AFSL holders must maintain adequate risk management systems appropriate to their business operations. This requirement arises from the general obligations in section 912A of the Corporations Act and is discussed in ASIC Regulatory Guide 104.
Many firms structure their risk management frameworks using principles from ISO 31000 risk management standards.
Risk management frameworks generally involve identifying operational, financial and compliance risks and implementing controls, monitoring processes and reporting structures to manage those risks.