AI and compliance: How one New Zealand brokerage stays audit-ready

Due diligence on data security was the unglamorous start of one brokerage's AI journey - consistent advice records are the payoff

AI and compliance: How one New Zealand brokerage stays audit-ready

Transformation

By Daniel Wood

The compliance load on New Zealand insurance brokers is not getting lighter. Financial advice providers (FAPs) carry licensing obligations enforced by the Financial Markets Authority (FMA). The new Conduct of Financial Institutions (CoFI) regime has been in full effect since March 31 2025, with the FMA expecting firms to put consumers at the forefront of their decisions - and there's more regulation on the way. The Contracts of Insurance Act 2024, a significant reform of New Zealand's insurance contract law, comes into effect in November 2027. For Nic Tyson (pictured), director of Taranaki-based brokerage The Advisers, the surprise of adopting artificial intelligence (AI) was discovering that the same technology could carry part of that load.

But before it could help with compliance, the technology itself had to pass a compliance test.

"When we were going through due diligence with JAVLN, we needed to understand what security measures they had in place, where the data was being stored, and what ISO rating they had – because we have to prove to our regulators that we are securing that data," Tyson said.

Proving data security to the regulator

Tyson described that vendor scrutiny as among the least enjoyable work in broking and among the most important. Client data obligations under New Zealand privacy law mean a brokerage cannot outsource its records without also satisfying itself, and ultimately its regulator, that the data is secure. The firm put substantial work into interrogating the platform's security posture before committing. JAVLN states that both its Platform and Officetech products hold SOC 2 Type 2 certification,  an independent audit standard that tests a vendor's security controls over time rather than on a single day, with data hosted in accredited Australian and New Zealand data centres.

The regulatory climate rewards that caution. The FMA's record-keeping standard condition requires FAPs to create and maintain adequate records of their financial advice service. Those records must be kept in a form that ensures the integrity of the information, available for inspection, for a minimum of seven years.

That scrutiny extends beyond the systems a brokerage formally adopts. Industry research into so-called "shadow AI" - staff using AI tools that haven't been vetted or approved by their employer - has found the practice is now widespread in regulated sectors. A 2026 survey by data-security firm BlackFog found 49% of workers use AI tools their employer hasn't sanctioned, while separate research from Netwrix found only 21% of organisations have full visibility into what sensitive data flows into AI tools their staff are using. For a brokerage handling regulated client data, that combination – ungoverned tools plus limited visibility – is precisely the kind of gap a formal, vetted platform is designed to close. Tyson said the payoff shows up in how little client information now sits outside that system: "If I look out in the office, there's almost no paper around – it's all in the cloud and it's all secure."

Consistent advice, every client, every time

The less obvious compliance gain is behavioural. A brokerage is a collection of personalities, and Tyson is candid that different advisers approach the same job in subtly different ways – the risk being inconsistency in how the stages of advice are documented from one client to the next. The platform lets the firm set those stages, with key points to tick off as each file progresses, so the process is standardised regardless of who runs it.

"It's been really good for ensuring we're meeting our compliance points in an intuitive way," Tyson said.

That consistency is precisely what conduct regulation is probing for. Under CoFI, the FMA has taken an outcomes-focused approach, expecting firms to analyse how products are performing and act quickly when something is not working. Demonstrating that requires records that tell the same complete story for every client, not just the ones handled by the most fastidious adviser. Tyson also found the oversight function valuable from a management standpoint: Reviewing what has happened on a client file from a compliance point of view was a benefit he had not foreseen when the firm signed up.

The result, Tyson suggested, is that compliance stops being a separate workstream bolted onto broking and becomes a by-product of how the work is already done. The audit trail builds itself.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!