The Federal Court today imposed penalties of $35 million against Harvey Norman Holdings Ltd and $20 million against Latitude Finance Australia for misleading conduct and false or misleading representations they made in a national advertising campaign promoting a 60-month interest free and no deposit payment method for goods purchased at Harvey Norman stores. The combined penalty is the highest obtained by ASIC for misleading conduct and false or misleading representations relating to financial products and services. In respect of the penalties, the Court considered the parties compliance processes I have concluded that Harvey Norman and Latitude were equally responsible for the misleading advertisements. All other things being equal, it would be appropriate to impose the same penalty on each defendant. It must be determined whether there is sufficient reason to impose differential penalties on the defendants. [201] I consider that a higher penalty should be imposed on Harvey Norman in comparison to Latitude. A higher penalty is warranted to deter repetition and to motivate Harvey Norman to improve its compliance processes … I consider that penalties in those amounts will be sufficient to ensure that neither defendant regards the penalties as merely the cost of doing business. [211] The proceeding concerned a national advertising campaign run by Harvey Norman and Latitude between 1 January 2020 and 11 August 2021 promoting “no deposit” and “60 months interest free” purchases of goods from Harvey Norman franchise stores. The advertisements were widespread (newspapers, radio, TV) and did not disclose that to access the promotion consumers had to enter a continuing credit contract linked to a credit card account (the “GO Mastercard”) and pay fees (including an establishment fee and monthly account service fees. Compliance and contrition In delivering his Honour’s reasons, Justice O’Bryan said Harvey Norman and Latitude ‘put sales and their commercial interests above the interests of consumers, and also distorted the markets in which competing goods and finance are offered.’ The Court said that ‘the compliance processes of both defendants were wholly inadequate to prevent the contravening conduct.’ Justice O’Bryan further said, ‘Given the scale and sophistication of both defendants, that is an extraordinary state of affairs’ and ‘is particularly striking in the case of Harvey Norman’. Justice O’Bryan said that ‘Harvey Norman and Latitude were equally responsible for the contravening advertisements’, however, his Honour ordered Harvey Norman to pay a higher penalty because ‘the defendants have…exhibited a different level of contrition’, ’public statements made by Harvey Norman’s Chairman show a disregard for the potential harm suffered by consumers from Harvey Norman’s misleading conduct’, and ‘A higher penalty is warranted to deter repetition and to motivate Harvey Norman to improve its compliance processes’. Compliance culture The Court made a number of findings in respect of the parties culture of ensuring compliance with the ASIC Act: Harvey Norman the evidence adduced with respect to its compliance systems and training can be described as paltry. No witness was called to give evidence about Harvey Norman’s compliance systems and training during the relevant period […]
Introduction: why “fairness” has become the organising idea in claims Claims handling is where the insurance promise is either delivered or denied. In Australia, expectations about claims conduct have historically been anchored in the duty of utmost good faith implied into insurance contracts and expressed in s 13 of the Insurance Contracts Act 1984 (Cth) (ICA). That duty remains central to modern disputes, but it is no longer the sole regulatory “north star”. Since claims handling and settling was brought within the definition of a financial service from 1 January 2022, claims conduct has been reframed through the AFSL regime and, in particular, the obligation to provide financial services “efficiently, honestly and fairly” (EHF) under s 912 A(1)(a) of the Corporations Act 2001 (Cth). That obligation is now complemented, and in many respects operationalised, by the GI Code of Practice (GI Code), which has steadily moved from principle to process, and is now being redrafted again to further elevate claims standards, vulnerability supports and governance. This article traces that evolution: from good faith, to fairness, to the “fairness-by-design” direction signalled by the Draft GI Code. 1. Utmost good faith: the original claims-handling guardrail 1.1 The duty as an implied condition of the insurance bargain The duty of utmost good faith in ICA s 13 is often described as a key statutory expression of a long-standing insurance norm. In modern authority, the High Court has emphasised that s 13 is not a free‑standing general duty, but is to be understood in a way that aligns with the duty’s operation as an implied contractual conditiongoverning the manner in which rights, powers and obligations are exercised “under or in relation to” the contract. That framing matters in claims because the “pressure points” in claims, information requests, investigations, repair pathways, reserving rights, reliance on remedies for non-disclosure or misrepresentation, partial admissions and settlement strategy, are all exercises of contractual or statutory rights in connection with the contract. 