ASIC expects an AFSL to demonstrate that its compliance framework operates effectively in practice. Preparation should focus on producing clear evidence of governance, supervision, monitoring, breach management, risk management, and recordkeeping. An AFSL should be able to show how obligations are identified, monitored, escalated, and remediated, rather than relying solely on policies or procedural documents.
Expanded Answer
An ASIC surveillance or compliance review is typically an assessment of how an AFSL manages its regulatory obligations in practice. ASIC increasingly focuses on operational evidence, decision-making processes, governance arrangements, and whether compliance controls are functioning effectively. The review is rarely limited to written policies. Regulators generally seek evidence that compliance activities occur consistently and that management receives reliable information about emerging risks and issues.
For most AFSLs, preparation should include reviewing governance records, compliance registers, breach assessments, complaints data, training records, adviser supervision evidence, file review outcomes, risk registers, remediation actions, and board or management reporting. Records should be complete, current, and capable of demonstrating how issues were identified, assessed, escalated, and resolved. Inconsistencies between policies and actual practices frequently attract regulatory attention.
Key preparation activities:
- Confirm compliance registers, risk registers, and remediation logs are current and accurate.
- Verify that supervision, surveillance, and file review programs are supported by evidence.
- Test whether breach reporting, complaints handling, and escalation processes can be demonstrated through records.
- Review previous audit, review, and surveillance findings to confirm corrective actions were completed and documented.
Why it matters
ASIC surveillance often assesses whether an AFSL can prove compliance rather than merely describe it. Poor documentation, incomplete remediation records, weak supervision evidence, or inconsistent governance reporting can increase regulatory scrutiny and may reveal broader compliance weaknesses requiring remediation.
Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call
Practical guidance
- Review governance, risk, compliance, breach, complaint, and supervision records for completeness and consistency.
- Prepare evidence showing how compliance issues were identified, escalated, investigated, and remediated.
- Conduct a mock regulatory review using recent adviser files, management reports, and compliance registers.
Further reading
How to respond to an ASIC notice: a practical step-by-step guide for licensees
What Does a Defensible Compliance Framework Look Like for AFSL and Credit Licensees?