Categories
Uncategorized

Investment governance under the microscope: Has risk and compliance kept pace with in-house investment management?

APRA has sharpened its expectations on investment governance and, over the past year, begun backing them with enforcement. The standards apply with equal force whether a Trustee outsources investment management, runs it in-house, or operates a hybrid. Our concern, drawn from years leading risk functions inside investment managers, is a quieter one that the enforcement headlines have yet to reach: as more funds have brought investment management in-house, has the risk and compliance capability meant to support it kept pace?

Over the past decade a growing number of superannuation funds have internalised investment management. The stock pickers, deal teams and portfolio management capability now sit inside the Trustee, and that investment capability is usually well built out. The second and third lines have often had less time and investment to scale alongside it. Independent oversight and challenge of the investment function is demanding work, and the risk and compliance capability to match a maturing in- house investment team takes time to build.

There is a good reason attention has sat elsewhere. In superannuation, the functions closest to the member naturally command the most focus. Complaints, death and disability claims, member disclosures, and the core business of accepting contributions and paying benefits are visible, time- critical and emotionally significant. It is understandable that risk and compliance effort has concentrated there. Investment governance, by contrast, can feel remote from the member, until a valuation dispute, a unit pricing error or a poorly monitored option makes it very close indeed.

This article sets out why the same rigour Trustees expect of their outsourced managers should be turned inward, and what recent regulatory activity tells us about the cost of leaving that gap open.

The standards converging on investment governance

Investment governance in superannuation rests first on SPS 530 Investment Governance, which has applied in its strengthened form since 1 January 2023. Under SPS 530 a Trustee must prudently select, manage and monitor investments, and maintain an investment governance framework appropriate to the size, business mix and complexity of its operations, with the board ultimately responsible. The strengthened standard sharpened expectations on valuation governance, liquidity management and stress testing, the same areas APRA and ASIC have found wanting in its review of unlisted asset valuations.

SPS 530 does not operate alone. SPS 515 Strategic Planning and Member Outcomes ties investment decisions back to the outcomes members receive. From 1 July 2025, CPS 230 Operational Risk Management added a resilience layer. It treats investment management as a critical operation or material service whether the function is outsourced, internalised, or a combination of both, and it raises the bar on how Trustees identify and oversee the service providers they depend on, including the fourth parties sitting behind their direct providers. Since early 2025, the Financial Accountability Regime has placed named, personal accountability on Trustees, their directors and senior executives. Accountability, in APRA’s words, cannot be outsourced.

Taken together, these requirements ask Trustees to govern the substance of investment decisions, connect them to member outcomes, make the function operationally resilient, and stand behind it personally. The distinction APRA is now testing is not whether a function was competently procured, but whether it is competently governed on an ongoing basis. That answer must hold wherever the function sits, and for many Trustees it is easier to give for what they outsourced than for what they built themselves.

The gap that has opened up in-house

A common assumption is that internalisation reduces governance risk, because the Trustee now controls the function directly. We are curious at to whether that consistently holds true. An outsourced relationship sits inside a contracted framework: there are service levels, defined reporting, due diligence rights, and a counterparty that is itself regulated. When a fund brings investment management in-house, that external scaffolding falls away, and it is not always replaced with an equivalent internal control environment.

Internal investment teams typically grow out of a small initial footprint and scale quickly alongside funds under management. The second and third lines often do not grow at the same rate. Risk and compliance coverage of the investment function often lags the front office in both capability and resourcing. Many Trustees lack a dedicated second line with the technical depth to challenge portfolio managers on execution quality, counterparty selection, mandate adherence and the conflicts specific to managing money in-house. Valuation governance for unlisted assets is particularly sensitive, since the investment team whose performance is judged on those assets often has the deepest knowledge of them and, without clear separation, can end up influencing how they are valued.

It is worth asking whether the internalisation of investment management was matched by a corresponding uplift in the risk and control functions that oversee it, and whether the same standard of due diligence, monitoring, control assurance and conflicts management a Trustee expects of an external manager would hold if applied to the internal team. For many funds, that is still developing. The opportunity is to bring the internal control environment up to the standard already expected of outsourced investment management.

Having led risk and compliance functions inside investment managers, the PX Partners team has seen this from the inside. We know how quickly an internal capability can outgrow the controls around it, and how easily independent oversight becomes an afterthought when the investment team is delivering.
The point is not that in-house management is wrong. It is that it carries obligations Trustees cannot meet by governing the internal team more lightly than they would an external one.