1.2 What good faith has come to mean in claims conduct (and what it does not) Although the duty is contextual and case-specific, judicial discussion and regulatory pleadings have repeatedly linked utmost good faith to commercial standards of decency and fairness, due regard to the insured’s interests, and conduct that is not merely “not dishonest” but also not oppressive, capricious or unfair in its practical operation. At the same time, a persistent theme in modern commentary is that utmost good faith is not fiduciary and does not demand “unnatural altruism”; it is compatible with insurers legitimately protecting their own interests within the contract and the statute, provided that protection is pursued consistently with the duty’s constraints. The High Court’s decision in Allianz Australia Insurance Limited v Delor Vue Apartments CTS 39788 [2022] HCA 38 illustrates the point. The case arose from claims and settlement communications following cyclone damage, complicated by non‑disclosure of pre-existing defects and a dispute about the scope/sequence of works and allocation of costs. The High Court ultimately held that the insurer’s conduct (including reliance […]
NIBA has today opened the final draft of its rewritten Insurance Brokers Code of Practice for public consultation. Consultation closes on Friday, 7 August 2026. Key takeaways The Draft 2027 Insurance Brokers Code of Practice (2027 Code) is a sound industry Code with the following improvements over the current Code: The 2027 Code: AFSL – has strengthened the connection with brokers AFSL obligations; conflicts of interest – codified ASIC’s RG 181 Conflicts of Interests and provided a structured mechanism to manage conflicts; strata insurance – requires documented management of conflicts of interest, remuneration disclosure for all strata insurance, and identifies the owners corporation as the client not the strata manager remuneration – required for Retail Clients at quotation $ or % or both) and invoicing ($) and disclosure to all clients (retail and wholesale) when requested vulnerability – requires a structured documented approach including staff training and working with insurers reporting – codifies requirement to keep, produce and retain records IBCCC – strengthened enforcement and sanction powers review – every 5 years My observations of each Section Section 1 – About this Code the 2027 Code connects the Code to AFS Licences. This will provide stronger enforcement powers to IBCCC however requires some caution as the 2027 Code is directed at operational transactions and conduct while the s912A(1) AFSL general obligations are positioned at a more elevated level focusing on systems and procedures rather than isolated conduct. Section 2 – how the Code works the 2027 Code recognises the time to implement material system changes and provides for a 2 to 18 month system-change runway (in particular Section 7.1(a)(ii), which extends commission disclosure to strata insurance). the 2027 Code expressly applies to interactions and dealings with prospective clients. the 2027 Code has 2 tiers – Code Principles (section 3) and Obligations (sections 4-14). Where an obligation in the Code does not expressly cover a situation, the Code Principles guide how a Code Subscriber should act. Section 3 – Code Principles and our commitments the Code Principles apply to a wide range of interactions other than client interactions including prospective clients, other brokers (whether NIBA members or not), insurers, assessors, loss adjusters, and experts, IBCCC, NIBA, AFCA and regulators. the Principles include professional commitment (training & competency), ethical behaviour, transparency and accountability the Code extends to employees and authorised representatives of the NIBA member Section 4 – Engagement and terms greater disclosure obligations apply before acting for a prospective client and an overarching requirement to do everything we reasonably can to give our clients clear information so they understand the services we are providing. Section 5 – Communications, behaviour, and who we act for the 2027 Code effectively negates general advice other than when provided in generic advertising materials. When providing advice, we must give our clients the information they need to understand the advice, including the costs, key risks and benefits of any products we recommend, and any other matters required by law. It’s difficult to see how the above […]
I have numerous conversations with people in Australia, UK and USA looking to start an Underwriting Agency in Australia and seeking to understand what’s involved from a regulatory perspective. Typically the clients in UK and USA are managing existing MGA’s across UK, Europe and USA. Australian clients are typically people who have worked at an insurer, broker, other underwriting agency or are currently managing an agency that is an AR of an insurer. Based on my experience, here are my top practical tips: 1. Understand the time frame It’s easy to feel a little overwhelmed by the task ahead however, rest assured, it’s a well-worn path although a sound plan is critical. Assuming you have landed on your insurance product offering and services (such as claims handling), some of the things you need to consider: as an underwriting agency you need to operate under a binder with an APRA regulated insurer. This can either be a general