Summary

  • CHESS replacement was never only an information-technology procurement. ASX controlled a post-trade service on which brokers, clearing entities, issuers, registries, investors and regulators depended, so its delivery evidence and public statements had market-wide consequences.
  • ASX paused the original program in November 2022 after an independent review identified major technology, governance and delivery challenges. ASX announced an estimated A$245 million to A$255 million pre-tax derecognition charge, while current CHESS remained the live system and required continued investment.
  • Legal stages must remain distinct. ASIC alleged misleading statements in 2024; ASX admitted misleading or deceptive conduct in June 2026 concerning the February 2022 “progressing well” statement; on 3 July 2026 ASIC announced that the Federal Court had ordered a A$20.5 million penalty and a separate A$3 million contribution to ASIC’s costs.
  • The redesigned program selected a TCS product and Accenture as solution integrator, adopted staged delivery and put Release 1 clearing live on 20 April 2026. That milestone did not complete Release 2 settlement and subregister work, and it did not erase the earlier governance and disclosure record.
  • Durable repair requires an assurance ledger that connects requirements, program status, board decisions, vendor dependencies, entity readiness, operational resilience, disclosure controls, regulatory findings and closure evidence. A green milestone without that chain is not public proof.

A replacement program became public infrastructure governance

CHESS is a post-trade system, not a consumer application that can be replaced behind a maintenance banner. It supports clearing and settlement functions and the subregister arrangements through which legal and operational interests in securities are administered. Its users include market operators, clearing and settlement entities, brokers, share registries, issuers and investors. Each organisation builds its own systems, procedures, testing calendars and staffing plans around the interfaces and operating rules ASX provides. A change at the centre therefore creates work and risk at every edge.

That dependency changes the meaning of accountability. A normal technology buyer can absorb some schedule error as an internal cost. ASX could not treat the replacement timetable as a private estimate because entities were spending money to connect, test, train and plan cutover. Nor could it solve delay simply by keeping quiet until certainty arrived. The operator of critical market infrastructure has to communicate uncertainty accurately enough for others to govern their own exposure. The information itself becomes a control.

The public record also shows why the case should not be reduced to a failed software build. ASX was simultaneously a listed company making market disclosures, the operator of the existing CHESS service, the sponsor of its replacement, a counterparty to technology suppliers, a rule setter for entities and a regulated infrastructure provider. Those roles created overlapping duties. A statement that might look like ordinary investor relations also influenced entity readiness. A program decision that looked like procurement also affected financial stability.

A board paper about delivery status therefore sat inside a much larger accountability perimeter.

This perimeter is the central question: who could observe the state of the work, who could stop or replan it, who could challenge optimistic reporting, who could require independent evidence, and who would pay when the timetable changed? Responsibility follows those practical controls. It does not disappear into a general label such as “complex transformation,” and it should not be assigned as unsupported percentages among ASX, vendors, regulators and users.

The chronology is an evidence chain, not a morality play

ASX decided to replace CHESS in 2016 and later chose an architecture associated with distributed-ledger technology. The program evolved through design, development and industry-test activity. Public timelines were revised more than once. By late 2021 and early 2022, the later ASIC record described material delivery concerns, red status reporting and test environments opening with reduced scope or performance. On 10 February 2022, ASX made public statements about the project’s progress and the planned April 2023 go-live.

Six weeks later, ASX announced a strong likelihood of delay. It commissioned Accenture to conduct an external review of the application, ledger and delivery arrangements. On 17 November 2022, ASX said it would pause the program, reassess the solution design and derecognise the capitalised software. The company estimated a non-cash pre-tax charge of A$245 million to A$255 million. The same announcement said current CHESS was performing and would continue to receive investment, an important boundary: the abandoned path had not replaced the live service.

The external review produced 45 recommendations. Public regulator material describes them as addressing the work needed to deliver a replacement aligned with program objectives, while later special-report and audit processes tracked ASX’s response. The recommendations should not be turned into invented quotations or treated as a single technical verdict. Their importance is structural. They covered the relationship between solution design, requirements, delivery planning, governance, testing, resourcing and assurance. A critical program had accumulated problems across those control layers.

In November 2023, ASX announced a new product-based solution using a TCS platform, with Accenture appointed as solution integrator. It proposed two releases: clearing first, followed later by settlement and subregister services. Regulators acknowledged the design decision while retaining expectations for safe delivery and independent assurance. This was a redesign and reallocation of implementation risk, not a restart that made the previous record irrelevant.

