In 2024, ASIC reviewed 11 general insurers to understand how they are supporting customers who make a complaint. ASIC’s review focused on how general insurers are complying with select enforceable obligations in Regulatory Guide 271 Internal dispute resolution (RG 271). While ASIC’s review focused on general insurers, the findings in this report are relevant for all financial firms that must comply with RG 271, this includes Underwriting Agencies, Claim Managers (TPAs), Claimant Intermediaries and Insurance Brokers. ASIC‘s key findings included: Insurers failed to identify 1 in 6 customer complaints Insurers only identified 85 systemic issues from over 1.4 million complaints Insurers had immature systems for handling complaints and reporting on complaints 1 in 8 IDR responses for rejected complaints did not meet mandatory content requirements 1 in 5 delay notifications failed to meet mandatory content requirements All insurers failed to provide delay notifications within required timeframes The General Insurance Code Governance Committee highlighted complaints handling as a main priority for 2025-26. Respondents to our consultation raised significant concerns about how insurers identify and handle complaints. We raised our own concerns about the handling of complaints in our Industry Data and Compliance Report FY24, with the number of complaints increasing by 18%. The Insurance Brokers Code Compliance Committee in their Annual Report 2024-25 found 42% of brokers reported no breaches or complaints (that) suggests continued underreporting and issues with internal monitoring… These failures represent service gaps that can expose clients to risk. Regulatory requirements AFS Licensees, as part of their general obligations (refer s912A(1)(g) and (2) Corporations Act) must have a dispute resolution system that consists of: an internal dispute resolution (IDR) procedure that complies with the enforceable paragraphs of RG 271; covers complaints against the licensee (and representatives) in connection with the provision of the financial services; and be a member of AFCA. All AFS Licensees that provide financial services to retail clients must submit an IDR report to ASIC. Firms must submit an IDR report to ASIC every six months. The reporting periods are: 1 January to 30 June, and 1 July to 31 December. A two-month submission window opens at the end of each reporting period. Submission windows are: 1 January to end of February, and, 1 July to 31 August. Financial firms that had complaints during the relevant six-month reporting period must submit an IDR report through ASIC’s Regulatory Portal that contains an IDR data file in machine-readable format, consistent with the specifications in the IDR data reporting handbook. In a recent media release, ASIC has confirmed that it will proceed with plans to publish IDR data at firm-level. The IDR dashboard will be published later this year. Code Complaint requirements Part 11 of The GI Code of Practice applies to Retail Insurance products. In addition, it is available to an uninsured person making a claim against a customer who is insured under a Retail Insurance policy (see paragraph 60). Part 11 also applies to Wholesale Insurance products where you are entitled to Financial Hardship support under […]
Compliance training in general insurance is not only a legal and Code requirement, it is also necessary to ensure that you have adequate compliance measures and for an individual’s growth and development as they progress through their insurance career. Compliance training for front-line staff, compliance teams, responsible managers and boards is one of the core compliance services that I offer to my clients. Over the years, I have identified what works. How do you know whether your compliance training has been successful? The measures of success Some of the metrics that can be adopted to measure the success of your compliance training are: a sustained increase in the number of incidents and complaints being identified and reported internally; an increase in the level of complexity of compliance questions being asked by front-line staff; a decrease in issues that were previously identified as pain points; a desire to attend future compliance training; better customer conversations (as assessed by monitoring); feedback from post-training surveys aimed at engagement and knowledge retention; and an increase in the maturity of compliance discussions within business team meetings. Importantly, some metrics that should not be used to assess the success of your compliance training are: the number of CPD/CIP points attained or annual hours of training completed. ; and the cost of training per employee. However these metrics are useful for other purposes The key requirements to conducting successful compliance In my professional experience, the following are some of the strategies that I adopt to ensure successful compliance training outcomes: Target the audience – training on financial services laws is not a one size fits all approach. Training for front-line staff differs to training for senior management, responsible managers or the board. Similarily, training must be tailored for different groups such as IDR teams, Authorised representatives, claims staff, sales & underwriters, onshore teams v offshore based teams. Understanding the lens of your audience is critical in how you poistion the same topic but to different audiences. For example RG 271 training for a mature IDR team will be different to complaints training for front-line customer service and claims teams. Fun and engaging – when an invite to a compliance training session pops in to your diary it may not necessarily generate your enthusiasm especially when accompanied by the dreaded words ‘attendance is compulsory.’ I consider that I have a training duty to ensure that the time that a person spends with me is of value and justifies them spending time away from their important day-to-day job (which continues even in their absence). Reading through the verbiage of s912A(1) Corporations Act may not be everyone’s cup of tea however, ensuring that s912A(1) is presented and discussed in a fun and engaging manner through, for example, story telling and case studies will faciliate learning as part of an overall enjoyable experience; Story telling – story telling brings compliance to life. I have 40 years experience in general insurance and in the last 8 years (as Compliance Advocacy Solutions) have […]
Misleading or deceptive regulatory obligations The Corporations Act prohibits engaging in conduct, in relation to a financial product or a financial service, that is misleading or deceptive or is likely to mislead or deceive (s1041H). Further, under the the ASIC Act, a person must not, in trade or commerce, engage in conduct in relation to financial services that is misleading or deceptive or is likely to mislead or deceive (s12DA). A breach of the misleading or deceptive conduct provisions is a Reportable Situation to ASIC unless: the breach has been rectified including consumer remediation within 60 days; and the number of impacted consumers is less than 10; and the total financial loss or damage to consumers is less than $1000. If a breach satisfies all these thresholds, it is not deemed reportable to ASIC. What is misleading or deceptive conduct? The key requirement is that the impugned conduct leads, or is likely to lead, a person into error. Advertising financial products and services (including insurance): Good practice guidance ASIC has developed good practice guidance (RG 234) to help promoters comply with their legal obligations to not make false or misleading statements or engage in misleading or deceptive conduct. The promoter will sometimes be the insurer, underwriting agency or broker but can also be a distributor or agent. ASIC’s guidance applies to advertising communicated through any medium in any form, including: magazines and newspapers radio and television; outdoor advertising, including billboards, signs at public venues, and transit advertising; the internet, including webpages, banner advertisements, video streaming (e.g. YouTube), and social networking and microblogging (e.g. LinkedIn); social media and internet discussion sites; mobile phone messages (e.g. SMS, MMS, text messages); product brochures and promotional fact sheets; direct mail (e.g. by post, facsimile or email); telemarketing activities and audio messages for telephone callers on hold; and presentations to groups of people, seminars and advertorials. Overview of Good practice guidance The following is extracted from RG 234, I have added general insurance context where relevant to do so. Returns, features, benefits and risks Advertisements for general insurance products should give a balanced message about the returns, features, benefits and risks associated with the product. Benefits should not be given undue prominence compared with risks. Warnings, disclaimers, qualifications and fine print Warnings, disclaimers and qualifications should not be inconsistent with other content in an advertisement, including any headline claims. Warnings, disclaimers and qualifications should have sufficient prominence to effectively convey key information to a reasonable member of the audience on first viewing the advertisement. Consumers should not need to go to another website (or other page of the website) or document (such as a PDS or TMD) to correct a misleading impression. Fees and costs Where a fee or cost is referred to in an advertisement, it should give a realistic impression of the overall level of fees and costs a consumer is likely to pay, including any indirect fees or costs. The premium, commission and government charges should be clearly identified. Comparisons Comparisons should […]
ASIC has released its Corporate Plan 2025-26. ASIC Chair Joe Longo Mr Longo said the plan formalised ASIC’s focus on regulatory simplification. (Media Release 25-177MR) ‘A focus on simpler and better regulation is now a concrete part of ASIC’s 2025-29 plan and will see the agency continue that focus to make it easier to interact with ASIC, to understand our expectations, for us to administer the law, and ultimately to cut red tape.’ ASIC’s Corporate Plan also outlines how the agency is maturing its approach to measuring and assessing its performance, including introducing a new suite of performance measures. ‘This will help our stakeholders better understand ASIC’s impact,’ Mr Longo said. Impacts for General Insurance I have extracted the parts of ASIC’s Corporate Plan 2025-26 that impact general insurance. 12 month work Guided by the strategic priorities set out in the plan, ASIC’s work over the next 12 months and beyond will include: driving regulatory reform to ensure the stability, fairness and transparency of our capital markets ensuring stable, secure and resilient market infrastructure pursuing continuous improvement in artificial intelligence (AI) governance and cyber security holding superannuation trustees accountable for Australians’ retirement savings, and reducing the regulatory burden on businesses. 