Home › Guides › The IT Side of AFSL Compliance
The IT Side of AFSL Compliance
Holding an Australian Financial Services Licence comes with IT obligations most licensees only discover during an audit, a breach, or a professional indemnity renewal. Here's what ASIC actually expects on cybersecurity, email retention and monitoring, translated into controls a small firm can run.
An AFS licensee's general obligations under s912A of the Corporations Act include adequate risk management systems — and since ASIC v RI Advice (2022), the Federal Court has confirmed that inadequate cybersecurity breaches them.
In practice that means documented cyber controls, multi-factor authentication, monitored and patched systems, tested backups, and email preserved in a tamper-evident archive — with the convention across most AFSL record-keeping obligations being seven years.
Most AFSL compliance effort goes into the visible obligations: advice documentation, disclosure, breach registers, CPD. The IT obligations sit underneath all of them and get far less attention, right up until a mailbox is compromised, an insurer asks for your MFA evidence, or a client dispute needs an email thread from six years ago that someone deleted.
This guide covers the three IT questions we get asked most by licensees and their compliance consultants: what ASIC actually expects on cybersecurity, what has to be retained and for how long, and what a proportionate technology stack looks like for a small Perth firm. It's written from the IT side. It complements your compliance adviser, it doesn't replace them.
Cybersecurity is a licence obligation — RI Advice settled that
For years, cybersecurity guidance for licensees was just that: guidance. That changed in May 2022 with ASIC v RI Advice Group. After a series of cyber incidents across RI Advice's authorised representative network between 2014 and 2020 (including a compromised practice where an intruder sat inside systems for months with access to thousands of clients' personal information), the Federal Court declared that RI Advice had breached its general obligations under s912A(1)(a) and (h) of the Corporations Act.
The two obligations that did the work:
- s912A(1)(a) — do all things necessary to ensure services are provided efficiently, honestly and fairly. The Court accepted that operating with inadequate cyber protections falls short of "efficiently and fairly".
- s912A(1)(h) — have adequate risk management systems. Cyber risk is a business risk like any other, and a risk management system that ignores it is not adequate.
RI Advice was ordered to pay $750,000 towards ASIC's costs and to engage an external cybersecurity expert to verify remediation. No fine was needed to make the point: cybersecurity is now a condition of holding the licence, and "adequate" is assessed against the nature, scale and complexity of your business — a two-adviser practice isn't held to a bank's standard, but it is held to a standard.
What the obligations translate to in IT terms
Here's the mapping we use when a licensee or their compliance consultant asks what "adequate" looks like on the technology side:
| Obligation | What it means for your IT |
|---|---|
| Adequate risk management (s912A(1)(h)) | A written cyber policy proportionate to your size, controls aligned to a recognised baseline such as the Essential Eight, and evidence the controls actually operate |
| Efficiently, honestly and fairly (s912A(1)(a)) | Resilient systems, an incident response plan you've actually read, and the ability to keep serving clients through an outage or breach |
| Record keeping (financial and advice records) | Email and documents preserved for seven years in storage that users can't quietly delete from — retention by policy, not by goodwill |
| Reportable situations regime (from Oct 2021) | You can't report a breach you can't see: logging, alerting and monitoring good enough to detect incidents, and forensics good enough to describe them within the 30-day reporting window |
| Privacy Act & Notifiable Data Breaches scheme | Breach detection and a response process — assess suspected breaches promptly and notify the OAIC and affected individuals where serious harm is likely |
| Outsourcing due diligence | Your IT provider is part of your risk system — document who they are, what they can access, and how they're vetted (yes, this includes us) |
Email retention: the obligation everyone underestimates
Advice happens over email. Instructions happen over email. Complaints, variations, disclosures — email. Which means email is a business record, and most AFSL record-keeping obligations converge on a seven-year retention period.
The trap is that "we keep everything in Outlook" is not retention. Mail in a user's mailbox can be deleted by that user, purged automatically, or lost when a departing adviser's account is closed. What a regulator, court or professional indemnity insurer asks for is mail preserved by policy — where deletion by the user doesn't actually remove the record.
What compliant email retention looks like on Microsoft 365
The stack most small licensees end up on
- Purview retention policy — all mail retained for seven years, including items users delete, enforced tenant-wide rather than per-mailbox.
- Litigation hold on principals' and advisers' mailboxes, so nothing is purged while a dispute or investigation is open.
- Audit logging turned on and retained — who accessed which mailbox, when, from where. This is also your first forensic source after a compromise.
- Departing-staff process — mailboxes converted and preserved, not deleted, when an adviser leaves.
- Supervision tooling where your obligations include monitoring representatives' communications — layered on top of the archive, not instead of it.
If your firm is on Business Standard licences, note that most of the above needs the compliance features in higher tiers — the Premium vs Standard breakdown covers what each tier actually includes.
Where CPS 234 fits (and where it doesn't)
AFSL ≠ APRA
CPS 234 is an APRA prudential standard for information security. It applies to APRA-regulated entities — banks, insurers, superannuation trustees — not to AFSL holders as such. If you hold an AFSL and nothing else, ASIC's regime is yours, not CPS 234.
