In May 2025, the Australian Securities and Investments Commission (ASIC) filed legal action against Macquarie Securities Australia Limited (MSAL), the broking division of Macquarie Group, alleging systemic failures in short sale reporting over a staggering 14-year period. You can read more here.
While it made big news (we shared more about this across our socials) it also serves as a powerful reminder for Australian business owners, directors, shareholders, and compliance officers: regulatory oversight is tightening, and no business is too big or too sophisticated to avoid scrutiny.
What Happened?
According to ASIC, from December 2009 to February 2023, MSAL allegedly:
- Failed to properly report short sale transactions for at least 321 securities;
- Continued these failures over more than a decade due to unresolved software errors;
- Misreported short sale volumes, with some inaccuracies reaching over 50%;
- Did not act sufficiently on internal concerns or external red flags.
This is ASIC’s fourth action against Macquarie in just over a year, raising broader concerns about the bank’s governance and risk controls.
Why This Matters Beyond Macquarie
While Macquarie faces the direct consequences, all companies operating in regulated industries should be paying close attention. This case speaks volumes about what regulators expect and how they respond when those expectations are not met.
What Business Leaders Need to Know
Directors Are Accountable – Even for System Failures
Directors can’t afford to “delegate and forget.” Even if the issue stems from outdated tech or an internal oversight, ASIC expects directors to have oversight and evidence of active risk management.
You’re responsible for ensuring that your systems – and the people who manage them – are operating within the law. Regular board-level reviews of compliance frameworks are essential.
“We Didn’t Know” Won’t Cut It
Macquarie allegedly received alerts – internally and externally – about issues in their short sale reporting but failed to act adequately. ASIC’s stance is clear: failure to address known issues is a breach in itself.
Ignoring red flags can be just as damaging as actively breaching the law. Investigate and act on anomalies early – and keep a paper trail of your response.
Technology Must Be Audited, Not Assumed
The reported errors were blamed in part on software flaws. But relying on automation is no defence if it leads to misreporting or non-compliance.
Review and test compliance systems regularly. Build internal controls that flag irregularities early – especially if you deal in high volumes of transactions or data.
Reputational Risk is Investment Risk
Following the lawsuit’s announcement, Macquarie’s share price dipped by 1.9%. Investors respond to perceived governance failures just as they do to poor earnings.
Shareholders are watching more than just your bottom line – they expect ethical leadership and proactive compliance.
Final Thoughts for All Australian Businesses
ASIC’s message is loud and clear: systemic failures, especially those left unchecked for years, will be investigated and acted upon – regardless of a company’s size or reputation.
This is a wake-up call for every organisation to:
- Review compliance systems
- Empower internal reporting
- Act swiftly on identified risks
- Prioritise transparency at all levels
In today’s regulatory environment, compliance is not a back-office function – it’s a boardroom priority.
Need Help With Compliance and Governance?
If you’re a director, executive, or business owner who wants to ensure your systems can withstand regulatory scrutiny, now is the time to act. Here at Litton Legal we can help you audit your current position and implement best-practice governance structures that reduce your legal exposure. Contact our friendly team here.