ASIC says governance matters remain a dominant misconduct theme. Use this records checklist to test whether your entity evidence, registers and approvals are ready.
ASIC governance failures are not only boardroom conduct problems. They are often record-control problems: unclear ownership, missing approvals, stale registers, weak books and records, incomplete director evidence, or no traceable response when an issue is raised. ASIC's September 2026 misconduct release says retail investor issues and governance matters continued to dominate reports received in the first half of 2026. For CFOs, General Counsel, Company Secretaries and governance teams, the practical response is to test whether each entity can prove its governance position quickly, from source record to approval to action.
General information only, not legal advice. Check ASIC guidance and professional advice before relying on any specific compliance position.
On 2 September 2026, ASIC released new data on reports of misconduct received from the public. ASIC said it received 9,807 reports between 1 January and 30 June 2026. It also said retail investor issues and governance matters continued to dominate reports received by ASIC, together accounting for over four in five reports.
ASIC's detailed reports-of-misconduct data page explains that the "Corporations and corporate governance" theme includes fraud allegations, corporate governance issues, registered liquidator conduct, insolvency matters, shareholder issues, reporting issues and failure to provide books and records on company activities and property to registered liquidators.
That is a useful signal for governance teams because it is broad. A governance failure is not always a dramatic scandal. It can start with a shareholder concern, a disputed register, a missing record, a director identification number issue, a deregistration concern, a liquidator request, an unresolved reporting question, or a pattern of complaints that points to weak control.
ASIC also noted that some reports directly assisted existing surveillance or investigation matters, and that other reports were linked to related reports and considered together. In other words, the records your team keeps today may matter later, when a concern has to be assessed with more context.
Many Australian companies can produce a company extract, a set of signed minutes and a folder of historical documents. That does not always mean the governance system is under control.
The harder test is whether the team can answer these questions without rebuilding the history from inboxes and adviser files:
This is why governance failures often show up as operational gaps before they become legal problems. The records may exist, but they are disconnected. The board decision is in one folder, the ASIC lodgement in another, the register update in a spreadsheet, the approval in an email thread, and the current owner in someone's memory.
For a single company, that might be manageable for a while. For a group with subsidiaries, trustee companies, SPVs, joint ventures, dormant entities, external advisers and overlapping directors, it becomes fragile.
Use this framework to test whether your governance records could stand up if a misconduct concern, board question, auditor request, shareholder query, creditor concern, regulator contact or leadership handover happened this quarter.
The goal is not to predict every issue. The goal is to make sure the source records are clear enough that the team can respond accurately and calmly.
Start with the basics. When a concern is raised, the first failure is often uncertainty about which legal entity is involved.
For each entity, confirm:
ASIC's company record keeping guidance says companies must keep certain records and that records may be kept electronically if they can be produced in hard copy. For governance teams, the operating standard should be higher than "we can probably find it." The standard should be a current entity profile that can be trusted before any decision is made.
ASIC's reports-of-misconduct data specifically includes failure to provide books and records to liquidators within the corporations and corporate governance theme. That should catch the attention of CFOs and General Counsel.
Books and records are not just a finance archive. They are the evidence base for decisions about solvency, reporting, transactions, disputes, director duties and entity status.
Check whether each material entity has:
ASIC's company financial reports guidance and record keeping materials should be checked directly for the current requirements applying to a specific company. Operationally, the governance team should also know where the records are, who controls access, and whether the right version can be produced quickly.
Director and officeholder data is one of the highest-friction parts of company governance because it changes through appointments, resignations, address changes, director ID issues, conflicts, delegated authority and board composition decisions.
ASIC's misconduct release notes that matters progressed for further action included failures to obtain a director identification number. The broader operational lesson is that officeholder evidence should not sit outside the entity record.
For each director or secretary appointment, check:
The key control is reconciliation. The board record, ASIC record, internal register, signing authority register and document vault should tell the same story.
ASIC's meetings and resolutions guidance explains that certain decisions are made by resolution and that company records should reflect them. In practice, governance teams need to know more than whether a resolution exists.
For each material decision, record:
This is where many governance problems become visible. A board may have approved a transaction, but the register was never updated. A director may have resigned, but ASIC was not notified. A share transfer may have been signed, but the beneficial ownership view was not refreshed. A deed may have been executed, but no one added it to the entity's evidence pack.
The record should follow the decision through to completion.
Governance concerns often become difficult when the internal register and external registry record do not match.
For Australian companies, review the events that can trigger register or ASIC updates, including:
Do not treat lodgement as the final step. The stronger control is:
If any one of those steps is missing, the company may be exposed to confusion later, even if someone believes the task was handled.
