The ecosystem of Insurance as a fairness mechanism

Over the past few days I’ve been involved in a number of fascinating discussions with insurance leaders from claims, product and pricing and repairers, loss assessors, brokers and experts (engineers etc). The conversation has always led to the role of fairness in insurance. This concept is underpinned by a legal and code structure that requires services and products to be provided efficiently, honestly, fairly, transparently and timely, acting with the utmost good faith. I have been thinking through a framework that operates as an insurance ecosystem providing procedural fairness delivering fair outcomes. This does not mean pay every claim. Far from it, but an adverse decision would be arrived at efficiently and be part of a robust decision-making process where the insured was an intrinsic part of the process. I welcome your thoughts on the components of an ecosystem that operates as a fairness mechanism. I’ve provided some of my initial thinking to promote the conversation: everyone involved in the ecosystem is focused on fairness through conduct, behaviors and compliance with laws and codes; Insurers design and act within fair frameworks and systems. Such as triaging claims and complaints at lodgement so that complexity and vulnerability characteristics are identified early and specialist resources allocated before problems arise; consumer advocates, brokers and claimant intermediaries act as the voice of the customer however the system acts as a customer advocate when the customer is unrepresented; the system starts with a proposition that: the claim is covered unless the evidence shows otherwise; the complaint is valid until the evidence shows otherwise – with short time frames for the evidence to show otherwise; the use of AI to streamline decision-making and ensure that the right people with the appropriate levels of skills, knowledge and authority are involved at an early stage where the policy/claim is not atypical (such as the early indicators of characteristics or complexity and vulnerability); frontline staff act as the guardians of the system and provided with the training, systems and tools to, for example; (1) resolve complaints at first point of contact, (2) identify complexity and vulnerability; and (3) challenge an experts report that they don’t understand so that a defective report doesn’t become part of the ecosystem; the time from ‘IDR-EDR-Determination’, is reduced from months or years to weeks; expert reports are truly independent and factual that anyone in the system can rely on in good faith as the basis for conversation or settlement; product design and distribution flows through marketing – product design and pricing – sales – underwriting – claims; distribution processes align product design to customer needs, objectives and requirements while enabling freedom of choice; unconscious bias is removed from the system; remuneration is merely an output of the value that a person contributes to the system and the system manages inherent conflicts the system ensures that relevant resources are allocated to the complex, the vulnerable, the difficult; the system includes controls that manages, regulates, or directs the behavior of people, processes, or systems to achieve […]
Read more

What does it mean to carry on an insurance business in Australia?

In order to determine whether you need to be: authorised by APRA to carry on a general insurance business in Australia (Part III Division 1 Insurance Act 1973)and/or hold an Australian Financial Services Licence (AFSL) to provide financial services in Australia (such services include general insurance) (Section 911A Corporations Act) its necessary to consider whether you are carrying on an insurance business in Australia. Sources: Sutton on Insurance Law, Enright, Merkin, Hawke, Lawbook Co 2025 and ASIC Regulatory Guide RG 121 Carrying on Business The concept of ‘carrying on a business’ has been interpreted by the Courts and is also affected by section 21 Corporations Act. It should be noted that carrying on a business in Australia depends on the factual circumstances. However generally: include the degree to which a body corporate’s activities in Australia are conducted with system, repetition and continuity; the relevant activity need not generate or be motivated by profit; the business may be a carried on as part of or in conjunction with any other business; and it may be carried on alone or in conjunction with others. In Australia Section 21 provides that a body corporate has a place of business in Australia if the body corporate: establishes or is using a share transfer office or share registration office in Australia; or is administering, managing, or otherwise dealing with, property situated in Australia as an agent, legal personal representative or trustee, whether by employees or agents or otherwise. Section 21(3) provides a number of factors that in and of themselves do not indicate that a body corporate carries on a business in Australia. If you: a) are or become a party to a proceeding or effect settlement of a proceeding or of a claim or dispute; (b) hold meetings of your directors or shareholders or carry on other activities concerning your internal affairs; (c) maintain a bank account; (d) effect a sale through an independent contractor; (e) create evidence of a debt or create a charge on property; (f) secure or collect any of your debts or enforce your rights in regard to any securities relating to such debts; (g) conduct an isolated transaction that is completed within 31 days, not being one of a number of similar transactions repeated from time to time; or (h) invest any of your funds or hold any property Inducing If you engage in conduct that is ‘intended to induce people’ in Australia (or you engage in conduct that is likely to induce people in Australia) to use financial services you provide, then you will need to hold an AFS licence, unless an exemption applies. This is because of the deeming provision in s911D, which says that such conduct is ‘taken to be’ carrying on a financial services business in Australia. ASIC have granted specific exemptions that may apply: see ASIC Corporations (Foreign Financial Services Providers—Limited Connection) Instrument 2017/182 for ‘inducing’ wholesale clients, which applies until 31 March 2027. (refer RG 121.50) ASIC provides the following example in Table […]
Read more

