PI Insurance and AI for Financial Services Firms

What Financial Planners and Accounting Practices Need to Know
Financial services professional reviewing AI governance controls and professional indemnity insurance risk requirements.

Quick answer

PI insurers writing professional indemnity cover for Australian financial planners and accounting practices are asking five specific AI governance questions at renewal in 2026. The questions are not about whether your firm uses AI, they are about whether you can prove what controls you have in place over how staff use it. ASIC v RI Advice Group Pty Ltd [2022] FCA 496 established the benchmark that insurers are applying: did the firm take reasonable steps? For AI governance, reasonable steps means a documented policy, technical controls that enforce it, protection of client data from unapproved AI tools, and evidence that the controls were operating. Firms that cannot answer these questions face premium increases, coverage exclusions, or policy terms that may not cover an AI-related claim.

Why PI insurers are asking about AI in 2026

Professional indemnity insurance for financial planning practices and accounting firms has always been calibrated to the quality of the firm’s systems and controls. A firm with documented processes, supervision frameworks, and clear accountability presents a lower risk profile than one that cannot demonstrate how its advice is produced and reviewed.

AI has changed what systems and controls means. Advisers and accountants are using AI tools to draft Statements of Advice, summarise client files, research product recommendations, and prepare tax advice. In many practices, this is happening without IT approval, without governance, and without any record of what data was submitted to which tool.

From an insurer’s perspective, this creates three intersecting risks that PI underwriters are now pricing explicitly.

  • Advice quality risk — if an AI tool generated a draft SOA that the adviser did not critically review, and the advice is later found unsuitable, the firm’s best interests duty process is not defensible. The claim has merit and the process that produced the advice is indefensible.
  • Privacy and data breach risk — if client financial data was submitted to a consumer AI tool without enterprise data protections, and that data is later involved in a breach or misuse event, the firm faces both a Privacy Act notifiable data breach and a PI claim arising from the same incident.
  • Reasonable steps risk — if the firm cannot demonstrate that it had adequate controls over AI use by staff – the RI Advice standard – the insurer’s exposure is not bounded by what actually happened. It is bounded by what could have happened, given the controls that were not in place.

Insurers have responded by adding AI governance questions to renewal questionnaires. The questions are specific. The answers are consequential.

The RI Advice benchmark and why it applies to your PI renewal

ASIC v RI Advice Group Pty Ltd [2022] FCA 496 is the most important decision for understanding what PI insurers mean when they ask about reasonable steps. The Federal Court found that RI Advice Group had contravened its AFSL obligations by failing to maintain adequate cyber risk management systems. The court did not require ASIC to prove that a specific client was harmed by the inadequate controls. The inadequacy of the controls was itself the contravention.

Applied to AI governance, the RI Advice principle runs like this: a financial planning practice or accounting firm that has no visibility into what AI tools staff are using, no technical controls that prevent client data from being submitted to unapproved tools, and no records of AI use in advice production, has not taken reasonable steps to manage AI risk. The absence of the system is the problem – not the outcome that the system would have prevented.

PI insurers are applying exactly this test at renewal. They are not asking whether you have had an AI-related claim. They are asking whether your controls are adequate to prevent one. A firm that cannot demonstrate adequate controls is a firm that presents an elevated, open-ended risk profile – which insurers price accordingly.

The reasonable steps standard in practice

ASIC’s May 2026 open letter to AFS licensees explicitly directed boards to treat AI governance as a material risk requiring documented controls. APRA’s April 2026 letter found that entities were relying on policy rather than technical enforcement. Both observations confirm the regulatory benchmark that PI insurers are using: reasonable steps is not a policy document. It is an operating system.

The five AI governance questions at PI renewal, what insurers want and what a gap costs you

These are the five questions now appearing in PI renewal questionnaires for financial planning practices and accounting firms in Australia. They are not hypothetical. They are the questions your broker will ask you to answer before your next renewal.

Does your practice have a documented AI acceptable use policy that identifies which tools are approved and which are not?

What insurers want to see What a gap means at renewal
A written policy that distinguishes approved enterprise AI tools from consumer-grade tools (free ChatGPT, Gemini, personal Claude accounts), addresses the specific use cases of SOA drafting, client file summarisation, and product research, and has been communicated to all staff. No policy, or a general technology policy that does not address AI specifically, is treated as an absence of AI governance. Premium loading is common. Some insurers are adding AI exclusion riders to policies for firms that cannot produce a documented AI acceptable use policy.

