Skip to main content
Skip to content

AI compliance for financial services

AI compliance for Australian financial services, after ASIC's governance review

In October 2024 ASIC published its first review of AI use by 23 AFS and credit licensees. Use at that point was cautious and mostly supported human decisions. What ASIC flagged was the gap opening between the pace of adoption and the governance around it.

That review covered larger licensees. The same gap appears in a four-adviser practice, without the risk function that would notice it.

General information about Australian obligations, not legal, financial or compliance advice. Check the requirements that apply to your own licence.

Where AI meets an obligation
1
Client informationComplete financial and often health circumstances, held for people who expect discretion.
2
Record keepingAdvice files have to reflect what was actually considered and advised.
3
Accuracy and fairnessASIC noted nearly half the licensees reviewed had no policy considering consumer fairness or bias.
4
OutsourcingAn AI provider processing client information is a third party you remain answerable for.
ASIC REP 798
Privacy Act 1988
APP 11 reasonable steps
Sensitive information
The regulator's finding

What did ASIC find about AI governance in licensees?

That governance risked falling behind adoption. ASIC's Report 798, Beware the gap: Governance arrangements in the face of AI innovation, published 29 October 2024, reviewed how 23 AFS and credit licensees across retail banking, credit, general and life insurance and financial advice were using AI and how they governed it.

Use at the time was predominantly cautious and focused on supporting human decisions and improving efficiency. Around 60% of licensees intended to increase their AI use, with a shift toward more complex and opaque types including generative AI. Nearly half did not have policies that considered consumer fairness or bias.

Two things are worth taking from that for a smaller practice. The first is the title. ASIC's concern was not that licensees were using AI recklessly. It was that the governance was not keeping pace with a use curve that was about to steepen. That description fits a great many advice, broking and accounting-adjacent practices right now.

The second is what governance meant in that context: policies that consider the effect on consumers, oversight arrangements that someone owns, and an understanding of what the technology is actually doing. None of those require a risk committee.

Source: REP 798 Beware the gap: Governance arrangements in the face of AI innovation (ASIC, 29 October 2024). Obligations differ by licence type and activity. Check what applies to yours.

Scaled down

What that means for a practice with four advisers

A small licensee is not going to build a model risk framework, and does not need one. What it does need is to be able to answer the questions ASIC's review was really asking.

  1. Know what is in use, including in your software

    Meeting transcription, advice document drafting, file note generation, research assistants, and AI features inside your CRM, advice software or lending platform. The features you did not choose are the ones most likely to be missing from any list you already have.

  2. Decide what may go into each one

    Client financial circumstances, health information where insurance advice is involved, tax file numbers, and information about third parties such as a spouse or a beneficiary who never engaged you. Health information is sensitive information and carries a higher bar.

  3. Set the verification rule for advice work

    Anything that reaches a client, informs a recommendation or enters an advice file needs a named person who read it. A generated file note that nobody corrected is a record of what a system produced, not of what was discussed.

  4. Consider effect on clients, not just efficiency

    This is the point ASIC pressed on. If AI influences which clients get contacted, how a circumstance is characterised or what is recommended, the effect on the client is the thing to think about, and a record of having thought about it is the governance.

  5. Treat AI providers as outsourced service providers

    They receive client information. Assess them the way you assess anyone else who does, record the assessment, and give it a review date.

  6. Work out whether anything is a significant decision

    If a program makes or substantially informs a decision that could significantly affect a client's rights or interests, the privacy policy disclosure that commences on 10 December 2026 is in scope. For most small advice practices the answer is currently no, and being able to show why you concluded that is worth having.

Across the practice

Where AI turns up, and what each raises

Use What it raises
Client meeting transcriptionA full financial and sometimes medical picture captured by a third party. The fastest-spreading use and the least assessed.
File note generationThe note becomes the record of what was discussed and considered. Accuracy is not cosmetic here.
Advice document draftingClient circumstances leaving the practice, in a document that carries a recommendation.
Research and product comparisonConfident answers that may be out of date, incomplete or drawn from another market entirely.
Fact find summarisationBulk upload of the most sensitive document the practice holds.
Email and client correspondenceRoutine, high volume, and where client names most often reach an unapproved tool.
Insurance underwriting supportHealth information, which is sensitive information and generally requires consent to be handled.
Lead scoring or client prioritisationEffect on which clients receive service. This is the fairness question ASIC raised, at practice scale.
AI features inside advice or CRM softwareData handling changed by a vendor update with no decision behind it.
Example

Strong controls, no governance

Illustrative example, not a real customer

A four-adviser financial planning practice

The practice has MFA everywhere, managed endpoints, tested backups and a capable IT provider. Two advisers use an AI transcription tool for client meetings and one uses a general chatbot to draft advice document sections. The practice manager knows about the transcription tool and not about the chatbot.

