The Five Levels of Compliance Maturity for AFSL and ACL Licensees

Compliance maturity is not measured by how much documentation a licensee holds, but by how reliably it turns obligations into evidence, judgement and oversight.

By Product Team·6 October 2026

Many AFSL and ACL licensees appear well organised because they have policies, registers, attestations and reporting packs. Yet those artefacts can conceal a weaker operating reality. Responsibilities are unclear, workflows depend on individuals, evidence sits in separate systems, remediation closes without testing, and reports describe activity without showing whether risk is being controlled.

A useful maturity model distinguishes five operating states: Reactive, Documented, Controlled, Evidence-driven and Governance intelligence. The distinction is not about sophistication for its own sake. It is about the quality of the governance trail a licensee can produce and the quality of decisions that trail supports.

From reaction to governance intelligence

At the Reactive level, compliance work is event-led. Issues receive attention when a complaint escalates, an incident occurs, an audit begins or a regulator asks questions. Records are often reconstructed after the fact. Outcomes depend heavily on who noticed the issue and who had the experience to respond.

At the Documented level, the organisation has policies, registers, templates and assigned roles. This is an important advance, but documentation can create false confidence. A policy may describe what should happen without proving that it happened, who exercised judgement, what evidence was considered or whether remediation worked.

At the Controlled level, key activities follow repeatable workflows. Responsibilities, escalation points, review steps and timeframes are clearer. Exceptions and overdue actions are visible. The weakness is often fragmentation. Complaints, incidents, monitoring, breaches and remediation may each be controlled within their own process but remain disconnected from one another.

At the Evidence-driven level, evidence is generated through the workflow rather than assembled later. Obligations can be linked to controls, decisions, findings, actions and outcomes. Material judgements record the issue, the information considered, the reasoning applied and the approval given. Oversight begins to focus on effectiveness and residual risk, not simply completion.

At the Governance intelligence level, connected evidence is used to identify patterns, emerging risks and capability gaps. The organisation can see whether complaints, incidents, monitoring results and breach assessments point to the same underlying weakness. Reporting becomes risk-weighted and decision-ready. Human judgement remains central, but it is supported by organisational memory and a more complete view of risk.

The most important transition is therefore not from fewer documents to more documents. It is from isolated compliance artefacts to a functioning compliance operating system.

Why the distinction matters

Responsible Managers and boards do not need more information by default. They need evidence that helps them decide where to challenge, where to intervene and where assurance is justified.

A fragmented environment makes that difficult. A control may be marked complete while related complaints continue. A remediation action may be closed without testing whether customer outcomes improved. A breach decision may be recorded without showing the evidence or reasoning behind it. Individually, each record may look acceptable. Collectively, the governance trail is incomplete.

Maturity changes the nature of oversight. At lower levels, reporting answers: What was done? At higher levels, it answers: What changed, what remains exposed, what patterns are emerging, and what requires judgement now?

That distinction matters under regulatory scrutiny because a licensee must be able to explain not only its framework, but how the framework operated in practice. It also matters commercially. Weak evidence slows decisions, increases rework and makes organisational capability dependent on a small number of people.

What this means in practice

Licensees should test maturity with five direct questions:

  1. Can each key obligation be traced to an accountable workflow and current evidence?
  2. Are material decisions supported by a clear and defensible reasoning trail?
  3. Can complaints, incidents, monitoring, breaches and remediation be viewed together?
  4. Is remediation tested for effectiveness rather than treated as complete when tasks close?
  5. Does governance reporting direct attention to risk, themes and unresolved exposure?

The objective is not to reach level five in every process immediately. It is to identify where low maturity creates the greatest governance risk and improve those areas deliberately.

How [complyᵉ] supports this

[complyᵉ] helps licensees structure workflows, connect evidence, maintain decision trails and track remediation across compliance activities. It can also help identify recurring themes and improve the quality of governance reporting by bringing related records into a more coherent operating view.

Technology does not replace professional judgement, legal analysis or governance accountability. Its role is to make the evidence supporting those functions more complete, accessible and useful.

Better systems do not make governance automatic. They make better governance more achievable.

Further reading

Ready to streamline your compliance?

See how Complye can help you manage AFSL and ACL compliance more effectively.

Request a Demo