<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:wfw="http://wellformedweb.org/CommentAPI/"
     xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:atom="http://www.w3.org/2005/Atom"
     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
     xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
    >
    <channel>
        <title>AdviserVoiceSimon Carrodus Archives - AdviserVoice</title>
        <atom:link href="https://www.adviservoice.com.au/tag/simon-carrodus/feed/" rel="self" type="application/rss+xml" />
        <link>https://www.adviservoice.com.au/tag/simon-carrodus/</link>
        <description>Financial planner information &#38; financial planner education/CPD - AdviserVoice</description>
        <lastBuildDate>Mon, 27 Jul 2026 09:08:33 +0000</lastBuildDate>
        <language>en-US</language>
        <sy:updatePeriod>hourly</sy:updatePeriod>
        <sy:updateFrequency>1</sy:updateFrequency>
        <generator>https://wordpress.org/?v=7.0.2</generator>
                    <item>
                <title>Ready or not: How to prepare your organisation for a data breach</title>
                <link>https://www.adviservoice.com.au/2022/11/ready-or-not-how-to-prepare-your-organisation-for-a-data-breach/</link>
                <comments>https://www.adviservoice.com.au/2022/11/ready-or-not-how-to-prepare-your-organisation-for-a-data-breach/#respond</comments>
                <pubDate>Mon, 21 Nov 2022 21:00:03 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Best Practice]]></category>
		<category><![CDATA[Alex Ninis]]></category>
		<category><![CDATA[Sarah Gilkes]]></category>
		<category><![CDATA[Simon Carrodus]]></category>
		<category><![CDATA[Sophie Bradshaw]]></category>
                <guid isPermaLink="false">https://www.adviservoice.com.au/?p=86251</guid>
                                    <description><![CDATA[<div id="attachment_86254" style="width: 660px" class="wp-caption alignleft"><img fetchpriority="high" decoding="async" aria-describedby="caption-attachment-86254" class="size-full wp-image-86254" src="https://www.adviservoice.com.au/wp-content/uploads/2022/11/Bradshaw-Sophie-650.png" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2022/11/Bradshaw-Sophie-650.png 650w, https://www.adviservoice.com.au/wp-content/uploads/2022/11/Bradshaw-Sophie-650-300x162.png 300w" sizes="(max-width: 650px) 100vw, 650px" /><p id="caption-attachment-86254" class="wp-caption-text">Sophie Bradshaw</p></div>
<h3>Cyber-attacks and other data breaches are, unfortunately, inevitable. But there are key steps every organisation should take to prepare for when the inevitable happens.</h3>
<p>Responding to a significant cyber incident or other major data breach is often a time of crisis for any organisation.  Anyone who has led or been part of the response team knows that these events are stressful for staff and require dedicated time and resources (both internal and external).</p>
<p>Regardless of your organisation’s size or regulatory obligations, with the cyber risk landscape becoming more complex, the Optus data breach <sup>[1]</sup>should be a clear warning sign to all organisations to prepare now, and prepare well, for the inevitable.</p>
<h2>Are you prepared?</h2>
<p>Preparation for a data breach should be seen as part of an organisation’s overall risk management framework.</p>
<p>As to what “prepared” looks like will depend on the organisation: you will need an understanding of your cyber threats and controls, what and where your “crown jewels” are (including but not limited to your data), and your legal obligations with respect to information security and reporting in the event of a data breach or cyber security incident.</p>
<p>Preparation should be considered across all business functions (not just IT), processes, people and levels within the organisation right up to the Board.  This is because data breaches are not just a result of malicious cyber attacks – people (and more often than not, human error) is consistently reported as one of the leading causes of notified data breaches<sup>[2]</sup> in Australia.</p>
<h2>Have a plan</h2>
<p>The cornerstone of your preparedness is having a documented response plan. Whether called a data breach response plan or a security incident response plan, if there is one step your organisation takes now, it should be to make sure you have one.</p>
<p>Having an actionable and tested plan will put your organisation in a position where it can meet its reporting obligations within the required timeframes and mitigate the risk of statutory non-compliance or breach of contract. This may include statutory reporting obligations under the Notifiable Data Breaches (NDB) scheme contained in the <em>Privacy Act 1988</em> (Cth) and, if applicable to your organisation, cyber security incident reporting obligations under the <em>Security of Critical Infrastructure Act 2018</em> (Cth). Your organisation may also have various other statutory reporting obligations to regulators, in Australia and overseas, as well as contractual obligations to report to government and other third parties, such as funding bodies.</p>
<p>In addition to helping the organisation meet its reporting obligations and manage the legal and reputational risks associated with a major data breach, having an actionable and tested plan is key to providing clear direction, mobilising stakeholders and maintaining a sense of order in a time of crisis.</p>
<h2>What to include in your data breach response plan</h2>
<p>For a data breach response plan to be useful, it needs to be easy to understand, tailored to your organisation and it must be actionable. This means the plan should tell the reader:</p>
<ol type="1">
<li>Who do I contact first if I know or suspect a cyber-attack or data breach affecting the organisation? What are the contact details for that person and a nominated alternative contact, including out-of-hours phone numbers?</li>
<li>What are the roles and responsibilities for internal teams responding to the data breach (for example, which person/team is responsible for the initial investigation? When should the privacy team be engaged?)</li>
<li>What are our reporting obligations, including timeframes? Who within the organisation makes the decision as to when and how we engage with law enforcement, our insurers and when and how we notify regulators, affected individuals and others?</li>
<li>When and how do we engage external legal and other advisers (such as for forensic technology and cyber security, communications or public relations services)? What are the contact names, emails and out-of-hours contact details for the external stakeholders? How do we maintain legal professional privilege if we are engaging a third party to provide an investigation report?</li>
<li>How do we deal with any requests for information (whether from staff, customers or the media)? Do we have any templated communications (proactive and reactive) ready that we can update for the incident?</li>
<li>How will we deal with privacy complaints? Can our customer service team/call centre deal with an increased volume in calls, or do we have a process to stand-up additional support?</li>
<li>What is the plan for where remediation requires support for affected individuals?</li>
</ol>
<p>The Office of the Australian Information Commissioner (OAIC) provides a number of useful resources for organisations. The Data Breach Preparation and Response Guide<sup>[3]</sup> contains a comprehensive description of what your data breach response plan should cover and a checklist.  This is a useful starting point and should be tailored for your particular organisation and, at a minimum, answer the above questions.</p>
<h2>Don’t set and forget</h2>
<p>We know from the recent Federal Court decision in <em>RI Advice</em><sup>[4]</sup><em> </em>and consistent comments from Australian regulators, that while it is not possible to eliminate all risk of cyber attach or data breach, organisations must have appropriate processes, controls, documentation and training in place.</p>
<p>This includes having a robust, tailored and actionable data breach response plan. But having a plan, as we know, is not enough: it is critical to ensure that once the plan is set, the organisation must communicate, test and train on the plan. Ideally, this would include tabletop exercises on the plan with key stakeholders. Training and awareness-building should also occur on a regular and on-going basis as part of your organisation’s cyber security strategy and privacy management framework.</p>
<p>Cyber-attacks and data breaches are inevitable. But the organisations that survive and come out the other side are those that are prepared. Having a data breach response plan is a critical tool to being able to comply with reporting obligations and to respond in a way that effectively reduces the impact of the data breach for affected individuals and mitigate the damage to the organisation’s reputation. This really is a case of preparation preventing poor performance.</p>
<p><strong><em>By </em><em>Sophie Bradshaw</em><em>, </em><em>Sarah Gilkes</em><em>, </em><em>Alex Ninis</em><em> and </em><em>Simon Carrodus, all partners</em><em>.</em></strong></p>
<p>&#8212;&#8212;&#8212;-</p>
<h6><strong>Notes:</strong><br />
[1] <a href="https://www.optus.com.au/about/media-centre/media-releases/2022/09/optus-notifies-customers-of-cyberattack?gclid=EAIaIQobChMIj_i4gve2-gIVCplmAh3esw-mEAAYASAAEgIgiPD_BwE&amp;gclsrc=aw.ds">https://www.optus.com.au/about/media-centre/media-releases/2022/09/optus-notifies-customers-of-cyberattack?gclid=EAIaIQobChMIj_i4gve2-gIVCplmAh3esw-mEAAYASAAEgIgiPD_BwE&amp;gclsrc=aw.ds</a><br />
[2] <a href="https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-statistics/notifiable-data-breaches-report-july-december-2021">https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-statistics/notifiable-data-breaches-report-july-december-2021</a><br />
[3] <a href="https://www.oaic.gov.au/privacy/guidance-and-advice/data-breach-preparation-and-response">https://www.oaic.gov.au/privacy/guidance-and-advice/data-breach-preparation-and-response</a><br />
[4] <a href="https://www.hamiltonlocke.com.au/asic-puts-afs-licensees-notice-following-landmark-case-fail-adequately-manage-cyber-security-risks">https://www.hamiltonlocke.com.au/asic-puts-afs-licensees-notice-following-landmark-case-fail-adequately-manage-cyber-security-risks</a></h6>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_86254" style="width: 660px" class="wp-caption alignleft"><img decoding="async" aria-describedby="caption-attachment-86254" class="size-full wp-image-86254" src="https://www.adviservoice.com.au/wp-content/uploads/2022/11/Bradshaw-Sophie-650.png" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2022/11/Bradshaw-Sophie-650.png 650w, https://www.adviservoice.com.au/wp-content/uploads/2022/11/Bradshaw-Sophie-650-300x162.png 300w" sizes="(max-width: 650px) 100vw, 650px" /><p id="caption-attachment-86254" class="wp-caption-text">Sophie Bradshaw</p></div>
<h3>Cyber-attacks and other data breaches are, unfortunately, inevitable. But there are key steps every organisation should take to prepare for when the inevitable happens.</h3>
<p>Responding to a significant cyber incident or other major data breach is often a time of crisis for any organisation.  Anyone who has led or been part of the response team knows that these events are stressful for staff and require dedicated time and resources (both internal and external).</p>
<p>Regardless of your organisation’s size or regulatory obligations, with the cyber risk landscape becoming more complex, the Optus data breach <sup>[1]</sup>should be a clear warning sign to all organisations to prepare now, and prepare well, for the inevitable.</p>
<h2>Are you prepared?</h2>
<p>Preparation for a data breach should be seen as part of an organisation’s overall risk management framework.</p>
<p>As to what “prepared” looks like will depend on the organisation: you will need an understanding of your cyber threats and controls, what and where your “crown jewels” are (including but not limited to your data), and your legal obligations with respect to information security and reporting in the event of a data breach or cyber security incident.</p>
<p>Preparation should be considered across all business functions (not just IT), processes, people and levels within the organisation right up to the Board.  This is because data breaches are not just a result of malicious cyber attacks – people (and more often than not, human error) is consistently reported as one of the leading causes of notified data breaches<sup>[2]</sup> in Australia.</p>
<h2>Have a plan</h2>
<p>The cornerstone of your preparedness is having a documented response plan. Whether called a data breach response plan or a security incident response plan, if there is one step your organisation takes now, it should be to make sure you have one.</p>
<p>Having an actionable and tested plan will put your organisation in a position where it can meet its reporting obligations within the required timeframes and mitigate the risk of statutory non-compliance or breach of contract. This may include statutory reporting obligations under the Notifiable Data Breaches (NDB) scheme contained in the <em>Privacy Act 1988</em> (Cth) and, if applicable to your organisation, cyber security incident reporting obligations under the <em>Security of Critical Infrastructure Act 2018</em> (Cth). Your organisation may also have various other statutory reporting obligations to regulators, in Australia and overseas, as well as contractual obligations to report to government and other third parties, such as funding bodies.</p>
<p>In addition to helping the organisation meet its reporting obligations and manage the legal and reputational risks associated with a major data breach, having an actionable and tested plan is key to providing clear direction, mobilising stakeholders and maintaining a sense of order in a time of crisis.</p>
<h2>What to include in your data breach response plan</h2>
<p>For a data breach response plan to be useful, it needs to be easy to understand, tailored to your organisation and it must be actionable. This means the plan should tell the reader:</p>
<ol type="1">
<li>Who do I contact first if I know or suspect a cyber-attack or data breach affecting the organisation? What are the contact details for that person and a nominated alternative contact, including out-of-hours phone numbers?</li>
<li>What are the roles and responsibilities for internal teams responding to the data breach (for example, which person/team is responsible for the initial investigation? When should the privacy team be engaged?)</li>
<li>What are our reporting obligations, including timeframes? Who within the organisation makes the decision as to when and how we engage with law enforcement, our insurers and when and how we notify regulators, affected individuals and others?</li>
<li>When and how do we engage external legal and other advisers (such as for forensic technology and cyber security, communications or public relations services)? What are the contact names, emails and out-of-hours contact details for the external stakeholders? How do we maintain legal professional privilege if we are engaging a third party to provide an investigation report?</li>
<li>How do we deal with any requests for information (whether from staff, customers or the media)? Do we have any templated communications (proactive and reactive) ready that we can update for the incident?</li>
<li>How will we deal with privacy complaints? Can our customer service team/call centre deal with an increased volume in calls, or do we have a process to stand-up additional support?</li>
<li>What is the plan for where remediation requires support for affected individuals?</li>
</ol>
<p>The Office of the Australian Information Commissioner (OAIC) provides a number of useful resources for organisations. The Data Breach Preparation and Response Guide<sup>[3]</sup> contains a comprehensive description of what your data breach response plan should cover and a checklist.  This is a useful starting point and should be tailored for your particular organisation and, at a minimum, answer the above questions.</p>
<h2>Don’t set and forget</h2>
<p>We know from the recent Federal Court decision in <em>RI Advice</em><sup>[4]</sup><em> </em>and consistent comments from Australian regulators, that while it is not possible to eliminate all risk of cyber attach or data breach, organisations must have appropriate processes, controls, documentation and training in place.</p>
<p>This includes having a robust, tailored and actionable data breach response plan. But having a plan, as we know, is not enough: it is critical to ensure that once the plan is set, the organisation must communicate, test and train on the plan. Ideally, this would include tabletop exercises on the plan with key stakeholders. Training and awareness-building should also occur on a regular and on-going basis as part of your organisation’s cyber security strategy and privacy management framework.</p>
<p>Cyber-attacks and data breaches are inevitable. But the organisations that survive and come out the other side are those that are prepared. Having a data breach response plan is a critical tool to being able to comply with reporting obligations and to respond in a way that effectively reduces the impact of the data breach for affected individuals and mitigate the damage to the organisation’s reputation. This really is a case of preparation preventing poor performance.</p>
<p><strong><em>By </em><em>Sophie Bradshaw</em><em>, </em><em>Sarah Gilkes</em><em>, </em><em>Alex Ninis</em><em> and </em><em>Simon Carrodus, all partners</em><em>.</em></strong></p>
<p>&#8212;&#8212;&#8212;-</p>
<h6><strong>Notes:</strong><br />
