For AFS Licensees
AFSL cyber security is more than antivirus and MFA
ASIC treats cyber and technology risk as part of an AFS licensee's general obligations under the Corporations Act. Cleverer helps you keep the safeguards, training and evidence that show how you're managing it.
The obligation
Why this matters for an AFS licensee
An AFS licence carries general obligations under section 912A of the Corporations Act, including a duty to have adequate risk management systems and to provide services efficiently, honestly and fairly. ASIC's Regulatory Guide 104 sets out what it looks for when assessing those obligations, and increasingly reads cyber and technology risk into them.
In ASIC v FIIG Securities Limited [2026] FCA 92, the Federal Court ordered an AFS licensee to pay a civil penalty for cyber security failures. It was the first case of its kind brought under the general licensee obligations in section 912A, rather than a standalone cyber rule. The judgment turned on that one licensee's own facts, so it isn't a checklist every licensee must copy. But the direction of travel is clear: ASIC now treats cyber and technology risk governance as part of running a licence properly, not as a separate technical add-on.
Coverage
What Cleverer helps you demonstrate
-
Governance and responsibility
Who owns cyber and technology risk, and how decisions and reviews are recorded.
-
Cyber safeguards
Core controls such as multi-factor authentication, endpoint protection, access control and backups, with their current state visible.
-
Staff awareness and training
Training assigned, completed and reviewed, including recognition of training your team already holds.
-
Third-party and provider oversight
Visibility over the suppliers and outsourced services that touch your systems and data.
-
Incident preparedness
A plan for identifying, responding to and reporting cyber incidents, kept current rather than filed away.
-
Evidence and review
Dated evidence, review history and remediation, not a one-off attestation.
The difference
One safeguard. More than one obligation.
Multi-factor authentication is one organisational safeguard. In Cleverer, the same control, the same evidence and the same review history can contribute to both your Privacy Act / Australian Privacy Principles obligations and your AFSL Cyber & Technology Risk obligation.
- 13 of 22 AFSL-mapped safeguards that also serve a Privacy Act / APP obligation
You don't stand up a second MFA control, a second policy and a second evidence trail because a different obligation asks about it. You operate the safeguard once. Cleverer shows how it counts toward each obligation that applies to you.
Scope
What Cleverer does not do
Cleverer records and evidences safeguards that map to Cleverer's reading of the cyber and technology dimension of the AFS licensee general obligations. It does not determine whether you meet them.
Cleverer does not manage your whole AFS licence. It has nothing to do with:
- advice conduct and the best interests duty
- adviser competence and training under RG 105
- conflicts of interest
- design and distribution obligations
- disclosure documents (FSG, PDS, SOA)
- ASIC's breach-reporting regime for reportable situations under RG 78 (a different regime to the Privacy Act notifiable data breach scheme, which Cleverer does support)
- AFCA membership
- professional indemnity insurance
- financial requirements
- other licence conditions unrelated to cyber and technology risk
Cleverer does not replace legal or compliance advice about whether your licence obligations are met.
Proving it
The difference between having a control and proving it
Saying a control exists is one sentence. Showing what was required, who was responsible, what safeguard operated, what evidence exists, when it was last reviewed or tested, what failed and what was remediated is a different exercise entirely. Cleverer is built for the second one.
Fit
Who this is for
- AFS licence holders managing their own safeguards.
- Authorised representatives who need to show their licensee what's in place. An authorised representative doesn't hold an AFSL directly, but their conduct and controls flow up to the licensee that authorises them.
- Financial advice and wealth management practices.
- Investment and corporate advisory firms.
- Other financial services businesses operating under AFSL Cyber & Technology Risk obligations.
If your practice provides financial advice, see how Cleverer's financial planning industry page covers the RI Advice precedent in detail.