The ecosystem of Insurance as a fairness mechanism

Over the past few days I’ve been involved in a number of fascinating discussions with insurance leaders from claims, product and pricing and repairers, loss assessors, brokers and experts (engineers etc). The conversation has always led to the role of fairness in insurance. This concept is underpinned by a legal and code structure that requires services and products to be provided efficiently, honestly, fairly, transparently and timely, acting with the utmost good faith. I have been thinking through a framework that operates as an insurance ecosystem providing procedural fairness delivering fair outcomes. This does not mean pay every claim. Far from it, but an adverse decision would be arrived at efficiently and be part of a robust decision-making process where the insured was an intrinsic part of the process. I welcome your thoughts on the components of an ecosystem that operates as a fairness mechanism. I’ve provided some of my initial thinking to promote the conversation: everyone involved in the ecosystem is focused on fairness through conduct, behaviors and compliance with laws and codes; Insurers design and act within fair frameworks and systems. Such as triaging claims and complaints at lodgement so that complexity and vulnerability characteristics are identified early and specialist resources allocated before problems arise; consumer advocates, brokers and claimant intermediaries act as the voice of the customer however the system acts as a customer advocate when the customer is unrepresented; the system starts with a proposition that: the claim is covered unless the evidence shows otherwise; the complaint is valid until the evidence shows otherwise – with short time frames for the evidence to show otherwise; the use of AI to streamline decision-making and ensure that the right people with the appropriate levels of skills, knowledge and authority are involved at an early stage where the policy/claim is not atypical (such as the early indicators of characteristics or complexity and vulnerability); frontline staff act as the guardians of the system and provided with the training, systems and tools to, for example; (1) resolve complaints at first point of contact, (2) identify complexity and vulnerability; and (3) challenge an experts report that they don’t understand so that a defective report doesn’t become part of the ecosystem; the time from ‘IDR-EDR-Determination’, is reduced from months or years to weeks; expert reports are truly independent and factual that anyone in the system can rely on in good faith as the basis for conversation or settlement; product design and distribution flows through marketing – product design and pricing – sales – underwriting – claims; distribution processes align product design to customer needs, objectives and requirements while enabling freedom of choice; unconscious bias is removed from the system; remuneration is merely an output of the value that a person contributes to the system and the system manages inherent conflicts the system ensures that relevant resources are allocated to the complex, the vulnerable, the difficult; the system includes controls that manages, regulates, or directs the behavior of people, processes, or systems to achieve […]
Read more

What does it mean to carry on an insurance business in Australia?

In order to determine whether you need to be: authorised by APRA to carry on a general insurance business in Australia (Part III Division 1 Insurance Act 1973)and/or hold an Australian Financial Services Licence (AFSL) to provide financial services in Australia (such services include general insurance) (Section 911A Corporations Act) its necessary to consider whether you are carrying on an insurance business in Australia. Sources: Sutton on Insurance Law, Enright, Merkin, Hawke, Lawbook Co 2025 and ASIC Regulatory Guide RG 121 Carrying on Business The concept of ‘carrying on a business’ has been interpreted by the Courts and is also affected by section 21 Corporations Act. It should be noted that carrying on a business in Australia depends on the factual circumstances. However generally: include the degree to which a body corporate’s activities in Australia are conducted with system, repetition and continuity; the relevant activity need not generate or be motivated by profit; the business may be a carried on as part of or in conjunction with any other business; and it may be carried on alone or in conjunction with others. In Australia Section 21 provides that a body corporate has a place of business in Australia if the body corporate: establishes or is using a share transfer office or share registration office in Australia; or is administering, managing, or otherwise dealing with, property situated in Australia as an agent, legal personal representative or trustee, whether by employees or agents or otherwise. Section 21(3) provides a number of factors that in and of themselves do not indicate that a body corporate carries on a business in Australia. If you: a) are or become a party to a proceeding or effect settlement of a proceeding or of a claim or dispute; (b) hold meetings of your directors or shareholders or carry on other activities concerning your internal affairs; (c) maintain a bank account; (d) effect a sale through an independent contractor; (e) create evidence of a debt or create a charge on property; (f) secure or collect any of your debts or enforce your rights in regard to any securities relating to such debts; (g) conduct an isolated transaction that is completed within 31 days, not being one of a number of similar transactions repeated from time to time; or (h) invest any of your funds or hold any property Inducing If you engage in conduct that is ‘intended to induce people’ in Australia (or you engage in conduct that is likely to induce people in Australia) to use financial services you provide, then you will need to hold an AFS licence, unless an exemption applies. This is because of the deeming provision in s911D, which says that such conduct is ‘taken to be’ carrying on a financial services business in Australia. ASIC have granted specific exemptions that may apply: see ASIC Corporations (Foreign Financial Services Providers—Limited Connection) Instrument 2017/182 for ‘inducing’ wholesale clients, which applies until 31 March 2027. (refer RG 121.50) ASIC provides the following example in Table […]
Read more

