Breach Reporting Obligations
Regulatory Guide 78, which was last updated in April 2023, has set the expectations for dealing with reportable situations. As indicated in the RG, AFS licensees and credit licensees have record-keeping obligations when breaches occur, this means licensees must maintain documentation of breaches, including details of the incident, actions taken, and any resolution measures.
However, certain breaches, and misconduct, are also required, by mandate, to be reported specifically to ASIC in order to improve transparency and accountability in the financial services. These include:
- Significant breaches of core obligations, fraud, and gross negligence; or
- Investigations into a potential breach that lasts more than 30 calendar days.
All breaches that meet one of the above criteria require to be reported within 30 calendar days of identifying the reportable situation.
The reporting expectations are extended to encompass the requirement to report the misconduct of representatives of other licensees.
Updates to Breach Reporting Obligations
On 18th February 2025, ASIC proposed the “CS16 Reportable situation- additional relief” consultation paper, which was open for feedback until March 11th, 2025.
This proposed amendment to the reportable situation regime aims to create consistency across breach reporting, as well as ensuring clarity, structure, and high-value reporting from licensees continues, without additional challenges for the licensee.
The key area of change in the reporting obligations is they exemptions to ASIC reportable situations. These include the need to not report breaches, of misleading or deceptive conduct, to ASIC if:
- The breach is rectified within 30 calendar days
- No more than five (5) consumers are impacted
- The total financial loss is below $500; and
- The breach does not involve client money or clearing and settlement reporting requirements.
While these amendments create exemptions from the requirement to report these breaches, or reportable situations, to ASIC, they are still required to be documented on the licensee’s breach record-keeping register.
Opportunity for Feedback
ASIC has provided another opportunity for licensees to give feedback, on IDR reporting requirements, until May 14th, 2025.
This consultation paper is titled “CP 383 Reportable situations and internal dispute resolution data publication” and can be found here: https://asic.gov.au/regulatory-resources/find-a-document/consultations/cp-383-reportable-situations-and-internal-dispute-resolution-data-publication/
If you require further information about your breach reporting requirements, please contact as at support@grcessentials.com

0 Comments