 

The policy distinction matters specifically because consumer-grade AI tools present a different risk profile to enterprise tools. Consumer accounts do not provide data processing agreements, do not guarantee data residency in Australia, and may use submitted content for model training. An AI policy that treats all tools the same has not addressed the material risk.

Do you have technical controls in place that prevent staff from submitting client financial data to unapproved AI tools?

What insurers want to see What a gap means at renewal
Browser-level controls that enforce the approved tool list, restrict file uploads and paste operations within consumer AI platforms, and produce a log of AI tool access events. The insurer wants evidence of technical enforcement, not just a policy that asks staff to comply voluntarily. A policy-only approach — no technical controls — is identified by insurers as a material control gap. The RI Advice precedent specifically addressed the inadequacy of policies that relied on staff compliance. Insurers applying that standard treat a policy without technical enforcement as insufficient.

 

This is the question that most practices cannot answer satisfactorily in 2026. The gap between a policy that says staff should not use unapproved AI tools with client data, and a control that enforces that policy at the browser level, is exactly the gap that ASIC and APRA have both identified as the most common failure across regulated financial services firms.

Do you have technical controls in place that prevent staff from submitting client financial data to unapproved AI tools?

What insurers want to see What a gap means at renewal
Browser-level controls that enforce the approved tool list, restrict file uploads and paste operations within consumer AI platforms, and produce a log of AI tool access events. The insurer wants evidence of technical enforcement, not just a policy that asks staff to comply voluntarily. A policy-only approach — no technical controls — is identified by insurers as a material control gap. The RI Advice precedent specifically addressed the inadequacy of policies that relied on staff compliance. Insurers applying that standard treat a policy without technical enforcement as insufficient.

 

This is the question that most practices cannot answer satisfactorily in 2026. The gap between a policy that says staff should not use unapproved AI tools with client data, and a control that enforces that policy at the browser level, is exactly the gap that ASIC and APRA have both identified as the most common failure across regulated financial services firms.

Does your practice maintain records of AI tool use in advice production, including which tools were used and what data was submitted?

What insurers want to see What a gap means at renewal
An AI tool usage log covering the adviser, the tool, the date, the nature of the task, and whether client data was involved. For SOA-related tasks, a record of the AI’s involvement in the drafting process attached to the advice file. Records retained for a minimum of seven years to match the RG 175 advice record-keeping obligation. No record of AI use in advice production means the advice file is incomplete for any SOA produced with AI assistance. An AFCA complaint that leads to a review of the advice process will surface this gap. The insurer may take the position that the absence of a process record affects the claim.

 

Insurers writing PI cover for financial planners are aware that RG 175 requires advice records to be kept for seven years and that those records must be sufficient to show the basis for the advice. A SOA produced with AI assistance, with no record of the AI’s involvement, is a file that cannot demonstrate the process behind the advice. Underwriters treat this as an advice quality risk that they cannot quantify, and price it accordingly.

Does your practice maintain records of AI tool use in advice production, including which tools were used and what data was submitted?

What insurers want to see What a gap means at renewal
A documented assessment of the enterprise terms of service for each approved AI tool, confirming data processing agreements are in place, data residency is within Australia or an adequate jurisdiction, and the tool does not use client content for model training. For consumer tools: confirmation that they are blocked or restricted from receiving client data. A practice that has not assessed the data protection terms of AI tools in use by staff cannot confirm that client data is being handled in accordance with the Australian Privacy Principles. Insurers writing cover for practices that hold sensitive client financial data treat an undocumented data handling position as a privacy breach waiting to be reported.

 

The data assessment question is where the intersection between PI insurance and Privacy Act compliance becomes direct. A practice that cannot confirm its data handling position for AI tools is a practice that may be operating in breach of APP 6 (use of personal information), APP 11 (security of personal information), and the Notifiable Data Breaches scheme. Each of those is a separate exposure that the PI insurer may or may not cover, depending on how the policy is worded and what the firm disclosed at renewal.

Have all staff received training on your AI governance policy, and do you have records of that training?

