Australia’s banks have told a Senate committee that the humble payslip has stopped being evidence. In a 20 July appearance before the Senate Select Committee on Productivity, the Australian Banking Association argued that generative AI has made fake income documents trivial to produce, and asked Parliament to let the Australian Taxation Office share a borrower’s own tax data with their lender through the Consumer Data Right. For brokers, this is not a distant policy debate — it is the beginning of the end of the document-collection workflow your business is built on.
Key Takeaways
- The ABA has formally asked Parliament for consent-based ATO income data sharing via the Consumer Data Right, framing it as both a productivity fix and a fraud defence.
- ABA chief executive Simon Birmingham told the committee that AI is making “fake payslips and doctored statements frighteningly easy to produce”.
- The Government committed $62 million in the May budget to explore extending consumer sharing of ATO-held data — a signal, not yet a rule.
- Open finance is already moving: non-bank lenders began sharing CDR product data on 13 July 2026, with consumer data sharing from 9 November 2026 for the first cohort.
- Brokers who still run on emailed PDFs are carrying risk that verified data feeds will strip out — and lender policy will move before the legislation does.
In This Article
- The Pitch: What the Banks Actually Asked For
- Why Now: Forgery Became a Commodity
- The Billion-Dollar Number That Changed the Conversation
- The Plumbing: Why the CDR Is the Chosen Pipe
- The Open Finance Clock Is Already Running
- What Verified ATO Data Would Not Fix
- What This Means for Australian Brokers
- Five Moves Worth Making Before the Rules Catch Up
- What to Watch Between Now and November
- The Bottom Line
The Pitch: What the Banks Actually Asked For
The ABA’s opening statement to the Senate Select Committee on Productivity, published on 20 July, is mostly about regulatory cost — the association cites roughly $160 billion a year spent by Australian organisations complying with federal regulation, and backs an economy-wide stocktake with a 25 per cent cost reduction target by 2030.
But the concrete reform it put in front of the committee is narrower and far more relevant to broking. As the statement puts it, today the ATO cannot share a customer’s own tax information with their bank even when the customer explicitly asks for it. The ABA’s proposed fix is a secure, consent-based channel for ATO data to reach lenders through the Consumer Data Right, for the purpose of credit decisions. Birmingham described the current process — customers manually assembling payslips, tax returns and bank statements — as “an anachronism in the digital age, unnecessarily burdensome for customers, and creates unnecessary risk in our financial system”.
The productivity framing is deliberate
Note where this argument was made. Not to ASIC, not to a fraud roundtable, but to a productivity inquiry. The ABA is selling faster approvals first and fraud prevention second — a framing that gives the reform a constituency beyond risk teams.
Why Now: Forgery Became a Commodity
The technical reality behind the submission is uncomfortable. Generative AI tools now produce income statements, payslips and identity documents with correct formatting, plausible employer details and internally consistent figures — in seconds, using consumer-grade tools rather than specialist criminal infrastructure.
The traditional verification stack was never designed for that. It assumed forgery was expensive, slow and detectable by a trained eye: a misaligned logo, a font that didn’t match, arithmetic that didn’t add up across three months of pay cycles. Every one of those tells has been automated away. Birmingham’s line to the committee is the sharpest summary of the industry’s position: “The single best defence against fake income documents is real income data — and the ATO already holds it.”
It is worth being precise about what is and isn’t established here. The ABA is describing a trend it says is growing, not publishing a quantified fraud rate. No regulator has published a figure attributing a specific share of Australian mortgage fraud to AI-generated documents, and the submission draws no causal line between AI availability and any particular loss number.
The Billion-Dollar Number That Changed the Conversation
What gave the ABA’s argument weight in the room was a case already on the public record. Earlier in 2026, Commonwealth Bank reported itself to police over concerns that around $1 billion in home loans may have been obtained using fraudulent documentation.
Appearing at the same inquiry, CBA’s executive general manager of financial crime compliance, Kylie Rixon, told the committee the bank was spending close to $1 billion this financial year on preventing financial crime, and described economic crime as “a material productivity drain on the Australian economy”.
Read that pairing carefully — it is the whole argument in miniature. One side of the ledger is a bank spending a billion dollars to detect bad documents after they enter the system. The other is a proposal to stop unverifiable documents entering it at all. Framed that way, ATO data sharing looks less like a technology upgrade and more like a cost-avoidance strategy banks will pursue regardless of how fast the legislation arrives.
The Plumbing: Why the CDR Is the Chosen Pipe
The banks did not ask for a bespoke ATO-to-lender data feed. They asked for it to run through the Consumer Data Right — and that choice tells you a lot about how this will land in your process.
The CDR is consent-based by design: the consumer authorises a specific recipient to receive specific data for a specific purpose and period. That architecture already exists, is already audited, and already has accredited data recipients operating in banking. Bolting ATO income data onto it is a rules-and-legislation problem rather than a build-from-scratch problem. It also means the consent moment sits with the borrower, not the broker. In a mature version of this, income verification becomes something the client authorises in a portal in ninety seconds — not something you chase over four emails and a reminder text.
The Government committed $62 million in the May budget to explore extending consumers’ ability to share ATO-held data. That is a scoping commitment, not a start date. Brokers should treat it as a direction of travel with an uncertain arrival time.
The Open Finance Clock Is Already Running
Whatever happens with ATO data, the CDR itself is expanding into the part of the market brokers use most.