[1] <a href="https://www.optus.com.au/about/media-centre/media-releases/2022/09/optus-notifies-customers-of-cyberattack?gclid=EAIaIQobChMIj_i4gve2-gIVCplmAh3esw-mEAAYASAAEgIgiPD_BwE&amp;gclsrc=aw.ds">https://www.optus.com.au/about/media-centre/media-releases/2022/09/optus-notifies-customers-of-cyberattack?gclid=EAIaIQobChMIj_i4gve2-gIVCplmAh3esw-mEAAYASAAEgIgiPD_BwE&amp;gclsrc=aw.ds</a><br />
[2] <a href="https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-statistics/notifiable-data-breaches-report-july-december-2021">https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-statistics/notifiable-data-breaches-report-july-december-2021</a><br />
[3] <a href="https://www.oaic.gov.au/privacy/guidance-and-advice/data-breach-preparation-and-response">https://www.oaic.gov.au/privacy/guidance-and-advice/data-breach-preparation-and-response</a><br />
[4] <a href="https://www.hamiltonlocke.com.au/asic-puts-afs-licensees-notice-following-landmark-case-fail-adequately-manage-cyber-security-risks">https://www.hamiltonlocke.com.au/asic-puts-afs-licensees-notice-following-landmark-case-fail-adequately-manage-cyber-security-risks</a></h6>
<p>The post <a href="https://www.adviservoice.com.au/2022/11/ready-or-not-how-to-prepare-your-organisation-for-a-data-breach/">Ready or not: How to prepare your organisation for a data breach</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2022/11/ready-or-not-how-to-prepare-your-organisation-for-a-data-breach/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>“Have you tried turning it off and on again?” – A review of the decision in ASIC V Ri Ad</title>
                <link>https://www.adviservoice.com.au/2022/05/have-you-tried-turning-it-off-and-on-again-a-review-of-the-decision-in-asic-v-ri-ad/</link>
                <comments>https://www.adviservoice.com.au/2022/05/have-you-tried-turning-it-off-and-on-again-a-review-of-the-decision-in-asic-v-ri-ad/#respond</comments>
                <pubDate>Tue, 24 May 2022 22:00:19 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Regulation/Reform]]></category>
		<category><![CDATA[Glenjon Aligiannis]]></category>
		<category><![CDATA[Simon Carrodus]]></category>
                <guid isPermaLink="false">https://www.adviservoice.com.au/?p=82255</guid>
                                    <description><![CDATA[<article class="blog-post grid-x">
<div class="large-12 cell">
<div class="blog-content dynamic-content inner-wrap">
<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="(max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>On 5 May 2021, the Federal Court handed down a landmark decision in Australian Securities and Investments Commission v RI Advice Group Pty Ltd (2022) FCA 496 by declaring that RI Advice Group Pty Ltd (RI Advice) had breached its obligation to:</h3>
<ol>
<li>provide financial services efficiently, honestly, and fairly, and</li>
<li>have in place adequate risk management systems, by failing to have adequate cybersecurity risk management controls in place. This was a landmark decision as it was the first time that an AFS licensee had been found to be in breach of the requirement for AFS licensees to provide financial services efficiently, honestly, and fairly by not having adequate cybersecurity risk management systems.</li>
</ol>
<p>In this article, we explore:</p>
<ol>
<li>What happened?</li>
<li>What did the Court say?</li>
<li>What does this mean for AFS licensees?</li>
<li>How The Fold can help.</li>
</ol>
<h2>What happened?</h2>
<p>RI Advice, as the AFS licensee of more than 100 authorised representative (AR) practices, provided financial services to approximately 60,000 retail clients.</p>
<p>Between June 2014 and May 2020, a number of separate cybersecurity incidents occurred at the AR practices. These cybersecurity incidents involved:</p>
<ol>
<li>the hacking of an AR practice’s Google email account</li>
<li>the hacking of an AR practice’s third party website provider (which hosted the AR practice’s knowledge centre)</li>
<li>a hacker sent an email to a client, from the email address of an employee of the AR practice, requesting money</li>
<li>an AR practice’s reception desk computer being subject to ransomware delivered by email, resulting in certain files being encrypted and made inaccessible</li>
<li>an AR practice’s server being hacked by brute force through a remote access port, resulting in files being held ransom and 220 client files becoming encrypted and unrecoverable</li>
<li>an AR practice being hacked through brute force and being undetected for several months, resulting in thousands of client files becoming compromised and personal information stolen &#8211; this also resulted in phishing emails being sent to clients</li>
<li>the hacking of an AR practice’s email and an email being sent to the AR practice’s bookkeeper requesting that funds be transferred to a Turkish bank, and</li>
<li>the hacking of an employee of an AR practice’s email resulting in 150 phishing emails being sent to the AR practice’s clients requesting that they access a Dropbox folder.</li>
</ol>
<p>While RI Advice had organised some cyber security training sessions for its ARs and had implemented some information security controls s, RI Advice conceded that these steps were inadequate to manage its cyber security risk across its AR practices.</p>
<p>It was also identified that at one particular AR practice up to 90% of the desktops did not have up to date anti-virus software, no scans were scheduled during the week for antivirus software, no offsite backup had been performed and password and security details were found in text files on the server desktop.</p>
<p>In June 2018, RI Advice engaged cyber security consultants and independent experts to investigate specific incidents and to identify and implement measures to address cybersecurity risks. RI Advice also updated its cyber security policies and introduced measures that required its authorised representatives hold cyber insurance. However, RI Advice but admitted that it took too long to implement these measures across its practices.</p>
<p>On 21 August 2020, ASIC commenced proceedings against RI Advice for an alleged failure to:</p>
<ol>
<li>provide financial services efficiently, honestly, and fairly</li>
<li>comply with the conditions of its AFS licence</li>
<li>comply with financial services laws, and</li>
<li>have available adequate resources provide the financial services and carry out supervisory arrangements.</li>
</ol>
<p>ASIC and RI Advice ultimately settled the matter, with RI Advice admitting to the Court on 7 April 2022 that it had contravened its obligations to:</p>
<ol>
<li>provide financial services efficiently, honestly, and fairly, and</li>
<li>have in place adequate risk management systems.</li>
</ol>
<h2><strong><u><br />
</u></strong>What did the Court say?</h2>
<h3>Efficiently, honestly, fairly</h3>
<p>Although RI Advice admitted to contravening section 912A(1)(a) of the Corporations Act, it disagreed with ASIC’s argument regarding what was the appropriate test for determining whether a breach of this section had occurred.</p>
<p>RI Advice argued that the “public expectation” test (as submitted by ASIC) was not the appropriate test for determining whether an AFS licensee had breached the efficiently, honestly, and fairly obligation.</p>
<p>Justice Rofe agreed with RI Advice, stating that:</p>
<blockquote><p>“In a technical area such as cybersecurity risk management, the reasonable standard of performance is to be assessed by reference to the reasonable person qualified in that area, and likely the subject of expert evidence before the Court, not the expectations of the general public”.</p></blockquote>
<p>RI Advice also argued that, while they admitted to contravening the efficiently, honestly, and fairly provision, it did not mean that they had not acted “honestly”.</p>
<p>Justice Rofe agreed with RI Advice stating that a party could contravene the efficiently, honestly, and fairly obligation without having acted dishonestly.</p>
<h3>Adequate risk management systems</h3>
<p>RI Advice also admitted to contravening the requirement under the Corporations Act to have in place adequate risk management systems. Justice Rofe provided some guidance around what constituted “adequate risk management systems”.</p>
<p>On the question of “adequacy”, her Honour clarified that the Court’s assessment of adequate risk management systems (including those of AFS licensee) will be informed by evidence from relevantly qualified experts in the field.</p>
<h3>Outcome</h3>
<p>As a result of RI Advice admitting to contravening sections 912A(1)(a) and (h) of the Corporations Act, the Court ordered that RI Advice must:</p>
<ol>
<li>Engage a cybersecurity expert to identify what further documentation and controls in respect of cybersecurity and cyber resilience are necessary for RI Advice to manage risk across its AR practices, and</li>
<li>Pay $750,000 towards ASIC’s costs.</li>
</ol>
<h2>What does this mean for AFS licensees?</h2>
<p>The RI Advice case clarifies that each AFS licensee must have in place cybersecurity risk management systems across their AR network to protect themselves and their clients from cybersecurity attacks. This includes:</p>
<ol>
<li>up-to-date anti-virus software</li>
<li>regular virus scans across the whole AR network</li>
<li>up-to-date cybersecurity and cyber resilience training for directors, employees and ARs</li>
<li>an AFS licensee cybersecurity policy which ARs are required to implement and comply with as a part of their AR agreement. The cybersecurity policy should address:
<ol>
<li>Data protection</li>
<li>Password protection and storage, and</li>
<li>Process for dealing with spam and suspected phishing emails.</li>
</ol>
</li>
</ol>
<p>This case also makes it abundantly clear that the cyber resilience of an AFS licensee’s AR network is the responsibility of the AFS licensee and not the individual AR practice. Determining whether a breach of your AFS licensee obligations requires technical knowledge and expertise in cybersecurity.</p>
<h2>How The Fold can help</h2>
<p>If you are concerned that your cybersecurity risk management systems and policies may not be adequate, we are here to help.</p>
<p>Through our relationship with some of the best cybersecurity firms in Australia, The Fold Legal can conduct a coordinated cybersecurity health check. We will:</p>
<p>1. Update or create your cybersecurity and cyber resilience policies;<br />
2. Conduct cybersecurity penetration tests of your risk management systems;<br />
3. Provide advice on any identified cybersecurity breaches and how they impact your AFS licensee obligations; and<br />
4. Conduct a full cybersecurity review to ensure that you are running a “best-in-practice” AFS licensee business.<br />
<strong><em>By Simon Carrodus and Glenjon Aligiannis.</em></strong></p>
</div>
</div>
</article>
]]></description>
                                            <content:encoded><![CDATA[<article class="blog-post grid-x">
<div class="large-12 cell">
<div class="blog-content dynamic-content inner-wrap">
<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>On 5 May 2021, the Federal Court handed down a landmark decision in Australian Securities and Investments Commission v RI Advice Group Pty Ltd (2022) FCA 496 by declaring that RI Advice Group Pty Ltd (RI Advice) had breached its obligation to:</h3>
<ol>
<li>provide financial services efficiently, honestly, and fairly, and</li>
<li>have in place adequate risk management systems, by failing to have adequate cybersecurity risk management controls in place. This was a landmark decision as it was the first time that an AFS licensee had been found to be in breach of the requirement for AFS licensees to provide financial services efficiently, honestly, and fairly by not having adequate cybersecurity risk management systems.</li>
</ol>
<p>In this article, we explore:</p>
<ol>
<li>What happened?</li>
<li>What did the Court say?</li>
<li>What does this mean for AFS licensees?</li>
<li>How The Fold can help.</li>
</ol>
<h2>What happened?</h2>
<p>RI Advice, as the AFS licensee of more than 100 authorised representative (AR) practices, provided financial services to approximately 60,000 retail clients.</p>
<p>Between June 2014 and May 2020, a number of separate cybersecurity incidents occurred at the AR practices. These cybersecurity incidents involved:</p>
<ol>
<li>the hacking of an AR practice’s Google email account</li>
<li>the hacking of an AR practice’s third party website provider (which hosted the AR practice’s knowledge centre)</li>
<li>a hacker sent an email to a client, from the email address of an employee of the AR practice, requesting money</li>
<li>an AR practice’s reception desk computer being subject to ransomware delivered by email, resulting in certain files being encrypted and made inaccessible</li>
<li>an AR practice’s server being hacked by brute force through a remote access port, resulting in files being held ransom and 220 client files becoming encrypted and unrecoverable</li>
<li>an AR practice being hacked through brute force and being undetected for several months, resulting in thousands of client files becoming compromised and personal information stolen &#8211; this also resulted in phishing emails being sent to clients</li>
<li>the hacking of an AR practice’s email and an email being sent to the AR practice’s bookkeeper requesting that funds be transferred to a Turkish bank, and</li>
<li>the hacking of an employee of an AR practice’s email resulting in 150 phishing emails being sent to the AR practice’s clients requesting that they access a Dropbox folder.</li>
</ol>
<p>While RI Advice had organised some cyber security training sessions for its ARs and had implemented some information security controls s, RI Advice conceded that these steps were inadequate to manage its cyber security risk across its AR practices.</p>
<p>It was also identified that at one particular AR practice up to 90% of the desktops did not have up to date anti-virus software, no scans were scheduled during the week for antivirus software, no offsite backup had been performed and password and security details were found in text files on the server desktop.</p>
<p>In June 2018, RI Advice engaged cyber security consultants and independent experts to investigate specific incidents and to identify and implement measures to address cybersecurity risks. RI Advice also updated its cyber security policies and introduced measures that required its authorised representatives hold cyber insurance. However, RI Advice but admitted that it took too long to implement these measures across its practices.</p>
<p>On 21 August 2020, ASIC commenced proceedings against RI Advice for an alleged failure to:</p>
<ol>
<li>provide financial services efficiently, honestly, and fairly</li>
<li>comply with the conditions of its AFS licence</li>
<li>comply with financial services laws, and</li>
<li>have available adequate resources provide the financial services and carry out supervisory arrangements.</li>
</ol>
<p>ASIC and RI Advice ultimately settled the matter, with RI Advice admitting to the Court on 7 April 2022 that it had contravened its obligations to:</p>
<ol>
<li>provide financial services efficiently, honestly, and fairly, and</li>
<li>have in place adequate risk management systems.</li>
</ol>
<h2><strong><u><br />
</u></strong>What did the Court say?</h2>
<h3>Efficiently, honestly, fairly</h3>
<p>Although RI Advice admitted to contravening section 912A(1)(a) of the Corporations Act, it disagreed with ASIC’s argument regarding what was the appropriate test for determining whether a breach of this section had occurred.</p>
<p>RI Advice argued that the “public expectation” test (as submitted by ASIC) was not the appropriate test for determining whether an AFS licensee had breached the efficiently, honestly, and fairly obligation.</p>
<p>Justice Rofe agreed with RI Advice, stating that:</p>
<blockquote><p>“In a technical area such as cybersecurity risk management, the reasonable standard of performance is to be assessed by reference to the reasonable person qualified in that area, and likely the subject of expert evidence before the Court, not the expectations of the general public”.</p></blockquote>
<p>RI Advice also argued that, while they admitted to contravening the efficiently, honestly, and fairly provision, it did not mean that they had not acted “honestly”.</p>
<p>Justice Rofe agreed with RI Advice stating that a party could contravene the efficiently, honestly, and fairly obligation without having acted dishonestly.</p>
<h3>Adequate risk management systems</h3>
<p>RI Advice also admitted to contravening the requirement under the Corporations Act to have in place adequate risk management systems. Justice Rofe provided some guidance around what constituted “adequate risk management systems”.</p>
<p>On the question of “adequacy”, her Honour clarified that the Court’s assessment of adequate risk management systems (including those of AFS licensee) will be informed by evidence from relevantly qualified experts in the field.</p>
<h3>Outcome</h3>
<p>As a result of RI Advice admitting to contravening sections 912A(1)(a) and (h) of the Corporations Act, the Court ordered that RI Advice must:</p>
<ol>
<li>Engage a cybersecurity expert to identify what further documentation and controls in respect of cybersecurity and cyber resilience are necessary for RI Advice to manage risk across its AR practices, and</li>
<li>Pay $750,000 towards ASIC’s costs.</li>
</ol>
<h2>What does this mean for AFS licensees?</h2>
<p>The RI Advice case clarifies that each AFS licensee must have in place cybersecurity risk management systems across their AR network to protect themselves and their clients from cybersecurity attacks. This includes:</p>
<ol>
<li>up-to-date anti-virus software</li>
<li>regular virus scans across the whole AR network</li>
<li>up-to-date cybersecurity and cyber resilience training for directors, employees and ARs</li>
<li>an AFS licensee cybersecurity policy which ARs are required to implement and comply with as a part of their AR agreement. The cybersecurity policy should address:
