Pricing governance is a customer trust control, not just a marketing decision

The recent examples of pricing actions by regulators is not only about whether a promotion complied with the rules, it tests whether product, pricing, marketing, legal, compliance and customer teams shared the same view of what customers were being led to believe.

The 30-second take

When Coles, Woolworths and IAG each faced regulatory action over pricing, the issue in every case was the same gap,

the customer was told one thing and the pricing system did another.

These are not isolated compliance failures, they reveal a structural problem in how pricing governance is owned across product, marketing, operations and legal. The better question is not “do we have a pricing policy?” It is whether your organisation can show how pricing decisions are tested against customer outcomes before a regulator does it for you.

Leaders need to test how the issue moves through strategy, operations, suppliers, controls, customers and assurance, and whether the answers hold up under scrutiny.

Two industries, the same governance failure

In retail, the ACCC took both Woolworths and Coles to the Federal Court over what it described as illusory discounts — prices temporarily inflated before being promoted as reduced under “Prices Dropped” and “Down Down” campaigns. The Federal Court found Coles misled customers in 13 of 14 cases examined; the Woolworths judgment is still pending. In insurance, ASIC alleges IAG misled more than one million home insurance customers across its SGIO, SGIC and RACV brands — loyalty discounts were applied after base premiums had been increased, so customers who stayed loyal received no real benefit. IAG faces a $40 million penalty.

The pattern is consistent: a pricing decision was made, a customer promise was communicated, and the two were never reconciled at an organisational level.

“Risk maturity shows up when the organisation can explain the decision, the dependency and the evidence at the same time.”

Customer trust needs evidence before the campaign goes live

A weak risk conversation turns these events into generic compliance points. A stronger risk conversation asks what each event reveals about the operating model:

  • Who owned the customer outcome across pricing, marketing, legal and operations — and at what point did those teams share a common view?
  • What evidence showed the promotion was fair, clear and not misleading before it went live?
  • Which data would have revealed the gap between the pricing system and the customer promise earlier?
  • Does monitoring pick up weak signals before external pressure forces the issue?
  • Would assurance have found the problem — and if not, why not?

That is the shift from risk activity to risk maturity.

All organisations should stop treating these events as someone else’s news and start using them as scenarios to test its own decisions, dependencies and evidence.

The key risk management question

Can your organisation use these events to show how pricing risk is understood, owned, tested, escalated and challenged across the lifecycle — before a regulator, customer or external shock forces the issue?

Start by asking yourself and your executive team how your risk and governance is today and what are the key areas to focus on for tomorrow.


Innovation of Risk provides risk maturity and assessment tools to help organisations have better internal risk, governance and assurance discussions.

More from the Reading Room

When National Alerts Miss Local Needs: Queensland’s Opt-Out from AusAlert

Queensland opted out of AusAlert this bushfire season despite a 94% national test success rate. This isn't about whether that call was right — it's about the resilience discipline it illustrates: weighing your own specific variables today and making a definitive decision ahead of the event that will test it.

Regulator sharpens the warning on facial recognition

The OAIC has updated its facial recognition guidance for APP entities using biometric technology in high-volume, publicly accessible retail spaces. The update reflects the ART’s March 2026 Bunnings decision and reinforces that each deployment needs…

Risk Maturity in Action: Turning Customer Promises into Reliable Outcomes

Two recent ASIC matters provide a useful opportunity to think differently about risk management. They can be read as stories about compensation, penalties and compliance...

APRA’s Level 3 conglomerate standard reset is a governance issue

APRA has published its response to consultation on remaking the Level 3 conglomerate standards. This is a substantive prudential and governance update for groups with complex conglomerate structures, especially where superannuation, insurance and banking interests…