Insurance brokers as an Authorised Representative – how are you managing contagion risk?

I’m often asked by insurance brokers, who are authorised representatives of a licensee, whether they should hold for their own AFS licence. I talk them through the mechanics of obtaining an AFS Licence, the cost (plus ongoing costs) of applying for a licence and how I can support them with their AFSL application. However, such a question requires an initial analysis of the risks, costs and benefits of holding your own AFS Licence compared to being an authorised representative of another licensee. With the increased regulatory scrutiny by ASIC over AR networks there is a strong case for obtaining your own licence. This scrutiny will, most likely, continue to increase. What is contagion risk? Contagion risk, in context of an AR network, is the likelihood that an adverse event, such as a cybersecurity failure or misconduct of one or more authorised representatives, impacts the entire AR network for that Licensee. This impact includes the impact to all other authorised representatives within the network and the licensee. A recent Federal court case highlighted contagion risk: Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496 (see ASIC media release (22-104MR)). RI Advice The Federal Court found AFS licensee, RI Advice, breached its license obligations to act efficiently and fairly when it failed to have adequate risk management systems to manage its cybersecurity risks. The finding comes after a significant number of cyber incidents occurred at authorised representatives of RI Advice between June 2014 and May 2020. In one of the incidents, an unknown malicious agent obtained, through a brute force attack, unauthorised access to an authorised representative’s file server from December 2017 to April 2018 before being detected, resulting in the potential compromise of confidential and sensitive personal information of several thousand clients and other persons. In addition to the declaration of contravention, the Court ordered RI Advice to engage a cybersecurity expert to identify and implement what, if any, further measures are necessary to adequately manage cybersecurity risks across RI Advice’s authorised representative network. RI Advice was ordered to pay $750,000 towards ASIC’s costs. Increased regulatory scrutiny leading to enhanced monitoring and supervision A number of insurance broker Licensee’s are having to report ‘reportable situations’ to ASIC, due to the conduct of authorised representatives. The reporting of reportable situations to ASIC, profile cases such as RI Advice, existing regulatory obligations and responsibility for the conduct of authorised representatives under Part 8.1 of the Insurance Brokers Code of Practice, will continue the enhanced regulatory focus of ASIC in respect of the operation and management of AR networks. Licensees are responding through rigourous due diligence processes as part of the AR appointment process and robust AR Monitoring Programs. I have worked with a number of licensed Insurance Brokers to set-up robust AR Monitoring Programs and due diligence. Licenced or AR? Costs and benefits – a compliance perspective From a risk and compliance persepective there is a benefit for a new brokerage to be an authorised representative of a […]
Read more

