ASIC Report 798 · Published 29 October 2024 · AFS and credit licensees

ASIC REP 798, in plain English.
No new rules. Just the ones you already had, applied to AI.

ASIC reviewed 23 licensees and 624 AI use cases, and found governance running behind adoption. The report is nearly two years old now, which is rather the point: the gap it described has had all that time to widen. This page is what it says, what already applies to you, and what is worth writing down.

ASIC // REP 798 REVIEW, NOT A RULE
What ASIC looked at
1
23 licensees
Banking, credit, insurance, financial advice
2
624 AI use cases
As at December 2023
3
Governance and risk arrangements
Whether they had kept pace
Not an enforcement action
A review, and a clear signal of expectations
What the review found

Adoption moved. Governance did not move with it.

These are ASIC's figures, not ours. Read together they describe a fairly ordinary problem: the AI arrived quickly, through software people already owned, and the paperwork never caught up.

57%
of AI use cases reviewed were less than two years old, or still in development
92%
of generative AI use cases were deployed in 2022 to 2023, or in development
43%
had policies covering disclosure of AI use to consumers
~50%
had updated risk management arrangements to address AI-specific risks

Around 60% of the licensees reviewed intended to increase their use of AI within a year. ASIC's concern was not that licensees were reckless. Most use was cautious, supporting human decisions rather than replacing them. The concern was the direction of travel: adoption accelerating while the governance underneath it stayed where it was.

The part people miss

REP 798 did not create an AI rulebook. It pointed at the one you already have.

This is the single most useful thing to take from the report. There is no separate AI licence condition to comply with. ASIC's position is that your existing obligations already reach your AI use, and have done since the day you switched it on.

01

Efficiently, honestly and fairly

The general obligation does not carve out decisions a model helped make. If an AI-assisted process produces an unfair outcome for a client, it is your outcome.

02

No misleading or deceptive representations

Applies to what the AI produces and to what you say about the AI. Both directions matter, and the second one catches people out in marketing more often than in advice.

03

Risk management and third-party supplier risk

ASIC called out ongoing due diligence on AI vendors specifically. A model you did not build, running on infrastructure you do not control, is a supplier like any other.

04

Data integrity, privacy and cyber security

What goes into the tool is client information. The obligation to protect it does not change because the destination is a chat box.

05

Directors' duties of care and diligence

Governance is a board-level responsibility, and REP 798 frames it that way. "The team started using it" is not a governance arrangement.

◉ The line we do not cross

We are not lawyers or compliance consultants, and this page is not legal advice. Your obligations under your AFS or credit licence belong with your lawyer or compliance adviser, and we are happy to work alongside them. What Evisent builds is the operational layer underneath: the inventory, the records, the approvals and the audit trail that turn a governance position into something you could actually evidence. Security-first managed IT since 2017, AI builds governed under the same discipline.

What is worth doing about it

Four things, none of which require buying anything.

We are a vendor-neutral firm and this is the honest version: most licensees do not need a new product here. They need the work written down and kept current. If you can do these four yourself, do them yourself.

Step 01

Inventory what is already running

Not the AI you plan to adopt. The AI already switched on inside the software you licence today, including features enabled by default in your practice management, CRM and Microsoft 365 tenant.

Why it comes first: ASIC found licensees who were unaware of AI features inside tools they already owned. You cannot govern what you have not counted.

Step 02

Write the data rule down

One page. Which client information may be sent to which tool, and which may not. Names, TFNs, account numbers and anything that identifies a client are the obvious line.

Why it works: a rule people can remember gets followed. A twenty-page policy gets filed and ignored, and ASIC will read the behaviour, not the binder.

Step 03

Decide what you disclose, and to whom

Only about 43% of the licensees ASIC reviewed had a position on disclosing AI use to consumers. Decide yours deliberately rather than by default.

Why it matters: this is the gap ASIC named most directly, and it is the cheapest one to close. It is a decision, not a project.

Step 04

Keep an audit trail you could actually produce

If AI contributed to advice or a working paper, note what was asked and what was done with the answer. Who approved each use, and when.

Why it is the hard one: the first three are decisions you make once. This one is a habit, which is exactly the sort of recurring load that systems carry better than people do.

Step four is where we are usually useful, and only step four. It is the same pattern as AML/CTF Tranche 2: the judgement stays with the professional, the paperwork gets carried by a system. If you want the wider picture for an advice practice, that sits on the financial advisors page, and the governance reporting is shown on the Management Dashboard.

What is ASIC REP 798?

REP 798, "Beware the gap: Governance arrangements in the face of AI innovation", is an ASIC report published on 29 October 2024. ASIC reviewed the AI governance arrangements of 23 Australian financial services and credit licensees, covering 624 AI use cases as at December 2023. It is a review and a signal of expectations, not an enforcement action and not a new rule.

Does REP 798 create new obligations?

No. ASIC's point is that your existing obligations already cover AI use: providing services efficiently, honestly and fairly, avoiding misleading representations, managing risk including third-party supplier risk, protecting data, and directors' duties of care and diligence. The report is about whether governance kept pace with adoption, not about adding a layer on top.

We are a small practice. Does this really apply to us?

The obligations apply to the licence, not to the headcount. What changes with size is proportionality: ASIC expects governance maturity to be aligned with the scale and nature of your AI use, so a solo practice using one tool for document drafting has a much shorter document to write than a bank. Short is fine. Absent is the problem.

Do we need to tell clients we use AI?

REP 798 does not mandate a specific disclosure. It found that only around 43% of licensees reviewed had any policy on the question, which is the finding worth acting on. Decide your position, write it down, and apply it consistently. Your compliance adviser should confirm what your particular licence and client agreements require.

Is this page legal or compliance advice?

No. Evisent is a security-first managed IT and AI firm, not a law firm. This page summarises a public ASIC report so it is easier to read. Your obligations belong with your lawyer or compliance adviser. We build the systems underneath a governance position, and we will tell you when you do not need us.

Sources

ASIC. REP 798 Beware the gap: Governance arrangements in the face of AI innovation. asic.gov.au

ASIC media release 24-238MR. ASIC warns governance gap could emerge in first report on AI adoption by licensees, 29 October 2024. asic.gov.au

Last reviewed August 2026. Next review due November 2026.

15 minutes · senior engineer · no pitch

Tell us which AI tools are already running in your practice. We will tell you what needs documenting.

Bring your compliance adviser's requirements if you have them. If the honest answer is that you can handle this yourself with a one-page policy, that is what we will say, and it happens more often than not.

Book a 15-minute chat → Take the 3-minute quiz first

SEE ALSO: FINANCIAL ADVISORS · AML/CTF TRANCHE 2 · LEGAL PRACTICES