APRA calls for a step-change in AI-related risk management and governance

Artificial Intelligence (AI) is being rapidly adopted across APRA-regulated industries as entities seek to realise benefits to their businesses and customers. AI presents great opportunity for productivity and efficiency, and failing to embrace AI may put businesses at a strategic disadvantage. AI also has the potential to create new risks and escalate existing challenges. To understand and assess the current state of AI adoption and associated prudential risks, APRA conducted a targeted engagement on a group of selected large banks, insurers and superannuation trustees in late 2025. The purpose of this letter is to outline these observations and APRA’s expectations in managing AI related risk. Lessons drawn from APRA’s observations of these larger entities, will assist other entities who may be earlier in their AI adoption journey.
Read more

The 5 compliance activities your business must be doing

Most firms in the insurance industry have reasonable compliance infrastructures in place (the pipeline). However, without data and information flowing through the pipeline, the adequacy of the compliance measures remains in doubt, especially as a means to protect the business, its people, customers, and stakeholders and to meet regulatory requirements on an ongoing basis. Worse, the pipeline, without data & information, provides false assurance to leaders, management and the board. However, by focusing on implementing and embedding 5 key compliance activitiesacross the business, the compliance measures will create a cadence that enables the firm to self-regulate, self-manage, self-report and continually improve business operations, the customer experience and pursue opportunities for growth with confidence. 1. Incidents An incident is an event that occurs where something has gone wrong. Adopting a simple definition of an incident has been identified by ASIC as a key driver of identifying and recording a high number of incidents. All businesses have incidents, things go wrong, errors occur, bugs are present, processes are not foolproof. Firms who are not reporting any incidents are simply not identifying them. Eventually the incident will result in harm or detriment. Firms should adopt a wide view of incidents including operational risk incidents, cybersecurity incidents, people incidents, change management incidents, financial & insurance incidents and startegic risk incidents in addition to compliance, legal and regualtory incidents. Your focus should be training your people (and providing artefacts) that enable them to identify, raise, and quickly report incidents that arise in their area of operation. A more skilled person can then triage incidents and funnel them down the correct pipeline (such as a likely breach or breach of regulatory or Code oprations or an operational risk or a privacy matter or a potential disruption event such as cybersecurity). 2. Complaints ASIC and the Insurance Brokers Code Compliance Committee have highlighted the under-reporting of complaints across general insurance. As at 30/06/2025 ASIC’s IDR data dashboard shows that 81.7% of general insurance complaints were lodged by only 20 firms. Fair, timely and effective IDR processes that provide a genuine opportunity for redress are a key consumer protection and can produce beneficial outcomes for both consumers and firms. A positive complaints management culture is imperative to achieve these outcomes— one that takes a proactive approach in identifying a ‘complaint’, and that does not compound or further delay the recovery of customers and businesses from distressing events. ASIC Cause for complaint: Complaints handling in general insurance Report 802 | December 2024 Understanding that a complaint is simply an expression of customer dissatifaction shifts the culture of complaints to a customer experience improvement rather than a compliance obligation. All complaints must be recorded by the firm including those resolved at first point of contact. Not only does this lead to better customer experiences and business improvements (through the identification of systemic issues) it also enables the firm to meet its regulatory and Code obligations including the reporting of IDR data. 3. Conflicts of interest Managing conflicts of interest is […]
Read more

General Insurance – do you need an Australian Financial Services Licence?

