RG 78 — Breach Reporting Obligations

Key takeaways:

When your adviser's licensee must tell ASIC, and how to use that as a consumer

What Is RG 78?

Regulatory Guide 78 interprets section 912D and Part 9.4AAA breach reporting for AFS licensees. It sets ASIC's expectations on identifying, investigating, deeming significance, lodging reports via ASIC Connect, notifying affected clients, and remediating. Our AFSL reporting guide covers the filing mechanics; this page focuses on the RG 78 significance test and what it signals to you.

ASIC updated RG 78 as industry adjusted to the expanded 2022 regime, which captured many more breaches and aligned with the Financial Accountability Regime. Targeted surveillances since have tested whether licensees lodge on time and remediate fairly.

The Significance Test in Plain English

A breach is reportable where the licensee has reasonable grounds to believe a financial services law was breached. It is deemed significant — 30-day report — where it has caused or is likely to cause substantial loss, indicates systemic conduct or resourcing failure, involves misleading or deceptive conduct, or represents a material departure from efficient, honest and fair services. Non-significant reportable breaches still require 90-day reports plus written records.

Examples relevant to advice include repeated fee-for-no-service, systemic SOA template errors omitting fees or risks, unregistered advice, failure to follow s961B inquiry steps across many files, and IT failures exposing client data. Isolated admin slips fixed promptly may still be reportable but not significant — the licensee must document why.

AdviserCheck puts no paywall on its guides. If you value independent consumer information, a small contribution helps us keep publishing.

Secure checkout via Stripe. No sign-up needed.

What Licensees Must Do

Under RG 78, licensees need breach registers, triage within days, investigation plans, and ASIC lodgement with root cause, client impact, remediation and prevention steps. Affected clients must generally be notified with an explanation, apology pathway, IDR contacts and AFCA rights. Records must be kept for five years and produced to ASIC on request.

Failure to report can itself draw infringement notices, licence conditions, or court action. For consumers, a licensee that reports promptly and remediates — fee refunds, file reviews, staff retraining — is demonstrating the compliance culture RG 104 requires. Evasiveness about breaches is the opposite signal.

How Consumers Can Use RG 78

You cannot search ASIC breach reports by adviser name, but you can ask direct questions: have you or your licensee lodged any breach reports relating to advice quality in the last two years, what was remediated, and am I affected? Check ASIC media releases and court actions, the Financial Advisers Register for bans and conditions, and AFCA determinations naming the licensee. Patterns of similar complaints suggest systemic issues that should have been breach-reported.

If you suffered loss from poor advice — for example undisclosed fees or unsuitable switching — complain in writing to the licensee's IDR team, then to AFCA within six years. Cite the breach-reporting duty in your complaint to prompt a proper file review. Keep your SOA, FSG, fee consents and statements as evidence.

Breach Reporting vs IDR: How They Differ

Consumers often confuse breach reporting with complaints. Breach reporting under RG 78 is a licensee-to-ASIC duty about systemic compliance failures, with 30-day and 90-day lodgement and five-year record keeping. Internal dispute resolution under RG 271 is a firm-to-consumer duty to resolve your individual complaint within 30 calendar days with reasons and AFCA rights. One targets market integrity, the other targets your remedy.

In practice they overlap: your IDR complaint about missing fees or unsuitable switching may reveal a template error affecting hundreds of clients, which then becomes breach-reportable. Cite both in your letter — request IDR resolution for yourself and ask whether the issue has been assessed for breach reporting and remediation of other affected clients. That dual framing prompts a fuller file review.

Frequently Asked Questions

How fast must breaches be reported?
Significant breaches within 30 days of the licensee first knowing the circumstances. Other reportable breaches within 90 days, with full records retained.

Will I be told if I am affected?
Generally yes. Licensees must notify affected clients, explain the issue, outline remediation and provide IDR and AFCA details.

Does a breach report mean my adviser is banned?
No. Many reports lead to remediation without individual bans. Bans follow serious or repeated misconduct.

Where does RG 78 fit with RG 104 and RG 105?
RG 104 requires the compliance framework that should catch breaches. RG 105 makes responsible managers accountable for it. RG 78 sets how breaches are reported once found.

How AdviserCheck Helps

Our six-layer scan surfaces the file-level failures that often drive breach reports — missing fees, unsuitable advice and contradictions. Try a free check before you complain.

Related guides:

Check your SOA for breach-reportable gaps — free credit to start

Try AdviserCheck Free

Last updated: 2026-09-14. This guide is for informational purposes only and does not constitute financial or legal advice.

By AdviserCheck Editorial Team

Privacy Policy · About · Editorial Policy