FAQ

What should an internal audit program look like for an AFSL?

ASIC expects AFS licensees to maintain an internal audit or review program that provides independent, risk-based assurance over compliance systems and controls, with documented testing, findings, and remediation to demonstrate that obligations are effectively monitored and managed.

Expanded Answer
ASIC does not prescribe a specific internal audit structure but expects licensees to have arrangements that test and verify the effectiveness of their compliance and risk management systems. An internal audit program should be risk-based, targeting higher-risk areas such as advice quality, breach reporting, AML/CTF, and governance. The program must be able to identify control weaknesses and systemic issues, not just confirm process completion.

In practice, an effective internal audit program includes a documented audit plan, defined scope, and regular testing cycles (often annual or rolling). Reviews should assess whether controls are designed appropriately and operating effectively, using file reviews, data analysis, and control testing. Independence is critical—this may be achieved through separate internal functions or external reviewers. Findings must be clearly documented, rated, and linked to remediation actions, with progress tracked and reported to senior management or the board.

Regulatory scrutiny increases where audit programs are superficial, checklist-driven, or fail to drive change. ASIC expects evidence that issues identified through audit are escalated, addressed, and re-tested. For practical expectations, see Compliance 101: reviews and audits and A practical guide to high-level file reviews for licensees and advisers.

Why it matters
A weak internal audit program fails to detect systemic issues and exposes licensees to regulatory action. ASIC increasingly focuses on whether licensees test and verify their controls, not just document them.

Unsure how this applies to you?
Get a clear answer in a 15-minute call with a compliance specialist. Book your call.

Practical guidance

  • Develop a risk-based audit plan that prioritises high-risk areas such as advice quality, breaches, and AML/CTF controls.
  • Ensure audit independence and depth by separating reviewers from operational roles or using external assurance where needed.
  • Track and evidence remediation, including clear ownership, timelines, and re-testing of previously identified issues.

Further reading
Preparing for a compliance review: key considerations
From samples to signals: a smarter approach to AFSL surveillance

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?