Release 1 clearing went live on 20 April 2026. ASX stated that the clearing service continued to operate normally. That is a material operational milestone. It is not evidence that Release 2 was complete, that all program risk had closed, or that earlier disclosures became accurate with hindsight. Accountability needs a chronology that permits both facts to remain true: a later release can succeed, and an earlier statement can still have been misleading when made.

Allegation, admission and court order are different records

Legal precision matters because accountability journalism can create its own distortion by compressing a proceeding into a verdict. In August 2024, ASIC commenced Federal Court proceedings and alleged that ASX’s February 2022 statements about the project being “on-track for go-live” in April 2023 and “progressing well” were misleading. At that stage, those were regulator allegations contained in a filed concise statement and media release. They were not yet findings.

The position changed in June 2026. ASIC announced that ASX had admitted the “progressing well” statement was misleading and exposed market entities to the risk of financial harm. ASIC’s account said ASX admitted that the project had not been on its critical path for the April 2023 date at the relevant earlier point, had been internally classified red and had unresolved scope, performance and timetable issues. The proposed resolution still required the Court’s approval.

On 3 July 2026, ASIC announced the Federal Court’s orders. The Court ordered ASX Limited to pay a A$20.5 million penalty for the misleading statement about the progress of the CHESS replacement project. ASIC also reported a separate order requiring ASX to contribute A$3 million toward the regulator’s costs. The final record therefore supports language about an admission and a Court-ordered penalty. It does not authorise claims about individual directors’ personal liability, criminal conduct, intentional deception or a judicial allocation of blame among every entity in the program.

The distinction between the two February representations also deserves care. ASIC’s 2024 case described both “on-track” and “progressing well” allegations. The 2026 admission and penalty material foregrounds the misleading “progressing well” statement and its relationship to the project’s actual status. A responsible account should not silently expand a settled admission beyond the published court and regulator record. The discipline is simple: identify the source, the procedural stage and the exact proposition it supports.

This legal sequence does more than resolve wording. It demonstrates that a delivery-status claim by a market-infrastructure operator can expose entities to financial risk even without a system outage. Entities make investments, reserve people, modify interfaces and schedule testing in reliance on the operator’s timetable. If the internal evidence and external message diverge, the harm perimeter includes wasted preparation, delayed alternatives and impaired planning. Disclosure control is therefore part of operational control.

Distributed ledger technology is not a substitute for root cause

The original replacement path used a distributed-ledger design, and that fact has made the case attractive as a referendum on blockchain. The public record does not support such a simple conclusion. A technology choice can increase novelty, integration work, performance uncertainty or specialist dependency, but those effects still have to be demonstrated in the particular architecture and delivery model. It is not enough to say that distributed ledger technology inherently caused the program’s failure.

The external review and subsequent public records point to a combination of solution-design, requirements, governance and delivery challenges. Those categories can exist in conventional systems too. A familiar database does not cure unclear requirements. A widely deployed product does not guarantee correct customisation. A strong vendor does not replace sponsor-side architecture authority. A sophisticated assurance plan cannot help if material findings are neither escalated nor reflected in decisions.

The useful comparison is therefore between control models, not slogans. In the original program, the key questions include whether requirements were complete and stable, whether the application and ledger could meet non-functional needs, whether delivery dependencies were visible, whether test evidence matched the timetable and whether status reporting reached decision makers without being diluted. In the redesigned program, the same questions return around product fit, configuration, integration, cloud and vendor dependencies, staged interfaces, data migration and operational readiness.

The choice of a TCS product in 2023 changed parts of the risk profile. A product used or implemented in other markets can reduce some bespoke-development risk and provide operating history. It may introduce product constraints, upgrade dependencies and the need to reconcile another market’s design assumptions with Australian legal and operational structures. Accenture’s solution-integrator role can add coordination capacity, but it also creates a boundary that ASX must govern. The accountable sponsor cannot outsource the meaning of “ready.”

Internal status must survive the path to public disclosure

The most consequential control gap in the legal record is the distance between internal program evidence and external language. A project can have thousands of status items, but a board and market announcement need a small number of truthful conclusions. The process that compresses detailed evidence into those conclusions is a disclosure system. It needs ownership, thresholds, challenge, traceability and a way to stop optimistic language when underlying indicators conflict.