2025-29 plan highlighting general insurance impacts ASIC are focused on addressing the most significant issues in the regulatory environment and bolstering ASIC’s capabilities to achieve this. In 2025–29, work under ASIC’s key activities will be guided by five strategic priorities. Improve consumer outcomes Strengthen market disclosure and professional conduct Support better retirement outcomes and member services Strengthen operational digital and data resilience and safety Drive integrity and transparency across markets Improve consumer outcomes – general insurance IDR – ASIC will review compliance by licensees with their obligations to report to ASIC on complaints, IDR processes, and outcomes. ASIC will continue publishing IDR data, a key part of the IDR reporting requirement. General insurance premiums – ASIC will examine the accuracy and transparency of general insurers’ disclosures about premiums and work to better understand consumer experiences. General insurance cash settlements – ASIC will review general insurers’ use of cash settlements to better understand the practices and disclosures surrounding the offers being made and to assess whether there are risks of consumer harm. Indigenous consumer outcomes – ASIC will maintain their Indigenous Outreach Program to ensure ASIC consider and understand the needs of Indigenous consumers responding to misconduct impacting Indigenous communities. ASIC will continue to build our understanding of how Indigenous communities are engaging with general insurance products and using these products to manage risks to assets of value. Strengthen market disclosure and professional conduct Sustainability-related actions – ASIC will take regulatory or enforcement action, where necessary, to protect investors and consumers. ASIC will focus on greenwashing and complaints handling by insurers following severe weather events. Auditor independence and conflicts of interest – ASIC will continue to examine auditors’ compliance with their independence and conflicts of interest obligations and publish our surveillance findings. Director and officer conflicts of interest – ASIC will […]
AFS Licensees must have processes, procedures or arrangements for ensuring that, as far as reasonably practicable, they comply with their obligations as a licensee (refer ASIC RG 104.23) and those measures should be documented (RG 104.26) APRA-regulated insurers must have mechanisms in place for monitoring and ensuring ongoing compliance with all prudential requirements (CPS 220 paragraph 35(f)). Insurers under the GI Code of Practice must have appropriate systems and processes in place to enable the Code Governance Committee to monitor compliance with the Code. (paragraph 180). Insurance brokers and their authorised representatives under the Brokers Code of Practice must have in place policies and procedures for their organisation and embed a culture that reflects the Code in the way they provide services and deal with others (paragraph 8.2(a)(iii)). If you don’t use an Obligations register to record your obligations, its likely: you have a reactive approach to compliance; compliance is seen as a series of random tasks and activities; providing evidence of compliance becomes a lengthy ‘search for a document’ process’; that compliance is not embedded within your business; there is a lack of assurance that you are complying with your obligations; and there is a heightened risk of non-compliance with unresolved incidents and breaches leading to increased operational risk, regulatory risk and regulatory scrutiny. The purpose of an Obligations register Irrespective of the source of an obligation, all obligations can be adequately managed by being recorded in an Obligations register. I adopt 2 approaches when designing an Obligations register for my clients (AFS Licensees such as brokers, underwriting agencies & TPAs; APRA regulated insurers and insurance service providers): I design the Obligations register within the Risk & Compliance Manual. This ensures that the obligation has context with a narrative explaining the source of the obligation and how it may operate with other obligations; or a stand-alone register, typically for larger organisations. Irrespective of the approach, the purpose of an Obligations Register is to identify obligations (irrespective of source) and capture those in a single register. Sources of obligations can arise under: Legislation such as Corporations Act, ASIC Act, Privacy Act, Autonomous Sanctions, Act, Competition and Consumer Act; APRA Prudential Standards such as CPS 230 (Operational risk) and CPS 234 (Information Security); ASIC Regulatory Guides such as RG 271 (Dispute resoultion) and RG 166 (Licensing financial requirements); Industry Codes – GI Code and Insurance Brokers Code; Binder Agreements; or Material Service Provider agreements. The [key] control environment Once Obligations have been captured in the register, Key controls are then assigned to each obligation, designed to ensure that each obligation is adequately managed. From this exercise, it is apparent that a Key control may adequately manage multiple obligations. This drives efficiency in business process and better customer experiences. Assigning key controls to each obligation enables a shift from a focus on obligations to a focus on the control environment. An annual control testing program ensures that key controls are tested from 2 perspectives: that they have been designed effectively (fit-for-purpose); and […]
