ASIC · Package 4 · RG 205
Australian Credit Licence — General Conduct Obligations Compliance Plan

Credit Licence Compliance Plan

Aligned with ASIC Regulatory Guide 205 Credit licensing: General conduct obligations and the general conduct obligations set out in s.47(1) of the National Consumer Credit Protection Act 2009 (Cth). To be submitted as Annexure C to Form CL01 in Year 2.

DRAFT v1.0 · Attachment I to Package 4

1. Purpose and Scope

This Compliance Plan documents how Life Without Debt Ltd (the Company) will comply, on an ongoing basis, with:

  1. each of the 11 general conduct obligations in s.47(1) of the NCCP Act;
  2. the responsible-lending obligations in Chapter 3 of the NCCP Act (to the extent they apply to a credit-assistance provider under s.115);
  3. the National Credit Code (Schedule 1 to the NCCP Act), where applicable;
  4. ASIC Regulatory Guides 203–210 (credit licensing suite) and RG 271 (Internal Dispute Resolution);
  5. the Company's obligations as a registered charity under the ACNC Act, Governance Standards 1–6, and its Constitution.

Where a general conduct obligation is inherent to the Company's charitable purpose (e.g. acting efficiently and fairly), this Plan explains how the ACNC obligation and the ASIC obligation are satisfied by the same control.

2. Compliance Ownership and Governance

RoleCompliance Responsibility
Board of DirectorsOverall accountability for the Compliance Plan. Reviews compliance reports at every scheduled meeting. Approves annual attestation and any material updates.
Audit and Risk CommitteeOversees compliance framework, breach register, internal audit findings, insurance renewals and PI cover adequacy.
Chief Executive OfficerExecutive accountability for day-to-day compliance. Certifies quarterly compliance report to the Board.
Chief Compliance Officer (CCO)Owns this Plan. Maintains policy register, breach register, complaints register, training register. Prepares quarterly compliance report and annual RG 205 attestation.
Responsible ManagersDay-to-day supervision of credit activities. Sign off on debt-negotiation strategies. Ensure staff working under them meet training requirements.
All staff and volunteersComply with policies. Immediately report breaches, complaints, potential conflicts, and material risk events to the CCO.

3. General Conduct Obligations — Controls Mapping

s.47(1)ObligationControls / Evidence
(a) Do all things necessary to ensure credit activities are engaged in efficiently, honestly and fairly Case management system with defined SLAs; documented debt-negotiation methodology; four-eyes review before any settlement proposal is put to a creditor; beneficiary written consent for every negotiation contact; no-fee model formalised in the Constitution.
(b) Have in place adequate arrangements to ensure clients are not disadvantaged by conflicts of interest Conflicts of Interest Policy (ACNC Attachment D); Register of Conflicts; mandatory disclosure by Directors, staff and Responsible Managers; annual attestation; standing conflicts already registered (Laurence Hugo, Lisa Hugo, Carla Oliver).
(c) Comply with the credit legislation Legal-obligations register maintained by the CCO with quarterly review against ASIC updates. External legal advice retained for material regulatory changes.
(d) Take reasonable steps to ensure representatives comply with the credit legislation Training program (see section 4); supervision matrix mapping every credit-activity staff member to a Responsible Manager; sample-based file reviews (10% of files quarterly); annual compliance attestation by every credit-activity staff member.
(e) Have adequate arrangements and systems to ensure compliance with credit legislation and this Compliance Plan This Compliance Plan; policy suite; breach register; training register; complaints register; case management system with audit trail; annual internal audit; annual external compliance review.
(f) Have a written procedure for supervising representatives Supervision Procedure — annexure to this Plan — sets out supervisor-to-staff ratios, review cadence, escalation triggers.
(g) Ensure representatives are adequately trained and competent Induction program (2 weeks) covering NCCP Act, responsible-lending concepts, hardship provisions of the National Credit Code, AFCA processes, privacy, vulnerable-consumer identification; annual 20-hour continuing education; competency assessments; training register.
(h) Have an internal dispute resolution procedure and be a member of AFCA IDR procedure compliant with RG 271 (see section 5); AFCA membership; complaints register; public-facing complaints information on website and in every beneficiary engagement letter.
(i) Have compensation arrangements Professional indemnity insurance of $[2M/claim, 2M aggregate] from an APRA-regulated insurer, sized per RG 210. Renewed annually with Audit and Risk Committee review.
(j) Have adequate resources — human, technological, financial — to engage in credit activities and to ensure ongoing compliance Board-approved annual budget with dedicated compliance line item; case management system with capacity monitoring; workforce plan; NTA compliance with RG 207.
(k) Have adequate risk management systems Risk management framework aligned with ISO 31000; risk register reviewed quarterly by the Audit and Risk Committee; risk appetite statement approved annually by the Board.

