, and governance reporting. Licensees should be able to show a clear link between policies, controls, monitoring activities, and outcomes. Data integrity is critical—records provided must reconcile with internal systems and reporting.

Regulatory scrutiny increases where documentation is incomplete, inconsistent, or not reflective of actual practices. ASIC and AUSTRAC place significant weight on evidence of control effectiveness, including testing, remediation, and oversight. Being able to respond clearly and consistently to information requests is a key indicator of a well-managed compliance framework. For practical preparation steps, see Preparing for a compliance review: key considerations and How to respond to an ASIC notice: a practical step-by-step guide for licensees.

Why it matters
Poor preparation increases the risk of adverse findings, extended regulatory engagement, and enforcement action. Regulators assess not only compliance but the licensee’s ability to evidence and explain it, making preparation a critical control.

Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call.

Practical guidance

  • Pre-position key documents and records, ensuring they are current, consistent, and aligned with actual business practices.
  • Test your ability to respond to regulator-style requests, including data extraction, file retrieval, and explanation of processes.
  • Review recent breaches, complaints, and audit findings to ensure issues are addressed and clearly documented.

Further reading
What auditors actually test and why checklists fail
Why AML programs fail adviser audits

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?