This file covers Australia's regulatory framework for life insurance and the
AU-specific rules for income protection. It is the Australia-second reference
that supports a possible AU expansion; Bob's NZ-first product and the NZ rule set
live separately under knowledge-base/nz/ and must not be conflated with anything
here. Everything below is AU law and AU regulator practice unless a section
explicitly contrasts it with NZ. As with the rest of the corpus, this is written in
our own words from public sources, carries no client PII and no premiums, and is
draft until a reviewer signs off.
APRA: the prudential regulator for life insurers
The Australian Prudential Regulation Authority (APRA) is the regulator that watches the financial safety and soundness of life insurers (and banks, general insurers, private health insurers, super funds and friendly societies). Its job is prudential, not conduct: APRA's aim for an insurer is that the company has the financial means to pay all legitimate policyholder claims under reasonable circumstances. So APRA cares whether the insurer can stay solvent and meet its promises, not how the insurer sells to or advises an individual customer (that is ASIC's side). Life insurers must hold capital against the risks they run and meet the solvency requirements that flow from the Life Insurance Act 1995; APRA sets these through legally binding Prudential Standards (for example the LPS 100 Solvency Standard), non-binding Prudential Practice Guides, and mandatory Reporting Standards. For an AU expansion, the practical point is that APRA-regulated capital settings sit behind every insurer Bob would deal with, and APRA can impose conditions or directions on an insurer that does not manage its risks (this is exactly the lever it used for income protection, below).
Source: APRA - What is prudential regulation / Life insurance standards (https://www.apra.gov.au/what-prudential-regulation) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
ASIC and the "twin peaks" model
The Australian Securities and Investments Commission (ASIC) is Australia's conduct and markets regulator. It oversees how financial firms behave with consumers: licensing, disclosure, financial advice, market integrity and consumer protection. ASIC issues the Australian Financial Services Licence (AFSL) and supervises the advisers and firms who deal in and advise on insurance, super, investments and credit. Australia runs a "twin peaks" model: ASIC governs conduct (how a firm deals with and advises customers) while APRA governs prudential safety (capital and solvency). A life insurer is therefore dual-regulated, answering to APRA for its financial soundness and to ASIC for its conduct, disclosure and advice. The two agencies have a formal cooperation relationship and share information about suspected breaches of each other's laws. [VERIFY] Both bodies are commonly dated to 1 July 1998 following the Wallis Inquiry; this is historically well established but was not stated on the specific ASIC relationship page reviewed, so treat the exact date as corroborated rather than primary.
For Bob, the twin-peaks split matters because the rules that constrain how Bob talks and what it can say are ASIC/Corporations Act rules, not APRA rules.
Source: ASIC - The ASIC-APRA relationship (https://www.asic.gov.au/about-asic/what-we-do/our-role/working-with-other-agencies-and-organisations-memoranda-of-understanding/the-asic-apra-relationship/) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
AFSL: the Australian Financial Services Licence and the adviser regime
If you carry on a business of providing financial services in Australia, you must hold an AFS licence, unless you are exempt or you act as an authorised representative of someone who holds one. An AFSL authorises a licensee to do things like provide financial product advice, deal in a financial product, make a market, and handle and settle insurance claims. Before granting a licence, ASIC checks that the applicant is competent, has adequate resources (unless it is APRA-regulated) and can meet ongoing obligations such as training, compliance, dispute resolution and adequate arrangements for managing conflicts. A licence is a point-in-time assessment, not an ASIC endorsement of service quality. For the financial adviser regime, giving personal advice to retail clients requires AFSL authorisation (held directly or as an authorised representative), and the individual adviser must meet professional standards (education, an exam, continuing professional development) and be listed on the Financial Advisers Register. The ongoing advice rules sit in the Corporations Act and ASIC's Regulatory Guide 175. The licensing-and-authorisation concept is the AU analogue of NZ's FAP/financial-adviser licensing, but the statutory machinery is entirely different and an AU build cannot reuse NZ licence assumptions.