APRA calls for a step-change in AI-related risk management and governance

Artificial Intelligence (AI) is being rapidly adopted across APRA-regulated industries as entities seek to realise benefits to their businesses and customers. AI presents great opportunity for productivity and efficiency, and failing to embrace AI may put businesses at a strategic disadvantage. AI also has the potential to create new risks and escalate existing challenges. To understand and assess the current state of AI adoption and associated prudential risks, APRA conducted a targeted engagement on a group of selected large banks, insurers and superannuation trustees in late 2025. The purpose of this letter is to outline these observations and APRA’s expectations in managing AI related risk. Lessons drawn from APRA’s observations of these larger entities, will assist other entities who may be earlier in their AI adoption journey.
Read more

The 5 compliance activities your business must be doing

Most firms in the insurance industry have reasonable compliance infrastructures in place (the pipeline). However, without data and information flowing through the pipeline, the adequacy of the compliance measures remains in doubt, especially as a means to protect the business, its people, customers, and stakeholders and to meet regulatory requirements on an ongoing basis. Worse, the pipeline, without data & information, provides false assurance to leaders, management and the board. However, by focusing on implementing and embedding 5 key compliance activitiesacross the business, the compliance measures will create a cadence that enables the firm to self-regulate, self-manage, self-report and continually improve business operations, the customer experience and pursue opportunities for growth with confidence. 1. Incidents An incident is an event that occurs where something has gone wrong. Adopting a simple definition of an incident has been identified by ASIC as a key driver of identifying and recording a high number of incidents. All businesses have incidents, things go wrong, errors occur, bugs are present, processes are not foolproof. Firms who are not reporting any incidents are simply not identifying them. Eventually the incident will result in harm or detriment. Firms should adopt a wide view of incidents including operational risk incidents, cybersecurity incidents, people incidents, change management incidents, financial & insurance incidents and startegic risk incidents in addition to compliance, legal and regualtory incidents. Your focus should be training your people (and providing artefacts) that enable them to identify, raise, and quickly report incidents that arise in their area of operation. A more skilled person can then triage incidents and funnel them down the correct pipeline (such as a likely breach or breach of regulatory or Code oprations or an operational risk or a privacy matter or a potential disruption event such as cybersecurity). 2. Complaints ASIC and the Insurance Brokers Code Compliance Committee have highlighted the under-reporting of complaints across general insurance. As at 30/06/2025 ASIC’s IDR data dashboard shows that 81.7% of general insurance complaints were lodged by only 20 firms. Fair, timely and effective IDR processes that provide a genuine opportunity for redress are a key consumer protection and can produce beneficial outcomes for both consumers and firms. A positive complaints management culture is imperative to achieve these outcomes— one that takes a proactive approach in identifying a ‘complaint’, and that does not compound or further delay the recovery of customers and businesses from distressing events. ASIC Cause for complaint: Complaints handling in general insurance Report 802 | December 2024 Understanding that a complaint is simply an expression of customer dissatifaction shifts the culture of complaints to a customer experience improvement rather than a compliance obligation. All complaints must be recorded by the firm including those resolved at first point of contact. Not only does this lead to better customer experiences and business improvements (through the identification of systemic issues) it also enables the firm to meet its regulatory and Code obligations including the reporting of IDR data. 3. Conflicts of interest Managing conflicts of interest is […]
Read more

General Insurance – do you need an Australian Financial Services Licence?