Technically strong

  • MFA enforced across the practice
  • Endpoint protection and device management
  • Backups configured and restore-tested
  • Patching on a defined cycle

Ungoverned

  • No decision about which AI account may receive client information
  • The transcription provider was never assessed
  • Clients were not told a third party processes their meetings
  • No rule about who reviews a generated file note
  • Nothing recorded, so nothing to produce at renewal or audit

This is exactly the shape ASIC described: capable operation, and governance that has not caught up. The practice is not doing anything wrong. It just cannot show that it decided anything, and the technical controls it is proud of do not reach the thing that would matter. Cyber compliance for financial planning businesses.

The record

What a practice should be able to produce

  • The approved AI services, with who approved them and on what basis.
  • Provider assessments for every service that receives client information, with sources and dates.
  • What clients are told about AI in meetings and in advice preparation.
  • The verification rule for file notes, advice documents and client correspondence.
  • Your position on sensitive information, particularly where insurance advice involves health information.
  • A recorded conclusion on whether anything constitutes a significant automated or computer-assisted decision.
  • Staff acknowledgements and training completions, by name and date.
  • MFA and offboarding on every AI account, including any personal one you have allowed.
  • Incident records and breach assessments where client information was exposed.
  • A review date and an owner for the policy and the approved list.
Where a platform fits

Closing the gap ASIC named, at practice scale

The gap is between doing the work and being able to show it was governed. Cleverer holds the second part: decisions with owners, providers with review dates, training with names against it, and a chronology of when each happened.

Providers as third parties

The supplier register records data types received, whether sensitive or health information is involved, storage country, offshore disclosure, subprocessor visibility, contract status, an owner and a next review date.

AI risks with a treatment decision

The risk register carries a category, likelihood and impact, a derived rating band, an owner and a treatment. A risk that is accepted requires a written acceptance rather than silence.

Oversight that leaves a record

Manager and director attestation, management review and board reporting, so the oversight ASIC was asking about produces something dated rather than a recollection.

Cleverer is not a financial services compliance system and does not address licence obligations, advice quality or best interests duties. It is the cyber and privacy compliance record around them, and it does not guarantee legal compliance.

Has your governance kept up with your adoption?

That is the gap ASIC described, and it is measurable rather than a matter of opinion. The Readiness Check puts a position against policies, responsibilities, training, suppliers and evidence so you can see which side of it you are on.

FAQ

Questions from Australian financial services practices

Has ASIC issued rules about AI use by licensees?

ASIC published REP 798 in October 2024, a review of AI use and governance across 23 AFS and credit licensees. It is a review with findings and expectations rather than a new rulebook, and it sits alongside the obligations that already attach to a licence. Requirements vary by licence type and activity, so check what applies to yours.

Can an adviser use AI to transcribe client meetings?

Practices do, and it works well. What has to be settled first is which tool the practice approved, what the provider does with the audio and transcript, where it is processed, whether the client was told, and who reviews the file note before it becomes the record. Where insurance advice is involved the conversation may include health information, which is sensitive information and carries a higher bar.

Is an AI-generated file note acceptable?

As a draft an adviser reviews and corrects, it is documentation like any other. Filed unread, it is a record of what a system produced rather than what was discussed and considered, which is a problem in a file that has to reflect the advice process. The review is the control, and it needs to be a rule rather than a habit.

Does the small business exemption apply to an advice practice?

If annual turnover has never exceeded $3 million and no exception applies, potentially. It is worth checking rather than assuming, since turnover is measured once and a single year above the threshold removes it permanently, and tax file number obligations apply regardless. Most practices are better served working to the standard, because clients, licensees and insurers ask the same questions either way.

Do we need to tell clients we use AI?

A client whose meeting is being captured and processed by a third party is likely to expect to be told, and the conversation goes better when the practice has already decided what it says. Where the Privacy Act applies there is also a transparency dimension: the OAIC expects AI use to be reflected in privacy policies and collection notices. Deciding this once, at engagement, is easier than improvising it when a client asks.

What is the first thing a small practice should do?

Find out what is actually in use, including AI features inside your advice software and CRM. Everything else depends on that list, and in most practices it turns out to be longer than the principal expected.

© 2026 Cleverer. Human-layer cyber compliance for Australian businesses.