Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

They Said They Would Monitor It. That Was the $7.3 Million Part.

There is a moment in an environmental audit that catches people out more reliably than anything in the aspects register. I ask to see the evidence behind a sentence on the company website.

Not a difficult sentence. Usually something like “we are committed to sustainable sourcing”, or “we monitor our suppliers’ environmental performance”, or “carbon neutral by 2030”. The sentence was written by someone in marketing, approved by someone in management, and has sat there quietly for three years. Nobody in the room thinks of it as part of the management system. It is, though. The moment you publish a claim about your environmental performance, you have created a requirement you have to meet and evidence, and you have handed a regulator, a customer and an auditor the same yardstick to measure you against.

An Australian court has now put a price on getting that wrong, and the useful part is not the number. It is which half of the failure the penalty attached to.

Miniature boardroom with a sustainability sign on the wall and a stack of unopened reports on a separate desk
The Supreme Court of NSW penalised Fiducian $7.3 million in August 2026. The finding was about the monitoring the fund promised and did not do, not the wording of the disclosure.

A $7.3 million lesson in monitoring

On 11 August 2026 the Supreme Court of New South Wales found that Fiducian Investment Management Services Limited had failed to act with the care and diligence required of a responsible entity, and had made statements liable to mislead the public about the ethical and socially responsible investment objectives of its Diversified Social Aspirations Fund. ASIC published the outcome on 12 August 2026 as media release 26-191MR. The penalty was $7.3 million, with ASIC’s costs agreed at an amount not exceeding $650,000.

The facts, as ASIC sets them out, are ordinary in a way that should worry people well outside financial services.

The fund opened in 2015 and closed in 2024. Its product disclosure statement was issued six times between October 2019 and May 2024. It said the fund would invest in companies that aim to be positive for society and the environment, and would avoid investments in harmful activities. It named the industries it would avoid. And it said that the responsible entity would routinely monitor the portfolio exposure, operations and performance of the fund.

The fund invested solely through underlying funds. Across that same period, those underlying funds held investments in companies deriving revenue from fossil fuels.

The Court found the responsible entity did not have reasonable grounds to make the environmental and social statements. It found that it failed to adequately monitor the underlying investments for alignment with those statements, failed to review the underlying funds’ investment strategies, failed to change the investments, and failed to amend the stated objectives to match what the fund was really doing. Investor concerns had been raised from at least 2019, and the claims were neither amended nor qualified.

ASIC Chair Sarah Court put it in one line: “This case is a reminder that ESG claims must be backed by robust systems, oversight and governance.”

That is the fourth greenwashing civil penalty outcome in Australia, following penalties against Mercer, Vanguard and Active Super. It is the first against the operator of a managed fund for failures in governance, compliance and oversight, and the first tied to a responsible entity’s duty to act with care and diligence.

The claim was not the problem

Read the findings again and notice what is missing.

The Court did not find that the disclosure was badly drafted. It did not find that the language was vague, or that a reasonable investor would have misread it, or that the wording needed a lawyer. The words were the words. What the Court found was that there were no reasonable grounds behind them, and that the monitoring the document itself promised did not happen.

This is the distinction almost every write-up of a greenwashing case misses, and it is the one that matters if you are running a management system. The exposure was not created by the marketing team. It was created by the absence of a loop that checks whether what you claim is still true.

If you hold ISO 14001, you already own that loop and it has a number. Clause 9.1 requires you to determine what needs to be monitored and measured, the methods, the criteria and when it happens. Clause 9.1.2 requires you to evaluate compliance with your obligations. Clause 9.2 requires internal audit at planned intervals to check the system against your own requirements as well as the standard’s. Clause 9.3 requires management review to consider the results and decide what to do about them.

A published environmental claim is one of your own requirements. It belongs in that loop. Most of the time it is not in it at all, because nobody ever treated the website as part of the scope.

We made a near-identical argument about information security recently, when APRA went after a bank over testing rather than controls. Different standard, same shape of failure: the thing that was missing was the assurance activity, not the control.

“We will monitor” is a control, and controls get audited

Here is the sentence that did the damage in the Fiducian matter. The disclosure said the entity would routinely monitor the portfolio.

Nobody made them write that. They wrote it because it was reassuring, and it was true of the intention if not the practice. The moment it was published it stopped being a marketing line and became a commitment that could be tested. It was tested, and it failed.

Now go and read your own environmental claims with that in mind. The phrases to look for are the ones that describe an ongoing activity rather than a one-off fact:

  • “We monitor our suppliers’ environmental performance.”
  • “We continually reduce our emissions.”
  • “All our packaging is responsibly sourced.”
  • “We review our environmental impacts annually.”
  • “We are working towards net zero by 2030.”

Every one of those is a control statement. Each promises an activity happening on a frequency. Each is evidence-hungry. And each is sitting on a website, in a capability statement, in a tender response or in a completed customer questionnaire where a regulator or a customer can read it.

A one-off fact is much safer ground. “In the 2025 financial year we diverted 62 per cent of site waste from landfill” is a statement you either have the weighbridge dockets for or you do not. It makes no promise about next year.

Where ordinary businesses make the same promise

The obvious objection is that this was a fund manager, and the duty breached was a responsible entity’s duty under financial services law. Fair enough. Most Australian businesses are not responsible entities and never will be.

But the misleading conduct half of the finding does not depend on that. Section 18 of the Australian Consumer Law prohibits conduct in trade or commerce that is misleading or deceptive, or likely to mislead or deceive. It reaches ordinary businesses, not just licensees, and the ACCC has kept environmental and sustainability claims on its enforcement priorities. You do not need a product disclosure statement to make a claim you cannot support. You need a website.