An AFS licence authorises you and your representatives to provide financial services to clients. Part 7.6 Division 2, Corporations Act sets out the requirements to be licensed or authorised. Generally, a person who carries on a financial services business in Australia must hold an Australian financial services licence (AFSL) covering the provision of the financial services (s 911A). Meaning of financial service A person provides a financial service (relevantly for general insurance), if they: provide financial product advice; deal in a financial product; or provide a claims handling and settling service. General insurance products are financial products (s764A), subject to certain exemptions for example surety bonds and reinsurance. This typically applies to insurers, underwriting agencies, insurance brokers, TPAs, and claimant intermediaries. What is financial product advice? A recommendation or a statement of opinion, or a report of either of those things, constitutes financial product advice under s766B (also refer RG 36.19) if: (a) it is intended to influence a person or persons in making a decision about general insurance products, or could reasonably be regarded as being intended to have such an influence; and (b) it is not exempted from the definition of financial product advice. Financial product advice will generally involve a qualitative judgement about, or an evaluation, assessment or comparison of, some or all of the features of one or more general insurance product(s). (refer RG 36.20) What is the meaning of ‘deal in a financial product’? The following conduct constitutes dealing in a financial product within the meaning of s766C(1): applying for or acquiring a general insurance product; issuing a general insurance product; varying a general insurance product (such as by endorsement); or disposing (cancelling) of a general insurance product. Arranging for a person to engage in the above conduct also constitutes dealing. Arranging refers to the process by which a person negotiates for, or brings into effect, a dealing in a general insurance product (e.g. an issue, variation, disposal, acquisition or application). The person who is arranging may be acting for a product issuer, seller or consumer. Arranging includes ‘arranging contracts of insurance’ (RG 36.38-39) Your conduct may constitute arranging if (RG 36.43): your involvement in the chain of events leading to the relevant dealing is of sufficient importance that without that involvement the transaction would probably not take place (e.g. where you are the main or only person consumers deal directly with in a particular transaction); your involvement significantly ‘adds value’ for the person for whom you are acting; and you receive benefits depending on the decisions made by the person for whom you are acting. Referrals You do not need to hold an AFS licence if you provide a financial service that consists only of a referral (RG 36.72), that is: informing another person that a licensee (or one of its representatives) is able to provide a particular financial service or class of financial services; and giving that other person contact details for the licensee or representative. You must disclose any benefits (including commission) […]
Read more

Using AI efficiently, honestly and fairly in general insurance

AFS Licensee’s have a general obligation to ensure that they provide their financial services efficiently, honestly and fairly (s912A(1)(a) Corporations Act). This obligation is viewed as an overarching obligation. If you fail to comply with the other general obligations, it is unlikely that you will be complying with the ‘efficiently, honestly and fairly’ obligation. (ASIC RG 104.55) However, the ‘efficiently, honestly and fairly’ obligation is also a stand-alone obligation that operates separately from the other general obligations. (RG 104.56) The relevant industry codes also include similar obligations: [we] will be honest, efficient, fair, transparent and timely in our dealings with [customers]. (GI Code of Practice paragraph 21) We, our staff, and representatives will act honestly and with integrity in all dealings.(Insurance Brokers Code of Practice Section 3.0(b)) It is clear that the obligation requires ethical behaviour It is not necessary to establish dishonesty in the criminal sense. The word ‘honestly’ may comprehend conduct which is not criminal but which is morally wrong in the commercial sense. The word ‘honestly’ when used in conjunction with the word ‘fairly’ tends to give a flavour of a person who not only is not dishonest, but also a person who is ethically sound Foster J in ASIC v Camelot Derivatives Pty Ltd (in liq) (2012) 88 ACSR 206 [201] FCA 414 at [69] The governance of AI The financial service laws and industry Codes are technology neutral. That is, the laws and policies focus on desired outcomes or functions rather than prescribing the use of specific technologies. It is therefore irrelevant whether a firm uses humans, technology or a combination of both to perform financial services tasks and services. The obligation ‘efficiently, honestly and fairly’, applies. This was emphasised in APRA’s letter to regulated-entities 30 April 2026 APRA expects Boards, at a minimum, to maintain sufficient understanding and literacy with respect to AI in order to set strategic direction and provide effective challenge and oversight This obligation, at an operational level, extends to executives, management, responsible managers, accountable persons and business leaders. That is, such persons must have sufficient skills and knowledge of AI to be able to discharge their respective duties. ASIC emphasised this point in their open letter to industry 8 May 2026 ‘Entities need to have robust incident response plans. Whether an entity faces a basic phishing attempt or a more sophisticated cyber attack, the underlying cyber risk management principles of govern, protect, detect, respond remain the same. ‘Appropriate cyber risk management starts at the leadership of licensees and participants. Boards and executives must ensure systems are tested, weaknesses are addressed early and that action is taken before threats can be exploited. AI Ethics Principles The Department of Industry, Science and Resources (Australian Government) updated Australia’s AI Ethics Principles on 2 December 2025. The principles aimed to help: achieve safer, more reliable and fairer outcomes for all Australians reduce the risk of negative impact on those affected by AI applications businesses and governments to practice the highest ethical standards when designing, […]
Read more

Insurance brokers as an Authorised Representative – how are you managing contagion risk?