<ol>
<li>Data protection</li>
<li>Password protection and storage, and</li>
<li>Process for dealing with spam and suspected phishing emails.</li>
</ol>
</li>
</ol>
<p>This case also makes it abundantly clear that the cyber resilience of an AFS licensee’s AR network is the responsibility of the AFS licensee and not the individual AR practice. Determining whether a breach of your AFS licensee obligations requires technical knowledge and expertise in cybersecurity.</p>
<h2>How The Fold can help</h2>
<p>If you are concerned that your cybersecurity risk management systems and policies may not be adequate, we are here to help.</p>
<p>Through our relationship with some of the best cybersecurity firms in Australia, The Fold Legal can conduct a coordinated cybersecurity health check. We will:</p>
<p>1. Update or create your cybersecurity and cyber resilience policies;<br />
2. Conduct cybersecurity penetration tests of your risk management systems;<br />
3. Provide advice on any identified cybersecurity breaches and how they impact your AFS licensee obligations; and<br />
4. Conduct a full cybersecurity review to ensure that you are running a “best-in-practice” AFS licensee business.<br />
<strong><em>By Simon Carrodus and Glenjon Aligiannis.</em></strong></p>
</div>
</div>
</article>
<p>The post <a href="https://www.adviservoice.com.au/2022/05/have-you-tried-turning-it-off-and-on-again-a-review-of-the-decision-in-asic-v-ri-ad/">“Have you tried turning it off and on again?” – A review of the decision in ASIC V Ri Ad</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2022/05/have-you-tried-turning-it-off-and-on-again-a-review-of-the-decision-in-asic-v-ri-ad/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>Who watches The Watchmen? We do – a review of the ASIC Enforcement Update</title>
                <link>https://www.adviservoice.com.au/2022/05/who-watches-the-watchmen-we-do-a-review-of-the-asic-enforcement-update/</link>
                <comments>https://www.adviservoice.com.au/2022/05/who-watches-the-watchmen-we-do-a-review-of-the-asic-enforcement-update/#respond</comments>
                <pubDate>Thu, 05 May 2022 21:35:18 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Regulation/Reform]]></category>
		<category><![CDATA[Glenjon Aligiannis]]></category>
		<category><![CDATA[Simon Carrodus]]></category>
                <guid isPermaLink="false">https://www.adviservoice.com.au/?p=81649</guid>
                                    <description><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>On 28 March 2022 the Australian Securities and Investments Commission (ASIC) released Report 722 ‘ASIC Enforcement Update July to December 2021’ (Report 722).</h3>
<p>In this article, we:</p>
<ol>
<li>review the key data points in Report 722 and compare them against the previous update &#8211; ‘ASIC Enforcement Update January to June 2021’ (Report 699)</li>
<li>provide you with our insights and commentary;</li>
<li>review the relevant data for financial services specifically, and</li>
<li>provide you with our contact details in case you have any questions!</li>
</ol>
<h2>Key data points from Report 722 and Report 699</h2>
<p>The second half of 2021 was another busy year for ASIC’s Enforcement Team. Here at The Fold Legal, we pay attention to ASIC’s biannual Enforcement Updates to monitor themes and trends. And of course we like to share our analysis with you.</p>
<p>Below are the figures for the second half of 2021 identified in Report 722 compared against the first half of 2021 as outlined in Report 699:</p>
<p><img loading="lazy" decoding="async" class="alignleft size-full wp-image-81650" src="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1.png" alt="" width="1687" height="1429" srcset="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1.png 1687w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1-300x254.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1-1024x867.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1-768x651.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1-1536x1301.png 1536w" sizes="auto, (max-width: 1687px) 100vw, 1687px" /></p>
<p>*Only two (2) people were imprisoned, although ASIC obtained six (6) custodial sentences. For consistency, we have only included the number of people imprisoned, in keeping with Report 699.</p>
<h2>What does this tell us?</h2>
<p>From the table above, we can see that in the second half of 2021, ASIC increased its activity within the market in the following areas:</p>
<ol>
<li>individual charges in criminal proceedings</li>
<li>criminal charges laid, and</li>
<li>civil penalty cases commenced.</li>
</ol>
<p>ASIC also appears to have experienced an increasingly successful end to 2021, by securing an increase in:</p>
<ol>
<li>non-custodial sentences;</li>
<li>the value of the civil penalties imposed by the courts (an increase of over 180%); and</li>
<li>individuals disqualified or removed from directing companies.</li>
</ol>
<p>Given this data, we expect the next Enforcement Update to indicate a proportionate increase in these areas for the first half of 2022. This is because ASIC has:</p>
<ol>
<li>commenced 21 civil penalty proceedings, an increase of 9 since the first half of 2021, and</li>
<li>seen the number of civil penalty proceedings before the courts increase by 12.</li>
</ol>
<p>We also can expect that ASIC will continue to conduct its investigations at a similar pace – around 50 investigations per half-year.</p>
<h2>What does this mean for the financial services industry?</h2>
<p>Report 722 showed a small, but important, decline in enforcement activity across the financial services industry more broadly.</p>
<p><img loading="lazy" decoding="async" class="alignleft size-full wp-image-81652" src="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2.png" alt="" width="1674" height="741" srcset="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2.png 1674w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2-300x133.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2-1024x453.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2-768x340.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2-1536x680.png 1536w" sizes="auto, (max-width: 1674px) 100vw, 1674px" /></p>
<p>When comparing the reported figures in Report 722 to those in Report 699, we see the trends outlined in the table further below.</p>
<p><strong>NOTE:</strong></p>
<ol>
<li>The figures represented are the differences between the two Reports. For example, the first reported number of -3 for ‘Credit’ means that there were 3 fewer criminal credit case outcomes in Report 722 vs Report 699, and</li>
<li>Insurance was not addressed in Report 699:</li>
</ol>
<p><img loading="lazy" decoding="async" class="alignleft size-full wp-image-81651" src="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3.png" alt="" width="1685" height="739" srcset="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3.png 1685w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3-300x132.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3-1024x449.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3-768x337.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3-1536x674.png 1536w" sizes="auto, (max-width: 1685px) 100vw, 1685px" /></p>
<p>From this we can see that:</p>
<ol>
<li>‘Financial advice’, ‘Investment management’ and ‘Other financial services’ saw moderate to significant increased enforcement activity during the latter half of 2021, and</li>
<li>‘Credit’ and ‘Superannuation’ saw significant declines in enforcement activity during the same period.</li>
</ol>
<p>These trends accord with what we are seeing in the market at the moment. Financial advice continues to be a strong area of interest to ASIC with an uptick in the number of administrative proceedings brought by the regulator.</p>
<h2>What next?</h2>
<p>We anticipate that the next Enforcement Update from ASIC will show that it has been an equally busy, if not busier, period than the second half of 2021. This is due to:</p>
<ol>
<li>the increased number of civil penalty proceedings commenced</li>
<li>the increased number of civil penalty proceedings before the courts currently, and</li>
<li>the consistently high number of investigations commenced during the latter half of 2021.</li>
</ol>
<p>This is in line with what we are seeing, and we encourage our clients to seek professional advice as early as possible when they receive a communication from ASIC.</p>
<p>If you’ve had contact from ASIC and are unsure of what to do, please contact us. We deal with ASIC every day and will be happy to navigate your through the process.</p>
<p><em><strong>By Simon Carrodus and Glenjon Aligiannis</strong></em></p>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>On 28 March 2022 the Australian Securities and Investments Commission (ASIC) released Report 722 ‘ASIC Enforcement Update July to December 2021’ (Report 722).</h3>
<p>In this article, we:</p>
<ol>
<li>review the key data points in Report 722 and compare them against the previous update &#8211; ‘ASIC Enforcement Update January to June 2021’ (Report 699)</li>
<li>provide you with our insights and commentary;</li>
<li>review the relevant data for financial services specifically, and</li>
<li>provide you with our contact details in case you have any questions!</li>
</ol>
<h2>Key data points from Report 722 and Report 699</h2>
<p>The second half of 2021 was another busy year for ASIC’s Enforcement Team. Here at The Fold Legal, we pay attention to ASIC’s biannual Enforcement Updates to monitor themes and trends. And of course we like to share our analysis with you.</p>
<p>Below are the figures for the second half of 2021 identified in Report 722 compared against the first half of 2021 as outlined in Report 699:</p>
<p><img loading="lazy" decoding="async" class="alignleft size-full wp-image-81650" src="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1.png" alt="" width="1687" height="1429" srcset="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1.png 1687w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1-300x254.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1-1024x867.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1-768x651.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-1-1536x1301.png 1536w" sizes="auto, (max-width: 1687px) 100vw, 1687px" /></p>
<p>*Only two (2) people were imprisoned, although ASIC obtained six (6) custodial sentences. For consistency, we have only included the number of people imprisoned, in keeping with Report 699.</p>
<h2>What does this tell us?</h2>
<p>From the table above, we can see that in the second half of 2021, ASIC increased its activity within the market in the following areas:</p>
<ol>
<li>individual charges in criminal proceedings</li>
<li>criminal charges laid, and</li>
<li>civil penalty cases commenced.</li>
</ol>
<p>ASIC also appears to have experienced an increasingly successful end to 2021, by securing an increase in:</p>
<ol>
<li>non-custodial sentences;</li>
<li>the value of the civil penalties imposed by the courts (an increase of over 180%); and</li>
<li>individuals disqualified or removed from directing companies.</li>
</ol>
<p>Given this data, we expect the next Enforcement Update to indicate a proportionate increase in these areas for the first half of 2022. This is because ASIC has:</p>
<ol>
<li>commenced 21 civil penalty proceedings, an increase of 9 since the first half of 2021, and</li>
<li>seen the number of civil penalty proceedings before the courts increase by 12.</li>
</ol>
<p>We also can expect that ASIC will continue to conduct its investigations at a similar pace – around 50 investigations per half-year.</p>
<h2>What does this mean for the financial services industry?</h2>
<p>Report 722 showed a small, but important, decline in enforcement activity across the financial services industry more broadly.</p>
<p><img loading="lazy" decoding="async" class="alignleft size-full wp-image-81652" src="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2.png" alt="" width="1674" height="741" srcset="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2.png 1674w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2-300x133.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2-1024x453.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2-768x340.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-2-1536x680.png 1536w" sizes="auto, (max-width: 1674px) 100vw, 1674px" /></p>
<p>When comparing the reported figures in Report 722 to those in Report 699, we see the trends outlined in the table further below.</p>
<p><strong>NOTE:</strong></p>
<ol>
<li>The figures represented are the differences between the two Reports. For example, the first reported number of -3 for ‘Credit’ means that there were 3 fewer criminal credit case outcomes in Report 722 vs Report 699, and</li>
<li>Insurance was not addressed in Report 699:</li>
</ol>
<p><img loading="lazy" decoding="async" class="alignleft size-full wp-image-81651" src="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3.png" alt="" width="1685" height="739" srcset="https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3.png 1685w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3-300x132.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3-1024x449.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3-768x337.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2022/05/ASIC-Enforce-3-1536x674.png 1536w" sizes="auto, (max-width: 1685px) 100vw, 1685px" /></p>
<p>From this we can see that:</p>
<ol>
<li>‘Financial advice’, ‘Investment management’ and ‘Other financial services’ saw moderate to significant increased enforcement activity during the latter half of 2021, and</li>
<li>‘Credit’ and ‘Superannuation’ saw significant declines in enforcement activity during the same period.</li>
</ol>
<p>These trends accord with what we are seeing in the market at the moment. Financial advice continues to be a strong area of interest to ASIC with an uptick in the number of administrative proceedings brought by the regulator.</p>
<h2>What next?</h2>
<p>We anticipate that the next Enforcement Update from ASIC will show that it has been an equally busy, if not busier, period than the second half of 2021. This is due to:</p>
<ol>
<li>the increased number of civil penalty proceedings commenced</li>
<li>the increased number of civil penalty proceedings before the courts currently, and</li>
<li>the consistently high number of investigations commenced during the latter half of 2021.</li>
</ol>
<p>This is in line with what we are seeing, and we encourage our clients to seek professional advice as early as possible when they receive a communication from ASIC.</p>
<p>If you’ve had contact from ASIC and are unsure of what to do, please contact us. We deal with ASIC every day and will be happy to navigate your through the process.</p>
<p><em><strong>By Simon Carrodus and Glenjon Aligiannis</strong></em></p>
<p>The post <a href="https://www.adviservoice.com.au/2022/05/who-watches-the-watchmen-we-do-a-review-of-the-asic-enforcement-update/">Who watches The Watchmen? We do – a review of the ASIC Enforcement Update</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2022/05/who-watches-the-watchmen-we-do-a-review-of-the-asic-enforcement-update/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>Financial Services and Credit Panel – with great power comes great responsibility</title>
                <link>https://www.adviservoice.com.au/2022/03/financial-services-and-credit-panel-with-great-power-comes-great-responsibility/</link>
                <comments>https://www.adviservoice.com.au/2022/03/financial-services-and-credit-panel-with-great-power-comes-great-responsibility/#respond</comments>
                <pubDate>Tue, 22 Mar 2022 20:55:01 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Regulation/Reform]]></category>
		<category><![CDATA[Jessica Smith]]></category>
		<category><![CDATA[Simon Carrodus]]></category>
                <guid isPermaLink="false">https://www.adviservoice.com.au/?p=80753</guid>
                                    <description><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>ASIC has released a consultation paper<sup>[1]</sup> on what matters should be heard by the Financial Services and Credit Panel and how it will assess an adviser as a fit and proper person.</h3>
<h2>A new Sheriff in town&#8230;</h2>
<p>Last year, the government passed legislation to give the Financial Services and Credit Panel (FSCP) its own legislative functions and powers to address a range of misconduct by financial advisers.</p>
<p>The powers of the FSCP include the power to direct financial advisers to undertake specified training, counselling or supervision and to report certain matters to ASIC.</p>
<p>The FSCP may also:</p>
<ul>
<li>suspend or cancel a financial adviser’s registration</li>
<li>issue infringement notices</li>
<li>recommend ASIC commence civil penalty proceedings, and</li>
<li>enter into enforceable undertakings with financial advisers.</li>
</ul>
<p>ASIC has now released consultation paper 359 (CP 359)<sup>[2]</sup> setting out changes to the FSCP and associated Regulatory Guide 263.</p>
<p>ASIC is seeking feedback on its proposed approach in deciding when to convene the FSCP including:</p>
<ul>
<li>determining whether loss or damage to a client or benefit to an adviser is material, and</li>
<li>assessing a financial adviser’s fitness and propriety.</li>
</ul>
<h2>To convene or not to convene…</h2>
<p>Ordinarily, if ASIC <em>has not</em> already exercised its banning and disciplinary powers, it has broad discretion to convene the FSCP to consider misconduct by financial advisers.</p>
<p>ASIC must convene the FSCP in the following circumstances:</p>
<ul>
<li>when an adviser is convicted of fraud</li>
<li>if ASIC believes they are not a fit and proper person</li>
<li>they have contravened the education and training requirements of the Corporations Act, or</li>