Red status is not automatically proof that a program cannot recover. Complex programs can return to plan. But a red classification, a broken critical path, reduced-scope test environments and delayed incomplete work are information that must be reconciled before management says a program is progressing well. The accountable question is not whether one report used a red colour. It is what the colour meant, which unresolved issues produced it, who saw it, what recovery evidence existed and why the public message remained supportable.

Boards cannot read every engineering ticket, and executives cannot put every caveat into a market release. That practical limit makes evidence design more important, not less. A critical-program dashboard should connect schedule confidence to named dependencies; test readiness to entry and exit criteria; architecture confidence to unresolved decisions; vendor confidence to deliverables; and entity readiness to observed results. Each summary claim should have an evidence owner and a dated source.

Disclosure committees or equivalent governance forums should test negative propositions as well as positive ones. What evidence would show that the date is no longer credible? Which assumptions have no margin? Are test environments representative? Have scope reductions changed what a milestone means? Are there risks that can only be retired after entities complete work? If management cannot answer those questions, confidence language should narrow.

The February 2022 record is also a lesson about timing. Information can be technically accurate at one layer and misleading in the whole. Code may have been delivered, a test environment may have opened and teams may have been working intensely. Those facts do not necessarily support a conclusion about the program as a whole. A disclosure control must prevent local progress from being aggregated into system-level reassurance without evidence that the critical path, performance and remaining scope are coherent.

The board’s control is direction, evidence demand and stop authority

ASX’s board did not write the software, but that does not make it a spectator. Board control in a critical transformation includes approving strategy and risk appetite, appointing accountable executives, demanding decision-useful reporting, ensuring sufficient independent assurance and challenging whether management’s confidence matches the evidence. The board also controls whether the organisation pauses, replans or continues when the cost of delay competes with the risk of unsafe migration.

The public record indicates that board and committee structures received program information at different points. Parliamentary and regulatory material later examined governance, board reporting and technology capability. It would be wrong to infer from the public record exactly what each director knew on every date. Board minutes, complete packs, oral briefings and privilege-protected advice are not fully public. The accountability test is instead what a robust record should show.

That record should identify the program’s decision rights. Who could change the go-live date? Who could accept reduced test scope? Who owned non-functional requirements? Who could declare a milestone complete over an assurance objection? Who decided the wording of market announcements? Who tracked the market cost of schedule changes? Ambiguity among committees is itself a risk because it allows every forum to believe another has resolved the hard question.

Decision-useful reporting should be shorter than the evidence base but not shallower. The RBA’s later assessment observed that technology and risk papers had been overly long and technical and did not sufficiently highlight key issues. Volume can create an appearance of diligence while hiding the decision. A useful board paper states the question, the evidence, dissent, uncertainty, option costs, control owners and consequences of delay. Appendices can hold detail, but the central conflict must be visible.

Stop authority is the most important control because market-infrastructure programs accumulate pressure to continue. Entities have spent money. Public dates have been announced. Executives have reputational capital invested. Vendors have teams mobilised. Those facts create sunk-cost and commitment bias. The November 2022 pause shows that stopping was possible, but accountability asks whether equivalent challenge should have changed language or direction earlier. The answer requires nonpublic evidence, so the article does not pretend to know it. It does insist that future governance make the stop criteria explicit.

Management owns the integrated truth

Senior management sits between technical evidence, vendor performance, entity readiness, board oversight and public disclosure. Its practical control is integration. Individual teams can report accurately while the overall program remains misrepresented if nobody owns the combined critical path. Management must reconcile schedule, scope, quality, operational risk and external dependency rather than allowing each workstream to define its own green status.

This requires a program baseline with controlled changes. Every deferred feature, reduced test condition, shifted dependency or workaround should alter the forecast and risk model. A milestone should not retain its old name after its substance changes. If an industry test environment opens with reduced capability, the report must state what cannot yet be tested and what that means for later confidence. “Opened” is an activity fact; “ready” is an assurance conclusion.

Management also controls resources. Critical infrastructure replacement competes with maintenance of the live system, other transformation work and regulatory remediation. A schedule that assumes scarce architects, testers or operational experts can work in several places at once is not a plan. Resource contention should appear in the integrated risk view, including vendor specialists and entity staff outside ASX’s direct employment.

