ASIC v Fortnum: Why Supervision Frameworks Are Being Put to the Test

Regulators rarely focus solely on the conduct of individual advisers. Increasingly, enforcement activity is examining the effectiveness of the licensee’s supervision framework and whether governance mechanisms can identify and address risks before they impact clients.

The ASIC v Fortnum matter serves as a reminder that the quality of a compliance framework is not measured by the number of policies a business maintains. It is measured by whether those controls actively identify issues, escalate risks and drive remediation when required.

Many licensees have invested heavily in monitoring programs, adviser reviews, breach registers and supervision systems. On paper, these frameworks often appear comprehensive. However, recent regulatory action continues to highlight a recurring challenge across the industry: controls may exist, but they are not always operating effectively.

The reality is that supervision becomes more complex as advice businesses grow. Larger adviser networks, authorised representatives operating across multiple locations, and increasingly diverse advice models all place additional pressure on oversight frameworks. As complexity increases, firms can become reliant on processes that focus on completing reviews rather than assessing whether those reviews are identifying meaningful risk.

This creates a dangerous blind spot.

A file review completed on time does not automatically indicate an effective supervision framework. Regular monitoring activity does not guarantee that issues are being identified. Compliance reporting does not necessarily mean risks are being escalated appropriately.

The fundamental question regulators continue to ask is:

“Can the licensee demonstrate that its supervision framework is capable of identifying poor conduct before regulators do?”

Where the answer is unclear, governance concerns begin to emerge.

In practice, weaknesses commonly develop when:

  • Monitoring focuses on administrative completion rather than advice quality.
  • Findings are recorded but not escalated.
  • Repeat issues are treated as isolated incidents.
  • Remediation actions are delayed or poorly tracked.
  • Compliance reporting becomes a retrospective exercise rather than an active risk management tool.

The consequence is that risks can remain within the business for extended periods without receiving the attention they require.

Strong supervision frameworks operate differently.

They focus on identifying patterns, challenging assumptions and escalating concerns early. They view file reviews, complaints, breach reporting and adviser monitoring as connected risk indicators rather than separate compliance obligations. Most importantly, they generate evidence that the framework is operating effectively.

For Responsible Managers and compliance professionals, the broader lesson is clear. Regulatory expectations continue to move away from the existence of controls and towards demonstrable effectiveness.

The firms most likely to withstand regulatory scrutiny are not those with the largest compliance manuals. They are the firms able to demonstrate that governance frameworks work in practice, detect emerging risks and support timely intervention.

Ultimately, ASIC v Fortnum reinforces a message that regulators have been delivering for years:

Effective supervision is not about proving that reviews occurred. It is about proving that those reviews mattered.

Call To Action

ASIC v Fortnum is a timely reminder that supervision frameworks must do more than exist. They must actively identify, escalate and address risk across the licensee and authorised representative network.

For AFSL holders, Responsible Managers and compliance teams, this means reviewing whether monitoring programs, adviser supervision, cybersecurity controls and escalation pathways are operating effectively in practice. Policies and registers alone will not be enough if they do not support timely intervention and evidence-based oversight.

AICS provides independent compliance reviews, governance assessments, and supervision framework support for AFSL and ACL holders, and training programs for Responsible Managers, helping firms identify control gaps, strengthen oversight, and demonstrate that their compliance framework is operating as intended.

If you would like to review the effectiveness of your supervision and governance framework, click here to contact Cheyenne and the team, email [email protected] or call 07 3251 2481.

References