ASIC has remade a legislative instrument that exempts Australian financial services (AFS) licensees from appointing a general insurance product distributor as their authorised representative. The ASIC Corporations (Basic Deposit and General Insurance Product Distribution) Instrument 2025/520 will extend the relief previously provided by ASIC Corporations (Basic Deposit and General Insurance Product Distribution) Instrument 2015/682 until 27 August 2030. This promotes the wide availability of general insurance products to consumers by reducing the compliance costs to providers. Criteria required to comply with the instrument In order to rely on the instrument, and provide a financial service without the need to be licensed or appointed as an Authorised Representative of a Licensee, the following criteria must be met: the principal must hold an Australian financial services licence covering the provision of the service; the service is dealing in a general insurance product; the provider is a product distributor of the licensee (but this does not include employees of the licensee); and the distributor is not an authorised representative of the licensee. Additional requirements when the general insurance products are distributed to Retail clients The licensee must have taken reasonable steps to ensure that when the distributor provides the financial service to a retail client: the distributor draws the client’s attention to the availability of a dispute resolution system of the licensee that covers complaints by the client in relation to the financial service and how that system may be accessed; and if the distributor is dealing in a general insurance product or a bundled consumer credit insurance product, the client is given information in writing about: (a) who the distributor acts for when providing the financial service; and (b) any remuneration (including commission) or other benefits that the distributor, or an associate of the distributor, may receive in respect of, or that is attributable to, the provision of the financial service. The Distributor must not provide financial product advice The ASIC instrument only applies to ‘dealing’. Dealing in a financial product within the meaning of s766C(1) Corporations Act (also refer RG 36 Part C) means: applying for or acquiring a financial product; issuing a financial product; varying a financial product; or disposing of a financial product. Arranging for a person to engage in the conduct referred to above also constitutes dealing. Arranging refers to the process by which a person negotiates for, or brings into effect, a dealing in a financial product (e.g. an issue, variation, disposal, acquisition or application). The person who is arranging may be acting for a product issuer, seller or consumer. As the instrument is restricted to ‘dealing’ only, this means that the distributor is not permitted to provide financial product advice, this restriction includes both general or personal advice. If the distributor requires authorisation to provide financial product advice, and the licensee is prepared to authorise the distributor to provide financial product advice, then the distributor must be appointed as an authorised representative of the licensee (or alternatively the distributor obtains their own AFSL). Typical general insurance situations when […]
I’m sometimes asked about the nature of work that I do or more accurately ‘what do your compliance services cover’. I thought it would be useful to share a ‘week in my life’. At the heart of my services is the expert knowledge and advice I provide on compliance, specifically across general insurance, for firms that operate within that sector, typically: insurers underwriting agencies lloyds coverholders TPAs (insurance claim managers) insurance brokers service suppliers and providers claimant intermediaries distributors Compliance is in respect of complying with financial service laws including those impacting AFS licensees, Authorised reps, Lloyds coverholders/security, APRA prudential standards, sanctions, privacy and the GI Code and Brokers Code of Practice. Including ASIC Regulatory Guides and other regulatory and Code materials. In a typical week, my work will fall within 1 of the 5 following areas. 1. AFS Licensing This is a broad category covering: new licence applications; variations to existing AFS Licenses such as to remove a key person condition, or add a new authorisation such as retail clients or claims handling; and changes to license, such as adding Responsible Managers. Licence work is very rewarding as often it signifies a key milestone in the client’s journey. It is a privilege to conduct such work for my clients. Licensing work is time-consuming and requires information to be provided and presented in a manner as required by ASIC however I enjoy the opportunity to work for the client on such an important piece of work. 2. Compliance documents and frameworks The documented evidence (as required under ASIC RG 104) is the output of the consideration of what a business is authorised to do, how it does it and developing an operating rhythm that provides: adequate compliance measures that manage the firms obligations (including under binder agreements or Auth Rep agreements); assurance to board, management, business partners (such as insurers) and regulators that obligations are being adequately managed; indicators of areas of potential concern; and data (incidents, complaints, control testing, monitoring etc) The documents I provide are all