Skip to main content

Broker guide

ASIC Reportable Situations for Credit Licensees 2026

Check the ASIC reportable situations regime when a compliance incident occurs, including significance, investigation records and the reporting clock.

Published
Updated

ASIC reportable situations are incidents a credit licensee must notify to the Australian Securities and Investments Commission (ASIC) under the breach reporting regime. They cover significant breaches, likely significant breaches, certain investigations and serious misconduct. You must generally report within 30 calendar days of the relevant awareness trigger, even while the investigation continues.

As at October 2026, the investigation reporting threshold is more than 60 days. That threshold is separate from the usual 30-day deadline for reporting an identified reportable situation. ASIC’s current regime overview confirms the distinction.

Triage the Incident

Capture the original evidence and awareness dates before deciding whether an incident is reportable. Stop continuing harm where you can, and give the licensee’s compliance lead responsibility for the assessment. A broker working as a credit representative must escalate through their licensee’s incident process.

Record what happened in plain language, including the credit activity and the people involved. Keep the original application, messages and document versions. Separate observed facts from explanations that still need testing.

Use the incident record to capture these facts.

  • The legal obligation or licence condition potentially breached.
  • The first occurrence and whether the conduct is continuing.
  • Clients affected or likely to be affected.
  • Actual financial loss or other harm, and likely further harm.
  • Similar incidents in other files or under the same process.
  • Who first saw each piece of evidence and when they escalated it.
  • Actions to stop the conduct and the person responsible for investigating it.

Put the escalation roles and backup decision-maker in your mortgage broker compliance manual. A manager’s later review date must not replace an earlier relevant awareness date.

Two Fictional Incidents

In the first case, a broker mistypes a client’s employer postcode in an internal draft. The broker corrects it before anyone relies on it. No application contains the error, and the file review finds no similar errors or client harm.

The compliance lead still records the incident and checks whether any legal obligation was breached. A corrected internal typo, on these facts, doesn’t establish a reportable situation. If the wrong information reached the client or lender, that changes the assessment.

In the second case, a supervisor finds altered income figures in several applications. The figures conflict with the payslips clients supplied. The broker has continued submitting files after a warning.

Preserve both versions of every document and identify all potentially affected applications. Investigate who changed the figures, who relied on them and whether the conduct caused loss. Repeated misleading conduct can trigger deemed significance and may also amount to serious fraud.

Correction alone doesn’t decide either case. The deciding facts are the breached obligation, applicable reporting test and scope of the conduct.

Use the Dashboard for Industry Context

The ASIC reportable situations data dashboard helps you examine industry patterns, such as how breaches are detected and remediated. Use that aggregate context to inform monitoring and file reviews.

The dashboard isn’t your incident register or a status check for a particular submission. Your reportability decision rests on the incident evidence and current reporting tests. Keep submission history in the Regulatory Portal and your own records.

Apply the Reporting Tests

Apply the reportable situations regime by identifying the core obligation, then testing significance and the other reportable categories. Regulatory Guide 78: Breach reporting by AFS licensees and credit licensees explains the tests. Australian financial services (AFS) licensees have parallel obligations, but this assessment concerns an Australian credit licence.

Identify the Obligation and Reporting Category

A core obligation includes relevant general licensee obligations under section 47 of the National Consumer Credit Protection Act 2009 and specified credit-law obligations. Record the actual provision involved. An internal procedure can help meet an obligation, but breaching the procedure alone doesn’t establish a breach of the law.

A likely significant breach means the licensee or representative is no longer able to comply with a core obligation, and the resulting breach would be significant. Record the reason compliance is no longer possible. A general possibility that something could go wrong doesn’t satisfy that test.

Gross negligence and serious fraud during credit activities are additional reportable situations. They don’t require a separate significance assessment. Reportable investigations also have their own trigger.

Test Significance and Relief

Some breaches are deemed significant under section 50A(4). Examples include relevant offences, civil penalty provisions subject to exclusions, misleading or deceptive conduct and material client loss. Relevant National Credit Code requirements also have a deeming test.

For offences, the imprisonment threshold is three months or more where dishonesty is involved, or 12 months or more otherwise. A deemed significant breach doesn’t need to affect many clients. The absence of a complaint doesn’t remove reportability.

Where deeming doesn’t settle the answer, assess the number and frequency of similar breaches. Consider the effect on the licensee’s ability to conduct credit activities and what the breach reveals about inadequate compliance arrangements. Record the evidence and reasoning for every applicable factor under section 50A(5).

As at October 2026, ASIC’s targeted relief removes deeming for certain low-impact breaches. The broader relief concerns civil penalty and misleading-conduct breaches with all applicable conditions met.

  • The circumstances produce only one eligible situation or one eligible group, with no other reportable situation arising or likely to arise.
  • No more than 10 affected consumers are impacted or likely to be impacted. Joint clients on the specified joint credit arrangements count as one affected consumer.
  • Total actual or likely financial loss across consumers doesn’t exceed $1,000, counting loss even if it is later repaid.
  • The breach and necessary client remediation are completed within 60 days after the situation first occurred.