One lens, wherever the function sits

CPS 230 and SPS 530 apply the same test regardless of the operating model. CPS 230 asks the operational questions: can you identify the critical operation, understand its dependencies and the
providers behind it, set tolerances for disruption, monitor against them, and respond when something fails? SPS 530 asks the substantive ones: can you evidence that investments were prudently selected and are being properly monitored and valued? Neither standard cares whether the function is run by a third party or by a team down the corridor. The Trustee owes the same answer either way.

Where Trustees run more than one model, there is an additional layer to manage. Hybrid arrangements, with some asset classes managed internally and others left with external managers, create a coordination point between the two that benefits from clear ownership. It is worth checking that the standard applied to external managers also informs the internal approach, and that member facing impacts have a clear owner rather than sitting between functions.

Where the gaps typically appear

  • For outsourced functions, the recurring weakness is what happens after onboarding. Initial due diligence tends to be thorough. Ongoing oversight then narrows to performance reporting, an annual due diligence questionnaire and the occasional site visit. Operational risk indicators, control attestations, visibility into sub-custodians and sub-advisers, business continuity testing and exit planning are often underdone. CPS 230 has raised the bar here, extending the
    expected depth of oversight beyond the direct provider to the fourth parties they in turn rely on.
  • For internalised functions, the gaps are structural. A common gap is second-line depth: the specialist skills needed to challenge the front office on investment risk take time and investment to build. Compliance coverage of trade execution, mandate adherence and conflicts of interest is often still maturing. Valuation governance for unlisted assets warrants particular attention.
  • For hybrid models, the risks of both combine.

What APRA has signalled

APRA has put its focus on investment governance beyond doubt. On 7 October 2025 it wrote to platform Trustees, following a thematic review covering Trustees responsible for around 95 per cent of platform assets, calling for stronger action on investment governance (the accompanying letter is available here). Two of its findings travel well beyond platforms. First, a Trustee’s core duties are the same irrespective of its business model. Second, accountability for deciding what belongs on the menu, and for the outcomes members experience, stays with the Trustee no matter how many parties sit in between.

APRA has since acted on those findings. On 17 December 2025 it accepted a court-enforceable undertaking from Netwealth Superannuation Services over the depth of due diligence and monitoring applied to onboarded options and the management of related-party conflicts, and imposed additional licence conditions on Equity Trustees Superannuation the following day. It has since taken action against further platform Trustees, including HTFS Nominees, the Trustee of the HUB24 Super Fund, in May 2026. The detail cuts against a comfortable assumption, that outsourcing investment management reduces the governance burden. It does not. The same logic runs in the other direction: bringing the function in-house does not reduce it either. APRA&’s Deputy Chair has said the platform segment will remain a supervisory priority throughout 2026, and the events sitting behind these actions, including the First Guardian and Shield collapses, have produced member losses and compensation running into the hundreds of millions. The stakes of weak investment governance are no longer hypothetical.

What separates mature Trustees

Across our engagements with Trustees running internalised, outsourced and hybrid models, three themes consistently separate mature investment governance from the rest.

1. Govern the function, not the form. Internal investment teams should be held to the same standard as external managers: documented mandates through investment policies, performance and risk monitoring, control assurance, conflicts management and contingency planning. The test is simple. If you would expect an external manager to produce it, your internal team should produce it too.
2. Build the second and third line to match the first. Investment risk and compliance need real technical depth. Investment risk management keeps strategies running true to label, but the area that most often needs attention is the expertise to review and challenge front office controls, such as execution quality and counterparty selection, and to understand the conflicts unique to managing money in-house. For Trustees with internalised capability, this is often where the greatest investment is required.
3. Anchor everything in member impact. Investment governance is not a back-office discipline. Unit pricing errors, delayed switches, valuation disputes and performance issues flow downstream from investment management to the very member-facing activities that already command a Trustee’s attention. Tolerances under CPS 230, and objectives under SPS 530, should be set against member outcomes, not internal service levels alone.

Why Trustees should act now

APRA’s focus has shifted from documentation to demonstration, and the events of late 2025 show what that shift looks like in practice. The question is no longer whether the material service provider register is current. It is whether the tolerances, controls and oversight hold when tested, and whether the Trustee can show it, for the functions it runs as much as the ones it buys.

This cannot be retrofitted on a supervisory timetable. Building second and third line technical depth takes time. Setting tolerances and objectives that connect to member outcomes, and testing them under stress, takes longer still. Trustees who start now will have something defensible by the time it is tested. Those who wait will be assessed against what their peers have already done.

