Breach Reporting Still Failing at the ‘Significance’ Assessment Stage

Recent regulatory focus has made one point clear: breach reporting is no longer failing at the point of identification; it is failing at the point of decision-making.

Since the expansion of the reportable situations regime, Australian Financial Services Licensees are required to report not only significant breaches, but also investigations into whether a significant breach has occurred, as well as a range of deemed reportable matters. While this has increased transparency, it has also exposed a critical weakness in how firms assess whether an incident actually meets the threshold of a “reportable situation”.

The Core Failure: Subjective Significance Assessment

In practice, most firms are capturing incidents effectively through complaints, monitoring, audits, and internal escalation channels. The failure occurs immediately after, when the business is required to determine whether the issue is “significant”.

This assessment is inherently judgment-based, requiring consideration of factors such as:

  • Client impact (financial and non-financial)
  • Frequency or systemic nature of the issue
  • Breakdown of controls
  • Whether the breach relates to a core obligation

However, where this process is not structured, the outcome is inconsistency. Industry observations show that similar incidents often lead to different reporting decisions across teams, purely due to subjective interpretation rather than defined criteria.

This creates a fundamental regulatory risk: not that breaches are missed, but that they are not classified correctly, or not classified in time.

Why This Matters: Timeliness and “Reasonable Grounds”

Under the regime, licensees must report a reportable situation within 30 calendar days of first knowing, or being reckless as to whether, there are reasonable grounds to believe it has occurred.

This introduces a critical timing risk.

If significance assessment is slow, unclear, or repeatedly revisited, firms often fall into one of two failure patterns:

  1. Delayed escalation
    Incidents remain in “investigation” while the business debates significance, resulting in missed reporting timeframes.
  2. False downgrading
    Issues are initially classified as “non-significant”, only to later be reclassified after additional facts emerge — creating retrospective reporting exposure.

ASIC surveillance has already identified that many firms are taking excessive time to identify and escalate breaches, often due to deficiencies in incident escalation, monitoring, and internal decision frameworks.

also exposed a critical weakness in how firms assess whether an incident actually meets the threshold of a “reportable situation”.

The Core Failure: Subjective Significance Assessment

In practice, most firms are capturing incidents effectively through complaints, monitoring, audits, and internal escalation channels. The failure occurs immediately afterwards, when the business must determine whether the issue is “significant”.

This assessment is inherently judgment-based, requiring consideration of factors such as:

  • Client impact (financial and non-financial)
  • Frequency or systemic nature of the issue
  • Breakdown of controls
  • Whether the breach relates to a core obligation

However, where this process is not structured, the outcome is inconsistency. Industry observations show that similar incidents often lead to different reporting decisions across teams, driven more by subjective interpretation than by defined criteria.

Why This Matters: Timeliness and “Reasonable Grounds”

Under the regime, licensees must report a reportable situation within 30 calendar days of first knowing, or being reckless as to whether, there are reasonable grounds to believe it has occurred.

This introduces a critical timing risk.

If significance assessment is slow, unclear, or repeatedly revisited, firms often fall into one of two failure patterns:

  1. Delayed escalation
    Incidents remain in “investigation” while the business debates significance, resulting in missed reporting timeframes.
  2. False downgrading
    Issues are initially classified as “non-significant”, only to later be reclassified after additional facts emerge — creating retrospective reporting exposure.

ASIC surveillance has already identified that many firms are taking excessive time to identify and escalate breaches, often due to deficiencies in incident escalation, monitoring, and internal decision frameworks.

The Structural Problem: No Defined Decision Framework

The root cause across most organisations is simple; significance is being assessed without a defined framework.

Instead of structured decision-making, firms rely on:

  • Email discussions between compliance and business units
  • Case-by-case judgment without precedent tracking
  • Reliance on individual experience rather than defined rules

This creates three immediate risks:

  • Inconsistency — similar matters treated differently
  • Audit failure — no clear rationale for decisions
  • Regulatory challenge — inability to demonstrate how conclusions were reached

Without a documented and repeatable process, significance assessment becomes indefensible under regulatory review.

What Regulators Are Actually Testing

Regulators are no longer focused purely on whether a breach was reported; they are testing how the decision was made.

In particular, ASIC will examine:

  • When the issue was first identified versus when it was reported
  • Whether “reasonable grounds to believe” existed earlier
  • The documented rationale for why a matter was (or was not) considered significant
  • Consistency with how similar incidents have been treated historically
  • Whether deemed significant breaches were correctly captured

This means the absence of a clear decision framework is itself a compliance failure.

What Good Looks Like

Leading firms are addressing this by operationalising significance assessment as a defined, controlled process rather than a judgement call.

This typically includes:

  • Structured decision trees aligned to RG 78 criteria
  • Pre-defined escalation triggers (e.g. client harm thresholds, repeat incidents)
  • Mandatory compliance review before final classification
  • Centralised incident and breach registers with full audit trails
  • Time-based escalation rules to prevent delays (e.g. forced reassessment checkpoints)
  • Periodic back-testing of breach decisions to ensure consistency

AICS Perspective

From an AICS standpoint, breach reporting issues are no longer about regulatory misunderstanding; they are about execution failure within governance frameworks.

Firms that continue to rely on subjective decision-making will struggle to meet regulatory expectations, particularly as ASIC continues to refine its focus on reporting quality and consistency.

Effective breach reporting is now a system, not a process step, and significance assessment is the point at which that system either works or fails.

If your significance assessment framework cannot clearly demonstrate how decisions are made, it may not meet regulatory expectations.

Many licensees continue to rely on informal judgment, inconsistent thresholds, or undocumented reasoning when assessing reportable situations. Under ASIC’s regime, this requires direct exposure assessments that are consistent, evidence-based, and capable of withstanding external scrutiny.

AICS works with AFSL and ACL holders to design and embed structured reportable situations frameworks, ensuring decisions are defensible, aligned to regulatory requirements, and supported by clear governance.

If you would like to assess whether your current approach is fit for purpose, click here to contact Cheyenne and the team, email [email protected] or call 07 3251 2481.

References

  • Australian Securities and Investments Commission (ASIC), Reportable situations for AFS and credit licensees
    View resource
  • Australian Securities and Investments Commission (ASIC), Regulatory Guide 78: Breach reporting by AFS licensees and credit licensees
    View guide
  • Hall & Wilcox, Key findings from ASIC’s breach reporting review
    Read insight