FAQ

Is a breach of s961B automatically reportable to ASIC?

No. ASIC’s breach reporting regime does not make a breach of s961B automatically reportable for AFS licensees. A best-interests duty failure is only reportable if it results in a significant breach of a core obligation under s912D, including where deemed significance applies and no regulatory carve-out (such as notional s912D(4AA)) is available.

Expanded Answer
Under the Corporations Act and ASIC Regulatory Guide 78, ASIC expects AFS licensees to report “reportable situations” where a breach of a core obligation is significant. A breach of s961B (best interests duty) is not itself determinative. Instead, the conduct is assessed through the core obligation framework, including representative obligations in Chapter 7 and the licensee’s obligation under s912A(1)(c). Those pathways typically engage civil penalty provisions such as ss 961K, 961Q or 961L, which can trigger deemed significance under s912D(4) or, if those do not apply, the objective test in s912D(5).

In practice, many s961B-related breaches will be reportable because they meet deeming thresholds, particularly where there is client loss, multiple affected clients, or evidence of systemic issues. However, ASIC’s modified regime introduces a narrow carve-out via notional s912D(4AA), which can exclude certain low-impact breaches from deemed significance where strict criteria are met, including limited client impact, minimal financial loss, and rectification within 60 days.

Even where that carve-out applies, ASIC expects licensees to reassess whether another reporting limb still applies, including material loss or damage or objective significance under s912D(5). This means an s961B-linked breach can be non-reportable, but only in tightly bounded, low-risk scenarios and with robust evidence supporting the conclusion.

Even where that carve-out applies, ASIC expects licensees to reassess other reporting triggers. A breach may still be reportable if it involves material loss or damage, indicates systemic issues, or is significant under s912D(5), particularly where compliance systems are inadequate. See further guidance in Reportable situations: how to meet ASIC’s expectations and ASIC’s findings on reportable situations.

Why it matters
Incorrectly treating s961B breaches as non-reportable creates enforcement risk. ASIC has identified under-reporting, poor incident identification, and weak breach governance as key failings. Misapplying deeming rules or carve-outs may indicate broader compliance system deficiencies, increasing the likelihood of regulatory scrutiny and action.

Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call

Practical guidance

  • Map the conduct to core obligations, including representative obligations and s912A(1)(c), before assessing reportability
  • Apply deemed significance tests first, then assess eligibility for notional s912D(4AA) using documented thresholds
  • Reassess material loss, systemic issues, and s912D(5) factors before concluding a breach is not reportable

Further reading

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?