FAQ

How should an AFSL prepare for an ASIC surveillance, compliance review, or regulatory visit?

ASIC expects an AFSL to demonstrate that its compliance framework operates effectively in practice. Preparation should focus on producing clear evidence of governance, supervision, monitoring, breach management, risk management, and recordkeeping. An AFSL should be able to show how obligations are identified, monitored, escalated, and remediated, rather than relying solely on policies or procedural documents.

Expanded Answer

An ASIC surveillance or compliance review is typically an assessment of how an AFSL manages its regulatory obligations in practice. ASIC increasingly focuses on operational evidence, decision-making processes, governance arrangements, and whether compliance controls are functioning effectively. The review is rarely limited to written policies. Regulators generally seek evidence that compliance activities occur consistently and that management receives reliable information about emerging risks and issues.

For most AFSLs, preparation should include reviewing governance records, compliance registers, breach assessments, complaints data, training records, adviser supervision evidence, file review outcomes, risk registers, remediation actions, and board or management reporting. Records should be complete, current, and capable of demonstrating how issues were identified, assessed, escalated, and resolved. Inconsistencies between policies and actual practices frequently attract regulatory attention.

Key preparation activities:

  • Confirm compliance registers, risk registers, and remediation logs are current and accurate.
  • Verify that supervision, surveillance, and file review programs are supported by evidence.
  • Test whether breach reporting, complaints handling, and escalation processes can be demonstrated through records.
  • Review previous audit, review, and surveillance findings to confirm corrective actions were completed and documented.

Why it matters

ASIC surveillance often assesses whether an AFSL can prove compliance rather than merely describe it. Poor documentation, incomplete remediation records, weak supervision evidence, or inconsistent governance reporting can increase regulatory scrutiny and may reveal broader compliance weaknesses requiring remediation.

Unsure how this applies to you?

Get a clear answer in a 15-minute call with a compliance specialist. Book your call

Practical guidance

  • Review governance, risk, compliance, breach, complaint, and supervision records for completeness and consistency.
  • Prepare evidence showing how compliance issues were identified, escalated, investigated, and remediated.
  • Conduct a mock regulatory review using recent adviser files, management reports, and compliance registers.

Further reading

How to respond to an ASIC notice: a practical step-by-step guide for licensees

What Does a Defensible Compliance Framework Look Like for AFSL and Credit Licensees?

Preparing for a compliance review: key considerations

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?