Vendors deliver components; ASX retains outcome accountability

The original program involved specialist technology providers, and the redesigned program selected TCS with Accenture as solution integrator. These firms control important deliverables, staffing, technical decisions, quality processes and escalation. They should be accountable for contractual performance and truthful reporting within their scope. But the market did not delegate the clearing and settlement licence to a vendor. ASX retained control over requirements, architecture acceptance, integration, entity obligations, public timing and the decision to migrate.

A solution-integrator model is useful only if interfaces are explicit. The integrator should maintain an integrated design, dependency map, test strategy, release plan and defect picture. Product teams should disclose limits and customisation. ASX should retain independent architecture, security and operations capability capable of challenging both. If the sponsor depends on the integrator to explain whether the integrator’s own work is acceptable, independence is weak.

Contracts matter, but the accountability file cannot end with contract compliance. A supplier may meet a deliverable definition while the system is not operationally ready. Conversely, a supplier can miss an intermediate date without threatening the final outcome if genuine recovery evidence exists. Governance needs technical acceptance criteria and system-level outcomes. It should identify which requirements are statutory, which arise from market practice, which protect financial stability and which can be deferred without changing the public meaning of a release.

Vendor concentration also deserves attention. Replacing bespoke technology with a product can bring mature capability, yet product roadmaps, specialist skills, security updates and other-market deployments create dependencies. Those dependencies should appear in exit plans, source and configuration escrow where appropriate, skills transfer, patch arrangements, performance evidence and long-term support terms. Accountability follows practical control, so ASX should show how it can continue to operate and govern the service when vendor incentives diverge.

Entities carried preparation risk outside ASX’s accounts

The A$245 million to A$255 million pre-tax derecognition estimate was an ASX-announced accounting consequence for capitalised software. It was not the total social or market cost of the paused program. Clearing entities, brokers, registries, market operators and service providers had their own development, testing, staffing and planning expenses. Regulators’ 2022 letter explicitly noted significant industry costs and concern that they had not been borne equally.

This distinction matters because accounting boundaries can hide accountability boundaries. ASX could recognise its own write-down, but it could not see every entity invoice or opportunity cost. A small firm may experience a timetable change differently from a large bank with reusable infrastructure. A registry may have a different dependency from a broker. A competing market operator may need interfaces whose value depends on the final scope. Aggregating them into “industry” conceals who absorbed risk.

Entity readiness is also a control input, not merely a communications task. The central system cannot be declared ready if essential entities cannot complete representative testing, reconcile messages, recover from failure or operate the cutover. But entities do not control the core design or the credibility of ASX’s schedule. They should not be assigned responsibility for delays caused by information they could not observe.

An accountable program should maintain a entity-impact ledger. It should record required changes, dependency dates, testing evidence, known workarounds, sunk costs created by replanning and the distribution of burden. Consultation should identify disagreement, not just attendance. When ASX changes scope or sequencing, the ledger should show which entities gain, which incur rework and which risks move rather than disappear.

Keeping current CHESS reliable was a parallel program

When the original replacement path paused, current CHESS remained the live system. ASX’s 2022 announcement said it was performing and would continue to receive investment. ASIC and the RBA stressed reliable support and maintenance until a replacement could safely go live. That boundary prevents two misleading narratives: the pause did not itself shut the market, and the existence of an ageing system did not make immediate migration safer than disciplined delay.

Legacy continuity requires its own roadmap, funding and skills. Teams must maintain vendor support, capacity, security, operational procedures and recovery arrangements while replacement work consumes attention. A long transition can create a dangerous assumption that the old system is temporary and therefore needs only minimum care. In critical infrastructure, temporary systems often remain for years. Their residual life has to be engineered, not wished away.

The RBA’s 2023–24 assessment described work to upgrade the CHESS database, test high-volume capacity and remediate a breakpoint found at an extreme volume. That evidence is useful because it shows active maintenance and limits. It should not be interpreted as proof that every resilience concern was closed. Capacity testing, incident recovery, cyber controls, change management, data integrity and specialist staffing are separate evidence streams.

The replacement and live-service programs also share resources. An expert needed to explain legacy settlement logic may be required for the new design and for daily operations. Moving that person can create hidden risk. An integrated portfolio view should show such conflicts and protect live-service staffing. The safe migration date is not only when the new release is ready; it is when the old service, transition mechanism, entities and new service can jointly support the move.