What insurers want to see What a gap means at renewal
Training records showing when each staff member received AI governance training, what was covered — approved tools, prohibited uses, client data handling requirements — and that training is reviewed at least annually or when a significant new AI tool enters the market. A practice that cannot produce training records when an AI-related claim is made cannot demonstrate that the policy was communicated and understood. Insurers view this as a gap in the firm’s ability to demonstrate that reasonable steps were taken. It does not automatically void a claim, but it weakens the firm’s position in any dispute about whether adequate controls were in place.

 

The training records question connects directly to the ASIC framework. ASIC’s expectations for adequate risk management systems under section 912A of the Corporations Act include not just having controls, but being able to demonstrate that those controls were communicated and operating. A policy without training records is a policy that cannot be evidenced as an operating system.

What firms with strong AI governance look like at renewal

Firms that are well-positioned at PI renewal in 2026 share a consistent set of characteristics. They are not necessarily the largest firms, or the most technically sophisticated. They are the firms that treated AI governance as a governance question rather than a technology question — and built the evidence base accordingly.

  • A written AI acceptable use policy — that specifically addresses financial services use cases: SOA drafting, client file summarisation, product research, and meeting preparation. Reviewed in the past twelve months. Available to share with the insurer or broker.
  • Browser-level technical controls — that enforce the approved tool list and restrict client data from reaching unapproved tools. Not just a firewall or URL block — controls that operate at the level of the AI interaction itself, restricting file uploads and paste operations within consumer tools.
  • An AI tool usage log — that records AI tool access by user, tool, and data category. Retained as part of the advice record-keeping obligation. Accessible on demand.
  • Documented enterprise tool assessments — confirming that approved AI tools have adequate data processing agreements and that their data handling terms are consistent with Australian Privacy Principle obligations.
  • Staff training records — showing when AI governance training was delivered, who attended, and what was covered. Updated when the policy changes or a significant new tool enters the market.

Firms that have all five in place can answer the PI renewal questionnaire in full, can demonstrate that their controls are operating rather than just documented, and can position themselves as a managed risk rather than an open-ended one. That is the difference that shows up in premium, in coverage terms, and in how quickly a claim is resolved.

How KMTech's Shadow AI Governance service prepares your practice for PI renewal

KMTech’s Shadow AI Governance service provides the technology layer that translates your AI governance policy into an operating system with an evidence base. For financial planning practices and accounting firms, the service produces the specific artefacts that PI insurers are asking to see.

  • Real-time AI tool inventory — complete visibility into which AI tools staff are accessing, addressing Question 1 with evidence rather than assertion. The insurer can see the tools in use, not just the policy that governs them.
  • Browser-level preventative controls — technical enforcement of your approved tool list, directly addressing Question 2. Policy plus enforcement, not policy alone.
  • AI tool usage log — a continuous, timestamped record of AI tool access by user and data category, addressing Question 3. Retained and available on demand for advice file review, AFCA processes, or insurer requests.
  • Data handling documentation support — clarity on which tools are operating under enterprise terms and which are restricted from client data, addressing Question 4.
  • Staff awareness communications — delivered in a format that can be recorded as training for Question 5. Not a one-time briefing — regular communications that refresh awareness as the AI tool landscape changes.

KMTech is not an insurance broker, PI adviser, or AFSL compliance consultant. We provide the managed IT and security infrastructure that makes your AI governance framework operate in practice. The evidence of controls we generate is the evidence your insurer is asking for.

Frequently Asked Questions

Are PI insurers actually asking about AI governance at renewal in 2026?

Yes. PI underwriters in Australia writing cover for financial planning practices and accounting firms have added AI governance questions to renewal questionnaires in 2026. The questions vary in specificity by insurer and broker, but the five areas covered in this article reflect the pattern of questions being asked across the market. The addition of AI governance questions follows the same trajectory as cyber security questions, which became standard renewal items following the uptick in data breach claims from 2019 onwards. AI governance is following the same path, accelerated by the RI Advice precedent and the ASIC and APRA guidance issued in 2026.

 

Can a PI insurer refuse to cover an AI-related claim if the firm did not disclose AI use at renewal?

