HomeInsights"governance failures ASIC"
    "governance failures ASIC"

    ASIC Governance Failures: A Records Checklist for Australian Companies

    ASIC says governance matters remain a dominant misconduct theme. Use this records checklist to test whether your entity evidence, registers and approvals are ready.

    E
    EntityFlo
    11 September 2026
    13 min read

    ASIC governance failures are not only boardroom conduct problems. They are often record-control problems: unclear ownership, missing approvals, stale registers, weak books and records, incomplete director evidence, or no traceable response when an issue is raised. ASIC's September 2026 misconduct release says retail investor issues and governance matters continued to dominate reports received in the first half of 2026. For CFOs, General Counsel, Company Secretaries and governance teams, the practical response is to test whether each entity can prove its governance position quickly, from source record to approval to action.

    General information only, not legal advice. Check ASIC guidance and professional advice before relying on any specific compliance position.

    What ASIC's Misconduct Data Says

    On 2 September 2026, ASIC released new data on reports of misconduct received from the public. ASIC said it received 9,807 reports between 1 January and 30 June 2026. It also said retail investor issues and governance matters continued to dominate reports received by ASIC, together accounting for over four in five reports.

    ASIC's detailed reports-of-misconduct data page explains that the "Corporations and corporate governance" theme includes fraud allegations, corporate governance issues, registered liquidator conduct, insolvency matters, shareholder issues, reporting issues and failure to provide books and records on company activities and property to registered liquidators.

    That is a useful signal for governance teams because it is broad. A governance failure is not always a dramatic scandal. It can start with a shareholder concern, a disputed register, a missing record, a director identification number issue, a deregistration concern, a liquidator request, an unresolved reporting question, or a pattern of complaints that points to weak control.

    ASIC also noted that some reports directly assisted existing surveillance or investigation matters, and that other reports were linked to related reports and considered together. In other words, the records your team keeps today may matter later, when a concern has to be assessed with more context.

    The Practical Risk: Compliant On Paper, Not In Control

    Many Australian companies can produce a company extract, a set of signed minutes and a folder of historical documents. That does not always mean the governance system is under control.

    The harder test is whether the team can answer these questions without rebuilding the history from inboxes and adviser files:

    • Which entity is affected?
    • Who owns the issue?
    • What source record supports the current position?
    • Which director, officer, member or adviser approved the action?
    • Was the relevant register updated?
    • Was ASIC notified where required?
    • Where is the signed evidence?
    • What changed after the issue was raised?
    • Who checked that the matter was closed?

    This is why governance failures often show up as operational gaps before they become legal problems. The records may exist, but they are disconnected. The board decision is in one folder, the ASIC lodgement in another, the register update in a spreadsheet, the approval in an email thread, and the current owner in someone's memory.

    For a single company, that might be manageable for a while. For a group with subsidiaries, trustee companies, SPVs, joint ventures, dormant entities, external advisers and overlapping directors, it becomes fragile.

    A Complaints-Ready Governance Records Framework

    Use this framework to test whether your governance records could stand up if a misconduct concern, board question, auditor request, shareholder query, creditor concern, regulator contact or leadership handover happened this quarter.

    The goal is not to predict every issue. The goal is to make sure the source records are clear enough that the team can respond accurately and calmly.

    1. Entity Identity And Ownership

    Start with the basics. When a concern is raised, the first failure is often uncertainty about which legal entity is involved.

    For each entity, confirm:

    • legal name, ACN and ABN where relevant
    • company type and registration status
    • registered office and principal place of business
    • directors, secretaries and other officeholders
    • review date and annual review status
    • ultimate holding company details where applicable
    • current shareholders or members
    • share classes and rights
    • beneficial ownership indicators where maintained
    • related trusts, trustee companies, SPVs or joint venture arrangements

    ASIC's company record keeping guidance says companies must keep certain records and that records may be kept electronically if they can be produced in hard copy. For governance teams, the operating standard should be higher than "we can probably find it." The standard should be a current entity profile that can be trusted before any decision is made.

    2. Books, Records And Source Evidence

    ASIC's reports-of-misconduct data specifically includes failure to provide books and records to liquidators within the corporations and corporate governance theme. That should catch the attention of CFOs and General Counsel.

