The Compliance Checklist Every Insurance Broker Needs Before an Audit

Most brokerages that fail an ASIC compliance audit already had a compliance framework in place. What they lacked was evidence that the framework was being applied, call by call and file by file. This article sets out the five documentation categories ASIC checks first, the specific gap between having a policy and proving it, and a practical checklist a brokerage can run as an ongoing operational standard rather than a pre-audit scramble.
Why This Matters Right Now
Brokerages rarely fail a compliance audit on the obligations they have never heard of. They fail on the ones they assumed they were meeting.
ASIC's surveillance activity has stepped up rather than eased off. In its 2024-25 annual report, the regulator recorded a 50% increase in investigations and completed 829 targeted surveillances across the financial services sector. That is a wider net, and it means more licensees are being asked to produce evidence, not just describe their processes.
For a brokerage that has already worked through its AFSL obligations, the checklist below is the operational layer that sits underneath it.
It also builds on current ASIC compliance requirements and what a compliant brokerage is expected to look like in practice.
And it complements the groundwork covered in preparing for an ASIC audit: this checklist is what that preparation should be able to produce on demand. A policy answers what the brokerage says it does. A checklist, tested against real files and real calls, answers what it can actually show.
This distinction is where most audit findings originate. The framework exists. The evidence trail behind it is thinner than anyone realised until someone was asked to produce it on short notice.
targeted surveillances completed by ASIC in 2024-25
year-on-year increase in ASIC investigations
in court-ordered civil penalties secured by ASIC in 2024-25
Your checklist is only as strong as the records behind it.
Callyx.ai turns every recorded call into evidence you can produce the moment it is requested.
The Five Documentation Categories ASIC Checks First
An ASIC review does not start with a broad question about culture or intent. It starts with a request for specific documents, and the request tends to follow a predictable pattern across five categories.
General obligations evidence
Corporations Act 2001 (Cth) s912A
Licensees must show how they meet the general obligations set out in the Corporations Act, including having adequate risk management systems and taking reasonable steps to ensure representatives comply with financial services laws.
Personal advice records
ASIC Instrument 2024/508
Statements of Advice and Records of Advice need to exist, be complete, and be retrievable for seven years, including where the representative has since left the business.
Internal dispute resolution records
IDR process and outcomes
A complaints register that lists outcomes without showing how each complaint was investigated and resolved does not meet what a review of internal dispute resolution processes expects to see.
Training and competence records
Corporations Act 2001 (Cth) s912A(1)(f)
Evidence that representatives completed the training they were assigned, when they completed it, and what they were assessed on.
Monitoring and supervision evidence
ASIC Regulatory Guide 104
ASIC's regulatory guide sets out an expectation that a brokerage can show how advice is actually delivered, not just that a supervision policy exists on paper. This sits alongside, rather than instead of, the general obligations above.
Licensees must show how they meet the general obligations set out in the Corporations Act, including adequate risk management systems.
ASIC's regulatory guide builds on that statutory base and sets out what the regulator looks for in the supervision and compliance arrangements built around it.
Since September 2024, record-keeping requirements for personal advice have required these records to be kept for seven years and produced on request.
Each category sounds administrative until a reviewer asks for a specific example rather than a general description. That is usually where the gap becomes visible.
These five categories are not arbitrary. They broadly reflect the areas ASIC's surveillance and review work commonly examines across licensees of every size, from single-adviser brokerages to firms with dozens of authorised representatives. A reviewer working through a file is not looking for perfection. They are looking for a consistent pattern of evidence across all five categories, applied the same way regardless of which representative handled the file or which product was being discussed. A brokerage that is strong on personal advice records but has never tested its internal dispute resolution process against a real complaint has not closed the gap. It has simply moved it to a different category.
For an insurance brokerage specifically, these categories rarely sit in isolation. A single client renewal call can touch four of the five at once: the adviser makes representations that fall under general obligations, the call may constitute personal advice requiring a record, a client query midway through the call can look very like the start of a complaint, and the way the adviser handles that moment says something about how well their training has actually landed. Treating the categories as five separate compliance projects misses how closely they are tied together in the calls a brokerage runs every day.
The Gap Between Having Documents and Proving Application
A brokerage can have every policy listed above and still fail to produce what ASIC asks for, because policies describe intent and reviews test application. Take duty of disclosure as an example: a brokerage may have a documented policy that every adviser is trained on, but a review tests whether disclosure was actually given, in the specific words used, on a specific client call. File notes can say disclosure occurred. They cannot show what was actually said, and for many firms, the call itself was never reviewed to confirm it.
The same gap shows up around best interest duty. The duty is well understood in policy terms. Whether a particular piece of advice, delivered verbally, actually met that standard is a different question, and one that a written file often cannot answer on its own.
1. File notes describe intent, not the actual conversation
A file note can say disclosure occurred. It cannot show what was actually said, and for many firms, the call itself was never reviewed to confirm it.
2. Training records disconnected from advice files
A completed training module and assessment says nothing about whether a representative applied what they learned on a call weeks later.
3. Complaints closed without evidence of how they were handled
A register that shows a complaint was logged and closed does not show how the initial conversation was handled or whether escalation happened within a reasonable timeframe.
This is not a case of brokerages ignoring their obligations. It is a structural gap: the parts of the business most exposed to compliance risk, live advice conversations, are also the parts least likely to be systematically reviewed. Spot-checking a small sample of calls each month can create a false sense of coverage while leaving most conversations unreviewed and unaccounted for.
The pattern repeats across internal dispute resolution as well. For many brokerages, the earliest and most revealing evidence of how a complaint was actually managed exists only in the original call, and that call is often the one piece of the file nobody thinks to check until it is requested.