I’m often asked by insurance brokers, who are authorised representatives of a licensee, whether they should hold for their own AFS licence. I talk them through the mechanics of obtaining an AFS Licence, the cost (plus ongoing costs) of applying for a licence and how I can support them with their AFSL application. However, such a question requires an initial analysis of the risks, costs and benefits of holding your own AFS Licence compared to being an authorised representative of another licensee. With the increased regulatory scrutiny by ASIC over AR networks there is a strong case for obtaining your own licence. This scrutiny will, most likely, continue to increase. What is contagion risk? Contagion risk, in context of an AR network, is the likelihood that an adverse event, such as a cybersecurity failure or misconduct of one or more authorised representatives, impacts the entire AR network for that Licensee. This impact includes the impact to all other authorised representatives within the network and the licensee. A recent Federal court case highlighted contagion risk: Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496 (see ASIC media release (22-104MR)). RI Advice The Federal Court found AFS licensee, RI Advice, breached its license obligations to act efficiently and fairly when it failed to have adequate risk management systems to manage its cybersecurity risks. The finding comes after a significant number of cyber incidents occurred at authorised representatives of RI Advice between June 2014 and May 2020. In one of the incidents, an unknown malicious agent obtained, through a brute force attack, unauthorised access to an authorised representative’s file server from December 2017 to April 2018 before being detected, resulting in the potential compromise of confidential and sensitive personal information of several thousand clients and other persons. In addition to the declaration of contravention, the Court ordered RI Advice to engage a cybersecurity expert to identify and implement what, if any, further measures are necessary to adequately manage cybersecurity risks across RI Advice’s authorised representative network. RI Advice was ordered to pay $750,000 towards ASIC’s costs. Increased regulatory scrutiny leading to enhanced monitoring and supervision A number of insurance broker Licensee’s are having to report ‘reportable situations’ to ASIC, due to the conduct of authorised representatives. The reporting of reportable situations to ASIC, profile cases such as RI Advice, existing regulatory obligations and responsibility for the conduct of authorised representatives under Part 8.1 of the Insurance Brokers Code of Practice, will continue the enhanced regulatory focus of ASIC in respect of the operation and management of AR networks. Licensees are responding through rigourous due diligence processes as part of the AR appointment process and robust AR Monitoring Programs. I have worked with a number of licensed Insurance Brokers to set-up robust AR Monitoring Programs and due diligence. Licenced or AR? Costs and benefits – a compliance perspective From a risk and compliance persepective there is a benefit for a new brokerage to be an authorised representative of a […]
Read more

The cadence of compliance

Cadence refers to a regular, rhythmic flow of activity. The cadence of compliance refers to compliance infrastructure and the information and data that flows through the infrastructure. The cadence of compliance is critical to ensure that a firm’s compliance measures are adequate and documented, enabling self-regulation and self-reporting. A compliance cadence, importantly, enables the firm’s compliance measures to evolve and adapt through business growth, innovation, use of automation, and the development of new products, services, distribution channels and partnerships. Compliance infrastructure Think of a pipeline infrastructure in the energy sector. The network of pipelines, compressor stations, valves, and monitoring systems used to transport crude oil, natural gas, and refined products. Similarily, the pipeline infrastructure for compliance is the network of governance, IT systems, people and processes used to transport risk and compliance information and data flows. The components of compliance infrastructure Governance Including: roles and responsibilities, based on the 3 lines of defence accountability model; delegated authority for risk-decision making, based on the firm’s risk appetite statement; risk and compliance committees including sub-committees such as the breach management committee; monitoring and supervision including of the compliance system and of staff, authorised representatives, distributors and service suppliers; training and competency mechanisms; regulatory change management; product governance (design and distribution obligations); reporting to business operations, management, board, business partners, stakeholders and regulators; and record keeping. Licence management This includes those things that must be done to maintain an AFSL/APRA licence/authorisation such as: annual regulatory returns; ASIC IDR data reporting; notifying regulators of change of details including changes in responsibilities (such as responsibile managers); administrative matters; and changes to licence authorisations and conditions Risk management processes This includes how risks and complance obligations are managed: identification; analysis; evaluation; treatment; and monitoring Frameworks and sub-frameworks Aligned to governance however it is important to ensure that there is an overarching framework (enterprise risk management framework (ERMF)) and sub-frameworks such as obligations management, incidents , complaints, monitoring, product governance etc that align with and are connected to the ERMF. Information and data flows With the compliance pipeline infrastructure in place the test of the adequacy of the system is the information and data that flows through the infrastructure. Data and information enables risk decision-makers to self-regulate and self-report. Data and information This includes and is not limited to: incidents including regulatory/code incidents, operational risk incidents, cybersecurity incidents, people incidents and financial incidents; complaints conflicts of interest quality assurance, audits, and file reviews (underwriting, claims and broking) control testing outcomes risk profiling obligation management remediation and rectification activities training risk committee meetings business operational data attestations The cadence of compliance must be documented Documentation helps you demonstrate whether or not you are complying with the general obligations. When you document your measures, we [ASIC] expect this will include details of who is responsible, the timeframes involved and associated record keeping and reporting. (ASIC RG 104.26) In addition a documented cadence of compliance: supports training and education for staff, authorised representatives and service suppliers; provides assurance to management, […]
Read more