In our experience, the Trustees getting ahead of this are interrogating their in-house investment governance against SPS 530 and CPS 230, testing whether they can evidence the same rigour internally as they expect of their external managers. Having sat on both sides of that question, inside investment managers and now advising Trustees, we think it is the right one to be asking.

Categories
ausbiz 

The wake-up call for Superannuation Trustees: Bridging the financial crime gap

The regulatory imperative

ASIC’s recent directive to superannuation trustees represents more than regulatory oversight – it signals a fundamental shift in expectations for an industry custodian of $4.3 trillion in Australian retirement savings. While the regulator’s February 2026 review focused on scam prevention, it exposed a broader truth: superannuation trustees must urgently strengthen their entire financial crime framework with members losing $22 million to super-related scams in 2025 alone.

ASIC Commissioner Simone Constant’s warning extends beyond scams: “As banks, telecommunications providers and other financial service businesses increase their anti-scam and anti- fraud capabilities, superannuation trustees must do the same or risk becoming a soft target.”

At PX Partners, our work across financial crime risk management reveals that successful prevention requires understanding the interconnected ecosystem of predicate crimes, money laundering, fraud, scams, and downstream threats like terrorism financing.

Understanding the financial crime ecosystem

Financial crime is not a series of isolated threats but an interconnected system where each element fuels and enables the others. Money laundering sits at the centre, serving as the mechanism that allows criminals to enjoy proceeds from predicate crimes – ranging from fraud and cybercrime to corruption and human trafficking.


Fraud – Scam – ML relationship

It is important to understand the concepts at play and the interrelationship between them:

  • Fraud is deception for personal gain or to cause loss to another. As a predicate crime, it generates proceeds requiring laundering;
  • Scams are a fraud subset and involve manipulating victims through social engineering (often using digital channels) to fraudulently transfer funds. A familiar example is pig-butchering which combines romance fraud, investment scams, cybercrime, and often human trafficking, with proceeds laundered through cryptocurrency; and
  • Money laundering is the process of obscuring the criminal origin of proceeds through placement, layering, and integration into the legitimate financial system.

What ASIC found?

ASIC’s recent review of 47 superannuation trustees focussed on the availability, quality and actionability of anti-scams and fraud content, including by checking the website content for clarity and relevance, prominence on the website and readability. The review found that banks scored positively in over 80% of criteria assessed, whereas most super funds scored positively against just 40–60% of the same criteria. This was a narrow review focussed on public facing content but may be viewed by the Regulator as an indicator of broader weaknesses in the financial crime framework.

Previous ASIC reviews have called out other gaps in the financial services industry that has immediate relevance for Superannuation Trustees:

1. Strategic Gaps: No organisation-wide scams OR fraud strategy. Inadequate integration with broader financial crime frameworks.

2. Operational Weaknesses: Over-reliance on identity verification while missing manipulation indicators. Limited transaction monitoring for scam typologies. No distinction between unauthorised fraud (identity theft) vs authorised fraud (scams where members are manipulated) where different approaches are required to manage the risk.

3. Governance Blind Spots: Insufficient oversight of administrators’ controls. Weak connection between cyber incidents and financial crime response. Limited board reporting on financial crime holistically.

An integrated financial crime framework

Drawing from ASIC’s REP 761 & 790, APRA’s SPG 223, AUSTRAC guidance, and our implementationexperience, we recommend an integrated three-pillars approach to managing this risk:

Third-Party Risk:Map third-party controls across the spectrum: transaction monitoring, cyber defences, fraud analytics, and scam detection. Ensure visibility into administrator capabilities and regular testing.

Pillar 2: Prevention and detection

Cyber as Predicate: Recognise cyber incidents as predicates to fraud / scams. Implement enhanced monitoring post-breach. Link IT security with financial crime teams.

Integrated Detection: Deploy scam-specific rules identifying manipulation (urgency, inconsistent requests, new beneficiaries). Complement traditional fraud detection (unauthorised access) with authorised fraud indicators.

Friction Points: Cooling-off periods for high-risk transactions. Multi-channel verification. Real-time alerts on unusual patterns. Enhanced due diligence for sudden behavioural changes.

Pillar 3: Member communications and victim support

Transformed Communications: Prominent scam/fraud warnings. Clear examples of common typologies (early release scams, pig-butchering, invoice fraud). Dedicated reporting channels (only 20% of funds provide this). Demographic-specific education.

Victim Support: Streamlined reporting processes. Trauma-informed victim support. Clear escalation paths. Integration with AFCA and law enforcement.