ASIC's misconduct pages make clear that reports help identify patterns, trends and broader systemic problems. That means governance teams should keep a clean internal record of how concerns are triaged, not only the final outcome.
For governance issues, complaints, shareholder concerns, whistleblower-related matters, liquidator requests, reporting questions or registry corrections, record:
This does not mean every minor query becomes a board matter. It means the company can show a disciplined pathway for issues that matter.
Run this diagnostic on three entities this week: one active trading entity, one subsidiary or SPV, and one entity with recent changes.
Set a 30-minute timer and try to answer these questions without asking the person who handled the original work:
| Question | Pass Standard | |
|---|---|---|
| Can you identify the current directors, secretaries, registered office and members? | Current record matches ASIC and internal registers. | |
| Can you find the latest annual statement, invoice, payment evidence and solvency resolution? | Evidence is linked to the entity record. | |
| Can you trace the last officer, address or share change? | Approval, lodgement, receipt and register update are visible. | |
| Can you produce core books and records if requested? | Finance and governance evidence locations are known. | |
| Can you show who owns each open obligation? | Owner, due date, status and next action are clear. | |
| Can you explain the last material board decision affecting the entity? | Paper, resolution, approvals and follow-up actions are connected. | |
| Can a new CFO, GC or Company Secretary understand the entity without a handover call? | The record tells the story without relying on memory. |
Score each answer:
A score below 10 out of 14 is not automatically a compliance breach. It is a governance-control warning. It means the entity record is not ready for a complaint, audit request, director question, adviser handover or regulatory query without manual reconstruction.
If the diagnostic exposes gaps, start with records that affect decision quality and external obligations.
Priority one: confirm entity identity and officeholders. If the wrong people, addresses or ownership details are driving decisions, everything downstream is exposed.
Priority two: reconcile registers and ASIC records. Internal and external records should not drift apart after director changes, share movements, address changes or annual reviews.
Priority three: connect approvals to evidence. A signed resolution is stronger when it is linked to the paper considered, the source information relied on, the lodgement made, the receipt received and the owner who closed the action.
Priority four: document open issues. If an issue was raised but not closed, assign an owner, status, next action and evidence location.
Priority five: standardise the repeatable workflow. Annual reviews, officer changes, register changes, solvency resolutions, shareholder updates and board decisions should not depend on the personal filing habits of whoever handled the last one.
EntityFlo is built for the operating problem behind this checklist: governance records spread across spreadsheets, shared drives, inboxes, adviser portals and old board packs.
For Australian groups, EntityFlo acts as a governance system of record for entities, roles, registers, obligations, ownership, approvals, documents and evidence. That matters because the response to a governance concern is rarely one document. It is the connected record: what happened, who approved it, what changed, what was lodged, which register was updated and where the evidence lives.
The goal is not to replace legal judgement or professional advice. It is to make the company record strong enough that CFOs, General Counsel, Company Secretaries and governance teams are not rebuilding the truth under pressure.
ASIC's misconduct data uses a corporations and corporate governance theme that includes corporate governance issues, fraud allegations, insolvency matters, shareholder issues, reporting issues and failure to provide company books and records to liquidators. The exact treatment of any matter depends on the facts and ASIC's assessment.
CFOs often rely on governance records for financial reporting, audit responses, solvency processes, group structure, delegations, intercompany arrangements and board reporting. If entity records are incomplete or hard to trace, finance teams may have to rebuild evidence under time pressure.
Start with entity identity, directors and secretaries, registered office, members or shareholders, annual review evidence, board and member resolutions, ASIC lodgements, registers, key contracts, financial records and open obligations. Then confirm who owns each record and when it was last verified.
A shared drive can store documents, but it usually does not prove that registers, obligations, approvals, lodgements, owners and evidence are connected. Governance teams need a way to trace the full record for each entity and event, not only retrieve files.
At minimum, review records around annual reviews, reporting cycles, director or secretary changes, share changes, restructures, acquisitions, deregistrations, audits and adviser handovers. Multi-entity groups should also maintain a recurring governance health check across the full portfolio.
No. This checklist is an operational governance tool. It helps teams identify record gaps and control weaknesses, but companies should obtain legal, accounting or governance advice for entity-specific obligations and regulator-facing matters.
Book an EntityFlo demo to see how a governance system of record can connect entities, registers, obligations, approvals, lodgements and evidence across your Australian group.
We use cookies to improve your experience. Essential cookies are always active.