But CPS 234 still reaches small firms contractually: an APRA-regulated entity whose information assets you manage must satisfy itself about your security controls. If a fund, insurer or bank is upstream of your business, expect their CPS 234 flow-down questionnaire — and treat it as the same evidence exercise as everything else on this page.
A proportionate stack for a small licensee
For a Perth advice practice, broker or fund services firm of two to twenty staff, "adequate" typically assembles from parts you mostly already pay for:
- Identity first — MFA enforced on every account with Conditional Access policies behind it. Compromised mailboxes remain the most common incident we see in financial services, and MFA is the control that would have prevented most of them.
- Managed, patched devices — endpoints enrolled in Intune, operating systems and applications patched on a schedule you can evidence, unsupported software removed.
- Endpoint detection and response — antivirus alone doesn't meet anyone's definition of adequate in 2026. EDR with someone actually watching the alerts.
- Email retention — the Purview configuration above, plus anti-phishing controls in front of the mailbox.
- Backups that restore — M365 data backed up independently, immutable copies, and restore tests on the calendar with the results filed as evidence.
- A one-page incident response plan — who isolates what, who calls the insurer, who assesses notification obligations, and where the evidence goes. Written before the bad day, not during it.
- The paper trail — a short cyber policy, a risk register entry, and a folder of operating evidence: MFA reports, patch reports, restore tests, phishing simulation results. This folder is also most of what a cyber insurance application asks for.
Aligning that stack to Essential Eight Maturity Level One gives you a recognised, defensible baseline to point at when anyone — ASIC, an insurer, a fund upstream — asks what standard you operate to. Our Essential 8 uplift service covers the gap assessment and implementation, and the financial services page covers how we work with licensees and their compliance advisers more broadly.
Where to start
If you do nothing else this quarter: turn on MFA everywhere, put a seven-year retention policy on email, and test one backup restore. Those three controls close the gaps behind the majority of the incidents that end up as reportable situations, and all three produce evidence you can hand to whoever asks next.
Security and compliance work is charged at $180/hr ex GST, one-hour minimum, then 30-minute increments, with no call-out fee in metro Perth. Larger uplifts are quoted as fixed scope before starting, and we're comfortable working alongside your compliance consultant — they define the obligation, we implement and evidence the control.
AFSL IT Questions, Answered
What licensees and their compliance consultants ask us.
Do AFSL holders have cybersecurity obligations?
Yes. The general obligations under s912A of the Corporations Act include providing services efficiently, honestly and fairly, and having adequate risk management systems. In ASIC v RI Advice (Federal Court, 2022) the Court found that inadequate cybersecurity risk management breached those obligations — establishing cybersecurity as a licence obligation, not just good practice.
How long does an AFSL holder need to keep emails and records?
Most AFSL record-keeping obligations converge on seven years — financial records and records relating to personal advice both carry seven-year retention periods. Because instructions and advice routinely happen over email, the practical standard is a tamper-evident email archive covering at least seven years, rather than relying on individual mailboxes where messages can be deleted.
Does CPS 234 apply to AFSL holders?
Not directly — CPS 234 is an APRA standard for banks, insurers and super trustees, while AFSL holders answer to ASIC. It reaches smaller firms contractually: if an APRA-regulated entity relies on you to manage its information assets, its CPS 234 obligations arrive in your contract as a security schedule and evidence requests.
What did ASIC v RI Advice decide?
In May 2022 the Federal Court declared RI Advice Group breached s912A(1)(a) and (h) by failing to have adequate cybersecurity risk management across its network, after incidents between 2014 and 2020. It was ordered to pay $750,000 towards ASIC's costs and engage an external cybersecurity expert. It was the first Australian case establishing cybersecurity as an AFSL obligation.
Do small AFS licensees need a documented cyber security policy?
In practice, yes. "Adequate" is judged against your size and complexity, but undocumented controls are very hard to defend. A small licensee should be able to produce a short written policy covering access, MFA, patching, backups, email retention and incident response — plus evidence the controls operate, like MFA reports and restore-test records.
What software do AFSL firms use for email retention and surveillance?
Most small and mid-sized licensees run it on Microsoft 365: Purview retention policies keeping all mail for the retention period, litigation hold on key mailboxes, and audit logging. Firms with representative-monitoring obligations add a supervision or archiving tool on top. The key distinction is mail preserved by policy versus mail sitting deletable in user mailboxes.
Related
Where to go next, depending on what prompted the question.
Been asked to evidence your IT controls?
We'll tell you where you stand against your obligations, in writing, with a costed gap list — and we're comfortable working directly with your compliance consultant.
Support Perth IT Pty Ltd · Perth, Western Australia · $180/hr ex GST, one-hour minimum, then 30-minute increments · No call-out fee in metro Perth. This guide is general information about IT controls, not legal or compliance advice — obligations vary with your licence conditions and authorisations, so confirm specifics with your compliance consultant or lawyer.