Where do I start?

If you are starting from a low level of maturity, it is important to do a risk-based prioritisation – you can’t do it all at once! Where you’ve already established a financial crime operating model, it’ll be targeted uplift to meet the upcoming reforms by 31 March 2026.

0-3 months Conduct gap analysis across full financial crime spectrum. Review website content for scams and fraud. Establish reporting channels. Appoint senior owner.
3-6 months Document integrated financial crime strategy. Map administrator controls. Implement transaction friction. Deploy awareness campaign.
6-12 months Develop detection rules spanning fraud, scams, and ML typologies. Enhance training on financial crime ecosystem. Establish integrated board reporting.

Ensure that existing frameworks are leveraged as much as possible. We see successful entities:

  • designating financial crime (not just scams) as FAR key responsibility.
  • mapping scam/fraud risks into CPS 230 operational risk assessments.
  • integrate with AML/CTF programs as scams and fraud are predicate crimes for money laundering.

The path forward

Scams don’t exist in isolation – they’re part of a continuum spanning predicate crimes, money laundering, and downstream threats.

ASIC’s scam focus is the catalyst, but the solution must be comprehensive. Trustees who understand the fraud – scam – ML relationship and implement an integrated approach will not only meet regulatory expectations but genuinely protect members from an evolving threat landscape.

At PX Partners, we’ve supported financial services organisations in developing holistic financial crime solutions that connect AML/CTF, fraud prevention, scam detection, and cyber resilience. Our experience implementing integrated frameworks positions us to help trustees navigate this complex challenge and transform member protection from compliance obligation to competitive advantage.

The time to act is now. Trustees who embrace this integrated approach demonstrate a true desire to protect the wellbeing of their members in their role as fiduciaries and further strengthen protections against financial crime.

Categories
ausbiz 

What we’ve learnt in 5 years

Five years ago, we established PX Partners with a clear mission: to provide an alternative to the traditional consulting model by delivering practitioner led, client aligned, practical and sustainable solutions.

What began as a boutique consultancy has since grown into a trusted partner for a diverse portfolio of clients across the financial services landscape and beyond – particularly in funds management, superannuation, and insurance. Because we put our clients and their end-customers at the centre of our work, we’re proud to report that over 90% of our engagements come from our existing clients and referrals by our clients.

Along the way, we’ve navigated a global pandemic, regulatory upheavals and generational changes in technology. While the world around us has changed, our commitment has remained constant.

As we celebrate this milestone, we’re sharing five things we’ve learnt from our first 5 years supporting clients.

You can’t do more with less

One of the classic refrains in corporate life when costs are being cut. The need to do more with less. Which is a complete furphy. You can only do less with less. And that’s okay, as long as it’s transparent.

Cutting budgets for Risk and Compliance teams at a time when the regulatory burden is increasing is a fast track to bad outcomes. If you think compliance is expensive, try non-compliance!

Risk leaders need to be clear that having less means doing less – fewer controls monitored, slower incident response and less proactive risk identification. This isn’t about lowering standards. It’s about recalibrating expectations and being clear about what can realistically be achieved with the resources available.

This is not to say that you can’t find ways to make your processes more efficient and embrace new technologies. We have and continue to iterate and improve how we operate to deliver benefits to our clients and Risk & Compliance teams have a really important role to play here – not just in supporting or challenging business teams with risk-in-change and vendor oversight but also in surfacing solutions that can make risk and compliance processes more efficient.

At PX Partners, we’re lucky to be doing more with more having grown our team from our founding two to a team of twelve today across both Sydney and Melbourne.

Don’t fear the tough decisions

Governance around decision making is a key enabler of business success. We have seen so many examples (usually through court action by Regulators) of firms deferring and delaying making critical business decisions.

Whether it is a decision where to invest resource and effort or to make a difficult decision to exit a product or business line, those who are successful have the structures and governance in place to:

  1. Gather the right information
  2. Get it to the right people
  3. Do it in a timely fashion
  4. Commit and execute
  5. Learn from the experience.

Don’t let decision making be paralysed by Committees – good governance around decision making means empowered and accountable executives and not deference to Committee structures. Committees have an important role to play but should be used sparingly and not as a default.

In our own business, ensuring we align to our values helps guide our decisions and makes them easier. Our decisions are centred on being fair to ourselves and our clients, making things better, and being real and transparent about the reasons. That doesn’t mean decisions are easy, but anchoring to these values has resulted in fast alignment around difficult decisions.