Forty-five recommendations required closure evidence

The Accenture external review produced 45 recommendations, and later regulatory notices required special reporting and audit around ASX’s response. Counting recommendations is not assurance. A recommendation can be marked complete because a policy exists while the underlying behaviour remains unchanged. Closure needs evidence that the intended control operates, is used in decisions and remains effective under pressure.

Recommendations should be grouped by risk outcome. Requirements recommendations should produce traceable, approved and testable requirements. Architecture recommendations should produce decisions, alternatives, non-functional evidence and accountable owners. Delivery recommendations should create realistic dependencies and forecast discipline. Governance recommendations should improve escalation and decision rights. Testing recommendations should connect environments, data, entry criteria, defect thresholds and operational scenarios.

Each closure should have an owner independent enough to challenge the delivery team. Evidence might include approved artefacts, observed governance meetings, sampled decisions, completed tests and proof that exceptions are escalated. If management accepts residual risk, the acceptance should name the impact, duration, compensating control and expiry. Closing an action without closing its risk should remain visible.

The special-report and audit process added regulator-directed structure, but external supervision cannot run the project. ASIC can require reports and assess licence obligations; the RBA can assess financial stability standards and operational risk; auditors can test defined controls. ASX still has to generate truthful evidence day by day. A regulator receiving late or compressed information cannot repair an earlier management decision in real time.

The 2023 redesign changed the delivery shape

ASX’s November 2023 announcement selected a TCS product and named Accenture as solution integrator. It divided delivery into Release 1 clearing and Release 2 settlement and subregister functions. ASX described stakeholder input from the Technical Committee, Business Committee and an advisory group, and anticipated further consultation on plan, scope and timing. The RBA and ASIC acknowledged the decision while emphasising safe implementation and independent assurance.

Staging can reduce a single cutover’s concentration of change. Clearing functionality can move while settlement and subregister services remain on the later path, allowing evidence and operational experience to accumulate. It can also create temporary interfaces and hybrid-state complexity. The accountability question is not whether staging is universally safer. It is whether ASX identified the new failure modes, tested cross-release boundaries and explained what remained dependent on current CHESS.

Release definitions must therefore be public enough for users to plan. “Clearing” should identify functions, messages, entities, migration conditions and fallback arrangements. Settlement and subregister work must not be implied complete because the program uses the singular label “CHESS replacement.” A staged program needs staged language. The public should be able to distinguish product selection, design completion, test readiness, operational readiness, go-live and post-implementation stability.

The product-based approach also requires fit analysis. Use in other markets is relevant evidence, but Australian market structures, direct holdings, messaging, legal obligations and entity ecosystems may differ. Product pedigree cannot replace local requirements. Customisation should be controlled because it can erode the benefits of a standard product; refusal to customise can also force risky operational workarounds. The decision record should make that trade-off visible.

Accenture’s integration role creates a second-order assurance question because Accenture also performed the 2022 external review. The public record supports both roles, but it does not by itself establish a conflict or lack of independence. Governance should document role boundaries, assurance-provider independence and who validates integrator work. The correct response is evidence, not insinuation.

Release 1 was a milestone, not absolution

ASX’s public Release 1 page says clearing went live on 20 April 2026 and continued to operate normally. That is concrete evidence that a material part of the redesigned program reached production. The Technical Committee record after go-live also shows ongoing design work and open matters associated with later stages. The responsible conclusion is that Release 1 happened; Release 2 remained later work in the selected record.

Post-go-live assurance should test more than service availability. It should reconcile transactions, exceptions, performance, capacity, security events, entity incidents, manual interventions and defects. It should compare actual operational results with assumptions used in the go-live decision. Early normal operation is encouraging, but low incident counts over a short window cannot establish long-term resilience.

A release also needs a defined warranty and stabilisation period. Ownership should move deliberately from program teams to service operations. Known defects should have risk classification, temporary controls and closure dates. Vendor support escalation should be exercised. Entities should have a route to report discrepancies without having to prove first that the central platform caused them.

The later success does not cancel the A$20.5 million penalty or turn the February 2022 statement into a harmless forecast. The Court order addressed conduct at the time of the statement. Nor does the penalty prove that the redesigned release was unsafe. Combining those propositions would reproduce the same accountability error in reverse: using one fact outside its time and scope.

