The regulatory paper trail AFSL-holding clients cannot afford to ignore

ASIC has commenced three cyber enforcement actions against AFSL holders since 2020. The second produced Australia's first civil penalties for cyber failures under general AFSL obligations. The third is still in court. The APRA-ASIC roundtable published today names the same governance gaps all three cases turned on

The regulatory paper trail AFSL-holding clients cannot afford to ignore

Cyber

By Roxanne Libatique

Brokers whose books include financial advisers, mortgage brokers, investment managers, or any other holder of an Australian Financial Services Licence (AFSL) are operating in a market where cyber governance failure has a documented court history, a personal liability regime, and a regulatory paper trail that names the exact gaps regulators will test. The joint APRA-ASIC roundtable publication released August 27 is the most recent layer in that stack – but for brokers, the more useful frame is the enforcement sequence it sits inside, and what it means for the financial lines cover those clients carry.

The Australian Prudential Regulation Authority (APRA) and the Australian Securities and Investments Commission (ASIC) convened nine roundtables across June and July 2026, drawing more than 600 attendees from over 380 entities including insurers, banks, financial advisers, and mortgage brokers. The paper’s headline finding – that boards are making critical governance decisions for the first time during live AI-accelerated incidents – describes the precise failure mode ASIC has now pursued three times in court.

The enforcement pattern that defines the risk

ASIC has commenced three cyber-related enforcement proceedings against AFSL holders since 2020, all alleging breaches of section 912A of the Corporations Act, reflecting a settled regulatory position that cyber security is a core governance obligation, not a technical matter, and that licensees are accountable across their authorised representative networks. The three cases define a clear trajectory. RI Advice Group was ordered in 2022 to implement a cyber security programme across its authorised representative network. FIIG Securities was ordered in February 2026 to pay $2.5 million in civil penalties – plus $500,000 in costs – after the Federal Court found it had failed to maintain an adequate incident response plan, lacked mandatory cyber security awareness training, and had sustained patching and multi-factor authentication failures over an extended period. This was the first time civil penalties had been imposed for cyber security failures under general AFSL obligations.

The third action is ongoing. ASIC filed proceedings in the NSW Supreme Court in July 2025 alleging Fortnum Private Wealth failed to have adequate policies, frameworks, systems, and controls to deal with cyber security risks across its authorised representative network, with several ARs experiencing cyber incidents – including a major breach that saw data relating to more than 9,000 clients published on the dark web. Fortnum CEO Matt Brown said the company strongly refutes ASIC’s allegations and will vigorously defend its position. He said the main incident involved legacy data held by an authorised advisory practice for record-keeping purposes, while regulatory reporting and client remediation were completed in a timely manner, according to Information Age. The proceedings remain before the courts.

The APRA-ASIC roundtable paper reinforces the same standard, stating that governance and escalation weaknesses are as disruptive as technical control failures and that regulators expect evidence of pre-established decision frameworks before an incident occurs – not during one.

FAR adds personal exposure above entity-level penalties

For insurers, RSE licensees and other APRA-regulated entities subject to the Financial Accountability Regime (FAR), the governance findings carry a further personal accountability dimension beyond entity-level regulatory exposure – a distinction relevant to D&O and PI coverage conversations. FAR has applied to general insurers, life companies, and RSE licensees since March 2025. It requires accountable persons to take reasonable steps to prevent matters from arising that could adversely affect an entity’s prudential standing or prudential reputation, as well as to prevent material contraventions of specified laws.

Under FAR, accountable persons can face personal civil penalty exposure for certain contraventions, adding an individual accountability dimension to the regulatory risks faced by covered entities. MinterEllison has warned that many FAR accountability maps may not have kept pace with the rapid adoption of AI, creating potential gaps in how responsibility for AI-related risks is allocated. The firm has also said FAR’s existing principles-based obligations extend to AI governance, including the need for clear accountability for AI systems and their associated risks.

In ASIC v Bekier [2026] FCA 196, Justice Lee considered the implications of directors using AI to navigate and process board materials, emphasising that AI cannot replace directors’ own critical assessment and independent judgment. Legal commentary on the judgment has highlighted the importance of clear governance frameworks for AI use, reinforcing that directors remain personally responsible for complying with their duty of care and diligence when using AI-assisted information.

What the D&O market is pricing and what brokers should check

These signals have reached D&O underwriters. According to Bellrock Advisory’s D&O market update for January 2026, the Australian D&O market experienced premium reductions of 15% to 40% in 2025, but a shift toward shareholder derivative action claims is anticipated for 2026, driven by governance and compliance issues. Bellrock noted that insurers may reduce derivative action cover and apply smaller sub-limits for D&Os of companies that have faced prosecution by ASIC, the Australian Competition & Consumer Commission (ACCC), APRA, and the Australian Transaction Reports and Analysis Centre (AUSTRAC).

Allianz Commercial’s D&O Insights 2026 identified cyber oversight failure as an accelerating category of claims globally. Alfred Mora, chief underwriter, financial lines, Germany and Switzerland at Allianz Commercial, said: “More and more we see companies and their investors holding board members responsible for cyber incidents. The threshold for asserting internal liability is falling while the number of cyberattacks with a systemic impact has increased. Cyber risk must be a top priority today – simply delegating it is not enough.”

Those three threads – the enforcement timeline, FAR personal penalties, and D&O market repricing – converge on three concrete renewal questions for any AFSL-holding client. First, whether D&O sub-limits account for ASIC derivative action exposure in an escalating enforcement environment, particularly for dealer groups with authorised representative networks where licensee liability extends beyond the firm’s own systems.

Second, whether cyber policies include dependent systems or contingent business interruption cover structured to named AI model and cloud providers, given the roundtable paper’s finding that common third-party dependencies can convert isolated incidents into sector-wide disruption. Marsh has found that 70% of organisations experienced at least one material third-party cyber incident in the past year, and contingent business interruption supply chain events accounted for 15% of large cyber insurance claims by value in the first half of 2025, up from 6% in 2024, according to Allianz Commercial’s large claims analysis. Third, whether the client’s governance documentation – incident response plans, AI policy frameworks, and board escalation protocols – is sufficient to meet the “demonstrably effective” standard ASIC applied in FIIG and signalled again in the roundtable paper.

ASIC Commissioner Simone Constant said: “Threat actors are exploiting frontier AI models to identify and exploit vulnerabilities that previously may have taken a team of professionals months to find. Australia’s financial system is only as resilient as its weakest link. Boards and executives must move beyond awareness and ensure their organisations have well-tested response plans.” For financial lines brokers, those three renewal questions are how that statement translates into a client conversation.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!