Client Advice Record Requirements Under Australian Law

Key takeaways:

What is a Client Advice Record?

A Client Advice Record (CAR) is a documentation format introduced under the Delivering Better Financial Outcomes (DBFO) reforms. It is designed to be more principles-based and flexible than a traditional Statement of Advice while still meeting all regulatory obligations.

Key Content Requirements

A CAR must clearly set out the advice given the basis for that advice and the fees and costs involved. It must be provided in clear understandable language. While it does not need to follow the rigid structure of a full SOA it must still evidence compliance with the best interests duty and appropriate advice obligation.

AdviserCheck puts no paywall on its guides. If you value independent consumer information, a small contribution helps us keep publishing.

Secure checkout via Stripe. No sign-up needed.

CAR vs SOA

The key difference between a CAR and an SOA is flexibility. A CAR can be more concise and tailored to the complexity of the advice. However simpler documentation does not mean lower compliance standards. The underlying obligations s961B s961G and fee disclosure remain the same regardless of the documentation format.

AdviserCheck Support

AdviserCheck architecture is document-type-agnostic. It checks documents against underlying regulatory obligations rather than assuming a fixed template format. This means it can analyse CARs SOAs and other advice documents using the same compliance framework.

Legal Framework for Client Advice Records

The legal framework for client advice records in Australia is established by multiple pieces of legislation and regulation. The Corporations Act 2001 sets out the core requirements for the content and provision of advice documents (including SOAs and CARs). The National Consumer Credit Protection Act 2009 applies additional requirements for credit advice records. The Privacy Act 1988 and Australian Privacy Principles govern the handling of client personal information.

ASIC Regulatory Guides provide detailed guidance on record-keeping expectations, including RG 175 (financial advice), RG 104 (licensing), and RG 146 (training). Licensees must be familiar with all applicable requirements and ensure their record-keeping systems comply. The complexity of the legal framework means licensees should seek legal advice when designing their record-keeping systems.

Specific Record-Keeping Obligations

Under section 912B of the Corporations Act, licensees must: keep all financial records and advice documents for at least 7 years, maintain records in a way that allows them to be properly audited, and ensure records are kept in English or in a form that can be readily translated. Advice records must include: all SOAs and CARs provided to clients, all product disclosure statements and other documents provided with the advice, all client instructions and communications, and records of any complaints or disputes.

Additional obligations include: maintaining a register of authorised representatives, keeping training records for all representatives, recording all fee disclosure statements and renewal notices, and retaining records of any compensation arrangements or PI insurance policies. These records must be available for inspection by ASIC on request.

Privacy and Data Security Requirements

Client advice records contain sensitive personal information and must be protected in accordance with the Australian Privacy Principles (APPs). Under APP 11, licensees must take reasonable steps to protect client information from misuse, interference, loss, and unauthorised access, modification, or disclosure. This includes implementing appropriate technical and organisational security measures.

Licensees must also comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If a data breach involving client personal information is likely to result in serious harm, the licensee must notify affected individuals and the Office of the Australian Information Commissioner (OAIC). Breach notification must include recommendations about the steps individuals should take in response to the breach.

Frequently Asked Questions

How long must client advice records be kept?
At least 7 years from the date the advice was provided. For ongoing advice arrangements, records should be kept for 7 years from the date the advice relationship ends. Some types of records (e.g., superannuation-related records) may need to be kept longer.

Can client advice records be stored electronically?
Yes. Electronic storage is permitted provided the records are secure, retrievable, and maintained in a format that is accessible for the required period. Electronic records should be backed up regularly and protected from loss, corruption, or unauthorised access.

What happens if a licensee loses client records?
Loss of client records can result in compliance issues during AFSL audits and may lead to ASIC enforcement action. Licensees must have appropriate data backup and disaster recovery processes. If records are lost due to a system failure or data breach, the licensee must notify affected clients and ASIC if required under the NDB scheme.

Do advisers need to keep their own copies of client records?
Licensees are responsible for record retention, but individual advisers may also keep copies for their own reference. However, the primary obligation rests with the licensee. Advisers changing licensees should ensure client records are properly transferred or retained by the original licensee.

Regulatory Context

Three reform waves frame modern Australian advice. Wave one: FOFA (2013), adding the best interests duty and prohibiting conflicted remuneration. Wave two: DBFO (2024-25), cutting red tape by abolishing the FDS requirement, streamlining fee consent and clarifying super deduction rules. Wave three is still moving: the Quality of Advice Review (2022) has driven draft Tranche 2 legislation (as at March 2025) covering simplified SOAs and a new class of adviser.

From Regulation to Plain English

This page explains the rule; AdviserCheck applies it. Our engine encodes FOFA obligations, the s961B best interests duty, RG 175 content standards and DBFO requirements into structured checks, then runs three independent AI models over your document. What reaches you is a short list of gaps that matter, each tied back to the obligation behind it. Put the rules to work on your own document — the first check is free.

Interested in learning more about compliance tools for financial advice?

Try AdviserCheck Free

Last updated: 2026-09-12. This guide is for informational purposes only and does not constitute financial or legal advice.

By AdviserCheck Editorial Team

Privacy Policy · About · Editorial Policy