- 13 July 2026 — product data sharing obligations commenced for the non-bank lending sector, meaning non-bank product reference data now flows through the same regime as the banks.
- 9 November 2026 — consumer data sharing begins for the initial cohort of in-scope non-bank lenders, those with more than $10 billion in loans and leases.
- 10 May 2027 — consumer data sharing obligations extend to large providers.
This is the quiet structural story of 2026. Open banking is becoming open finance, and the non-bank sector — where a great deal of specialist, self-employed and near-prime volume sits — is being pulled inside the perimeter. Combine that with digital identity infrastructure opening to private sector participants from December 2026, and the direction is unambiguous: verified data feeds are replacing customer-supplied documents as the default evidentiary standard.
What Verified ATO Data Would Not Fix
Brokers should resist the idea that a data pipe solves lending risk. It does not.
- It verifies income, not capacity. Living expenses, undisclosed liabilities, buy-now-pay-later commitments and household circumstances remain assessment problems, not data-retrieval problems.
- It lags. ATO data is strongest for prior financial years. A borrower who changed employer, went contracting, or took a pay cut three months ago is exactly the case where lodged tax data tells you the least.
- Self-employed complexity survives. Add-backs, trust distributions, retained profits and one-off events still require judgement — which is precisely the ground brokers earn their fee on.
- Identity fraud is a different attack. Verified income attached to a synthetic or stolen identity is still fraud. Income data closes one door.
- It is not law yet. A budget commitment to explore a reform is not a commencement date, and tax secrecy provisions are not trivial to amend.
What This Means for Australian Brokers
The immediate risk for brokers is not regulatory — it is reputational and operational.
Brokers are generally not the reporting entity under the AML/CTF regime; the lender is. But you sit at the point where documents enter the chain. If a file you submitted contained fabricated income evidence, the question of what you saw, what you checked and what you recorded becomes very live — under your credit licence obligations, under Best Interests Duty, and in whatever accreditation review follows.
ASIC has already signalled that mortgage broking is a credit focus area, with attention on Best Interests Duty compliance, complaints handling, and audit and compliance practices. A broker whose file notes show a considered verification process is in a materially different position to one whose notes show a forwarded PDF.
The second effect is competitive. When verified income feeds arrive — through the CDR, through open banking transaction data, or through lender-side tools — the brokers who have already moved clients onto digital data-sharing flows will approve faster than those still running on email attachments. Speed to unconditional will become a data-plumbing question as much as a relationship question.
Five Moves Worth Making Before the Rules Catch Up
None of this requires waiting for legislation. Five practical steps:
- Move income and transaction capture into a verified digital flow now. If your aggregator platform supports open banking bank statement retrieval, make it the default rather than the exception. Customer-supplied PDFs should be the fallback, not the standard.
- Write down what you actually checked. Not “payslips sighted” — record the specific consistency checks: employer name against ABN lookup, YTD figures against pay cycle arithmetic, net pay against credits in the account. If a file is later questioned, contemporaneous notes are the only defence that carries weight.
- Build a short internal red-flag list and use it every time. Payslips with no discernible metadata, YTD amounts that don’t reconcile to pay dates, bank statements where salary credits don’t match the payslip employer, documents that arrive already converted to image formats, and clients unwilling to use open banking when it is offered.
- Have the consent conversation early. Clients increasingly expect to authorise data sharing rather than assemble documents. Position it as faster and more secure, because it is — and it puts your process on the right side of where the market is heading.
- Talk to your aggregator about the November CDR milestone. If a meaningful share of your book sits with non-bank lenders, ask now what changes on 9 November 2026 and what tooling will be available to you.
What to Watch Between Now and November
Three markers will tell you how fast this moves.
The Senate committee’s report. Whether ATO data sharing appears as a recommendation determines whether the $62 million turns into a rules process or sits in a drawer.
Lender policy, not legislation. Watch for individual lenders mandating open banking retrieval for certain applicant types, or declining static PDF statements outright. Policy moves faster than statute, and this is where brokers will feel the change first.
The 9 November CDR milestone. When the first non-bank lenders begin sharing consented consumer data, the verification gap between banks and non-banks starts to close — reshaping where specialist deals can be placed quickly.
One countervailing signal: new Statements of Expectations issued for APRA and ASIC in mid-July put economic growth and reduced regulatory burden more explicitly in the frame. A deregulatory mood can accelerate a reform sold as removing friction — or slow anything that adds obligations to a data holder. Both readings are live.
The Bottom Line
The banks have made a clear-eyed argument to Parliament: manual document collection is slow, expensive and now structurally insecure, and the fix is to let borrowers point lenders at authoritative data they already own. It is a reasonable proposal, it has budget attention, and it has an existing regulatory vehicle in the CDR. What it does not have is a start date.
Brokers should not wait for one. The verification shift is arriving through lender policy and the open finance rollout regardless of what happens to the ATO proposal, and the practical work — digital data capture, disciplined file notes, an honest red-flag process — is worth doing on its own merits. If AI has made a payslip easy to fake, the correct response is not to look harder at payslips. It is to stop relying on them. Watch the committee’s report, watch your panel’s document policies, and watch 9 November: the brokers who move first will spend 2027 approving faster than the ones still asking clients to scan things.
Disclaimer: This article is for general information and professional development purposes only. It does not constitute legal, compliance, or financial advice. Brokers should consult their aggregator’s compliance team and, where required, seek independent legal advice regarding their obligations under the National Consumer Credit Protection Act 2009 and ASIC’s responsible lending guidelines.