The cadence of compliance

Cadence refers to a regular, rhythmic flow of activity. The cadence of compliance refers to compliance infrastructure and the information and data that flows through the infrastructure. The cadence of compliance is critical to ensure that a firm’s compliance measures are adequate and documented, enabling self-regulation and self-reporting. A compliance cadence, importantly, enables the firm’s compliance measures to evolve and adapt through business growth, innovation, use of automation, and the development of new products, services, distribution channels and partnerships. Compliance infrastructure Think of a pipeline infrastructure in the energy sector. The network of pipelines, compressor stations, valves, and monitoring systems used to transport crude oil, natural gas, and refined products. Similarily, the pipeline infrastructure for compliance is the network of governance, IT systems, people and processes used to transport risk and compliance information and data flows. The components of compliance infrastructure Governance Including: roles and responsibilities, based on the 3 lines of defence accountability model; delegated authority for risk-decision making, based on the firm’s risk appetite statement; risk and compliance committees including sub-committees such as the breach management committee; monitoring and supervision including of the compliance system and of staff, authorised representatives, distributors and service suppliers; training and competency mechanisms; regulatory change management; product governance (design and distribution obligations); reporting to business operations, management, board, business partners, stakeholders and regulators; and record keeping. Licence management This includes those things that must be done to maintain an AFSL/APRA licence/authorisation such as: annual regulatory returns; ASIC IDR data reporting; notifying regulators of change of details including changes in responsibilities (such as responsibile managers); administrative matters; and changes to licence authorisations and conditions Risk management processes This includes how risks and complance obligations are managed: identification; analysis; evaluation; treatment; and monitoring Frameworks and sub-frameworks Aligned to governance however it is important to ensure that there is an overarching framework (enterprise risk management framework (ERMF)) and sub-frameworks such as obligations management, incidents , complaints, monitoring, product governance etc that align with and are connected to the ERMF. Information and data flows With the compliance pipeline infrastructure in place the test of the adequacy of the system is the information and data that flows through the infrastructure. Data and information enables risk decision-makers to self-regulate and self-report. Data and information This includes and is not limited to: incidents including regulatory/code incidents, operational risk incidents, cybersecurity incidents, people incidents and financial incidents; complaints conflicts of interest quality assurance, audits, and file reviews (underwriting, claims and broking) control testing outcomes risk profiling obligation management remediation and rectification activities training risk committee meetings business operational data attestations The cadence of compliance must be documented Documentation helps you demonstrate whether or not you are complying with the general obligations. When you document your measures, we [ASIC] expect this will include details of who is responsible, the timeframes involved and associated record keeping and reporting. (ASIC RG 104.26) In addition a documented cadence of compliance: supports training and education for staff, authorised representatives and service suppliers; provides assurance to management, […]
Read more

AFS Licensees must provide website addresses to ASIC to protect against scams

Names, licence numbers and websites of Australian Financial Services (AFS) licensees are increasingly being impersonated online, exposing consumers to scams. To combat this, in April 2026 ASIC decided that AFS licensee website addresses should be added to the AFS licensee professional register. These websites addresses will be published on the ASIC Professional Registers Search (PRS) from June 2026. Listing website addresses will enable consumers and businesses to check that they are dealing with genuine AFS licensee websites and combat impersonation scams where criminals copy the name and licence details of AFS licensees to create fake websites. From 4 May 2026, ASIC will begin to collect AFS licensee website addresses for all existing AFS licensees via the Regulatory Portal on a voluntary basis. If an AFS licensee provides ASIC with its website addresses (or confirms that it does not operate a website) then they must keep those details up to date. For example, an AFS licensee must inform ASIC, in relation to the websites used to carry on its financial services business, when it starts operating a website, stops using a website address it previously listed, or changes its principal website address. Key actions for AFS licensees Prepare Check that the AFS licensee’s Regulatory Portal ongoing contact person details are up to date so that it receives emails from ASIC about this change. If the AFS licensee uses more than one website address to carry on its financial services business, it should select one to nominate as the ‘principal’ website address. Provide Log into the Regulatory Portal and provide ASIC with the AFS licensee’s website addresses used to carry on its financial services business. See ASIC FAQ for guidance on which website addresses to provide and what format to provide them in. Update If an AFS licensee provides ASIC with its website addresses (or confirms that it does not operate a website) then they must update ASIC within 10 business days if their website addresses used to carry on their financial services business change or they start operating a website. Late fees will apply for changes provided after 10 business days. What will ASIC publish on the Professional Registers Search (PRS) webpage? ASIC will display an AFS licensee’s principal website address (or the fact that they do not have a website) prominently on the PRS. Any additional website addresses the AFS licensee provides will appear lower down in an expandable section. Why this matters Make it easier to spot AFS licensee impersonation websites and reduce investment scam losses. Help detect and disrupt scam websites that misuse AFS licensee details. Support other agencies and businesses to verify website addresses as part of a broader anti-scam effort. Align ASIC’s AFS professional register with approaches used by other international regulators. Disclaimer: Reproduction of statements made in this article by media outlets, whether in full or in part, is strictly prohibited without the written express consent of the author. The views, opinions, and positions expressed within this article are those solely of the author and […]
Read more

Insurance brokers – general or personal advice – what is the difference?

