ASIC 2026 Enforcement Priorities: The Admin and Reporting Gaps That Will Trip Up AFSL Holders and Finance Businesses
ASIC's 2026 enforcement priorities target financial reporting misconduct, complaints handling failures, and pricing disclosure gaps. Here is what investigation-ready documentation actually looks like.
13 June 2026
ASIC has named its 2026 enforcement priorities. The list covers misleading pricing practices, weak private credit standards, financial reporting misconduct, poor complaints handling, and failures in super trustee service delivery.
What sits underneath each of those categories is an admin and documentation failure. The businesses that attract enforcement attention are the ones where the evidence of compliance was incomplete, the records were inconsistent, or the processes that were meant to be running were not actually running the way the compliance manual described.
That gap, between what a business says its process is and what the paper trail shows, is what regulators find.
What ASIC Has Flagged for 2026
ASIC’s 2026 enforcement priorities are clearer about operational failure modes than previous years. A few are worth unpacking for finance businesses and professional services firms.
Financial reporting misconduct is an explicit priority. ASIC and BDO have both flagged non-lodgement of financial reports and the quality of financial reporting as specific surveillance targets for 30 June 2026 financial reports. For businesses with lodgement obligations, the exposure covers both the accuracy of the numbers and the timeliness of lodgement. Reports that are filed late, or that do not meet the standards ASIC has already signalled it will be scrutinising, are in scope.
Misleading pricing practices covers the gap between what a business says it charges and what the client actually pays, including hidden fees, unclear disclosure, and pricing that varies in ways not adequately explained to the client. The admin failure here is usually a disclosure and file documentation problem.
Small-business creditor practices and claims and complaints handling are both areas where the evidence gap is particularly common. A business might have a complaints process. But if the complaints register is not current, the resolution timeframes are not documented, and there is no evidence that the process was actually followed for each complaint received, the process does not exist from a regulator’s perspective.
Private credit practices reflects ASIC’s concern about standards in a market segment that has grown quickly. Due diligence documentation, credit assessment records, and the evidence of suitability assessments are all in scope.
The Documentation Gap ASIC Finds Most Often
Across each of ASIC’s priority areas, the pattern is consistent. The business had a process. The process was not adequately documented. The documentation that existed was incomplete, inconsistent, or not current. When the regulator asked for evidence, the business could not produce it.
In a complaints handling context, that looks like: a complaints register that was not updated after each resolution; a log that shows the complaint was received but not how it was handled; missing sign-off on the remediation decision; no evidence that the required timeframe was met.
In a financial reporting context, it looks like: a lodgement that was two weeks late because the person responsible was on leave and the backup process was not documented; financial statements that were prepared but not lodged because the approvals process broke down.
In a pricing disclosure context, it looks like: a fee disclosure document that was not version-controlled, so the version the client received cannot be confirmed; a CRM record that shows the client was contacted but not what was disclosed.
These are ordinary operations gaps. The kind that accumulate when documentation is treated as a trailing task rather than a core part of the process.
What “Investigation-Ready” Actually Means in Practice
A business that is genuinely ready for an ASIC investigation can produce, on request, a specific set of records: the register of complaints and their resolutions, the lodgement log with dates and confirmation receipts, the fee disclosure documents matched to the client and the date, the credit assessment evidence for each facility, the correspondence trail that shows how each client communication was handled.
Getting to that state requires that someone owns those records on an ongoing basis. The records cannot be reconstructed at short notice from memory, spreadsheets, or email threads. They need to exist in a consistent format, kept current, and retrievable on demand.
For most finance businesses under AFSL obligations, the challenge is that the people best positioned to understand what the records need to contain, the advisers, brokers, and compliance officers, are also the people who carry the client-facing workload. The documentation work gets deferred. It catches up when it is already too late to be useful.
The Tasks That Fall Through
In practice, the documentation and evidence tasks that are most commonly underdone fall into a predictable set.
Complaints and disputes registers: Logging the complaint is usually done. Logging the resolution, the timeframe, the remediation, and the sign-off is done inconsistently.
Pricing and fee disclosure records: Creating the document is done. Saving the version the client received, matched to the client record and the date of disclosure, is done inconsistently.
Financial report lodgements: The report is prepared. The lodgement is confirmed. The confirmation receipt, matched to the period and the lodgement date, is stored inconsistently or not at all.
Credit assessment files: The assessment is run. The supporting evidence, the documents collected, the decision rationale, the version of the assessment document used, is assembled and filed inconsistently.
Monitoring and surveillance logs: Where businesses have obligations to monitor adviser conduct, product suitability, or credit performance, the log is often maintained at summary level rather than at the task level ASIC expects.
Each of these tasks is rules-based once the standard is defined. They require accuracy, consistency, and someone whose job it is to do them. They do not require a compliance officer or a senior adviser. They require a person with a clear process, a defined output standard, and time to do the work properly every week.
How to Redesign the Back Office Before 30 June
The 30 June 2026 financial reporting deadline creates a practical window. Between now and then, a finance business or professional services firm can audit its documentation against ASIC’s stated priorities and identify the specific gaps.
A useful audit asks four questions for each compliance-relevant task.
- Is the task being done at all?
- Is the output stored in a consistent, retrievable format?
- Is there someone specifically responsible for it, with time allocated to do it?
- If that person were absent, would someone else be able to find the records and continue the work?
A no to any of those questions is a gap. The gaps that matter most are the ones on ASIC’s 2026 list.
For businesses that identify significant gaps, the practical fix is to separate the documentation and record-keeping work from the advisory and client-facing work. The two require different skills and different time allocations. Putting both on the same person produces a predictable outcome: the advisory work happens, and the documentation gets compressed.
An offshore operations specialist with clear procedures, defined output standards, and a weekly review by a local compliance or senior staff member can own the documentation layer for a finance business at a fraction of the cost of adding a local compliance administrator. The review layer stays onshore. The production work moves to a specialist who can do it consistently, every week, without it competing with client-facing priorities.
The businesses that reach a 30 June audit ready are the ones that treated documentation as a production task, allocated it to someone with the right skill set and enough time, and reviewed it regularly rather than quarterly.
Want to map where your documentation gaps are before 30 June? A Connect Session identifies the specific records and registers that carry ASIC risk in your business, and works out what can be handled offshore with the right procedures in place. Book a Connect Session
Ready to build
your back office?
Book a Connect Session to talk through how a specialist role fits your business. You leave with a written Leverage Plan the same day.