insurer (Australian based) or Lloyds underwriter. It’s important to have the binder discussions advanced as a draft copy of the binder (including the schedule(s) but unsigned) needs to be submitted as part of your AFSL application (see point 2). Binder discussions will also include claims management and complaint management. if you will be using Lloyd’s capacity you need to consider the time-frame for becoming a Lloyd’s coverholder. This requires engaging a sponsoring Lloyd’s broker and/or managing agent and Lloyd’s Australia. if the company (and including the ultimate parent) who controls the Australian licensee is based overseas with overseas domiciled directors you need to account for the time to obtain fit and proper checks from those jurisdictions the time to obtain an AFS Licence; and setting up your business including registration, systems, people and a myriad of other tasks and activities 2. Do you need an AFSL? An Underwriting Agency generally is required to hold an AFS Licence for general insurance products with financial product advice, dealing, and claims handling (if agreed by the insurer) authorisation. You do not need to hold an AFSL if you are an authorised representative of a suitably authorised licensee or can rely on an exemption. If you are intending to provide financial services to Wholesale clients only, there is an exemption for APRA regulated insurers and Lloyds underwriters. However, this creates practical issues in dealings with insurance brokers plus most Agencies prefer the governance that a Licence affords. 3. Setting up a business in Australia There are the usual steps involved in setting up a business in Australia, including: choosing the company type and shareholder/ownership structure registering the company with ASIC apply for an ABN and register Business name(s) RG 121 is an ASIC guide is for people or companies from overseas who propose to conduct a financial services business in Australia. 4. What are the people requirements for AFS licensing? The main requirements are: the fit and proper requirement – ASIC must ensure that your key people meet the requirements of the fit and proper test. This […]
A recent case in the NSW Supreme Court has highlighted the hidden risks, and care required, by brokers using letters of appointment Sphere Healthcare Pty Ltd v Allianz Australia Insurance Ltd [2026] NSWSC 579 The case involved a breach of the duty of disclosure for failing to disclose the storage of bulk ethanol that exceeded the capacity of the dangerous goods area and was placed next to the factory. The factory was destroyed in a fire and the insurer successfully denied indemnity. The insured manufactured health care products and infant formula however, as a result of the COVID-19 pandemic, the insured decided to make hand sanitiser and sought cover under an ISR policy. However, during the period that the insured was trying to source ethanol (to use in the production of hand sanitiser), the insured changed brokers. My focus for the purposes of this article is the circumstances of the appointment of the broker. The circumstances In parallel with the sourcing of a large quantity of ethanol, the Group (who had recently acquired the insured), was working with three insurance brokers to source insurance for the group. The Group wanted to keep the ISR policy which the holding broker had arranged. The new broker asked the insurer to transfer the ISR policy, while the holding broker asked the insurer to cancel it. After some confusion caused by the fact that the new broker’s letter of appointment was back-dated, the insurer issued a new policy schedule and wording but for the same premium. [4] The appointment of the holding broker 4 months prior to the fire and following a tender process, the insured provided the holding broker with a letter of appointment [76]. The Court highlighted the insured’s discussions to change brokers; notwithstanding the letter of appointment, the Group was continuing to seek cheaper insurance through the new broker. The insured emailed the new broker, pressing for the best price, “Please try any good strategies to get us a good package deal”. The insured proposed to “fully follow” some policies arranged by the holding broker, including for the relevant site, and then use the new broker to arrange other policies, “This way, the total cost is still much lower than the current [holding broker] pricing.” But the policies arranged by the new broker “cannot be backdated”. Nor did they want to pay “broker fees twice”. It was decided to appoint the new broker on receiving confirmation that the policies arranged by the holding broker “will remain unchanged after [the new broker] takes over, and we won’t be double charged.” [127] Back-dating the letter of appointment for the new broker In order … to take over some of the policies”, the new broker recommended that its appointment be backdated to 29 February 2020. The insured was asked to photocopy a letter onto the Group’s letterhead and to sign and return the document that day. In respect of the policy for the relevant site, the new broker noted “to take over, premium amended”. […]