<li>have contravened a financial services law and that contravention is serious.</li>
</ul>
<p>A contravention is ‘serious’ if it:</p>
<ul>
<li>has resulted, or is likely to result, in material loss or damage to a client of the financial adviser</li>
<li>has resulted, or is likely to result, in a material benefit to the financial adviser, or</li>
<li>involves dishonesty.</li>
</ul>
<p>CP 359, however, proposes the FSCP also be able to meet to address issues that would provide a regulatory benefit to investors and consumers without any convening circumstances being present.</p>
<p>“We consider that targeting misconduct that is widespread or part of a growing trend and matters that, if considered by a sitting panel, will send an effective and deterrent message to industry, is likely to result in regulatory benefit.”</p>
<p>In theory, this sounds great. Financial adviser misconduct will be assessed and sanctioned by peers, which the Federal Government believes will drive further improvements within the industry. The thing is, out of the 31 members of the FSCP who were appointed last week, only about 25% of these members are qualified financial advisers.</p>
<p>With only 2 panel members required for each case, theoretically, there should be enough financial advice specialists on the panel so that advice hearings will be attended by at least one qualified financial adviser. However, there is no guarantee that this will be possible.</p>
<p>It’s unknown as to what percentages of cases are expected to cover financial advice and whether the number of financial advisers on the panel is sufficient. Importantly, the availability of panel members will be impacted by numerous factors both personal and professional, including the requirement to sit out hearings where a conflict of interest exists.</p>
<h2>More than a synonym &#8211; When is a financial adviser fit and proper?</h2>
<p>ASIC must convene a sitting panel where they reasonably believe that a financial adviser is not a fit and proper person to provide personal advice to retail clients in relation to relevant financial products.</p>
<p>In terms of assessing a financial adviser’s fitness and propriety, ASIC intends to consider whether the financial adviser:</p>
<ul>
<li>is competent to provide personal advice to retail clients on the relevant financial products they are authorised to provide personal advice on (based on their knowledge, skills and experience), and</li>
<li>has the attributes of good character, diligence, honesty, integrity and judgement.</li>
</ul>
<p>This assessment of fitness and proprietary represents a departure from the prescriptive tests applied to both credit and AFS licensees and relies on rather vague and subjective notions of favourable personality attributes. In the absence of defined criteria or additional guidance, and in light of ASIC’s existing resourcing problems, one might question whether the drafting is deliberately broad to allow ASIC to palm off ‘pesky little adviser issues’ to the FSCP more often.</p>
<h2>IS ASIC still judge, jury and executioner?</h2>
<p>In most circumstances, yes. When it wants to be, that is.</p>
<p>ASIC’s proposed changes to Regulatory Guide 263 effectively widen the circumstances in which ASIC must convene a sitting panel. Whilst ASIC can still exercise their own banning powers, these powers may be delegated to the sitting panel where ASIC considers the matter is appropriate because of its significance, complexity or novelty.</p>
<p>What do you think? Whilst a financial adviser is unable to forum shop between ASIC and the FSCP, would you prefer to be heard by a panel of your ‘peers’?</p>
<p>Submissions to ASIC are open until 28 March 2022.</p>
<p><em><strong>By Jessica Smith and Simon Carrodus </strong></em></p>
<p>&#8212;&#8212;&#8211;</p>
<h6>[1] <a href="https://download.asic.gov.au/media/v45jwlhf/cp359-published-28-february-2022.pdf">https://download.asic.gov.au/media/v45jwlhf/cp359-published-28-february-2022.pdf</a><br />
[2] Ibid.</h6>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>ASIC has released a consultation paper<sup>[1]</sup> on what matters should be heard by the Financial Services and Credit Panel and how it will assess an adviser as a fit and proper person.</h3>
<h2>A new Sheriff in town&#8230;</h2>
<p>Last year, the government passed legislation to give the Financial Services and Credit Panel (FSCP) its own legislative functions and powers to address a range of misconduct by financial advisers.</p>
<p>The powers of the FSCP include the power to direct financial advisers to undertake specified training, counselling or supervision and to report certain matters to ASIC.</p>
<p>The FSCP may also:</p>
<ul>
<li>suspend or cancel a financial adviser’s registration</li>
<li>issue infringement notices</li>
<li>recommend ASIC commence civil penalty proceedings, and</li>
<li>enter into enforceable undertakings with financial advisers.</li>
</ul>
<p>ASIC has now released consultation paper 359 (CP 359)<sup>[2]</sup> setting out changes to the FSCP and associated Regulatory Guide 263.</p>
<p>ASIC is seeking feedback on its proposed approach in deciding when to convene the FSCP including:</p>
<ul>
<li>determining whether loss or damage to a client or benefit to an adviser is material, and</li>
<li>assessing a financial adviser’s fitness and propriety.</li>
</ul>
<h2>To convene or not to convene…</h2>
<p>Ordinarily, if ASIC <em>has not</em> already exercised its banning and disciplinary powers, it has broad discretion to convene the FSCP to consider misconduct by financial advisers.</p>
<p>ASIC must convene the FSCP in the following circumstances:</p>
<ul>
<li>when an adviser is convicted of fraud</li>
<li>if ASIC believes they are not a fit and proper person</li>
<li>they have contravened the education and training requirements of the Corporations Act, or</li>
<li>have contravened a financial services law and that contravention is serious.</li>
</ul>
<p>A contravention is ‘serious’ if it:</p>
<ul>
<li>has resulted, or is likely to result, in material loss or damage to a client of the financial adviser</li>
<li>has resulted, or is likely to result, in a material benefit to the financial adviser, or</li>
<li>involves dishonesty.</li>
</ul>
<p>CP 359, however, proposes the FSCP also be able to meet to address issues that would provide a regulatory benefit to investors and consumers without any convening circumstances being present.</p>
<p>“We consider that targeting misconduct that is widespread or part of a growing trend and matters that, if considered by a sitting panel, will send an effective and deterrent message to industry, is likely to result in regulatory benefit.”</p>
<p>In theory, this sounds great. Financial adviser misconduct will be assessed and sanctioned by peers, which the Federal Government believes will drive further improvements within the industry. The thing is, out of the 31 members of the FSCP who were appointed last week, only about 25% of these members are qualified financial advisers.</p>
<p>With only 2 panel members required for each case, theoretically, there should be enough financial advice specialists on the panel so that advice hearings will be attended by at least one qualified financial adviser. However, there is no guarantee that this will be possible.</p>
<p>It’s unknown as to what percentages of cases are expected to cover financial advice and whether the number of financial advisers on the panel is sufficient. Importantly, the availability of panel members will be impacted by numerous factors both personal and professional, including the requirement to sit out hearings where a conflict of interest exists.</p>
<h2>More than a synonym &#8211; When is a financial adviser fit and proper?</h2>
<p>ASIC must convene a sitting panel where they reasonably believe that a financial adviser is not a fit and proper person to provide personal advice to retail clients in relation to relevant financial products.</p>
<p>In terms of assessing a financial adviser’s fitness and propriety, ASIC intends to consider whether the financial adviser:</p>
<ul>
<li>is competent to provide personal advice to retail clients on the relevant financial products they are authorised to provide personal advice on (based on their knowledge, skills and experience), and</li>
<li>has the attributes of good character, diligence, honesty, integrity and judgement.</li>
</ul>
<p>This assessment of fitness and proprietary represents a departure from the prescriptive tests applied to both credit and AFS licensees and relies on rather vague and subjective notions of favourable personality attributes. In the absence of defined criteria or additional guidance, and in light of ASIC’s existing resourcing problems, one might question whether the drafting is deliberately broad to allow ASIC to palm off ‘pesky little adviser issues’ to the FSCP more often.</p>
<h2>IS ASIC still judge, jury and executioner?</h2>
<p>In most circumstances, yes. When it wants to be, that is.</p>
<p>ASIC’s proposed changes to Regulatory Guide 263 effectively widen the circumstances in which ASIC must convene a sitting panel. Whilst ASIC can still exercise their own banning powers, these powers may be delegated to the sitting panel where ASIC considers the matter is appropriate because of its significance, complexity or novelty.</p>
<p>What do you think? Whilst a financial adviser is unable to forum shop between ASIC and the FSCP, would you prefer to be heard by a panel of your ‘peers’?</p>
<p>Submissions to ASIC are open until 28 March 2022.</p>
<p><em><strong>By Jessica Smith and Simon Carrodus </strong></em></p>
<p>&#8212;&#8212;&#8211;</p>
<h6>[1] <a href="https://download.asic.gov.au/media/v45jwlhf/cp359-published-28-february-2022.pdf">https://download.asic.gov.au/media/v45jwlhf/cp359-published-28-february-2022.pdf</a><br />
[2] Ibid.</h6>
<p>The post <a href="https://www.adviservoice.com.au/2022/03/financial-services-and-credit-panel-with-great-power-comes-great-responsibility/">Financial Services and Credit Panel – with great power comes great responsibility</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2022/03/financial-services-and-credit-panel-with-great-power-comes-great-responsibility/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>Who Would Be An AFSL? &#8211; The Court’s Review Of Section 961L</title>
                <link>https://www.adviservoice.com.au/2022/03/who-would-be-an-afsl-the-courts-review-of-section-961l/</link>
                <comments>https://www.adviservoice.com.au/2022/03/who-would-be-an-afsl-the-courts-review-of-section-961l/#respond</comments>
                <pubDate>Thu, 17 Mar 2022 20:45:38 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Regulation/Reform]]></category>
		<category><![CDATA[Glenjon Aligiannis]]></category>
		<category><![CDATA[Simon Carrodus]]></category>
                <guid isPermaLink="false">https://www.adviservoice.com.au/?p=80623</guid>
                                    <description><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>On 2 August 2021, the Federal Court handed down its decision in the matter of <em>Australian Securities and Investments Commission v RI Advice Group Pty Ltd (No 2)</em> (2021) FCA 877.</h3>
<h2>Background</h2>
<p>The Australian Securities and Investments Commission (ASIC) commenced proceedings against RI Advice Group Pty Ltd (<strong>RI Advice</strong>) for an alleged failure to comply with section 961L of the <em>Corporations Act 2001</em> (Cth) (<strong>Corporations Act</strong>) by failing to take ‘reasonable steps’ to ensure that its authorised representative (Mr John Doyle) complied with his obligation to:</p>
<ol>
<li>Act in the best interests of the client (section 961B of the Corporations Act)</li>
<li>Provide personal advice that is appropriate for the client (section 961G)</li>
<li>Warn the client where personal advice is based on incomplete or inaccurate information (section 961H), and</li>
<li>Prioritise the client’s interests where there is a conflict of interest between the interests of the adviser and the client (section 961J).</li>
</ol>
<p>Mr Doyle admitted to each of the alleged contraventions of the Corporations Act.</p>
<h2>ASIC’s case against RI Advice</h2>
<p>In summary, ASIC’s case against RI Advice was that:</p>
<ol>
<li>RI Advice knew or ought to have known that Mr Doyle was not meeting RI Advice’s standards and was not complying with its business rules, and that there was a substantial risk that he was breaching his legal obligations</li>
<li>Despite repeated warning signs, RI Advice failed to take any significant steps to investigate Mr Doyle until mid-2015, after ANZ, which owned RI Advice at the time, reviewed a selection of Mr Doyle’s advice files and gave them the worst possible rating on its advice scorecard;</li>
<li>As a result, ANZ undertook further file reviews, which identified similar issues with Mr Doyle’s other client</li>
<li>By failing to take reasonable steps, RI Advice effectively ensured that Mr Doyle’s clients and their investments would stay with RI Advice as Mr Doyle’s clients would not be made aware of the inappropriate advice they had received, and</li>
<li>RI Advice permitted Mr Doyle to keep advising clients where there was a substantial risk that he would breach the best interest obligation.</li>
</ol>
<h2>Lessons for AFS licensees</h2>
<p><em>&#8220;Although the duty in s 961L is broad, the case law has begun to fill in the contours of what is expected of a licensee by way of compliance with the provision.&#8221;</em></p>
<p>In making its decision, the Federal Court supported the proposition that whilst AFS licensees are legally obliged under section 961L to take <em>reasonable</em> steps to ensure that their representatives (including authorised representatives) comply with sections 961B, 961G, 961H and 961J (<strong>Relevant Sections</strong>), they are not required to take <em>optimal</em> steps in ensuring compliance with those sections.</p>
<p>This is a particularly interesting statement from the Federal Court as it creates a scale that the Federal court will use when assessing the steps taken by an AFS licensee to comply with the Relevant Sections. This scale is divided into four parts:</p>
<ol>
<li>Steps at the higher end, considered &#8220;optimal&#8221; (read as best practice)</li>
<li>Steps which, although not optimal, are reasonable</li>
<li>Steps which are not reasonable in ensuring that representatives comply with the Relevant Sections, and</li>
<li>Steps which were not taken by the AFS licensee but, had they been taken, would have been reasonable in ensuring that representatives complied with the Relevant Sections.</li>
</ol>
<p>Distinguishing between the first two categories is unnecessary as any steps taken by an AFS licensee that are considered to be optimal will mean that it is automatically categorised as reasonable.</p>
<p>With this in mind, The Fold Legal considers it to be of significant importance for AFS licensees to be able to:</p>
<ol>
<li>Distinguish between steps that are reasonable, and those that are not reasonable, in ensuring that representatives comply with the Relevant Sections</li>
<li>On an ongoing basis, consider whether a step that was once reasonable may no longer be reasonable as the business evolves (particularly as the business grows or down-sizes), and</li>
<li>Consider which steps they are not taking, which, had they been taken, may be reasonable in ensuring that their representatives comply with the Relevant Sections.</li>
</ol>
<p>The Federal Court also outlined that the steps an AFS licensee must take to ensure its representatives are complying with the Relevant Sections are dependent on the specific obligation that the AFS licensee is attempting to comply with. This means that what is reasonable in ensuring that a representative complies with the best interest duty may not be reasonable in ensuring that a representative prioritises the client’s interests over their own.</p>
<p>Unfortunately, there are an enormous number of compliance measures, actions and steps that an AFS licensee must consider and take in attempting to ensure that its representatives comply with the Relevant Sections. Each of these steps falls into one of the four categories outlined above.</p>
<p>Unlike the safe harbour steps outlined in section 961B(2) of the Corporations Act, there is no clear pathway for compliance for section 961L, which makes it still particularly tricky for AFS licensees to navigate safely.</p>
<h2>Penalties</h2>
<p>The penalties for failing to comply with section 961L can be significant. Recently, on 6 February 2022, the Federal Court penalised RI Advice $6 million for their repeated failure to comply with section 961L, even though RI Advice had taken steps to remediate all clients affected by Mr Doyle’s conduct. The Federal Court determined that a substantial penalty was warranted in this case, signifying the importance of understanding the obligation to take reasonable steps pursuant to section 961L.</p>
<p>AFS licensees will need to take into consideration the following when determining whether any step, measure or action is to be implemented or taken:</p>
<ol>
<li>The number of representatives of the AFS licensee</li>
<li>The composition of the AFS licensee’s representatives (either employed advisers or authorised representatives), and</li>
<li>The structure of the AFS licensee (is it a vertically integrated model or not?).</li>
</ol>
<p>Here at The Fold Legal, we try to make the complex simple. We have advised many AFS licensees on the steps, measures and actions they should take (and not take) to ensure compliance with section 961L.</p>
<p>If you are concerned about your obligations as an AFS licensee or would like to review the steps you are taking to comply with section 961L, please get in touch. We are here to help.</p>
<p><em><strong>By  Simon Carrodus and Glenjon Aligiannis</strong></em></p>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>On 2 August 2021, the Federal Court handed down its decision in the matter of <em>Australian Securities and Investments Commission v RI Advice Group Pty Ltd (No 2)</em> (2021) FCA 877.</h3>
