Back to blog resources
1 September 2026
Offshore Staffing for Financial Planners: What Can You Delegate Under an AFSL?

Financial Planning

gradient overlay

Offshore Staffing for Financial Planners — What Is Allowed Under an AFSL?

Yes. AFSL holders can use offshore staff, including administrative support and paraplanning functions, provided the arrangement is appropriately governed and the licensee continues to meet its regulatory obligations. Outsourcing does not transfer accountability. AFSL holders remain responsible for risk management, organisational competence, client data security, oversight and the controls surrounding outsourced work.

For financial planning practices considering offshore staffing, the question is often framed simply:

Is it legal?

The more useful question is: 

What can we offshore, and what controls need to sit around it?

Offshore staffing is already used across Australian financial services for administration, paraplanning and client support. The regulatory issue is therefore less about the location of a team member and more about how the arrangement is structured, supervised and secured.

ASIC RG 104, AFS licensing: Meeting the general obligations, is particularly relevant because it places responsibility on the licensee to maintain adequate risk management arrangements. ASIC RG 105, AFS licensing: Organisational competence, is also relevant when assessing whether the business continues to have the competence required to provide its financial services. VAP's offshore security whitepaper consequently recommends assessing prospective providers against RG 104, RG 105 and ASIC's Cyber Resilience Good Practices before proceeding with an offshore arrangement.

For a financial planner or AFSL holder new to offshore staffing, that distinction matters.

You can delegate work. You cannot delegate the AFSL holder's responsibility for how that work is governed.

What tasks can financial planners legally offshore?

Financial planning practices can offshore a range of administrative, paraplanning and client service functions where the work is appropriately structured within the practice's licensing, supervision, privacy and security arrangements.

In practical terms, an offshore team can support different stages of the advice process. See how VAP supports financial planning practices from administration and client services through to paraplanning.

A financial planning assistant offshore can assist with preparing and maintaining client files and fact-finding documentation, updating CRM systems and supporting administrative workflows.

Client Services Officers can respond to client emails and inbound enquiries, assist with policy reviews, withdrawals and insurance changes, and provide administrative support across the advice process.

Paraplanners can support more technical work, including preparing draft Statements of Advice and Records of Advice, conducting research and modelling, and assisting with advice documentation.

The important distinction is that assigning a task offshore does not remove the AFSL holder's responsibility for determining whether that activity is appropriate within its own licence, authorisations and governance framework.

This is why an offshore staffing model should begin with the function rather than simply the job title.

Before providing system access, the AFSL holder should consider questions such as:

  • Is the function client-facing, compliance-critical or high risk?
  • What client information does the person need to access?
  • What level of supervision is appropriate?
  • Does the outsourcing arrangement affect the firm's ability to meet RG 104 and RG 105?
  • Are there contractual restrictions on third-party access?
  • Has the use of third-party providers been appropriately considered and disclosed?

These questions form part of the decision framework recommended in VAP and The Cyber Collective's Safe Solutions or Distant Dangers: Reclaiming Security in Offshore Operations.

For practices looking to outsource paraplanning in Australia, this means delegation should be deliberate. Access, responsibility and supervision should reflect the nature and risk of the work being performed.

What does ASIC say about offshore staffing for AFSL holders?

ASIC's guidance places responsibility for the AFSL holder's obligations with the licensee, including when third parties are involved.

For offshore staffing, two Regulatory Guides identified in VAP's compliance material are particularly relevant.

ASIC RG 104 addresses the general obligations of an AFS licensee. The VAP security whitepaper identifies adequate risk management frameworks as a relevant RG 104 consideration when outsourcing.

ASIC RG 105 addresses organisational competence. When an AFSL introduces outsourced personnel into its operating model, the licensee should therefore consider whether the arrangement supports its ability to maintain the competence required to provide its financial services.

The whitepaper's recommended decision framework asks AFSL holders to establish whether an offshore provider can meet requirements associated with RG 104, RG 105 and ASIC's Cyber Resilience Good Practices before proceeding.

ASIC's expectations extend into cybersecurity.

The material identifies third-party due diligence, ongoing monitoring, cyber awareness training and incident response planning as relevant considerations when external providers have access to systems or data. The principle running throughout the guidance is straightforward: outsourcing a service does not remove the licensee's accountability for the risks surrounding that service.

This becomes particularly important where offshore personnel access personal client information.

The Privacy Act 1988 and Australian Privacy Principles also need to be considered. The supplied compliance material identifies APP 8 in relation to cross-border disclosure and APP 11 in relation to the security of personal information.

Practices also need to consider how personal information is handled when an overseas team member is given access to client data, including appropriate privacy and security measures and accountability for that information. [Read more about using offshore staff while complying with Australian privacy laws.]

As a result, AFSL compliant offshore staff should be considered as part of the practice's broader governance, cybersecurity and data-handling framework rather than treated as a separate workforce sitting outside it.

Can paraplanners be based offshore?

Yes. Paraplanning functions can form part of an offshore financial planning team, provided the AFSL holder appropriately assesses the work being performed and maintains the necessary governance, security and oversight.

VAP's financial planning model includes offshore paraplanners supporting practices with draft Statements of Advice and Records of Advice, research and modelling, and the preparation of advice documentation.

The location of the paraplanner does not remove the need to consider how the function interacts with the AFSL's obligations.