Over the past few days I’ve been involved in a number of fascinating discussions with insurance leaders from claims, product and pricing and repairers, loss assessors, brokers and experts (engineers etc). The conversation has always led to the role of fairness in insurance. This concept is underpinned by a legal and code structure that requires services and products to be provided efficiently, honestly, fairly, transparently and timely, acting with the utmost good faith. I have been thinking through a framework that operates as an insurance ecosystem providing procedural fairness delivering fair outcomes. This does not mean pay every claim. Far from it, but an adverse decision would be arrived at efficiently and be part of a robust decision-making process where the insured was an intrinsic part of the process. I welcome your thoughts on the components of an ecosystem that operates as a fairness mechanism. I’ve provided some of my initial thinking to promote the conversation: everyone involved in the ecosystem is focused on fairness through conduct, behaviors and compliance with laws and codes; Insurers design and act within fair frameworks and systems. Such as triaging claims and complaints at lodgement so that complexity and vulnerability characteristics are identified early and specialist resources allocated before problems arise; consumer advocates, brokers and claimant intermediaries act as the voice of the customer however the system acts as a customer advocate when the customer is unrepresented; the system starts with a proposition that: the claim is covered unless the evidence shows otherwise; the complaint is valid until the evidence shows otherwise – with short time frames for the evidence to show otherwise; the use of AI to streamline decision-making and ensure that the right people with the appropriate levels of skills, knowledge and authority are involved at an early stage where the policy/claim is not atypical (such as the early indicators of characteristics or complexity and vulnerability); frontline staff act as the guardians of the system and provided with the training, systems and tools to, for example; (1) resolve complaints at first point of contact, (2) identify complexity and vulnerability; and (3) challenge an experts report that they don’t understand so that a defective report doesn’t become part of the ecosystem; the time from ‘IDR-EDR-Determination’, is reduced from months or years to weeks; expert reports are truly independent and factual that anyone in the system can rely on in good faith as the basis for conversation or settlement; product design and distribution flows through marketing – product design and pricing – sales – underwriting – claims; distribution processes align product design to customer needs, objectives and requirements while enabling freedom of choice; unconscious bias is removed from the system; remuneration is merely an output of the value that a person contributes to the system and the system manages inherent conflicts the system ensures that relevant resources are allocated to the complex, the vulnerable, the difficult; the system includes controls that manages, regulates, or directs the behavior of people, processes, or systems to achieve […]
In order to determine whether you need to be: authorised by APRA to carry on a general insurance business in Australia (Part III Division 1 Insurance Act 1973)and/or hold an Australian Financial Services Licence (AFSL) to provide financial services in Australia (such services include general insurance) (Section 911A Corporations Act) its necessary to consider whether you are carrying on an insurance business in Australia. Sources: Sutton on Insurance Law, Enright, Merkin, Hawke, Lawbook Co 2025 and ASIC Regulatory Guide RG 121 Carrying on Business The concept of ‘carrying on a business’ has been interpreted by the Courts and is also affected by section 21 Corporations Act. It should be noted that carrying on a business in Australia depends on the factual circumstances. However generally: include the degree to which a body corporate’s activities in Australia are conducted with system, repetition and continuity; the relevant activity need not generate or be motivated by profit; the business may be a carried on as part of or in conjunction with any other business; and it may be carried on alone or in conjunction with others. In Australia Section 21 provides that a body corporate has a place of business in Australia if the body corporate: establishes or is using a share transfer office or share registration office in Australia; or is administering, managing, or otherwise dealing with, property situated in Australia as an agent, legal personal representative or trustee, whether by employees or agents or otherwise. Section 21(3) provides a number of factors that in and of themselves do not indicate that a body corporate carries on a business in Australia. If you: a) are or become a party to a proceeding or effect settlement of a proceeding or of a claim or dispute; (b) hold meetings of your directors or shareholders or carry on other activities concerning your internal affairs; (c) maintain a bank account; (d) effect a sale through an independent contractor; (e) create evidence of a debt or create a charge on property; (f) secure or collect any of your debts or enforce your rights in regard to any securities relating to such debts; (g) conduct an isolated transaction that is completed within 31 days, not being one of a number of similar transactions repeated from time to time; or (h) invest any of your funds or hold any property Inducing If you engage in conduct that is ‘intended to induce people’ in Australia (or you engage in conduct that is likely to induce people in Australia) to use financial services you provide, then you will need to hold an AFS licence, unless an exemption applies. This is because of the deeming provision in s911D, which says that such conduct is ‘taken to be’ carrying on a financial services business in Australia. ASIC have granted specific exemptions that may apply: see ASIC Corporations (Foreign Financial Services Providers—Limited Connection) Instrument 2017/182 for ‘inducing’ wholesale clients, which applies until 31 March 2027. (refer RG 121.50) ASIC provides the following example in Table […]
