Under the Corporations Act 2001 (s912H), Australian financial services licensees — including insurance brokers — must retain records supporting the advice they give for at least 7 years. But the more expensive problem isn't the retention period. It's that AFCA can hear disputes about conduct going back up to 6 years from when a client first became aware of their loss, and by the time that complaint lands, the broker who handled it may have left, the laptop may have been wiped, and the emails that actually explain why a policy was structured the way it was may exist only as fragments in someone's "2022 Renewals" folder.

That's the scenario that actually costs brokerages money: not the retention breach itself, but standing in front of AFCA or a court unable to produce the email where you explained the exclusion the client is now disputing, or the one where they confirmed they didn't want business interruption cover added. Advice given verbally and confirmed by email, negotiated over a dozen back-and-forth messages, is only defensible if the whole trail survives — not just the final Statement of Advice.

What the regulation actually requires

For AFSL holders, s912H of the Corporations Act requires records that demonstrate a reasonable basis for the advice given to retail clients, retained for 7 years from when the advice was provided. ASIC's Regulatory Guide 104 (licensing obligations) and RG 175 (advice conduct) both assume those records include the correspondence around the advice, not just the formal Statement of Advice or Record of Advice document. For general insurance brokers specifically, the National Insurance Brokers Association (NIBA) Code of Practice reinforces the same expectation: brokers should be able to show what was recommended, why, and what the client agreed to.

The retention clock and the dispute clock don't run on the same schedule. AFCA's rules generally allow a complaint up to 6 years after the client became aware of the loss, or within 2 years of a firm's internal dispute resolution response — whichever is later. A policy placed in 2020 can still generate a live dispute in 2026. If your retention practice is "we keep the last 3 years," you're already exposed.

UK brokers work under a similar shape with different numbers. FCA's SYSC 9.1 and ICOBS require records to be kept for at least 5 years for most retail general insurance business, and the Financial Ombudsman Service can generally hear complaints up to 6 years after the event or 3 years from when the client reasonably became aware of it. Either way, the practical retention window a broker needs is longer than the regulatory minimum suggests.

What most small brokerages actually do

In practice, retention at a small brokerage usually means: email lives in Outlook or Gmail until someone's mailbox gets full, at which point it gets archived to a PST file, moved to a shared drive, or just left alone until the account is deactivated when the broker leaves. Sent mail is patchier than received mail — people forget it matters just as much. None of this is malicious. It's just what happens when there's no dedicated compliance function and email retention is nobody's actual job.

It holds up fine until someone needs to search it. A PST file from a departed broker's laptop, sitting on a shared drive since 2021, is technically "retained" but practically useless when your principal needs every email mentioning a specific policy number within 48 hours of an AFCA notice. Firms find this out the hard way — usually during the dispute itself, not before.

What good looks like

An audit-ready email archive for a brokerage has a few concrete characteristics, and none of them require a compliance department to achieve:

Continuous capture. Every email — sent and received, across every broker and every mailbox — is captured automatically at the point it's sent or received, not archived manually later when someone remembers. Manual archiving has gaps, and the gap is always in the email you needed.

Tamper-evident storage. Once captured, an email can't be quietly edited or deleted from the archive, even by the person who sent it. This matters more than most brokers expect: in a dispute, the other side's lawyer will ask whether the record could have been altered, and "no, technically" is a much better answer than "we don't know."

Full metadata. Headers, timestamps, attachments, and thread context need to survive intact — a forwarded email stripped of its original sender and timestamp is much weaker evidence than the full chain.

Fast, specific retrieval. You need to search by client name, policy number, or date range and get a complete result in minutes, not by asking IT to restore a backup and hoping.

Coverage of every mailbox, including departed staff. The broker who placed a policy in 2021 and left the firm in 2023 doesn't get to take the email record with them when their account is deactivated — see what actually happens to a departed employee's mailbox for the mechanics.

This is exactly the gap AutoArchive Mail is built for: it captures every mailbox continuously, stores messages in a tamper-evident archive with full metadata intact, and makes them searchable by client, policy, or date range without anyone having to remember to do anything.

The practical path forward

Start with a 30-minute audit: pull up your last three departed employees' mailboxes and confirm you can actually access and search their sent mail. If you can't, that's your priority gap. Next, write down an actual retention period — 7 years minimum for AFSL-regulated advice, longer if you want a buffer against AFCA's look-back window — and check it against what's really happening to mail after 90 days. Then move capture off manual habit and onto something automatic — here's how the capture and retrieval actually work — this is where a tool like AutoArchive Mail earns its keep, and it's worth trying against your own mailbox before rolling it out firm-wide — you can Start Free Trial and test retrieval on a real client file. If your brokerage has more than a handful of AFSL authorised reps, or you're already mid-dispute, get your compliance consultant or lawyer involved before you change process — retention policy changes made during an active complaint can look worse than no policy at all.

If your brokerage has fewer than 10 staff and no advice more than 3 years old, a disciplined manual process — consistent naming, a shared drive backup, someone actually responsible for it — may be adequate for now. The risk grows with headcount, tenure, and claims history, not with firm size alone.

This article covers email specifically. If your brokers are confirming advice over SMS, WhatsApp, or a CRM's internal notes, that record-keeping gap is separate and just as real — worth a second look, but not one this article solves.

Ready to automate your email archiving?

AutoArchive Mail captures every email automatically — incoming and outgoing — with clean filenames and full .MSG preservation. 14-day free trial, no credit card required.

Start Free Trial See How It Works

Related Articles

Compliance
PST Files: Your Hidden Compliance Time Bomb
Compliance
That Email You Deleted in 2023 Might Still Surface
Compliance
Litigation Hold vs. Standard Retention: Why It Matters
Compliance
Email Archiving for Accountants: What the ATO Actually Expects
← Back to all articles