<h2>Background</h2>
<p>The Australian Securities and Investments Commission (ASIC) commenced proceedings against RI Advice Group Pty Ltd (<strong>RI Advice</strong>) for an alleged failure to comply with section 961L of the <em>Corporations Act 2001</em> (Cth) (<strong>Corporations Act</strong>) by failing to take ‘reasonable steps’ to ensure that its authorised representative (Mr John Doyle) complied with his obligation to:</p>
<ol>
<li>Act in the best interests of the client (section 961B of the Corporations Act)</li>
<li>Provide personal advice that is appropriate for the client (section 961G)</li>
<li>Warn the client where personal advice is based on incomplete or inaccurate information (section 961H), and</li>
<li>Prioritise the client’s interests where there is a conflict of interest between the interests of the adviser and the client (section 961J).</li>
</ol>
<p>Mr Doyle admitted to each of the alleged contraventions of the Corporations Act.</p>
<h2>ASIC’s case against RI Advice</h2>
<p>In summary, ASIC’s case against RI Advice was that:</p>
<ol>
<li>RI Advice knew or ought to have known that Mr Doyle was not meeting RI Advice’s standards and was not complying with its business rules, and that there was a substantial risk that he was breaching his legal obligations</li>
<li>Despite repeated warning signs, RI Advice failed to take any significant steps to investigate Mr Doyle until mid-2015, after ANZ, which owned RI Advice at the time, reviewed a selection of Mr Doyle’s advice files and gave them the worst possible rating on its advice scorecard;</li>
<li>As a result, ANZ undertook further file reviews, which identified similar issues with Mr Doyle’s other client</li>
<li>By failing to take reasonable steps, RI Advice effectively ensured that Mr Doyle’s clients and their investments would stay with RI Advice as Mr Doyle’s clients would not be made aware of the inappropriate advice they had received, and</li>
<li>RI Advice permitted Mr Doyle to keep advising clients where there was a substantial risk that he would breach the best interest obligation.</li>
</ol>
<h2>Lessons for AFS licensees</h2>
<p><em>&#8220;Although the duty in s 961L is broad, the case law has begun to fill in the contours of what is expected of a licensee by way of compliance with the provision.&#8221;</em></p>
<p>In making its decision, the Federal Court supported the proposition that whilst AFS licensees are legally obliged under section 961L to take <em>reasonable</em> steps to ensure that their representatives (including authorised representatives) comply with sections 961B, 961G, 961H and 961J (<strong>Relevant Sections</strong>), they are not required to take <em>optimal</em> steps in ensuring compliance with those sections.</p>
<p>This is a particularly interesting statement from the Federal Court as it creates a scale that the Federal court will use when assessing the steps taken by an AFS licensee to comply with the Relevant Sections. This scale is divided into four parts:</p>
<ol>
<li>Steps at the higher end, considered &#8220;optimal&#8221; (read as best practice)</li>
<li>Steps which, although not optimal, are reasonable</li>
<li>Steps which are not reasonable in ensuring that representatives comply with the Relevant Sections, and</li>
<li>Steps which were not taken by the AFS licensee but, had they been taken, would have been reasonable in ensuring that representatives complied with the Relevant Sections.</li>
</ol>
<p>Distinguishing between the first two categories is unnecessary as any steps taken by an AFS licensee that are considered to be optimal will mean that it is automatically categorised as reasonable.</p>
<p>With this in mind, The Fold Legal considers it to be of significant importance for AFS licensees to be able to:</p>
<ol>
<li>Distinguish between steps that are reasonable, and those that are not reasonable, in ensuring that representatives comply with the Relevant Sections</li>
<li>On an ongoing basis, consider whether a step that was once reasonable may no longer be reasonable as the business evolves (particularly as the business grows or down-sizes), and</li>
<li>Consider which steps they are not taking, which, had they been taken, may be reasonable in ensuring that their representatives comply with the Relevant Sections.</li>
</ol>
<p>The Federal Court also outlined that the steps an AFS licensee must take to ensure its representatives are complying with the Relevant Sections are dependent on the specific obligation that the AFS licensee is attempting to comply with. This means that what is reasonable in ensuring that a representative complies with the best interest duty may not be reasonable in ensuring that a representative prioritises the client’s interests over their own.</p>
<p>Unfortunately, there are an enormous number of compliance measures, actions and steps that an AFS licensee must consider and take in attempting to ensure that its representatives comply with the Relevant Sections. Each of these steps falls into one of the four categories outlined above.</p>
<p>Unlike the safe harbour steps outlined in section 961B(2) of the Corporations Act, there is no clear pathway for compliance for section 961L, which makes it still particularly tricky for AFS licensees to navigate safely.</p>
<h2>Penalties</h2>
<p>The penalties for failing to comply with section 961L can be significant. Recently, on 6 February 2022, the Federal Court penalised RI Advice $6 million for their repeated failure to comply with section 961L, even though RI Advice had taken steps to remediate all clients affected by Mr Doyle’s conduct. The Federal Court determined that a substantial penalty was warranted in this case, signifying the importance of understanding the obligation to take reasonable steps pursuant to section 961L.</p>
<p>AFS licensees will need to take into consideration the following when determining whether any step, measure or action is to be implemented or taken:</p>
<ol>
<li>The number of representatives of the AFS licensee</li>
<li>The composition of the AFS licensee’s representatives (either employed advisers or authorised representatives), and</li>
<li>The structure of the AFS licensee (is it a vertically integrated model or not?).</li>
</ol>
<p>Here at The Fold Legal, we try to make the complex simple. We have advised many AFS licensees on the steps, measures and actions they should take (and not take) to ensure compliance with section 961L.</p>
<p>If you are concerned about your obligations as an AFS licensee or would like to review the steps you are taking to comply with section 961L, please get in touch. We are here to help.</p>
<p><em><strong>By  Simon Carrodus and Glenjon Aligiannis</strong></em></p>
<p>The post <a href="https://www.adviservoice.com.au/2022/03/who-would-be-an-afsl-the-courts-review-of-section-961l/">Who Would Be An AFSL? &#8211; The Court’s Review Of Section 961L</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2022/03/who-would-be-an-afsl-the-courts-review-of-section-961l/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>A winter change is coming – fee consent and lack of independence</title>
                <link>https://www.adviservoice.com.au/2021/06/a-winter-change-is-coming-fee-consent-and-lack-of-independence/</link>
                <comments>https://www.adviservoice.com.au/2021/06/a-winter-change-is-coming-fee-consent-and-lack-of-independence/#respond</comments>
                <pubDate>Thu, 03 Jun 2021 22:00:44 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Regulation/Reform]]></category>
		<category><![CDATA[Corbin Jennings]]></category>
		<category><![CDATA[Simon Carrodus]]></category>
                <guid isPermaLink="false">https://adviservoice.com.au/?p=74572</guid>
                                    <description><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>Courtesy of the latest round of Royal Commission legislation<sup>[1]</sup>, from 1 July 2021 financial advice firms need to update their Financial Services Guides <strong>(FSGs)</strong>, Ongoing Service Agreements and Financial Disclosure Statements (FDSs).</h3>
<p>The key changes are:</p>
<ul class="li-listing">
<li>FSGs must include written disclosure that you are not “independent, impartial or unbiased” (assuming you are not independent within the meaning of section 923A of the Corporations Act);</li>
<li>FDSs must include forward-looking disclosure as well as the current backward-looking disclosure; and</li>
<li>All Ongoing Fee Arrangements must be renewed by the client each year (including pre-1 July 2013 arrangements).</li>
</ul>
<p>There is effectively no transition period for the new FSG rules – you must include the “Not Independent” disclosure in your FSG from 1 July. The new FDS rules also commence on 1 July, but there is a 12-month transition period.</p>
<h2>Ongoing fee arrangements</h2>
<h3>What are the new requirements?</h3>
<p>Under the new rules, the Fee Recipient in respect of an Ongoing Fee Arrangement must give the client a FDS each year within 60 days of the client’s “Anniversary Day” – a new term which replaces both “Disclosure Day” and “Renewal Notice Day”.</p>
<p>A client’s Anniversary Day will be:</p>
<ul class="li-listing">
<li>For existing clients, the date that you first provide the client with a FDS after 1 July 2021; or</li>
<li>For new clients, the date that you enter into an Ongoing Fee Arrangement with the client.</li>
</ul>
<p>The FDS must include:</p>
<ul class="li-listing">
<li>Information about the services received and fees paid over the previous 12 months (as per the current requirements);</li>
<li>Information about services and fees for the next 12 months; and</li>
<li>A statement that if the client does not renew the Ongoing Fee Arrangement within 120 days of the Anniversary Day, the arrangement will terminate.</li>
</ul>
<h3>Consent</h3>
<p>The new rules also require that:</p>
<ul class="li-listing">
<li>A Fee Recipient must not deduct or receive Ongoing Fees without the client’s consent; and</li>
<li>The client’s consent automatically expires 150 days after the client’s next Anniversary Day.</li>
</ul>
<p>The Fee Recipient must obtain a new fee consent before the old one expires, or the Ongoing Fee Arrangement will terminate.</p>
<p>You are free to obtain the client’s consent separately, but we think it makes sense to do it at the same time as you renew the Ongoing Fee Arrangement (via the FDS) to avoid unnecessary duplication.</p>
<p>If you wish to obtain the client’s consent via the FDS, it must include certain prescribed information including: an explanation of why consent is being sought, frequency and amount of the fee, which account the fee will be deducted from and how the client can vary or withdraw their consent.</p>
<p>For joint accounts, you must obtain the consent of each account holder.</p>
<h3>Termination</h3>
<p>The client can terminate an Ongoing Fee Arrangement at any time, effective immediately. Otherwise, it will automatically terminate 150 days after the client’s Anniversary Day if the Fee Recipient:</p>
<ul class="li-listing">
<li>Fails to give the client a FDS within 60 days of the Anniversary Day; or</li>
<li>Fails to obtain the client’s consent to renew the Ongoing Fee Arrangement within 120 days of the Anniversary Day.</li>
</ul>
<p>If an Ongoing Fee Arrangement terminates for any reason, the Fee Recipient must notify both the client and the product provider (if any) through which the Ongoing Fee is paid within 10 business days of termination. Failure to do so is a civil penalty provision.</p>
<h3>What about Renewal Notices?</h3>
<p>Renewal Notices are going the way of the Dodo. They will be repealed as at 1 July 2021 and clients will renew their Ongoing Fee Arrangements via the FDS.</p>
<h3>What about pre-1 July 2013 arrangements?</h3>
<p>The honeymoon is over. The new rules will apply to all Ongoing Fee Arrangements, including pre-1 July 2013 arrangements.</p>
<h2>Disclosure of lack of independence</h2>
<h3>What are the new requirements?</h3>
<p>Under the new rules, any adviser or advice firm that issues an FSG must disclose their lack of independence on the front page of the FSG.</p>
<h3>What do you mean by ‘independent’?</h3>
<p>Section 923A of the Corporations Act<sup> [2]</sup>restricts the use of the words “independent”, “impartial” and “unbiased”. Only advisers/firms that satisfy a list of strict criteria are free to use those words. Everyone else is categorised as “Not Independent” and subject to the new FSG disclosure obligations.</p>
<p><strong>Am I independent?</strong></p>
<p>Probably not. Only about 2% of advisers/firms are independent within the meaning of section 923A.</p>
<p>However, you may qualify if you, your AFS licensee and all authorised representatives:</p>
<ul class="li-listing">
<li>Do not receive insurance commissions (or rebate them back to clients in full);</li>
<li>Do not receive any gifts or benefits from product providers;</li>
<li>Have no restrictions regarding the products you can recommend; and</li>
<li>Do not own, are not owned by, and do not have any interest or association with any product providers.</li>
</ul>
<p>It’s important to get this right.</p>
<p><strong>What is the “Not Independent” disclosure?</strong></p>
<p>If you don’t qualify as independent, you must specifically disclose that you are not independent, impartial or unbiased and explain why. There are also requirements about how this disclosure must be displayed in the FSG.</p>
<p>In terms of explaining why you are not independent, impartial or unbiased, ASIC has chosen not to issue any prescribed wording as it considers that advice firms are best placed to describe their business model to their clients. This means there is flexibility to develop a statement that reflects your firm’s circumstances and will be easily understood by your clients.</p>
<p><strong>I’m not ready for this – where do I start?</strong></p>
<p>Don’t worry, we’ve got you covered. To help you prepare for the changes, we’ve updated our Financial Services Guide Template,<sup>[3]</sup>a MDA Provider Financial Services Guide <sup>[4]</sup>and Ongoing Service Toolkit <sup>[5]</sup>to comply with the enhanced disclosure obligations. These templates include the prescribed content as well as helpful tips and guidance. They are a simple way to satisfy the new rules and can be tailored to suit your business and fee structure.</p>
<p><em><strong>By Simon Carrodus and Corbin Jennings</strong></em></p>
<p>&#8212;&#8212;&#8211;</p>
<h6>[1] <a href="https://www.legislation.gov.au/Details/C2021A00019">https://www.legislation.gov.au/Details/C2021A00019</a><br />
[2] Ibid.<br />
[3] <a href="https://www.thefoldlegal.com.au/products/disclosure-documents/financial-services-guide-template-financialplanners">https://www.thefoldlegal.com.au/products/disclosure-documents/financial-services-guide-template-financialplanners</a><br />
[4] <a href="https://www.thefoldlegal.com.au/products/managed-discretionary-accounts/mda-provider-fsg">https://www.thefoldlegal.com.au/products/managed-discretionary-accounts/mda-provider-fsg</a><br />
[5] <a href="https://www.thefoldlegal.com.au/products/compliance-tools/ongoing-service-toolkit">https://www.thefoldlegal.com.au/products/compliance-tools/ongoing-service-toolkit</a></h6>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>Courtesy of the latest round of Royal Commission legislation<sup>[1]</sup>, from 1 July 2021 financial advice firms need to update their Financial Services Guides <strong>(FSGs)</strong>, Ongoing Service Agreements and Financial Disclosure Statements (FDSs).</h3>
<p>The key changes are:</p>
<ul class="li-listing">
<li>FSGs must include written disclosure that you are not “independent, impartial or unbiased” (assuming you are not independent within the meaning of section 923A of the Corporations Act);</li>
<li>FDSs must include forward-looking disclosure as well as the current backward-looking disclosure; and</li>
<li>All Ongoing Fee Arrangements must be renewed by the client each year (including pre-1 July 2013 arrangements).</li>
</ul>
<p>There is effectively no transition period for the new FSG rules – you must include the “Not Independent” disclosure in your FSG from 1 July. The new FDS rules also commence on 1 July, but there is a 12-month transition period.</p>
<h2>Ongoing fee arrangements</h2>
<h3>What are the new requirements?</h3>
<p>Under the new rules, the Fee Recipient in respect of an Ongoing Fee Arrangement must give the client a FDS each year within 60 days of the client’s “Anniversary Day” – a new term which replaces both “Disclosure Day” and “Renewal Notice Day”.</p>
<p>A client’s Anniversary Day will be:</p>
<ul class="li-listing">
<li>For existing clients, the date that you first provide the client with a FDS after 1 July 2021; or</li>
<li>For new clients, the date that you enter into an Ongoing Fee Arrangement with the client.</li>
</ul>
<p>The FDS must include:</p>
<ul class="li-listing">
<li>Information about the services received and fees paid over the previous 12 months (as per the current requirements);</li>
<li>Information about services and fees for the next 12 months; and</li>
<li>A statement that if the client does not renew the Ongoing Fee Arrangement within 120 days of the Anniversary Day, the arrangement will terminate.</li>
</ul>
<h3>Consent</h3>
<p>The new rules also require that:</p>
<ul class="li-listing">
<li>A Fee Recipient must not deduct or receive Ongoing Fees without the client’s consent; and</li>
<li>The client’s consent automatically expires 150 days after the client’s next Anniversary Day.</li>
</ul>
<p>The Fee Recipient must obtain a new fee consent before the old one expires, or the Ongoing Fee Arrangement will terminate.</p>
<p>You are free to obtain the client’s consent separately, but we think it makes sense to do it at the same time as you renew the Ongoing Fee Arrangement (via the FDS) to avoid unnecessary duplication.</p>