An AFS licence authorises you and your representatives to provide financial services to clients. Part 7.6 Division 2, Corporations Act sets out the requirements to be licensed or authorised. Generally, a person who carries on a financial services business in Australia must hold an Australian financial services licence (AFSL) covering the provision of the financial services (s 911A). Meaning of financial service A person provides a financial service (relevantly for general insurance), if they: provide financial product advice; deal in a financial product; or provide a claims handling and settling service. General insurance products are financial products (s764A), subject to certain exemptions for example surety bonds and reinsurance. This typically applies to insurers, underwriting agencies, insurance brokers, TPAs, and claimant intermediaries. What is financial product advice? A recommendation or a statement of opinion, or a report of either of those things, constitutes financial product advice under s766B (also refer RG 36.19) if: (a) it is intended to influence a person or persons in making a decision about general insurance products, or could reasonably be regarded as being intended to have such an influence; and (b) it is not exempted from the definition of financial product advice. Financial product advice will generally involve a qualitative judgement about, or an evaluation, assessment or comparison of, some or all of the features of one or more general insurance product(s). (refer RG 36.20) What is the meaning of ‘deal in a financial product’? The following conduct constitutes dealing in a financial product within the meaning of s766C(1): applying for or acquiring a general insurance product; issuing a general insurance product; varying a general insurance product (such as by endorsement); or disposing (cancelling) of a general insurance product. Arranging for a person to engage in the above conduct also constitutes dealing. Arranging refers to the process by which a person negotiates for, or brings into effect, a dealing in a general insurance product (e.g. an issue, variation, disposal, acquisition or application). The person who is arranging may be acting for a product issuer, seller or consumer. Arranging includes ‘arranging contracts of insurance’ (RG 36.38-39) Your conduct may constitute arranging if (RG 36.43): your involvement in the chain of events leading to the relevant dealing is of sufficient importance that without that involvement the transaction would probably not take place (e.g. where you are the main or only person consumers deal directly with in a particular transaction); your involvement significantly ‘adds value’ for the person for whom you are acting; and you receive benefits depending on the decisions made by the person for whom you are acting. Referrals You do not need to hold an AFS licence if you provide a financial service that consists only of a referral (RG 36.72), that is: informing another person that a licensee (or one of its representatives) is able to provide a particular financial service or class of financial services; and giving that other person contact details for the licensee or representative. You must disclose any benefits (including commission) […]
Read more

Using AI efficiently, honestly and fairly in general insurance

AFS Licensee’s have a general obligation to ensure that they provide their financial services efficiently, honestly and fairly (s912A(1)(a) Corporations Act). This obligation is viewed as an overarching obligation. If you fail to comply with the other general obligations, it is unlikely that you will be complying with the ‘efficiently, honestly and fairly’ obligation. (ASIC RG 104.55) However, the ‘efficiently, honestly and fairly’ obligation is also a stand-alone obligation that operates separately from the other general obligations. (RG 104.56) The relevant industry codes also include similar obligations: [we] will be honest, efficient, fair, transparent and timely in our dealings with [customers]. (GI Code of Practice paragraph 21) We, our staff, and representatives will act honestly and with integrity in all dealings.(Insurance Brokers Code of Practice Section 3.0(b)) It is clear that the obligation requires ethical behaviour It is not necessary to establish dishonesty in the criminal sense. The word ‘honestly’ may comprehend conduct which is not criminal but which is morally wrong in the commercial sense. The word ‘honestly’ when used in conjunction with the word ‘fairly’ tends to give a flavour of a person who not only is not dishonest, but also a person who is ethically sound Foster J in ASIC v Camelot Derivatives Pty Ltd (in liq) (2012) 88 ACSR 206 [201] FCA 414 at [69] The governance of AI The financial service laws and industry Codes are technology neutral. That is, the laws and policies focus on desired outcomes or functions rather than prescribing the use of specific technologies. It is therefore irrelevant whether a firm uses humans, technology or a combination of both to perform financial services tasks and services. The obligation ‘efficiently, honestly and fairly’, applies. This was emphasised in APRA’s letter to regulated-entities 30 April 2026 APRA expects Boards, at a minimum, to maintain sufficient understanding and literacy with respect to AI in order to set strategic direction and provide effective challenge and oversight This obligation, at an operational level, extends to executives, management, responsible managers, accountable persons and business leaders. That is, such persons must have sufficient skills and knowledge of AI to be able to discharge their respective duties. ASIC emphasised this point in their open letter to industry 8 May 2026 ‘Entities need to have robust incident response plans. Whether an entity faces a basic phishing attempt or a more sophisticated cyber attack, the underlying cyber risk management principles of govern, protect, detect, respond remain the same. ‘Appropriate cyber risk management starts at the leadership of licensees and participants. Boards and executives must ensure systems are tested, weaknesses are addressed early and that action is taken before threats can be exploited. AI Ethics Principles The Department of Industry, Science and Resources (Australian Government) updated Australia’s AI Ethics Principles on 2 December 2025. The principles aimed to help: achieve safer, more reliable and fairer outcomes for all Australians reduce the risk of negative impact on those affected by AI applications businesses and governments to practice the highest ethical standards when designing, […]
Read more

