This is a concept website · Enquire about this domain

aiconsultancy.com.auAdopting AI, practice by practice

Entry 05 · Licensees

AI governance for financial services and credit licensees

ASIC’s Report 798, “Beware the gap”, released on 29 October 2024, found that some licensees were adopting AI faster than they were updating their risk and governance arrangements, and warned that the gap could widen as AI use grows. It rests on a review of 624 AI use cases at 23 AFS and credit licensees, as they stood in December 2023.

Document
ASIC report 798, released 29 October 2024
Reviewed
624 use cases at 23 licensees in banking, credit, insurance and financial advice, as at December 2023
Kind
A report of what ASIC found in a review, not a new rule

General information, not legal or financial advice. Everything below is what ASIC reported finding in one review, dated 29 October 2024; it is not law. The official place to check is ASIC’s report, read for this guide on 9 October 2026.

The review

What ASIC looked at

ASIC analysed the AI use cases that the 23 licensees were using or developing as at December 2023, limited to uses that affected consumers directly or indirectly, and including generative AI and advanced data analytics models. It also asked the licensees about their risk management and governance for AI and their plans, and met 12 of them in June 2024.

Findings 1 to 8

The eight findings

All eight findings of REP 798, in ASIC’s order, in plain words. ASIC groups 1 to 3 under use of AI and 4 to 8 under risk management and governance.
FindingWhat ASIC found
1How far licensees used AI varied widely: some had used it for years, others were just starting. Overall, adoption was accelerating fast.
2Most current uses relied on long-established techniques, but there was a move to more complex and opaque ones, and generative AI use was rising sharply.
3Deployment was mostly cautious. AI supported human decisions or made work more efficient, generally did not decide on its own, and mostly did not deal with consumers directly.
4Not every licensee had adequate arrangements for managing AI risks.
5Some licensees judged risk from the business’s side rather than the consumer’s, with gaps around risks particular to AI, such as algorithmic bias.
6AI governance varied widely, with weaknesses that could open gaps as AI use speeds up.
7Governance and risk management did not always keep pace with the nature and scale of AI use; where they lagged, ASIC saw the greatest risk of consumer harm.
8Many licensees leaned heavily on third parties for their AI models, and not all governed the risks that brings.

Among the report’s key statistics: 57% of all use cases were under two years old or still in development; 61% of the licensees planned to increase their AI use in the next 12 months; only 12 licensees had AI policies that referred to fairness or related ideas, and only 10 had policies that referred to telling affected consumers about AI use.

The title

The gap ASIC means

ASIC’s reasoning is that governance and risk arrangements are “by their nature, slow to change”, so any gap between AI use and governance is likely to widen as adoption increases. In the case of two licensees, it found governance already lagged AI use. Its response is that licensees should review and update those arrangements regularly so they do not fall behind their changing use of AI, and that governance “should lead their AI use”.

The report names consumer risks it has in mind, among them: biased outputs falling hardest on vulnerable people, including being refused credit or insurance or paying more; advice that looks right but contains errors; confidential or sensitive information reproduced without consent, and exposure to cyber attacks and leaks; and marketing that plays on customers’ feelings or narrows their choices.

Existing obligations

The obligations ASIC points to

The report points to the law that already applies: it says the regulatory framework for financial services and credit is “technology neutral”, and that licensees need to consider their existing obligations before deploying AI. Among ASIC’s examples, in its own summary:

  • providing financial or credit services “efficiently, honestly and fairly”;
  • not engaging in unconscionable conduct, including through AI use;
  • making sure what a licensee says about its AI use, model performance and outputs matches how it actually operates;
  • adequate risk management systems, reviewed for how AI changes the risk profile;
  • staying responsible for outsourced functions, with measures to choose, monitor and deal with service providers;
  • directors’ and officers’ duty of care and diligence, which ASIC says extends to adopting, deploying and using AI.

The full list, which also covers compliance measures and technological and human resources, is on pages 33 and 34 of the report. The directors’ duty is section 180 of the Corporations Act 2001. Its first two subsections read:

“(1) A director or other officer of a corporation must exercise their powers and discharge their duties with the degree of care and diligence that a reasonable person would exercise if they: (a) were a director or officer of a corporation in the corporation’s circumstances; and (b) occupied the office held by, and had the same responsibilities within the corporation as, the director or officer.”

“(2) A director or other officer of a corporation who makes a business judgment is taken to meet the requirements of subsection (1), and their equivalent duties at common law and in equity, in respect of the judgment if they: (a) make the judgment in good faith for a proper purpose; and (b) do not have a material personal interest in the subject matter of the judgment; and (c) inform themselves about the subject matter of the judgment to the extent they reasonably believe to be appropriate; and (d) rationally believe that the judgment is in the best interests of the corporation. The director’s or officer’s belief that the judgment is in the best interests of the corporation is a rational one unless the belief is one that no reasonable person in their position would hold.”

Corporations Act 2001, s 180(1) and (2), compilation of 19 September 2026. A note to subsection (1) marks it as a civil penalty provision. A note to subsection (2) says it operates only in relation to duties under s 180 and their equivalent duties at common law or in equity, not duties under any other provision of the Act or under any other law.

Pages 35 and 36

ASIC’s eleven questions for licensees

ASIC expects licensees to weigh their readiness to deploy AI safely and responsibly, and suggests its findings and a set of questions to help. The questions sit under eleven headings, all of them here: taking stock; AI strategy; ethics and fairness; accountability; risk; alignment; policies and procedures; resourcing; oversight and monitoring; third parties; and regulatory reform. The first asks whether a licensee knows where AI is used in its organisation and keeps an AI inventory, the same kind of record the national guidance calls an AI register in the six essential practices.

Back to the registerThe laws a business already answers to, beside the guidance.