An eligible group involves the same or substantially similar conduct, apart from consumer identity and conduct date, within a period of no more than 60 days. Relief doesn’t erase other significance tests or serious misconduct. Keep evidence for each condition and reassess if more clients or loss emerge.

In the fictional postcode case, no legal breach is established on the stated facts. There’s no need to assume relief is the reason reporting isn’t required. In the altered-income case, repeated deliberate conduct can satisfy other reporting grounds despite correction or repayment.

Keep the Reporting Clocks Separate

The usual deadline is 30 calendar days after the licensee first knows, or is reckless about whether, reasonable grounds exist to believe a reportable situation arose. Record that trigger independently of the investigation’s completion and management approval. Waiting for a final loss figure or board meeting doesn’t restart the clock.

An investigation into a significant breach or likely significant breach becomes reportable if it continues for more than 60 days. If reasonable grounds for a reportable breach arise earlier, the usual reporting clock starts then. The investigation threshold doesn’t give you 60 days to delay reporting an identified breach.

If an investigation exceeds that threshold and later concludes that there are no reasonable grounds for a reportable breach, its outcome is also reportable. Record the separate outcome reporting deadline.

A limited 90-day reporting period can apply to a further situation with the same or substantially similar underlying circumstances as one already reported. Document the earlier report and why the conditions apply. Similarity to an unreported incident doesn’t establish that extension.

Keep separate dates for first occurrence, discovery, relevant awareness, investigation start, decision and submission. Name the person authorised to make the decision and retain their reasoning. That timeline lets a later reviewer reconstruct the deadline without treating the submission date as the awareness date.

Report and Remediate

Submit the required report through the ASIC Regulatory Portal and continue fixing the underlying failure. Your working record helps you prepare the prescribed form, track updates and demonstrate the decision. It doesn’t replace the portal submission.

Credit Licence Breach Reporting Template

Use this field list for your internal incident record. Complete the portal’s mandatory questions for the reporting category you select.

FieldWhat to record
Incident identityInternal reference, licensee name and licence number, responsible people and affected credit activities
Conduct and obligationPlain description, relevant legal provisions and representative details
TimelineFirst and last occurrence, awareness evidence, investigation dates, decision date and calculated reporting deadline
Reporting testSignificant or likely significant breach, investigation, gross negligence or serious fraud, with reasons and any relief assessment
ImpactAffected clients, incident count, actual and likely loss, complaints and ongoing exposure
Cause and correctionRoot cause, containment, process repairs and measures to prevent recurrence
Client responseNotifications, investigation outcomes, loss calculations, remediation payments and outstanding actions
Submission historyPortal event reference, submitted copy, confirmation, updates and correction reasons

ASIC’s submission instructions describe how to create and update an event.

  1. Create a reportable situation event under Transaction groups and give it a searchable title.
  2. Set access for the portal users connected to the licensee who need the event.
  3. Launch Submit/update reportable situation by licensee and complete the relevant questions.
  4. Save the submitted report and confirmation against the incident record.
  5. For later information, open the original event and submit an update where the update function remains available and the relevant fields are editable.

A submitted report can’t be corrected directly in the portal. RG 78.175-178 and Tables 13-14 distinguish updates from correction requests.

For a minor factual error, use an available update to note the error in the Describe the reportable situation field. The licensee must decide whether the error is minor.

For a material error or locked field, request a correction by emailing feedback.breach@asic.gov.au. Use that route if information changes after completion and updates are unavailable, or if a minor error can’t be noted through an update. Include the submission ID and submission date, with specific error details and the grounds for correction.

ASIC considers correction requests case by case. If approved, ASIC may remove the incorrect report from the portal view and ask you to submit corrected information. ASIC retains the original version in its systems.

A missing update button can also mean an earlier transaction remains unsubmitted. Complete that transaction first, as ASIC’s submission instructions explain. Keep each update or correction request’s reason and supporting evidence, alongside earlier submitted versions.

Continue Client Communication and Remediation

ASIC’s notify, investigate and remediate guidance applies to a defined subset of reportable situations. For credit licensees, the trigger requires affected credit assistance, a relevant breach or serious misconduct, suspected client loss and a suspected legally enforceable recovery right.

Where those duties apply, take reasonable steps to notify affected clients in writing within 30 days of the trigger. Start the investigation within that period too, and complete it as soon as reasonably practicable. The notice explains the conduct, possible client harm and what happens next.

Notify clients of the investigation outcome within 10 days of completion. Where recoverable loss is established, take reasonable steps to pay remediation equal to that loss within 30 days of completion. These actions can overlap with the ASIC reporting process.

Keep clients informed while you calculate loss or identify additional affected files. Record payments and outstanding cases, with an owner and next contact date. A complaint also needs its own internal dispute resolution process, even while the incident assessment continues.

Before closing the incident, reconcile the submission record with the client response and corrected process. Confirm that every affected file has an outcome, every required update is lodged and the prevention measure actually works. Assign any unfinished remediation to a named owner with a due date.

Check the policy behind your next scenario

Ask Bulma a lender policy question and inspect the source behind the answer.