People over technology every time

Now more than ever before, firms are looking to technology to deliver efficiencies and reduce cost. The advent of Generative Artificial Intelligence has only super charged this shift. The Fear of Missing Out (FOMO) is rife – firms are rushing to do something in the fear of being left behind. Technology is an enabler, not a silver bullet. Because at the end of the day, technology should serve people and strategy and not the other way around.

Take this thought experiment. How would you feel if we offered you a robot to do a bunch of your usual tasks well? Brilliant, we assume, as you could spend time doing more satisfying things. What if we instead offered your boss a robot to do your job well? Threatened or insecure perhaps? At PX Partners, we have been in the fortunate position to start with a blank slate unencumbered by legacy technology and systems. We want technology to serve our team and clients and therefore encourage our team to automate and streamline what they can and do it transparently and with accountability.

We have embraced technology to enable our team in supporting clients. Our Know Your Distributor (KYD) solution is a prime example: designed in collaboration with product issuers and distributors, KYD helps streamline due diligence for the whole industry.

No set and forget

In financial services, there’s often a trigger for refreshing risk frameworks, and most recently, APRA’s CPS 230 has prompted firms to take a hard look at their operational resilience and third-party risk settings. But this shouldn’t be a one-off exercise. Risk management is a verb not a framework.

This takes effort from the Boardroom to the front line. And deliberate focus. The tone from the top matters and sets the standard for the firm.

What does good risk management look like? Don’t overthink it – just start with something. Start measuring things – are they useful? If not, change it. Do you need a forum to discuss key risks? Set it up. If it’s not working, change it. It’s a verb. Just do it. Set a process and repeat it, improve it and reap the benefits.

At PX Partners, our risk mindset is essential to how we run our business. We take risks. We learn and respond. As a business servicing regulated clients, we have a high bar to meet. In truth, these are no higher than standards we set for ourselves – to keep improving. It underpins how we serve clients, manage our own business and partnerships, and make decisions. By treating risk as a continuous practice, we stay agile, accountable, and aligned with our mission to deliver trusted outcomes in a complex and evolving world.

Compliance does not conflict with customer outcomes

Doing the right thing always wins in the end. It might not always seem that way but it is true.

We see compliance not as a constraint, but as a catalyst for better customer outcomes. In financial services, it can often feel that compliance with regulatory requirements is just that – a tick the box exercise. But it is not just about meeting the regulatory requirements, it’s about building trust, transparency, and resilience. When compliance is embedded thoughtfully into processes, it strengthens the quality and reliability of the products & services. Regulatory enforcement is littered with examples of firms who should have invested early in robust compliance and governance – from fees for no service to recent MIS failures. A commitment to meaningful compliance from all firms in the chain could have avoided these adverse outcomes for clients.

At PX Partners, we are hugely proud of the level of repeat client work. We don’t shy away from telling our clients what we think is right for them and their end customers. These clients are working with our team to invest in governance, risk and compliance to uplift and enhance what they do which ultimately benefits end customers.

Categories
ausbiz 

Investment Management CPS 230 Webinar

PX Partners recently hosted a webinar exploring what it means to be a CPS230 “Material Service Provider” (MSP) in today’s regulatory and operational landscape. The session covered practical insights and key considerations across the following areas:
  • Roles and responsibilities as an MSP
  • Taking a practical approach to process mapping
  • Establishing effective risk management settings
  • Aligning Business Continuity Plans (BCPs) and Disaster Recovery (DR) strategies
  • Meeting enhanced Due Diligence requirements

Categories
ausbiz 

Risk & Reform Webinar – Insights on AML/CTF, CPS230 and ASIC Compliance Plans

PX Partners recently hosted a webinar to share practitioner insights on:

  • AML/CTF Changes –
    what to watch ahead of AUSTRAC’s 2026 AML/CTF reforms
  • CPS 230 –
    enhanced expectations of APRA-regulated entities and downstream impacts on Material Service Providers (MSPs)
  • Compliance Plans and Controls Uplift –
    aligning with evolving APRA and ASIC expectations

Categories
ausbiz 

Rethinking Scheme Compliance Plans: A Risk-Based Imperative for Responsible Entities

In light of the Australian Securities and Investments Commission’s (ASIC) recent review into  compliance plans across the managed investment industry, Responsible Entities (REs) are being urged to move beyond a legalistic, checkbox approach and adopt a more robust, risk-based mindset. The findings, published in ASIC’s media release 25-090MR, reveal systemic deficiencies in Compliance Plans and large scale non-compliance with Regulatory requirements. 

