Small Fintech ASIC Compliance Checklist: Licensing, Disclosure, and Conduct
Small fintechs in Australia cannot launch a product before working out which ASIC licence applies to it.
This single decision, like Australian Financial Services Licence (AFSL), Australian Credit Licence (ACL), or an authorised representative arrangement, determines every disclosure document, conduct obligation, and reporting duty that follows.
Getting it wrong is expensive. ASIC issued over $2.2 million in infringement notices in 2025 to companies that failed to meet reporting obligations alone, and licensing missteps can delay a product launch by months.
Most small fintech teams are lean. They don’t have an in-house compliance department, and founders are often building the product and managing investor relations at the same time as trying to interpret ASIC’s regulatory guides.
This guide by Vista Information breaks the process into four stages: licensing, disclosure, ongoing conduct, and breach reporting. Each stage ends with a checklist item you can act on directly, so you can move from “what does ASIC require” to “what do I do next” without needing to cross-reference five different regulatory guides.
Key Takeaways
- A fintech needs an AFSL if it provides a financial product or advice and an ACL if it provides credit – some fintechs need both.
- ASIC’s Innovation Hub offers free, informal (non-binding) licensing guidance to eligible fintechs and regtechs but it does not replace formal legal advice.
- Design and Distribution Obligations (DDO) require every regulated product to have a Target Market Determination (TMD) before it is sold.
- Fintechs must join the Australian Financial Complaints Authority (AFCA) and maintain an internal dispute resolution (IDR) process before they can operate.
- Breaches must generally be reported within 30 days of becoming aware of them, under the ASIC reportable situations regime.
Do Small Fintechs Need an AFSL or ACL in Australia?
Most small fintechs need either an Australian Financial Services Licence (AFSL) or an Australian Credit Licence (ACL) before they can operate legally.
Which one applies depends on what fintech actually does, not what it calls itself.
When an AFSL Applies
An AFSL is required if a fintech company provides a financial product, financial advice, or deals in financial products on behalf of clients. This covers payment platforms, investment apps, robo-advice tools, and digital wealth products.
When an ACL Applies
An ACL is required if a fintech provides consumer credit, arranges credit, or acts as an intermediary for credit products. Buy-now-pay-later and lending platforms typically sit in this category, though recent reforms have brought more BNPL providers under credit licensing.
Can a Fintech Operate as an Authorised Representative Instead?
Yes. A fintech can operate under another AFSL or ACL holder’s licence as an authorised representative, rather than holding its own licence. This is often the fastest way to launch, though it means the fintech operates within the licence holder’s compliance framework rather than its own.
Working out which category a product falls into is rarely obvious from ASIC’s guides alone. It depends on the specific product structure, and many fintechs bring in legal research support services to test their licensing position before committing to a build.
How Does ASIC’s Innovation Hub Help Fintechs Before Licensing?
ASIC’s Innovation Hub gives eligible fintechs and regtechs free, informal guidance on licensing before they submit a formal application.
To qualify, a business must be developing an innovative financial product or service and either need an AFSL/ACL, be in the process of getting one, or have held one for less than 12 months.
The process runs in four stages: submission, evaluation (about one week), a response confirming whether the business meets the requirements, and if it does, either email guidance or a meeting within two to three weeks.
Importantly, ASIC does not provide legal advice through this service and does not endorse any business it assists. It also won’t tell you with certainty whether your particular product requires a license; the firm will still make that decision.
Because of this gap, many small fintechs turn to financial research outsourcing to interpret ASIC guidance against their product design, rather than assuming informal assistance covers the full picture. A specialist research consultancy in Australia can run this analysis faster than an in-house team without compliance expertise.
What Disclosure Documents Does ASIC Require From Fintechs?
Every licensed fintech must give customers specific disclosure documents before a sale, and the document required depends on the product type.
Financial Services Guide (FSG)
An FSG explains who the fintech is, what services it offers, and how it’s paid. It must be given to a client before providing a financial service.
Product Disclosure Statement (PDS)
A PDS sets out a product’s features, costs, and risks. It’s required for most financial products before a customer buys.
Target Market Determination (TMD) Under Design and Distribution Obligations (DDO)
Every regulated product must have a Target Market Determination (TMD), which is a document outlining the product’s intended market and the circumstances under which it may be delivered, according to Design and Distribution Obligations (DDO). A TMD must exist before the product is sold, not drafted retroactively.
What Ongoing Conduct Obligations Apply Once a Fintech Is Licensed?
Holding a licence is not a one-off achievement; it comes with ongoing conduct obligations that apply for as long as the fintech operates.
Responsible Manager Requirements
An AFSL or ACL holder must appoint at least one responsible manager with relevant skills and experience, who oversees compliance with licence conditions.
Anti-Hawking Provisions
Fintechs cannot sell certain financial products through unsolicited contact, such as cold calls or unsolicited meetings, unless a specific exemption applies.
Internal Dispute Resolution and AFCA Membership
Every licensed fintech must maintain an internal dispute resolution (IDR) process and join the Australian Financial Complaints Authority (AFCA). This must be in place before the fintech starts dealing with customers, not arranged after the first complaint arrives.
What Happens If a Fintech Breaches ASIC’s Reportable Situations Regime?
If a fintech breaches its licence obligations, it must generally report this to ASIC within 30 days of becoming aware of the breach, under the reportable situations regime.
Failing to report is treated separately from the original breach, and can carry its own penalty. In 2025, ASIC issued over $2.2 million in infringement notices to 12 companies for failing to lodge required reports. A reminder that reporting delays, not just the underlying conduct, attract enforcement attention.
Persistent or serious non-compliance can also lead to licence conditions being varied, suspended, or cancelled.
What Does an ASIC Compliance Checklist Look Like for a Small Fintech?
| Phase | Checklist Item |
| Pre-licensing | Confirm whether the product needs an AFSL, ACL, or both |
| Check eligibility for ASIC Innovation Hub informal assistance | |
| Consider an authorised representative arrangement as a faster path to market | |
| Licensing | Appoint a responsible manager with relevant experience |
| Submit a complete AFSL/ACL application with supporting policies | |
| Disclosure | Prepare an FSG before any client-facing service begins |
| Prepare a PDS for each regulated product | |
| Complete a TMD under DDO before the product is sold | |
| Ongoing conduct | Confirm anti-hawking compliance for any outbound sales contact |
| Join AFCA and establish an IDR process before launch | |
| Set a 30-day internal deadline for reportable situations assessment |
Running through this checklist once doesn’t cover a fintech long-term – obligations shift as products, distribution channels, and customer bases change. This is where ongoing business intelligence services & solutions add value: tracking regulatory changes, competitor licensing moves, and market shifts that affect a fintech’s compliance position over time, rather than treating the checklist as a single pre-launch exercise.
How Should Small Fintechs Approach ASIC Compliance From Here?
Licensing, disclosure, and conduct obligations aren’t separate hurdles for a small fintech to clear one at a time, they’re connected. The licence type determines the disclosure documents required, and both shape the ongoing conduct obligations that follow.
Getting this sequence right before launch avoids the costlier alternative: retrofitting compliance after ASIC flags a gap.
Vista Information has spent almost 20 years helping firms across Australia’s financial sector interpret exactly this kind of regulatory detail, combining research rigour with the intelligence services fintechs need to make confident licensing decisions early.
Not sure whether your product needs an AFSL, an ACL, or both? Vista Information can review your product structure against current licensing requirements and flag what’s missing before you approach ASIC.