Insurance brokers as an Authorised Representative – how are you managing contagion risk?

I’m often asked by insurance brokers, who are authorised representatives of a licensee, whether they should hold for their own AFS licence. I talk them through the mechanics of obtaining an AFS Licence, the cost (plus ongoing costs) of applying for a licence and how I can support them with their AFSL application. However, such a question requires an initial analysis of the risks, costs and benefits of holding your own AFS Licence compared to being an authorised representative of another licensee. With the increased regulatory scrutiny by ASIC over AR networks there is a strong case for obtaining your own licence. This scrutiny will, most likely, continue to increase. What is contagion risk? Contagion risk, in context of an AR network, is the likelihood that an adverse event, such as a cybersecurity failure or misconduct of one or more authorised representatives, impacts the entire AR network for that Licensee. This impact includes the impact to all other authorised representatives within the network and the licensee. A recent Federal court case highlighted contagion risk: Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496 (see ASIC media release (22-104MR)). RI Advice The Federal Court found AFS licensee, RI Advice, breached its license obligations to act efficiently and fairly when it failed to have adequate risk management systems to manage its cybersecurity risks. The finding comes after a significant number of cyber incidents occurred at authorised representatives of RI Advice between June 2014 and May 2020. In one of the incidents, an unknown malicious agent obtained, through a brute force attack, unauthorised access to an authorised representative’s file server from December 2017 to April 2018 before being detected, resulting in the potential compromise of confidential and sensitive personal information of several thousand clients and other persons. In addition to the declaration of contravention, the Court ordered RI Advice to engage a cybersecurity expert to identify and implement what, if any, further measures are necessary to adequately manage cybersecurity risks across RI Advice’s authorised representative network. RI Advice was ordered to pay $750,000 towards ASIC’s costs. Increased regulatory scrutiny leading to enhanced monitoring and supervision A number of insurance broker Licensee’s are having to report ‘reportable situations’ to ASIC, due to the conduct of authorised representatives. The reporting of reportable situations to ASIC, profile cases such as RI Advice, existing regulatory obligations and responsibility for the conduct of authorised representatives under Part 8.1 of the Insurance Brokers Code of Practice, will continue the enhanced regulatory focus of ASIC in respect of the operation and management of AR networks. Licensees are responding through rigourous due diligence processes as part of the AR appointment process and robust AR Monitoring Programs. I have worked with a number of licensed Insurance Brokers to set-up robust AR Monitoring Programs and due diligence. Licenced or AR? Costs and benefits – a compliance perspective From a risk and compliance persepective there is a benefit for a new brokerage to be an authorised representative of a […]
Read more

