
Zoe Beesley
14 Sept 2026
From conduct obligations to reporting, here's what AFSL holders need to prioritise in the year ahead.
For many financial services businesses, the question used to be:
Are we compliant?
In 2026–27, the better question is:
Can we demonstrate that our business is being actively governed, monitored and improved?
That is a meaningful shift.
An Australian Financial Services Licence ("AFSL") comes with ongoing obligations around areas such as organisational competence, compliance, risk management, supervision and record-keeping.
ASIC's regulatory work increasingly highlights the importance of whether systems and controls operate effectively in practice—not simply whether the policy document exists.
For AFSL license holders, that means compliance needs to move closer to the center of business operations.
The compliance framework needs to reflect the real business
A common weakness in compliance programs is that they describe an organisation that no longer exists.
The business may have changed its products, outsourced functions, introduced new technology, grown its authorised representative network, adopted AI tools or changed its customer acquisition strategy—but the compliance framework remains largely unchanged.
That creates a dangerous gap between documented compliance and operational compliance.
A useful 2026–27 review might ask:
Does our compliance framework reflect what we actually do?
Are our financial products and services being distributed in the way our governance documents assume?
Do our people understand their obligations?
Are incidents being identified and escalated early?
Can management demonstrate that issues are being remediated?
Are outsourced providers subject to appropriate oversight?
Are our compliance reports telling directors something useful, or simply producing paperwork?
The answers matter more than the thickness of the compliance manual.
Reportable situations should be treated as intelligence
The reportable situations regime remains one of the areas where a mature compliance function can distinguish itself.
ASIC's guidance makes clear that AFS licensees have obligations to identify and report relevant reportable situations, and that specific circumstances can also trigger obligations to notify affected clients, investigate the matter and remediate affected consumers. ASIC's reportable situations data also provides a useful industry-level view of the types of breaches being identified and how AFS licensees are responding to them.
The important operational lesson is that breach reporting should not sit in isolation from the rest of the business.
A recurring complaint, failed control, staff error or technology problem may each look relatively small when viewed individually. Collectively, however, they can reveal a systemic weakness.
The question for management should therefore be:
What are our incidents telling us about the business?
A good incident register is not just a compliance record. It is a source of management information.
AI changes the compliance conversation
AI is making this even more important.
ASIC's 2026 outlook specifically identifies risks associated with advanced technology, automated decision-making, AI-driven interactions, scams and agentic AI.
ASIC has also highlighted the need for financial services businesses to maintain robust risk management and operational resilience.
That means businesses should be asking:
Where is AI already being used in our organisation?
Not just formally approved AI systems. Consider:
marketing content;
customer communications;
advice preparation;
research;
coding and software development;
document review;
fraud detection;
customer service;
recruitment;
internal decision-making.
The governance question is not simply whether employees are permitted to use an AI tool.
It is whether the organisation understands what decisions AI is influencing, what information is being entered into those systems, who is accountable for its use and outputs, and what happens when the output is wrong.
The 2026–27 AFSL health check
For many businesses, a practical annual review could be organised around six questions:
Governance
Are roles, responsibilities and escalation pathways clear?
People
Do staff and representatives understand the obligations relevant to their actual roles?
Products
Are products being designed, approved, marketed and distributed consistently with the business's obligations?
Incidents
Are breaches, complaints and near misses identified and escalated consistently?
Technology and third parties
Can the business explain its dependence on critical systems and service providers?
Evidence
If ASIC asked, 'Show us how you know these controls work,' could the business answer confidently?
That final question is perhaps the most useful.
Compliance should make the business stronger
The strongest compliance teams are not the ones that say "no" most often.
They are the ones that help management understand where the business can safely say yes.
That requires a move away from compliance as an annual exercise and towards compliance as an operating discipline.
For 2026–27, the opportunity for AFSL holders is to build systems that are proportionate, commercially useful and capable of demonstrating genuine oversight.
The license may give you permission to operate.
Good governance is what helps you keep earning that permission every day.
Sources:
ASIC, RG 78 Breach reporting by AFS licensees and credit licensees;
ASIC, Complying with the notify, investigate and remediate obligations;
ASIC, Reportable situations for AFS and credit licensees; and
ASIC, Key issues outlook 2026.
Disclaimer: This article is provided for general information and educational purposes only and does not constitute financial, legal, regulatory, tax, accounting or other professional advice. Regulatory requirements and guidance can change. Readers should check current primary sources and seek independent professional advice where appropriate.