The true purpose of Compliance What is your compliance narrative? Is it about rules, regulations and laws? A legalistic approach to compliance does not engage your people and projects compliance as a series of task and activities that must be undertaken – hardly inspiring or motivational, with the outcome that compliance is often reactive in nature. How do you change the compliance narrative so that it is about people and caring, driving a proactive approach to compliance? The true purpose of compliance is to protect. The question becomes – protect who and from what? Your firm’s response to this fundamental question is important. People are motivated to act by caring, and its what we care about, that we want to protect. The protect analogy Think about driving a car. You need a drivers licence to drive a motor vehicle on a public road. This licensing process requires you to gain knowledge and skills to operate a motor vehicle in accordance with the road rules. Why? to protect yourself, people you care about (as your passengers), other road users and the community from the cost of motor vehcile accidents – fatalities, injuries and property damage and consequential social costs. Similarily, in order to conduct a general insurance business in Australia you need to be authorised by APRA and to provide a financial service (which includes general insurance) you need to be licensed by ASIC, or be a representative of a licensee. Like a drivers licence, you need to demonstrate to APRA and ASIC the knowledge, skills, and experience in general insurance with the approriate capital requirements and human, financial and IT resources with people who meet standards of honesty, ethics and integrity. Why, to protect what matters, and who you care about. Let’s explore this further. Who does compliance protect? Compliance, in a general insurance context, protects: our customers, clients and consumers from the risk of financial harm and detriment and consequential impacts on their life, business and assets (due to issues such as availability and affordability; partial or total declined claims; underinsurance, claim delays etc); our people (this includes staff, external representatives, material service providers and anyone involved in the insurance sales & claims supply chain) from the risk of being banned or disqualified, individual fines & penalties, damage to their reputation and asscoaited mental health issues and impacts to the enjoyment of their life; our business – the risk of fines & penalties, loss of licence, enforcement action, lost management time, loss of business, reputational impacts and class actions including shareholder actions for ASX listed entities; our business partners such as insurers, MGAs, TPAs, service suppliers, authorised representatives, referrers, distributors, and material service providers from the risk of financial and reputational harm, regulatory enforcement action, loss of business partner and associated loss of business; and the community, arising from systemic failures and mistrust in the general insurance industry. What happens when we care? Caring motivates people to take action, and to perform tasks that make a positive difference. This […]
The following are extracted from remarks by ASIC Commissioner Alan Kirkland at the Insurance Council of Australia Annual Conference on 10 October 2025. I have grouped the remarks under various headings for ease of reference. The full speech may be accessed here. Claims handling – 2022 floods It’s hard to forget those who let you down when you’ve had a hard time – and that was unfortunately the experience of many Australians in the aftermath of the 2022 floods. “Some people, who turned to their insurer in their darkest hour after paying premiums for years, felt that they became engaged in an adversarial situation with a company meant to be on their side.”[9] That quote is from the House of Representatives Standing Committee on Economics report into claims handling failures after the 2022 floods, which was handed down almost a year ago. It’s fair to say that there remains a significant trust gap to be addressed following this report. Reputation data from RepTrak[10] and Roy Morgan[11] suggests that insurance is among Australia’s most distrusted industries – and you only need to look at the testimony of individuals impacted to understand why. David Norris, whose family owned the Central Hotel in Eugowra, told the inquiry after more than 60 years with their insurer it was apparent that “loyalty only goes one way[12]. This is the challenge that must be addressed by you as you try to “pitch your tent” in the middle of these storms – showing people like David that loyalty is a two-way street. Areas of improvement in claims handling As insurers though, you are in the business of recovery. You know that rebuilding doesn’t happen overnight. It takes continual effort and care. And we know from our latest review that some of you are putting in the work and starting to see some green shoots of recovery as a result of that work. As noted recently by AFCA[13], the industry has made progress on reducing historically high complaint numbers, which should be commended. And we have also observed some promising signs in our recent follow-up on Report 768 – which of course was the report that examined claims handling practices following the 2022 floods[14]. When that report was published, we found that poor communications, poor resourcing, and poor treatment of vulnerable customers were endemic across the insurance industry. But it is clear that a lot of work has happened in the past two years in response to those findings. For example, every insurer we looked at this time around had established a program to improve their approach to claims handling. Most had introduced a single point of contact for claims, so customers didn’t have to tell their stories over and over again. Some had gotten smarter about how they used their data to identify and support vulnerable customers, before and after major events. And a few went beyond this – towards truly consumer-centric practices. For example, we’ve seen some insurers appoint a dedicated consumer advocate to be a […]
Last month I attended the AILA 2025 National Conference in Melbourne. One of the highlights was the regulators panel featuring: Jane Magill Executive Director General Insurance & Banking, APRA Peter Soros Executive Director, Regulation & Supervision, ASIC David Locke CEO, AFCA Chair Alexandra Hordern General Manager, Regulatory & Consumer Policy, ICA (Insurance Council of Australia) General insurance – areas of increased regulatory oversight The following areas were identified as subject to regulatory oversight during 2026: it was noted the increased complaints for motor vehicle insurance, this will be a focus for ASIC claims handling is improving however areas such as cash settlements will be a focus risk culture including how this permeates throughout the organisation feedback on CPS 230 based on reviews of larger insurers the use of AI however both ASIC and APRA consider that the existing regulatory regime is sufficient to manage the risks and are continuing to observe this space. A human should be involved in any AI decision-making process. APRA will be undertaking a narrow review of larger entities to test that principle based Prudential Standards 220, 230 & 234 are adequate to manage the risk of AI the use of AI by complainants as part of the IDR and EDR was observed and is being considered by AFCA (and is consistent with what I’m being told by my clients) pricing; the expectation is for transparency, and insurers to recognise efforts by insureds to improve their own risk sustainability reporting requirements The role of the regulator David Locke provided the following view on the role of the regulator which I have produced below with David’s permission: As a regulator your role is to clearly spell out where the red and yellow flags are on the beach and make it very easy for the public (and financial firms) to swim between the flags. There will always be some people who drift or accidentally swim just outside them and you blow your whistle and use the lightest regulatory tools necessary to get them to swim back in safe water. You then focus the majority of your compliance resources on the idiots jumping off the rocks at the end of the beach. You want to prosecute them to deter others from doing so, and in some cases want them permanently off the beach. David’s analogy strongly resonates with my ‘Compliance protects what matters‘ theme. A company’s compliance arrangements can serve a similar purpose of keeping their people and other representatives swimming safely between the flags (that is: conducting general insurance business efficiently, honestly, fairly, transparently and timely) by adopting the following compliance operating rhythm: the documented compliance process and procedures, training and IT systems provides a safe place to conduct business protecting the business, its people, its customers and cliients and its business partners; the firm’s people acting as ‘an early warning system’ to quickly identify and raise incidents and complaints; an effective monitoring program; and a culture of wanting to do the right thing. Disclaimer: Reproduction of statements […]
Underwriting Agencies generally require an APRA-regulated insurer as a partner to provide general insurance products in Australia. The Underwriting Agency typically has delegated binding authority from an insurer (see section 916E Corporations Act). In this instance, the Agency is acting on behalf of the insurer. In other arrangements, such as an open-market placement, it’s likely that the agency is acting on behalf of the insured (commonly referred to as wholesale broking) and would require the relevant authorisation under their AFS Licence. It is necessary for an Underwriting Agency to ensure that the insurer is authorised by APRA to carry on general insurance business in Australia. Who is an insurer and what authorisation does an insurer require to carry on general insurance business in Australia? Under the Insurance Act 1973, it is an offence to conduct insurance business in Australia without the proper authority. If your business intends to conduct any business that can be classed as insurance business, you need a licence from APRA giving you the authority to conduct insurance business in Australia. Part 3 of the Insurance Act defines ‘insurance business’ as the business of undertaking liability by way of insurance (including reinsurance), in respect of any loss or damage. It includes liability to pay damages or compensation, contingent upon the happening of a specified event, and any business incidental to insurance business as so defined. There are some exclusions to the definition of insurance business, such as life insurance (covered by the Life Insurance Act 1995) and health insurance (covered by the Private Health Insurance Act 2007). The Insurance Act only allows corporations or Lloyd’s underwriters to carry out insurance business in Australia, which means APRA cannot consider applications from partnerships or unincorporated entities. APRA expects all applicants to be able to comply with all of its prudential requirements, as set out in the Insurance Act and prudential standards, from the commencement of insurance business in Australia and continuously thereafter. Requirements APRA will consider the following matters in the application: ownership governance including board composition and FAR Capital and Assets in Australia including minimum capital requirements Risk management framework Compliance Reinsurance management Informations security and accounting systems Intra-group transactions and arrangements General insurers authorisation – Section 12 A general insurer, including a foreign general insurer, is authorised under section 12 to carry on general insurance business in Australia. The obligation to comply with APRA Prudential Standards applies to general insurers authorised under section 12. Lloyds Underwriters – Section 93 Part VII, section 93 of the Insurance Act authorises Lloyd’s Underwriters to write Australian insurance business. Sections 65 to 73 of the Act provide for special Australian policyholder protection provisions associated with Lloyd’s. At all times, Lloyd’s must ensure that security trust fund arrangements, and ancillary or incidental arrangements, in accordance with Lloyd’s security trust fund instrument No. 2 of 2017 are in existence. Unauthorised foreign insurers Certain insurance business is an exemption under the Insurance Act (subsection 3A(1)) Insurance Regulation Section 8 provides that where insurance is […]
ASIC has released its Corporate Plan 2025-26. ASIC Chair Joe Longo Mr Longo said the plan formalised ASIC’s focus on regulatory simplification. (Media Release 25-177MR) ‘A focus on simpler and better regulation is now a concrete part of ASIC’s 2025-29 plan and will see the agency continue that focus to make it easier to interact with ASIC, to understand our expectations, for us to administer the law, and ultimately to cut red tape.’ ASIC’s Corporate Plan also outlines how the agency is maturing its approach to measuring and assessing its performance, including introducing a new suite of performance measures. ‘This will help our stakeholders better understand ASIC’s impact,’ Mr Longo said. Impacts for General Insurance I have extracted the parts of ASIC’s Corporate Plan 2025-26 that impact general insurance. 12 month work Guided by the strategic priorities set out in the plan, ASIC’s work over the next 12 months and beyond will include: driving regulatory reform to ensure the stability, fairness and transparency of our capital markets ensuring stable, secure and resilient market infrastructure pursuing continuous improvement in artificial intelligence (AI) governance and cyber security holding superannuation trustees accountable for Australians’ retirement savings, and reducing the regulatory burden on businesses. 2025-29 plan highlighting general insurance impacts ASIC are focused on addressing the most significant issues in the regulatory environment and bolstering ASIC’s capabilities to achieve this. In 2025–29, work under ASIC’s key activities will be guided by five strategic priorities. Improve consumer outcomes Strengthen market disclosure and professional conduct Support better retirement outcomes and member services Strengthen operational digital and data resilience and safety Drive integrity and transparency across markets Improve consumer outcomes – general insurance IDR – ASIC will review compliance by licensees with their obligations to report to ASIC on complaints, IDR processes, and outcomes. ASIC will continue publishing IDR data, a key part of the IDR reporting requirement. General insurance premiums – ASIC will examine the accuracy and transparency of general insurers’ disclosures about premiums and work to better understand consumer experiences. General insurance cash settlements – ASIC will review general insurers’ use of cash settlements to better understand the practices and disclosures surrounding the offers being made and to assess whether there are risks of consumer harm. Indigenous consumer outcomes – ASIC will maintain their Indigenous Outreach Program to ensure ASIC consider and understand the needs of Indigenous consumers responding to misconduct impacting Indigenous communities. ASIC will continue to build our understanding of how Indigenous communities are engaging with general insurance products and using these products to manage risks to assets of value. Strengthen market disclosure and professional conduct Sustainability-related actions – ASIC will take regulatory or enforcement action, where necessary, to protect investors and consumers. ASIC will focus on greenwashing and complaints handling by insurers following severe weather events. Auditor independence and conflicts of interest – ASIC will continue to examine auditors’ compliance with their independence and conflicts of interest obligations and publish our surveillance findings. Director and officer conflicts of interest – ASIC will […]
AFS Licensees must have processes, procedures or arrangements for ensuring that, as far as reasonably practicable, they comply with their obligations as a licensee (refer ASIC RG 104.23) and those measures should be documented (RG 104.26) APRA-regulated insurers must have mechanisms in place for monitoring and ensuring ongoing compliance with all prudential requirements (CPS 220 paragraph 35(f)). Insurers under the GI Code of Practice must have appropriate systems and processes in place to enable the Code Governance Committee to monitor compliance with the Code. (paragraph 180). Insurance brokers and their authorised representatives under the Brokers Code of Practice must have in place policies and procedures for their organisation and embed a culture that reflects the Code in the way they provide services and deal with others (paragraph 8.2(a)(iii)). If you don’t use an Obligations register to record your obligations, its likely: you have a reactive approach to compliance; compliance is seen as a series of random tasks and activities; providing evidence of compliance becomes a lengthy ‘search for a document’ process’; that compliance is not embedded within your business; there is a lack of assurance that you are complying with your obligations; and there is a heightened risk of non-compliance with unresolved incidents and breaches leading to increased operational risk, regulatory risk and regulatory scrutiny. The purpose of an Obligations register Irrespective of the source of an obligation, all obligations can be adequately managed by being recorded in an Obligations register. I adopt 2 approaches when designing an Obligations register for my clients (AFS Licensees such as brokers, underwriting agencies & TPAs; APRA regulated insurers and insurance service providers): I design the Obligations register within the Risk & Compliance Manual. This ensures that the obligation has context with a narrative explaining the source of the obligation and how it may operate with other obligations; or a stand-alone register, typically for larger organisations. Irrespective of the approach, the purpose of an Obligations Register is to identify obligations (irrespective of source) and capture those in a single register. Sources of obligations can arise under: Legislation such as Corporations Act, ASIC Act, Privacy Act, Autonomous Sanctions, Act, Competition and Consumer Act; APRA Prudential Standards such as CPS 230 (Operational risk) and CPS 234 (Information Security); ASIC Regulatory Guides such as RG 271 (Dispute resoultion) and RG 166 (Licensing financial requirements); Industry Codes – GI Code and Insurance Brokers Code; Binder Agreements; or Material Service Provider agreements. The [key] control environment Once Obligations have been captured in the register, Key controls are then assigned to each obligation, designed to ensure that each obligation is adequately managed. From this exercise, it is apparent that a Key control may adequately manage multiple obligations. This drives efficiency in business process and better customer experiences. Assigning key controls to each obligation enables a shift from a focus on obligations to a focus on the control environment. An annual control testing program ensures that key controls are tested from 2 perspectives: that they have been designed effectively (fit-for-purpose); and […]
ASIC has remade a legislative instrument that exempts Australian financial services (AFS) licensees from appointing a general insurance product distributor as their authorised representative. The ASIC Corporations (Basic Deposit and General Insurance Product Distribution) Instrument 2025/520 will extend the relief previously provided by ASIC Corporations (Basic Deposit and General Insurance Product Distribution) Instrument 2015/682 until 27 August 2030. This promotes the wide availability of general insurance products to consumers by reducing the compliance costs to providers. Criteria required to comply with the instrument In order to rely on the instrument, and provide a financial service without the need to be licensed or appointed as an Authorised Representative of a Licensee, the following criteria must be met: the principal must hold an Australian financial services licence covering the provision of the service; the service is dealing in a general insurance product; the provider is a product distributor of the licensee (but this does not include employees of the licensee); and the distributor is not an authorised representative of the licensee. Additional requirements when the general insurance products are distributed to Retail clients The licensee must have taken reasonable steps to ensure that when the distributor provides the financial service to a retail client: the distributor draws the client’s attention to the availability of a dispute resolution system of the licensee that covers complaints by the client in relation to the financial service and how that system may be accessed; and if the distributor is dealing in a general insurance product or a bundled consumer credit insurance product, the client is given information in writing about: (a) who the distributor acts for when providing the financial service; and (b) any remuneration (including commission) or other benefits that the distributor, or an associate of the distributor, may receive in respect of, or that is attributable to, the provision of the financial service. The Distributor must not provide financial product advice The ASIC instrument only applies to ‘dealing’. Dealing in a financial product within the meaning of s766C(1) Corporations Act (also refer RG 36 Part C) means: applying for or acquiring a financial product; issuing a financial product; varying a financial product; or disposing of a financial product. Arranging for a person to engage in the conduct referred to above also constitutes dealing. Arranging refers to the process by which a person negotiates for, or brings into effect, a dealing in a financial product (e.g. an issue, variation, disposal, acquisition or application). The person who is arranging may be acting for a product issuer, seller or consumer. As the instrument is restricted to ‘dealing’ only, this means that the distributor is not permitted to provide financial product advice, this restriction includes both general or personal advice. If the distributor requires authorisation to provide financial product advice, and the licensee is prepared to authorise the distributor to provide financial product advice, then the distributor must be appointed as an authorised representative of the licensee (or alternatively the distributor obtains their own AFSL). Typical general insurance situations when […]
I’m sometimes asked about the nature of work that I do or more accurately ‘what do your compliance services cover’. I thought it would be useful to share a ‘week in my life’. At the heart of my services is the expert knowledge and advice I provide on compliance, specifically across general insurance, for firms that operate within that sector, typically: insurers underwriting agencies lloyds coverholders TPAs (insurance claim managers) insurance brokers service suppliers and providers claimant intermediaries distributors Compliance is in respect of complying with financial service laws including those impacting AFS licensees, Authorised reps, Lloyds coverholders/security, APRA prudential standards, sanctions, privacy and the GI Code and Brokers Code of Practice. Including ASIC Regulatory Guides and other regulatory and Code materials. In a typical week, my work will fall within 1 of the 5 following areas. 1. AFS Licensing This is a broad category covering: new licence applications; variations to existing AFS Licenses such as to remove a key person condition, or add a new authorisation such as retail clients or claims handling; and changes to license, such as adding Responsible Managers. Licence work is very rewarding as often it signifies a key milestone in the client’s journey. It is a privilege to conduct such work for my clients. Licensing work is time-consuming and requires information to be provided and presented in a manner as required by ASIC however I enjoy the opportunity to work for the client on such an important piece of work. 2. Compliance documents and frameworks The documented evidence (as required under ASIC RG 104) is the output of the consideration of what a business is authorised to do, how it does it and developing an operating rhythm that provides: adequate compliance measures that manage the firms obligations (including under binder agreements or Auth Rep agreements); assurance to board, management, business partners (such as insurers) and regulators that obligations are being adequately managed; indicators of areas of potential concern; and data (incidents, complaints, control testing, monitoring etc) The documents I provide are all individually developed and include: tailored Risk and Compliance manual (~ 35 pages, an all-in-one document that represents the business from a compliance perspective and can also be used as a training tool); Monitoring Program (monitoring employees, Authorised Reps, Distributors and/or Material Service Providers); Obligations register covering relevant (to your business) financial service laws, Prudential Standards and Codes. This enables you to assign key controls, accountability and control testing to your obligations Registers inlcuding complaints; incidents and breaches; conflicts of interest and training; and ad hoc, tailored policies & documents. All documents are tailored to your business – what it does, how it does it and who does it. 3. Training and education Training is becoming an often requested compliance service that I provide with delivery through online, face-to-face or a combination of both. I really love engaging with your business and having fun and meaningful conversations with your people addressing compliance issues that are of concern (or confusing) to them. All training […]
ASIC has released proposed updates to its conflicts management guidance for financial services businesses. Media Release 25-150MR Regulatory Guide 181 Licensing: Managing conflicts of interest (RG 181) was last updated in August 2004. The proposed changes will align the guidance with developments in law and policy and have been informed by ASIC’s private markets surveillance work. ASIC Commissioner Kate O’Rourke said: ‘Conflicts management is a core obligation for financial services businesses and helps promote consumer protection and market credibility. ‘Conflicts of interest are more than mere moral dilemmas. They can undermine trust, integrity and performance, causing serious harm to consumers, investors and overall market confidence.’ The updated guidance sets out how Australian financial services (AFS) licensees should comply with their conflicts management obligation and explains: how the law applies, including its scope and interaction with other related obligations the types of conflicts AFS licensees need to identify and manage to meet their obligation the need to have robust and tailored arrangements that are adequate to manage conflicts, and how licensees can effectively manage conflicts. Consultation CP 385 was released 30 July 2025. Comments close 5 September 2025. Draft Regulatory Guide 181 July 2025 – AFS Licensing: Managing conflicts of interest Your obligation If you are an AFS licensee, or an AFS licence applicant, you must comply with your general licensing obligations under s912A of the Corporations Act 2001 (Corporations Act). This includes your obligation to have in place adequate arrangements for managing conflicts of interest that may arise wholly, or partially, in relation to activities undertaken by you or your representative in the provision of financial services as part of your financial services business (‘the conflicts management obligation’): see s912A(1)(aa). Scope of the obligation The conflicts management obligation is broad and is intended to apply widely—it is not limited in its application. It applies to all conflicts of interest other than those wholly outside the financial services business of you or your representative. It applies to conflicts of interest that arise within the financial services business. It also applies to conflicts that arise between something within thefinancial services business and something outside it. For example: (a) a conflict between the financial services business and corporate lending business within a conglomerate firm; or (b) a conflict between the financial services business and an employee’s personal or financial interest outside it. Complying with your obligation If ASIC have reason to believe you are not complying with your conflicts management obligation, ASIC may take administrative action. This could include suspending or cancelling your AFS licence or imposing additional licence conditions: see ss915C(1) and 914A(1). Depending on the severity, a breach of your conflicts management obligation may result in civil penalties for individuals or for corporations. What is a conflict of interest? A conflict of interest can arise where there are competing financial interests, personal interests, business or related party interests—whether direct or indirect—or competing loyalties and obligations. In some circumstances, a combination of these may give rise to a conflict. You should take […]
What is the obligation? Under s912B of the Corporations Act, AFS licensees must have arrangements for compensating retail clients for losses they suffer as a result of a breach by the licensee or its representatives of their obligations in Ch 7 of the Corporations Act. (also refer ASIC RG 126) This obligation does not apply to APRA regulated insurers (see reg 7.6.02AAA(3)) but does apply to Underwriting Agencies, Insurance Brokers, Insurance Claim Managers and Claimant Intermediaries who hold an AFS Licence. These arrangements must: satisfy the requirements in the Corporations Regulations, which are that licensees must obtain PI insurance that is adequate, considering the nature of the licensee’s business and its potential liability for compensation claims (see reg 7.6.02AAA); or be approved by ASIC as alternative arrangements For the purposes of this article, I will be focusing on PI insurance under reg 7.6.02AAA. What this means for AFS Licensees and consumers ASIC’s approach to administering the compensation requirements means that all AFS licensees that provide financial services to retail clients must have PI insurance that meets the minimum standards, unless an exemption applies. Tt is important, however, to recognise the limitations of PI insurance as a consumer protection mechanism. PI insurance is not designed to protect consumers directly and is not a guarantee that compensation will be paid. It is designed to protect the insured (i.e. the AFS licensee) against the risk of financial losses arising from poor quality services (e.g. poor advice or execution of services) and other misconduct by a financial services provider (e.g. fraud by its representatives). The insurance is not intended to cover product failure or general investment losses, claims for loss solely as a result of the failure (e.g. insolvency) of a product issuer or where a return on a financial product has not met expectations. Nor is it intended to underwrite the products of a product issuer. ASIC recognise that the PI insurance that is currently available in the market is unlikely to provide a source of funds when an AFS licensee has become insolvent before the claim was brought. Ideally, insurance policies would continue to cover the licensee after it has become insolvent or otherwise ceased business, but ASIC understands that this insurance is generally not available in the current market to the average licensee. ASIC also recognise that insurers may exclude some areas of cover in policies for risk management reasons. (see RG 126.8 – 126.11) Disclosure to retail clients AFS Licensee must disclose to retail clients the kind of compensation arrangements they have in place and whether these arrangements comply with s912B: see regs 7.7.03A and 7.7.06B. The disclosure must be presented as a statement in your Financial Services Guide (FSG) or website disclosure information and the FSG or website disclosure information of your representatives. (RG 126.19) Adequate PI Insurance What is adequate? (See Section C RG 126) The Corporations Regulations require you to hold PI insurance that is adequate, considering: (a) your liability for claims brought through the Australian Financial […]