    Books and records are not just a finance archive. They are the evidence base for decisions about solvency, reporting, transactions, disputes, director duties and entity status.

    Check whether each material entity has:

    • financial records and working papers
    • bank, invoice, loan and intercompany records
    • key contracts and deeds
    • board and member minutes
    • signed resolutions and circulating approvals
    • consents to act and resignation evidence
    • ASIC annual statements, invoices and receipts
    • lodgement confirmations
    • register change history
    • auditor or adviser correspondence where relevant

    ASIC's company financial reports guidance and record keeping materials should be checked directly for the current requirements applying to a specific company. Operationally, the governance team should also know where the records are, who controls access, and whether the right version can be produced quickly.

    3. Director And Officeholder Control

    Director and officeholder data is one of the highest-friction parts of company governance because it changes through appointments, resignations, address changes, director ID issues, conflicts, delegated authority and board composition decisions.

    ASIC's misconduct release notes that matters progressed for further action included failures to obtain a director identification number. The broader operational lesson is that officeholder evidence should not sit outside the entity record.

    For each director or secretary appointment, check:

    • consent to act
    • appointment or resignation date
    • residential address and service address records where relevant
    • director ID status where applicable
    • board or member approval evidence
    • ASIC lodgement status
    • register of officeholders update
    • conflict or interest declarations
    • related committee appointments
    • signing authority or delegation changes
    • induction or handover records where relevant

    The key control is reconciliation. The board record, ASIC record, internal register, signing authority register and document vault should tell the same story.

    4. Approvals, Minutes And Resolutions

    ASIC's meetings and resolutions guidance explains that certain decisions are made by resolution and that company records should reflect them. In practice, governance teams need to know more than whether a resolution exists.

    For each material decision, record:

    • what decision was made
    • which entity or entities it affected
    • who had authority to approve it
    • who approved it and when
    • what paper or recommendation was relied on
    • whether conflicts were declared or managed
    • whether member, lender, trustee, adviser or regulator steps were needed
    • what follow-up actions were created
    • who owned completion
    • where the signed evidence sits

    This is where many governance problems become visible. A board may have approved a transaction, but the register was never updated. A director may have resigned, but ASIC was not notified. A share transfer may have been signed, but the beneficial ownership view was not refreshed. A deed may have been executed, but no one added it to the entity's evidence pack.

    The record should follow the decision through to completion.

    5. Registers And ASIC Change Events

    Governance concerns often become difficult when the internal register and external registry record do not match.

    For Australian companies, review the events that can trigger register or ASIC updates, including:

    • director, secretary or officer changes
    • registered office or principal place of business changes
    • member or shareholder changes
    • share issues, cancellations and transfers
    • share class changes
    • ultimate holding company changes
    • company name or type changes
    • registered agent appointments or cessations
    • special purpose company status changes
    • voluntary deregistration steps

    Do not treat lodgement as the final step. The stronger control is:

    • decision or source event recorded
    • approval captured
    • ASIC or registry action completed where required
    • receipt or confirmation stored
    • internal register updated
    • ownership map or related record refreshed
    • responsible owner signs off closure

    If any one of those steps is missing, the company may be exposed to confusion later, even if someone believes the task was handled.

    6. Issue Escalation And Response History

    ASIC's misconduct pages make clear that reports help identify patterns, trends and broader systemic problems. That means governance teams should keep a clean internal record of how concerns are triaged, not only the final outcome.

    For governance issues, complaints, shareholder concerns, whistleblower-related matters, liquidator requests, reporting questions or registry corrections, record:

    • date received
    • source of the concern
    • entity or entities affected
    • issue category
    • initial assessment owner
    • board, committee, legal, finance or external adviser escalation
    • documents reviewed
    • decisions made
    • actions taken
    • closing position
    • evidence retained
    • lessons or control improvements

    This does not mean every minor query becomes a board matter. It means the company can show a disciplined pathway for issues that matter.

    7. The 30-Minute Governance Failure Diagnostic

    Run this diagnostic on three entities this week: one active trading entity, one subsidiary or SPV, and one entity with recent changes.