individually developed and include: tailored Risk and Compliance manual (~ 35 pages, an all-in-one document that represents the business from a compliance perspective and can also be used as a training tool); Monitoring Program (monitoring employees, Authorised Reps, Distributors and/or Material Service Providers); Obligations register covering relevant (to your business) financial service laws, Prudential Standards and Codes. This enables you to assign key controls, accountability and control testing to your obligations Registers inlcuding complaints; incidents and breaches; conflicts of interest and training; and ad hoc, tailored policies & documents. All documents are tailored to your business – what it does, how it does it and who does it. 3. Training and education Training is becoming an often requested compliance service that I provide with delivery through online, face-to-face or a combination of both. I really love engaging with your business and having fun and meaningful conversations with your people addressing compliance issues that are of concern (or confusing) to them. All training […]
ASIC has released proposed updates to its conflicts management guidance for financial services businesses. Media Release 25-150MR Regulatory Guide 181 Licensing: Managing conflicts of interest (RG 181) was last updated in August 2004. The proposed changes will align the guidance with developments in law and policy and have been informed by ASIC’s private markets surveillance work. ASIC Commissioner Kate O’Rourke said: ‘Conflicts management is a core obligation for financial services businesses and helps promote consumer protection and market credibility. ‘Conflicts of interest are more than mere moral dilemmas. They can undermine trust, integrity and performance, causing serious harm to consumers, investors and overall market confidence.’ The updated guidance sets out how Australian financial services (AFS) licensees should comply with their conflicts management obligation and explains: how the law applies, including its scope and interaction with other related obligations the types of conflicts AFS licensees need to identify and manage to meet their obligation the need to have robust and tailored arrangements that are adequate to manage conflicts, and how licensees can effectively manage conflicts. Consultation CP 385 was released 30 July 2025. Comments close 5 September 2025. Draft Regulatory Guide 181 July 2025 – AFS Licensing: Managing conflicts of interest Your obligation If you are an AFS licensee, or an AFS licence applicant, you must comply with your general licensing obligations under s912A of the Corporations Act 2001 (Corporations Act). This includes your obligation to have in place adequate arrangements for managing conflicts of interest that may arise wholly, or partially, in relation to activities undertaken by you or your representative in the provision of financial services as part of your financial services business (‘the conflicts management obligation’): see s912A(1)(aa). Scope of the obligation The conflicts management obligation is broad and is intended to apply widely—it is not limited in its application. It applies to all conflicts of interest other than those wholly outside the financial services business of you or your representative. It applies to conflicts of interest that arise within the financial services business. It also applies to conflicts that arise between something within thefinancial services business and something outside it. For example: (a) a conflict between the financial services business and corporate lending business within a conglomerate firm; or (b) a conflict between the financial services business and an employee’s personal or financial interest outside it. Complying with your obligation If ASIC have reason to believe you are not complying with your conflicts management obligation, ASIC may take administrative action. This could include suspending or cancelling your AFS licence or imposing additional licence conditions: see ss915C(1) and 914A(1). Depending on the severity, a breach of your conflicts management obligation may result in civil penalties for individuals or for corporations. What is a conflict of interest? A conflict of interest can arise where there are competing financial interests, personal interests, business or related party interests—whether direct or indirect—or competing loyalties and obligations. In some circumstances, a combination of these may give rise to a conflict. You should take […]
What is the obligation? Under s912B of the Corporations Act, AFS licensees must have arrangements for compensating retail clients for losses they suffer as a result of a breach by the licensee or its representatives of their obligations in Ch 7 of the Corporations Act. (also refer ASIC RG 126) This obligation does not apply to APRA regulated insurers (see reg 7.6.02AAA(3)) but does apply to Underwriting Agencies, Insurance Brokers, Insurance Claim Managers and Claimant Intermediaries who hold an AFS Licence. These arrangements must: satisfy the requirements in the Corporations Regulations, which are that licensees must obtain PI insurance that is adequate, considering the nature of the licensee’s business and its potential liability for compensation claims (see reg 7.6.02AAA); or be approved by ASIC as alternative arrangements For the purposes of this article, I will be focusing on PI insurance under reg 7.6.02AAA. What this means for AFS Licensees and consumers ASIC’s approach to administering the compensation