| Banks, insurers, super funds | APRA CPS 234, information security, including suppliers handling their information | Software that runs inside the client's environment with no network access by default, and an evidence pack that returns only aggregate results |
| Banks, insurers, super funds | APRA CPG 235, managing data risk | Data lineage, every figure computed as of its date, and the decision record |
| Banks, insurers, super funds | APRA CPS 220 and CPS 510, risk management and governance, where model risk expectations sit | Model cards, validation on later periods held out from tuning, and monitoring against outcomes |
| Banks, insurers, super funds | The Financial Accountability Regime | Decisions an accountable executive can defend, each kept with its evidence |
| Consumer lenders | NCCP and ASIC RG 209, responsible lending and verification | Income and expenses read from transactions rather than trusted as declared |
| Consumer lenders | AFCA and ASIC RG 271, dispute resolution | Reasons, and what would have changed the decision, with a record that can be traced |
| Anyone using bureau data | Privacy Act Part IIIA, credit reporting | Bureau data used inside the client's environment, only for the client's permitted purpose under their contract |
| Everyone | Privacy Act and the Australian Privacy Principles, including the automated decision making disclosure that applies from 10 December 2026 | Documentation of how each model works, written so a client can lift it into its own privacy policy |
| Open banking users | Consumer Data Right | Data received only within the arrangement it was collected under |
| Banks and payment providers | AML/CTF obligations and the Scams Prevention Framework | Account level monitoring for mule and scam behaviour, with alerts calibrated to the team's capacity |
| Everyone | Anti discrimination law | Proxies for protected attributes screened before a signal is used, and each customer judged against peers that operate the same way |