Potentially, yes. PI policies contain disclosure obligations — the firm is required to disclose material facts at renewal that a reasonable insurer would want to know. The use of AI tools in advice production is arguably a material fact if the firm has not disclosed it and a claim arises from an AI-assisted advice process. The practical consequence depends on the specific policy wording, the insurer, and the facts of the claim. However, a firm that answers the AI governance questions inaccurately or incompletely at renewal, and subsequently makes a claim arising from an AI-related incident, is in a significantly more difficult position than a firm that disclosed its governance position honestly, even if that position had gaps.

 

Does the RI Advice Group decision apply to AI governance for financial planners?

The principle established in ASIC v RI Advice Group Pty Ltd [2022] FCA 496 applies directly. The court held that an AFSL holder’s failure to maintain adequate cyber risk management systems was itself a breach of section 912A of the Corporations Act — regardless of whether a specific client was harmed by the inadequate controls. Applied to AI governance, a financial planning practice that has no visibility into AI tool use by staff, no technical controls over what client data is submitted to AI tools, and no records of AI use in advice production, has not maintained adequate risk management systems. The inadequacy is the breach. The RI Advice principle is the benchmark that both ASIC and PI insurers are applying.

 

What is the difference between a PI claim and a cyber insurance claim for an AI-related incident?

PI insurance covers professional liability — claims that arise from a failure to perform professional services to the required standard. Cyber insurance covers data breach, cyber extortion, and related incidents. An AI-related incident in a financial planning practice can trigger both simultaneously: if an adviser uses an unapproved AI tool to draft an SOA and the advice is unsuitable, that is a PI claim. If the same tool exposed client data, that is a cyber claim. The interaction between the two policies — which covers what, whether the same incident can be claimed under both, and how the excess and limits interact — is a question for your broker. What matters for AI governance is that both insurers will ask what controls were in place, and both will apply the reasonable steps standard.

 

How quickly can a financial services practice get its AI governance in order before a PI renewal?

KMTech’s Shadow AI Governance service can provide real-time visibility into AI tool usage and deploy browser-level controls within five to seven business days. A written AI acceptable use policy can be drafted and reviewed within one week. Staff training can be delivered as a short briefing and recorded within the same period. The AI tool usage log starts from the date controls are deployed. For a practice facing a PI renewal in four to six weeks, the most important steps are the documented policy, the technical controls, and the training record — these are the three artefacts that directly address the renewal questionnaire. The usage log and data handling documentation follow from having the controls in place.

Shadow AI & AI Governance Protection

For executives and technical leaders who need visibility and control

Your workforce is already using AI tools. The question is whether you can see it, govern it, and prevent data leakage.

If you're concerned about Shadow AI risk, AI governance gaps, or enabling AI safely without blocking innovation, we'll show you exactly what's happening in your organisation and how to protect it.

Request a demo to view real‑time visibility, protection, and governance controls

About the author

Bradley Kaine is the CEO and Co-Founder of Kaine Mathrick Tech (KMTech), a Melbourne-based cyber-first managed IT and security provider. KMTech works with financial planning practices, accounting firms, and professional services organisations across Australia, providing managed IT, managed security, and compliance-ready technology infrastructure. KMTech holds ISO 27001, ISO 9001, and ISO 45001 certifications and is a consecutive MSP 501 global ranking recipient and Pax8 Peak Performance APAC 2026 winner.

kmtech.com.au | 1300 174 389 | info@kmtech.com.au

More on Web Filtering and Shadow AI from KMTech

Everything on this topic, in one place.

Last updated:

Related Stories

IT security professional reviewing a Managed Detection and Response (MDR) dashboard, illustrating KMTech's practical guide to 24/7 cyber threat monitoring

What is MDR? A Practical Guide to Managed Detection and Response

Learn what MDR cybersecurity is, how it works, and MDR vs EDR. See what an MDR service includes for Australian SMBs and mid‑market teams.

shadow ai

Shadow AI by the Numbers: Risk Data, Resources and Where to Start

Shadow AI, the unauthorised use of AI tools outside IT oversight, is already widespread in Australian businesses. This page brings together the data behind that risk.

Team meeting in an office setting with text overlay reading “Web Filtering and ISO 27001.”

Web Filtering and ISO 27001

This guide explains what ISO 27001 expects from web filtering and internet access controls, why legacy approaches often fall short, and how modern web filtering supports audit readiness, risk management, and ongoing compliance. Written for directors, executives, and IT leaders responsible for information security governance.

Want to be part of the crowd?

html