ARC NEXUS
Independent Cyber Governance
Board Governance Insights

Knowing the risk is not the same as governing it

What the ASX Inquiry found, how Board oversight failed in practice and what other Boards should do differently.

By Ashwin Ram, Founder and Managing Director, ARC Nexus
Published 25 August 2026 · Last reviewed 25 August 2026 · 11 min read

In June 2025, the Australian Securities and Investments Commission (ASIC) commissioned an expert-led inquiry into the ASX Group after repeated and serious failings. ASX operates Australia's predominant equity-trading market and core infrastructure that clears and settles share trades.

The Final Report was released on 2 April 2026. One of its central findings was blunt: the resilience of critical market infrastructure had been compromised to deliver high shareholder returns.

The Panel said ASX's problems were systemic, long-standing and deeply embedded in how strategic priorities had been set. It attributed the shortcomings to the cumulative effect of decisions made and actions taken by ASX's boards over an extended period. It also found that ASX's boards and executives had underestimated the full extent of the change required.

Taken together, the Panel's findings describe more than old technology or one unsuccessful project. They show known risk that did not consistently produce timely investment, accountable action or sustainable outcomes.

What happened

The Inquiry followed a pattern of failures and warnings, not one incident.

ASX's unsuccessful attempt to replace CHESS ran from 2017 to 2022. CHESS, the Clearing House Electronic Subregister System, is used to clear and settle Australian share trades. It helps calculate what market participants owe, supports the transfer of payment and ownership, and maintains an electronic subregister of shareholdings. The Panel found that the unsuccessful replacement put ASX further behind and constrained its ambitions for the future.

In November 2022, an internal assessment examined 46 critical systems and infrastructure. Almost 40 per cent were rated red or amber and were outside the Board's approved risk appetite. The assessment said funding and delivery of mitigating actions were not keeping pace with the age and overall risk profile of the technology environment.

On 20 December 2024, a full batch of ASX equity settlements could not be completed. For the first time, it had to be moved to a later day. On Saturday, only one core engineering team was working on the problem. The investigation stopped for four hours while that team took a break because no replacement team was available. ASX ultimately relied on an offshore third-party expert who had worked on the original CHESS development in the 1990s and whose assistance was outside ASX's usual support arrangements.

By the time of the Inquiry, ASX had a Risk Appetite Statement, Board committees, a three lines of defence model, internal audit and extensive external review. Since January 2020, it had been subject to more than 120 external reports examining aspects of its governance, capability, culture and risk management.

The central question was not whether ASX knew it had problems. It was why that knowledge had not produced an adequate response.

What the Inquiry did, and did not, determine

The Inquiry Panel was not a court. The Panel was asked to contribute to ASIC's assessment of how well the ASX licensees were complying with their obligations under Chapter 7 of the Corporations Act. It did not determine that any individual director breached their statutory duties.

Its Board-level finding was nevertheless serious: governance arrangements failed to provide the necessary focus on critical market infrastructure, and the shortcomings were the cumulative effect of Board decisions and actions over time.

Which Boards were responsible for what

There was not one ASX Board governing everything.

The ASX Limited Board governed the listed parent company. Separate Boards governed four licensed entities responsible for clearing cash equities and derivatives, and for settling cash equities and wholesale debt transactions.

At 31 December 2025, each of the four Clearing and Settlement Boards comprised the same seven directors. Three also sat on the ASX Limited Board. The remaining four, including the Chair, were independent of other ASX Group companies.

The Boards frequently met together in formal joint sessions. Since 2023, the ASX Limited Board would typically meet first, followed by a broader joint meeting involving ASX Limited and Clearing and Settlement directors. Stand-alone meetings of individual Clearing and Settlement Boards were not held as a matter of course.

The Panel found that this sequence could constrain the subsidiary Boards from exercising stand-alone, independent judgement where ASX Limited directors had already made decisions. In the larger joint meetings, the number of ASX Limited directors relative to Clearing and Settlement directors who did not sit on the parent Board created a risk of disproportionate influence.

That structure is central to understanding how oversight failed in practice.

Where oversight failed in practice

1. Risk outside appetite did not reliably produce a decision

A risk appetite states how much and what type of risk an organisation is prepared to accept. The governance test is what happens when a material risk moves outside that boundary.

At ASX, the Risk Appetite Statement had not been well articulated or effectively operationalised to support informed business decisions. Risks remained outside tolerance for extended periods with limited demonstrated accountability for remediation. Key risk indicators were not effectively designed to drive risk-based decisions. Audits and external reviews found that risk appetite reporting and monitoring lacked the insight needed for meaningful discussions of risk.

An internal audit in 2024 also found that ASX's response to technology obsolescence had been reactive. It identified insufficient funding and prioritisation across the technology lifecycle as a primary root cause.

