ASIC Report 798: governance arrangements and AI
ASIC's October 2024 review of how 23 financial services and credit licensees govern AI, and its warning that adoption is outrunning governance. Existing licensee obligations already apply to AI use.
- Status
- In force · Australia (Commonwealth) · ASIC
- Applies to
- AFS licensees and credit licensees. Not other businesses.
- Key date
- 29 October 2024: Report published
- Primary source
- Official document →
- Last reviewed
- 28 September 2026
What it is
ASIC’s first examination of how Australian financial services and credit licensees use AI where it affects consumers, published 29 October 2024. ASIC reviewed 23 licensees across banking, credit, insurance and financial advice and 624 AI use cases in use or development as at December 2023, and met 12 of them in June 2024. Its headline finding is a “governance gap”: some licensees are adopting AI faster than they are updating their risk and governance arrangements, and the gap will widen as use accelerates. The report creates no new obligation. Its point is that the existing ones already apply.
What it requires
Nothing new, and ASIC is explicit that this is the message. The regulatory framework is technology neutral, so licensees must consider their existing obligations before deploying AI: the general obligation to provide services efficiently, honestly and fairly; to have adequate risk management systems and adequate technological and human resources; to document and review the measures they rely on; directors’ duties of care and diligence, including accountability for outsourced functions; and consumer protections, including the prohibitions on unconscionable conduct and on misleading representations about what AI does or produces.
The findings show where those obligations bite. About 60 per cent of licensees planned to increase AI use. Nearly half had no policies addressing consumer fairness or bias. Few had policies on disclosing AI use to consumers. Governance maturity ranged from licensees with no AI-specific arrangements at all to those with a centralised, strategic approach, and reliance on third-party AI was heavy without consistent oversight. ASIC’s chair put the expectation plainly: safe adoption “can only happen if adequate governance arrangements are in place before AI is deployed”, and ASIC “will take enforcement action if appropriate and where necessary”.
Does this reach your business?
Only if you hold an Australian financial services licence or an Australian credit licence. If you do, the report is ASIC telling you how it will interpret your existing obligations when AI is involved, and pages 35 and 36 give the questions it expects you to be able to answer. If you are not a licensee, nothing in it applies to you directly, though the eight findings are a fair description of what goes wrong in any business that adopts AI faster than it governs it.
What we recommend
For a licensee, our advice is to answer ASIC’s own questions before ASIC asks them: which AI you use and where it touches consumers, who owns each system, what could go wrong for a customer (bias, error, a wrong decision) and how you would know, whether you would tell a consumer AI was involved and on what basis, and what you have actually tested rather than assumed about a vendor’s model. The report’s case studies reward one habit above others: routine monitoring with root-cause analysis when a model misbehaves, rather than quietly adjusting thresholds. Keep the record of all of this in one place; that record is what the “adequate risk management systems” obligation looks like when the subject is AI. For a supplier to a licensee, expect these questions to arrive in due diligence.
Questions people ask
No. ASIC says the existing framework is technology neutral: the general licensee obligations, directors' duties and consumer protection laws already cover AI use.
23 AFS and credit licensees across banking, credit, insurance and financial advice, and 624 AI use cases in use or development as at December 2023.
Licensees adopting AI faster than they update their risk and governance arrangements. Nearly half had no policy on consumer fairness or bias, and few had a policy on disclosing AI use to consumers.
The report treats disclosure as an open question and found most licensees had not settled it. It expects licensees to have considered it and to have a basis for their answer, and it flags that a lack of transparency can erode consumer trust.