Study this subject by regime identification. For every scenario, name the duty-holder, the trigger that engages the regime, and the specific obligation, then state a justified decision and note interactions between regimes. The six domains — the AFS regulatory framework, director duties, AML/CTF, privacy, whistleblower protections, and competition and consumer protection — all reward this same answering structure.
Where the six compliance domains overlap and where they stay separate
The domains share one goal — governing conduct risk — but they differ in the duty-holder, the trigger that engages the regime, and the oversight body. Map those three features before studying any details.
The regulatory framework domain supplies the structure: it determines who must be licensed and what obligations attach to a licensee when providing financial services. Director duties operate at the level of officers regardless of licensing. AML/CTF attaches to designated services and transactions, privacy to the handling of personal information, and competition and consumer law to how products are promoted and sold. One product launch can therefore engage several regimes at once.
Revise by decision rather than by statute. For each domain, write one sentence naming the regulated party, the core obligation, and the body responsible for oversight. Then compare the sentences: where similar conduct sits under different regimes — say, customer records under AML retention rules versus privacy rules — write the difference down explicitly. The table below captures those three features per domain and becomes the spine of your notes. This guide addresses the named subject; it is not a verified blueprint for any specific assessment.
| Domain | Duty-holder | Trigger to watch | Typical decision point |
|---|---|---|---|
| AFS regulatory framework | Licensee and its representatives | Providing financial services | Naming the obligation engaged |
| Director duties | Directors and other officers | Board decisions and personal conflicts | Identifying which duty the facts engage |
| AML/CTF | Reporting entities | Designated services, unusual transactions | Due diligence versus reporting escalation |
| Privacy and data protection | Entities handling personal information | Collection, reuse, or breach of data | Purpose test and breach assessment |
| Whistleblower protections | Disclosers and eligible recipients | Reports of misconduct or improper conduct | Eligibility and identity confidentiality |
| Competition and consumer protection | Firms promoting and selling products | Advertising, selling, and customer dealings | Misleading or unconscionable conduct analysis |
AFS licensing: licensee obligations versus individual conduct standards
The framework distinguishes obligations attaching to the licensee as an entity from the standards applying to individuals acting for it. Trace every conduct question back to who is licensed, what the authorisation covers, and which general obligations engage.
Licensee obligations cover matters such as resources, risk management, competence, compliance arrangements, and dispute handling. A common paper-question mistake is assigning an entity obligation to a single adviser, or assuming an authorised representative carries the licensee's full obligation set. Representatives act within their authorisation, but the licensee keeps responsibility for oversight of the financial services the representative provides on its behalf.
When practising, read each scenario for three anchors: the licence holder's name, the described scope of authorisation, and whether the issue is a breach, a remuneration structure, or a disclosure failure. Then name the general obligation engaged. If you cannot name it, return to the obligation list rather than re-reading the story. This keeps framework answers anchored in the regime instead of intuitions about what seems fair.
Director duties in practice: care and diligence against the conflict rules
Director duties divide into process duties — care and diligence, good faith and proper purpose — and conduct duties covering conflicts, use of position, and use of information. Scenario questions test which duty the facts engage first.
Paper scenario: a director hears in a board meeting that the company will acquire a supplier, then buys shares in that supplier before the deal is public. The tempting answer is 'breach of duty of care and diligence' — but care and diligence concerns the quality of decision-making, not personal trading. The better decision identifies misuse of information and the duties around conflicted positions, along with the separate prohibition on trading while holding inside information. Mis-locating the duty sends the whole analysis down the wrong branch.
Structure every duty answer in two lines: the duty engaged, then the facts that satisfy it. Facts describing a flawed process — no advice sought, no financials considered — signal care and diligence; facts describing personal benefit or information leakage signal the conflict-based duties. Where a conflict arises in a transaction, add disclosure obligations and any need to abstain from the decision. Keeping the two branches visually separate in your notes prevents the crossover under time pressure.
AML/CTF: tracing a customer from due diligence to suspicious matter reporting
AML/CTF questions follow a lifecycle: enrolment or registration where applicable, customer due diligence, ongoing monitoring, and reporting to AUSTRAC. Locate the scenario's facts on that lifecycle before selecting a response.
Paper scenario: a customer requests a large international transfer, the stated source of funds does not match the account history, and the customer asks staff not to document the source. The tempting decision is to decline the transaction and move on. The better decision recognises the mismatch and the avoidance request as risk factors in their own right: record the reasoning, escalate under the AML/CTF program's internal process, and consider whether a suspicious matter report is required.