I continue to receive questions from general insurance brokers on the difference between general advice and personal advice. Personal advice is where the provider of the advice has considered one or more of the person’s objectives, financial situation and needs or a reasonable person might expect the provider to have considered one or more of those matters. (my emphasis) It is important to note that general advice is narrow in application and ASIC and the Court will adopt an approach of ‘substance over form’ as to whether general or personal advice has been provided. That is, providing a general advice warning does not mean that financial product advice is general advice per se, an examination of the facts and circumstances is required. This question was revisited by the High Court of Australia Westpac Securities Administration Ltd v Australian Securities and Investments Commission [2021] HCA 3. Also refer to ASIC media release 21-013MR Corporations Act Section 766B(3)(b) of the Corporations Act 2001 (Cth) defines “personal advice” so as to include “financial product advice” given or directed to a person in circumstances where a reasonable person might expect the provider to have considered one or more of the person’s objectives, financial situation and needs. Section 766B(4) defines “general advice” as financial product advice that is not personal advice. As the High Court stated [T]he division of the universe of financial product advice into “personal advice” and “general advice” serves to organise the obligations owed by a financial product adviser to a retail client, with more onerous obligations being imposed upon the adviser where the circumstances are apt to suggest to the client that the financial product, the subject of the advice, is appropriate to the particular circumstances of the individual client. Circumstances Westpac Bank subsidiaries, Westpac Securities Administration Limited (WSAL) and BT Funds Management Limited (BTFM), conducted two telephone campaigns by the Westpac companies which recommended that customers roll out of their other superannuation funds into a Westpac-related superannuation account. As a result of the campaigns, Westpac increased its funds under management by almost $650 million between 1 January 2013 and 16 September 2016. The High Court confirmed that WSAL and BTFM breached financial services laws, including the requirement to act in their clients’ best interests and the requirement to act honestly, efficiently and fairly. The unanimous High Court judgment upheld the Full Federal Court decision regarding the conduct of WSAL and BTFM, dismissing their appeal and holding that they breached the Corporations Act by providing personal financial product advice in calls made to 14 customers. Neither company was licensed to provide personal financial advice. Judgment In the judgment, Justice Gordon reinforced that s766B(3) of the Corporations Act, which outlines the meaning of general and personal advice, ‘is directed to the protection of the retail client’ and clarified that ‘[…] the general advice warning must be assessed in light of all the circumstances. The general advice warning was given only once, at the beginning of the telephone conversation. Members were subsequently asked […]
Read more

Complaints in General Insurance – RG 271 – what must you comply with?

AFS Licensee’s must; have a dispute resolution system (process) that complies with standards and requirements made or approved by ASIC and covers complaints made by [retail] clients in connection with the provision of the financial services; and, be a member of AFCA. (refer s912A(1)(g) and (2) Corporations Act). The licensee’s IDR must include complaints against representatives including authorised representatives. It follows that authorised representatives must immediately notify the licensee about the complaint. In addition, subscribers to the GI Code of Practice and Insurance Brokers Code of Practice must comply with parts 11 and 9.0, respectively. Understanding the nuances of RG 271 – enforceable paragraphs The general obligation for IDR in section 912A(1) gives rise to a legal obligation imposed on the Licensee. However, the legal requirement only applies to the enforceable paragraphs in RG 271and not all paragraphs RG 271. Any paragraph that is not identified by ASIC as an ‘enforceable paragraph’ in RG 271 is regulatory guidance only and not a legal requirement. (refer RG 271.8 and RG 271.9) What are the enforceable paragraphs of RG 271 for general insurance? definition of complaint RG 271.27 – RG 271.29 (including note) posts (that meet the definition of ‘complaint’ set out in RG 271.27) on a social media channel or account owned or controlled by the financial firm that is the subject of the post, where the author is both identifiable and contactable RG 271.32 small business complaints RG 271.36 outsourcing IDR processes RG 271.48 what an IDR response must contain RG 271.43- RG 271.54 (including notes) when an IDR response must be provided by RG 271.56 – RG 271.60 (including note) complaint management delays RG 271.64- RG 271.66 (including notes) complaints closed within five business days of receipt RG 271.71 IDR response within 5 business days RG 271.75 the role of customer advocates RG 271.109- RG 271.110 (including note 1) links between the IDR process and AFCA RG 271.111- RG 271.112 how to manage systemic issues RG 271.118- RG 271.120 (including note) accessibility of IDR process RG 271.134 no charges or detriment RG 271.141 resourcing and staff numbers RG 271.142 – RG 271.143 empowering staff and financial delegations RG 271.146- RG 271.147 maximum IDR timeframes and closing complaints RG 271.163 and RG 271.165 policy and procedures RG 271.172 data collection, analysis and internal reporting RG 271.179 report complaints data internally and publicly RG 271.183 Disclaimer: Reproduction of statements made in this article by media outlets, whether in full or in part, is strictly prohibited without the written express consent of the author. The views, opinions, and positions expressed within this article are those solely of the author and Compliance Advocacy Solutions Pty Ltd and not the views of other individuals, companies or organisations they may be affiliated with. The author and Compliance Advocacy Solutions Pty Ltd make no representations as to accuracy, completeness, currency, suitability, or validity of any information in this article and will not be liable for any errors or omissions or any loss or damage arising from […]
Read more