Source: ASIC - Do you need an AFS licence? (https://www.asic.gov.au/for-finance-professionals/afs-licensees/do-you-need-an-afs-licence/) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
Personal advice vs general advice vs factual information (the AU information line)
This is the most legally load-bearing distinction in the AU framework, and it differs from NZ. The definitions sit in s766B of the Corporations Act 2001. Financial product advice is a recommendation or statement of opinion (or a report of either) intended, or that could reasonably be regarded as intended, to influence a person's decision about a financial product. Advice splits two ways:
- Personal advice is given where the provider has considered (or a reasonable person would expect the provider to have considered) one or more of the person's objectives, financial situation or needs. The Full Federal Court in ASIC v Westpac Securities Administration Ltd [2019] FCAFC 187 read "considered" as "took account of" (the High Court refused Westpac special leave to appeal in 2021, leaving it settled law), and held that taking account of even one of those matters can make advice personal, even if the objective is common to most people in the client's position. This is a low bar to cross.
- General advice is any financial product advice that is not personal advice (it does not weigh the individual's circumstances). General advice must carry a general advice warning telling the client it does not account for their personal situation.
- Factual information is not advice at all: objective, true statements that a reasonable person would not read as a recommendation or opinion meant to influence a product decision. Providing purely factual information does not require an AFSL. The danger is that the moment information is framed, filtered or characterised so that it implies a recommendation, it can tip into general or personal advice.
ASIC's plain-language guidance is Regulatory Guide 244 (giving information, general advice and scaled advice), with the broader advice obligations in RG 175.
How this differs from NZ: NZ does not use the "personal advice / general advice" split. Under NZ's FSLAA/FMC regime, giving "regulated financial advice" triggers duties regardless of a general-vs-personal distinction, and NZ leans on a "financial advice vs factual information" line rather than AU's three-way split. An AU build must re-implement the line at s766B, not port NZ's.
[VERIFY] The verbatim subsection wording of s766B(1)/(3)/(4) should be pulled from the official text at legislation.gov.au before any word-for-word quote; the substance above is corroborated across ASIC guidance and the High Court ruling.
Source: ASIC - Giving financial product advice (https://www.asic.gov.au/regulatory-resources/financial-services/giving-financial-product-advice/) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: advice · status: draft
Best interests duty for personal advice (s961B)
When a provider gives personal advice to a retail client, they must act in the best interests of the client in relation to that advice. The duty sits in s961B of the Corporations Act 2001 (introduced by the Future of Financial Advice "FOFA" reforms). Section 961B(2) sets out a "safe harbour": a provider is taken to have met the duty if they prove they took the listed steps, which in substance are to identify the client's objectives, situation and needs as disclosed; identify the subject matter of the advice; make reasonable inquiries where information is incomplete or inaccurate; assess whether they have the required expertise (and decline if not); where recommending a product, conduct a reasonable investigation of products that could meet the client's needs; base judgements on the client's relevant circumstances; and take any other step that would reasonably be regarded as being in the client's best interests. The safe harbour is one way to comply, not the only way, and is not a mechanical box-ticking checklist. Related duties sit alongside it: the advice must be appropriate to the client (s961G), and the adviser must prioritise the client's interests over their own or the licensee's where there is a conflict (s961J).
This is the AU analogue of an adviser duty, but it is statutory, attaches specifically to personal advice to retail clients, and comes with a defined safe harbour, none of which maps cleanly onto NZ's Code of Professional Conduct duties.
[VERIFY] Confirm the exact (a)-(g) lettering of the s961B(2) steps against the official statutory text before quoting verbatim.
Source: AustLII - Corporations Act 2001 s961B (https://www.austlii.edu.au/cgi-bin/viewdoc/au/legis/cth/consol_act/ca2001172/s961b.html) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: advice · status: draft
Design and distribution obligations (DDO) and target market determinations
The design and distribution obligations (DDO) sit in Part 7.8A of the Corporations Act 2001 and commenced on 5 October 2021. ASIC's guidance is Regulatory Guide 274. DDO applies to issuers and distributors of financial products available to retail clients, and life insurance products are squarely in scope. The core mechanism is the target market determination (TMD): the issuer must prepare a TMD that describes the class of retail clients the product is appropriate for, sets any conditions or restrictions on how the product is distributed, and specifies review triggers (events that would suggest the TMD is no longer appropriate). Both issuers and distributors must take reasonable steps so that distribution is consistent with the TMD, and issuers must keep the product and its TMD under review. DDO is being actively enforced against life insurers: ASIC issued its first stop order for a life insurance product (ClearView) in July 2023 over alleged TMD deficiencies. For Bob, DDO is the reason any AU product Bob surfaces should be matched against the insurer's stated target market, and why "who is this product for" is a structured constraint, not a marketing line.
