9 Sept 2026 Tetiana George 7 min read

Risk and Compliance at Speed: Meeting Regulator Expectations Without More People

Curium hero graphic for “Risk and Compliance at Speed,” featuring bold neon icons for speed, compliance, risk and monitoring against a vibrant pink, purple and blue background.

How insurers can meet rising regulator expectations with stronger obligations, controls and monitoring — without adding more compliance headcount.

On 25 August, Curium hosted a webinar on one of the more persistent problems in insurance risk and compliance: regulators now expect firms to prove a framework works, not simply describe the framework in place. The bigger issue now is that most compliance teams are being asked to do that without any extra headcount. Tetiana George, our co-founder and CEO, Louise Andrews, our Head of Partnerships and Growth, and I walked through what that looks like in practice.

For years, the regulator’s question was fairly simple: do you have a policy for this, and is there a document describing your framework? That question has shifted. What regulators want now is evidence that the framework operates as described, in practice, on an ongoing basis.

The shift is visible across almost every area of regulatory change insurers, MGAs and brokers are currently managing. CPS 230, APRA’s operational risk standard, continues to be one of the more demanding changes for insurers and underwriting agencies. The Financial Accountability Regime is doing something similar, mainly for insurers. Privacy Act reform will apply to every business, regardless of licence type, with the deadline to update privacy policies and disclosures falling before the end of this year. Climate reporting obligations are being phased in, starting with the largest entities and extending to smaller ones over the coming years. ASIC’s updated advertising guidance, RG 234, was released in July (we covered that update in detail separately). The law on conflict of interest hasn’t changed, but the regulatory guidance has: firms are now expected not just to identify a conflict, but to actively manage it and provide evidence that they are doing so.

None of this represents a wholesale rewrite of the rules. It represents regulators asking harder questions of the same frameworks many firms already have in place, which is arguably a bigger practical problem than a new law would be.

Where obligations registers break down

An obligations register is the foundation everything else sits on. Every risk assessment a business makes is only as reliable as the obligation underneath it, and where that register has gaps or overlaps, the assessment is compromised before any judgement has even been exercised.

Gaps are obligations nobody owns: not assessed, not controlled, not visible, until something goes wrong and someone has to go looking for where it should have appeared on the list. One example from a broker client illustrates the risk clearly. Renewal reminders were worded to the effect of, “if we don’t hear from you, we’ll bind this on your behalf.” The intent was to protect customers from a gap in cover. The effect, unrecognised at the time, was a breach.

Overlaps cause the opposite problem, and they are just as common. The same obligation can sit in three different places in a business, with three different owners and three different controls, all addressing the one issue. That produces three potentially different answers to what is fundamentally a single question, with no reliable way of knowing which answer would be presented to a regulator if one came asking.

Curium’s obligations module is built to close both gaps. Every obligation is pre-loaded per jurisdiction, covering the relevant acts, industry codes and supervisory requirements, and maintained directly with our law firm partners so clients review, approve and operationalise rather than source and interpret the law themselves. Each obligation links back to the source legislation with its exact wording, a plain-English explanation, and real examples of what a breach looks like. When the law changes, the register updates and clients are told exactly what has changed and what it means for them; 22 new obligations were added last year alone, each supported by a dedicated webinar or drop-in session.

Controls: existence is not evidence

The second recurring pattern concerns controls. Most registers record two things: that a control exists, and that a named person is accountable for it. Both are necessary, and neither tells a regulator whether the control was actually performed.

If a regulator asks, the questions get specific quickly. Who owns this control? How often should it run? When did it last run? Where is the evidence it was tested? In practice, control ownership is often concentrated on one or two people, not through any deliberate decision, but because that is how responsibility has drifted as a business has grown. A static line in a register cannot surface that. An actual run history can, showing scheduled activity against what actually happened, and where ownership needs to be redistributed before it becomes a problem rather than after.

This is the gap Curium’s controls register and risk management module are built to close, alongside a Risk Appetite Statement and register with a summary dashboard and linked controls, so risk and control ownership are visible in one place rather than reconstructed after the fact.

What the data says about how breaches are actually found

ASIC’s own findings back up why this matters. In a December 2024 review of complaints handling across eleven general insurers, covering more than 1.4 million complaints, ASIC found insurers were failing to identify one in six customer complaints. Many of those complaints had been handled in some form; what was missing was the record, meaning there is no auditable trail if a regulator, or a customer, asks for one later.

Separately, ASIC extended the reportable situations investigation window from 30 to 60 days, effective 27 June 2025, in response to industry feedback that the original timeframe was often unworkable in practice. It’s a useful signal of how difficult firms have found it to properly investigate and document issues within tight windows, even before deciding whether something needs to be reported at all.

Curium’s compliance monitoring module is designed for exactly this failure mode. It scans emails and case data for incidents, breaches and complaints as they occur, pinpoints the specific obligation at risk, and suggests next steps, rather than waiting for a person to notice and manually raise it. Complaints and incidents logged this way generate regulator-ready reports in a few clicks and cannot be deleted once recorded, so the audit trail holds up regardless of what happens afterwards.

The tools built to close the gap

Curium’s risk and compliance platform brings obligations, complaints, incidents and breaches, risk appetite, controls, conflict of interest, staff training and material service providers into a single system, built specifically for insurance rather than adapted from generic governance, risk and compliance software. It is designed to sit alongside tools like Protecht, Archer or ServiceNow, or to replace them, depending on what a business already has in place.

The conflict of interest module is a direct response to the regulatory shift described earlier: built to capture, assess and monitor conflicts on an ongoing basis, rather than as a one-off declaration. Embedded AI works across the platform to guide users as they enter structured data, and an AI-powered knowledge base supports staff training and certification alongside the platform’s regulatory content.

A separate File Audit Tool extends the same approach to file-level reviews. Rather than the 5 to 10% sample a manual audit programme typically manages, it audits every file against a business’s process, citing the rule checked and the exact evidence behind each decision, and flags potential incidents, breaches and complaints that were never logged as it goes, ready to push into Curium in one click. A broker audit that would ordinarily take a person two to three hours per file, working through advice classification, needs analysis, statement of advice, best interest duty and warnings in turn, runs in minutes instead, with a person reviewing the findings and deciding what happens next rather than manually sourcing the evidence.

This isn’t a replacement for judgement

None of the above replaces a person’s judgement. It replaces the searching, the chasing, the manual reconciliation, and the weeks typically spent assembling evidence for a single request. What remains for the person is the part that was always theirs: deciding what a finding means, and what to do about it.

The question worth asking of any risk or compliance function right now is how much of its time goes on proving that things happened, compared with actually making sure they happen well.

If you would like to see how the obligations register, compliance monitoring, or File Audit Tool would work against your own obligations, book a demo or get in touch directly.

Author:
Laura Thomas
, Head of Operations and Customer Success. LinkedIn Profile.

Ready to turn claims and compliance into your competitive advantage?