AFS Licensee’s have a general obligation to ensure that they provide their financial services efficiently, honestly and fairly (s912A(1)(a) Corporations Act). This obligation is viewed as an overarching obligation.
If you fail to comply with the other general obligations, it is unlikely that you will be complying with the ‘efficiently, honestly and fairly’ obligation. (ASIC RG 104.55) However, the ‘efficiently, honestly and fairly’ obligation is also a stand-alone obligation that operates separately from the other general obligations. (RG 104.56)
The relevant industry codes also include similar obligations:
- [we] will be honest, efficient, fair, transparent and timely in our dealings with [customers]. (GI Code of Practice paragraph 21)
- We, our staff, and representatives will act honestly and with integrity in all dealings.(Insurance Brokers Code of Practice Section 3.0(b))
It is clear that the obligation requires ethical behaviour
It is not necessary to establish dishonesty in the criminal sense. The word ‘honestly’ may comprehend conduct which is not criminal but which is morally wrong in the commercial sense. The word ‘honestly’ when used in conjunction with the word ‘fairly’ tends to give a flavour of a person who not only is not dishonest, but also a person who is ethically sound
Foster J in ASIC v Camelot Derivatives Pty Ltd (in liq) (2012) 88 ACSR 206 [201] FCA 414 at [69]
The governance of AI
The financial service laws and industry Codes are technology neutral. That is, the laws and policies focus on desired outcomes or functions rather than prescribing the use of specific technologies.
It is therefore irrelevant whether a firm uses humans, technology or a combination of both to perform financial services tasks and services. The obligation ‘efficiently, honestly and fairly’, applies.
This was emphasised in APRA’s letter to regulated-entities 30 April 2026
APRA expects Boards, at a minimum, to maintain sufficient understanding and literacy with respect to AI in order to set strategic direction and provide effective challenge and oversight
This obligation, at an operational level, extends to executives, management, responsible managers, accountable persons and business leaders. That is, such persons must have sufficient skills and knowledge of AI to be able to discharge their respective duties.
ASIC emphasised this point in their open letter to industry 8 May 2026
‘Entities need to have robust incident response plans. Whether an entity faces a basic phishing attempt or a more sophisticated cyber attack, the underlying cyber risk management principles of govern, protect, detect, respond remain the same. ‘Appropriate cyber risk management starts at the leadership of licensees and participants. Boards and executives must ensure systems are tested, weaknesses are addressed early and that action is taken before threats can be exploited.
AI Ethics Principles
The Department of Industry, Science and Resources (Australian Government) updated Australia’s AI Ethics Principles on 2 December 2025.
The principles aimed to help:
- achieve safer, more reliable and fairer outcomes for all Australians
- reduce the risk of negative impact on those affected by AI applications
- businesses and governments to practice the highest ethical standards when designing, developing and implementing AI.
AI Ethics Principles at a glance
- Human, societal and environmental wellbeing: AI systems should benefit individuals, society and the environment.
- Human-centred values: AI systems should respect human rights, diversity, and the autonomy of individuals.
- Fairness: AI systems should be inclusive and accessible, and should not involve or result in unfair discrimination against individuals, communities or groups.
- Privacy protection and security: AI systems should respect and uphold privacy rights and data protection, and ensure the security of data.
- Reliability and safety: AI systems should reliably operate in accordance with their intended purpose.
- Transparency and explainability: There should be transparency and responsible disclosure so people can understand when they are being significantly impacted by AI, and can find out when an AI system is engaging with them.
- Contestability: When an AI system significantly impacts a person, community, group or environment, there should be a timely process to allow people to challenge the use or outcomes of the AI system.
- Accountability: People responsible for the different phases of the AI system lifecycle should be identifiable and accountable for the outcomes of the AI systems, and human oversight of AI systems should be enabled.
AI Governance
The Board (or management for smaller firms) should update its Risk Appetite Statement (RAS) to incorporate the ethical use of AI and approve an AI Policy setting the guardrails for business decision-making.
As part of their governance arrangements, all general insurance firms using, or likely to use, AI to provide general insurance service or products should constitute a board approved (through a Charter) AI Committee.
The AI Committee is a management committee and comprises relevant executives who approve the ethical use of AI across the business based on the RAS and Policy, adopting the AI Ethics Principles and the matters raised in APRA and ASIC’s AI letters.
In addition to the matters referenced in the APRA and ASIC’s AI letters, the following risk and compliance measures should be implemented by general insurance firms for the use of AI:
- access to specialist skill-sets within the firms IT function or outsourcing such skill-sets (this aligns to the general obligation to have adequate human and technology resources to provide the financial services s912A(1)(d) Corporations Act);
- training for staff to understand how AI works and the firm’s approach to the use of AI;
- An IT plan (or standard operating procedures) that sit under the AI Policy (including matters referenced in APRA Prudential Standards CPS 230 and CPS 234)
- key controls (approved and periodically tested by relevant AI specialists);
- incident and breach management processes;
- updated BCP and DRP including testing of severe but plausible scenarios involving a cyber security incident due to a failure of AI;
- updating risk and compliance frameworks;
- monitoring of service suppliers and their use of AI;
- the firm’s Monitoring Program continues to oversight and monitor the use of AI when ‘live’ with reporting through to the AI Committee.
Disclaimer: Reproduction of statements made in this article by media outlets, whether in full or in part, is strictly prohibited without the written express consent of the author. The views, opinions, and positions expressed within this article are those solely of the author and Compliance Advocacy Solutions Pty Ltd and not the views of other individuals, companies or organisations they may be affiliated with. The author and Compliance Advocacy Solutions Pty Ltd make no representations as to accuracy, completeness, currency, suitability, or validity of any information in this article and will not be liable for any errors or omissions or any loss or damage arising from its use or reliance. This article is intended for educational and informational purposes only and should not be relied upon as professional legal advice.