Responding to multi-regulator issues

With Memoranda of Understanding in place between financial services regulators covering information sharing, and in response to increased expectations from the Government, cybersecurity breaches, AI rogue agents attacks and AML/CTF non-compliance by the same organisation can now result in multiple coordinated enforcement actions from ASIC, APRA and Austrac.

It is now accepted that “non-financial risk management” does in fact have significant financial and prudential implications, both for the company itself and its directors and officers.

Your systems need to prevent you from committing a breach but also to identify when a breach occurs so that you can report it to a regulator.

Less than 10 years ago CBA’s Chief Risk Officer told the Banking Royal Commission that “ the state of our systems that recorded and aggregated instances of misconduct … were not particularly advanced. They were not particularly well connected. The difficulty that the bank experienced was that various incidents of misconduct were recorded on different systems in different business units, without necessarily being all encompassed in a single business unit.”

The expectation now is that businesses have systems with high-quality data accessible to identify how, or to what extent, the entity as a whole is failing to comply with the law.

It is not uncommon now for APRA to impose licence conditions and capital requirements on a regulated entity when APRA says the entity “does not have a complete view of its regulatory obligations, material risks and key controls; there are material deficiencies in governance, accountability, compliance management, risk oversight and risk management capability; and key weaknesses have persisted despite several years of remediation activity”.

An Austrac investigation can lead to a penalty action as well as an ASIC action for breach of financial services licence obligations.

And for an APRA-regulated entity, additional APRA licence conditions and capital requirements can be imposed as well as ASIC actions against directors and executives.

Under the Financial Accountability Regime (previously the Banking Executive Accountability Regime) directors and executives are financially accountable for past deficiencies in relation to cybersecurity protection and enforcement of anti-money laundering laws.

Proving that you have addressed alleged deficiencies requires documenting decisions and maintaining records.

Otherwise, the company will face remediation and compliance costs as well as a penalty, and executives will risk losing bonuses and incentives.

And for a listed company, there is the risk of a shareholder class action.

If you found this article helpful, then subscribe to our news emails to keep up to date and look at our video courses for in-depth training. Use the search box at the top right of this page or the categories list on the right hand side of this page to check for other articles on the same or related matters.

Author: David Jacobson
Principal, Bright Corporate Law
Email:
About David Jacobson
The information contained in this article is not legal advice. It is not to be relied upon as a full statement of the law. You should seek professional advice for your specific needs and circumstances before acting or relying on any of the content.

 

Your Compliance Support Plan

We understand you need a cost-effective way to keep up to date with regulatory changes. Talk to us about our fixed price plans.