AFS Licensees must provide website addresses to ASIC to protect against scams

Names, licence numbers and websites of Australian Financial Services (AFS) licensees are increasingly being impersonated online, exposing consumers to scams. To combat this, in April 2026 ASIC decided that AFS licensee website addresses should be added to the AFS licensee professional register. These websites addresses will be published on the ASIC Professional Registers Search (PRS) from June 2026. Listing website addresses will enable consumers and businesses to check that they are dealing with genuine AFS licensee websites and combat impersonation scams where criminals copy the name and licence details of AFS licensees to create fake websites. From 4 May 2026, ASIC will begin to collect AFS licensee website addresses for all existing AFS licensees via the Regulatory Portal on a voluntary basis. If an AFS licensee provides ASIC with its website addresses (or confirms that it does not operate a website) then they must keep those details up to date. For example, an AFS licensee must inform ASIC, in relation to the websites used to carry on its financial services business, when it starts operating a website, stops using a website address it previously listed, or changes its principal website address. Key actions for AFS licensees Prepare Check that the AFS licensee’s Regulatory Portal ongoing contact person details are up to date so that it receives emails from ASIC about this change. If the AFS licensee uses more than one website address to carry on its financial services business, it should select one to nominate as the ‘principal’ website address. Provide Log into the Regulatory Portal and provide ASIC with the AFS licensee’s website addresses used to carry on its financial services business. See ASIC FAQ for guidance on which website addresses to provide and what format to provide them in. Update If an AFS licensee provides ASIC with its website addresses (or confirms that it does not operate a website) then they must update ASIC within 10 business days if their website addresses used to carry on their financial services business change or they start operating a website. Late fees will apply for changes provided after 10 business days. What will ASIC publish on the Professional Registers Search (PRS) webpage? ASIC will display an AFS licensee’s principal website address (or the fact that they do not have a website) prominently on the PRS. Any additional website addresses the AFS licensee provides will appear lower down in an expandable section. Why this matters Make it easier to spot AFS licensee impersonation websites and reduce investment scam losses. Help detect and disrupt scam websites that misuse AFS licensee details. Support other agencies and businesses to verify website addresses as part of a broader anti-scam effort. Align ASIC’s AFS professional register with approaches used by other international regulators. Disclaimer: Reproduction of statements made in this article by media outlets, whether in full or in part, is strictly prohibited without the written express consent of the author. The views, opinions, and positions expressed within this article are those solely of the author and […]
Read more