<p>If you wish to obtain the client’s consent via the FDS, it must include certain prescribed information including: an explanation of why consent is being sought, frequency and amount of the fee, which account the fee will be deducted from and how the client can vary or withdraw their consent.</p>
<p>For joint accounts, you must obtain the consent of each account holder.</p>
<h3>Termination</h3>
<p>The client can terminate an Ongoing Fee Arrangement at any time, effective immediately. Otherwise, it will automatically terminate 150 days after the client’s Anniversary Day if the Fee Recipient:</p>
<ul class="li-listing">
<li>Fails to give the client a FDS within 60 days of the Anniversary Day; or</li>
<li>Fails to obtain the client’s consent to renew the Ongoing Fee Arrangement within 120 days of the Anniversary Day.</li>
</ul>
<p>If an Ongoing Fee Arrangement terminates for any reason, the Fee Recipient must notify both the client and the product provider (if any) through which the Ongoing Fee is paid within 10 business days of termination. Failure to do so is a civil penalty provision.</p>
<h3>What about Renewal Notices?</h3>
<p>Renewal Notices are going the way of the Dodo. They will be repealed as at 1 July 2021 and clients will renew their Ongoing Fee Arrangements via the FDS.</p>
<h3>What about pre-1 July 2013 arrangements?</h3>
<p>The honeymoon is over. The new rules will apply to all Ongoing Fee Arrangements, including pre-1 July 2013 arrangements.</p>
<h2>Disclosure of lack of independence</h2>
<h3>What are the new requirements?</h3>
<p>Under the new rules, any adviser or advice firm that issues an FSG must disclose their lack of independence on the front page of the FSG.</p>
<h3>What do you mean by ‘independent’?</h3>
<p>Section 923A of the Corporations Act<sup> [2]</sup>restricts the use of the words “independent”, “impartial” and “unbiased”. Only advisers/firms that satisfy a list of strict criteria are free to use those words. Everyone else is categorised as “Not Independent” and subject to the new FSG disclosure obligations.</p>
<p><strong>Am I independent?</strong></p>
<p>Probably not. Only about 2% of advisers/firms are independent within the meaning of section 923A.</p>
<p>However, you may qualify if you, your AFS licensee and all authorised representatives:</p>
<ul class="li-listing">
<li>Do not receive insurance commissions (or rebate them back to clients in full);</li>
<li>Do not receive any gifts or benefits from product providers;</li>
<li>Have no restrictions regarding the products you can recommend; and</li>
<li>Do not own, are not owned by, and do not have any interest or association with any product providers.</li>
</ul>
<p>It’s important to get this right.</p>
<p><strong>What is the “Not Independent” disclosure?</strong></p>
<p>If you don’t qualify as independent, you must specifically disclose that you are not independent, impartial or unbiased and explain why. There are also requirements about how this disclosure must be displayed in the FSG.</p>
<p>In terms of explaining why you are not independent, impartial or unbiased, ASIC has chosen not to issue any prescribed wording as it considers that advice firms are best placed to describe their business model to their clients. This means there is flexibility to develop a statement that reflects your firm’s circumstances and will be easily understood by your clients.</p>
<p><strong>I’m not ready for this – where do I start?</strong></p>
<p>Don’t worry, we’ve got you covered. To help you prepare for the changes, we’ve updated our Financial Services Guide Template,<sup>[3]</sup>a MDA Provider Financial Services Guide <sup>[4]</sup>and Ongoing Service Toolkit <sup>[5]</sup>to comply with the enhanced disclosure obligations. These templates include the prescribed content as well as helpful tips and guidance. They are a simple way to satisfy the new rules and can be tailored to suit your business and fee structure.</p>
<p><em><strong>By Simon Carrodus and Corbin Jennings</strong></em></p>
<p>&#8212;&#8212;&#8211;</p>
<h6>[1] <a href="https://www.legislation.gov.au/Details/C2021A00019">https://www.legislation.gov.au/Details/C2021A00019</a><br />
[2] Ibid.<br />
[3] <a href="https://www.thefoldlegal.com.au/products/disclosure-documents/financial-services-guide-template-financialplanners">https://www.thefoldlegal.com.au/products/disclosure-documents/financial-services-guide-template-financialplanners</a><br />
[4] <a href="https://www.thefoldlegal.com.au/products/managed-discretionary-accounts/mda-provider-fsg">https://www.thefoldlegal.com.au/products/managed-discretionary-accounts/mda-provider-fsg</a><br />
[5] <a href="https://www.thefoldlegal.com.au/products/compliance-tools/ongoing-service-toolkit">https://www.thefoldlegal.com.au/products/compliance-tools/ongoing-service-toolkit</a></h6>
<p>The post <a href="https://www.adviservoice.com.au/2021/06/a-winter-change-is-coming-fee-consent-and-lack-of-independence/">A winter change is coming – fee consent and lack of independence</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2021/06/a-winter-change-is-coming-fee-consent-and-lack-of-independence/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>Breach reporting is about to become more onerous</title>
                <link>https://www.adviservoice.com.au/2021/04/breach-reporting-is-about-to-become-more-onerous/</link>
                <comments>https://www.adviservoice.com.au/2021/04/breach-reporting-is-about-to-become-more-onerous/#respond</comments>
                <pubDate>Mon, 05 Apr 2021 21:55:09 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Regulation/Reform]]></category>
		<category><![CDATA[Simon Carrodus]]></category>
                <guid isPermaLink="false">https://adviservoice.com.au/?p=73322</guid>
                                    <description><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>A new breach reporting regime will commence on 1 October 2021 and it will be more onerous on licensees than ever before. One of the most notable changes is that credit licensees are now required to report significant breaches for the first time. In this blog, we outline the other key changes that you need to know.</h3>
<h2>What is a ‘reportable situation’?</h2>
<p>Under the new regime, a licensee must lodge a report within 30 days (previously 10 days) of when the licensee first knows or is reckless with respect to whether there are reasonable grounds to believe a reportable situation has arisen.</p>
<p>A reportable situation arises when:</p>
<ul class="li-listing">
<li>the licensee or its representative has breached a core obligation and the breach is significant;</li>
<li>the licensee or its representative is no longer able to comply with a core obligation and the breach, when it occurs, will be significant;</li>
<li>the licensee or its representative has commenced an investigation into whether a reportable situation has occurred, and the investigation has continued for more than 30 days; or</li>
<li>the licensee or its representative has engaged in gross negligence or serious fraud.</li>
</ul>
<p>While the term ‘core obligation’ is new, the provisions that it covers are identical to the current breach regime. What has changed is the significance test and the timeline for reporting.</p>
<h2>The clock starts ticking earlier</h2>
<p>You will need to review your breach assessment processes to ensure they can meet the new timelines. The 30-day clock now starts ticking once you have reasonable grounds to believe there has been or will be a significant breach, or you are reckless as to whether there are reasonable grounds.</p>
<p>The breach must also be reported to ASIC at the investigation stage if the investigation has continued for more than 30 days, and the licensee must provide a second report to ASIC on the outcome of the investigation once it is complete. In this way, there is an incentive to finalise any such investigation within 30 days to avoid having to report to ASIC twice.</p>
<p>There are several questions that remain unanswered here, including what constitutes an investigation and when an investigation actually commences.</p>
<h2>The significance test has been expanded</h2>
<p>Breach reporting is required in a broader range of circumstances because the significance test has been expanded. The new regime introduces deeming provisions that are supposed to take the guesswork out of determining whether a breach is significant or not.</p>
<p>A breach of a core obligation is deemed to be significant if:</p>
<ul class="li-listing">
<li>the provision breached is an offence that may involve imprisonment for 12 months (3 months for dishonesty offences);</li>
<li>the provision breached is a civil penalty provision;</li>
<li>the provision breached relates to misleading or deceptive conduct under the <i>Corporations Act </i>or the <i>ASIC Act</i>; or</li>
<li>the breach results, or is likely to result, in material loss or damage to clients or members.</li>
</ul>
<p>Remember that gross negligence and serious fraud are automatically reportable as well.</p>
<p>For credit licensees, breach of a “key requirement” under the National Credit Code is also deemed to be significant.</p>
<p>By deeming a breach with a civil penalty provision as significant, it means that almost all breaches of the relevant legislative provisions will be reportable, regardless of their size. This means you should expect to lodge breach reports more frequently.</p>
<p>It’s worth noting that the Explanatory Memorandum contemplates that Treasury may introduce new regulations to pare back the deeming provisions if ASIC receives too many ‘minor, technical or inadvertent’ breach reports. This remains to be seen, however, and it is unlikely to happen for at least 12 months after commencement.</p>
<p>Even if a breach is not automatically ‘deemed’ to be significant, licensees must still assess whether the breach is significant by considering:</p>
<ul class="li-listing">
<li>the number or frequency of similar breaches;</li>
<li>the impact of the breach on their ability to provide the services covered by their licence; and</li>
<li>the extent to which the breach indicates the licensee’s compliance arrangements are inadequate.</li>
</ul>
<h2>Licensees will be required to notify affected clients</h2>
<p>If a reportable breach involves financial advice to retail clients or credit assistance by mortgage brokers, the affected clients must also be notified of the breach. The licensee must investigate the breach and compensate affected clients for any loss or damage.</p>
<p>You may need to implement new systems to ensure you can meet this new obligation.</p>
<h2>Licensees will be required to notify ASIC of breaches by other licensees</h2>
<p>Licensees will also be required to report to ASIC about breaches by other licensees to ASIC in certain circumstances. This new reporting provision is targeted at misconduct by individual financial advisers and mortgage brokers.</p>
<p>AFS and credit licensees are required to lodge a report with ASIC if:</p>
<ul class="li-listing">
<li>you have reasonable grounds to believe that a reportable situation has arisen in relation to another AFS or credit licensee;</li>
<li>the breach relates to the conduct of an individual; and</li>
<li>the individual provides personal advice to retail clients or credit assistance by a mortgage broker.</li>
</ul>
<p>The report must be lodged with ASIC within 30 days after you first know, or are reckless with respect to whether, there are reasonable grounds to believe that a reportable situation has occurred. A copy of the report must also be given to the relevant licensee within the same 30-day period. Failure to do so is a civil penalty provision.</p>
<p>Once these new provisions come into effect, you can expect to be lodging breach reports more frequently. These breach reports are currently required to be lodged via the ASIC portal and we do not expect this to change. The new requirements may mean you need to put in place additional systems and controls to identify and report on breaches.</p>
<p><em><strong>By Simon Carrodus, Solicitor Director</strong></em></p>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>A new breach reporting regime will commence on 1 October 2021 and it will be more onerous on licensees than ever before. One of the most notable changes is that credit licensees are now required to report significant breaches for the first time. In this blog, we outline the other key changes that you need to know.</h3>
<h2>What is a ‘reportable situation’?</h2>
<p>Under the new regime, a licensee must lodge a report within 30 days (previously 10 days) of when the licensee first knows or is reckless with respect to whether there are reasonable grounds to believe a reportable situation has arisen.</p>
<p>A reportable situation arises when:</p>
<ul class="li-listing">
<li>the licensee or its representative has breached a core obligation and the breach is significant;</li>
<li>the licensee or its representative is no longer able to comply with a core obligation and the breach, when it occurs, will be significant;</li>
<li>the licensee or its representative has commenced an investigation into whether a reportable situation has occurred, and the investigation has continued for more than 30 days; or</li>
<li>the licensee or its representative has engaged in gross negligence or serious fraud.</li>
</ul>
<p>While the term ‘core obligation’ is new, the provisions that it covers are identical to the current breach regime. What has changed is the significance test and the timeline for reporting.</p>
<h2>The clock starts ticking earlier</h2>
<p>You will need to review your breach assessment processes to ensure they can meet the new timelines. The 30-day clock now starts ticking once you have reasonable grounds to believe there has been or will be a significant breach, or you are reckless as to whether there are reasonable grounds.</p>
<p>The breach must also be reported to ASIC at the investigation stage if the investigation has continued for more than 30 days, and the licensee must provide a second report to ASIC on the outcome of the investigation once it is complete. In this way, there is an incentive to finalise any such investigation within 30 days to avoid having to report to ASIC twice.</p>
<p>There are several questions that remain unanswered here, including what constitutes an investigation and when an investigation actually commences.</p>
<h2>The significance test has been expanded</h2>
<p>Breach reporting is required in a broader range of circumstances because the significance test has been expanded. The new regime introduces deeming provisions that are supposed to take the guesswork out of determining whether a breach is significant or not.</p>
<p>A breach of a core obligation is deemed to be significant if:</p>
<ul class="li-listing">
<li>the provision breached is an offence that may involve imprisonment for 12 months (3 months for dishonesty offences);</li>
<li>the provision breached is a civil penalty provision;</li>
<li>the provision breached relates to misleading or deceptive conduct under the <i>Corporations Act </i>or the <i>ASIC Act</i>; or</li>
<li>the breach results, or is likely to result, in material loss or damage to clients or members.</li>
</ul>
<p>Remember that gross negligence and serious fraud are automatically reportable as well.</p>
<p>For credit licensees, breach of a “key requirement” under the National Credit Code is also deemed to be significant.</p>
<p>By deeming a breach with a civil penalty provision as significant, it means that almost all breaches of the relevant legislative provisions will be reportable, regardless of their size. This means you should expect to lodge breach reports more frequently.</p>
<p>It’s worth noting that the Explanatory Memorandum contemplates that Treasury may introduce new regulations to pare back the deeming provisions if ASIC receives too many ‘minor, technical or inadvertent’ breach reports. This remains to be seen, however, and it is unlikely to happen for at least 12 months after commencement.</p>
<p>Even if a breach is not automatically ‘deemed’ to be significant, licensees must still assess whether the breach is significant by considering:</p>
<ul class="li-listing">
<li>the number or frequency of similar breaches;</li>
<li>the impact of the breach on their ability to provide the services covered by their licence; and</li>
<li>the extent to which the breach indicates the licensee’s compliance arrangements are inadequate.</li>
</ul>
<h2>Licensees will be required to notify affected clients</h2>
<p>If a reportable breach involves financial advice to retail clients or credit assistance by mortgage brokers, the affected clients must also be notified of the breach. The licensee must investigate the breach and compensate affected clients for any loss or damage.</p>
<p>You may need to implement new systems to ensure you can meet this new obligation.</p>
<h2>Licensees will be required to notify ASIC of breaches by other licensees</h2>
<p>Licensees will also be required to report to ASIC about breaches by other licensees to ASIC in certain circumstances. This new reporting provision is targeted at misconduct by individual financial advisers and mortgage brokers.</p>
<p>AFS and credit licensees are required to lodge a report with ASIC if:</p>
<ul class="li-listing">
<li>you have reasonable grounds to believe that a reportable situation has arisen in relation to another AFS or credit licensee;</li>
<li>the breach relates to the conduct of an individual; and</li>
<li>the individual provides personal advice to retail clients or credit assistance by a mortgage broker.</li>
</ul>
<p>The report must be lodged with ASIC within 30 days after you first know, or are reckless with respect to whether, there are reasonable grounds to believe that a reportable situation has occurred. A copy of the report must also be given to the relevant licensee within the same 30-day period. Failure to do so is a civil penalty provision.</p>
