Thirty days from the
moment you knew
A reportable situation is due to ASIC within 30 days of the reasonable grounds test. FormaOS keeps the register, the clock and the evidence together.
| Obligation | Status | |
|---|---|---|
| General conduct obligations | Mapped | |
| Financial resource requirements | Mapped | |
| Breach reporting (s912D) | At Risk | |
| AML/CTF Program, Part A | Mapped | |
| CPS 230, Critical operations | Unmapped | |
| IDR procedures | Mapped |
Where the 30-day clock is usually lost
Not in the lodgement. In the weeks before anyone agreed the situation was reportable.
Without FormaOS
Breach register not maintained, s912D self-reporting deadlines missed or detected late
No record of when reasonable grounds were formed, so the clock cannot be evidenced afterwards
AFS licence conditions not mapped to operational obligations, gaps invisible until ASIC review
Board unable to demonstrate active oversight, no structured compliance reporting to directors
With FormaOS
Centralised breach register with s912D workflow, days-since-detection counter, and deadline alerts
Detection, classification and sign-off timestamped, so the clock is defensible on review
Every licence condition mapped to named owners with evidence requirements and review schedules
One-click board reporting pack with RAG status, open breaches, and attestation workflow
Compared with spreadsheets and legacy GRC tools
Legacy GRC holds a register. It rarely holds the evidence, the owner and the clock against the same obligation.
| Feature | Spreadsheets | Legacy GRC Tools | FormaOS |
|---|---|---|---|
| ASIC obligation register pre-built | No | Partial | Yes |
| s912D breach register | No | Partial | Yes |
| Board reporting pack | No | Partial | Yes |
| APRA CPS 230 tracking | No | No | Yes |
| Named ownership per obligation | No | Yes | Yes |
| Immutable evidence chain | No | No | Yes |
| AU data residency | No | Partial | Yes |
| AUSTRAC AML/CTF tracking | No | No | Yes |
| Onboarding time | Weeks | Days | Hours |
| Price | Hidden | $$$+ | from $297/mo |
- Spreadsheets
- No
- Legacy GRC Tools
- Partial
- FormaOS
- Yes
- Spreadsheets
- No
- Legacy GRC Tools
- Partial
- FormaOS
- Yes
- Spreadsheets
- No
- Legacy GRC Tools
- Partial
- FormaOS
- Yes
- Spreadsheets
- No
- Legacy GRC Tools
- No
- FormaOS
- Yes
- Spreadsheets
- No
- Legacy GRC Tools
- Yes
- FormaOS
- Yes
- Spreadsheets
- No
- Legacy GRC Tools
- No
- FormaOS
- Yes
- Spreadsheets
- No
- Legacy GRC Tools
- Partial
- FormaOS
- Yes
- Spreadsheets
- No
- Legacy GRC Tools
- No
- FormaOS
- Yes
- Spreadsheets
- Weeks
- Legacy GRC Tools
- Days
- FormaOS
- Hours
- Spreadsheets
- Hidden
- Legacy GRC Tools
- $$$+
- FormaOS
- from $297/mo
Obligation coverage across every financial services regulator
Pre-built frameworks map your ASIC, APRA, AUSTRAC, and AFCA obligations out of the box. Each obligation links to an owner, evidence requirement, and review cycle.
ASIC AFS licence: s912A obligations
Australian Securities and Investments Commission · Last updated: 2025-11-15
The registers a licensee is asked to produce
Obligations, breaches, board reporting, AML/CTF and disputes, each with a named owner and an evidence trail.
Obligations Register
Every ASIC, APRA, and AUSTRAC obligation mapped to licence conditions with regulation references, named owners, evidence requirements, and review schedules.
- Pre-loaded obligation sets for AFS licence conditions
- Regulation reference linked to each obligation (e.g. s912A(1)(a))
- Named owner assignment with escalation paths
- RAG status tracking, mapped, at risk, unmapped, breached
- Scheduled review cycles with automated reminders
Breach Register
Centralised register for reportable situations under s912D with self-reporting workflow, days-since-detection counter, and immutable audit trail.
- s912D reportable situation classification
- Days-since-detection counter with regulatory deadline alerts
- Self-reporting workflow, draft, review, lodge, confirm
- Root cause analysis and remediation tracking
- Immutable evidence chain from detection to resolution
Board Reporting Pack
One-click PDF generation with RAG compliance status, open breach summary, upcoming regulatory deadlines, and attestation-ready formatting for directors.
- RAG status dashboard across all obligation categories
- Open breaches with days outstanding and severity
- Upcoming regulatory deadlines, next 30/60/90 days
- Compliance programme effectiveness metrics
- Director attestation and sign-off workflow
AML/CTF Programme Tracking
Map AUSTRAC AML/CTF programme obligations across Part A and Part B, track annual compliance report requirements, and monitor suspicious matter reporting.
- Part A and Part B obligation coverage dashboard
- Customer identification procedure tracking
- Ongoing customer due diligence monitoring
- Annual compliance report deadline tracker with evidence assembly
- Suspicious matter and threshold transaction reporting log
AFCA Dispute Register
Track complaints from intake through resolution with AFCA notification workflow, resolution timelines, and systemic issue identification.
- Complaint intake with categorisation and severity
- Internal dispute resolution (IDR) timeframe tracking
- AFCA escalation and notification workflow
- Resolution timeline monitoring against regulatory requirements
- Systemic issue identification and reporting
Experience the Platform
Explore real workflows without creating an account.
Worked examples of how the platform maps to common operating models. These are illustrations, not customers.
Map all s912A obligations to named owners and maintain a breach register without hiring a dedicated compliance team.
Pre-loaded obligation register with RAG tracking, automated breach workflow, and board-ready reporting, run by a team of three.
Demonstrate AUSTRAC AML/CTF programme compliance and prepare the annual compliance report without months of evidence gathering.
Continuous evidence capture across AML/CTF obligations with one-click annual report assembly and AUSTRAC-aligned audit trail.
Provide directors with structured compliance oversight across ASIC, APRA, and AFCA obligations for board meetings.
Unified board reporting pack covering all three regulators, open breaches, upcoming deadlines, and attestation workflow.
Built for frameworks governed by
ASIC surveillance reviews don't announce themselves. Can you demonstrate your obligation coverage right now?
Start Governing Financial Services Compliance Today
Every obligation in one register, each with a named owner and the evidence attached as the work is done.
1 site · up to 10 staff
Up to 3 sites · 10-25 staff
Unlimited sites · up to 75 staff
Unlimited everything · custom rollout
AU-hosted by default · Assessment-led onboarding · Your data never leaves Australia
Financial Services compliance questions
Also see FormaOS for
Framework packs built for the obligations each of these sectors works to.
NDIS Providers
Practice Standards, worker screening, SIRS notifications
Healthcare
AHPRA tracking, NSQHS accreditation, clinical governance
Mental Health
NSMHS standards, restrictive practices, reportable incidents
Childcare
NQF quality areas, educator credentials, QIP builder
Construction
WHS compliance, SWMS registers, contractor inductions
