Skip to main content
Skip to main content

Thirty days from the
moment you knew

A reportable situation is due to ASIC within 30 days of the reasonable grounds test. FormaOS keeps the register, the clock and the evidence together.

300+ ASIC obligations mapped·s912D breach tracking·Board reporting automated
app.formaos.com.au / dashboard
FO
Organisationgreenfield-careOwner
Search...
E
14d left
0 Overdue0 Due Soon0 Completed
Obligations Register
AFS Licence Obligations
4 Mapped1 At Risk1 Unmapped
ObligationStatus
General conduct obligationsMapped
Financial resource requirementsMapped
Breach reporting (s912D)At Risk
AML/CTF Program, Part AMapped
CPS 230, Critical operationsUnmapped
IDR proceduresMapped
6 of 6 records
Live

Where the 30-day clock is usually lost

Not in the lodgement. In the weeks before anyone agreed the situation was reportable.

Without FormaOS

Breach register not maintained, s912D self-reporting deadlines missed or detected late

No record of when reasonable grounds were formed, so the clock cannot be evidenced afterwards

AFS licence conditions not mapped to operational obligations, gaps invisible until ASIC review

Board unable to demonstrate active oversight, no structured compliance reporting to directors

vs

With FormaOS

Centralised breach register with s912D workflow, days-since-detection counter, and deadline alerts

Detection, classification and sign-off timestamped, so the clock is defensible on review

Every licence condition mapped to named owners with evidence requirements and review schedules

One-click board reporting pack with RAG status, open breaches, and attestation workflow

Compared with spreadsheets and legacy GRC tools

Legacy GRC holds a register. It rarely holds the evidence, the owner and the clock against the same obligation.

ASIC obligation register pre-built
Spreadsheets
No
Legacy GRC Tools
Partial
FormaOS
Yes
s912D breach register
Spreadsheets
No
Legacy GRC Tools
Partial
FormaOS
Yes
Board reporting pack
Spreadsheets
No
Legacy GRC Tools
Partial
FormaOS
Yes
APRA CPS 230 tracking
Spreadsheets
No
Legacy GRC Tools
No
FormaOS
Yes
Named ownership per obligation
Spreadsheets
No
Legacy GRC Tools
Yes
FormaOS
Yes
Immutable evidence chain
Spreadsheets
No
Legacy GRC Tools
No
FormaOS
Yes
AU data residency
Spreadsheets
No
Legacy GRC Tools
Partial
FormaOS
Yes
AUSTRAC AML/CTF tracking
Spreadsheets
No
Legacy GRC Tools
No
FormaOS
Yes
Onboarding time
Spreadsheets
Weeks
Legacy GRC Tools
Days
FormaOS
Hours
Price
Spreadsheets
Hidden
Legacy GRC Tools
$$$+
FormaOS
from $297/mo

Obligation coverage across every financial services regulator

Pre-built frameworks map your ASIC, APRA, AUSTRAC, and AFCA obligations out of the box. Each obligation links to an owner, evidence requirement, and review cycle.

ASIC AFS licence: s912A obligations

Australian Securities and Investments Commission · Last updated: 2025-11-15

300+
Obligations
Pre-built
Key requirements covered
General conduct obligations
Financial resource requirements
Organisational competence
Risk management systems
Dispute resolution (IDR/EDR)
Breach reporting and self-reporting
Client money and property handling
Disclosure and conduct obligations

The registers a licensee is asked to produce

Obligations, breaches, board reporting, AML/CTF and disputes, each with a named owner and an evidence trail.

Obligations Register

Every ASIC, APRA, and AUSTRAC obligation mapped to licence conditions with regulation references, named owners, evidence requirements, and review schedules.

  • Pre-loaded obligation sets for AFS licence conditions
  • Regulation reference linked to each obligation (e.g. s912A(1)(a))
  • Named owner assignment with escalation paths
  • RAG status tracking, mapped, at risk, unmapped, breached
  • Scheduled review cycles with automated reminders
Obligations Register
Illustrative · sample data
General conduct, s912A(1)(a)
Head of Compliance
Financial resources, s912A(1)(d)
CFO
Breach reporting, s912D
Compliance Mgr
CPS 230, Critical operations
COO

Breach Register

Centralised register for reportable situations under s912D with self-reporting workflow, days-since-detection counter, and immutable audit trail.

