Australian insurers sit at the intersection of prudential, conduct and privacy regulation, and AI now touches underwriting, pricing, claims triage and fraud detection. APRA prudential standards, ASIC conduct obligations, the Privacy Act and anti-discrimination law all bear on how models use personal, health and genetic data to decide who is covered and on what terms. This matrix maps the duties that govern automated and AI-assisted decisions across the insurance value chain.
9 obligations across the insurance regulators. Map every AI system you run against each.
Insurers are APP entities handling personal, health and genetic information across underwriting, claims and fraud models. The 13 Australian Privacy Principles in Schedule 1 govern collection, use, disclosure, quality and security of that data. APP 1 requires open and transparent handling, APP 6 limits use to the primary purpose, and APP 11 mandates reasonable security. Sensitive information generally needs consent, so training and running AI on health or genetic data demands careful legal basis.
Source: OAIC - Australian Privacy PrinciplesFrom 10 December 2026, amendments made by the Privacy and Other Legislation Amendment Act 2024 require APP entities to disclose in their privacy policy where a computer program is used to make, or substantially help make, a decision that could reasonably be expected to significantly affect the rights or interests of an individual. For insurers this reaches automated underwriting declines, premium loadings and claims decisioning. Policies must describe the kinds of information used and decisions made.
Source: OAIC - automated decision-making transparency guidanceThe Voluntary AI Safety Standard and the October 2025 Guidance for AI Adoption set out essential practices for organisations that develop or deploy AI: accountability and governance, risk management, data governance, testing and monitoring, human oversight, transparency and stakeholder engagement, plus record keeping. Though voluntary, the practices reflect the direction of future regulation and give insurers a defensible baseline for governing pricing, underwriting and claims models responsibly.
Source: DISR - Voluntary AI Safety Standard and AI adoption guidanceCPS 230 Operational Risk Management commenced 1 July 2025 for APRA-regulated entities including general, life and private health insurers. It requires sound management of operational risk, maintenance of critical operations within tolerance levels through disruptions, and rigorous oversight of material service providers. AI vendors, model-hosting platforms and data suppliers used in underwriting or claims can be material arrangements, so insurers must assess, monitor and hold contingency plans for those dependencies.
Source: APRA - CPS 230 Operational Risk ManagementCPS 234 Information Security requires APRA-regulated insurers to maintain an information security capability commensurate with the threats they face, implement controls proportionate to the criticality and sensitivity of information assets, test control effectiveness, and notify APRA no later than 72 hours after becoming aware of a material information security incident. AI systems that ingest large volumes of policyholder and health data expand the attack surface and fall squarely within scope.
Source: APRA - CPS 234 Information SecurityCPS 220 Risk Management requires an APRA-regulated insurer to maintain a risk management framework covering all material risks, with a risk appetite statement, clear board accountability, adequate resourcing and regular review of effectiveness. Model risk, data quality risk and the conduct risk introduced by AI-driven pricing and underwriting must be identified, measured and controlled within that framework, with the board ultimately responsible for its appropriateness.
Source: APRA - Risk Management (CPS 220)ASIC Regulatory Guide 271 sets enforceable internal dispute resolution standards for financial firms including insurers. Complainants must generally receive an IDR response no later than 30 calendar days, the response must give reasons, and systemic issues must be identified and escalated. Where AI or automated systems triage or decide claims and complaints, insurers must ensure human reviewability, adequate reasons and adherence to the maximum timeframes so consumers are not disadvantaged.
Source: ASIC - RG 271 Internal Dispute ResolutionThe Design and Distribution Obligations in Part 7.8A of the Corporations Act require insurers issuing retail products to make a target market determination, distribute only consistent with it, take reasonable steps so products reach the right consumers, and review the determination when triggers arise. AI-driven marketing, lead-scoring and distribution tools must be governed so targeting stays inside the defined market and does not steer unsuitable consumers toward products.
Source: ASIC - RG 274 Design and Distribution ObligationsThe unfair contract terms regime in the ASIC Act applies to standard-form consumer and small-business insurance contracts entered, renewed or varied on or after 5 April 2021. A term causing significant imbalance, not reasonably necessary to protect legitimate interests and causing detriment can be declared unfair, and unfair terms now attract penalties with each term a separate contravention. Terms generated or applied through automated policy engines must be reviewed for fairness.
Source: ASIC - unfair contract term protectionsEach obligation links to its primary or official source. Verified against APRA, ASIC, OAIC, AHRC and the relevant Australian legislation, July 2026. General information, not legal advice: confirm your specific obligations with the regulator or your adviser.
Detailed analysis of the obligations that apply in this sector.
Build an inventory of every AI and automated model used in underwriting, pricing, claims and fraud, and record where each significantly affects a rights or interests decision.
Update the privacy policy before 10 December 2026 to disclose the kinds of personal information used in automated decisions and the kinds of decisions made.
Map health and genetic data flows into models and confirm a lawful basis and consent under the APPs before training or inference.
Test underwriting and pricing models for unlawful discrimination and document reliance on reasonable actuarial or statistical data to support any differential treatment.
Classify AI vendors and data suppliers as material service providers under CPS 230 and secure oversight, contingency and incident terms in contracts.
Embed human oversight and reasons into automated claims and complaints handling so RG 271 timeframes and reviewability are met.
Review standard-form policy wordings applied through automated engines for unfair contract terms and align distribution logic with each target market determination.
The free AI Health Check maps your sector and the AI you actually use to the specific Australian duties you have triggered, then gives you a board-ready report. Your answers stay in your browser.
Take the free AI Health Check