Shield froze in February 2024, went into receivership in August, and was wound up that December.
My thought for you this is week is this…
Time is not neutral. Time becomes evidence that can damn you. Or it becomes your triumph.
The difference between those is in your handling, and thus your hands (metaphorically speaking obv).
CONTEXT
ASIC now alleges former Keystone Asset Management director Paul Chiodo was raising fresh SMSF money in August 2025 through the Royce entities, promoting offshore vehicles tied to a Fiji hotel development with a “guaranteed or fixed return of 13% per annum.”
To be clear, these are allegations, not findings. Still, we’re looking at:
- Guaranteed 13%
- A Fiji hotel
- With a collapsed fund in the rear-view mirror.
Sometimes the red flag isn’t hiding. It’s wearing hi-vis and waving.
ASIC’s action against Royce is the latest in a long chain of investigations, court proceedings and adviser bannings connected to Shield and First Guardian.
Strong action, sure, but it’s also litigating sh1t that’s already gone wrong, people’s money gone.
I’m all for enforcement, but it’s not prevention, and it doesn’t halt harm that is WIP.
Warnings, and high vis danger signs, were clear before any public interventions landed.
Eventually, things moved to stop Chiodo, but the money moved faster.
Now the Compensation Scheme of Last Resort estimates its FY2027 levy at $198.1 million, with $190.3 million falling on personal financial advice. Advisers who did nothing wrong are being invoiced for failures they did not create.
I’m using this example to point to risk in your own business.
Bendigo gave us the same sickness in a different outfit this week.
APRA says Bendigo and Adelaide Bank has agreed to an $8 million civil penalty, subject to court approval. A 2020 penetration test identified weak password and customer-ID controls. APRA says those weaknesses remained in March 2023 when an attacker accessed 257 accounts and moved $490,000 across 87 Alliance Bank customers.
Again, the issue is the gap between “we found the problem” and “we fixed the problem.”
That gap is where liability lives, and your credibility falls to its death.
So don’t just ask what risks exist in your business.
Ask how old they are.
Get the ageing report on unresolved audit findings, cyber fixes, whistleblower reports, complaints and risk actions.
You don’t want a neat fact summary, imo. You want an ugly one with dates.
Anything sitting there for years is, yes, a risk issue.
It’s also a future media question. Or a GEO / LLM result that will stain your name.
That is T in F.E.L.T.
Time tells on you… actually us all. Timing can really bite your brand, or more colloquially, your @rse.