Source: ASIC - RG 274 Product design and distribution obligations (https://download.asic.gov.au/media/etgm1amc/rg274-published-10-september-2024.pdf) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: advice · status: draft
Life Insurance Code of Practice
The Life Insurance Code of Practice is the industry code that sets minimum standards for how subscribing life insurers treat customers. It is now owned and administered by the Council of Australian Life Insurers (CALI), which took it over from the Financial Services Council (the original 2016 author). The current edition took effect on 1 March 2025. The Code binds CALI members that are registered life insurers plus any other entity that formally adopts it; it is mandatory for subscribers but is not universally mandatory for every Australian life insurer. It covers product design and advertising, sales practices, policy documentation, customer communications, underwriting decisions, claims handling, complaints, support for vulnerable consumers, and mental-health protections (for example, not declining cover before the applicant has had a chance to provide relevant information, and considering loadings or exclusions rather than outright denial). It also sets claims-decision timeframes (for example, income-related claim decisions within a shorter window than lump-sum claims) and makes allowances for customers in remote or regional communities. Compliance is monitored by the independent Life Code Compliance Committee, which can investigate breaches and impose sanctions. This is the AU counterpart to NZ's industry codes (such as the FSC NZ code and ICNZ Fair Insurance Code), but it is a different document with different obligations.
[VERIFIED-AI 2026-06-21: the current Code is the "Life Insurance Code of Practice" March 2025 edition (footer label "Life Insurance Code of Practice 2025"), published by the Council of Australian Life Insurers; clause 1.4 states it took effect 1 March 2025 and replaced the previous version. Claims-decision timeframes (Section 5): income-related benefit claims decided within 2 months of the claim received date (or end of the waiting period, if later) (cl 5.48); lump-sum benefit claims within 6 months (cl 5.49); once all needed information is received, the written decision follows within 15 Business Days (cl 5.50). Source: CALI Life Insurance Code of Practice 2025 PDF (cali.org.au).]
Source: CALI - Life Insurance Code of Practice (https://cali.org.au/life-code/) · retrieved 2026-06-18 · rights: industry-code-public · drives: information · status: draft
How income protection works in Australia (high level)
Income protection (called "salary continuance" when held inside super) pays a regular monthly income for a set period if illness or injury stops you working. Two structural levers define a policy: the waiting period (how long you wait after becoming unable to work before payments start; commonly anywhere from around two weeks up to a couple of years) and the benefit period (how long payments continue while you remain unable to work; commonly two years, five years, or up to a set age such as 65). A policy can be held inside super (premiums come out of the super balance, often with fewer features) or outside super (paid from your own pocket, generally tax-deductible, often with more features and potentially higher cover). The amount of income a new policy can replace is now constrained by APRA's reforms (next section). The high-level mechanics are similar to NZ income protection, but the AU regulatory caps below are AU-specific and do not apply in NZ.
[VERIFY] The specific replacement percentage shown on Moneysmart's consumer page was not confirmed verbatim (the page blocks automated fetch); the binding figure for new policies is the APRA ratio in the next section.
Source: Moneysmart - Income protection insurance (https://moneysmart.gov.au/how-life-insurance-works/income-protection-insurance) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
APRA's IDII (income protection) sustainability reforms, what changed
This is the single most AU-specific thing in this file and it has no NZ equivalent. APRA found that individual disability income insurance (IDII, the industry term for individual income protection) had produced sustained, very large losses, and that the industry had repeatedly failed to design, price and manage these products appropriately. APRA intervened with binding expectations on life insurers. The measures that actually took effect are:
- Removal of agreed-value contracts. With effect from 31 March 2020, APRA expects life companies to have stopped writing IDII contracts where benefits are not based on the policyholder's income at the time of claim. This includes "agreed value" and "endorsed agreed value" contracts. New cover must be income-at-claim based.
- Income-at-risk replacement-ratio caps. With effect from 1 October 2021, for new IDII policies the total benefits paid under the product must not exceed 90% of earnings at the time of claim for the first six months of a claim, and not exceed 70% thereafter. (Note: an earlier 2019 consultation proposed 100% then 75%; APRA revised these down to 90%/70% in the final September 2020 letter. The older 100%/75% figures still appear on some APRA overview pages and should not be used.)
