Tuesday, September 8, 2026

Part 1 - SIRA Had a Compliance and Enforcement Policy. So What Happened to My Complaints?

Following directly from: “The Regulator Already Knew the System Was Failing”

In the previous instalment, I wrote about August 2022 and the increasingly serious concerns I was taking to the State Insurance Regulatory Authority — SIRA.


I was trying to get somebody to listen.


I was trying to get the regulator responsible for the NSW workers compensation system to look beyond an individual complaint and recognise what was much more serious: patterns of conduct, failures in injury management and return to work, the conduct of insurers and other scheme participants, and the consequences for injured workers when the system that’s supposed to protect them doesn’t work.


I kept asking about compliance.


I kept asking about enforcement.


I kept asking what SIRA was actually going to do with the information being given to it.


And there’s something important that needs to sit alongside that part of my story.


SIRA had a published Compliance and Enforcement Policy.


SIRA Compliance and Enforcement Policy, July 2017. SIRA publication catalogue no. SIRA08886. A copy of this publication was downloaded and retained when it was publicly available.


It was published in July 2017.


When I read that policy against what I was trying to report in 2022, I found myself asking an even more fundamental question:


What happened between the policy on the page and the injured worker asking the regulator to use it?


——


What SIRA Said Its Role Was


The 2017 policy began with SIRA’s regulatory objectives.


They included promoting the efficiency and viability of the insurance and compensation schemes, minimising the cost to the community of workplace injuries, promoting effective injury management and return-to-work programs, ensuring injured people had access to treatment that would assist their recovery, providing effective supervision of claims handling and disputes, and promoting compliance with the legislation.


These were not peripheral functions.


This was the regulator describing why it existed, and that matters enormously to me.

  • I was an injured worker trying to recover.
  • I was trying to return to my work.
  • I was trying to have injury management actually occur.
  • I was trying to have an insurer comply with its responsibilities.


I was trying to have somebody with regulatory authority look at what was happening rather than continually allowing the burden of identifying, documenting, reporting and somehow trying to correct it to fall back on me.


I wasn’t asking SIRA to invent a regulatory function for my benefit.


I was asking SIRA to perform the functions its own policy said it had.


——


SIRA Had Regulatory Tools




The policy then identified the regulatory tools available to SIRA.


They included education and engagement, licensing and supervision, complaints and dispute resolution, compliance activity, and enforcement activity.


That matters.


An injured worker making a complaint isn’t necessarily asking only for “customer service.”


A complaint can contain regulatory intelligence.


A complaint can reveal non-compliance.


A complaint can identify a pattern.


A complaint can expose a risk to other people in the scheme.


And according to SIRA’s own policy, its compliance function existed to ensure that parties within the schemes were conforming to legislation or policy. The policy expressly referred to audits of scheme participants, including employers and insurers.


That’s what I needed.


I needed someone to look at the conduct I was reporting and ask:


Is this compliant?


And if it isn’t:


What is SIRA going to do about it?


——


Compliance Was Not the Same as Enforcement


The policy went further.


It described enforcement as the function through which SIRA could use statutory regulatory powers to apply penalties and prosecute matters involving breaches of the legislation it administered. It also contemplated SIRA working with other law-enforcement agencies where appropriate.


That distinction is critical.


There was supposed to be an escalation pathway.


Education where education was appropriate.


Engagement where engagement was appropriate.


Compliance intervention where compliance was the problem.


And enforcement where the seriousness of the conduct required enforcement.


The policy expressly said that when non-compliance or limited compliance was identified, SIRA’s objective was to use an escalating method of enforcement.


But importantly, it didn’t say escalation always had to happen slowly.


SIRA recognised that the response didn’t necessarily have to be linear. The greater the risk and potential for harm, the policy said, the greater the enforcement response could be — ranging from warnings through to prosecution.


That matters when the subject is injured and vulnerable people.


It matters when the harm is continuing.


And it matters when somebody has been repeatedly telling a regulator that something is seriously wrong.


——


What Was SIRA Trying to Achieve?


The 2017 policy also explained what SIRA wanted compliance and enforcement to accomplish.


Among its stated aims were changing harmful behaviour by industry participants, reducing risks to the schemes’ objectives, improving scheme performance, clarifying the legislation and providing deterrence against deliberate non-compliance.


This was exactly why I kept speaking.

  • I wanted the conduct to stop.
  • I wanted compliance.
  • I wanted prevention.
  • I wanted accountability.
  • I wanted other vulnerable and injured workers protected from anything similar.

That’s one of the reasons I became increasingly frustrated when my complaints seemed to move around systems without anybody taking ownership of the regulatory question at their centre.


——


Then Comes the Most Important Part of the Policy: Risk


SIRA acknowledged in 2017 that it couldn’t investigate every allegation of non-compliance.


That’s understandable. No regulator has unlimited resources.


But SIRA didn’t leave it there.


It published criteria explaining the kinds of matters on which it would concentrate its regulatory resources.


SIRA said it would focus on matters that posed greater risks to its regulatory objectives; affected larger numbers of scheme participants; affected a group of people severely even where that group was not large; adversely affected vulnerable sections of the community; had longer-term consequences; demonstrated histories of systemic non-compliance or recidivism; involved significant public interest; or created risks capable of undermining community confidence in SIRA or the schemes it regulated.


