Guides · Financial Services Guide · Chapter 7 of 7

Breach reporting, remediation and enforcement

Last reviewed 29 August 2026

The reportable situations regime, how to run an incident, client remediation, and what to expect from ASIC surveillance and enforcement.

In short

Licensees must report reportable situations to ASIC within 30 calendar days of first knowing, or being reckless as to whether, there are reasonable grounds to believe one has arisen. Certain breaches are deemed significant. The clock starts at knowledge of reasonable grounds — not at the end of your investigation — so incident triage must be fast and documented.

Every licensee will have breaches. What distinguishes a well-run licensee is the speed and discipline with which it identifies, reports and fixes them.

The reportable situations regime

The obligation covers significant breaches and likely breaches of core obligations, investigations into whether a significant breach has occurred that run beyond 30 days, conduct constituting gross negligence or serious fraud, and certain matters about other licensees' representatives. Some breaches are deemed significant by the legislation — including breaches of specified civil penalty provisions, conduct constituting an offence punishable above a set threshold, and conduct resulting in material loss or damage to clients. For everything else, significance is assessed against statutory factors including the number and frequency of similar breaches, the impact on the ability to provide services, and the extent of resulting loss.

Reports are lodged through ASIC's prescribed portal within 30 calendar days. Late reporting is itself a breach, and it is one ASIC can identify simply by comparing your incident log to your lodgements.

Running an incident

  1. Log immediately. Date and time of identification, source, description, systems and clients potentially affected.
  2. Contain. Stop the conduct continuing before you finish analysing it.
  3. Triage against the reporting test quickly, and record the reasoning either way. A documented decision not to report is defensible; an undocumented one is not.
  4. Scope. Determine the full population affected and the period. Under-scoping is the most common remediation failure.
  5. Report within time, and update ASIC as the investigation develops.
  6. Remediate clients, including interest where money was wrongly taken or withheld.
  7. Fix root cause and record the control change, then test that the change worked.

Client remediation

ASIC expects remediation to be timely, fair and comprehensive, with the licensee bearing the cost and adopting assumptions favourable to clients where records are incomplete. Remediation programs should have a governance structure, defined methodology, an independent review element for larger programs, and clear client communications.

Surveillance and enforcement

ASIC's contact usually begins with a request for information or a notice to produce. Responses should be accurate, complete and on time; scope should be clarified in writing rather than assumed; and privileged material should be identified before production. Escalation paths run through additional licence conditions, infringement notices, enforceable undertakings, licence variation, suspension or cancellation, banning orders against individuals, and civil penalty or criminal proceedings.

The practical posture

Licensees that fare best are those whose records show they found the problem themselves, escalated it immediately, reported it on time, remediated fully and changed the control. That narrative is built in the weeks after an incident, not in the response to a notice — which is why the incident log and the remediation file matter more than any policy document.

Where this fits

We advise on breach assessment and reporting, run remediation scoping, and manage ASIC correspondence — on a fixed fee agreed before we start.

Talk to us

Want this applied to your business?

Send us a note about what you're working on. We'll respond within one business day and, if we're a fit, book a free 15-minute consultation with a senior lawyer.

We treat every message as confidential.

CallBook Call