  • s912D reportable situation classification
  • Days-since-detection counter with regulatory deadline alerts
  • Self-reporting workflow, draft, review, lodge, confirm
  • Root cause analysis and remediation tracking
  • Immutable evidence chain from detection to resolution
Breach Register
Illustrative · sample data
BR-2026-041, Client money shortfall
12 days
BR-2026-038, Disclosure failure
28 days
BR-2026-035, Training lapse
Resolved
BR-2026-029, SOA deficiency
Resolved

Board Reporting Pack

One-click PDF generation with RAG compliance status, open breach summary, upcoming regulatory deadlines, and attestation-ready formatting for directors.

  • RAG status dashboard across all obligation categories
  • Open breaches with days outstanding and severity
  • Upcoming regulatory deadlines, next 30/60/90 days
  • Compliance programme effectiveness metrics
  • Director attestation and sign-off workflow
Board Reporting Pack
Illustrative · sample data
Overall compliance posture
94%
Open breaches
2 active
Overdue obligations
0
Next regulatory deadline
15 Apr 2026

AML/CTF Programme Tracking

Map AUSTRAC AML/CTF programme obligations across Part A and Part B, track annual compliance report requirements, and monitor suspicious matter reporting.

  • Part A and Part B obligation coverage dashboard
  • Customer identification procedure tracking
  • Ongoing customer due diligence monitoring
  • Annual compliance report deadline tracker with evidence assembly
  • Suspicious matter and threshold transaction reporting log
AML/CTF Programme
Illustrative · sample data
Part A, Customer ID
100% covered
Part B, CDD procedures
96% covered
Annual report
Due 30 Sep
SMR log
3 pending

AFCA Dispute Register

Track complaints from intake through resolution with AFCA notification workflow, resolution timelines, and systemic issue identification.

  • Complaint intake with categorisation and severity
  • Internal dispute resolution (IDR) timeframe tracking
  • AFCA escalation and notification workflow
  • Resolution timeline monitoring against regulatory requirements
  • Systemic issue identification and reporting
AFCA Dispute Register
Illustrative · sample data
DR-2026-118, Fee dispute
IDR, Day 14
DR-2026-112, Advice complaint
AFCA escalated
DR-2026-105, Service delay
Resolved
DR-2026-099, Disclosure query
Resolved

Experience the Platform

Explore real workflows without creating an account.

Notification Timeline
Regulatory notification workflow
T+0:00
Reportable situation detected, s912D workflow initiated
T+1:00
Breach classification completed, severity assessed
T+24:00
Investigation commenced, root cause analysis
T+48:00
Compliance Officer review and sign-off
T+20d
ASIC self-report lodged within 30-day window
T+60d
Remediation verified, breach register closed
ASIC, APRA, AUSTRAC and AFCA obligations pre-builts912D breach workflow with days-since-detectionAU-hosted by default, data never leaves AustraliaImmutable, timestamped evidence chain

Worked examples of how the platform maps to common operating models. These are illustrations, not customers.

A boutique AFS licensee
What this kind of organisation needs

Map all s912A obligations to named owners and maintain a breach register without hiring a dedicated compliance team.

What FormaOS delivers

Pre-loaded obligation register with RAG tracking, automated breach workflow, and board-ready reporting, run by a team of three.

A non-bank credit provider
What this kind of organisation needs

Demonstrate AUSTRAC AML/CTF programme compliance and prepare the annual compliance report without months of evidence gathering.

What FormaOS delivers

Continuous evidence capture across AML/CTF obligations with one-click annual report assembly and AUSTRAC-aligned audit trail.

A wealth management firm
What this kind of organisation needs

Provide directors with structured compliance oversight across ASIC, APRA, and AFCA obligations for board meetings.

What FormaOS delivers

Unified board reporting pack covering all three regulators, open breaches, upcoming deadlines, and attestation workflow.

Built for frameworks governed by

ASIC
APRA
AUSTRAC

ASIC surveillance reviews don't announce themselves. Can you demonstrate your obligation coverage right now?

Start Governing Financial Services Compliance Today

Every obligation in one register, each with a named owner and the evidence attached as the work is done.

Foundation
$297/ month

1 site · up to 10 staff

Most Popular
Growth
$797/ month

Up to 3 sites · 10-25 staff

Scale
$1,800/ month

Unlimited sites · up to 75 staff

Enterprise
Customtailored agreement

Unlimited everything · custom rollout

AU-hosted by default · Assessment-led onboarding · Your data never leaves Australia

Financial Services compliance questions

FormaOS includes pre-built obligation sets for key Regulatory Guides including RG 104 (AFS licence conditions), RG 132 (managed investment scheme compliance plans), and RG 259 (risk management systems for responsible entities). Obligations from each guide are mapped to named owners with evidence requirements and review schedules.