Obtaining an AFS Licence for general insurance

I’m often asked to outline what is involved in obtaining an AFS Licence in Australia for general insurance. I have assisted many people to obtain a new AFS Licence, vary an existing Licence and add new responsible managers. The process to obtain an AFS licence to provide general insurance services or products is not overly complex however, it is time-consuming and labour-intensive, as ASIC’s information requirements are specific. All AFS licence applications (new and variations) must be submitted via ASIC’s online regulatory portal. I assist my clients in setting their business up in the portal and providing me with access so that I can facilitate the application for them. My typical clients requiring a new AFS licence include: insurance brokers who are currently authorised representatives; people who want to operate an Underwriting Agency in Australia (including Lloyds coverholders); foreign companies that want to provide financial services in Australia; and people wanting to provide claim services either for insurers (insurance claim managers) or insureds (claimant intermediaries) I manage AFS Licence variations (including adding responsible managers) for insurers, brokers, underwriting agencies, claim service providers and anyone who currently has an AFS Licence for general insurance products Typical general insurance authorisations AFSL authorisations relevant for general insurance are: providing financial product advice including general financial product advice only; dealing including issuing (when acting on behalf of insurers) and dealing on behalf of another person (insurance brokers including obtaining the use of restricted broker terms); and claims handling and settling services on behalf of insurers or on behalf of an insured. The financial services can be provided to Retail and/or Wholesale clients. The AFS Licence application process The process for a new AFS Licence application is more involved and complicated than a licence variation. This example deals with a new AFSL application however I can assist you with information requirements and the process for variations on request. Contact me here ASIC provides guidance on the process and information requirements in RG 1 and INFO 294. People requirements Information must be provided to ASIC on your fit and proper people and your responsible managers. Fit and Proper people Section 913BA of the Corporations Act requires that, before a licence is granted, ASIC must be satisfied that there is no reason to believe that certain people involved in the management or control of your financial services business are not ‘fit and proper persons’ to undertake that role. You will need to include details of your fit and proper people in the application (refer RG 1.138 – 1.166). A fit and proper person is your ‘officers’ and this is defined in section 9 Corporations Act, relevantly to include: a director or secretary of the corporation; or person: (i) who makes, or participates in making, decisions that affect the whole, or a substantial part, of the business of the corporation; or (ii) who has the capacity to affect significantly the corporation’s financial standing; or (iii) in accordance with whose instructions or wishes the directors of the corporation are accustomed to act […]
Read more