The cadence of compliance

Cadence refers to a regular, rhythmic flow of activity. The cadence of compliance refers to compliance infrastructure and the information and data that flows through the infrastructure. The cadence of compliance is critical to ensure that a firm’s compliance measures are adequate and documented, enabling self-regulation and self-reporting. A compliance cadence, importantly, enables the firm’s compliance measures to evolve and adapt through business growth, innovation, use of automation, and the development of new products, services, distribution channels and partnerships. Compliance infrastructure Think of a pipeline infrastructure in the energy sector. The network of pipelines, compressor stations, valves, and monitoring systems used to transport crude oil, natural gas, and refined products. Similarily, the pipeline infrastructure for compliance is the network of governance, IT systems, people and processes used to transport risk and compliance information and data flows. The components of compliance infrastructure Governance Including: roles and responsibilities, based on the 3 lines of defence accountability model; delegated authority for risk-decision making, based on the firm’s risk appetite statement; risk and compliance committees including sub-committees such as the breach management committee; monitoring and supervision including of the compliance system and of staff, authorised representatives, distributors and service suppliers; training and competency mechanisms; regulatory change management; product governance (design and distribution obligations); reporting to business operations, management, board, business partners, stakeholders and regulators; and record keeping. Licence management This includes those things that must be done to maintain an AFSL/APRA licence/authorisation such as: annual regulatory returns; ASIC IDR data reporting; notifying regulators of change of details including changes in responsibilities (such as responsibile managers); administrative matters; and changes to licence authorisations and conditions Risk management processes This includes how risks and complance obligations are managed: identification; analysis; evaluation; treatment; and monitoring Frameworks and sub-frameworks Aligned to governance however it is important to ensure that there is an overarching framework (enterprise risk management framework (ERMF)) and sub-frameworks such as obligations management, incidents , complaints, monitoring, product governance etc that align with and are connected to the ERMF. Information and data flows With the compliance pipeline infrastructure in place the test of the adequacy of the system is the information and data that flows through the infrastructure. Data and information enables risk decision-makers to self-regulate and self-report. Data and information This includes and is not limited to: incidents including regulatory/code incidents, operational risk incidents, cybersecurity incidents, people incidents and financial incidents; complaints conflicts of interest quality assurance, audits, and file reviews (underwriting, claims and broking) control testing outcomes risk profiling obligation management remediation and rectification activities training risk committee meetings business operational data attestations The cadence of compliance must be documented Documentation helps you demonstrate whether or not you are complying with the general obligations. When you document your measures, we [ASIC] expect this will include details of who is responsible, the timeframes involved and associated record keeping and reporting. (ASIC RG 104.26) In addition a documented cadence of compliance: supports training and education for staff, authorised representatives and service suppliers; provides assurance to management, […]
Read more

AFS Licensees must provide website addresses to ASIC to protect against scams

Names, licence numbers and websites of Australian Financial Services (AFS) licensees are increasingly being impersonated online, exposing consumers to scams. To combat this, in April 2026 ASIC decided that AFS licensee website addresses should be added to the AFS licensee professional register. These websites addresses will be published on the ASIC Professional Registers Search (PRS) from June 2026. Listing website addresses will enable consumers and businesses to check that they are dealing with genuine AFS licensee websites and combat impersonation scams where criminals copy the name and licence details of AFS licensees to create fake websites. From 4 May 2026, ASIC will begin to collect AFS licensee website addresses for all existing AFS licensees via the Regulatory Portal on a voluntary basis. If an AFS licensee provides ASIC with its website addresses (or confirms that it does not operate a website) then they must keep those details up to date. For example, an AFS licensee must inform ASIC, in relation to the websites used to carry on its financial services business, when it starts operating a website, stops using a website address it previously listed, or changes its principal website address. Key actions for AFS licensees Prepare Check that the AFS licensee’s Regulatory Portal ongoing contact person details are up to date so that it receives emails from ASIC about this change. If the AFS licensee uses more than one website address to carry on its financial services business, it should select one to nominate as the ‘principal’ website address. Provide Log into the Regulatory Portal and provide ASIC with the AFS licensee’s website addresses used to carry on its financial services business. See ASIC FAQ for guidance on which website addresses to provide and what format to provide them in. Update If an AFS licensee provides ASIC with its website addresses (or confirms that it does not operate a website) then they must update ASIC within 10 business days if their website addresses used to carry on their financial services business change or they start operating a website. Late fees will apply for changes provided after 10 business days. What will ASIC publish on the Professional Registers Search (PRS) webpage? ASIC will display an AFS licensee’s principal website address (or the fact that they do not have a website) prominently on the PRS. Any additional website addresses the AFS licensee provides will appear lower down in an expandable section. Why this matters Make it easier to spot AFS licensee impersonation websites and reduce investment scam losses. Help detect and disrupt scam websites that misuse AFS licensee details. Support other agencies and businesses to verify website addresses as part of a broader anti-scam effort. Align ASIC’s AFS professional register with approaches used by other international regulators. Disclaimer: Reproduction of statements made in this article by media outlets, whether in full or in part, is strictly prohibited without the written express consent of the author. The views, opinions, and positions expressed within this article are those solely of the author and […]
Read more