Taken together, these findings show the oversight gap: a known exposure outside the Board-approved boundary did not consistently lead to a funded treatment, accountable owner, deadline and evidence that the exposure had reduced.

2. The responsible Boards were engaged too late

Project Align, ASX's cost-optimisation program initiated in late 2024, showed the difference between receiving information and having a meaningful opportunity to govern.

From December 2024 to April 2025, management provided regular updates to the ASX Limited Board. During that period, the Clearing and Settlement Boards received one procedural update in February.

The Clearing and Settlement directors received a detailed paper on 7 May. On 8 May, the parent and subsidiary Boards were asked to "consider and note" the proposed changes. The Clearing and Settlement directors challenged management on the process undertaken and requested further material to confirm and verify the conclusions in the board papers. Further material was produced, a meeting involving the two Chairs and management occurred on 11 May, and consultation with affected staff began on 12 May.

The Panel's concern was not that the subsidiary directors remained silent. They challenged management. Its concern was that they were engaged too late and with insufficient detail to understand, influence and challenge changes affecting the entities for which they were responsible.

The Panel said earlier and more substantive engagement could have supported a more robust assessment. It also said that asking the Boards only to "consider and note" the proposals indicated the limited extent to which they were expected to engage deeply.

3. Short-term financial priorities outweighed long-term resilience

ASX is a listed company and is expected to produce returns for shareholders. The Panel's criticism was not that profit or dividends were improper. It was that short-term financial objectives had taken precedence over the investment needed to maintain resilient, future-ready infrastructure and capability.

The Panel reported that ASX had consistently delivered earnings before interest and tax margins close to or above 60 per cent. It also identified long-term underinvestment in systems, technology, expertise and broader capability. The Panel expressly recognised that ASX had increased investment in recent years and that its capital expenditure exceeded its peer exchange groups in FY24.

The finding concerned the cumulative effect of decisions over time. The Panel said the weighting towards financial objectives in ASX's remuneration framework, relative to other objectives, had been a factor in insufficient spending.

It also identified a Board-controlled lever. ASX had at times relied on Board discretion to adjust executive incentive payments when non-financial outcomes were not met. The Panel said the framework would be stronger if desired outcomes for risk management, resilience and regulation were embedded directly in performance scorecards and incentive structures.

4. High availability did not establish resilience

Austraclear is the electronic depository and settlement system for Australia's wholesale debt market. It records ownership of more than $3 trillion in securities and settles more than $80 billion in transactions on an average day.

The platform dates from 2006 and had consistently achieved high availability. The Panel nevertheless found that the Austraclear Board had tended to focus on short-term strategy and financial performance rather than the resilience and resources required for the platform's long-term health.

A small, dedicated group of developers maintained the software, creating concentration and key-person risk. Spending had focused on maintaining existing functions rather than long-term resilience and modernisation.

The December 2024 CHESS incident exposed similar fragility through one core team, no relief capacity and dependence on expertise outside the usual support arrangements.

Historical availability does not, by itself, demonstrate that a system can withstand disruption, recover under pressure or continue operating when key people are unavailable.

5. Reviews did not consistently resolve root causes

The Panel found that the cycle of external reviews following repeated incidents produced a large number of recommendations. This contributed to ASX applying tactical solutions rather than addressing root causes, becoming overwhelmed and focusing too heavily on obvious gaps and minimum standards.

Weaknesses in ASX's risk and compliance frameworks and three lines model also contributed to reactive responses to incidents and to gaps identified across more than 120 external reports. ASX became narrowly focused on separate recommendations, contributing to a tick-a-box approach to risk management and compliance.

The Panel observed that many assurance reviews focused on the processes used to address weaknesses rather than the outcomes achieved. It warned against measuring success through completed milestones instead of demonstrable progress towards sustainable outcomes.

Closing an action proves that an activity was completed. It does not, by itself, prove that the underlying risk reduced or that the improvement will last.

What has changed, and what remains unproven

ASX's public disclosures report that the Clearing and Settlement Boards are now composed of directors who do not sit on the ASX Limited Board. A Clearing and Settlement Risk Committee and a Clearing and Settlement Audit and Supervision Committee were established with effect from 1 July 2026. ASX has also been developing more dedicated management, risk, financial-reporting and support arrangements for the licensed clearing and settlement businesses.

In February 2026, the Boards approved a redeveloped enterprise risk management framework, a new three lines of defence operating model and new risk appetite statements. ASX also advised that executive performance scorecards had been revised to align more strongly with its Commitments Plan and the outcomes of the reset Accelerate program.

ASX reset Accelerate with ASIC and the Reserve Bank of Australia around five core priorities: Culture and Leadership, Risk Transformation, Operational Resilience, Resource Sufficiency and Governance. Promontory was engaged to provide external assurance over delivery of the milestone plan.

