The recent examples of pricing actions by regulators is not only about whether a promotion complied with the rules, it tests whether product, pricing, marketing, legal, compliance and customer teams shared the same view of what customers were being led to believe.
The 30-second take
When Coles, Woolworths and IAG each faced regulatory action over pricing, the issue in every case was the same gap,
the customer was told one thing and the pricing system did another.
These are not isolated compliance failures, they reveal a structural problem in how pricing governance is owned across product, marketing, operations and legal. The better question is not “do we have a pricing policy?” It is whether your organisation can show how pricing decisions are tested against customer outcomes before a regulator does it for you.
Leaders need to test how the issue moves through strategy, operations, suppliers, controls, customers and assurance, and whether the answers hold up under scrutiny.
Two industries, the same governance failure
In retail, the ACCC took both Woolworths and Coles to the Federal Court over what it described as illusory discounts — prices temporarily inflated before being promoted as reduced under “Prices Dropped” and “Down Down” campaigns. The Federal Court found Coles misled customers in 13 of 14 cases examined; the Woolworths judgment is still pending. In insurance, ASIC alleges IAG misled more than one million home insurance customers across its SGIO, SGIC and RACV brands — loyalty discounts were applied after base premiums had been increased, so customers who stayed loyal received no real benefit. IAG faces a $40 million penalty.
The pattern is consistent: a pricing decision was made, a customer promise was communicated, and the two were never reconciled at an organisational level.
“Risk maturity shows up when the organisation can explain the decision, the dependency and the evidence at the same time.”
Customer trust needs evidence before the campaign goes live
A weak risk conversation turns these events into generic compliance points. A stronger risk conversation asks what each event reveals about the operating model:
- Who owned the customer outcome across pricing, marketing, legal and operations — and at what point did those teams share a common view?
- What evidence showed the promotion was fair, clear and not misleading before it went live?
- Which data would have revealed the gap between the pricing system and the customer promise earlier?
- Does monitoring pick up weak signals before external pressure forces the issue?
- Would assurance have found the problem — and if not, why not?
That is the shift from risk activity to risk maturity.
All organisations should stop treating these events as someone else’s news and start using them as scenarios to test its own decisions, dependencies and evidence.
The key risk management question…
Can your organisation use these events to show how pricing risk is understood, owned, tested, escalated and challenged across the lifecycle — before a regulator, customer or external shock forces the issue?
Start by asking yourself and your executive team how your risk and governance is today and what are the key areas to focus on for tomorrow.
Innovation of Risk provides risk maturity and assessment tools to help organisations have better internal risk, governance and assurance discussions.

