An AFS licensee is responsible for the conduct of every authorised representative it appoints, but most broker networks oversee their ARs by sampling a handful of files each year. With breach numbers rising, the Code Compliance Committee questioning zero-breach reports and a new Insurance Brokers Code of Practice due in 2027, sampling no longer shows a licensee what is happening across its network. AR oversight works when files are reviewed at scale, results are visible by representative, and remediation is ranked by risk.
Key takeaways
- The IBCCC recorded 5,417 Code breaches affecting 14,842 clients in its 2025 data (Insurance Business).
- “Accountability cannot stop at the point where the broker hands work to a representative” — IBCCC Chair Oscar Shub (Insurance Business).
- Five of six brokers that reported zero breaches in 2024 reported breaches in 2025: nothing to report often means nothing detected.
- The revised Insurance Brokers Code of Practice is targeted for 1 January 2027, with record-keeping moving from recommended practice to a Code requirement.
What is a licensee responsible for when it appoints ARs?
When a broker appoints an authorised representative, it lends that representative its licence. Under the Corporations Act, the licensee is responsible for the representative’s conduct as if it were its own (section 917A), and must take reasonable steps to ensure its representatives comply with financial services laws (section 912A).
In practice, that means the licensee answers for every file an AR touches: the advice given, the disclosures made, the renewals handled, the complaints received and the breaches that should have been reported. The AR runs the client relationship. The licensee carries the accountability.
For a network with dozens or hundreds of ARs, spread across offices the Responsible Manager may never visit, that is a supervision problem of real scale.
What are the regulators and the industry saying?
Breaches are rising, and they cluster in routine work. The Insurance Brokers Code Compliance Committee (IBCCC) recorded 5,417 Code breaches in its 2025 data, affecting 14,842 clients. Around half related to renewals, including 2,077 failures to contact clients 14 days before expiry. Terms of engagement disclosure breaches rose 65% on the year (Insurance Business).
Zero is a warning sign, not a result. In the 2024 data, 42% of brokers reported no breaches or complaints at all. “Reporting zero breaches or complaints may indicate a lack of internal scrutiny, rather than flawless services,” said IBCCC Chair Oscar Shub (Medianet). The following year, five of six brokers that had declared zero reported breaches. “Good compliance is not shown by simply reporting nothing,” Shub said in June 2026, calling for systems that “actively identify issues, including minor process failures.”
Representatives are squarely in view. In June 2026 the IBCCC found that all seven strata brokers it examined failed to consistently meet Code safeguards, and referred two to ASIC. Representative agreements lacked explicit requirements for Code compliance and breach reporting. “Accountability cannot stop at the point where the broker hands work to a representative,” Shub said (Insurance Business).
The standard is rising. The revised Insurance Brokers Code of Practice is targeted for 1 January 2027, according to NIBA. It extends pre-renewal contact to a 28-day window and moves record-keeping from recommended practice to a Code requirement (Insurance Business). Meanwhile, consumer groups are pressing government to make the Code mandatory (Insurance Business).
Enforcement is intensifying. AFCA complaints about general insurance brokers rose to 788 in 2024–25, from 447 the year before, and ASIC’s civil penalties in 2025–26 were roughly eight times the prior year’s (Insurance Business).
Why does file sampling fall short for AR networks?
Most licensees supervise their ARs the same way: a compliance officer or Responsible Manager reviews a few files per representative each year, often against a spreadsheet checklist, and forms a view about the rest.
That approach had logic when reviewing a file meant a person reading it end to end. But it leaves three gaps a growing network can’t close:
- You can’t see who is slipping. A sample of five files per AR says little about the other few hundred, and even less about which ARs have gone quiet.
- Patterns stay hidden. The same renewal miss or disclosure gap across ten representatives looks like ten isolated findings, not one systemic issue that may need reporting.
- The evidence is thin. When an insurer, the IBCCC or ASIC asks how you supervise your network, a sampling spreadsheet shows effort, not coverage.