The Compliance Plan Wake-Up Call

ASIC’s review of 50 compliance plans – covering 1,471 funds and nearly $1 trillion in assets – found that most failed to adequately address key Regulatory obligations. These include:

  • Design and Distribution Obligations (DDO) under Part 7.8A of the Corporations Act;
  • Internal Dispute Resolution (IDR) systems under s912A(1)(h) and associated regulations; and
  • Reportable Situations (RS) under Subdivision B, Division 3 of Part 7.6.

Alarmingly, some compliance plans did not address DDO at all, suggesting they had not been meaningfully reviewed since the regime’s introduction in 2021. ASIC Commissioner Alan Kirkland noted, “Failing to plan is planning to fail,” underscoring the critical role compliance plans play in safeguarding retail investors.

From Legal Formalism to Risk Management

Historically, many Responsible Entities have relied heavily on their legal advisers to draft compliance plans. While lawyers play a vital role in identifying and interpreting the relevant legislative obligations, this approach often results in documents that are technically compliant but operationally ineffective.

What’s missing is the practical application of those obligations – how they are controlled, monitored, and assured in day-to-day operations. This is where risk managers must step in. Risk professionals are best placed to:

  • Translate legal obligations into operational controls;
  • Design assurance mechanisms that test the effectiveness of those controls;
  • Identify gaps and emerging risks; and
  • Ensure the compliance plan evolves with the business and Regulatory landscape.

This shift aligns with ASIC’s broader Regulatory expectations, particularly those outlined in Regulatory Guide 259 (RG 259), which emphasises the need for Responsible Entities to maintain adequate risk management systems under s912A(1)(h) of the Corporations Act. RG 259 complements RG 132 by reinforcing that compliance is not just about documenting obligations – it’s about embedding risk awareness and control effectiveness into the operational fabric of the organisation.

Tailoring Compliance to Scheme-Specific Risks

A key theme emerging from ASIC’s review is the need for compliance plans to reflect the specific risks of each registered scheme. Too often, REs rely on generic templates that fail to consider the unique features, investment strategies, and operational risks of individual schemes. This undermines the effectiveness of the compliance framework and exposes investors to risk.

To meet ASIC’s expectations, REs must be able to demonstrate that their compliance plans:

  • Identify the particular risks associated with each scheme;
  • Include controls that are tailored to those risks;
  • Provide for regular testing and review of those controls; and
  • Are updated in response to changes in the scheme’s structure, strategy, or Regulatory environment.

This was reinforced in ASIC’s recent correspondence with Responsible Entities, where the Regulator raised concerns that some compliance plans did not adequately identify relevant obligations or appropriate controls, and that the same plan was being used across multiple schemes without sufficient customisation.

ASIC’s Direct Engagement with REs

In a clear signal of its intent to drive reform, ASIC has begun writing directly to Responsible Entities whose compliance plans were found wanting. These letters have urged REs to review and modify their compliance plans in line with RG 132 and the findings of the review. ASIC has also reminded REs of their obligation to lodge modified plans under s601HE(3) and to consider their breach reporting duties under the Corporations Act.

What This Means for Responsible Entities

The message is clear: REs must treat compliance plans as living documents that reflect a genuine understanding of their Regulatory obligations and the risks inherent in their operations. This means:

  • Moving beyond generic templates;
  • Embedding compliance into operational processes;
  • Ensuring board and senior management oversight;
  • Tailoring controls to scheme-specific risks; and
  • Being proactive in identifying and addressing gaps.

ASIC has signalled that it will continue to monitor compliance plans and may take enforcement action where deficiencies persist.

What to do?

For Responsible Entities, the time to act is now. Drafting, reviewing and approving takes time. ASIC is expecting industry to act quickly given the issues highlighted in their review. 

PX Partners works with REs to draft fit for purpose and pragmatic Compliance Plans which align with Regulatory requirements and expectations. 

Jon O’Keeffe is the author of this article. Jon provides regulated entities with pragmatic advice on governance anchored in more than 20 years of practitioner experience.

Categories
ausbiz 

Governance: The golden thread holding it all together

Depending who you ask, definitions of Governance vary wildly. Some see governance as something that Boards do, others as reporting or even as an administrative function that adds no value. To us at PX Partners, governance is at the heart of the organisation. It as is the linchpin that connects strategy with planning with risk management, obligations, reporting, and accountability. It is the mechanism through which organisations demonstrate their integrity, resilience, and compliance – especially under the weight of new regulatory expectations like APRA’s CPS 230 and the Financial Accountability Regime (FAR).

