Buried in a consumer warning ASIC published on 13 August 2026 is one of the more useful control findings of the year. Reporting a surveillance of nine named online brokers conducted between March and June 2026, the regulator listed among its concerns "[o]nboarding shortcomings, including limited tailoring of questions to client circumstances and repeated or unlimited attempts to pass onboarding questionnaires".
Read quickly, that is a complaint about a questionnaire. Read properly, it is a statement that a control which cannot be failed is not a control, and that the evidence it generates is worse than no evidence at all.
What did ASIC actually find?
The surveillance covered nine entities, named in the release: Interactive Brokers Australia, Moomoo Securities Australia, Sharesies Australia, Stakeshop AFSL, tastytrade Australia, Tiger Brokers (AU), Totality Wealth, Trading 212 AU and Webull Securities (Australia). ASIC is explicit that those results must not be read back onto any firm individually: "[t]he surveillance findings are presented thematically and are not attributed to individual entities and did not apply to every entity reviewed". Nothing that follows is a finding against a particular broker. ASIC also found deficiencies in some target market determinations, "including insufficient detail on how products met the likely objectives, situations and needs of clients".
The outcomes matter as much as the findings. As at the date of the release, ASIC records that "[f]ive entities have improved their compliance practices", including "two entities who have stopped onboarding options clients while remediation work is underway", and that "[o]ne entity has exited the Australian market since ASIC's review". It closes by noting it "is continuing to address concerns with some entities and is considering further regulatory or enforcement action in relation to matters identified in the review".
Commissioner Simone Constant put the obligation in continuing terms: entities offering complex or high-risk products "must ensure their products are distributed to the right target market, not only at onboarding but throughout the client relationship", requiring "effective product governance, including appropriate onboarding, ongoing client monitoring and clear disclosures that explain the real risks and costs involved".
That last point does independent work. A gate is a moment. The obligation is a period.
Why is the retry policy the control?
Take the ordinary purpose of a knowledge or suitability questionnaire. It exists to separate clients who understand a product from clients who do not, so that distribution is consistent with the target market. The reasonable-steps obligation on distributors sits at section 994E of the Corporations Act, headed "Reasonable steps to ensure consistency with target market determinations", inside the design and distribution regime in Part 7.8A.
Now allow unlimited attempts. Every client who wants the product passes eventually, because a fixed question set with unbounded retries converges. Nobody is excluded. The cohort the gate was built to stop is fully inside it.

The second-order effect is the dangerous one. The gate still writes a record. Every file now contains a completed questionnaire with a passing score, which is exactly what a controls tester, an internal auditor or a regulator would expect to see in a compliant file. The artefact that was meant to evidence the control instead conceals its absence, and it does so at scale, in a form that survives sampling.
That last point deserves weight, because it is why this defect can persist for years inside an organisation that tests its controls properly. Attribute testing samples files and asks whether the required evidence is present. In a population where every client passed, every sampled file passes, and the sample size makes no difference: a defect with a 100 percent pass rate is invisible to a test designed to detect exceptions. Finding it requires a different question, asked of the population rather than the sample, which is how many attempts each client took. That data usually exists and is almost never looked at, because nobody specified it as a control attribute in the first place.
This is not hypothetical. In March 2026 ASIC announced that Binance Australia Derivatives had been ordered to pay a $10 million penalty, having admitted "serious failures in client onboarding and poor staff training that allowed clients seeking to be verified as sophisticated investors to make unlimited attempts at a multiple-choice quiz until they achieved a passing score". The consequence ASIC recorded was misclassification of "more than 85% of its Australian client base over a nine-month period", producing "$8.66 million in client trading losses" and "$3.89 million in fees".
More than 85 percent. That is what a gate with no attempt limit does to a client base.

What changes when the customer has an agent?
Here the analysis becomes ours rather than ASIC's. Nothing in the 13 August release mentions AI, automation, algorithms or models, and it should not be represented as an AI finding.
But the defect has an obvious trajectory. An unbounded retry allowance is safe only because of an unstated assumption: that a human attempting a questionnaire bears a real cost in time, attention and patience, and that most will stop. Attempt limits have been under-engineered for years because human impatience was doing the work.
A client using an agent bears none of that cost. The same questions, answered differently, at machine speed, until the combination passes. Where the question set is fixed, the answers are scoreable and the attempts are unlimited, the outcome is arithmetic. And unlike the trading conduct ASIC examined in its work on agentic execution and the purpose problem, this needs no sophistication at all. It is a form submitted repeatedly.
The other direction of travel matters too. Firms are rebuilding onboarding with conversational and model-assisted front-ends, which are genuinely better at "limited tailoring of questions to client circumstances", the other half of ASIC's finding. A conversational gate can adapt its questions to a client's stated experience in a way a static form cannot. But a rebuilt front-end inherits the attempt-integrity question, and there is nothing about a conversational interface that answers it. If anything, an interface that regenerates its questions each session makes attempt counting harder to see, and a session that can simply be restarted is an unlimited retry by another name.
