In short
An AFSL compliance document suite typically comprises a compliance manual, risk management framework, conflicts of interest policy, complaints (IDR) policy aligned to ASIC RG 271, breach reporting procedures and a training and competence register. It exists to demonstrate the licensee's compliance with its general obligations under section 912A of the Corporations Act 2001 (Cth), not just to sit in a drawer.
Why licensees need more than a template
Section 912A of the Corporations Act 2001 (Cth) requires an AFSL holder to have adequate arrangements for managing conflicts of interest, adequate risk management systems, and adequate resources including compliance staff and monitoring systems. ASIC does not accept a downloaded template as evidence of any of that. When an authorised representative goes rogue, a client complains, or a breach report is lodged, the first thing ASIC asks for is the compliance manual and evidence it was actually followed. A document that has never been updated since licensing, or that describes controls the business doesn't run, is worse than no document at all — it shows the licensee's own paper trail contradicts its conduct.
We build the suite around the business as it actually operates: the products authorised on the licence, the distribution channels used, and the number and type of representatives. A digital advice business, a mortgage aggregator, and a wholesale funds manager need materially different compliance architecture even though all three hold an AFSL.
What sits inside the suite
The core compliance manual sets out governance structure, the responsible manager's authority, escalation paths and the licensee's obligations under its licence conditions. Sitting alongside it, the risk management framework maps regulatory, operational, conduct and financial risks to specific controls and named owners — this is the document ASIC's surveillance teams increasingly ask for by name, and it is also required by ASIC as a condition of licensing for most applicants.
The breach reporting procedure has to reflect the reportable situations regime introduced by the Financial Sector Reform (Hayne Royal Commission Response) Act, including the 30-day reporting trigger to ASIC for significant breaches and the requirement to notify affected clients. We draft this as an operational workflow, not a policy statement, because the people who need to use it under time pressure are advisers and operations staff, not lawyers.
- Compliance manual and governance structure
- Risk management framework (regulatory, conduct, operational, financial risk)
- Conflicts of interest policy and register
- Internal dispute resolution (IDR) policy aligned to ASIC RG 271
- Breach and reportable situations procedure
- Training, competence and CPD tracking register
The clauses and controls that get tested first
ASIC's licensing and surveillance teams focus disproportionately on three things: whether the conflicts of interest policy actually names the conflicts the business has (related party product recommendations, referral commissions, in-house platform preferencing), whether the IDR policy meets the maximum response timeframes and internal escalation requirements in RG 271, and whether representative supervision is evidenced with dated file notes rather than asserted in a policy document. We build monitoring and supervision templates into the suite so the licensee has something to show, not just something to say.
How this interacts with your AFS Licence conditions and representative agreements
The compliance suite has to be read together with the licence conditions ASIC imposed at authorisation and with each authorised representative agreement, because supervision obligations and product authorisations flow through both documents. We cross-check the suite against the current licence conditions on the ASIC Connect register before finalising, and we align the training register with the competency standards that apply to the specific financial products the licensee is authorised to deal in or advise on.
What we deliver
A working set of documents built for the licensee's actual authorisations and distribution model, cross-referenced against current licence conditions, with editable templates for the registers that need to be maintained (breach register, conflicts register, training log) rather than static PDFs.
What the fixed fee covers
- Compliance manual tailored to licence authorisations
- Risk management framework with named risk owners
- Conflicts of interest policy and register template
- IDR policy aligned to ASIC RG 271
- Breach and reportable situations workflow
- Training and competence register template
Mistakes we see
- Using a generic template that references product authorisations the licensee doesn't hold
- IDR timeframes that don't match the maximum response periods in RG 271
- Conflicts policy that doesn't name the licensee's actual conflicts (referral fees, related platforms)
- No evidence trail for representative supervision beyond the policy document itself
- Breach procedure that omits the 30-day reportable situations trigger
Who this is for
- New AFSL applicants preparing for lodgement
- Existing licensees due for a compliance review
- Licensees onboarding new authorised representatives
- Businesses expanding authorisations to new product classes
Frequently asked questions
- Do we need a full compliance suite if we only have one responsible manager and no representatives?
- Yes, in a scaled-down form. Section 912A applies regardless of headcount, and ASIC assesses adequacy relative to the business's size and complexity, not against a fixed checklist. A sole-operator licensee still needs a documented risk framework, conflicts policy and IDR process, just without the supervision layer a multi-representative business requires.
- How often does the suite need to be updated?
- At minimum annually, and whenever there's a material change to authorisations, products, distribution channels or key personnel. ASIC expects the compliance manual to reflect the business as it currently operates, so a document that hasn't moved in three years while the business has grown is a red flag in its own right.
- Does this cover AML/CTF obligations too?
- No. AML/CTF Program obligations under the AML/CTF Act 2006 sit in a separate document because they're triggered by different obligations (reporting entity status) and audited by AUSTRAC rather than ASIC. We cross-reference the two where relevant, particularly around client due diligence and record-keeping, but they're built and maintained separately.
- Will this help if ASIC is already conducting a surveillance review of us?
- It can, but timing matters. If a review has already commenced, engage us early so the documents we prepare reflect the actual conduct ASIC is examining rather than retrofitting policy after the fact, which surveillance teams are trained to spot.
- Do responsible managers need to sign off on the suite personally?
- We recommend it. Responsible manager sign-off creates a documented accountability trail that supports the licensee's position that the framework was properly authorised and adopted, which matters if ASIC later questions whether the board or RM genuinely engaged with the compliance framework.
Related
