01
Desk research · 25 July 2026 · Confidence marked per source
What organisations are actually required to record about a complaint
People are often told a complaint “has been logged” without ever learning what that means. It has a fairly precise answer, and in the regulated part of the Australian economy the answer is legally binding. We went looking for it — because an intake layer that produces something a company cannot file is of no use to anyone, and because a person is entitled to know what happens to what they said.
The regulated segment: ASIC’s IDR data reporting
Australian financial firms must report internal dispute resolution data to ASIC under RG 271, which commenced on 5 October 2021, with data reporting phased in from 2023 across roughly 10,500 firms. The IDR data reporting handbook sets a mandatory data dictionary, submitted as CSV and machine-validated. It is not a wishlist: a firm that cannot produce these fields is in breach.
| What is recorded |
Notes |
Our confidence |
| Complaint status |
Open or closed. |
High
Verified in the handbook text
|
| Complaint channel |
The channel the complaint was first received through — face to face, phone, email, web chat, online form, social media, AFCA referral, other, unknown. |
High
Verified in the handbook text
|
| Date received |
Calendar date. |
High
Verified in the handbook text
|
| Date closed |
Required once the complaint is closed. |
High
Verified in the handbook text
|
| Days taken to resolve |
Calendar days; a same-day close counts as zero. |
High
Verified in the handbook text
|
| Product or service |
Up to three per complaint. |
High
Verified in the handbook text
|
| Complaint issue |
Up to three; where there are more, the firm records the three most significant. |
High
Verified in the handbook text
|
| Identifier, brand or fund, complainant type, representative involved, outcome, compensation amount |
Reported alongside the above. |
Medium
From ASIC summary material, not checked line-by-line
|
| Complainant gender, age and postcode |
Part of the dictionary; see our position on demographics below. |
Medium
From ASIC summary material, not checked line-by-line
|
The narrative around the table — the commencement date, the phase-in from 2023, and the figure of roughly 10,500 firms — comes from ASIC’s own summary material rather than the handbook’s text, and should be read at the same medium confidence as the last two rows.
Hardship is a complaint issue, not a footnote.
Financial difficulty and debt collection sit in the taxonomy as a top-level issue category alongside charges, service, transactions and scams. An organisation that treats hardship as a special-case flag bolted onto the side of its process is not organised the way its own regulatory report is.
“Service” is one issue category among more than a dozen.
A great many complaints are, in ordinary language, about being treated badly. In the regulated taxonomy that is a single category — a useful corrective in both directions: poor service is squarely reportable, and it is also far from the whole map.
Everyone else: ISO 10002 and AS 10002
Most organisations are not regulated financial firms. ISO 10002:2018, adopted as AS 10002:2022, applies to any organisation of any size, and its minimum record set per complaint is short.
Nature of the complaint
Date received
Product or service
Organisational unit or location
Resolution provided
Time to resolution
Outcome
What the standard says the record is for matters more than the list: identifying trends that indicate systemic problems, finding root causes so corrective action is possible, and measuring the process against its own timeframes. A complaint record that cannot support those uses is filing, not complaint handling. The clearest public treatment is the UK FCA’s review of complaints and root cause analysis — which applies to a gym as much as to a bank.
The finding
The two regimes were written for different audiences and converge on four things. These are the irreducible record of a complaint in Australia; everything else is segment-specific.
01
The date it was received
02
The product or service involved
03
The nature of the issue
A complaint that states plainly what you bought, what went wrong, when, and what you want done lands as something the receiving organisation can file, count and escalate on day one. Our free complaint guides are built around exactly those elements.
Our position on demographics
ASIC’s dictionary includes complainant gender, age and postcode. Trumis does not collect them, and our measurement store cannot hold them — it permits no geography finer than jurisdiction, by construction rather than by policy. Those fields belong to the organisation, from the customer records it already keeps. The obligation is met and nothing about the person transits us.
02
Method · Pre-registered
No results yet
Measuring conversational complaint intake: a pre-registered protocol
We think a person should be able to make a complaint by explaining what happened, in their own words, in their own language — instead of translating themselves into a web form’s twelve required fields. We would be poor advocates for that claim if we asked anyone to take it on faith, and worse ones if we ran a trial and then chose the flattering numbers afterwards.