The Australian Institute of Company Directors (AICD) defines governance as “the systems that direct and control – or govern – an organisation.” It is fundamentally about relationships between the board, management, and stakeholders and the mechanisms by which authority is exercised and accountability is enforced. As the Hon. Justice Neville Owen described during the HIH Royal Commission, governance is “the framework of rules, relationships, systems and processes within and by which authority is exercised and controlled in corporations”.

This framing is particularly relevant in the current regulatory environment, where governance is not just a structural concept but a dynamic enabler of compliance, performance, and trust. Whether through formal board oversight or embedded operational controls, governance is the thread that weaves together the obligations and expectations placed on financial services entities.

Licensing Obligations: The Foundation of Governance

At its core, governance ensures that entities meet their general licensing obligations under the Corporations Act and ASIC’s Regulatory Guides. These obligations require financial services providers to:

  • • Maintain adequate risk and compliance frameworks.
  • • Deliver services efficiently, honestly, and fairly.
  • • Manage conflicts of interest and ensure appropriate oversight of representatives.

Governance is the structure that ensures these obligations are not only met but embedded in day-to-day operations. It defines who is responsible, how oversight is exercised, and how breaches are identified and addressed. As noted in governance also plays a critical role in how entities assess and report on their service providers, particularly in the context of due diligence and ongoing monitoring.

CPS 230: Governance in Operational Resilience

CPS 230 elevates governance from a compliance function to a strategic imperative. It requires regulated entities to:

  • • Map critical operations and define tolerances for disruption.
  • • Establish governance frameworks that ensure Board and Executive oversight of operational resilience.
  • • Formalise service provider arrangements with clear performance metrics, audit rights, and remediation protocols.

Governance under CPS 230 is not just about structure—it’s about action. Boards must receive regular reporting on risk exposure, service performance, and compliance. Executives must ensure that SLAs, risk assessments, and control testing are not only in place but actively monitored.

FAR: Personal Accountability in Focus

The Financial Accountability Regime (FAR) introduces a new layer of governance by making accountability personal. It requires entities to:

  • • Identify Accountable Persons and assign clear responsibilities.
  • • Maintain accountability maps and statements.
  • • Ensure that governance frameworks support the oversight of these responsibilities.

This means that governance is no longer just about committees and policies—it’s about traceability. As seen in State Super CPS 230 Support – PX Partners – v1.0 – 310125, aligning reporting lines from General Managers to Board Committees is now a regulatory expectation, not a best practice.

APRA’s Governance Review: Raising the Bar

In March 2025, APRA released a discussion paper  proposing eight key reforms to its core governance standards (CPS 510, SPS 510, CPS 520, SPS 520, and SPS 521). The review reflects APRA’s view that while governance practices have improved, significant weaknesses remain—particularly in areas such as director capability, board performance assessment, and conflict management.

The proposals aim to:

  • • Strengthen expectations around board skills, tenure, and independence.
  • • Introduce more prescriptive requirements for fitness and propriety assessments.
  • • Improve transparency and rigour in board performance evaluations.
  • • Clarify and tighten rules around conflicts of interest.

APRA’s message is clear: governance is not a “tick-the-box” exercise. It is a live, evolving discipline that must be embedded in the culture and operations of every prudentially regulated entity.

Governance as the Integrator

Governance connects the dots between:

  • • Risk Management: Ensuring that risk frameworks are embedded and aligned with Board and Executive oversight.
  • • Reporting and Oversight: Defining the cadence, content, and escalation pathways for risk and compliance reporting.
  • • Accountability: Mapping responsibilities under FAR and ensuring traceability of decisions and actions.

The Governance Imperative

In our work with clients across the financial services industry, we’ve seen that the most successful CPS 230 and FAR programs are those that treat governance not as a compliance obligation, but as a strategic enabler. Governance is what allows organisations to:

  • • Translate regulatory expectations into operational reality.
  • • Connect Board-level oversight with frontline execution.
  • • Demonstrate resilience, transparency, and accountability to regulators, customers, and stakeholders.

As the regulatory bar continues to rise, governance is no longer optional—it is the key that unlocks sustainable compliance and long-term trust.

Jon O’Keeffe is the author of this article. Jon provides regulated entities with pragmatic advice on governance anchored in more than 20 years of practitioner experience.

Categories
ausbiz 

PX Partners opens Melbourne office with appointment of new Senior Practitioner

3 February 2025, Melbourne, Australia – PX Partners announces the expansion of its practitioner-led business, appointing Alka Sivapalan as Director to lead the newly established Melbourne office. This strategic move reinforces PX Partners’ commitment to delivering pragmatic and sustainable solutions through a client aligned business model free of structural conflicts of interest.

