Preparing for an AFSL Audit: A Step-by-Step Guide

Key takeaways:

Understanding the AFSL Audit Process

AFSL audits are conducted by ASIC or by external compliance consultants engaged by your licensee. They assess whether your practice is meeting its general obligations under s912A including providing services efficiently honestly and fairly maintaining adequate resources and managing conflicts of interest.

Step 1 — Conduct a Pre-Audit File Review

Before any audit review a representative sample of your advice files. Check for completeness of SOAs evidence of best interests duty compliance fee disclosure adherence to RG 175 requirements and proper records of ongoing fee arrangements. AdviserCheck can automate this step.

We publish these guides free because consumers deserve independent information. A $5 donation helps cover the cost of keeping them accurate.

Secure payment via Stripe. No account needed.

Step 2 — Organise Compliance Documentation

Ensure your compliance manual policies and procedures are up to date. This includes your AFSL compliance framework, risk management plan, breach register, professional indemnity insurance certificate, and ongoing training records for all advisers.

Step 3 — Respond to Audit Findings

After the audit you may receive a findings letter identifying areas for improvement. Develop a remediation plan with clear timelines and responsibilities. Demonstrating proactive remediation is viewed favourably by ASIC compared to having no plan at all.

Understanding the AFSL Audit Process

An AFSL audit (also known as a compliance audit) is a review of your advice practice's compliance with its Australian Financial Services Licence conditions and relevant laws. Audits are typically conducted by an independent external auditor approved by ASIC. The audit scope covers advice documentation quality, compliance with the best interests duty (s961B) and appropriate advice duty (s961G), fee disclosure compliance, training and competence records, and complaints handling.

Audits are typically required annually for most licensees, though ASIC may require more frequent audits for licensees with a history of compliance issues. The auditor will review a sample of advice files, interview key personnel (including the responsible manager), and assess your compliance policies and procedures. The audit report is provided to the licensee and may be required to be lodged with ASIC.

Step-by-Step Audit Preparation

Step 1 (3-6 months before): Conduct a comprehensive internal file review of at least 20-30% of advice files. Identify any compliance gaps and remediate them. Step 2 (2-3 months before): Review your compliance policies and procedures manual to ensure it reflects current regulatory requirements. Update any outdated procedures. Step 3 (1-2 months before): Conduct training sessions with all advisers on common compliance issues and audit expectations.

Step 4 (1 month before): Prepare your compliance register, training records, complaints register, and PI insurance certificates. Ensure all adviser appointments are current and recorded correctly. Step 5 (2 weeks before): Conduct a pre-audit file review of the files you expect the auditor to examine. Step 6 (during the audit): Cooperate fully with the auditor, provide requested documents promptly, and address any preliminary findings constructively.

Common Audit Findings and How to Avoid Them

The most common AFSL audit findings include: inadequate SOA documentation (missing required warnings, insufficient disclosure of fees, inadequate basis for advice), failure to conduct adequate product research and comparison, incomplete client records (missing client information, outdated fact finds), and non-compliance with fee disclosure and renewal requirements.

To avoid these findings, implement a robust compliance framework with: standardised SOA templates that include all required disclosures, mandatory file review before advice documents are provided to clients, regular training on compliance obligations, and a documented process for monitoring and responding to regulatory changes. Engage an external compliance consultant for a pre-audit review if your internal resources are limited.

Frequently Asked Questions

How often are AFSL audits required?
Most licensees require an annual audit. ASIC may require more frequent audits (e.g., every 6 months) for licensees with compliance concerns or conditions on their licence. The audit frequency is specified in your AFSL conditions.

What happens if the audit identifies compliance issues?
The auditor will include the findings in their report. The licensee must address the issues within a specified timeframe. Serious or systemic issues may be reported to ASIC, which can take enforcement action including imposing additional licence conditions, suspending the licence, or banning individuals.

Can I conduct my own pre-audit file review?
Yes, and this is strongly recommended. A pre-audit review by an internal compliance team member or external consultant can identify and remediate issues before the formal audit. Document all remediation actions taken to demonstrate proactive compliance management.

What documents should I prepare for an AFSL audit?
Prepare: AFSL and authorised representative register, compliance policies and procedures manual, sample advice files (SOAs, ROAs, CARs), training records, complaints register, PI insurance certificate, fee disclosure records, and any previous audit reports.

Why ASIC Enforcement Matters for Your Advice Documents

Every penalty below is a documented failure mode — the kind of conduct that slipped past clients who had no independent check. In 2024-25 ASIC recorded 19 criminal convictions, 38 new civil proceedings, $104.1 million in imposed penalties and restrictions on 58 individuals or companies, with investigation activity up around 50%.

ASIC describes its own posture as increasingly that of a "more confident and ambitious regulator," and has flagged particular concern for business models pressuring superannuation savers with promises of better returns.

Sources: ASIC Annual Report 2025; ASIC Financial Advice Update, August 2025.

AdviserCheck's Analysis Pipeline

Unlike single-model tools, AdviserCheck runs a progressive consensus pipeline: one AI model performs the initial six-layer review, a second independently validates every finding, and a third must confirm it before anything reaches your report. Only findings all three models agree on reach the report — trading some recall for much higher precision. For professionals benchmarking automated compliance, that chain-of-verification design is the differentiator. See the output for yourself with a free check.

Interested in learning more about compliance tools for financial advice?

Try AdviserCheck Free

Last updated: 2026-09-12. This guide is for informational purposes only and does not constitute financial or legal advice.

By AdviserCheck Editorial Team

Privacy Policy · About · Editorial Policy