In brief

On 10 October 2025, ASIC published findings from its review conducted on the use of offshore services providers (OSPs) by financial advice licensees and responsible entities (REs).

The review into the use of OSPs found a number of weaknesses in licensees' governance and risk management, with some entities relying too heavily on OSPs to provide services without adequate supervision or compliance frameworks in place. In particular, the review focused on technology, data sharing and privacy, with ASIC identifying risks relating to control, protection of sensitive data, and operational disruptions that could result in harm to businesses and consumers.

Given that Australian financial services (AFS) licensees retain ultimate responsibility (and liability) for the operation of their financial services businesses, it is critical that businesses consider ASIC's recommendations and take steps to independently review the performance and suitability of their OSPs. As ASIC Commissioner Alan Kirkland said, "Advice licensees and REs can outsource services but they cannot outsource their fundamental obligations."

Key takeaways

  • ASIC reviewed the use of OSPs by financial advice licensees and REs, finding several deficiencies in terms of governance and risk management which pose harm to investors.
  • The review found that a reliance on OSPs can result in licensees neglecting their responsibilities, resulting in harm to consumers, investors and financial services businesses.
  • Licensees and REs must take proactive action to review their OSP arrangements and governance frameworks in order to ensure that due skill and care are taken in choosing and maintaining suitable service providers.

 

In more detail

ASIC reviewed how financial advice licensees and REs, and their representatives, use OSPs through themselves or intermediary businesses. Their investigation focused on the adequacy of risk management systems and the possibility of consumers and financial services businesses being put at risk through lack of oversight and monitoring. Several key weaknesses were found in the use of OSPs, posing harm to investors and leading ASIC to call for stronger governance and risk management by AFS licensees.

AFS licensee obligations

Among other general obligations imposed by the Corporations Act 2001 (Cth) ("Act") and associated regulations, AFS licensees must:

Do all things necessary to ensure that the financial services covered by their licence are provided efficiently, honestly and fairly

  • Comply with their licence conditions
  • Comply with the financial services laws
  • Establish and maintain adequate risk management systems
  • Have adequate financial, technological and human resources to provide the financial services covered by their licence and to carry out supervisory arrangements

 

Outsourcing functions

AFS licensees who have financial advice practices frequently outsource overseas services such as financial planning assistants (for example client data entry and product research services), paraplanning services, insurance application and document support, and client communication (such as client situation updates or business updates). Similarly, REs also often offshore certain services relating to managed investment schemes, including management and oversight of investment process and administration of fund's portfolio, custody, fund administration and transaction processing services.

While outsourcing certain services is common and accepted within the Australian financial services industry, it is critical for AFS licensees to remember that the responsibility to comply with the obligations on their licence cannot be delegated out. Where an AFS licensee fails to comply with its obligations for any reason, the liability arising out of such failure rests with the licensee despite any outsourcing arrangement.

In order to strengthen their compliance mechanisms, when considering and reviewing service providers for outsourced serviced, AFS licensees must:

  • Have measures in place to ensure due skill and care is taken in choosing suitable service providers
  • Actively monitor the ongoing performance of service providers and consider whether they remain suitable
  • Routinely review that service providers are adhering to the requirements of service level agreements
  • Appropriately deal with any actions by service providers that breach service level agreements or the AFS licensees' obligations

This is important for all service providers, however is particularly vital for service providers from offshore jurisdictions that may have differing, conflicting or weaker compliance frameworks to those required in Australia. Failing to adequately supervise outsourced functions may lead to significant detrimental effects on the licensee and consumers, with ASIC noting that more critical the outsourced function, the greater the risk. Non-compliance with an AFS licensee's obligations can result in a range of consequences including administrative action, civil and criminal penalties, and reputational damage.

ASIC's findings

ASIC reviewed 10 licensees with financial advice businesses as well as a total of 40 REs over two stages. The financial services regulator identified the following risks arising from the use of OSPs by financial advice licensees and REs:

  • Risk of loss of control over some outsourced tasks or functions that can impede a licensee's or RE's ability to protect the confidentiality of its own and client information
  • Risks related to data and technology, particularly protection of client information, because OSPs subject to foreign government laws may have to comply with directions that conflict with Australian laws or may lose control over, or access to, an RE's or AFS licensee's data
  • Risks related to the effective detection and management of a data breach or cyber incident for an Australian business
  • Risk of operational disruption to the service that can harm consumers and market participants (with ASIC flagging that offshore infrastructure may be less reliable than that in Australia, resulting in disruptions to information technology services)
  • Risk of a licensee or RE losing control over the people and processes dealing with outsourced business functions, which may pose challenges to the effectiveness of supervisory regimes and systems

Notably for financial advice licensees, ASIC flagged "most of the advice licensees reviewed did not have adequate arrangements in place". The licensees reviewed did not have sufficient frameworks for the assessment, appointment and ongoing monitoring of offshore outsourced services used by their representatives, but instead relied on the representative to ensure risks are managed appropriately.

For REs, ASIC found that the sophistication of risk management services varied significantly, often depending on the size of the RE's business. ASIC noted that the REs reviewed generally maintained "appropriate risk management systems", highlighting the following areas for improvement:

  • Implementing comprehensive initial and ongoing due diligence processes for choosing and monitoring OSPs
  • Ensuring clearly defined metrics in service level agreements
  • Monitoring the ongoing performance of OSPs
  • Maintaining the necessary resources and skills for monitoring outsourced activities
  • Implementing mechanisms for dealing with breaches of service level agreements by OSPs
  • Enhancing cyber security and resilience

For both financial advice licensees and REs, ASIC found that the degree of sophistication of risk management practices varied significantly.

Next steps

Licensees should review their governance and risk management frameworks and consider how the findings from ASIC's reports apply to their businesses, particularly where they are engaging with service providers and OSPs. Their practices and internal policies should be updated to align with recommendations from ASIC's reports and the relevant regulatory guides (RG 104, RG 132 and RG 259). In particular, where AFS licensees rely on OSPs, they should conduct their due diligence and put in place mechanisms to ensure that suitable service providers are being used. As ASIC's review reminds us, while the provision of services can be delegated out, the responsibility rests on the licensee to ensure it is complying with its obligations.

Please reach out to us should you have any questions on how these recommendations or findings apply to your business.

* * * * *

Andy Thamsirisup, Associate, has contributed to this legal update.

Explore More Insight