For AFSL and ACL licensees, aggregators and networks
See the cyber governance position across your entire authorised network
Cleverer already helps a business manage its cyber governance: controls, training, policies, evidence, reviews and suppliers. We are building the next layer on top of that: one place for a licensee or aggregator to see how every practice in its network is tracking.
Set expectations. Track completion. Surface gaps. Keep the evidence.
Your network
482 practices. One view.
An illustration of a proposed network oversight view, built from the same governance data Cleverer already tracks inside each practice.
The oversight problem
How do you know what every practice is actually doing?
Every practice or representative in your network runs its own business. They use different IT providers. Their cyber maturity varies. Their policies, training records, supplier checks and evidence sit in different places, if they sit anywhere consistent at all.
-
Different providers
Each practice may run its own IT and security arrangements, set up on its own terms, with no shared record of what is actually in place.
-
Different maturity
Some practices are well ahead. Others have never been asked to demonstrate anything. Both look the same from head office until someone checks.
-
Scattered records
Policies, training completions and supplier reviews live wherever each practice happens to keep them, which usually means nowhere you can see.
The question becomes: how do you know which practices are actually meeting the standard you expect?
See every practice
One view of the whole network
The position of every practice, in one place: what is on track, what needs action, and what has gone quiet for too long.
- Training complete
- Annual review complete
- No high-risk actions
- Supplier review outstanding
- 2 evidence requests open
- 3 overdue controls
- Training incomplete
- Annual review overdue
- 1 high-risk issue
Showing 3 of 482 practices. Sorted by governance status.
An illustration of a proposed network oversight view. Practice names and figures are examples, not live data. "Governance" reflects required actions current against what has been assigned, not a legal compliance determination.
From network to practice
Drill into any practice on the list
A network view is only useful if it explains itself. Click into a practice and see exactly why it is red or amber, not just that it is.
Jones Advice
Action required58% of required actions current. Governance status last updated today.
- MFA confirmation, overdue 34 days
- Critical supplier review, overdue 12 days
- Cyber policy acknowledgement, overdue 5 days
- 2 of 6 staff have not completed Cyber Security Compliance Essentials
- Annual Cyber Governance Review, overdue
- 1 critical supplier flagged, no review actioned
- MFA confirmation evidence not yet uploaded
- 3d ago: reminder sent to the practice
- 1d ago: requirement escalated to network compliance
An illustration of a proposed practice-level view, extending the same governance record each Cleverer workspace already keeps.
Set the standard once
Define a requirement once. Cleverer takes it from there.
Set what every practice needs to do and by when. Cleverer distributes the work to each workspace and reports completion back to you.
- Confirm MFA
- Complete annual cyber review
- Review critical suppliers
- Complete staff training
- Acknowledge current cyber policy
- Upload required evidence
Sent to 482 practices. Each one sees the requirement inside its own Cleverer workspace.
Focus on the exceptions
You should not have to check 482 practices by hand
Cleverer surfaces the practices that need a decision, so attention goes where it is actually needed.
Why this matters
What happens when one practice gets it wrong?
If a practice in your network falls behind, the question is not only what they did. It is also what you required, what you knew, and what you did about it.
AFS and credit licensees carry a continuing obligation to monitor and supervise every representative and authorised practice, with a documented, risk-based approach and sufficient records of that supervision (RG 104; NCCP Act s47). ASIC's most recent review of outsourcing arrangements found licensees relying on their own representatives to manage third-party risk, while the licensee itself keeps ultimate responsibility.
Depending on what went wrong, that gap can turn into a reportable situation, an investigation, remediation costs, client harm, additional licence conditions, or, in serious cases, suspension or cancellation of the licence.
In February 2026, the Federal Court ordered FIIG Securities to pay a $2.5 million penalty plus $500,000 in costs over cyber security failures under its AFS licence, the first civil penalty of its kind. The failures were in FIIG's own systems, not an authorised representative's, but the case shows what cyber failures under an AFS licence can now cost.
Keep the evidence
A record of what happened, not just what should have
When someone later asks what happened, the history is already there: what was required, what was done, and what follow-up occurred.
- 12 Aug
Annual cyber review assigned
- 18 Aug
Practice acknowledged the requirement
- 21 Aug
MFA evidence uploaded
- 24 Aug
Supplier review completed
- 1 Sep
Training reminder issued automatically
- 8 Sep
Training remained overdue
- 12 Sep
Issue escalated to network compliance
- 15 Sep
Training completed
Built on the Cleverer platform
A layer on top, not a replacement underneath
Every practice keeps its own Cleverer workspace and runs its own business. The network layer sits above it, giving the licensee visibility without changing how each practice works day to day.
- Controls
- Training
- Policies
- Evidence
- Reviews
- Risks
- Suppliers
Get involved
Help shape how licensee oversight should work
Cleverer already manages cyber governance inside individual businesses. We are now working with a small number of financial services licensees and aggregators to shape the network oversight layer around real supervision requirements, not a generic dashboard.
- → Map your current oversight process
- → Configure your governance requirements
- → Identify what management needs to see
- → Build the reporting and escalation model around real workflows
- → Pilot with a small group of practices
Talk to us about a foundation partnership
A conversation about how your network runs today, and what you would need to see across it.