Morning light and eucalyptus shadows on the limestone wall of an Australian home

Trust & compliance

The compliance is in the architecture.

Brokerfront is the platform; the firms we serve hold the licences. So we don't ask you to trust a policy document — we build each obligation into a mechanism that produces its own evidence, automatically, on every file. Here is the map, regulation by regulation.

The plain claim first. Open any row for how the platform builds it in and the evidence it produces.

Every recommendation is reviewed, owned and signed by a licensed broker.

Best Interests Duty · NCCP s158LA/s158LE · ASIC RG 273

How the platform builds it in

Recommendations cannot be one-click approved. A licensed broker reviews a frozen comparison basis (every lender considered, why each won or lost, what would change the answer), resolves or reasons past information gaps, adopts or amends the drafted reasons, attests to best interests and conflicts, and signs.

The evidence it produces

The approval record: who signed, the exact frozen basis they reviewed, what they edited, what they attested to and how long they took. It sits on a trail nobody can edit and rolls up into the firm's supervision view, with review durations and rubber-stamp flags.

The reasons behind a recommendation are frozen before the client sees them.

Evidence of the recommendation · RG 273.165–.169 (records), s120 NCCP (preliminary assessment)

How the platform builds it in

Every comparison shown to a client is frozen as a reasoning trace before they see it: rates used, all options considered, near-misses, sensitivity analysis. Rate refreshes can never silently change what was said.

The evidence it produces

A per-file compliance pack: one printable document with the full record set, generated from the trail rather than reconstructed.

Once written, a record can't be changed, and it keeps for seven years.

Complete, unaltered records · NCCP record-keeping · RG 273.165 · CR Code

How the platform builds it in

Open any file and the trail is there, and nothing on the platform can rewrite it: the database itself refuses an edit or a delete, whoever asks. Loan files carry a seven-year retention guard, and a firm that leaves is closed off while its trail stays.

The evidence it produces

The refusal rule and the retention guard live in the database schema, and the rare permitted deletion is itself recorded with its legal basis.

No personalised comparison appears until the client has accepted the disclosures.

The advice boundary · ASIC RG 203 (Example 10/12)

How the platform builds it in

The credit guide is delivered and the fee quote accepted by the client's own tap before the first personalised lender comparison will render. That's enforced in code, not by a disclaimer, and the assistant can't accept it, claim it or work around it.

The evidence it produces

Timestamped disclosure events with document versions, per file.

Serviceability is computed the way lenders compute it, and the assessment is written down.

Responsible lending · NCCP ss115–120 · ASIC RG 209

How the platform builds it in

Structured fact-find with code-enforced completeness; document extraction with per-field confidence; serviceability computed the way lenders compute it (APRA +3% buffer, HEM floors, income shading), per lender, with the same inputs giving the same answer every time.

The evidence it produces

The written preliminary assessment: a computed “not unsuitable” verdict with the serviceability numbers behind it, generated from the frozen basis and retrievable for seven years.

A loan file cannot skip a stage of its legal life.

Process integrity · NCCP process integrity · RG 273

How the platform builds it in

Every status change runs through a legal state machine with evidence gates: a file cannot become “recommended” without a licensed broker's approval of a frozen basis, client authority requires a completed Credit Proposal, and “lodged” requires a gateway application reference. There is no code path around it.

The evidence it produces

A transition event on the audit log for every stage change, carrying the evidence that satisfied its gate.

No data is collected about a client without their own recorded consent.

Consent before collection · Privacy Act APPs 3 & 5 · CR Code

How the platform builds it in

Consent is an engine, not a checkbox: explicit, timestamped, versioned consents recorded on the file, captured only by the client's own tap. A credit-file pull or identity check is refused in code, before any vendor is contacted, unless the matching consent exists and hasn't been withdrawn.

The evidence it produces

Consent records with document versions on every file; refusal events where a pull was attempted without one.

The AI assists; it never decides. Every action it takes is logged.

AI accountability · ASIC REP 798

How the platform builds it in

The assistant prepares and a broker decides. Every number comes from a calculation engine that gives the same answer for the same inputs, never from the model. The recommendation narrative is written only from the frozen record, and every figure and lender name in it is checked against the facts before anyone sees it. Anything that doesn't match is rejected.

The evidence it produces

Every AI action logged and attributable; model and prompt versions stamped on every narrative; evaluation suites run against the live models.

A product the client isn't eligible for on the recorded facts is never ranked for them.

Target market distribution · DDO · ASIC RG 274

How the platform builds it in

Target-market filters run inside the matching engine itself, on the facts recorded on the file, so an ineligible product is dropped before the ranking is drawn.

The evidence it produces

Per-lender eligibility reasons recorded on every comparison.

Complaints run on the statutory clock, from intake to outcome.

Complaints handling · ASIC RG 271 (IDR) · AFCA

How the platform builds it in

A complaints register with intake on every surface (the public site, the assistant and Workspace), with the 24-hour acknowledgement and 30-day resolution timers computed and tracked, and escalation to AFCA recorded per case.

The evidence it produces

The register itself: every complaint's clock, actions, outcome and AFCA reference, exportable, with lifecycle events on the audit log.

Only verified licensees can go live with clients.

Licensee verification · NCCP licensing · ASIC Credit Registers

How the platform builds it in

A firm's licensing identity is structured data: ACL, ABN or ACN, credit-rep number and AFCA membership, each checksum-validated and checked against the government registers. A firm can't activate a paid, client-facing plan until it passes.

The evidence it produces

The verified licensing record per firm, and audited activation-blocked events when the gate refuses.

Consumer data sits behind the right accreditation, closed by default.

Consumer Data Right · Consumer Data Right (Treasury/ACCC)

How the platform builds it in

Today: public Product Reference Data only, whole-of-market rates discovered from the open CDR register, no consumer data. Consumer-consented bank data arrives via the accreditation ladder (trusted-adviser and CDR-representative arrangements), a gate that is enforced in code and defaults closed, with Privacy Act controls and hard tenant isolation.

The evidence it produces

Data-quality guards and freshness quarantine on every ingested rate; per-tenant isolation re-proven by an automated auditor on every code change.

Hand-drawn records strongroom: an open vault flanked by shelves of sealed ledgers

The compliance pack

Every loan file exports a regulator-ready record: disclosures with timestamps, the frozen comparison basis, the broker's signed approval, the full audit trail. Generated from the log, never reconstructed.

The governance kit

Firms onboard with an AI governance policy template, consumer AI disclosure copy, and a human-review path: the three gaps ASIC's REP 798 found across the industry, addressed in the onboarding box rather than left to each firm.

Caged by code, not prompts

Verification flags the AI cannot write. Checklist evidence it cannot fake. Consents it cannot click. Numbers it cannot invent. Stages it cannot skip; history it cannot erase. The guardrails are in the type system and the database, not in polite instructions.

See it, don't take our word

The best way to test any claim above is a 20-minute walkthrough on a live file: watch the disclosure gate fire, open the broker ceremony, export the compliance pack. Compliance officers welcome. Bring your hardest questions.

Request a compliance walkthrough

Brokerfront provides technology to licensed credit businesses. It does not hold an Australian Credit Licence and does not provide credit assistance; regulatory obligations described here rest with the licensee, supported by the platform's mechanisms. Vendor-dependent checks (identity, credit bureau, document verification, lodgement) run against certified providers as part of production activation; until a firm activates, the platform runs them against conformant mock adapters and labels the results as such. Nothing on this page is legal advice.

Related: how we compare · the glossary · the platform

Reviewed by the Brokerfront team ·