<p>Once these new provisions come into effect, you can expect to be lodging breach reports more frequently. These breach reports are currently required to be lodged via the ASIC portal and we do not expect this to change. The new requirements may mean you need to put in place additional systems and controls to identify and report on breaches.</p>
<p><em><strong>By Simon Carrodus, Solicitor Director</strong></em></p>
<p>The post <a href="https://www.adviservoice.com.au/2021/04/breach-reporting-is-about-to-become-more-onerous/">Breach reporting is about to become more onerous</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2021/04/breach-reporting-is-about-to-become-more-onerous/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>History repeats &#8211; The risks of inadequate due diligence</title>
                <link>https://www.adviservoice.com.au/2020/07/history-repeats-the-risks-of-inadequate-due-diligence/</link>
                <comments>https://www.adviservoice.com.au/2020/07/history-repeats-the-risks-of-inadequate-due-diligence/#respond</comments>
                <pubDate>Thu, 23 Jul 2020 21:55:10 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Best Practice]]></category>
		<category><![CDATA[Katie Johnston]]></category>
		<category><![CDATA[Lydia Carstensen]]></category>
		<category><![CDATA[Simon Carrodus]]></category>
                <guid isPermaLink="false">https://adviservoice.com.au/?p=69276</guid>
                                    <description><![CDATA[<div id="attachment_69277" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-69277" class="size-full wp-image-69277" src="https://adviservoice.com.au/wp-content/uploads/2020/07/repeat-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2020/07/repeat-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2020/07/repeat-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-69277" class="wp-caption-text">If you purchase a business with a history of non-compliance, ASIC may hold you accountable for regulatory non-compliance.</p></div>
<h3>Exposure to historical non-compliance can be fatal for purchasers but many don’t include it in their due diligence. ASIC is on the warpath and you can be liable even if you weren’t operating the business at the time of the non-compliance.</h3>
<p>So before you purchase a business that holds an Australian Financial Services Licence or Australian Credit Licence you need to make sure the compliance records and policies are up to standard.</p>
<h2>What is due diligence good for?</h2>
<p>Due diligence is crucial to any transaction. As a buyer, it gives you comfort that:</p>
<ul class="li-listing">
<li>The value of the business is appropriate;</li>
<li>You have the appetite for the risks associated with the business; and</li>
<li>The share sale agreement addresses these risks and exposures in exchange for due consideration.</li>
</ul>
<p>If you don’t perform due diligence you won’t know what potential exposures you have in the business you’re purchasing.</p>
<h2>What are the risks of historical non-compliance?</h2>
<p>If you purchase a business with a history of non-compliance, ASIC may hold you accountable for regulatory non-compliance. This is possible even if the acts or omissions that led to non-compliance took place under the previous owner.</p>
<p>If ASIC finds the business guilty of non-compliance, they can impose a range of remedies including:</p>
<ul class="li-listing">
<li>Additional licence conditions;</li>
<li>Requiring you to undertake a client remediation program;</li>
<li>Publishing a ‘name and shame’ media release. This may tarnish the business’ reputation and cause clients to panic;</li>
<li>Suspending the licence. During this time the business and its representatives cannot provide financial services or generate income;</li>
<li>Cancelling the licence; or</li>
<li>Imposing civil penalties for corporates and financial service licensees for breaching their licence conditions.</li>
</ul>
<p>Even if the licence isn’t cancelled, you could face significant financial strain or insolvency. This could be caused by:</p>
<ul class="li-listing">
<li>Paying the purchase price;</li>
<li>Incurring additional legal and compliance costs to defend and remediate non-compliance;</li>
<li>Representatives deciding to transfer to another licensee with a better compliance record and reputation. Operating with a reduced number of representatives may severely impact the business’ ability to generate revenue; and</li>
<li>Reputational damage and business disruption that stagnates the business.</li>
</ul>
<p>There is also no guarantee the non-compliance is purely historical – it might be an ongoing issue that needs to be addressed at significant cost.</p>
<p>You can protect yourself in the share sale contract by including specific indemnities, for example. But if these protections haven’t been drafted appropriately, the cost of defending the business may be prohibitive and impossible for you to recover from the seller.</p>
<h2>Minimise your compliance risk</h2>
<p>As a buyer, once you’ve completed your financial due diligence, there are 4 steps you should take to minimise your compliance risk:</p>
<h3>Step 1: Undertake compliance due diligence</h3>
<ul class="li-listing">
<li>Ask for details of any ASIC investigations or surveillances in the last 5 years.</li>
<li>Ask for audit reports for each representative over the last 5 years.</li>
</ul>
<p>Red flag: <em>The business doesn’t regularly audit their representatives.</em></p>
<ul class="li-listing">
<li>Request details of any client compensation paid over the last 5 years.</li>
<li>Review the business’ breach register.</li>
</ul>
<p>Red flag<em>: The business doesn’t have a breach register.</em></p>
<ul class="li-listing">
<li>Review the business’ key policies and procedures.</li>
<li>Conduct sample testing to check the quality of the business’ record-keeping practices.</li>
</ul>
<p>If you find any issues you can require the seller to update their compliance framework and address specific issues (like client compensation) prior to purchase.</p>
<h3>Step 2: Protect yourself contractually</h3>
<p>When drafting the contract, include:</p>
<ul class="li-listing">
<li>Warranties that you can rely on and indemnities you can enforce.</li>
</ul>
<p><em>TIP: Draft specific indemnities for any particular issues identified during your compliance due diligence that aren’t deal breakers.</em></p>
<ul class="li-listing">
<li>A remediation clause that covers any costs including fines, client compensation and legal expenses. Also include requirements for the seller to produce records and information and promise to work collaboratively and in good faith to negotiate and achieve the most favourable outcome possible for you.</li>
<li>Guarantees that can be enforced against the seller on a corporate and individual level. Obviously, these will only be as strong as the financial resources of the party giving them.</li>
</ul>
<p><em>TIP: Ask for guarantees from owner directors.</em></p>
<ul class="li-listing">
<li>Structuring the purchase price payment so that part of the purchase price is held in escrow for a set period of time. If compliance issues arise during that time this amount can be used to address the issue. Once the escrow period has lapsed, the amount can be paid to the seller. The length of the escrow period is a commercial point of negotiation between the parties. The longest we’ve seen them run for is 2 to 3 years.</li>
</ul>
<p><em>TIP: This arrangement works best if the exposure you’re protecting against has a set ceiling. If not, indemnities are optimal contractual protection.</em></p>
<h3>Step 3: Be vigilant when running the business</h3>
<ul class="li-listing">
<li>If your due diligence has identified gaps in compliance, you should address these immediately. Your compliance framework should be sufficient to prevent recurrence.</li>
<li>Consider engaging an external compliance consultant to help you determine the extent of a compliance issue and how best to fix it.</li>
<li>If clients need to be compensated for historical compliance breaches, you should expedite this program and notify the seller as early as possible.</li>
</ul>
<h3>Step 4: Review the representatives of the business</h3>
<ul class="li-listing">
<li>If you’re retaining representatives, you should review their individual compliance history. You may need to terminate a representative if they have a poor compliance history or require the seller to do so as a condition precedent.</li>
<li>You may need some employees or representatives to stay on after the purchase to assist with remediation or oversee improvements to the compliance framework. You will need to identify them and make sure they aren’t planning to terminate their employment or authorisation upon sale as this may impact your valuation of the business.</li>
</ul>
<p><em><strong>By Simon Carrodus, Katie Johnston and Lydia Carstensen</strong></em></p>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_69277" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-69277" class="size-full wp-image-69277" src="https://adviservoice.com.au/wp-content/uploads/2020/07/repeat-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2020/07/repeat-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2020/07/repeat-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-69277" class="wp-caption-text">If you purchase a business with a history of non-compliance, ASIC may hold you accountable for regulatory non-compliance.</p></div>
<h3>Exposure to historical non-compliance can be fatal for purchasers but many don’t include it in their due diligence. ASIC is on the warpath and you can be liable even if you weren’t operating the business at the time of the non-compliance.</h3>
<p>So before you purchase a business that holds an Australian Financial Services Licence or Australian Credit Licence you need to make sure the compliance records and policies are up to standard.</p>
<h2>What is due diligence good for?</h2>
<p>Due diligence is crucial to any transaction. As a buyer, it gives you comfort that:</p>
<ul class="li-listing">
<li>The value of the business is appropriate;</li>
<li>You have the appetite for the risks associated with the business; and</li>
<li>The share sale agreement addresses these risks and exposures in exchange for due consideration.</li>
</ul>
<p>If you don’t perform due diligence you won’t know what potential exposures you have in the business you’re purchasing.</p>
<h2>What are the risks of historical non-compliance?</h2>
<p>If you purchase a business with a history of non-compliance, ASIC may hold you accountable for regulatory non-compliance. This is possible even if the acts or omissions that led to non-compliance took place under the previous owner.</p>
<p>If ASIC finds the business guilty of non-compliance, they can impose a range of remedies including:</p>
<ul class="li-listing">
<li>Additional licence conditions;</li>
<li>Requiring you to undertake a client remediation program;</li>
<li>Publishing a ‘name and shame’ media release. This may tarnish the business’ reputation and cause clients to panic;</li>
<li>Suspending the licence. During this time the business and its representatives cannot provide financial services or generate income;</li>
<li>Cancelling the licence; or</li>
<li>Imposing civil penalties for corporates and financial service licensees for breaching their licence conditions.</li>
</ul>
<p>Even if the licence isn’t cancelled, you could face significant financial strain or insolvency. This could be caused by:</p>
<ul class="li-listing">
<li>Paying the purchase price;</li>
<li>Incurring additional legal and compliance costs to defend and remediate non-compliance;</li>
<li>Representatives deciding to transfer to another licensee with a better compliance record and reputation. Operating with a reduced number of representatives may severely impact the business’ ability to generate revenue; and</li>
<li>Reputational damage and business disruption that stagnates the business.</li>
</ul>
<p>There is also no guarantee the non-compliance is purely historical – it might be an ongoing issue that needs to be addressed at significant cost.</p>
<p>You can protect yourself in the share sale contract by including specific indemnities, for example. But if these protections haven’t been drafted appropriately, the cost of defending the business may be prohibitive and impossible for you to recover from the seller.</p>
<h2>Minimise your compliance risk</h2>
<p>As a buyer, once you’ve completed your financial due diligence, there are 4 steps you should take to minimise your compliance risk:</p>
<h3>Step 1: Undertake compliance due diligence</h3>
<ul class="li-listing">
<li>Ask for details of any ASIC investigations or surveillances in the last 5 years.</li>
<li>Ask for audit reports for each representative over the last 5 years.</li>
</ul>
<p>Red flag: <em>The business doesn’t regularly audit their representatives.</em></p>
<ul class="li-listing">
<li>Request details of any client compensation paid over the last 5 years.</li>
<li>Review the business’ breach register.</li>
</ul>
<p>Red flag<em>: The business doesn’t have a breach register.</em></p>
<ul class="li-listing">
<li>Review the business’ key policies and procedures.</li>
<li>Conduct sample testing to check the quality of the business’ record-keeping practices.</li>
</ul>
<p>If you find any issues you can require the seller to update their compliance framework and address specific issues (like client compensation) prior to purchase.</p>
<h3>Step 2: Protect yourself contractually</h3>
<p>When drafting the contract, include:</p>
<ul class="li-listing">
<li>Warranties that you can rely on and indemnities you can enforce.</li>
</ul>
<p><em>TIP: Draft specific indemnities for any particular issues identified during your compliance due diligence that aren’t deal breakers.</em></p>
<ul class="li-listing">
<li>A remediation clause that covers any costs including fines, client compensation and legal expenses. Also include requirements for the seller to produce records and information and promise to work collaboratively and in good faith to negotiate and achieve the most favourable outcome possible for you.</li>
<li>Guarantees that can be enforced against the seller on a corporate and individual level. Obviously, these will only be as strong as the financial resources of the party giving them.</li>
</ul>
<p><em>TIP: Ask for guarantees from owner directors.</em></p>
<ul class="li-listing">
<li>Structuring the purchase price payment so that part of the purchase price is held in escrow for a set period of time. If compliance issues arise during that time this amount can be used to address the issue. Once the escrow period has lapsed, the amount can be paid to the seller. The length of the escrow period is a commercial point of negotiation between the parties. The longest we’ve seen them run for is 2 to 3 years.</li>
</ul>
<p><em>TIP: This arrangement works best if the exposure you’re protecting against has a set ceiling. If not, indemnities are optimal contractual protection.</em></p>
<h3>Step 3: Be vigilant when running the business</h3>
<ul class="li-listing">
<li>If your due diligence has identified gaps in compliance, you should address these immediately. Your compliance framework should be sufficient to prevent recurrence.</li>
<li>Consider engaging an external compliance consultant to help you determine the extent of a compliance issue and how best to fix it.</li>
<li>If clients need to be compensated for historical compliance breaches, you should expedite this program and notify the seller as early as possible.</li>
</ul>
<h3>Step 4: Review the representatives of the business</h3>
<ul class="li-listing">
<li>If you’re retaining representatives, you should review their individual compliance history. You may need to terminate a representative if they have a poor compliance history or require the seller to do so as a condition precedent.</li>
<li>You may need some employees or representatives to stay on after the purchase to assist with remediation or oversee improvements to the compliance framework. You will need to identify them and make sure they aren’t planning to terminate their employment or authorisation upon sale as this may impact your valuation of the business.</li>
</ul>
<p><em><strong>By Simon Carrodus, Katie Johnston and Lydia Carstensen</strong></em></p>
<p>The post <a href="https://www.adviservoice.com.au/2020/07/history-repeats-the-risks-of-inadequate-due-diligence/">History repeats &#8211; The risks of inadequate due diligence</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2020/07/history-repeats-the-risks-of-inadequate-due-diligence/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>How Covid-19 has affected reforms to wealth businesses</title>
                <link>https://www.adviservoice.com.au/2020/05/how-covid-19-has-affected-reforms-to-wealth-businesses/</link>
                <comments>https://www.adviservoice.com.au/2020/05/how-covid-19-has-affected-reforms-to-wealth-businesses/#respond</comments>
                <pubDate>Wed, 27 May 2020 21:45:34 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Regulation/Reform]]></category>
		<category><![CDATA[Charmian Holmes]]></category>
		<category><![CDATA[Lydia Carstensen]]></category>
		<category><![CDATA[Simon Carrodus]]></category>
                <guid isPermaLink="false">https://adviservoice.com.au/?p=68210</guid>
                                    <description><![CDATA[<div id="attachment_61326" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-61326" class="size-full wp-image-61326" src="https://adviservoice.com.au/wp-content/uploads/2019/04/Charmian-Holmes-650.jpg" alt="Charmian Holmes" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/04/Charmian-Holmes-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/04/Charmian-Holmes-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-61326" class="wp-caption-text">Charmian Holmes</p></div>