- Income-at-risk basis. From 1 October 2021, "income at risk" for new contracts is set from earnings at the time of the claim (for stable income, generally annual earnings no older than 12 months; for variable income, an average over a longer period).
- Capital charge. APRA applied an upfront supervisory (Pillar 2) capital charge to life companies with IDII exposure, which stays in place per insurer until it demonstrates sufficient and sustained progress against APRA's expectations.
The upfront capital charge took effect on 31 March 2020 (the same date as the agreed-value cessation), per APRA's final IDII sustainability measures. [VERIFIED-AI 2026-06-21: the ~$30,000/month benefit cap was a CONSULTATION question only and was NOT adopted; APRA's final IDII measures impose the 90%/70% income-replacement-ratio limit (effective 1 Oct 2021) with no dollar cap, so do not state a $30k/month cap as in force. Source: APRA, "Final individual disability income insurance sustainability measures".]
Source: APRA - Final IDII sustainability measures (https://www.apra.gov.au/final-individual-disability-income-insurance-sustainability-measures) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
IDII five-year policy-term measure: proposed, deferred, then suspended
A separate IDII measure deserves its own section because it is easy to misstate. As part of the sustainability framework, APRA proposed that life companies only offer new IDII contracts with a policy term not exceeding five years (renewable, but with the new contract on the terms then on offer), replacing the older long-term "guaranteed renewable to retirement age" contracts, with an original effective date of 1 October 2021. This measure did not land as written. APRA first deferred it by one year (to 1 October 2022) in May 2021, while keeping the other IDII measures on their 1 October 2021 dates. APRA then suspended the five-year contract-term measure on 24 March 2022 for at least two years, citing risks of material short-term premium increases, the risk of policyholders inadvertently failing to renew, and insufficient industry engagement. So as of this writing the agreed-value cessation (31 March 2020) and the income/ratio measures (1 October 2021) are the IDII rules that actually apply; the five-year term measure is suspended. An AU build should treat the five-year term as not in force unless and until APRA reactivates it.
Source: APRA - Suspension of IDII policy contract term measure (https://www.apra.gov.au/individual-disability-income-insurance-suspension-of-policy-contract-term-measure) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
Privacy Act 1988 and the Australian Privacy Principles
Australia's privacy law is the Privacy Act 1988 (Cth), and its operative core is the 13 Australian Privacy Principles (APPs) in Schedule 1. The APPs govern how personal information is collected, used, disclosed, secured and corrected, and give individuals rights to access their information. They bind "APP entities": most Australian Government agencies plus private-sector organisations with annual turnover over $3 million (with some smaller organisations also caught, notably health service providers). The regulator is the Office of the Australian Information Commissioner (OAIC), which issues guidance, handles complaints, runs investigations and audits, and can pursue penalties; a breach of an APP is an "interference with the privacy of an individual". For Bob, the AU privacy regime is the analogue of NZ's Privacy Act 2020, but it is a different statute with different machinery (APPs rather than NZ's Information Privacy Principles) and a turnover threshold that NZ does not have.
Source: OAIC - Australian Privacy Principles (https://www.oaic.gov.au/privacy/australian-privacy-principles) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
APP 8: cross-border disclosure (the data-residency control)
APP 8, working with section 16C of the Privacy Act, governs sending personal information overseas, and is the privacy rule most relevant to Bob's data-residency posture. Before an APP entity discloses personal information to an overseas recipient, it must "take such steps as are reasonable in the circumstances" to ensure the overseas recipient does not breach the APPs in relation to that information (APP 8.1). In practice, this usually means an enforceable contract binding the recipient to APP-equivalent handling. The accountability rule in s16C makes the disclosing entity generally responsible for the overseas recipient's acts: a breach by the recipient is "taken to have been done by the APP entity" itself. The main exceptions are (a) where the entity reasonably believes the recipient is subject to a law or binding scheme that protects the information in a way "at least substantially similar" to the APPs with accessible enforcement, or (b) where the entity expressly informs the individual that consent means APP 8.1 will not apply and the individual then consents.
Practical residency implication: keeping AU personal information stored and processed within Australia (for example, the Sydney Supabase region Bob uses) avoids triggering an APP 8 "disclosure to an overseas recipient", which removes the reasonable-steps and accountability burden that arises when data is sent offshore.