Sequence matters here. Customer due diligence operates before and during the relationship; reporting sits on top of due diligence, not instead of it. Tipping off a customer is prohibited, so staff must not explain a report to the person concerned. Record-keeping also carries its own retention rules, which means AML records are not simply deleted on request — a boundary worth writing down before you revise privacy, where retention logic differs.
Privacy compliance: applying the data lifecycle to reuse and breach decisions
Privacy obligations track the data lifecycle: collection with notice, use and disclosure limited to purpose, security, access and correction, and notification of eligible data breaches. Identify the lifecycle stage before answering.
Scenario: a marketing team wants to reuse details collected through loan applications for a new product campaign. The tempting decision is 'customers gave us the details, so reuse is fine.' The better analysis asks whether the secondary use matches the purpose stated in the collection notice; if it does not, consent or another permitted basis is needed. Identical data, different purpose, different answer — purpose is the hinge of most privacy scenarios.
For breach scenarios, name the steps in order: contain and assess, decide whether serious harm is likely, and complete the assessment within the Notifiable Data Breaches scheme's 30-day window. Then check interactions: AML/CTF retention obligations can override a customer's deletion request, so a strong answer sometimes explains the competing obligation rather than giving a flat yes or no. Write these boundary notes once and revisit them in both domain blocks.
Whistleblower protections: testing eligibility before applying the safeguards
Protection turns on criteria: who the discloser is, what the information concerns, and to whom it is made. A disclosure must concern misconduct or an improper state of affairs and reach an eligible recipient. Check each criterion in turn.
Scenario: an employee tells a manager that the team's bonus structure encourages inflating client fees. The tempting shortcut is 'all internal complaints are protected disclosures.' The better decision tests the criteria: does the information concern misconduct or an improper state of affairs, and is the manager an eligible recipient such as an officer, senior manager, or the entity's disclosure channel? A purely personal work grievance may not qualify. Eligibility decides whether confidentiality and anti-retaliation protections attach.
Identity confidentiality is the next layer: information likely to identify a discloser must not be shared except in limited circumstances, including with consent. Around this sit governance expectations — processes for receiving and escalating disclosures, and a prohibition on victimisation. Link the topic to board and compliance functions when revising, because combined scenarios test both the legal criteria and the organisation's response to a valid disclosure.
A cross-domain practice exercise, marking rubric, and study sequence
Build one cross-domain fact pattern each week and mark it against a fixed rubric: domain identified, duty-holder named, obligation cited, decision justified, interaction noted. Sequence domains by anchoring role — framework and duties first, lifecycle regimes next, conduct overlays last.
Exercise: draft a one-page scenario in which a licensed firm launches a new product. Include the licensee, a director on the deal, customer onboarding, a marketing reuse of existing customer data, an internal complaint about the campaign, and an advertisement. Then answer five questions: which obligations attach; which duties the director must observe; what due diligence applies at onboarding; whether the data reuse is permitted; and whether the complaint could be a protected disclosure.
A workable sequence: first pass on the regulatory framework and director duties, which anchor entity and individual conduct; second pass on AML/CTF and privacy as lifecycle regimes; third pass on whistleblower and competition and consumer protection as overlays; then a final block on cross-domain patterns using the exercise above and practice questions. Re-mark earlier scenarios after each pass and compare scores against the rubric. Treat rubric scores as learning milestones, not predictions of any assessment result.
- Write the three features — duty-holder, trigger, core obligation — for all six domains from memory before each study block.
- For any short scenario, name the engaged regime and the specific obligation within two minutes of reading it.
- Produce every decision with a because-clause tied to a named obligation, not to general fairness.
- Note at least one cross-domain interaction per scenario, such as AML retention versus a privacy deletion request.
- Use the free practice questions alongside your own fact patterns and re-mark old answers after each pass.
| Check | Strong work looks like | Learning milestone |
|---|---|---|
| Domain and duty-holder | Named specifically, not 'a compliance issue' | 5 of 5 across your last five scenarios |
| Obligation or duty | Cited by name with its source regime | 4 of 5 |
| Decision | Stated with a because-clause | 4 of 5 |
| Cross-domain interaction | At least one regime boundary noted | 3 of 5 |
| Marking speed | Full rubric applied within ten minutes | Consistent by your final study week |
