The Insurance Council of Australia (ICA) recently closed the public consultation on the redrafted General Insurance Code of Practice (the Code). The current redraft draws on the Industry Action Plan released by the ICA in March 2025, which responded to recommendations from the Independent Code Review that was finalised in December 2024, and the Parliamentary Flood Inquiry into insurers’ responses to the 2022 NSW and South-East Queensland floods.
Across these reviews, one message is clear: historical practice has not kept pace with rising community and customer expectations. Under the proposed changes, shortfalls in Code compliance will carry more weight for Code subscribers. For the first time, the Code is proposed to be legally enforceable as a part of consumer insurance contracts (except the Principles and Section 10 on Enforcement), similar to the Banking Code of Practice. This marks a major step up from the current voluntary commitment to follow the Code and increases reputational risk for non-compliance.
The redrafted Code sets standards of conduct across the insurance lifecycle, including product disclosure, claims handling and investigations (with timeframes for responding to claims), complaints, support for people experiencing vulnerability, and reporting obligations to the Code Governance Committee.
The ICA is working through consultation responses and intends to seek ASIC approval of the redrafted Code in October 2026. The ICA currently anticipates a 24-month transition period before commencement.
The changes are designed to strengthen consumer protections and clarify insurer obligations.
Pending ASIC approval, the Code will form a part of retail consumer contracts (except the Principles and Section 10 on Enforcement) — making it legally enforceable as part of an insurance contract for the first time.
Home and motor claims will be automatically accepted after 12 months where no decision has been made, subject to defined exceptions.
A circumstances-based definition of vulnerability and a new Extra Care framework setting out additional support and flexibility for customers who need it most.
The definition now covers family and domestic violence, including financial abuse and coercion, with key protections becoming contractually enforceable obligations.
Enhanced expectations for trauma-informed claims handling and strengthened requirements for primary points of contact and cash settlements.
New obligations for insurers and external experts to comply with the ICA's Expert Report Best Practice Standard.
Source: ICA media release
Insurance is a promise, customers pay today for certainty that their insurer will be there when the worst happens. The redrafted Code targets areas in the moments that matter most: when a customer makes a claim, when they are experiencing hardship or when they are vulnerable.
Insurers who are already taking meaningful steps in this direction will have the opportunity earn lasting customer loyalty by leading on the outcomes that matter most to customers, and to strengthen the trust that sits at the heart of the insurance promise.
While the Code Governance Committee (CGC) can apply sanctions and issue compensation for individuals or community benefit payments for breaches under the current Code, the redrafted version adds a layer of legal exposure and reputational risk that did not previously exist. With the redrafted Code being embedded in insurance contracts (except the Principles and Section 10 on Enforcement), consumers would have the option to challenge a breach of the Code in court. This provides a sharper incentive for compliance. Definitions, timeframes and claims handling requirements will carry direct legal consequence, and will need to be sustainably embedded into policies, processes and controls, systems, reporting and frontline practice.
Insurers’ oversight of their distributors, service suppliers and claims fulfilment providers (e.g. builders and motor repairers) will be crucial, as insurers themselves will be in breach if these parties do not comply with the Code when they are acting on the insurer’s behalf. This aligns with the trajectory of regulation over recent years, including CPS 234 Information Security, CPS 230 Operational Risk Management and the Financial Accountability Regime, all of which make clear that outsourcing an activity does not outsource the responsibility for it.
Increasing Code breaches and rising complaint numbers reflect entrenched weaknesses in claims handling and the treatment of vulnerable customers - the key areas the redraft targets.
We see the CGC's 2024–25 Industry Data & Compliance Report as more than a compliance scorecard, it is a preview of where insurers are most exposed under the new Code. The data provides a compelling motivation for insurers to uplift their claims practices, address data limitations and strengthen controls to demonstrate compliance.
Source: CGC 2024–25 Industry Data & Compliance Report
The flip side of this exposure is opportunity. Many of the issues that drive Code breaches also undermine customer trust and increase cost-to-serve. Addressing them can deliver benefits that extend beyond compliance.
The direction of travel is evident, and the operational and cultural changes required will take time to embed. Insurers that understand their gaps and start work now will be best placed to demonstrate compliance when the new Code takes effect.
Key actions that insurers should look to move on now include:
1. Reassess Code compliance through an enforceability lens.
Treat the redrafted Code as a set of contractual terms and perform a gap analysis of areas such as claims handling and vulnerability identification. Once the Code obligations are contractually enforceable, insurers must be able to demonstrate, monitor and assure compliance.
2. Learn from historic breaches across the industry.
Review historic Code breaches and their root causes to understand the risk of non-compliance and identify improvements required. Look wider to learn from experience across the industry and assess your own capability to avoid the types of issues experienced in other parts of the sector.
3. Embed compliance by design through transformation.
As claims, data and technology transformation programs progress, treat them as an opportunity to embed Code compliance from the outset rather than retrofitting it later. Designing compliance in from the start is the most effective route to minimising the risk of breaches.
Well-governed AI tools can support this work, for example by analysing customer interactions to support the identification of vulnerability flags or when a complaint is raised, facilitating root cause analysis and automating quality assurance.