The problem with cash settlements – a blight on our industry

Typically, for home building claims, a cash settlement payment is offered as a settlement option when a repairer can’t guarantee repairs due to concurrent wear & tear or maintenance issues. Under paragraph 86 of the GI Code of Practice, insurers who have authorised repairs must accept responsibility for the quality of the builders work and the materials they use. This clause has led to an unfair practice of offering cash payments as a first resort. Most customers aren’t aware of their rights at law and under the GI Code, and simply accept the cash settlement offer. Problems arise when repair costs escalate (due to the rising cost of living or petrol cost increases and commensurate impact on supply chain) and the risks associated with project managing repairs. The standard claims settlement process appears to be that whenever there is a mix of covered damage and damage caused due to wear and tear or lack of maintenance, there is a default to a cash settlement payment. This position is difficult to reconcile when the same builder (under the guise of an expert report) has clearly been able to distinguish between storm damage and wear & tear/maintenance and provides a causation report. Most consumers don’t want the inconvenience of having to arrange repairs, coordinate trades and generally project management the work. A simple solution would be to provide the customer with the option of being provided with a detailed Scope of Works itemising insurance covered work and excluded work. The Code guarantee would be provided for the insurance covered work with the customer acknowledging their liability and payment for excluded work. Regulatory view of cash settlements (and cash settlement fact sheets) Cash settlements and cash settlement fact sheets (CSFS) remain on the radar of regulators. ASIC We will review general insurers’ use of cash settlements to better understand the practices and disclosures surrounding the offers being made and to assess whether there are risks of consumer harm. ASIC Corporate Plan 2025-2026 Code Governance Committee As part of our 2024-25 workplan, we committed to reviewing the information insurers provided to customers on cash settlements and the processes they follow when deciding to offer a cash settlement. We note that, in the Industry Action Plan, insurers have committed to a range of actions to address recommendations relating to cash settlements. We also note ASIC’s recent report, finding that insurers need to provide better information to consumers around cash settlements. We will review what information insurers provide to customers, and what information those customers need to make effective decisions around cash settlements. CGC Priorities 2025-26 Cash Settlement Fact Sheets An insurer, underwriting agency or TPA acting on behalf of either must provide a cash settlement fact sheet where: the financial service is claims handling and settling; and the service is offering to settle all or part of a claim under a general insurance product using a cash payment; and the customer is a retail client; and the PDS provides repair or replacement as settlement options. […]
Read more

Disclosure documents – it’s all about the timing (and content)

I’m often asked when must a certain document be provided to a client? Disclosure documents for general insurance generally have have 2 requirements: content requirements; and timing requirements This article will focus on the timing requirements. Customer/client journey The simplest way to think about the timing requirements for disclosure documents is to think about the various customer touchpoints or the customer journey. Insurance brokers often send an important noticedocument when invoicing clients containing all relevant information such as FSG, general advice warning, duty to take reasonable care, duty of disclosure etc. While convenient, care should be taken with this approach to ensure the regulatory timing requirements are met Code requirements Brokers and insurers (including underwriting agencies, TPAs and other material service providers) also have requirements under respective industry Codes to provide certain information at a specific time. The customer/client journey should not only be mapped out to cover regulatory disclosure documents but should also pick up Code requirements such as providing a Terms of Engagement (brokers). The regulatory disclosure cycle It should be noted that disclosure documents are only required to be provided to Retail clients however it is common practice for a FSG to be provided to both retail and wholesale clients. A TMD is not a disclosure document as it only must be made available by a product issuer before it distributes a general insurance product. The product issuer must make a TMD available and a distributor must not engage in retail product distribution conduct unless a TMD is available or not required (see RG 274). It’s important to note that a TMD is not only relevant for Retail clients. The test is whether a Retail client could purchase the product, even if intended for Wholesale clients. Let’s explore the disclosure documents relevant for general insurance based on the customer experience or journey. I’ve included the reference in the Corporations Act for the content requirements in case you wish to have a look at these requirements in addtiion to the timing requirements. FSG Obligation to give a FSG if financial services provided to a Retail client (s941A for licensees and s941B for authorised representatives) Timing of FSG (s941D) Content requirements (s942A – 942E including a combined FSG/PDS) A FSG must be given to the (retail) client as soon as practicable after it becomes apparent that the financial service will be, or is likely to be, provided to the client, and in any event must be given to the client before the financial service is provided. (s941C provides situations in which a FSG is not required). Practically speaking, the FSG will be provided before any financial product advice is provided, this means on appointment (for brokers) or at quote stage (for underwriters). A claimant intermediary must provide a FSG before they provide any claims handling settling services to the client (s941C(7A)). This is because they are acting on behalf of the insured. A claims manager, acting on behalf of the insurer, is not required to provide a FSG, as […]
Read more