<p>With the ongoing COVID-19 pandemic, it’s fair to say that regulators and businesses have shifted their priorities. Timelines for legislative reforms driven by the Hayne Royal Commission and licence applications for wealth businesses have changed.</p>
<h2>APRA and ASIC licences may be delayed</h2>
<p>APRA has <a href="https://www.apra.gov.au/covid-19-apra%E2%80%99s-approach-to-licensing" target="_blank" rel="noopener noreferrer">announced that</a> it will not issue any new insurance or banking licences for at least 6 months. While ASIC has said it’s ‘business as usual’ for the Australian financial services licensing process, we expect timelines to be impacted by remote working and a reduced workforce.</p>
<h2>Regulators have changed their priorities</h2>
<p>ASIC is prioritising challenges arising from the pandemic and regulatory change where:</p>
<ul class="li-listing">
<li>There is the risk of significant consumer harm;</li>
<li>There are serious breaches of the law;</li>
<li>There are risks to market integrity; or</li>
<li>The matter is time critical.</li>
</ul>
<p>Policy work on key Royal Commission reforms were to start on 1 July 2020 but these will be delayed by at least six months.<sup>1</sup></p>
<p>To help you plan, we’ve identified which changes apply now and which ones are likely to be delayed. This means you may have more time to prepare. We’ll update this blog as more information comes to hand.</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="alignleft size-large wp-image-68212" src="https://adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-1-1024x396.png" alt="" width="1024" height="396" srcset="https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-1-1024x396.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-1-300x116.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-1-768x297.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-1.png 1436w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="alignleft size-large wp-image-68211" src="https://adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-2-1024x970.png" alt="" width="1024" height="970" srcset="https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-2-1024x970.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-2-300x284.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-2-768x728.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-2.png 1444w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></p>
<p>&nbsp;</p>
<p><em><strong>By Charmian Holmes, Simon Carrodus and Lydia Carstensen</strong></em></p>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_61326" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-61326" class="size-full wp-image-61326" src="https://adviservoice.com.au/wp-content/uploads/2019/04/Charmian-Holmes-650.jpg" alt="Charmian Holmes" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/04/Charmian-Holmes-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/04/Charmian-Holmes-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-61326" class="wp-caption-text">Charmian Holmes</p></div>
<p>With the ongoing COVID-19 pandemic, it’s fair to say that regulators and businesses have shifted their priorities. Timelines for legislative reforms driven by the Hayne Royal Commission and licence applications for wealth businesses have changed.</p>
<h2>APRA and ASIC licences may be delayed</h2>
<p>APRA has <a href="https://www.apra.gov.au/covid-19-apra%E2%80%99s-approach-to-licensing" target="_blank" rel="noopener noreferrer">announced that</a> it will not issue any new insurance or banking licences for at least 6 months. While ASIC has said it’s ‘business as usual’ for the Australian financial services licensing process, we expect timelines to be impacted by remote working and a reduced workforce.</p>
<h2>Regulators have changed their priorities</h2>
<p>ASIC is prioritising challenges arising from the pandemic and regulatory change where:</p>
<ul class="li-listing">
<li>There is the risk of significant consumer harm;</li>
<li>There are serious breaches of the law;</li>
<li>There are risks to market integrity; or</li>
<li>The matter is time critical.</li>
</ul>
<p>Policy work on key Royal Commission reforms were to start on 1 July 2020 but these will be delayed by at least six months.<sup>1</sup></p>
<p>To help you plan, we’ve identified which changes apply now and which ones are likely to be delayed. This means you may have more time to prepare. We’ll update this blog as more information comes to hand.</p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="alignleft size-large wp-image-68212" src="https://adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-1-1024x396.png" alt="" width="1024" height="396" srcset="https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-1-1024x396.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-1-300x116.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-1-768x297.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-1.png 1436w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></p>
<p>&nbsp;</p>
<p><img loading="lazy" decoding="async" class="alignleft size-large wp-image-68211" src="https://adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-2-1024x970.png" alt="" width="1024" height="970" srcset="https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-2-1024x970.png 1024w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-2-300x284.png 300w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-2-768x728.png 768w, https://www.adviservoice.com.au/wp-content/uploads/2020/05/thefold-may-28-2.png 1444w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></p>
<p>&nbsp;</p>
<p><em><strong>By Charmian Holmes, Simon Carrodus and Lydia Carstensen</strong></em></p>
<p>The post <a href="https://www.adviservoice.com.au/2020/05/how-covid-19-has-affected-reforms-to-wealth-businesses/">How Covid-19 has affected reforms to wealth businesses</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2020/05/how-covid-19-has-affected-reforms-to-wealth-businesses/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
                    <item>
                <title>FASEA Code of Ethics – what you need to know</title>
                <link>https://www.adviservoice.com.au/2020/02/fasea-code-of-ethics-what-you-need-to-know/</link>
                <comments>https://www.adviservoice.com.au/2020/02/fasea-code-of-ethics-what-you-need-to-know/#respond</comments>
                <pubDate>Sun, 23 Feb 2020 20:50:11 +0000</pubDate>
                <dc:creator>
                                    </dc:creator>
                		<category><![CDATA[Industry Bodies]]></category>
		<category><![CDATA[Simon Carrodus]]></category>
                <guid isPermaLink="false">https://adviservoice.com.au/?p=66196</guid>
                                    <description><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>We’re well into 2020 and the FASEA Code of Ethics (the Code) is currently in force. What should advisers and licensees be doing to make sure they comply with the Code?</h3>
<p>The Code came into effect on 1 January 2020. To make sure we’re all on the same page, I’ve answered some FAQs.</p>
<p><strong>I am an AFS licensee, does the Code apply to me?</strong></p>
<p>No. The Code applies to individuals not companies. But AFS licensees must take reasonable steps to ensure that their advisers comply with financial services laws and this includes the Code.</p>
<p><strong>Who is monitoring and enforcing the Code?</strong></p>
<p>AFS licensees are responsible for monitoring that their advisers comply with the Code. There is no external organisation monitoring the Code (yet).</p>
<p><strong>Isn’t there a Code monitoring body?</strong></p>
<p>Treasurer Josh Frydenberg has said that the Government will establish a new body to monitor the Code in early 2021, but this depends on the passage of legislation through Parliament. So in reality a Code monitoring body might be 18-24 months away.</p>
<p><strong>Isn’t ASIC monitoring and enforcing the Code?</strong></p>
<p>No. ASIC has made it clear that it is not their role to enforce the Code, but they do monitor AFS licensees.</p>
<p><strong>What about AFCA?</strong></p>
<p>AFCA made a statement that it will take a “measured and considered approach” to interpreting the Code’s provisions until a monitoring body is established. In other words, advisers have some breathing space.</p>
<p><strong>No man’s land</strong></p>
<p>Even though the Code came into effect on 1 January, the consultation process is not yet complete. In late 2019, FASEA conducted consultation sessions and accepted submissions from licensees, educational and industry bodies, advisers and consumer groups.</p>
<p>Many hoped this process would result in a re-drafted Code that would clarify the major points of confusion. Second on the wish list was a re-drafted guidance document. No such luck.</p>
<p>Instead, we have a “preliminary response to the submissions” (i.e. more guidance) and the promise of a “further detailed response” later in 2020.</p>
<p>We are in a phase of ‘facilitative compliance’. This means that no regulatory action will be taken provided licensees take reasonable steps to ensure their advisers comply with the Code. This means licensees should:</p>
<ul class="li-listing">
<li>Review their policies;</li>
<li>Update systems;</li>
<li>Provide training and guidance about the Code; and</li>
<li>Monitor their adviser’s compliance with the Code.</li>
</ul>
<p>This is in recognition of, as ASIC put it, “…the timing of the guidance provided by FASEA… and the evolving industry understanding about the meaning and implications of the Code.” In other words, the Code is technically in effect but it’s in such a state of flux that it would be unfair to punish an adviser for not complying with it.</p>
<p><strong>Wood for the trees</strong></p>
<p>Putting aside the shortcomings of the wording used in the Code and its related guidance, the principles and themes of the Code make it clear what FASEA is trying to achieve. FASEA wants advisers to put their clients’ interests first and manage any potential <a href="https://www.thefoldlegal.com.au/blog/when-can-financial-advisers-recommend-a-switch-to-an-in-house-product">conflicts of interests</a> so that they don’t result in poor client outcomes like those exposed by the Royal Commission.</p>
<p>Sound familiar? It should. The Corporations Act already requires advisers to:</p>
<ul class="li-listing">
<li>Avoid conflicted remuneration;</li>
<li>Prioritise their client’s interests;</li>
<li>Act honestly and fairly;</li>
<li>Provide appropriate advice; and</li>
<li>Act in the best interests of each client.</li>
</ul>
<p>If you’re already doing (and adequately documenting) these things then you shouldn’t be worried about complying with the Code.</p>
<p><strong>What should I do now?</strong></p>
<p>You have until sometime in 2021 to adapt and enhance your compliance framework. You should use this time to:</p>
<ul class="li-listing">
<li>Educate your advisers about the Code;</li>
<li>Review your best interests duty policy and guidance;</li>
<li>Update your product replacement policy, paying particular attention to in-house or related-party products and services;</li>
<li>Review your referral arrangements, in particular the referral fees you <em>receive</em> for outbound referrals;</li>
<li>Review your SOA template and APL policy to ensure they don’t restrict advisers from complying with the Code;</li>
<li>Review your guidance on scoped/scaled advice to ensure that advisers are not inadvertently scoping out topics that a client needs advice on; and</li>
<li>Identify clients who have <u>not</u> yet provided clear consent to the fees that you receive.</li>
</ul>
<p><em><strong>By Simon Carrodus, Solicitor Director</strong></em></p>
]]></description>
                                            <content:encoded><![CDATA[<div id="attachment_60513" style="width: 660px" class="wp-caption alignleft"><img loading="lazy" decoding="async" aria-describedby="caption-attachment-60513" class="size-full wp-image-60513" src="https://adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg" alt="" width="650" height="350" srcset="https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650.jpg 650w, https://www.adviservoice.com.au/wp-content/uploads/2019/03/Carrodus-Simon-650-300x162.jpg 300w" sizes="auto, (max-width: 650px) 100vw, 650px" /><p id="caption-attachment-60513" class="wp-caption-text">Simon Carrodus</p></div>
<h3>We’re well into 2020 and the FASEA Code of Ethics (the Code) is currently in force. What should advisers and licensees be doing to make sure they comply with the Code?</h3>
<p>The Code came into effect on 1 January 2020. To make sure we’re all on the same page, I’ve answered some FAQs.</p>
<p><strong>I am an AFS licensee, does the Code apply to me?</strong></p>
<p>No. The Code applies to individuals not companies. But AFS licensees must take reasonable steps to ensure that their advisers comply with financial services laws and this includes the Code.</p>
<p><strong>Who is monitoring and enforcing the Code?</strong></p>
<p>AFS licensees are responsible for monitoring that their advisers comply with the Code. There is no external organisation monitoring the Code (yet).</p>
<p><strong>Isn’t there a Code monitoring body?</strong></p>
<p>Treasurer Josh Frydenberg has said that the Government will establish a new body to monitor the Code in early 2021, but this depends on the passage of legislation through Parliament. So in reality a Code monitoring body might be 18-24 months away.</p>
<p><strong>Isn’t ASIC monitoring and enforcing the Code?</strong></p>
<p>No. ASIC has made it clear that it is not their role to enforce the Code, but they do monitor AFS licensees.</p>
<p><strong>What about AFCA?</strong></p>
<p>AFCA made a statement that it will take a “measured and considered approach” to interpreting the Code’s provisions until a monitoring body is established. In other words, advisers have some breathing space.</p>
<p><strong>No man’s land</strong></p>
<p>Even though the Code came into effect on 1 January, the consultation process is not yet complete. In late 2019, FASEA conducted consultation sessions and accepted submissions from licensees, educational and industry bodies, advisers and consumer groups.</p>
<p>Many hoped this process would result in a re-drafted Code that would clarify the major points of confusion. Second on the wish list was a re-drafted guidance document. No such luck.</p>
<p>Instead, we have a “preliminary response to the submissions” (i.e. more guidance) and the promise of a “further detailed response” later in 2020.</p>
<p>We are in a phase of ‘facilitative compliance’. This means that no regulatory action will be taken provided licensees take reasonable steps to ensure their advisers comply with the Code. This means licensees should:</p>
<ul class="li-listing">
<li>Review their policies;</li>
<li>Update systems;</li>
<li>Provide training and guidance about the Code; and</li>
<li>Monitor their adviser’s compliance with the Code.</li>
</ul>
<p>This is in recognition of, as ASIC put it, “…the timing of the guidance provided by FASEA… and the evolving industry understanding about the meaning and implications of the Code.” In other words, the Code is technically in effect but it’s in such a state of flux that it would be unfair to punish an adviser for not complying with it.</p>
<p><strong>Wood for the trees</strong></p>
<p>Putting aside the shortcomings of the wording used in the Code and its related guidance, the principles and themes of the Code make it clear what FASEA is trying to achieve. FASEA wants advisers to put their clients’ interests first and manage any potential <a href="https://www.thefoldlegal.com.au/blog/when-can-financial-advisers-recommend-a-switch-to-an-in-house-product">conflicts of interests</a> so that they don’t result in poor client outcomes like those exposed by the Royal Commission.</p>
<p>Sound familiar? It should. The Corporations Act already requires advisers to:</p>
<ul class="li-listing">
<li>Avoid conflicted remuneration;</li>
<li>Prioritise their client’s interests;</li>
<li>Act honestly and fairly;</li>
<li>Provide appropriate advice; and</li>
<li>Act in the best interests of each client.</li>
</ul>
<p>If you’re already doing (and adequately documenting) these things then you shouldn’t be worried about complying with the Code.</p>
<p><strong>What should I do now?</strong></p>
<p>You have until sometime in 2021 to adapt and enhance your compliance framework. You should use this time to:</p>
<ul class="li-listing">
<li>Educate your advisers about the Code;</li>
<li>Review your best interests duty policy and guidance;</li>
<li>Update your product replacement policy, paying particular attention to in-house or related-party products and services;</li>
<li>Review your referral arrangements, in particular the referral fees you <em>receive</em> for outbound referrals;</li>
<li>Review your SOA template and APL policy to ensure they don’t restrict advisers from complying with the Code;</li>
<li>Review your guidance on scoped/scaled advice to ensure that advisers are not inadvertently scoping out topics that a client needs advice on; and</li>
<li>Identify clients who have <u>not</u> yet provided clear consent to the fees that you receive.</li>
</ul>
<p><em><strong>By Simon Carrodus, Solicitor Director</strong></em></p>
<p>The post <a href="https://www.adviservoice.com.au/2020/02/fasea-code-of-ethics-what-you-need-to-know/">FASEA Code of Ethics – what you need to know</a> appeared first on <a href="https://www.adviservoice.com.au">AdviserVoice</a>.</p>
]]></content:encoded>
                                    <wfw:commentRss>https://www.adviservoice.com.au/2020/02/fasea-code-of-ethics-what-you-need-to-know/feed/</wfw:commentRss>
                <slash:comments>0</slash:comments>                            </item>
            </channel>
</rss>