None of this is unique to any one product line, or to firms that have historically had compliance issues. The hidden compliance risk in a brokerage's day-to-day phone calls rarely announces itself as a red flag at the time. It sits inside the ordinary, unremarkable renewal call or claims conversation that nobody thought to review, which is exactly why a checklist built only around documents will miss it, and a checklist built around the calls themselves will not.
Most compliance checklists cover documents. They rarely cover what was actually said on the call.
Callyx.ai reviews 100% of your recorded calls against your compliance obligations automatically, so the gap between policy and practice stops being a guessing game.
Book a DemoWhat Audit-Ready Actually Looks Like
"Audit-ready" is not an ASIC-defined term, but a practical working definition is useful here. Audit-ready is not a folder of policies updated the week before a review. It is a standing checklist that can be tested at any time, against any file, without preparation. In practice, that means each of the five documentation categories carries a defined risk level and a defined way of proving compliance, not just describing it.
| Checklist category | Risk level | What proves it |
|---|---|---|
| Personal advice records and verbal disclosure | Highest | Retrievable evidence per file, not a policy summary |
| Internal dispute resolution and monitoring evidence | Medium | Consistent application across complaints and calls, not just a register entry |
| Training and competence records | Lower, but not optional | Current completion and assessment records for every representative |
A brokerage that can pull a random file or a random call and show, without notice, how it meets each category is in a fundamentally different position from one that can only produce a policy manual. The risk rating matters because it determines where limited compliance resources should go first: personal advice records and verbal disclosure carry the most direct exposure, so they warrant the most review time.
The risk rating is only half of the picture. The consequence side matters just as much. A gap in personal advice records can have more significant regulatory consequences, particularly where it affects the ability to demonstrate compliance or respond to a client complaint, while deficiencies in training records may be identified during supervisory reviews depending on the circumstances. Mapping both risk and likely consequence against each category is what turns a checklist from a filing exercise into something that actually changes where a brokerage spends its compliance attention.
How Callyx.ai Fits
The categories that are hardest to prove on request are the ones tied to what was actually said on a call: disclosure, advice content, and how a complaint was first raised and handled. These are also the categories a compliance officer has the least practical ability to review at scale using manual sampling.
Every call becomes evidence
Callyx.ai listens to every recorded call and flags where the compliance elements a checklist requires, disclosure statements, advice language, complaint indicators, were or were not present.
Closes the disclosure and advice gap
Instead of a compliance team sampling a handful of calls a month, every call becomes reviewable evidence.
Answers requests before they're made
When a reviewer asks for a specific file, the call-related sections of the checklist are already answered rather than reconstructed after the fact.
This does not replace the documentation categories that sit outside call data, training records or IDR case files, for example. It closes the specific gap explored above: the distance between a policy that says disclosure happens and proof that it did, on a particular call, for a particular client.
Turning the Checklist Into an Ongoing Standard
A checklist run once before an audit tells a brokerage what it looked like on one day. Run continuously, it tells a brokerage what it actually looks like most of the time. Five practical steps make the difference, usually coordinated by whoever holds the compliance officer role in the business.
Consolidate the five categories into a single checklist
Rather than five separate policy documents referenced from memory, keep one list, reviewed as one artefact.
Assign an owner per category
Even where the role is shared across other responsibilities, one person should be accountable for each category.
Test it against a real file and a real call each month
Not a hypothetical scenario. Pull one at random and see what the checklist can actually produce.
Review the checklist quarterly rather than annually
This is a practical recommendation, not a regulatory requirement, but many firms find that annual review cycles miss changes in ASIC's areas of focus and leave gaps unnoticed for months at a time.
Automate the categories tied to call recording compliance
This is usually the step brokerages defer longest, not because the category matters less, but because reviewing every call manually does not scale.
Call recording compliance is the category most exposed to manual review gaps and most improved by systematic, rather than sampled, coverage.
None of these steps require a larger compliance team. They require the checklist to be treated as something the business runs against continuously, rather than something it assembles when a review letter arrives.
Summary
The brokerages that struggle in an ASIC review are rarely the ones without a compliance framework. They are the ones whose framework cannot be tested on demand, particularly around what was actually said in client conversations rather than what a policy document says should have been said. A checklist built around the five documentation categories, applied continuously and tested against real files rather than assumed compliance, closes most of that gap. The categories tied to call content are the hardest to keep current through manual review alone, which is where Callyx.ai fits: turning every recorded call into evidence the checklist can already answer, rather than evidence that has to be reconstructed after a request lands.
2026 Compliance Checklist
General obligations evidence
Corporations Act s912A and ASIC Regulatory Guide 104
Personal advice records
Instrument 2024/508 record-keeping requirements
Internal dispute resolution records
IDR process and outcomes
Training and competence records
Representative training and assessment
Monitoring and supervision evidence
How advice delivery is actually reviewed
Frequently Asked Questions
About the Author
Vincent Keogh
Vincent is an operations specialist on the Callyx.ai team, writing for compliance managers and principals on how to get maximum value from recorded calls: across compliance, staff training, and business performance.
Related Articles
This article is general information only and does not constitute legal or financial advice. It does not take into account the specific circumstances of any individual Australian financial services licensee. Brokerages should seek advice from a qualified professional regarding their own compliance obligations under the Corporations Act 2001 (Cth) and applicable ASIC instruments and regulatory guidance.
Your calls are already being recorded.
Now make them count.
Recorded advice conversations are reviewed against your compliance criteria, with issues flagged and documented. Less reliance on sampling. Fewer blind spots.