The gap has always been resourcing, not judgement. Responsible Managers know what good looks like; they simply cannot read enough files to see it across the network.
What does good authorised representative oversight look like?
Good AR oversight moves a licensee from sampling to seeing. It comes down to three qualities: straightforward, easy and automated.
Straightforward. One view per representative. Audit results, complaints and incidents sit against the AR they relate to, so the Responsible Manager can see who is compliant, who is slipping and where the same issue repeats across the network.
Easy. Nothing to roll out to the network. File review works on the files your representatives already keep, measured against the standard you set: the Insurance Brokers Code of Practice, your licence obligations and the terms of your own AR agreements. Findings come back as a ranked queue, by representative and by exposure, so judgement goes where it matters.
Automated. AI file audits do the reading. Every step passes or fails with reasoning, and every finding cites the evidence in the file, the obligation it relates to and the representative responsible. The point is not to audit every file at any cost. It is to audit more of the right files, more cheaply, with a structured record behind each one.
How does Curium make AR oversight simple?
Curium is compliance, risk and claims software built for insurance. For licensees and broker networks, that means:
- AI file audits across the network. Files assessed against the Insurance Brokers Code of Practice, your licence obligations and your AR agreements, with every finding citing its evidence.
- A scorecard per representative. Results by AR, showing which obligations fail most often and where.
- Complaints and incidents by AR. Recorded against the representative they relate to, alongside that representative’s audit results.
- Remediation, ranked. A queue by representative and by exposure. Judgement stays with your Responsible Managers; the reading is done.
- Supervision evidence. A record you can show your board, your insurers and the regulator.
In our first client deployment, the audit engine cut reviewer time by 78% for the same audit; results depend on file type and current review depth.
We’ve made AR oversight straightforward, easy and automated. From sampling to seeing.
Book a conversation to see how it works for your network.
Frequently asked questions
Is a licensee responsible for its authorised representatives? Yes. Under section 917A of the Corporations Act, an AFS licensee is responsible for the conduct of its authorised representatives when they provide financial services on its behalf. Under section 912A, it must also take reasonable steps to ensure they comply with financial services laws.
What is an authorised representative? An authorised representative (AR) is a person or business authorised by an AFS licensee to provide financial services under that licensee’s licence, rather than holding a licence of their own. Many broking networks operate this way.
How often should a licensee review its ARs’ files? There is no fixed number in the law; the test is whether the licensee takes reasonable steps to supervise. In practice, supervision should be risk-based, with more review for representatives, products or processes showing more issues.
What does the IBCCC say about reporting zero breaches? The IBCCC has warned that reporting zero breaches or complaints may indicate a lack of internal scrutiny rather than flawless service, and expects brokers to have systems that actively identify issues, including minor process failures.
When does the new Insurance Brokers Code of Practice start? NIBA has targeted 1 January 2027 for the revised Code. Changes include a 28-day pre-renewal contact window and record-keeping obligations becoming Code requirements.
Is the Insurance Brokers Code the same as the General Insurance Code of Practice? No. The Insurance Brokers Code of Practice is NIBA’s code for brokers, monitored by the IBCCC. The General Insurance Code of Practice is the Insurance Council of Australia’s code for insurers. They are separate codes with separate compliance committees.
Sources
- Insurance Business — IBCCC puts renewal failures at centre of 2025 breach data
- Medianet — Rise in breach reports signals progress but more than 40% of brokers still reported zero
- Insurance Business — Damning strata investigation: all seven broker firms breaching the Code
- Insurance Business — Final countdown for Insurance Brokers Code of Practice
- Insurance Business — Broker code dispute puts mandatory regulation back in focus
-
Insurance Business — Premium diversion, licensing failures escalated in ASIC misconduct data
Author:
Tetiana George, CEO of Curium, Co-Chair of Insurtech Australia and member of ASIC Digital Finance Advisory Committee. LinkedIn Profile.