ASIC’s latest enforcement action against two New South Wales directors is a sharp reminder that small compliance gaps can escalate quickly into material personal risk.
In its recent media release, ASIC confirmed that both individuals were convicted and fined $10,000 each for failing to obtain a Director Identification Number (Director ID), in breach of section 1272C(1) of the Corporations Act 2001. On the surface, this may appear to be a relatively minor compliance failure. In reality, it highlights a much broader and more confronting risk landscape for directors.
The starting point is that the offence is of strict liability. In practical terms, this means it does not matter whether the failure arose from oversight, misunderstanding, or poor systems – liability attaches regardless.
More significantly, this is not a civil penalty framework – it is criminal enforcement. A conviction of this nature becomes part of a director’s record. That has real-world implications. It may affect a director’s ability to satisfy the “fit and proper” criteria, secure finance, obtain insurance, or accept future appointments. In a professional environment where credibility and trust underpin commercial relationships, reputational damage can often outlast the fine itself.
From a financial perspective, the legislation provides for higher maximum penalties than the $10,000 imposed, and ASIC has made clear that enforcement is intended to act as a deterrent across the director community.
The underlying policy objective is clear. Director IDs are designed to prevent the misuse of false identities and improve transparency across corporate structures, aligning with broader anti-phoenixing measures. All directors are required to verify their identity with the Australian Business Registry Services before receiving a Director ID, and must comply with prescribed application timeframes:
- Directors appointed before 1 November 2021 were required to apply by 30 November 2022;
- Directors first appointed between 1 November 2021 and 4 April 2022 had 28 days from appointment
- From 5 April 2022, intending directors must apply before appointment.
Advisors should take this opportunity to actively warn and remind their clients to confirm their Director ID status. A simple check, ensuring the ID has been obtained and aligns with current roles, can eliminate a risk that is otherwise entirely avoidable.
Director identity compliance now sits within corporate governance
From an Australian corporate governance perspective, these prosecutions should be understood as more than an administrative reminder. They demonstrate that director identity compliance now sits within the broader governance architecture expected of Australian companies, alongside director appointment processes, registers, onboarding controls and board assurance practices.
For boards and company secretaries, the key issue is not simply whether an individual director has applied for a Director ID. It is whether their organisation has implemented reliable processes and internal controls to mitigate the risk of Director appointments being invalid. Director ID status should be embedded into pre-appointment due diligence, consent-to-act procedures, board nomination packs and corporate register maintenance.
This is particularly important for corporate groups. Implementing and maintaining a Director ID compliance register, confirming status before lodging appointment documents, and including periodic checks as part of annual corporate governance review should become common place, especially for corporate groups with multiple controlled entities, special purpose vehicles, foreign resident directors or where frequent board changes are anticipated.
These prosecutions also reinforce the importance of director education. Many private company directors, particularly in family businesses, start-ups and small proprietary companies, may not see themselves as operating in a regulated governance environment. That assumption is increasingly risky. The Director ID regime applies broadly, and enforcement action shows that ASIC is prepared to pursue non-compliance even where the underlying failure appears simple.
Best practice for ensuring DIN compliance
To meet these obligations effectively, companies could consider implementing the following processes and internal controls:
- Centralised record-keeping: Maintain a secure, centralised database of all directors’ DINs, including the date of issuance and any updates.
- Regular audits: Conduct periodic audits to ensure all directors have valid DINs and that records are up to date.
- Director onboarding procedures: Include DIN verification as part of the onboarding process for new directors. For example, require proof of a valid DIN before formal appointment.
- Automated reminders: Use automated systems to send reminders to directors about DIN application deadlines or renewal requirements (if applicable in the future).
- Training and awareness: Provide training for directors and company secretaries on the importance of DIN compliance and the potential consequences of non-compliance
The message for Australian boards is clear: implementing and maintaining accurate Director ID compliance is a key objective in protecting the interests of Directors, the company, their reputations and for the benefit of all stakeholders in the organisation.
Stay ahead of your governance obligations
If you’re unsure whether your Director ID processes and corporate governance controls are meeting current requirements, William Buck can help. Our advisors can review your compliance framework, identify potential risks and help you implement practical measures to protect your directors, your organisation and its reputation. Get in touch with our team to discuss your governance and compliance obligations.