ASIC also imposed a $150 million regulatory capital charge. ASX must accumulate an additional $150 million in net tangible assets, relative to 31 December 2025, by 30 June 2027 and hold it until relevant milestones are achieved and ASIC approves a staged reduction or release. ASX lowered its dividend payout ratio to support that requirement.

The new clearing component of CHESS entered service on 20 April 2026. ASX says it continues to work with the industry towards 2029 for delivery of Release 2, which will provide settlement and subregister services.

At the time of the Final Report, ASIC and the Reserve Bank had also established a joint working group to review their supervisory model and move towards a more strategic, forward-looking and outcomes-based approach.

These actions establish that changes have been made or commenced. They do not yet demonstrate that the intended outcomes are embedded and sustainable. The Panel said Boards need the right information, resources and mechanisms to enforce accountability, and that success should be measured through sustainable outcomes rather than completed activities.

What other Boards should take from it

The evidence supports six broader governance lessons.

  1. A technical incident can expose a governance failure. Code, process and ageing systems may explain how an incident occurred. Investment, capability and accountability decisions may explain why the conditions persisted.
  2. Being informed is not the same as governing. Information must reach the responsible Board early enough, with sufficient detail and authority, for challenge to influence the outcome.
  3. Independence must operate in practice. Formal independence does not guarantee independent decision-making. Meeting sequence, information, resources and group dynamics can constrain a subsidiary Board and create a risk of disproportionate parent influence.
  4. Reliable is not the same as resilient. High availability can coexist with ageing technology, fragile support arrangements and dependence on a small number of people.
  5. Risk appetite needs a decision trail. A material risk outside appetite should lead to a recorded decision, funded treatment, accountable owner, deadline and evidence of reduction.
  6. More review does not necessarily mean less risk. The number of reports, recommendations and closed actions does not, by itself, establish that risk has reduced. Boards need evidence that root causes were addressed and exposure was reduced.

Why this matters for cyber

The ASX Inquiry was not a cyber security inquiry and made no finding that ASX had underinvested in cyber security. The cyber relevance lies in the governance mechanism it identified: whether a known exposure changes investment, accountability and action.

The Federal Court's 2026 FIIG Securities judgment provides a separate cyber example. FIIG admitted contraventions of its Australian financial services licence obligations. The parties agreed, and the Court accepted, that FIIG had failed to invest adequately in cyber security and resilience despite being aware of the risks. They also agreed that FIIG failed to fully implement, maintain and monitor controls adopted under its risk-management system.

The Court imposed a $2.5 million penalty and recorded that the estimated cost of compliance across the relevant period would have been approximately $1.2 million. It also made clear that the mere fact of a successful cyberattack does not necessarily establish a failure to meet statutory obligations.

For Boards, the question is not whether cyber appears on the agenda. It is whether the governance record shows that a material exposure changed a decision.

The questions worth asking at the next meeting

Questions worth asking
  1. Which material technology and cyber risks sit outside the appetite the Board approved, and for how long?
  2. What decision did each exposure trigger, who owns the outcome and when is it due?
  3. Are the legally responsible directors receiving complete information early enough for their challenge to influence the decision?
  4. Which critical systems depend on ageing technology, a small number of people or specialists outside normal support arrangements?
  5. Do cost targets or executive incentives conflict with the investment needed to reduce material risk? If so, how has the conflict been resolved?
  6. Are recurring findings grouped and addressed by root cause, or tracked only as separate actions to close?
  7. What independent evidence shows that completed work reduced the exposure and that the improvement will last?

If those answers cannot be supported by evidence, the Board knows what its risk appetite says. It does not yet know whether that appetite is governing decisions.

Knowing the risk is not the same as governing it.

Not assumed. Evidenced.

The ASIC Inquiry into ASX examined governance, capability and risk-management frameworks and practices. It did not determine that any individual director breached their statutory duties and made no finding that ASX had underinvested in cyber security. Observations about ASX are drawn from the Panel's Final Report and ASX's public disclosures. The FIIG discussion is drawn from admissions and findings recorded in the Federal Court's judgment. Statements about ASX's current arrangements are not independent assurance of their effectiveness. This is governance commentary, not legal advice.

Ashwin Ram, Founder and Managing Director of ARC Nexus

Ashwin Ram (GAICD, CISM) is the Founder and Managing Director of ARC Nexus, an independent cyber governance advisory practice for Australian Boards, Audit and Risk Committees and senior leaders. He combines formal governance training with more than fifteen years in cybersecurity.

Sources

Key primary sources for this article are set out below.

From article to assessment

Testing this on your own Board

This article reflects several questions an ARC Nexus review is built to answer: whether material cyber risk changes investment decisions, whether accountability and decision authority are clear, and whether completed work is evidenced to have reduced risk. A confidential briefing determines whether a Board Cyber Governance Review is warranted and how it would be scoped.

Request a confidential Board briefing