CREW Webinar: Systemic Issues

Lessons from RG271 and ASIC’s Complaints Handling Landscape

Exploring Board Accountability, Regulatory Expectations and Practical Implementation

CREW (Compliance and Risk Executive Women) members gathered virtually to examine a topic that’s increasingly drawing the attention of both boards and regulators: systemic issues arising from complaints. With the fifth anniversary of ASIC’s RG271 provisions on complaints handling looming, many are taking stock of their processes, questioning whether their frameworks are fit-for-purpose and whether they can readily demonstrate compliance should the regulator come knocking.

In this post, we unpack the major themes covered by Jocelyn Furlan FAICD (Non-executive Director and Chair) in her in-depth discussion, drawing on recent ASIC reports, the key requirements of RG271 and practical challenges organisations face in embedding effective frameworks.

The Evolving Definition: What Exactly Is a “Systemic Issue”?

Much of the confusion in the sector stems from the deceptively simple definition of a systemic issue in RG271 - “a matter that could affect or has the potential to affect more than one consumer.” As Jocelyn pointed out, this means a systemic issue could theoretically involve as few as two customers, making the bar for investigation low.

ASIC helpfully provides several examples in RG271, including:

  • Inadequate or misleading disclosure documents

  • System errors producing calculation mistakes

  • Procedural weaknesses or breaches, like privacy issues

  • Insurance administration errors affecting eligibility

But Jocelyn was quick to stress that it’s critical to distinguish systemic issues arising from complaints (the focus of RG271) from those emerging from incidents, breaches or general operational oversight. As she noted, boardroom confusion about this distinction is all too common, underlining the need for shared understanding and clear definitions internally.

RG271: The Obligations in Black and White

ASIC sets out several enforceable provisions in RG271 to ensure boards and financial firms identify and act upon systemic issues emerging from complaints. Among the highlights:

  • Boards (or owners of small firms) must set clear accountabilities for handling systemic issues

  • Firms must have robust systems to investigate, report, and follow up possible systemic issues

  • Internal reporting to boards must include metrics and analysis on systemic issues

  • Staff should be encouraged and enabled to escalate issues identified from individual complaints, with regular analysis of complaint trends

Crucially, smaller firms aren’t off the hook. ASIC expects the same level of diligence even where escalation processes are informal. And, while some recommendations in RG271 are non-enforceable (“shoulds” rather than “musts”), the general expectation is clear - prompt action, fair remediation and timely regulatory reporting where systemic issues are confirmed.

Navigating Grey Areas: Systemic Issues vs. Breaches vs. Opportunities

On the ground, the distinction between a systemic issue, a breach and an improvement opportunity isn’t always clear-cut. Jocelyn highlighted that not all systemic issues are breaches (eg confusing wording in a disclosure may require fix but isn’t necessarily a legal breach). Conversely, a recurring complaint could flag either a compliance issue or simply an opportunity to improve.

A key practical takeaway: the threshold for “systemic” is as much about pattern recognition as numbers. Jocelyn recommended erring on the side of caution, if an issue crops up more than once and could affect others, treat it as a potential systemic issue and investigate further.

The root cause analysis comes later, after an initial flag, so even if the number is small, the investigation period is critical, especially as “most people won’t complain, but may be impacted”.

Lessons from ASIC’s Reviews: Supervisory Focus Areas

ASIC’s recent Reports 751 and 831 have pulled back the curtain on how superannuation trustees, and by extension, the wider financial services sector, are approaching systemic issues. The findings don’t exactly inspire confidence:

  • Only half of trustees had clearly nominated accountability for systemic issues

  • Just two in ten included metrics on systemic issues in their complaints reporting

  • Many definitions and procedures lacked substance, or were not well understood

ASIC’s stance is unambiguous, clear accountability and fit-for-purpose oversight are non-negotiable. Complaints should serve as an “early warning system”, giving boards and management the opportunity to detect issues proactively, not simply respond after the fact.

Reports of service failures or theme-based weaknesses (eg in paying death benefits or handling fund transitions) are now directly tied to ASIC’s enforcement priorities. As Jocelyn noted, ASIC says “where we identify non-compliance, we will consider the full range of regulatory tools available, including enforcement action”.

Who Owns the Issue? Accountability and Governance in Practice

For many organisations, the “who” of systemic issues is still up for debate. In an audience poll, we found responsibilities were split between risk and compliance, business units, the complaints officer and sometimes senior management.

Jocelyn advocated for clear delineation, ideally, senior management takes carriage of actioning systemic issues, with risk/compliance providing line-two oversight and assurance. But crucially, all staff, including those at third-party service providers, must be trained to identify and escalate possible systemic issues. For large organisations with distributed call centres, robust systems and technology are needed to aggregate and flag similar complaints received by different staff.

Implementation Challenges: From Frameworks to Remediation

Having a “systemic issues framework” is increasingly seen as better practice even though it’s not an express regulatory requirement. The value lies in being able to demonstrate, in a single document:

  • How accountabilities are delegated and recorded (eg matrices or RACI charts)

  • Steps for identification, confirmation, treatment, and remediation

  • How reporting is escalated to board level, complete with supporting metrics and analysis

A key focus - remediation must encompass both fixing the root cause and rectifying harm for the affected customers or members. Boards (and regulators) will want to see evidence of both, the classic “what have you done for the member?” question.

The Role of AFCA: Statutory Referral Powers and Practical Impact

The Australian Financial Complaints Authority (AFCA) has statutory responsibility  to refer confirmed systemic issues to ASIC. With their own dedicated systemic issues teams, AFCA will guide firms through investigation, request evidence of process, and, if unsatisfied, escalate the matter to the regulator.

The take-home message from Jocelyn - if you’re proactive, transparent and can demonstrate robust action plans, AFCA is less likely to wade in heavily. If not, expect direct intervention and potentially significant remediation programs.

Wrapping Up: Culture, Clarity and Continuous Review

RG271 hasn’t just tweaked complaints processes, it’s ushered in a broader cultural shift that cuts across lines of accountability, suppliers and reporting hierarchies. With ASIC flagging ongoing reviews and enforcement, the expectation is that firms not only “talk the talk” on systemic issues but can point to concrete, end-to-end processes.

In summary, top-performing organisations will ensure:

  • Definitions are agreed and well-understood

  • Frameworks capture board-level accountability and regular reporting

  • Staff and outsource partners are trained and empowered to escalate

  • Remediation is holistic, addressing root cause and member harm

  • Automation and tech are harnessed to spot patterns early, well before they become enforcement cases

With the next iteration of ASIC’s scrutiny around the corner, there’s never been a better time for a health check on your systemic issues framework. If you’re not already across these themes, now is the time to get your board (and your evidence files) in order.

This blog was prepared from a CREW (Compliance and Risk Executive Women) session held in August 2026. CREW is managed by Mayflower Consulting.