That means an offshore FPA financial planner or paraplanning arrangement should be assessed according to the actual responsibilities involved, the information being accessed and the environment in which the work takes place.

Security is particularly important.

The offshore security whitepaper distinguishes between controlled office environments and less controlled home-based arrangements. A secure offshore office can incorporate company-managed devices, MFA, VPN access, endpoint protection, role-based system access, audit logging, physical access controls and ongoing cyber training.

The whitepaper also recommends matching the sensitivity of the work to the security of the environment.

In its case-study framework, personnel in a secure office could access full client files and financial modelling tools, while people operating in less controlled environments received more restricted access. The rationale was to match task criticality with the security controls surrounding the worker.

For financial planning practices, this provides a useful way to think about paraplanning offshore.

The question should not stop at, Can this task be done overseas?

It should also ask, What information does this task require, where will that information be accessed, and what controls can we demonstrate around that access?

What governance does an AFSL need before offshoring?

An AFSL should have a documented framework covering the decision to outsource, provider due diligence, information security, access, contracts, monitoring and incident management before offshore staff begin accessing sensitive systems or client information.

For a deeper look at these considerations, Safe Solutions or Distant Dangers: Reclaiming Security in Offshore Operations explores the regulatory, cybersecurity and governance considerations involved in offshore operations for AFSL and ACL holders. 

VAP's compliance material recommends approaching the decision in three stages.

First, assess strategic fit and regulatory considerations.

Determine what is being outsourced, whether it is client-facing or compliance-critical, and whether the provider can operate within requirements relevant to RG 104, RG 105 and ASIC's Cyber Resilience Good Practices.

The AFSL should also consider cross-border privacy requirements and any contractual restrictions that apply to third-party access.

Second, conduct risk assessment and due diligence.

The physical work environment matters.

Practices should understand whether the team member will operate from a secure office or home environment, what security standards apply, and what monitoring, logging and access controls exist.

The whitepaper recommends examining whether providers are certified or aligned with recognised frameworks such as ISO 27001, SOC 2 or the NIST Cybersecurity Framework.

Third, establish contractual and operational controls.

Written agreements should address data security responsibilities, incident response, audit rights, access limitations and what happens to data when the arrangement ends.

Governance then needs to continue after onboarding.

The whitepaper recommends ongoing provider monitoring, documented vendor risk assessments, regular security reviews and an incident response plan that specifically includes outsourced providers.

Access controls are another important consideration.

Rather than giving every offshore team member broad access to every system, the practice can apply role-based permissions and the principle of least privilege. The material also recommends MFA, secure cloud access, company-managed or compliant devices, encryption, monitoring and logging, and restrictions on local storage and printing.

These controls help turn offshore staffing from an informal delegation arrangement into a documented operating model that the AFSL can supervise.

How VAP supports financial planning practices

VAP supports financial planning businesses with dedicated offshore team members across financial planning administration, paraplanning and client services.

The model is designed around financial services rather than general-purpose outsourcing.

Team members can support activities such as client file administration, fact-find documentation, CRM management, draft advice documentation, research and modelling, client enquiries and ongoing administrative support.

VAP also recruits according to the client's requirements rather than simply assigning available personnel. Its financial services model includes specialised training for financial planning roles, with team members developing capability around the systems, processes and workflows relevant to the practices they support.

The operating environment also matters.

VAP's broader approach to offshore staffing emphasises controlled office environments and security practices rather than treating offshore staffing as simply finding someone overseas who can perform a task.

That distinction becomes important for AFSL holders because the whitepaper's security framework shows how dramatically the risk profile can change between a managed offshore office and an uncontrolled work-from-home arrangement.

A secure corporate environment can include managed devices, MFA and SSO, endpoint protection, VPN access, physical access controls, role-based permissions, audit logs and cybersecurity training.

VAP's model also incorporates ongoing support around the team member rather than ending once recruitment is complete.

For a practice new to offshore staffing, this creates a more structured starting point. The financial planner still determines what work should be delegated, what access is appropriate and how responsibilities fit within the AFSL's own compliance framework.

The objective is to build an offshore team that operates as part of the practice's established workflows and governance rather than alongside them.

For AFSL holders, that is ultimately the distinction that matters.

Offshoring itself is not the end of the compliance conversation.

The work being delegated, the people performing it, the systems they can access, the environment they work from and the AFSL's ability to supervise and document the arrangement all need to be considered together.

When those foundations are established, offshore staffing can give financial planning practices additional capacity across administration, paraplanning and client support while maintaining clear accountability within the Australian practice.

Assess Your Offshore Staffing Approach

Considering offshore staffing within your AFSL?
Download Safe Solutions or Distant Dangers: Reclaiming Security in Offshore Operations for practical guidance on secure and compliant offshoring. The white paper also includes tools for assessing work environments and offshore provider risk.

Download the Offshore Compliance & Security Guide

Want to Discuss Offshore Staffing for Your Practice?

Speak with a VAP Financial Planning Expert about the roles you're considering delegating and where dedicated offshore support could fit within your practice.

Book a Meeting With a VAP Financial Planning Expert

Subscribe to our newsletter

Get industry insights delivered straight to your inbox.

Subscribe
Thank You for subscribing!
We've received your message and will get back to you shortly.
Oops! Something went wrong while submitting the form.
icon mark