Compliance by Design
Most agencies prepare for an audit. A better position is to run a business whose ordinary records are already the evidence.
Before an audit, a coverholder typically spends several weeks pulling files and reconciling spreadsheets. Someone rebuilds the referral log from email, and someone asks why the premium on one policy differs from the bordereau. This work is expensive. Its purpose is to reconstruct what the business did months earlier so that someone else can check it.
This essay argues that most of that reconstruction can be avoided. It sets out what that requires and what it cannot achieve.
What the auditor is asking
The LMA Coverholder Audit Scope, now in its V3.1 form, covers eight areas: underwriting, contract documentation, claims, accounting, reporting, compliance, IT and information security, and customer outcomes. Most risk items in it ask one of two questions.
The first is whether something happened that should not have. Was a risk bound by someone without authority, taxed incorrectly, discounted without a reason, or written after the premium income limit was reached? The second is whether the business can prove what did happen: who bound the risk, on which rates, with which wording, and when the documents were issued.
The first question concerns prevention and the second concerns evidence. Few items ask about intention. Policies and frameworks matter, but the audit tests whether transactions complied with them.
If the controls are applied when the transaction happens, the first question is settled, because a bind outside authority cannot be completed. If the transaction is recorded in a form that cannot be edited without trace, the second question is settled too. The auditor is then left to confirm the records rather than reconstruct them.
Controls at bind compared with controls at month end
Most agencies find breaches after the event. A month-end review identifies a discount with no recorded reason, a certificate issued late, or a risk located outside the binder’s territory. By then the insured has the policy and the capacity provider carries the exposure.
A control applied at bind takes seconds:
- The system checks the underwriter’s authority before the bind can proceed, and checks the premium income limit before the risk is written.
- A potential sanctions match prevents the bind until a second person reviews it and records the decision.
- A discount beyond the underwriter’s authority requires a manager’s approval, with the reason recorded.
Perspective 05 argued that a capacity provider prices a line according to what it costs to trust the agency. Audit findings are the most visible evidence a capacity provider has of control failures. Each control that moves from after-the-event review to the point of bind removes one type of finding permanently.
One record for the policy, the bordereau and the audit
A frequent audit finding is a mismatch: the schedule, the rating record and the bordereau show different figures. The usual cause is re-keying. The same facts were entered in three places by different people, and one entry was wrong.
Perspective 03 described the alternative, which is to enter the facts once and generate every output from them. When the policy documents, the bordereau and the audit pack are all produced from one bound record, they match. When that record can only be added to, with corrections recorded as new entries rather than changes to old ones, anyone can verify that the document the insured holds is the one that was issued. The file review becomes a report run against the record.
Retail and wholesale clients
Retail classification is a good test of this approach, because software often handles it incorrectly.
Under section 761G of the Corporations Act and its regulations, only certain kinds of general insurance can be retail products. They are motor vehicle, home building, home contents, sickness and accident, consumer credit, travel, personal and domestic property, and (by regulation) medical indemnity. Insurance outside that list is wholesale, whoever buys it. Insurance inside the list is retail when the insured is an individual or a small business. A small business generally has fewer than 20 employees, or fewer than 100 for a manufacturer. Retail status brings the PDS regime and internal and external dispute resolution; the General Insurance Code of Practice adds financial hardship obligations for insurers that subscribe to it.
A common approach assigns each product a class code and looks up the classification in a table. This gives the wrong answer in the cases that matter. The same personal accident code is wholesale when sold to a corporate scheme and retail when sold to a sole trader. The code describes the risk, while the Act asks about the buyer.
A correct design separates the two questions:
- At product definition, each section records whether it can never be retail, can sometimes be retail, or is always retail.
- At bind, a fixed rule tests the insured for the sections where the answer depends on the buyer. The record keeps the result, the inputs and the version of the rule used.
- For packages, a package containing one retail section is treated as retail.
- Where information is missing, the risk is referred to a person rather than classified by default.
Many obligations depend on the transaction rather than the product. Retail status, target-market fit, and the statutory renewal notice due at least 14 days before expiry on the policies it covers are examples. These obligations can only be properly evidenced at the time they arise.
The platform provider is part of the audit
V3.1 asks each coverholder how it manages its outsource providers, and it now refers to artificial intelligence explicitly. An agency’s underwriting system is usually its most significant outsourced service, so the auditor’s questions apply to the system provider as well.
An agency can ask its provider three questions:
- Resilience: are the commitments written to the standard that APRA-regulated insurers apply to their own providers under CPS 230, in force since July 2025? Are incident notification times short enough for the agency to meet its own notification obligations?
- Exit: if the contract ends, does the agency get its complete data back, in a usable format, without a fee?
- AI: does any model decide cover or price, or does it only read documents and draft text while fixed rules make the decisions?
Our field note on why we never let the AI set the price gives our answer to the third question.
What software cannot do
A platform can prevent non-compliant transactions and keep evidence of compliant ones. It cannot provide governance, culture, conflict management, clear wordings or appropriate treatment of vulnerable customers. The licensee must demonstrate those, and a vendor that claims otherwise is overstating what software does.
The same limit applies to decisions the system supports. A classification engine proposes a result and shows how it reached it. The licensee confirms the result and remains responsible for it. The platform records; the licensee confirms.
This changes how compliance professionals spend their time. When the evidence is produced as part of normal work, less time goes on rebuilding files before an audit. More time can go on setting the rules the transactions must follow: reviewing a product’s authority limits, target market and classification before it goes live. That is where a compliance professional’s expertise has the most effect.
The evidence test
Three questions for any agency, whatever system it uses.
For any policy, can you show who bound it, under which authority, on which rate version, and why it was treated as retail or wholesale, without asking anyone? Could a bind outside authority or over the premium income limit happen today, or would you only find it afterwards? If your system provider failed tomorrow, what does your contract say you get back, and how quickly?
The conclusion
An agency that can answer yes to all three questions will find its audit is a matter of confirming records. An agency that cannot will repeat the reconstruction every year. It pays for that in staff time and in the terms capacity providers offer, because, as Perspective 07 argued, buyers and capacity providers both discount for uncertainty.
Cuttleflow Systems · Perspective 19 · 33°53′S · 151°16′E · Sydney