This is the same structural point as gating what an agent is allowed to do before it acts, turned around to face the customer.
Where else does this gate design exist?
The DDO exposure is sharpest for distributors, but the design question is generic, and this is the part worth taking to a control owner rather than a lawyer. Any automated step that exists to exclude a cohort has an attempt policy, whether or not anyone chose it deliberately.
Consider where these sit: sophisticated and wholesale investor assessments, knowledge checks before complex or leveraged products, eligibility and pre-qualification steps, hardship and vulnerability triage, identity and verification flows, and the various suitability declarations that gate access to a feature. In most organisations at least one of those has no attempt limit, because nobody specified one and the default is unbounded.
Four design decisions convert the artefact back into a control: an enforced attempt limit, a cooling-off period between attempts, variation in the question set across attempts, and tracking of answers that change between attempts. The last is the most useful and the least implemented. A client whose stated trading experience changes between attempt one and attempt three has told you something specific, and that signal is generally discarded.
None of the four is technically difficult, and that is worth saying plainly to anyone who owns a remediation budget. Each is a configuration decision rather than a rebuild, and the hard part is not engineering but ownership: deciding who is accountable for the number, what it is, and on what evidence it was set. A limit of three with a twenty-four hour cooling-off is defensible if someone chose it and can say why. An unbounded limit is equally a choice; it is simply one nobody made deliberately.
The evidence position follows from Constant's framing. If the obligation runs throughout the client relationship rather than at onboarding, then the attempt history is not a transient log to be purged at session end. It is part of how a firm demonstrates the steps it took, and it is the sort of operational record that ASIC's supervisory posture on AI expects an entity to be able to produce. It is also worth noting that on 6 August 2026 ASIC announced the suspension of a contracts-for-difference issuer's licence, effective from 23 July to 18 December 2026, on grounds that included that it "did not have adequate financial resources, technological systems and staffing". Systems adequacy is itself a licensing obligation, not merely an input to one.
None of this displaces the product governance work that sits above it, including the target market and personalisation questions that decide who should be reached in the first place. It sits underneath: once a target market is defined, the gate is what enforces it, and a gate that cannot be failed enforces nothing.
Bottom line
ASIC has described, in a consumer warning, a control defect that is trivially cheap to fix and expensive to leave. Unlimited attempts do not make a gate lenient; they remove it while continuing to generate the paperwork of its operation. The $10 million penalty in March established what the consequence looks like when the defect meets a real client base. The retry policy is the control, it is a design decision someone must own, and it needs to be verified rather than assumed on every automated gate an organisation runs.
Do this Monday
- List every automated gate that exists to exclude a cohort, including knowledge checks, sophisticated investor tests, eligibility steps and vulnerability triage, and record for each whether an attempt limit is enforced in the system rather than described in a procedure
- Pull the attempt logs for each gate and produce the distribution of attempts to pass, because a long tail is the fastest evidence that the gate is not screening
- Check whether answers that change between attempts are retained, and treat a material change in stated experience as a signal to review rather than a keystroke to overwrite
- Confirm whether restarting a session resets the attempt count, since an unlimited retry frequently hides behind a new session rather than a new submission
- Review any conversational or model-assisted onboarding front-end specifically for attempt integrity, because the tailoring improvement and the attempt control are separate features and only one of them tends to get built
- Re-test the reasonable-steps position for any product whose gate has no attempt limit, and record the date the defect was identified so the remediation clock is visible
- Extend monitoring past onboarding for the products where the obligation is continuing, and name the trigger that would cause a client's classification to be revisited
This article is general information and education only. It is not legal advice or compliance advice, and it is not advice about any particular product, licensee or obligation. Regulatory obligations turn on the specific circumstances of each entity. The extension of ASIC's findings to AI-assisted and agent-mediated onboarding is analysis by TheAICommand and is not a finding or position of ASIC. Seek advice specific to your organisation.
Primary sources
- ASIC, ASIC warns retail investors about risky products offered by online brokers, 26-193MR, 13 August 2026. https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-193mr-asic-warns-retail-investors-about-risky-products-offered-by-online-brokers
- ASIC, Binance Australia Derivatives ordered to pay $10 million penalty for onboarding failures causing millions in client trading losses, 26-055MR, 27 March 2026. https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-055mr-binance-australia-derivatives-ordered-to-pay-10-million-penalty-for-onboarding-failures-causing-millions-in-client-trading-losses
- ASIC, ASIC suspends AFS licence of CFD issuer GFA Capital Markets, 26-183MR, 6 August 2026. https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-183mr-asic-suspends-afs-licence-of-cfd-issuer-gfa-capital-markets
- Federal Register of Legislation, Corporations Act 2001, Compilation No. 147 (C2026C00339), registered 28 July 2026, Part 7.8A Division 3, section 994E. Section 994E is unaffected by the amendments in force from 27 August 2026. https://www.legislation.gov.au/C2004A00818/2026-07-01/2026-07-01/text
TheAICommand. Intelligence, At Your Command.