requirements means that all AFS licensees that provide financial services to retail clients must have PI insurance that meets the minimum standards, unless an exemption applies. Tt is important, however, to recognise the limitations of PI insurance as a consumer protection mechanism. PI insurance is not designed to protect consumers directly and is not a guarantee that compensation will be paid. It is designed to protect the insured (i.e. the AFS licensee) against the risk of financial losses arising from poor quality services (e.g. poor advice or execution of services) and other misconduct by a financial services provider (e.g. fraud by its representatives). The insurance is not intended to cover product failure or general investment losses, claims for loss solely as a result of the failure (e.g. insolvency) of a product issuer or where a return on a financial product has not met expectations. Nor is it intended to underwrite the products of a product issuer. ASIC recognise that the PI insurance that is currently available in the market is unlikely to provide a source of funds when an AFS licensee has become insolvent before the claim was brought. Ideally, insurance policies would continue to cover the licensee after it has become insolvent or otherwise ceased business, but ASIC understands that this insurance is generally not available in the current market to the average licensee. ASIC also recognise that insurers may exclude some areas of cover in policies for risk management reasons. (see RG 126.8 – 126.11) Disclosure to retail clients AFS Licensee must disclose to retail clients the kind of compensation arrangements they have in place and whether these arrangements comply with s912B: see regs 7.7.03A and 7.7.06B. The disclosure must be presented as a statement in your Financial Services Guide (FSG) or website disclosure information and the FSG or website disclosure information of your representatives. (RG 126.19) Adequate PI Insurance What is adequate? (See Section C RG 126) The Corporations Regulations require you to hold PI insurance that is adequate, considering: (a) your liability for claims brought through the Australian Financial […]
ASIC expects that financial firms (including those providing general insurance products and services – insurers, Underwriting Agencies, TPAs, Insurance brokers and Claimant Intermediaries) to have adequate compliance measures for ensuring that, as far as reasonably practicable, licensees comply with their obligations as a licensee, including the general obligations in section 912A(1) Corporations Act. (refer RG 104 Section B) ‘compliance measures’ refer to your processes, procedures or arrangements for ensuring compliance with your AFSL obligations. This includes people, systems and policies and processes. Documenting your measures Documentation helps you demonstrate whether or not you are complying with the general obligations. When you document your measures, ASIC expects this will include details of who is responsible, the timeframes involved and associated record keeping and reporting. (RG 104.26) It follows that your documented compliance measures should be tailored to your business based upon the nature, scale and complexity’ of your business. Care needs to be taken in adopting an ‘off-the-shelf’, ‘one-size-fits-all’ compliance manual. Implementing, monitoring and reporting on your measures It is not enough just to document your measures. You also need to fully implement them. This means you need to put them into practice and integrate them into the day-to-day conduct of your business. For measures to work effectively in practice, you need people at all levels of your business, including your senior management, to understand them and be committed to their success. Integrating your measures into the culture of your business helps ensure they are effective on an ongoing basis. You also need to monitor and report on your compliance, including reporting relevant breaches to ASIC. ASIC expects that you will keep records of your monitoring and reporting, including records of reports on compliance and breach notifications. (refer RG 104.27 – RG 104.29) Reviewing your measures Regularly reviewing your measures will help to ensure they remain effective. In some cases, it may be sensible for you to consider external review. Where compliance issues have arisen (such as major breaches or repeated compliance failures), external compliance review is particularly appropriate. You need to review your measures when there are changes to your obligations, your business or the environment in which you operate. ASIC expects that you will have a process for identifying changes that may impact on the effectiveness of your measures. Your compliance measures Compliance with your obligations as a licensee is central to the protection of consumers and the promotion of market integrity. Having effective compliance measures is a way for you to ensure you comply with your obligations as a licensee, including identifying and appropriately dealing with instances of non-compliance. Compliance measures also help you demonstrate to ASIC that you can comply and are complying with your obligations. (RG 104.41) What your compliance measures need to cover ASIC considers that the broad compliance obligations (s912A(1) are both stand-alone obligations and obligations that encompass the other general obligations. For this reason, ASIC expect your measures for ensuring compliance with the broad compliance obligations will cover all of your obligations as […]