I’m often asked by insurance brokers, who are authorised representatives of a licensee, whether they should hold for their own AFS licence. I talk them through the mechanics of obtaining an AFS Licence, the cost (plus ongoing costs) of applying for a licence and how I can support them with their AFSL application. However, such a question requires an initial analysis of the risks, costs and benefits of holding your own AFS Licence compared to being an authorised representative of another licensee. With the increased regulatory scrutiny by ASIC over AR networks there is a strong case for obtaining your own licence. This scrutiny will, most likely, continue to increase. What is contagion risk? Contagion risk, in context of an AR network, is the likelihood that an adverse event, such as a cybersecurity failure or misconduct of one or more authorised representatives, impacts the entire AR network for that Licensee. This impact includes the impact to all other authorised representatives within the network and the licensee. A recent Federal court case highlighted contagion risk: Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496 (see ASIC media release (22-104MR)). RI Advice The Federal Court found AFS licensee, RI Advice, breached its license obligations to act efficiently and fairly when it failed to have adequate risk management systems to manage its cybersecurity risks. The finding comes after a significant number of cyber incidents occurred at authorised representatives of RI Advice between June 2014 and May 2020. In one of the incidents, an unknown malicious agent obtained, through a brute force attack, unauthorised access to an authorised representative’s file server from December 2017 to April 2018 before being detected, resulting in the potential compromise of confidential and sensitive personal information of several thousand clients and other persons. In addition to the declaration of contravention, the Court ordered RI Advice to engage a cybersecurity expert to identify and implement what, if any, further measures are necessary to adequately manage cybersecurity risks across RI Advice’s authorised representative network. RI Advice was ordered to pay $750,000 towards ASIC’s costs. Increased regulatory scrutiny leading to enhanced monitoring and supervision A number of insurance broker Licensee’s are having to report ‘reportable situations’ to ASIC, due to the conduct of authorised representatives. The reporting of reportable situations to ASIC, profile cases such as RI Advice, existing regulatory obligations and responsibility for the conduct of authorised representatives under Part 8.1 of the Insurance Brokers Code of Practice, will continue the enhanced regulatory focus of ASIC in respect of the operation and management of AR networks. Licensees are responding through rigourous due diligence processes as part of the AR appointment process and robust AR Monitoring Programs. I have worked with a number of licensed Insurance Brokers to set-up robust AR Monitoring Programs and due diligence. Licenced or AR? Costs and benefits – a compliance perspective From a risk and compliance persepective there is a benefit for a new brokerage to be an authorised representative of a […]
Cadence refers to a regular, rhythmic flow of activity. The cadence of compliance refers to compliance infrastructure and the information and data that flows through the infrastructure. The cadence of compliance is critical to ensure that a firm’s compliance measures are adequate and documented, enabling self-regulation and self-reporting. A compliance cadence, importantly, enables the firm’s compliance measures to evolve and adapt through business growth, innovation, use of automation, and the development of new products, services, distribution channels and partnerships. Compliance infrastructure Think of a pipeline infrastructure in the energy sector. The network of pipelines, compressor stations, valves, and monitoring systems used to transport crude oil, natural gas, and refined products. Similarily, the pipeline infrastructure for compliance is the network of governance, IT systems, people and processes used to transport risk and compliance information and data flows. The components of compliance infrastructure Governance Including: roles and responsibilities, based on the 3 lines of defence accountability model; delegated authority for risk-decision making, based on the firm’s risk appetite statement; risk and compliance committees including sub-committees such as the breach management committee; monitoring and supervision including of the compliance system and of staff, authorised representatives, distributors and service suppliers; training and competency mechanisms; regulatory change management; product governance (design