I’m often asked by insurance brokers, who are authorised representatives of a licensee, whether they should hold for their own AFS licence.

I talk them through the mechanics of obtaining an AFS Licence, the cost (plus ongoing costs) of applying for a licence and how I can support them with their AFSL application.

However, such a question requires an initial analysis of the risks, costs and benefits of holding your own AFS Licence compared to being an authorised representative of another licensee.

With the increased regulatory scrutiny by ASIC over AR networks there is a strong case for obtaining your own licence. This scrutiny will, most likely, continue to increase.

What is contagion risk?

Contagion risk, in context of an AR network, is the likelihood that an adverse event, such as a cybersecurity failure or misconduct of one or more authorised representatives, impacts the entire AR network for that Licensee. This impact includes the impact to all other authorised representatives within the network and the licensee.

A recent Federal court case highlighted contagion risk: Australian Securities and Investments Commission v RI Advice Group Pty Ltd [2022] FCA 496 (see ASIC media release (22-104MR)).

RI Advice

The Federal Court found AFS licensee, RI Advice, breached its license obligations to act efficiently and fairly when it failed to have adequate risk management systems to manage its cybersecurity risks.

The finding comes after a significant number of cyber incidents occurred at authorised representatives of RI Advice between June 2014 and May 2020. In one of the incidents, an unknown malicious agent obtained, through a brute force attack, unauthorised access to an authorised representative’s file server from December 2017 to April 2018 before being detected, resulting in the potential compromise of confidential and sensitive personal information of several thousand clients and other persons.

In addition to the declaration of contravention, the Court ordered RI Advice to engage a cybersecurity expert to identify and implement what, if any, further measures are necessary to adequately manage cybersecurity risks across RI Advice’s authorised representative network.

RI Advice was ordered to pay $750,000 towards ASIC’s costs.

Increased regulatory scrutiny leading to enhanced monitoring and supervision

A number of insurance broker Licensee’s are having to report ‘reportable situations’ to ASIC, due to the conduct of authorised representatives.

The reporting of reportable situations to ASIC, profile cases such as RI Advice, existing regulatory obligations and responsibility for the conduct of authorised representatives under Part 8.1 of the Insurance Brokers Code of Practice, will continue the enhanced regulatory focus of ASIC in respect of the operation and management of AR networks.

Licensees are responding through rigourous due diligence processes as part of the AR appointment process and robust AR Monitoring Programs.

I have worked with a number of licensed Insurance Brokers to set-up robust AR Monitoring Programs and due diligence.

Licenced or AR? Costs and benefits – a compliance perspective

From a risk and compliance persepective there is a benefit for a new brokerage to be an authorised representative of a licensee to enable the AR to build up their risk management systems and compliance competence as they focus on establishing their broker business. However, over time, this benefit may be outweighed by contagion risk.

AR’s clearly obtain benefits from the compliance and training services provided by their licensee however, similar services can be provided by cluster groups and independent third parties (such as ANZIIF and my business Compliance Advocacy Services). It is noted that there are other non-compliance benefits for ARs that are outside the scope of this article.

The costs of managing an AFSL are comparable to the ongoing fees payable by ARs.

If you are an authorised representative and would like to have a conversation about obtaining your own AFS Licence. Contact me Paul Muir, to discuss.

How should AR’s manage contagion risk?

An authorised representative should ensure that their AR agreement enables them to adequately manage the impact of AR network contagion risk to their business.

Naturally, the AR should have their own robust compliance measures to adequately manage their business including the independent compliance obligations of an AR in addition to the requirements of being an AR of a licensee.

To manage the AR network contagion risk, an AR should consider the following actions:

  • understand the effectiveness and robustness of the licensee’s due diligence process to appoint new ARs;
  • obtain a copy of the documented compliance measures of the licensee & understand how those measures adequately manage the Licensee’s risk;
  • obtain a copy of the documented AR Monitoring Program of the licensee & understand how the Program adequately manages contagion risk;
  • obtain the Licensee’s risk profile and understand how the licensees key controls manage key risks such as technology risk, compliance risk, financial risk and operational risk;
  • understand the Licensee’s strategic growth of its AR network and how its compliance measures and resourcing will remain adequate to manage such growth;
  • obtain periodic reporting from the Licensee covering the AR networks indentification and reporting of incidents, complaints, breaches, coflicts of interests, training, and control breakdowns. What is the data telling you? What is the data not telling you? Is there an under-reporting issue?
  • have oversight of all reportable situations to ASIC, both in respect of the licensee and other ARs in the network;
  • be a member of the Licensee’s Risk & Compliance Committee or, attend as a guest, or obtain a copy of the agenda and minutes; and
  • ensure that you are part of the AR community for that network and have a forum to discuss contagion risk.

Disclaimer: Reproduction of statements made in this article by media outlets, whether in full or in part, is strictly prohibited without the written express consent of the author. The views, opinions, and positions expressed within this article are those solely of the author and Compliance Advocacy Solutions Pty Ltd and not the views of other individuals, companies or organisations they may be affiliated with. The author and Compliance Advocacy Solutions Pty Ltd make no representations as to accuracy, completeness, currency, suitability, or validity of any information in this article and will not be liable for any errors or omissions or any loss or damage arising from its use or reliance. This article is intended for educational and informational purposes only and should not be relied upon as professional legal advice.