The December 2024 incident is a distinct signal

On 20 December 2024, a technology issue in current CHESS caused a batch settlement failure, and the failed transactions were settled on the next business day. The RBA’s out-of-cycle assessment described incorrect memory-allocation logic and the absence of planned and fully tested alternative arrangements for that scenario. It downgraded operational-risk ratings for ASX Clear and ASX Settlement.

That incident belongs in the accountability record because it concerned the same operator and live infrastructure during a long replacement period. It should not be described as an outage caused by the abandoned replacement design. It occurred in current CHESS and had its own technical and contingency-control chain. Conflating the two would obscure rather than explain risk.

The incident demonstrates why legacy maintenance and replacement governance cannot be separated. A delay extends exposure to current-system limitations. An unsafe rush creates migration risk. Regulators and the board must compare those risks using evidence, not assume that either “replace faster” or “delay until perfect” is automatically correct. The decision changes as defects, capacity, entity readiness and assurance findings change.

It also shows the value of scenario-specific contingency testing. General business-continuity plans do not prove that a failed settlement batch can be recovered within the market’s timing and liquidity constraints. Critical functions need rehearsed alternatives, decision thresholds, communications and reconciliation. The absence of a tested path is an operational fact with governance consequences.

The wider inquiry expands scrutiny but does not rewrite causation

ASIC launched a broader inquiry into ASX in 2025, and the expert panel’s final report was published in April 2026. ASIC described work on governance, capability, risk management and the stewardship of critical market infrastructure. The panel’s observations included concerns about infrastructure resilience, governance focus, capability, culture and the maturity of risk and compliance practices.

Those findings provide institutional context. They do not prove that every concern caused the original CHESS replacement failure, nor should every later operational issue be treated as part of one undifferentiated event. The inquiry drew on a wider record, including interviews, documents, benchmarking and case studies. Its recommendations and ASX commitments deserve their own tracking.

The connection is accountability architecture. Repeated concerns about reporting, project capability, operational incidents and board focus can indicate that controls need enterprise-level repair rather than isolated fixes. If a program improves while the institution still cannot surface bad news, allocate resources or challenge risk, durable repair remains incomplete.

ASIC and the RBA have complementary roles. ASIC supervises market and clearing-and-settlement licence obligations, including fair and effective services. The RBA applies financial stability standards and assesses clearing and settlement facilities. Joint oversight can strengthen coverage, but it creates a coordination boundary. Expectations, evidence requests and escalation should be coherent so that ASX cannot satisfy one reporting track while a material issue remains invisible to another.

Responsibility should be allocated by practical control

ASX’s board controlled governance design, executive accountability, risk appetite, major direction, assurance demand and the authority to pause or approve critical decisions. Its boundary was that directors depended on management and assurance providers for detailed evidence. That dependence increases the need for decision-useful reporting; it does not erase oversight responsibility.

ASX management controlled the integrated plan, resources, vendor direction, escalation, internal status, entity engagement and public recommendations. Its boundary was that suppliers and entities controlled work in their own environments. Management nevertheless owned the system-level truth and should have adjusted conclusions when dependencies weakened.

Program leadership controlled day-to-day baselines, requirements, architecture coordination, testing, issue management and reporting. Its boundary was formal authority: leaders could not necessarily change public dates, budgets or risk appetite alone. They did control whether evidence was accurately recorded and escalated.

Technology vendors and integrators controlled contracted components, technical skill, delivery estimates, defect disclosure and integration work. Their boundary was ASX’s retained authority over licensed infrastructure, market rules, acceptance and migration. Contracting did not transfer the public duty to operate reliable clearing and settlement services.

Clearing entities, registries, brokers and other market users controlled their own builds, tests, operations and timely disclosure of readiness problems. Their boundary was information and central design. They could not validate evidence ASX or suppliers did not expose, and they should not bear blame for reliance on materially misleading progress language.

ASIC controlled investigation, enforcement, licence supervision and requirements for special reports within its legal remit. The RBA controlled financial-stability assessment and supervisory expectations within its remit. Their boundary was that neither regulator could replace ASX management or guarantee delivery. Regulatory action can compel evidence and consequences; it cannot manufacture operational capability.

Government and Parliament controlled legislation, regulator powers, inquiry and public policy. Investors and end users controlled little of the program but bore confidence and service consequences. An accountability model should therefore avoid symmetrical language such as “all stakeholders were responsible.” Stakeholders had different powers. The party able to decide, observe or stop a risk should carry the matching evidence duty.