Those terms stop me.


Vulnerable people.


Severe harm.


Systemic non-compliance.


Public interest.


Community confidence.


Those concepts were written into SIRA’s own regulatory policy.


I’m not saying that the existence of my complaint automatically proved that any person or organisation had breached the law. Allegations require proper assessment and evidence.


But that’s precisely the point.


Where was the assessment?


When I repeatedly provided information that demonstrated serious and continuing non-compliance, was that information assessed against these published risk criteria?


If it was, what was the outcome?


If it wasn’t, why wasn’t it?


——


What Could SIRA Actually Do?


The answer wasn’t simply “receive complaints.”


The policy set out actual regulatory tools.


SIRA could engage with a party.


It could conduct regular and targeted audits.


An organisation could be required to undertake an audit itself (note: not a good idea in my opinion), or be subjected to an audit by SIRA’s compliance team.


The policy said those audits could examine whether an organisation’s processes, structures and resourcing were sufficient to meet the objectives of the scheme.


SIRA could also issue formal written warnings where it reasonably believed a person or organisation had failed to comply with legislation, regulations or licence conditions.


And then there were investigations.


This part is particularly important.


The policy expressly said:


“An investigation may be as a result of a formal complaint, data analysis or intelligence obtained by SIRA.”


That’s what I had been trying to understand.


What happens when the information provided by an injured worker stops being treated merely as that worker’s individual “complaint” and starts being recognised as regulatory intelligence?


Because an investigation under the 2017 policy could result in considerably more than correspondence.


Potential outcomes included restrictions or conditions on licences, administrative penalties, civil or criminal prosecution and licence revocation.


——


SIRA Also Had Information-Gathering Powers


The final substantive section of the policy described significant information-gathering and investigative powers.


Depending upon the applicable legislation, SIRA officers and inspectors could enter insurer premises or workplaces, search for and copy evidence, in some circumstances seize evidence, compel organisations or individuals to produce information or give evidence, audit business records, apply administrative penalties, commence prosecutions and share information with other bodies.


This is why I find the experience of repeatedly trying to obtain regulatory intervention so difficult to reconcile with the policy.


I was one injured person.


I did not have statutory investigative powers.


I could not compel an insurer to produce records.


I could not audit an insurer.


I could not issue a penalty or commence prosecutions.


I could not investigate the wider scheme.


SIRA could.


That’s why regulators exist.


The person being harmed shouldn’t have to become the investigator, compliance officer, enforcement officer and archivist* of her own case simply to try to make a statutory system function.


*I am, however, a highly qualified information manager with over twenty years of professional experience. But the Independent Review Office also just accepted the deceit from Catholic Church Insurance that I was “always unfit for work” without ant independent verification whatsoever. 


Apart from having to demand IRO public servants to have CCI provide answers to my questions in writing, all the regulators had to do was Google me to learn if that was true or not. 


And why don’t we also ask my professional peers, clients and colleagues in academia, if that’s true or not? 


——


And Then, in August 2022, I Was Asking Again


This brings me directly back to the previous instalment.


On 17 August 2022, I contacted SIRA again.


Among the matters I raised were serious concerns about practitioner Deepinder Miller and her position as a SIRA-approved assessor. I supplied material that included numerous publicly posted reviews from other people describing their own alleged experiences. Those third-party reviews were allegations and personal accounts, not findings of fact, and I can’t independently verify them.


But I wasn’t asking SIRA to accept internet reviews as proof of wrongdoing.


I was asking the regulator whether the material warranted scrutiny.


I asked:


“What are you going to do about Deepinder Miller?”


And:


“When will this regulator start to enforce the law on all stakeholders in the scheme…”


SIRA responded the following day.


I was told:


“I have forwarded your concerns to SIRA’s specialist team responsible for the approval of permanent impairment assessors for their information.”


SIRA also referred me to the Health Care Complaints Commission. 


For their information.


But now put those words beside SIRA’s own 2017 policy.


A formal complaint could potentially initiate an investigation.


Regulatory intelligence could potentially initiate an investigation.


Risk assessment was supposed to consider vulnerability, severity, systemic patterns, public interest and community confidence.


SIRA possessed information-gathering powers.


SIRA possessed compliance powers.


SIRA possessed enforcement powers.


So what happened to the information?


That is the question.


——


What’s the current status of SIRA’s July 2017 Compliance and Enforcement Policy?


I downloaded and retained the policy when it was publicly available. It’s identifiable as a formal SIRA publication, including catalogue number SIRA08886. I’ve been unable to locate a subsequently published Compliance and Enforcement Policy replacing it.


If the July 2017 policy remains operative, where is the current authoritative version?


If it’s been withdrawn or superseded, when did that occur, what replaced it, and where can the public find the replacement?


Most importantly, what policy now governs how allegations of non-compliance are assessed, escalated, investigated and enforced?


——


See also:

I’m sure readers get the idea. There’s plenty more to come. The systemic harm caused by SIRA NSW continued. 

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.