With a proven track record of delivering superior outcomes for clients, PX Partners is uniquely positioned to meet the needs of Melbourne’s thriving financial services ecosystem with governance, risk and compliance solutions.

Alka Sivapalan, a highly experienced risk and compliance professional, brings more than two decades of experience working in the financial services sector, including roles within the ‘Big 4’ Australian banks, wealth management, insurance, and the aged care industry. Alka has established and led second-line risk teams, developed and implemented risk and compliance frameworks, and spearheaded assurance reviews across complex organisations.

Managing Director, Tanushree Dabral, commented: “We are delighted to welcome Alka to PX Partners and to see our presence grow in Melbourne. Her deep expertise in risk, compliance, and governance, combined with her commercial acumen  will deliver immense value to our clients in Victoria.” Tanushree added that “Alka shares the PX Partners belief that best solutions come from practitioners who understand the commercial realities of running businesses.”

Fellow Managing Director Jon O’Keeffe added: “At a time when businesses are facing high levels of regulatory change and increasing cost pressures, there is more demand for the solutions provided by PX Partners. We are really excited to expand the PX Partners footprint in Melbourne with Alka joining the team to lead the Melbourne office. Alka’s impressive career, including her work with leading financial institutions, aligns perfectly with our mission to deliver practitioner-led solutions.”

Alka commented: “I am thrilled to join PX Partners and lead the Melbourne office during this exciting period of growth. PX Partners has established itself as a leading provider of risk and compliance solutions through the commitment to hands-on, practical solutions and its focus on delivering meaningful impact. I look forward to working with businesses in Melbourne to help them bolster their governance and risk capabilities.” Alka added “I am pleased to be joining a Company that really lives its values as set out in PX for Good, operating a business in an ethical way and genuinely giving back to the community. This resonates deeply with my own values.”

Alka holds a Bachelor of Science and a Masters of Commercial Law from The University of Melbourne, and she is a Graduate of the Australian Institute of Company Directors (GAICD).
For more information on this story please contact:

Mithila Jayaratne
Operational Enablement
PX Partners
Phone: 0421 797 147
Email: mithila@staging.px.partners
Website: www.px.partners

Categories
ausbiz 

KYD Webinar – Distributor Oversight post ASIC Report 795

Following ASIC report 795, PX Partners hosted a webinar to share insights on distributor oversight and explored:

  • What can reasonably be achieved in the context of the Issuer – Distributor relationship.
  • The experience of a large scale product Issuer (Phil Blackmore from Perpetual Corporate Trust).
  • The KYD RegTech Solution – Supporting Issuers and Distributors with efficient and effective oversight

Categories
ausbiz 

PX Partners Managing Director appointed to Board of the Alliance for Gambling Reform

September 2024, Sydney Australia: Jon O’Keeffe, Managing Director of PX Partners, has been appointed to the Board of the Alliance for Gambling Reform, an organization committed to advocating for significant reforms in gambling policies and reducing harm in the community.

Jon brings his extensive experience in risk management, compliance, and governance—skills that will be crucial in supporting the Alliance’s mission to drive meaningful change. His expertise in these areas will help the organisation ensure effective oversight and contribute to shaping strategies that uphold the highest standards of accountability and transparency.

With a deep understanding of financial systems and a strong background in risk, Jon is uniquely positioned to provide the board with valuable insights to guide the Alliance in its pursuit of sensible reforms that are supported by the overwhelming majority of Australians.

Tanushree Dabral, Managing Director of PX Partners, commented on Jon’s appointment:
“We are incredibly proud of Jon’s new role on the Board of the Alliance for Gambling Reform. His extensive experience in risk, compliance, and governance will be instrumental in helping the Alliance achieve its goals. Through our PX for Good program, we are committed to supporting employees in pro bono activities which align with our common values. Jon’s appointment to the Board of the Alliance reflects our dedication to supporting organisations that drive positive societal impact.”

Jon O’Keeffe added: “I am honored to join the Alliance for Gambling Reform. I look forward to contributing to their efforts in reducing the harm caused by gambling through strong governance and strategic oversight. This is an important opportunity to make a difference in the lives of vulnerable individuals and communities.”

– ENDS – 

For more information on this story, or the opportunity to interview the co-founders, please contact Mithila Jayaratne on mithila@staging.px.partners or +61 421 797 147.