Known unknowns constrain the conclusion

The public record does not provide the complete board packs, minutes, internal correspondence, vendor work papers, source code, architecture decisions, defect registers, test results, assurance evidence or entity cost data for the original program. It cannot establish what every individual knew on every date. It does not support assigning percentage blame or alleging deliberate concealment by named people.

It also does not permit a clean technology counterfactual. No public experiment shows that the same requirements, people, governance and timetable would have succeeded on a conventional architecture. Nor can Release 1 prove how the original design would have performed under different controls. Claims that blockchain caused everything, or that management alone caused everything, exceed the evidence.

For the redesigned program, public information confirms selection, staging and Release 1 go-live, but not every security test, defect, capacity scenario, entity exception or independent assurance result. Release 2 remained future work in the selected evidence. The article therefore does not claim complete CHESS replacement.

The total external cost of the pause is also unknown. ASX disclosed its derecognition estimate, while regulators noted industry costs. A credible total would need entity-level evidence, treatment of reusable work, opportunity cost and time boundaries. The absence of a single number should not be mistaken for absence of harm.

A concrete assurance ledger is the durable repair

Durable repair should be visible in a ledger that boards, regulators and market users can interrogate. It need not expose sensitive security designs or commercial terms. It should expose the structure of confidence: what claim is being made, what evidence supports it, who owns it, what remains open and what event would invalidate it.

The first ledger domain is requirements. Every critical function and non-functional property should have an owner, source, acceptance method and change history. Requirements should distinguish clearing, settlement, subregister, messaging, security, availability, recovery, capacity, legal and entity obligations. Deferred requirements should show which release owns them and what temporary dependency remains.

The second domain is architecture and product fit. Records should connect Australian market structures to product capability, customisation and interfaces. Major decisions should state alternatives, assumptions, performance evidence, security review and residual risks. Vendor claims should be validated against representative environments. Architecture waivers should expire rather than become permanent through silence.

The third domain is integrated delivery status. The critical path should link ASX, TCS, Accenture, other suppliers and entity milestones. Status should preserve negative evidence: overdue dependencies, compressed test windows, reduced scope and unresolved design. Recovery plans should have measurable actions and probability ranges, not only new dates.

The fourth domain is testing and assurance. It should identify environments, data representativeness, entry and exit criteria, defects, capacity scenarios, security testing, operational simulations, migration rehearsals and independent reviews. A passed test should specify what was tested and what was not. Assurance findings should map to actions, owners, due dates, residual risk and independent closure evidence.

The fifth domain is entity readiness and burden. ASX should record which entities completed which tests, exceptions by function, interface stability, support volumes, workarounds and readiness attestations. It should also track rework and timetable costs by entity class where feasible. Aggregates should not conceal a small group unable to operate a critical function.

The sixth domain is current-system continuity. Current CHESS capacity, security, change, incident, vendor-support, staffing and recovery evidence should remain visible until the relevant functions are retired. The ledger should show resource conflicts between maintenance and replacement. Every extension of legacy life should trigger a reassessment of support and contingency assumptions.

The seventh domain is cutover and fallback. Each release needs objective go/no-go criteria, authority, rollback or contingency conditions, entity communications, reconciliation and post-go-live monitoring. If rollback is technically impossible after a point, the plan should state the alternative recovery path. A board should not learn that distinction during an incident.

The eighth domain is disclosure control. Every material public claim about progress, date or readiness should cite the internal evidence set and record challenge. The file should identify who drafted, verified and approved the language, how contrary indicators were resolved and which later event would require correction. This is where the 2022 lesson becomes operational rather than rhetorical.

The ninth domain is regulatory and board oversight. ASIC and RBA recommendations, licence conditions, financial-stability findings, inquiry commitments and board actions should share stable identifiers. Closure should include evidence, reviewer and date. Repeated themes across programs should trigger enterprise remediation rather than duplicate paperwork.

The tenth domain is outcomes. After go-live, ASX should publish bounded evidence about availability, settlement and clearing integrity, exceptions, material incidents, capacity, entity impacts and closure of stabilisation findings. Confidential details can remain protected while aggregate assurance becomes public. A release that cannot show outcomes remains dependent on reassurance.

The ledger should be versioned and tamper-evident, with access appropriate to sensitivity. It should preserve historical status rather than overwrite red with later green. Boards need the trend; regulators need the evidence chain; entities need the implications for their own controls. Independent reviewers should sample not only artefacts but decisions made from them.