[VERIFY] Confirm that no third-party sub-processor in Bob's stack routes AU personal data offshore, because an app-layer integration can re-introduce an APP 8 disclosure even when primary storage is in Sydney.
Source: OAIC - APP 8 cross-border disclosure (https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-8-app-8-cross-border-disclosure-of-personal-information) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
Sensitive information, including health data
Under the Privacy Act, health information is "sensitive information", and sensitive information gets stricter protection than ordinary personal information. Health information is defined broadly: it covers information collected while providing a health service, and genetic information in a form that is or could be predictive of the health of an individual or a genetic relative. The key practical rule for insurance is the higher consent bar to collect: an APP entity generally must not collect sensitive (including health) information without the individual's consent, unless an exception applies, a stricter standard than for ordinary personal information. Consent can be express or implied, but sensitive-information collection is treated as a higher-risk scenario where consent is the expected basis. Because life insurance underwriting routinely collects an applicant's medical and health data, an AU underwriting flow must meet the sensitive-information collection rules (consent plus reasonable necessity) on top of the ordinary APP notice and transparency obligations. This higher bar for health data is a hard constraint on how Bob would gather underwriting information in AU.
[VERIFY] Confirm the exact wording of the small-business/health-service exception (which pulls some sub-threshold health providers into the Act) before asserting it in any consumer-facing fact sheet.
Source: OAIC - APP guidelines, key concepts (sensitive/health information) (https://www.oaic.gov.au/privacy/australian-privacy-principles/australian-privacy-principles-guidelines/chapter-b-key-concepts) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
Privacy Act reform direction (2024 amendments)
Australia's privacy law is in the middle of a reform program. The Privacy and Other Legislation Amendment Act 2024 was registered (instrument C2024A00128), which the OAIC described as "a significant step for Australia's privacy law". Reported high-level changes include expanded OAIC enforcement and investigation powers (new tiers of civil penalties and an ability to issue infringement notices), a mandate to develop a Children's Online Privacy Code, a statutory tort for serious invasions of privacy, and a mechanism to prescribe a "white list" of countries or binding schemes with adequate protections to facilitate cross-border transfers (which would interact with APP 8). This is described as the first tranche of a broader reform following the Privacy Act Review; later tranches were flagged but their status and timing are uncertain.
The majority of amendments within the Information Commissioner's remit commenced on 11 December 2024 (confirmed; Royal Assent was 10 December 2024). [VERIFIED-AI 2026-06-21: the overseas-data-flow "white list" is the new s100(1A) regulation-making power (to prescribe a country or binding scheme as "substantially similar" to the APPs), operationalised by new APP 8.3, under the Privacy and Other Legislation Amendment Act 2024 (C2024A00128). No countries have been prescribed yet, so do not treat any country as white-listed. Source: legislation.gov.au C2024A00128 (overseas data flows).] Treat the
later-tranche items as moving targets.
Source: OAIC - Passing of the Bill: a significant step for Australia's privacy law (https://www.oaic.gov.au/news/media-centre/pasing-of-bill-a-significant-step-for-australias-privacy-law) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
AML/CTF and AUSTRAC
Australia's anti-money-laundering and counter-terrorism-financing regime is the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, administered by AUSTRAC (the financial intelligence agency and AML/CTF regulator). A business that provides a "designated service" with a link to Australia must enrol with AUSTRAC and comply with the Act; AUSTRAC publishes sector guidance for the life insurance sector, confirming that certain life-insurance and financial services are regulated designated services. Reporting entities must maintain an AML/CTF program to manage money-laundering, terrorism-financing and proliferation-financing risk, and must do customer due diligence (KYC): initial CDD before providing a designated service and ongoing CDD, using a risk-based approach. Reporting obligations include Suspicious Matter Reports (within 24 hours for terrorism-financing matters, otherwise 3 business days) and Threshold Transaction Reports for physical-currency transactions of A$10,000 or more (within 10 business days). The AML/CTF concept maps to NZ's AML/CFT Act 2009, but the AU obligations, thresholds and reporting forms are AU-specific and run through AUSTRAC, not NZ supervisors.