and distribution obligations); reporting to business operations, management, board, business partners, stakeholders and regulators; and record keeping. Licence management This includes those things that must be done to maintain an AFSL/APRA licence/authorisation such as: annual regulatory returns; ASIC IDR data reporting; notifying regulators of change of details including changes in responsibilities (such as responsibile managers); administrative matters; and changes to licence authorisations and conditions Risk management processes This includes how risks and complance obligations are managed: identification; analysis; evaluation; treatment; and monitoring Frameworks and sub-frameworks Aligned to governance however it is important to ensure that there is an overarching framework (enterprise risk management framework (ERMF)) and sub-frameworks such as obligations management, incidents , complaints, monitoring, product governance etc that align with and are connected to the ERMF. Information and data flows With the compliance pipeline infrastructure in place the test of the adequacy of the system is the information and data that flows through the infrastructure. Data and information enables risk decision-makers to self-regulate and self-report. Data and information This includes and is not limited to: incidents including regulatory/code incidents, operational risk incidents, cybersecurity incidents, people incidents and financial incidents; complaints conflicts of interest quality assurance, audits, and file reviews (underwriting, claims and broking) control testing outcomes risk profiling obligation management remediation and rectification activities training risk committee meetings business operational data attestations The cadence of compliance must be documented Documentation helps you demonstrate whether or not you are complying with the general obligations. When you document your measures, we [ASIC] expect this will include details of who is responsible, the timeframes involved and associated record keeping and reporting. (ASIC RG 104.26) In addition a documented cadence of compliance: supports training and education for staff, authorised representatives and service suppliers; provides assurance to management, […]
Names, licence numbers and websites of Australian Financial Services (AFS) licensees are increasingly being impersonated online, exposing consumers to scams. To combat this, in April 2026 ASIC decided that AFS licensee website addresses should be added to the AFS licensee professional register. These websites addresses will be published on the ASIC Professional Registers Search (PRS) from June 2026. Listing website addresses will enable consumers and businesses to check that they are dealing with genuine AFS licensee websites and combat impersonation scams where criminals copy the name and licence details of AFS licensees to create fake websites. From 4 May 2026, ASIC will begin to collect AFS licensee website addresses for all existing AFS licensees via the Regulatory Portal on a voluntary basis. If an AFS licensee provides ASIC with its website addresses (or confirms that it does not operate a website) then they must keep those details up to date. For example, an AFS licensee must inform ASIC, in relation to the websites used to carry on its financial services business, when it starts operating a website, stops using a website address it previously listed, or changes its principal website address. Key actions for AFS licensees Prepare Check that the AFS licensee’s Regulatory Portal ongoing contact person details are up to date so that it receives emails from ASIC about this change. If the AFS licensee uses more than one website address to carry on its financial services business, it should select one to nominate as the ‘principal’ website address. Provide Log into the Regulatory Portal and provide ASIC with the AFS licensee’s website addresses used to carry on its financial services business. See ASIC FAQ for guidance on which website addresses to provide and what format to provide them in. Update If an AFS licensee provides ASIC with its website addresses (or confirms that it does not operate a website) then they must update ASIC within 10 business days if their website addresses used to carry on their financial services business change or they start operating a website. Late fees will apply for changes provided after 10 business days. What will ASIC publish on the Professional Registers Search (PRS) webpage? ASIC will display an AFS licensee’s principal website address (or the fact that they do not have a website) prominently on the PRS. Any additional website addresses the AFS licensee provides will appear lower down in an expandable section. Why this matters Make it easier to spot AFS licensee impersonation websites and reduce investment scam losses. Help detect and disrupt scam websites that misuse AFS licensee details. Support other agencies and businesses to verify website addresses as part of a broader anti-scam effort. Align ASIC’s AFS professional register with approaches used by other international regulators. Disclaimer: Reproduction of statements made in this article by media outlets, whether in full or in part, is strictly prohibited without the written express consent of the author. The views, opinions, and positions expressed within this article are those solely of the author and […]