No ledger can remove uncertainty. Its purpose is to make uncertainty governable. It allows ASX to say, for example, that clearing has gone live and operates normally while settlement and subregister work remains later; that one assurance issue is closed while another is accepted temporarily; or that a date has confidence only if named entity milestones occur. This precision is more trustworthy than a broad claim that the program is going well.

Accountability means preserving both continuity and memory

ASX’s CHESS replacement record is valuable because it contains failure, enforcement, redesign and a later operational milestone without collapsing them into one verdict. The 2022 pause did not cause a market outage. The current system remained live. The write-down did not capture all external cost. The distributed-ledger label did not by itself establish root cause. The 2024 settlement incident was distinct. Release 1’s 2026 go-live did not complete Release 2.

The legal record is equally bounded. ASIC’s allegations in 2024 became a narrower admission and Court-ordered consequence in 2026. The A$20.5 million penalty and A$3 million costs contribution are official outcomes, but they do not answer every technical or individual-responsibility question. They establish that accuracy about a critical infrastructure program carries enforceable weight.

The enduring standard is practical control. ASX controlled the licensed service, program acceptance, disclosure and migration decision. Vendors controlled important components. Entities controlled their own readiness. Regulators controlled supervision and enforcement. Each actor owes evidence proportionate to that control, and boundaries should be explicit rather than used as places to lose accountability.

Evidence trail

  1. https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-143mr-asx-ordered-to-pay-20-5-million-penalty-for-misleading-conduct-relating-to-chess-replacement-project/
  2. https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-119mr-asx-admits-misleading-conduct-relating-to-chess-replacement-project/
  3. https://asic.gov.au/about-asic/news-centre/find-a-media-release/2024-releases/24-177mr-asic-sues-asx-for-alleged-misleading-statements/
  4. https://download.asic.gov.au/media/zx2jijyi/24-177mr-concise-statement-13-august-2024.pdf
  5. https://www.asx.com.au/content/dam/asx/about/media-releases/2022/60-17-november-2022-CHESS-Replacement-ASX-reassessing-financial-derecognition_.pdf
  6. https://download.asic.gov.au/media/sypbow5u/22-320mr-asic-rba-letter-to-asx-board.pdf
  7. https://asic.gov.au/about-asic/news-centre/news-items/asic-acknowledges-asx-s-release-of-the-chess-program-external-review-special-report-and-audit-report/
  8. https://www.asic.gov.au/regulatory-resources/markets/inquiry-into-asx/
  9. https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-059mr-asic-publishes-asx-inquiry-panel-final-report-and-acknowledges-observations/
  10. https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2025-releases/25-303mr-asic-announces-transformational-package-to-safeguard-australia-s-financial-markets-in-response-to-asx-inquiry-interim-report/
  11. https://www.asx.com.au/content/dam/asx/about/media-releases/2023/70-20-november-2023-chess-replacement-solution-announced-and-2024-consultation.pdf
  12. https://www.rba.gov.au/media-releases/2023/mr-23-32.html
  13. https://www.rba.gov.au/payments-and-infrastructure/financial-market-infrastructure/clearing-and-settlement-facilities/assessments/2023-2024/developments.html
  14. https://www.rba.gov.au/payments-and-infrastructure/financial-market-infrastructure/clearing-and-settlement-facilities/assessments/2024-2025/march/pdf/out-of-cycle-assessment-report-march-2025.pdf
  15. https://www.aph.gov.au/Parliamentary_Business/Committees/Joint/Corporations_and_Financial_Services/OversightofASIC/Competition_in_clearing_and_settlement_and_the_ASX_CHESS_Replacement_Project/Chapter_5_-_The_ASX_CHESS_Replacement_Project_-_Background
  16. https://www.aph.gov.au/Parliamentary_Business/Committees/Joint/Corporations_and_Financial_Services/OversightofASIC/Competition_in_clearing_and_settlement_and_the_ASX_CHESS_Replacement_Project/Chapter_7_-_The_ASX_CHESS_Replacement_Project_-_ASX_Governance
  17. https://www.asx.com.au/markets/clearing-and-settlement-services/chess-project/release-1-clearing
  18. https://www.asx.com.au/content/dam/asx/markets/clearing-and-settlement-services/technical-committee/2026/chess-replacement-technical-committee-6-may-2026-presentation.pdf