ASIC reviewed 23 licensees and 624 AI use cases, and found governance running behind adoption. The report is nearly two years old now, which is rather the point: the gap it described has had all that time to widen. This page is what it says, what already applies to you, and what is worth writing down.
These are ASIC's figures, not ours. Read together they describe a fairly ordinary problem: the AI arrived quickly, through software people already owned, and the paperwork never caught up.
Around 60% of the licensees reviewed intended to increase their use of AI within a year. ASIC's concern was not that licensees were reckless. Most use was cautious, supporting human decisions rather than replacing them. The concern was the direction of travel: adoption accelerating while the governance underneath it stayed where it was.
This is the single most useful thing to take from the report. There is no separate AI licence condition to comply with. ASIC's position is that your existing obligations already reach your AI use, and have done since the day you switched it on.
The general obligation does not carve out decisions a model helped make. If an AI-assisted process produces an unfair outcome for a client, it is your outcome.
Applies to what the AI produces and to what you say about the AI. Both directions matter, and the second one catches people out in marketing more often than in advice.
ASIC called out ongoing due diligence on AI vendors specifically. A model you did not build, running on infrastructure you do not control, is a supplier like any other.
What goes into the tool is client information. The obligation to protect it does not change because the destination is a chat box.
Governance is a board-level responsibility, and REP 798 frames it that way. "The team started using it" is not a governance arrangement.
We are not lawyers or compliance consultants, and this page is not legal advice. Your obligations under your AFS or credit licence belong with your lawyer or compliance adviser, and we are happy to work alongside them. What Evisent builds is the operational layer underneath: the inventory, the records, the approvals and the audit trail that turn a governance position into something you could actually evidence. Security-first managed IT since 2017, AI builds governed under the same discipline.
We are a vendor-neutral firm and this is the honest version: most licensees do not need a new product here. They need the work written down and kept current. If you can do these four yourself, do them yourself.
Not the AI you plan to adopt. The AI already switched on inside the software you licence today, including features enabled by default in your practice management, CRM and Microsoft 365 tenant.
Why it comes first: ASIC found licensees who were unaware of AI features inside tools they already owned. You cannot govern what you have not counted.
One page. Which client information may be sent to which tool, and which may not. Names, TFNs, account numbers and anything that identifies a client are the obvious line.
Why it works: a rule people can remember gets followed. A twenty-page policy gets filed and ignored, and ASIC will read the behaviour, not the binder.
Only about 43% of the licensees ASIC reviewed had a position on disclosing AI use to consumers. Decide yours deliberately rather than by default.
Why it matters: this is the gap ASIC named most directly, and it is the cheapest one to close. It is a decision, not a project.
If AI contributed to advice or a working paper, note what was asked and what was done with the answer. Who approved each use, and when.
Why it is the hard one: the first three are decisions you make once. This one is a habit, which is exactly the sort of recurring load that systems carry better than people do.
Step four is where we are usually useful, and only step four. It is the same pattern as AML/CTF Tranche 2: the judgement stays with the professional, the paperwork gets carried by a system. If you want the wider picture for an advice practice, that sits on the financial advisors page, and the governance reporting is shown on the Management Dashboard.
REP 798, "Beware the gap: Governance arrangements in the face of AI innovation", is an ASIC report published on 29 October 2024. ASIC reviewed the AI governance arrangements of 23 Australian financial services and credit licensees, covering 624 AI use cases as at December 2023. It is a review and a signal of expectations, not an enforcement action and not a new rule.
No. ASIC's point is that your existing obligations already cover AI use: providing services efficiently, honestly and fairly, avoiding misleading representations, managing risk including third-party supplier risk, protecting data, and directors' duties of care and diligence. The report is about whether governance kept pace with adoption, not about adding a layer on top.
The obligations apply to the licence, not to the headcount. What changes with size is proportionality: ASIC expects governance maturity to be aligned with the scale and nature of your AI use, so a solo practice using one tool for document drafting has a much shorter document to write than a bank. Short is fine. Absent is the problem.
REP 798 does not mandate a specific disclosure. It found that only around 43% of licensees reviewed had any policy on the question, which is the finding worth acting on. Decide your position, write it down, and apply it consistently. Your compliance adviser should confirm what your particular licence and client agreements require.
No. Evisent is a security-first managed IT and AI firm, not a law firm. This page summarises a public ASIC report so it is easier to read. Your obligations belong with your lawyer or compliance adviser. We build the systems underneath a governance position, and we will tell you when you do not need us.
ASIC. REP 798 Beware the gap: Governance arrangements in the face of AI innovation. asic.gov.au
ASIC media release 24-238MR. ASIC warns governance gap could emerge in first report on AI adoption by licensees, 29 October 2024. asic.gov.au
Last reviewed August 2026. Next review due November 2026.
Bring your compliance adviser's requirements if you have them. If the honest answer is that you can handle this yourself with a one-page policy, that is what we will say, and it happens more often than not.
SEE ALSO: FINANCIAL ADVISORS · AML/CTF TRANCHE 2 · LEGAL PRACTICES