Speaking as part of an IMAP MDA360 webinar series sponsored by Mason Stevens, Jesse Vermiglio Partner at Holley Nethercott and Stephen Hughes, AJ Gallagher discussed the aspects of Professional Indemnity insurance for MDA Providers and Advisers.
PI insurance for Managed Discretionary Account (MDA) providers operates under a materially different framework to the general financial services regime — and, as a recent IMAP MDA 360 webinar made clear, understanding that distinction matters more than ever as ASIC prepares to roll over the MDA instrument in October.

By IMAP
Jesse Vermiglio
Partner
Holley Nethercote

Stephen Hughes
Senior Adviser
A J Gallagher

PI insurance is a mandated risk management
A tailored and less prescriptive regime
Jesse Vermiglio, partner at Holley Nethercote, opened by framing PI insurance as mandated risk management: a consumer protection mechanism ensuring sufficient financial resources exist to compensate retail clients for losses, with an added emphasis on guarding against misappropriation given the discretion MDA providers exercise over client assets.
The technical differences from RG 126 are significant. Where financial advisers' PI cover is governed by section 912B and a detailed regulatory guide setting minimum cover of at least $2 million (up to a $20 million cap based on revenue), MDA providers instead face a minimum covering the lesser of $5 million or the average value of client portfolio assets over the preceding 12 months.
Notably, the MDA legislative instrument lacks RG 126's extensive lists of required inclusions and exclusions — automatic reinstatement, defence costs in addition to the sum insured, retroactive cover and so on. Vermiglio's view is that most of these would likely still be expected under the instrument's overarching "adequacy" requirement, even without being explicitly listed. Both regimes are focused squarely on retail client losses, so Vermiglio suggested licensees check carefully whether their policy also extends to wholesale clients

MDA operators carry a different risk profile to traditional advisers precisely because of ongoing discretionary decision-making
Claims lessons from the coalface
Stephen Hughes of AJ Gallagher followed with practical claims experience, noting that MDA operators carry a different risk profile to traditional advisers precisely because of ongoing discretionary decision-making — a trend he expects AI and automation to accelerate. He observed that the largest claims are typically triggered by investment losses, but that these then expose underlying governance failures: misclassification of wholesale investors, poor suitability assessment, and inadequate oversight.
Two case studies illustrated the point. In one, a wholesale-classified couple's SMSF investment via an MDA became a dispute once AFCA revisited their classification — opening years of discretionary trading decisions to scrutiny, rather than any particular single recommendation. In another, a leveraged FX strategy complaint expanded well beyond performance once classification issues surfaced, becoming a broader governance case.
Hughes walked through common policy traps:
- conflict-of-interest exclusions that can be broadly worded to exclude fraud-related claims;
- related-party and high-leverage investment exclusions;
- assumed-liability-under-contract exclusions that can catch outsourcing arrangements;
- the importance of continuous retroactive cover when switching insurers, given new insurers typically exclude "known circumstances."
- a single excess can multiply into multiple deductibles if a collapsed fund is deemed by the insurer to be separate complaints from multiple clients.
On cyber, Hughes noted 95% of incidents stem from human error rather than sophisticated hacking, and stressed that PI and cyber policies serve different purposes — cyber policies typically cover
- incident response,
- extortion or ransom
- business interruption and
- data restoration,
PI responds to advice and investment-decision disputes. Hughes urged licensees to check whether their cyber wording explicitly captures AI-enabled attacks, given many policies appear silent on the point.
Responding to audience questions, both panellists agreed that liability for fraud in underlying investments (a live issue given the Shield and First Guardian matters) still depends on establishing the AFSL's civil liability — typically for inadequate due diligence in approving a product — rather than the fraud itself, which cannot be insured directly.
For a full version of the webinar including CPD points visit IMAP Connect

About
Jesse Vermiglio is a Partner at Holley Nethercott, and
Stephen Hughes is a senior insurance adviser at AJ Gallagher
They spoke on the topic ‘PI Insurance for MDAs: Different Risks, A Different Regime’ as part of an IMAP MDA360 webinar series sponsored by Mason Stevens