Most firms in the insurance industry have reasonable compliance infrastructures in place (the pipeline). However, without data and information flowing through the pipeline, the adequacy of the compliance measures remains in doubt, especially as a means to protect the business, its people, customers, and stakeholders and to meet regulatory requirements on an ongoing basis.
Worse, the pipeline, without data & information, provides false assurance to leaders, management and the board.
However, by focusing on implementing and embedding 5 key compliance activitiesacross the business, the compliance measures will create a cadence that enables the firm to self-regulate, self-manage, self-report and continually improve business operations, the customer experience and pursue opportunities for growth with confidence.
1. Incidents
An incident is an event that occurs where something has gone wrong. Adopting a simple definition of an incident has been identified by ASIC as a key driver of identifying and recording a high number of incidents.
All businesses have incidents, things go wrong, errors occur, bugs are present, processes are not foolproof. Firms who are not reporting any incidents are simply not identifying them. Eventually the incident will result in harm or detriment.
Firms should adopt a wide view of incidents including operational risk incidents, cybersecurity incidents, people incidents, change management incidents, financial & insurance incidents and startegic risk incidents in addition to compliance, legal and regualtory incidents.
Your focus should be training your people (and providing artefacts) that enable them to identify, raise, and quickly report incidents that arise in their area of operation. A more skilled person can then triage incidents and funnel them down the correct pipeline (such as a likely breach or breach of regulatory or Code oprations or an operational risk or a privacy matter or a potential disruption event such as cybersecurity).
2. Complaints
ASIC and the Insurance Brokers Code Compliance Committee have highlighted the under-reporting of complaints across general insurance. As at 30/06/2025 ASIC’s IDR data dashboard shows that 81.7% of general insurance complaints were lodged by only 20 firms.
Fair, timely and effective IDR processes that provide a genuine opportunity for redress are a key consumer protection and can produce beneficial outcomes for both consumers and firms. A positive complaints management culture is imperative to achieve these outcomes— one that takes a proactive approach in identifying a ‘complaint’, and that does not compound or further delay the recovery of customers and businesses from distressing events. ASIC Cause for complaint: Complaints handling in general insurance Report 802 | December 2024
Understanding that a complaint is simply an expression of customer dissatifaction shifts the culture of complaints to a customer experience improvement rather than a compliance obligation.
All complaints must be recorded by the firm including those resolved at first point of contact. Not only does this lead to better customer experiences and business improvements (through the identification of systemic issues) it also enables the firm to meet its regulatory and Code obligations including the reporting of IDR data.
3. Conflicts of interest
Managing conflicts of interest is a central pillar of financial services regulation. The obligation (s912A(1)(aa) Corporations Act) is intended to ensure financial markets and services are fair, efficient, and honest. It promotes both consumer protection and market integrity—preventing misconduct and reducing harm to consumers or investors. It can also improve economic efficiency. ASIC RG 181.8-9
Firms must train their people (employees and authorised representatives) to understand what a conflict of interest is and provide an infrastructure for the periodic reporting of such conflicts. The infrastructure must also enable the firm to adequately manage the conflict and record the conflict and its management.
A conflict of interest can include (see RG 181.33):
(a) conflicts of, or within, the financial services business (including conflicts arising from its corporate structure and relationships);
(b) the conflicts of any individual—for example, clients (retail or wholesale), members, shareholders, employees, directors, third parties—that arise in relation to the financial services business; and
(c) the conflicts of any entity—for example, wholesale clients, counterparties, related entities in intra-group structures, commercial third parties—that arise in relation to the financial services business.
4. Training
AFSL general obligations, APRA Prudential Standards, GI Code of Practice and the Insurance Brokers Code of Practice all impose obligations to have trained and competent employees, authorised representatives, distributors and service suppliers.
Training must cover financial service laws, the relevant Code(s) and the firm’s financial services and products.
People who provide financial product advice to retail clients must have RG 146 qualifications or operate under the clerks or cashiers exemption or the special requirements for customer service representatives.
Training must be recorded, usually in a training register.
5. Assurance activities
Firms have an obligation to monitor and supervise employees, authorised representatives, those providing financial services on behalf of an AFS licensee (including distributors and claims services) and material service providers.
Assurance activities include the following:
- file reviews;
- call recording;
- assurance conducted by the business (1st line) or a central function (2nd line);
- control testing; and
- periodic attestations.
Data and information flowing from the assurance activities assist leaders, management and the board to have a view on the adequacy of compliance measures.
Conclusion
By focusing on implementing and embedding the 5 key compliance activities across the business, your compliance measures will create a cadence that enables your firm to self-regulate, self-manage, self-report and continually improve business operations, the customer experience and pursue opportunities for growth with confidence.
- Incidents
- Complaints
- Conflicts of Interest
- Training
- Assurance activities
Disclaimer: Reproduction of statements made in this article by media outlets, whether in full or in part, is strictly prohibited without the written express consent of the author. The views, opinions, and positions expressed within this article are those solely of the author and Compliance Advocacy Solutions Pty Ltd and not the views of other individuals, companies or organisations they may be affiliated with. The author and Compliance Advocacy Solutions Pty Ltd make no representations as to accuracy, completeness, currency, suitability, or validity of any information in this article and will not be liable for any errors or omissions or any loss or damage arising from its use or reliance. This article is intended for educational and informational purposes only and should not be relied upon as professional legal advice.