The General Insurance Code Governance Committee – role and responsibilities

The General Insurance Code of Practice is monitored and enforced by the Code Governance Committee (CGC) (paragraph 165 GI Code). The CGC’s constitution, functions and powers are set out in its Charter (paragraph 166). The CGC comprises: a consumer representative – Julia Davis an industry representative – Dallas Booth an independent chair – Veronique Ingram The Code Governance Committee Association Inc. (Association) powers and obligations are set out in the Charter (clause 5 Constitution). A management committee is responsible for controlling and managing the affairs of the Association. (clause 7 Constitution) CGC Charter The Code Governance Committee (CGC) is a committee of the Code Governance Committee Association Inc. The CGC is responsible for (Charter clause 1.2): (a) providing stewardship of the Code by helping the general insurance industry understand and comply with the Code; (b) identifying areas for improvement of insurance practices; (c) liaising with the ICA on relevant matters; (d) providing quarterly reports to the ICA Board; (e) publishing an annual public report containing aggregate industry data and consolidated analysis on Code compliance The CGC is also responsible for monitoring and enforcing compliance with the Code through (Charter clause 1.3 ): (a) investigations, analysis of data, analysis of evidence and stakeholder engagement; (b) receiving, investigating and making decisions about alleged breaches and giving Code Subscribers the opportunity to respond to any allegations that they have breached the Code; (c) considering whether it is more appropriate for ASIC or another enforcement agency to investigate an alleged breach of the Code; (d) agreeing with Code Subscribers on any corrective measures to implement within an agreed timeframe; (e) imposing sanctions; and (f) publishing breach decisions on a de-identified basis. The CGC is responsible for monitoring and enforcing compliance with the Code in the manner set out in the Code. Without limiting the CGC’s Code functions and powers, the CGC may for the purposes of monitoring compliance with the Code (Charter clause 4): (a) make reasonable requests for a Code Subscriber and/or the Service Provider to provide access to information, documents and systems, which the CGC considers necessary to discharge its functions; (b) seek independent professional legal, accounting or other advice; (c) request each Code Subscriber to lodge an annual data return and survey reporting on their compliance with the Code; and (d) enter into appropriate arrangements with the Service Provider or AFCA for the purpose of facilitating: (i) information exchange relevant to the CGC’s functions; and (ii) referrals to the CGC of an allegation that a Code Subscriber has breached the Code Additional powers CGC investigate Code Compliance (Charter clause 5) consider Code breaches (clause 5.3) and make breach decisions (5.4) impose sanctions (6.1) report Significant Breaches or serious misconduct to ASIC (6.2) publish significant breaches (7.1) publish an Annual report and provide to ICA Board and AFCA Board (9.2) develop policies, guidelines, reporting forms and operating procedure consistent with the Charter and Code (10) CGC reviews Upcoming review Motor insurance claims handling CGC are currently scoping a targeted review into motor […]
Read more

Insurance brokers – general or personal advice – what is the difference?

I continue to receive questions from general insurance brokers on the difference between general advice and personal advice. Personal advice is where the provider of the advice has considered one or more of the person’s objectives, financial situation and needs or a reasonable person might expect the provider to have considered one or more of those matters. (my emphasis) It is important to note that general advice is narrow in application and ASIC and the Court will adopt an approach of ‘substance over form’ as to whether general or personal advice has been provided. That is, providing a general advice warning does not mean that financial product advice is general advice per se, an examination of the facts and circumstances is required. This question was revisited by the High Court of Australia Westpac Securities Administration Ltd v Australian Securities and Investments Commission [2021] HCA 3. Also refer to ASIC media release 21-013MR Corporations Act Section 766B(3)(b) of the Corporations Act 2001 (Cth) defines “personal advice” so as to include “financial product advice” given or directed to a person in circumstances where a reasonable person might expect the provider to have considered one or more of the person’s objectives, financial situation and needs. Section 766B(4) defines “general advice” as financial product advice that is not personal advice. As the High Court stated [T]he division of the universe of financial product advice into “personal advice” and “general advice” serves to organise the obligations owed by a financial product adviser to a retail client, with more onerous obligations being imposed upon the adviser where the circumstances are apt to suggest to the client that the financial product, the subject of the advice, is appropriate to the particular circumstances of the individual client. Circumstances Westpac Bank subsidiaries, Westpac Securities Administration Limited (WSAL) and BT Funds Management Limited (BTFM), conducted two telephone campaigns by the Westpac companies which recommended that customers roll out of their other superannuation funds into a Westpac-related superannuation account. As a result of the campaigns, Westpac increased its funds under management by almost $650 million between 1 January 2013 and 16 September 2016. The High Court confirmed that WSAL and BTFM breached financial services laws, including the requirement to act in their clients’ best interests and the requirement to act honestly, efficiently and fairly. The unanimous High Court judgment upheld the Full Federal Court decision regarding the conduct of WSAL and BTFM, dismissing their appeal and holding that they breached the Corporations Act by providing personal financial product advice in calls made to 14 customers. Neither company was licensed to provide personal financial advice. Judgment In the judgment, Justice Gordon reinforced that s766B(3) of the Corporations Act, which outlines the meaning of general and personal advice, ‘is directed to the protection of the retail client’ and clarified that ‘[…] the general advice warning must be assessed in light of all the circumstances. The general advice warning was given only once, at the beginning of the telephone conversation. Members were subsequently asked […]
Read more