[VERIFIED-AI 2026-06-21: the life-insurance designated services are in Table 1 (Financial services) of section 6 of the AML/CTF Act 2006: item 37 (issuing, or undertaking liability as the insurer under, a life policy or sinking fund policy), item 38 (accepting a premium for such a policy), item 39 (making a payment to a person under such a policy). There is no separate "investment-linked life insurance" item; investment-linked life policies fall under items 37-39 via the "life policy" definition (s5, by reference to the Life Insurance Act 1995). Reform timeline: the AML/CTF Amendment Act 2024 received Royal Assent 10 December 2024; tranche-2 obligations commence 1 July 2026 (enrolment opens 31 March 2026; AML/CTF Transitional Rules 2026, F2026L00393). Source: legislation.gov.au (AML/CTF Act 2006 s6 Table 1 full text) + austrac.gov.au reform pages.] [VERIFY] the program and CDD specifics (occasional-transaction triggers, transitional-rule detail) against current AUSTRAC pages before go-live, because tranche-2 does not commence until 1 July 2026 and the detail is still settling.
Source: AUSTRAC - Your obligations (https://www.austrac.gov.au/industry-and-business/obligations-and-guidance/your-obligations) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
AFCA: external dispute resolution
The Australian Financial Complaints Authority (AFCA) is Australia's single external dispute resolution (EDR) scheme, a free, independent ombudsman that handles complaints about financial products and services and helps consumers and small businesses resolve disputes with financial firms. It is free to consumers and can award compensation for losses caused by a firm's error or inappropriate conduct. Membership is mandatory for many financial firms: AFS licensees, Australian credit licensees, authorised credit representatives and super trustees are required to be AFCA members under their licence conditions, so insurers and advice firms must belong. If a complaint is not resolved between the parties, AFCA decides an outcome, and its determinations can be binding on the financial firm. AFCA commenced on 1 November 2018, replacing the former Financial Ombudsman Service, Credit and Investments Ombudsman and Superannuation Complaints Tribunal. AFCA is the AU analogue of NZ's dispute-resolution schemes (IFSO/FSCL), but it is a single consolidated body, whereas NZ has multiple approved schemes.
[VERIFIED-AI 2026-06-21: confirmed against AFCA's published process/rules: an AFCA determination binds the financial firm only if the complainant accepts it (within 30 days of the determination); if the complainant does not accept, neither party is bound and the consumer may pursue court or other action. Exception: superannuation determinations bind both parties. Source: AFCA, "The process we follow" / AFCA Rules.]
Source: AFCA - About AFCA (https://www.afca.org.au/about-afca) · retrieved 2026-06-18 · rights: public-govt-attribution · drives: information · status: draft
Key NZ vs AU differences an expansion must handle
A quick map of where an AU expansion cannot reuse NZ assumptions:
- Two regulators, not one frame. AU splits prudential (APRA) from conduct (ASIC) under "twin peaks". NZ's conduct/advice regime runs through the FMA, and prudential supervision of insurers sits with the Reserve Bank of New Zealand, a different split Bob must model separately.
- The advice line is shaped differently. AU has a three-way split (personal advice / general advice / factual information) with a statutory best-interests duty and safe harbour for personal advice to retail clients (s961B). NZ does not use the general-vs-personal split and frames the line as regulated financial advice vs factual information. Bob's "is this advice?" guardrail must be jurisdiction-aware.
- Product governance. AU's DDO/TMD regime is an explicit, enforced product-design obligation for life insurers; the NZ equivalent obligations differ and are not a TMD regime. Matching a product to its stated target market is an AU-specific control.
- Income protection rules are AU-specific. APRA's IDII reforms (no agreed value from 31 March 2020; 90%/70% income-at-risk caps from 1 October 2021; a suspended five-year term measure; an IDII capital charge) have no NZ equivalent and materially change what an AU income-protection product can offer.
- Privacy machinery differs. AU uses the 13 APPs, a A$3m turnover threshold, APP 8 cross-border rules with s16C accountability, and a stricter consent bar for health data. NZ uses its own Privacy Act 2020 and Information Privacy Principles. Data residency reasoning (keeping AU data in Sydney to avoid an APP 8 disclosure) is an AU-specific argument.
- AML and disputes. AML/CTF runs through AUSTRAC (vs NZ's AML/CFT supervisors), and external disputes run through the single AFCA scheme (vs NZ's multiple approved EDR schemes).
Source: Knowledge-base synthesis of APRA/ASIC/OAIC/AUSTRAC/AFCA sources cited above (https://www.apra.gov.au/) · retrieved 2026-06-18 · rights: own-summary · drives: information · status: draft