    Set a 30-minute timer and try to answer these questions without asking the person who handled the original work:

    QuestionPass Standard
    Can you identify the current directors, secretaries, registered office and members?Current record matches ASIC and internal registers.
    Can you find the latest annual statement, invoice, payment evidence and solvency resolution?Evidence is linked to the entity record.
    Can you trace the last officer, address or share change?Approval, lodgement, receipt and register update are visible.
    Can you produce core books and records if requested?Finance and governance evidence locations are known.
    Can you show who owns each open obligation?Owner, due date, status and next action are clear.
    Can you explain the last material board decision affecting the entity?Paper, resolution, approvals and follow-up actions are connected.
    Can a new CFO, GC or Company Secretary understand the entity without a handover call?The record tells the story without relying on memory.

    Score each answer:

    • 2 = clear, current and evidenced
    • 1 = partly available but requires manual follow-up
    • 0 = unclear, missing or owner-dependent

    A score below 10 out of 14 is not automatically a compliance breach. It is a governance-control warning. It means the entity record is not ready for a complaint, audit request, director question, adviser handover or regulatory query without manual reconstruction.

    What To Fix First

    If the diagnostic exposes gaps, start with records that affect decision quality and external obligations.

    Priority one: confirm entity identity and officeholders. If the wrong people, addresses or ownership details are driving decisions, everything downstream is exposed.

    Priority two: reconcile registers and ASIC records. Internal and external records should not drift apart after director changes, share movements, address changes or annual reviews.

    Priority three: connect approvals to evidence. A signed resolution is stronger when it is linked to the paper considered, the source information relied on, the lodgement made, the receipt received and the owner who closed the action.

    Priority four: document open issues. If an issue was raised but not closed, assign an owner, status, next action and evidence location.

    Priority five: standardise the repeatable workflow. Annual reviews, officer changes, register changes, solvency resolutions, shareholder updates and board decisions should not depend on the personal filing habits of whoever handled the last one.

    Where EntityFlo Fits

    EntityFlo is built for the operating problem behind this checklist: governance records spread across spreadsheets, shared drives, inboxes, adviser portals and old board packs.

    For Australian groups, EntityFlo acts as a governance system of record for entities, roles, registers, obligations, ownership, approvals, documents and evidence. That matters because the response to a governance concern is rarely one document. It is the connected record: what happened, who approved it, what changed, what was lodged, which register was updated and where the evidence lives.

    The goal is not to replace legal judgement or professional advice. It is to make the company record strong enough that CFOs, General Counsel, Company Secretaries and governance teams are not rebuilding the truth under pressure.

    FAQ

    What does ASIC mean by governance failures?

    ASIC's misconduct data uses a corporations and corporate governance theme that includes corporate governance issues, fraud allegations, insolvency matters, shareholder issues, reporting issues and failure to provide company books and records to liquidators. The exact treatment of any matter depends on the facts and ASIC's assessment.

    Why should CFOs care about governance records?

    CFOs often rely on governance records for financial reporting, audit responses, solvency processes, group structure, delegations, intercompany arrangements and board reporting. If entity records are incomplete or hard to trace, finance teams may have to rebuild evidence under time pressure.

    What records should a governance team check first?

    Start with entity identity, directors and secretaries, registered office, members or shareholders, annual review evidence, board and member resolutions, ASIC lodgements, registers, key contracts, financial records and open obligations. Then confirm who owns each record and when it was last verified.

    Is a shared drive enough for governance evidence?

    A shared drive can store documents, but it usually does not prove that registers, obligations, approvals, lodgements, owners and evidence are connected. Governance teams need a way to trace the full record for each entity and event, not only retrieve files.

    How often should companies review governance records?

    At minimum, review records around annual reviews, reporting cycles, director or secretary changes, share changes, restructures, acquisitions, deregistrations, audits and adviser handovers. Multi-entity groups should also maintain a recurring governance health check across the full portfolio.

    Does this checklist replace legal advice?

    No. This checklist is an operational governance tool. It helps teams identify record gaps and control weaknesses, but companies should obtain legal, accounting or governance advice for entity-specific obligations and regulator-facing matters.

    Ready To Make Your Entity Records Complaints-Ready?

    Book an EntityFlo demo to see how a governance system of record can connect entities, registers, obligations, approvals, lodgements and evidence across your Australian group.

    We use cookies to improve your experience. Essential cookies are always active.