So the protocol is fixed and published before any data is collected. The final report may not add, drop or redefine a metric; anything learned along the way goes in a clearly marked post-hoc appendix.
| Measured |
How |
| Intake completion |
Conversations started versus complaints produced, against the existing form’s start-to-submission rate. |
| Actionable without a callback |
An audit of 50 complaints from each cohort, same scorer, same checklist: could a handler classify it and open a case without ringing the person first? |
| Time to classification and resolution |
Median hours from intake to classified, median days to closed, from the organisation’s own case system. |
| Languages served |
Complaints completed in a language other than English — typically near zero on a form. |
| Phone-channel volume |
Complaints lodged by phone per month, against the same quarter a year earlier. |
| Ombudsman escalation and fees |
External dispute referrals per 100 complaints, and scheme invoice totals, measured 90 days after the pilot. |
The design is deliberately conservative. Trumis is added beside the existing complaint form, never replacing it, so the two cohorts run concurrently and can be compared against each other and against the same quarter last year. Trumis itself contributes only three aggregate counters; every other number comes from a system the organisation already runs and already trusts.
There are no results to report
This is a protocol, not a finding. The thresholds in it are commitments about what would count as success, not outcomes we have achieved. When a pilot has run, the results will be published here against this protocol — including if they fall short of it.
03
Measurement design · Privacy analysis
Publishing complaint trends without holding anyone’s story
There is a genuinely useful public good sitting just out of reach: which complaint topics are rising, which kinds of failure are spreading, and how quickly organisations respond. Nobody publishes it, because the obvious way to build it is to keep everyone’s complaints and analyse them — precisely what we have promised never to do. So the research question is the interesting one: can you measure complaint trends usefully while holding nothing about any person?
Never stored
The conversation, the person’s words, the quotes, the drafted complaint, uploaded evidence, exact amounts, exact incident dates, request identifiers or anything that could be joined back to a payment.
Day granularity only
Never a timestamp, because a timestamp is a linking key.
No geography finer than jurisdiction
And monetary values banded rather than exact.
Conduct categories, never individuals
Misconduct trends are counted from a fixed taxonomy of argument types — no branch, no role, no free text, nothing that could point at an employee.
Every external view is k-anonymous at k = 5
Any cell with fewer than five complaints is suppressed, so a sentence like “one Vietnamese-language urgent complaint about this organisation this week” can never be published, even by us.
Rows expire
On a fixed retention schedule, and internal access is role-gated.
The design is written against OAIC de-identification guidance under the Privacy Act 1988 (Cth), and aims at the stricter GDPR Recital 26 bar for genuinely anonymous information. We also take the view that disclosure is owed even for anonymous data.
The honest limitation
This approach can tell you that complaints about a kind of failure are rising in an industry. It can never tell you whose they were, and it is designed so that no future decision by us could change that.
04
Position paper · Design in progress
The early-warning gap: complaints rarely reach whoever owns the cause
The pattern behind most complaint disasters is not that nobody complained. It is that people complained, repeatedly, into a channel that was never connected to anyone with the authority to change the thing being complained about. The complaint was handled. The cause was not.
We think the missing piece is a route from a lodged complaint to the accountable executive or risk owner, triggered by severity rather than volume — and that severity has to be defined by something other than the organisation being complained about. The floor treats a complaint as critical if it is substantial on any one of three axes.
Organisational
Critical when the incident could substantially damage the organisation itself — systemic conduct, regulatory or legal exposure, reputational risk.
Individual
Critical when the incident could substantially harm the person complaining — financial ruin, loss of an essential service, health, safety or legal rights.
Public safety
Critical when the incident could substantially endanger people beyond the complainant — a hazard or a systemic danger to the public.
The advocacy claim is in the second and third rows. An organisation may raise its own sensitivity and route more to its executives, but it cannot define the floor away — it cannot mark a complaint routine when the harm lands on the person or the public. Severity is computed by deterministic rules over a maintained knowledge base; the language model never sets it.
Trumis does not route externally.
Even a public-safety-critical complaint goes only to the recipients named in the organisation’s contract — never to a regulator, an ombudsman or any duty-to-warn body. Serving the person and the organisation at once is already the hard problem; a third loyalty would break it.
Our role ends at lodgement.
Where a matter is serious, Trumis’s responsibility to the person is discharged at intake, by making sure they understand how serious it is and what escalation path exists. It does not act on that severity itself.
Corrections, citation and contact
Everything above is desk research and design work by the Trumis team, published under our own name — no individual bylines, and no third-party endorsement is implied by any source we cite. Where we have summarised a regulatory document you should read the document.
If we have something wrong, tell us and we will correct it in place and date the change.
Suggested citation
Trumis Pty Ltd, Research, trumis.com.au/research/, 25 July 2026.