4. Training and Competency

  • All credit-activity staff must hold, or be working towards, a Certificate IV in Finance and Mortgage Broking or an equivalent qualification recognised in ASIC RG 206.
  • Responsible Managers must hold at least a Diploma of Finance and Mortgage Broking Management, or a legal qualification with at least 2 years' consumer-credit experience.
  • Induction: 2-week structured program covering the NCCP Act, National Credit Code (particularly hardship provisions in s.72), responsible lending, AFCA, privacy, vulnerable-consumer identification, end-of-life communication skills.
  • Ongoing: minimum 20 hours of continuing education per year, including at least 4 hours on regulatory updates.
  • Training register maintained by CCO; annual training report to the Board.

5. Complaints and Internal Dispute Resolution (RG 271)

  1. Acknowledgement — within 24 hours of receipt.
  2. IDR response — final IDR response within 30 calendar days for standard complaints and 21 calendar days for financial-hardship-related complaints, per RG 271.
  3. Every IDR response includes the client's right to escalate to AFCA within the applicable time limits, and AFCA's contact details.
  4. Complaints register maintained by the CCO. Systemic issues reported to the Board and, where required, to ASIC as reportable situations under s.912D of the Corporations Act (as applied under s.50A NCCP Act).
  5. Special protocol for beneficiary complaints: because beneficiaries are, by definition, in end-of-life care, IDR responses are prioritised and, where the beneficiary is deceased, the Company will continue the process with the beneficiary's legal representative or executor.

6. Vulnerable Consumer Protections

Every beneficiary of the Company is, by definition, a person with a terminal illness. The Company adopts a "vulnerability-as-baseline" approach:

  • Written consent, with a 48-hour cooling-off period, obtained before any creditor contact is made.
  • Beneficiaries offered the option of a nominated support person or advocate at every stage.
  • Referral pathway to independent financial counselling (via National Debt Helpline 1800 007 007) provided at intake and documented.
  • No pressure sales — the no-fee model is confirmed in writing and repeated at each engagement.
  • Staff trained in Advanced Vulnerable Consumer identification (ACCC / ASIC joint guidance) and in end-of-life communication.
  • Automatic escalation to a Responsible Manager if any indicator of coercion, elder abuse or diminished capacity is identified.

7. Record-Keeping

The Company will retain the following records for the longer of (a) seven years from the end of the financial year to which they relate, or (b) any longer period required by the National Credit Code, the Corporations Act, the ACNC Act, or the Privacy Act 1988 (Cth):

  • Beneficiary case files (intake, consents, correspondence, settlement records);
  • Compliance breach register;
  • Complaints register and IDR responses;
  • Training register and competency assessments;
  • Board minutes and resolutions;
  • Financial records (per s.286 Corporations Act and the ACNC record-keeping standard);
  • Reportable situations lodged with ASIC.

8. Breach Reporting and Reportable Situations

All staff must report a potential compliance breach to the CCO immediately on becoming aware of it. The CCO logs it in the breach register and assesses:

  1. whether the situation is a reportable situation under s.50A NCCP Act (as amended by the Financial Sector Reform Act 2020);
  2. if so, the CCO lodges an ASIC notification within 30 calendar days of the Company first knowing that there are reasonable grounds to believe the situation has arisen;
  3. the CEO and Chair are informed on the same day the assessment is completed;
  4. a summary is presented at the next Audit and Risk Committee meeting and the next Board meeting;
  5. affected beneficiaries are informed and, where applicable, remediation is offered — funded, if necessary, from the operating budget (not from restricted-donor or beneficiary-relief funds).

9. Monitoring, Assurance and Attestation

  • Quarterly — CCO delivers a written compliance report to the Board covering breach register, complaints register, training compliance, PI cover status, AFCA correspondence, and ASIC correspondence.
  • Semi-annually — file-review sample of at least 10% of active cases, focusing on consent, disclosure, conflict-of-interest identification, and IDR handling.
  • Annually — external compliance review by an independent credit-industry consultant. Findings tabled at the Audit and Risk Committee and remediated to a documented plan.
  • Annually — CEO signs an attestation to the Board that this Compliance Plan has been complied with in all material respects during the year, with any exceptions noted.
  • Annually — Board approves any updates to this Plan and re-attests to it as part of the ASIC Annual Compliance Certificate.

10. Interaction with ACNC Governance Obligations

This Plan is designed to be complementary with — not additional to — the Company's obligations under the ACNC Governance Standards 1–6 (Attachment C to the ACNC application). Specifically:

  • Governance Standard 1 (Purposes and not-for-profit) is discharged by ensuring credit activities remain within the charitable-purpose limbs of the Constitution (clause 4).
  • Governance Standard 4 (Suitability of Responsible People) overlaps with the RG 206 responsible-manager fitness standard; the same evidence base is used.
  • Governance Standard 5 (Duties of Responsible People) is enforced via the Board Charter and Directors' induction.
  • The Reserves Policy (Attachment F) ensures the Company can meet the RG 207 minimum financial requirements.
Independent compliance review required before lodgement

Before this Compliance Plan is submitted to ASIC as Annexure C to Form CL01, it must be reviewed and updated by an independent Australian credit-licensing compliance consultant (or by an Australian lawyer with credit-licensing expertise). The controls must reflect the Company's actual systems, staffing and technology at the date of lodgement — not the aspirational state described here.