There is a second route that is arriving faster than most small and medium suppliers expect, and it does not involve a regulator at all. Australia’s mandatory climate reporting regime has pulled a second cohort of large entities into reporting, and their Scope 3 disclosure is built from their suppliers’ data. When that questionnaire lands on your desk, whatever you write on it becomes a representation your customer will rely on and publish. We wrote about that pipeline separately, and it is the single most likely place a small business will make a formal environmental claim for the first time.

The pattern is the same in all three settings. Somebody asks what you do. You describe your intentions. The description outlives the practice.

The concerns arrived in 2019 and nothing closed

The detail in the ASIC release that I keep coming back to is not the fossil fuel holdings. It is this: investor concerns were raised from at least 2019, and the claims were not amended or qualified.

That is roughly five years of a live signal arriving and going nowhere.

In management system terms that is a clause 10.2 nonconformity and corrective action failure, and it is the most common one I see. Clause 10.2 does not ask you to have no problems. It asks you to react to a nonconformity, evaluate whether it needs action so it does not recur, look for the cause, implement action, review effectiveness and retain evidence of the lot.

An organisation with a working 10.2 process, receiving that complaint in 2019, has four honest options. Change the investments so the claim becomes true. Change the claim so it matches the investments. Qualify the claim. Or document why the concern is not valid. All four close the loop. Doing none of them leaves an open, evidenced, dated signal that you were told and did not act, which is worse than never having been told at all.

A finding you have received and not closed is not neutral. It is a record of knowledge.

What the 2026 edition sharpened

If you are transitioning to ISO 14001:2026, there is a direct connection worth drawing out. One of the areas the 2026 edition strengthens is externally provided processes, products and services, with a clearer expectation about the environmental performance of your suppliers and contractors, the controls you set over them, and how you monitor those controls.

Fiducian’s fund invested solely through underlying funds. Everything that went wrong went wrong at arm’s length, in an externally provided arrangement, where the responsible entity had made a claim about something it did not directly operate and did not adequately check.

If your environmental claim depends on somebody else’s performance, and most supply chain claims do, the 2026 wording is pointed straight at you. Our transition guide covers the rest of the changes and the April 2029 deadline.

What an auditor looks for

If I were auditing your environmental claims tomorrow, this is the thread I would pull, in order.

  1. The register. Is there a list of the environmental claims the organisation has published, and where each one appears? Website, capability statements, tender responses, packaging, completed customer questionnaires, social media. Almost nobody has this, and building it usually takes an afternoon and produces a surprise.
  2. The basis. For each claim, what is the evidence, how old is it, and who owns it? A claim whose evidence is a supplier’s assurance from four years ago is a claim with a problem.
  3. The frequency. Where a claim promises an ongoing activity, does that activity appear in the 9.1 monitoring plan with a method and a frequency? If it does not, the promise is unmanaged.
  4. The trigger for review. What causes a claim to be re-checked? A date, a change of supplier, a complaint? Nothing at all?
  5. The closure record. Has anyone ever challenged a claim, internally or externally, and what happened to that challenge under 10.2?
  6. The management review input. Does 9.3 ever see any of this, or does the environmental section of the management review pack only carry incident and waste numbers?

Point 3 is where most systems break, and point 5 is where the expensive ones break.

Five questions before your next environmental claim

Worth asking before the sentence goes live, not after.

  1. Is this a fact about a period that has finished, or a promise about a period that has not? Facts are cheap to defend. Promises are not.
  2. If a customer asked for the evidence in writing tomorrow, what would we send, and would we be comfortable with a regulator reading it?
  3. Does the claim depend on anyone outside our direct control, and have we checked them recently enough to still be right?
  4. Who owns this claim, and does that person know they own it?
  5. What would have to change in our business for this claim to quietly stop being true, and would we notice?

Where Streamline fits

Most organisations that get into trouble here are not being dishonest. They wrote something true in 2021 and never built the mechanism to keep it true. The fix is not a rewrite of the website. It is putting published claims inside the same monitoring, audit and review loop as everything else in the system.

Streamline is run by a practising ISO Lead Auditor, so the perspective you get is the one from the other side of the audit table. We can run a gap analysis against ISO 14001, including a claims and evidence review, and give you a prioritised list of what to fix first. We provide the independent internal audit your system needs under clause 9.2. If your team would rather build the capability in-house, our ISO mentoring guides your own people through it so the knowledge stays with you. And for organisations that want the loop kept running year after year, we offer ongoing management system support.

For most small and medium Australian organisations, ISO 14001 certification takes three to six months and a first-year investment of roughly $7,000 to $25,000, and environmental is more often added to an existing quality or safety system than built on its own. Our full cost and timeline guide breaks that down.

If you have claims on your website you have not looked at in a while, that is a good place to start. Get in touch and we will take a look at them with you.

Sources

  • ASIC media release 26-191MR, Court orders Fiducian Investment Management Services to pay $7.3 million penalty over operation of ESG fund, 12 August 2026. Supreme Court of NSW findings dated 11 August 2026.
  • Competition and Consumer Act 2010 (Cth), Schedule 2, Australian Consumer Law, section 18.
  • ISO 14001, clauses 9.1, 9.1.2, 9.2, 9.3 and 10.2.

This article is general information from an auditing and management system perspective. It is not legal advice, and it does not assess the conduct of any organisation other than as reported in ASIC’s own media release.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Tilt-shift miniature of an AI data centre and microchip: AI tools and ISO 42001
    ISO 42001 AI Management Consulting, Audits & Mentoring
  • Tilt-shift miniature of a submarine periscope casting a narrow cone of light onto one small island of activity in a vast dark ocean
    ISO Clause 4.3: Determining Your Scope (Inside Your…
  • Consultant outlining ISO 9001 requirements
    How to Get ISO Certified in Australia: The Full…

Filed Under: Articles Tagged With: #iso14001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire