Breach reporting by AFS Licensees in General Insurance

ASIC’s recent review of reportable situations (4th December 2024) revealed a number of poor practices among licensees (the review covered 14 licensees across all financial sectors): Licensees were generally slow to report to ASIC. The key driver of these delays was that licensees took a long time to identify breaches in the first place and begin investigating. When ASIC reviewed why this was happening, ASIC found that there were deficiencies in licensees’ incident management, particularly how they identified, escalated and recorded incidents. Most licensees had gaps in how they monitored their own compliance with the regime. These poor practices had real impacts on consumers. The failures to promptly identify breaches meant that licensees were very slow to rectify breaches and remediate customers. Start with a focus on incidents GI Licensees should focus on raising awareness for staff and authorised representatives so that they can identify and raise incidents. This ensures all potential harm and areas of continuous improvement are identified in a timely manner and potentially before a breach of obligations (or Industry Code has arisen). ASIC advises to adopt a simple definition of an incident. This reduces the risk of the business acting as a filter or blockage. Once an incident is pushed down the incident pipeline an experienced person can review the incident and determine whether it is a breach, or likely breach, of an obligation. ‘An incident is an event that occurs where something has gone wrong.’ Operational risk incidents All incidents have the potential to cause harm or detriment. Adopt the APRA CPS 230 definition of operational risk: ‘Legal risk, regulatory risk, compliance risk, conduct risk, technology risk, data risk and change management risk. To this definition, add financial risk incidents (including insurance risk) and strategic risk incidents. Reportable situations Once an incident has been identified, raised and reported by the business and/or distributors & service suppliers the incident(s) need to be categorized and managed to ensure the proper treatment. Incidents need to be considered singularly and, as part of a group in case of an emerging trend or theme. Compliance incidents need to be considered in context of the reportable situations regime. In addition, they must be considered in context of all financial services laws, privacy laws and Code (where relevant) and the separate reporting regime that applies for APRA insurers, the privacy notifiable breaches scheme and the relevant industry Codes. The reportable situations regime arises under Section 912DAA Corporations Act (also refer RG 78). There are 3 types of reportable situations for general insurance: (a) breaches or ‘likely breaches’ of core obligations that are significant; (b) investigations into breaches or likely breaches of core obligations that are significant; (c) additional reportable situations. What does significant breach mean? There are two ways to determine whether a breach is significant: (a) Deemed significant breaches: In certain situations, a breach or likely breach of a core obligation is taken to be significant; Generally speaking a breach is deemed significant if it is a civil/criminal penalty breach however […]
Read more

The use of technology in General Insurance – a compliance perspective

The use of technology in general insurance is increasing at a cautious pace due to the perceived lack of regulatory guidance or guardrails. APRA guardrails In respect of the General Insurance industry, it’s more likely that APRA will shape the governance for the use of technology rather than ASIC. Having said that, the influence of ASIC will continue to be significant at the operational level especially for Insurance brokers. We have already seen the influence of CPS 234 (Information security) on the industry & moreso with CPS 230 (Operational risk). APRA regulated insurers are responsible for their service suppliers therefore the Prudential Standards result in a cascading effect leading to industry change for Insurers and their Underwriting Agencies, TPAs and other service suppliers. A similar situation exists for Lloyds coverholders due to UK regulations and governance applying to Lloyds underwriters. ASIC recently released REP 798 Beware the gap: Governance arrangements in the face of AI innovation (29th October 2024). ASIC reviewed how 23 AFS licensees and credit licensees are using and planning to use artificial intelligence, how they are identifying and mitigating associated consumer risks, and their governance arrangements. The report outlines the key findings from that review. ASIC commented but on the whole, the way licensees used AI was quite cautious in terms of decision making and interactions with consumers: AI generally augmented rather than replaced human decision making and there was only limited direct interaction between AI and consumers. From a regulatory compliance perspective, the blending of human expertise and technology efficiency appears to be the sensible approach in the short to medium term. As a rule of thumb, the more severe the consequences of non-compliance, the higher involvement of people in technology driven processes and decision-making. The theme from ASIC’s report was that the (t)he maturity of governance and risk management did not always align with the nature and scale of licensees’ AI use (finding 7). This supports an APRA driven approach for governance. Start with insurers and allow the changes to cascade downstream to service suppliers and throughout the industry. Regulations are technology neutral It’s important to note that financial services laws are technology neutral. The AFSL general obligation to provide financial services ‘efficiently, honestly and fairly’, does not care whether human or technological means are used to provide the financial services, provided the overarching obligation is met. This is supported by the AFSL adequate resources general obligation, requiring AFS Licensees to have adequate resources (that is, the adequacy of human, technological and financial resources) to provide the financial services. This requirement does not apply to APRA regulated insurers as their obligations in this respect are covered by Prudential Standards such as CPS 234 and 230. Technology and the law – General insurance: where to start? The starting point should be Australia’s AI Ethics Principles Australia’s 8 Artificial Intelligence (AI) Ethics Principles are designed to ensure AI is safe, secure and reliable. They will help: achieve safer, more reliable and fairer outcomes for all Australians reduce […]
Read more

How to successfully manage regulatory change in General Insurance

Change is constant – none moreso the case in General Insurance – regulatory change, upcoming Code changes, changes due to regulator reviews, Court decisions, Code compliance reviews, the list is endless, add to that internal change due to binder & capacity changes, service supplier changes and the list goes on. Large insurers manage change through project management teams & change pipelines however what do you do if your resources are limited? This article has been written for Underwriting Agencies, Lloyds coverholders, Insurance Brokers, TPAs, Service Suppliers & small to medium sized insurers who must manage regulatory change and remain compliant through the complexity created by change. 1. The importance of a compliance operating rhythm The starting point is to have a tailored to your business, Risk & Compliance Manual that describes your compliance measures and provides you with an operating rhythm to managing risk & compliance. The Manual must include your obligations (financial services laws, GI or NIBA Code, binder agreement(s), service supplier agreements etc) and the key controls that are assigned to manage the obligations. A seperate Obligations register is suitable for larger firms provided the register is referenced in the Manual including how the register is managed. 2. The source of regulatory change Your manual must identify your sources of regulatory change. They are numerous and generally include (for non-lawyers) signing up to receive email feeds from regulators such as ASIC, APRA, OAIC, Austrac, ACCC AFCA Industry Associations such as ICA, NIBA, UAC and Insurtech Australia Financial services legal firms Insurance news services me via my Linkedin posts and my monthly Newsletter Navigating Compliance in General Insurance Also be mindful of internal change or change from your business partners. 3. High level review You’ve identified the regulatory change. What next? At this stage ask 3 questions: does this change apply to General Insurance? and, if so, does this change apply to the cohort I’m part of? (brokers, underwriting agency, TPA, service suppliers, insurers); and/or will this change impact me upstream/downstream (eg a Prudential Standard or the GI Code of Practice that applies to an insurer)? If yes to these questions proceed with step 4 otherwise ignore the change. 4. Deep analysis You need to work out the impact of the regulatory change to your business. It is useful to engage with your Industry Association, peers or your risk & compliance advisor (I’m happy to assist with any queries) to understand the common approaches that are being adopted across the industry to the regulatory change. Adopting the Who, What, When, Where, Why, and How approach is useful start with ‘why’ and understand the underlying rationale and purpose of the change ‘what’ is about the details. What does the new law require me to do? ‘when’ does the regulatory change take effect? This assists in planning the runway. ‘Where’ does the regulatory change apply? eg underwriting, claims, broking ‘how’ provides the details of what you must do to comply with the new regualtory change ‘who’ does the change apply to […]
Read more

Deciphering Personal Advice: A Guide to General Insurance

An Australian financial services licensee (Kalkine) must appoint an independent compliance consultant to address ASIC concerns that the Kalkine’s customer service representatives were giving unlicensed advice. (refer ASIC Media Release 25-085MR) New licence conditions have been imposed on the Kalkine’s licence to ensure compliance with its obligations as an AFS licensee. These conditions require Kalkine to engage a consultant to review, assess and report to ASIC whether Kalkine’s interactions with its customers are compliant and its supervision mechanisms are adequate. ASIC had concerns that: Kalkine’s representatives, who are based in India, may have provided personal advice as part of the sale of subscription services when Kalkine’s AFS licence only authorised it to provide general financial product advice, Kalkine’s representatives may have misrepresented to customers the kind of advice being given, by qualifying this as general advice but leaving customers with the impression that the advice was directed to their own personal circumstances, Kalkine failed to do all things necessary to ensure that the financial services covered by its AFS licence were provided efficiently, honestly and fairly including but not limited to ensuring the advice being given by its representatives was appropriate and within the scope of its licence, and Kalkine’s processes to ensure that its representatives were complying with the law when interacting with consumers were inadequate. Westpac case and personal advice The High Court in Westpac Securities Administration Ltd v Australian Securities and Investments Commission [2021] HCA 3 held that WSAL and BTFM breached the Corporations Act by providing personal financial product advice in calls made to 14 customers. Neither company was licensed to provide personal financial advice. The decision of the High Court clarified the difference between general and personal advice for consumers and financial services providers. ASIC Commissioner Danielle Press said (ASIC Media Release 3 February 2021), ‘The High Court has provided clarity concerning the differences between personal advice and general advice. Westpac were actively conducting a sales campaign aimed at rolling customers into Westpac products under the banner of general advice.’ In the judgment, Justice Gordon reinforced that s766B(3) of the Corporations Act, which outlines the meaning of general and personal advice, ‘is directed to the protection of the retail client’ and clarified that ‘[…] the general advice warning must be assessed in light of all the circumstances. The general advice warning was given only once, at the beginning of the telephone conversation. Members were subsequently asked directly about their personal objectives. Members were not encouraged to seek personal advice before deciding whether to accept the rollover service.’ Key compliance takeaways A General Advice Warning does not make the advice provided general advice. It is substance over form When you are giving general advice to a client, in addition to giving a general advice warning, it is good practice to take reasonable steps to ensure that the client understands upfront that they are getting general advice and not personal advice. You should take reasonable steps to ensure that the client understands that you have not taken […]
Read more

The general obligations of an AFS Licensee providing general insurance products & services

AFS Licensed insurers, underwriting agencies, TPAs (insurance claim managers), general insurance brokers and claimant intermediaries must comply with the general obligations set out in Section 912A(1) Corporations Act. You must have measures for ensuring you comply with your obligations ASIC uses the expression ‘measures’ or ‘compliance measures’ to refer to your processes, procedures or arrangements for ensuring that, as far as reasonably practicable, you comply with your obligations as a licensee, including the general obligations (see RG 104.23-24). ASIC expects you too: (a) document your measures in some form; (b) fully implement them and monitor and report on their use; and (c) regularly review the effectiveness of your measures and ensure they are up to date Tip: For most licensees (other than APRA regulated insurers) a single, tailored (describing your business and your products/services & your obligations; & how these are managed), Risk & Compliance Manual is sufficient. The Manual should also include governance & breach management. Contact me for assistance. What are the general obligations? the financial services covered by the licence must be provided efficiently, honestly and fairly In INFO 253 ASIC provides insights into what this obligation means in context of claims handling & settling services. The principles can be provided to sales & underwriting. providing the financial services in a timely manner including meeting time frames and standards in the GI Code of Practice or Insurance Brokers Code of Practice providing the financial services in the least onerous and intrusive way possible providing the financial services fairly and transparently, and in a way that supports consumers, particularly ones who are experiencing vulnerability or financial hardship 2. have in place adequate arrangements for the management of conflicts of interest This means identifying conflicts of interests and managing them by: disclosure controlling (through key controls); and avoiding. All conflicts (& there management) should be included in a conflicts of interest register with training provided to employees and other representatives. 3. comply with the conditions on the licence The conditions on your AFS licence reinforce some of the general obligations, so breaching a licence condition will sometimes also be a breach of the general obligation that the condition relates to. You must have measures in place to manage your licence conditions including, for example, a key person requirement condition or for insurance brokers the use of restricted broker terms. 4. comply with the financial services laws Financial services laws is a wide concept and in addition to Corporations Act & ASIC Act includes any other Commonwealth, State or Territory legislation that covers conduct relating to the provision of financial services (whether or not it also covers other conduct), but only in so far as it covers conduct relating to the provision of financial services. Financial services laws therefore relevantly includes: Insurance Contracts Act, Insurance Act and other Acts applying to APRA regulated insurers and the Privacy Act. 5. take reasonable steps to ensure that its representatives comply with the financial services laws This obligation requires licensees to train and […]
Read more

General Insurance broker commissions & informed consent – are you ready?

General insurance products are excluded from the conflicted remuneration obligations in respect of monetary or non-monetary benefits. However, from 9th July 2025, where personal advice is provided, or is likely to be provided, on general insurance products, the exclusion for monetary benefits only applies if the client’s informed consent to the monetary benefit has first been given. Refer: Corporations Act s963B(1)(a), s963BB, s963C(1)(a), and reg 7.7A.12G. Also refer ASIC RG 246 and INFO 292. what are the requirements? If you are a general insurance broker holding an AFS licence (or an [authorised] representative of a licensee) that receives monetary benefits (e.g. commissions) in connection with issuing or selling general insurance to a retail client while providing, or being likely to provide, personal advice to that client, you must: – obtain the client’s informed consent to receive the benefit before the insurance is issued or sold; – have the client’s written consent (or a copy of it), or a written record of any verbal consent that the client gave, and – as soon as practicable after the client provided informed consent, give the client a copy of the written consent, or a copy of the written record of the client’s verbal consent what does this mean in practice? The informed consent requirement applies to monetary benefits received by brokers from insurers (including underwriting agencies & Lloyds coverholders) given in connection with general insurance issued or sold after 9th July 2025 (including renewals after that date). if a broker is an authorised representative, the obligation applies to you in your capacity as an authorised representative. personal advice is financial product advice where the broker has considered one or more of the clients objectives, financial situation and needs or a reasonable person might expect the broker to have considered one or more of those matters. All other financial product advice is general advice. The informed consent requirement does not apply to monetary benefits given in connection with insurance issued or sold by AFS licensees and representatives if only general advice is provided or likely to be provided. If the situation involves both general advice and personal advice, the informed consent requirement applies to these benefits. The informed consent requirement does not apply to the giving of non-monetary benefits (e.g. education and training) to AFS licensees or representatives in connection with issuing or selling insurance. Note that AFSL general obligations ‘efficient, honest & fair’ and ‘conflicts of interest’ would apply to these arrangements especially if they are used to ‘disguise’ otherwise commission payments. This would also be misleading or deceptive conduct. If you are paid a monetary benefit without obtaining informed consent from your client, the monetary benefit you receive will breach the ban on conflicted remuneration. The consequences of breaching this ban could include a civil penalty, a banning order, or AFS licence suspension or cancellation. what must be provided to the client before they provide informed consent? Before a client can provide informed consent, you must disclose the following information to them: […]
Read more

Managing compliance in General Insurance through obligations and key controls

‘Documentation helps you demonstrate whether or not you are complying with the general obligations.’ – ASIC RG 104.26 Insurers, underwriting agencies, TPAs, Lloyds coverholders, insurance brokers and claim service suppliers have a myriad of obligations to comply with. Compliance with your obligations, through your processes, procedures, systems and people are collectively known as your ‘compliance measures‘. Your compliance measures, together with your governance mechanisms, should work as an operating rhythm that manages your obligations in a systematic manner, incorporates changes, evolves as your business grows and responds to the external environment. The Risk & Compliance Manuals that I design and are tailored for my general insurance clients achieve this purpose, through the following: 1. Identifying the source of your obligations The source of your obligations are defined by: Who you are ? – an APRA regulated insurer holding an ASF Licence and who subscribes to the GI Code has different obligations to a NIBA insurance broker who is an authorised representative of a Licensee. Who do you act on behalf of? an underwriting agency or material service provider acting on behalf of an insurer or an insurance broker acting on behalf of a client? What do you do? – provide financial advice, issue general insurance products, provide a claims handling service or are a claims service supplier to an APRA regulated insurer How do you do it? – do you distribute direct or through brokers, do you sell through human interaction or automated processes, do you provide claims under your licence or through a TPA? Who are your clients? – retail or wholesale clients , consumer insurance contract or other insurance contracts. standard form contracts 2. Capture your obligations For my smaller-medium sized clients I capture obligations within their Risk & Compliace Manual, providing a single source document. Larger clients usually have a stand-alone obligations register. The manual or register should also include the source of the obligations (e.g., Section 912A(1)(a) Corporations Act or paragraph 21 GI Code of Practice), this enables the reader to deep-dive into the actual obligation when required. 3. Assign key controls This is the heart of ensuring your compliance measures are adequate. Key control(s) are assigned to each obligation, so that the obligation is managed within risk appetite. The focus of the Board, Senior Managers and Risk & Compliance Committee now shifts from the numerous obligations to a suite of more manageable key controls. 4. Test your key controls A key control that is not periodically tested is no control. Testing should incorporate (1) design effectiveness – is it fit for purpose? and (2) operational effectiveness – is it operating as intended? Gaps must be identified, reported and closed out in a timely manner. The gaps must be assessed for regulatory or Code breaches. You must have a control testing program. 5. Monitoring and reviewing your compliance measures Your compliance measures must be monitored on an ongoing basis. An effective risk & compliance operating rhythm generates data – incidents, complaints, control testing, file reviews, attestations, […]
Read more

Responsible Managers in General Insurance – your obligations

The obligation One of the general obligations for AFS Licensees under Section 912A(1) Corporations Act is the ‘organisational competence obligation’. s912A(1)(e) ASIC assesses your compliance with this obligation by looking at the knowledge and skills of the people who manage your financial services business. ASIC refer to these people as your ‘responsible managers’. (refer RG 105) This is on ongoing obligation therefore it is important that your compliance measures, including how you comply with your obligations, are documented. How many responsible management should we nominate? At a minimum, you need to nominate responsible managers who: (a) are directly responsible for significant day-to-day decisions about the ongoing provision of your financial services; (b) together, have appropriate knowledge and skills for all of your financial services and products; and (c) individually, meet one of the five options for demonstrating appropriate knowledge and skills (refer Table 1 of RG 105). If you have a responsible manager with appropriate knowledge and skills for some, but not all, of your financial services or products, you need to ensure that your other responsible managers have appropriate knowledge and skills for the remaining services and products. The number of people you need to nominate as responsible managers will depend on the nature, scale and complexity of your business. However, ASIC expects that you will nominate at least two responsible managers. If you are heavily dependent on the competence of one or two responsible managers (e.g. in a small organisation with one or two principals), ASIC will generally impose a ‘key person’ condition on your AFS licence. Telling ASIC about your responsible managers You must demonstrate your organisational competence when you apply for an AFS licence. You may also need to demonstrate your organisational competence if you later apply to vary your licence authorisations. When you apply for an AFS licence, or to vary your licence authorisations, you must nominate your responsible managers in your application and answer questions about their role, training and experience, and which of the five options in they meet. You must also support your application with a ‘core proof’ demonstrating that your responsible managers: (a) individually meet one of the five options for demonstrating appropriate knowledge and skills; and (b) together have appropriate knowledge and skills to cover all of your financial services and products You must advise ASIC within 10 Business Days when you remove or add a responsible manager, refer the following link Changing your responsible managers If the responsible manager you are changing is named on your AFS licence as a key person, you must also apply to vary the key person condition on your licence. (Form FS03) If you need assistance with adding/removing responsible managers or varying your AFS Licence conditions, contact me. Obligations of a responsible manager The obligation for organisational competence applies to the licensee not the responsible manager with civil penalties applying for non-compliance however responsible managers may be subject to banning or disqualification orders for failing to fulifill their duties. The following cases are relevant […]
Read more