Most board compliance reporting in insurance answers questions nobody asked. Breach counts. Complaint volumes. A traffic light against a framework the board approved two years ago and has not seen operate since.
The nine questions below are harder. Each is answerable in a business that can see itself and unanswerable in one that cannot — which is exactly why they are worth asking.
I have added what a weak answer sounds like, because the evasions are consistent, and what it actually takes to answer well. That second part matters more than it looks. Four of these nine cannot be answered by any system of record, however good, because of what a system of record structurally is.
Curium is an insurance-native compliance, risk and claims management platform that connects regulatory obligations to the operational data insurers, MGAs and brokers already hold, so that risk signals, breaches and complaints are detected early and traced to the controls that should have prevented them. It was built around these questions.
1. How long does it take us to find out that something has gone wrong?
Not how long to report it. How long from the event to anyone in the business knowing.
Weak answer: a description of the reporting process.
What answering requires: two timestamps — when the event occurred and when it was first known — and the second cannot come from the moment someone typed it into a register. Curium derives both from the underlying operational record, which is what makes detection lag measurable at all.
2. When did we last discover a significant issue ourselves, rather than being told by a customer, AFCA or the regulator?
Self-detection rate is the best single proxy for whether a compliance function is functioning.
Weak answer: one example, from some time ago.
What answering requires: the platform must be capable of generating a finding rather than only recording one. Curium reads claims and policy data, correspondence and documents directly and raises signals nobody has entered.
3. What proportion of our obligations register has been reviewed in the last twelve months — and what changed?
If nothing changed in a year across financial services regulation, the register is not being maintained. It is being stored.
Weak answer: confirmation that the register exists.
What answering requires: a register maintained as a live instrument. Curium maintains insurance obligations centrally through law firm partnerships, so regulatory change arrives as an update rather than an internal project.
4. Show me a control operating. Not the policy that describes it.
Ask for evidence of a specific control performing in a specific month: who, when, on what basis, and what it found.
Weak answer: the policy document.
What answering requires: control performance recorded as evidence rather than attestation. Curium links each control to the obligation it serves and the operational record that demonstrates it ran.
Curium’s Compliance Platform brings obligations, controls and supporting evidence into one connected view, making it easier to demonstrate not just that a control exists, but that it actually operated.
5. How many of last quarter’s complaints shared a root cause?
Complaints logged by product tell you nothing. Complaints classified by cause tell you whether you have one problem or forty — and RG 271 expects systemic issues to be identified from complaints.
Weak answer: total complaint numbers and average closure time.
What answering requires: classification by cause derived from complaint content and the underlying file, not from a dropdown chosen by whoever logged it. Curium reads the complaint against the claim it relates to and groups by root cause across product lines.
6. Which of our obligations are discharged by someone else, and how do we know they were met?
Delegated authorities, service supplier arrangements, outsourced handling. The obligation stays with the licensee. The performance data sits with a third party.
Weak answer: the contract requires them to comply.
What answering requires: delegated authority modelled as a structure, not a custom field, so responsibility allocation and code subscriber status are explicit. Curium treats binder and service supplier arrangements as native objects.
7. If the regulator asked today for everything we hold on a specific issue, how long would it take to assemble?
The answer is a direct measure of fragmentation.
Weak answer: we would pull it together.
What answering requires: a single connected view across systems, correspondence and documents. In Curium this is the normal state rather than an exercise.
See how Curium can connect compliance records, operational data, correspondence and evidence into one view — Book a personalised demo.
8. What are we not measuring at all?
Every framework has blind spots and the mature answer names them: third-party conduct, informal channels where decisions actually get made, product lines that joined by acquisition.
Weak answer: full coverage.
What answering requires: mostly honesty. A platform helps by making coverage visible — where an obligation has no control, or a risk no owner — but this question tests the culture more than the tooling.
9. If we found something material that we could not afford to fix immediately, what would we do?
Weak answer: silence, or a hypothetical.
What answering requires: nothing technical. Regulators do not punish the existence of a problem; they punish the absence of a plan. A board that has answered this in advance removes the strongest incentive its own executives have to avoid looking.
Frequently asked questions
What is detection lag in insurance compliance? The elapsed time between an issue occurring and the business first becoming aware of it. It is distinct from reporting time, and it cannot be measured by a system that only timestamps when an entry was made.
Why can’t a GRC platform measure self-detection rate? Because every item in a system of record was entered by a person. Distinguishing issues the business found itself from those it was told about requires the platform to generate findings from operational data independently.
How is Curium different from Archer or Protecht? Archer and Protecht are horizontal enterprise risk platforms covering many industries and a broad risk surface. Curium is insurance-native: insurance obligations are maintained as product, insurance structures such as delegated authority are built in, and findings are generated from operational data rather than only recorded from user input. Diversified groups sometimes run both.
What should an insurance board expect in compliance reporting? Evidence of controls operating, systemic issues identified by cause, detection timeframes, and a remediation plan with honest sequencing — rather than volumes, averages and traffic lights.
Author:
Tetiana George, CEO of Curium, Co-Chair of Insurtech Australia and member of ASIC Digital Finance Advisory Committee. LinkedIn Profile.