The Broker Times · Compliance
A Flag Is Not a Finding — But It Does Change What You Can Rely On
Document-analysis tools are arriving in broker workflows. The obligations they trigger were already written into the Credit Act and ASIC’s guidance. Here is the map.
The five anchors that govern what you do next
Every one of these applies whether or not you use a detection tool.
You must take reasonable steps to verify the consumer’s financial situation — not merely inquire about it.
National Credit Act 2009
Information counts only if you had reason to believe it was true — or would have, had you done the s 117 verification.
National Credit Act 2009
“The licensee must act in the best interests of the consumer in relation to the credit assistance.”
National Credit Act 2009
Where doubt is raised: set the information aside until confirmed, and corroborate from a separate source.
ASIC guidance, Dec 2019
Passing on inaccurate information is not acting in the client’s best interests — even if it helps approval.
ASIC guidance, June 2020
From flag to file note: the five-step response
A defensible sequence when something in a document does not reconcile.
What a document flag is — and is not
The distinction matters for your client, your file and your language.
It is
- A prompt to make further inquiries
- Evidence sitting inside an electronic file — edit history, prior references, inconsistencies
- Something you now have to deal with on the record
- Often explained by ordinary document handling
It is not
- A finding that a document is fraudulent
- A finding about your client’s honesty
- A regulator’s determination of anything
- A substitute for your own verification judgement
The question brokers keep asking
The worry“If I run a detection tool and it flags something, haven’t I just given myself knowledge I would rather not have had?”
What the Act sayss 118(4)(b)(ii) allows information to be taken into account where the licensee would have had reason to believe it was true had the s 117 verification been done. The benchmark is what reasonable verification would have shown — not what you happened to notice. Seeing less does not lower the bar.
The takeaway
The tools are new. The duty is not. What changes when detection software lands on the desk is the quality of the record you are expected to keep — and how hard it becomes to say the anomaly was not reasonably apparent.
General information only, current as at 15 September 2026. Not legal or compliance advice. Confirm your obligations with your licensee or compliance adviser.
outsource Financial Put Document Forensics on the Broker’s Desk. What Happens After a Flag Is Governed by Section 118(4)
A new aggregator tool reads the edit history hidden inside an electronic payslip. It will not tell you whether the document is fake — and that is precisely where your obligations start.
In this article
Key takeaways
- A flag is evidence, not a finding. The commentary given at launch was explicit that the system does not tell a broker whether a document is fraudulent.
- Using a detection tool does not create a new legal duty. Section 117(1)(c) of the Credit Act already requires reasonable steps to verify, and s 118(4)(b)(ii) measures you against what that verification would have shown.
- Once doubt is raised, ASIC’s RG 209.133 describes the reasonable response: set the doubtful information aside until confirmed, then corroborate it from an independent source.
- Mortgage brokers are not AUSTRAC reporting entities for arranging a loan. Your obligations run through the Credit Act, the best interests duty and your licensee’s policy.
- The file note is the deliverable. ASIC warns that records drafted at the end of a process may be less effective than contemporaneous ones.
What actually launched
In the week to 15 September, aggregator outsource Financial rolled out a document-analysis tool called Fraud Finder to brokers in its network. The Adviser reported the rollout date as 11 September. The premise is narrow and, for once, technically interesting: the tool inspects the electronic file itself rather than the page you see when you open it.
That distinction is the whole product. A PDF or a spreadsheet carries structure beneath the rendered page — revision data, prior content, references to other documents and files. None of it is visible when a payslip is printed or screenshotted, and none of it survives if a document is scanned. Steven Chamos, quoted by The Adviser in its report on the launch, put it this way:
“A document can look completely normal on the viewed page, but the electronic file itself may still contain a history of changes, who it previously referred to, or other inconsistencies that are not obvious to the naked eye.”
Steven Chamos, quoted in The Adviser, 15 September 2026
The more important quote is the second one, because it defines the tool’s limits and, by extension, where the broker’s own judgement has to take over:
“We are not telling a broker whether a document is fraudulent. Our system’s task is to surface the available evidence within an electronic file so the broker can make a better-informed decision.”
Steven Chamos, quoted in The Adviser, 15 September 2026
outsource Financial chief executive Tanya Sale framed the rollout in compliance terms rather than enforcement terms — “practical solutions that can support stronger compliance and verification processes without adding unnecessary complexity”, as she told The Adviser. The architecture is unusual too: on the aggregator’s account, documents stay on the broker’s own device and the platform never receives, stores or views them, which sidesteps the obvious question about who else ends up holding a client’s bank statements.
For now the tool is available to brokers inside the outsource Financial network. Australian Broker reported the same launch and described the tool consistently, though it dated the launch 14 September rather than 11 September and attributed a slightly different set of words to Sale. Where the two accounts differ we have gone with the detail each outlet published rather than blending them.
So much for the product. The reason this matters to every broker in the country — including the large majority who will never touch this particular tool — is what a flag does to a file.
The question brokers are asking about knowing too much
There is a version of this conversation happening in broker group chats that goes roughly: if I run a forensic check and it turns something up, I now have knowledge I did not previously have, and knowledge is exposure. Wasn’t I safer not looking?
It is an understandable instinct. It is also, on the face of the legislation, wrong — and the section that settles it is one most brokers have never read.
Section 117(1) of the National Consumer Credit Protection Act 2009 sets out what a licensee must do before making a preliminary assessment. Three limbs matter here: make reasonable inquiries about the consumer’s requirements and objectives; make reasonable inquiries about the consumer’s financial situation; and — separately — “take reasonable steps to verify the consumer’s financial situation”. Subsection 117(1) carries a civil penalty of 5,000 penalty units. The verification limb is not a restatement of the inquiry limb. It is an additional obligation, and it has been sitting in the Act since the start.
Then comes section 118(4), which is where the “safer not looking” argument falls over. When assessing whether a credit contract will be unsuitable, only information meeting both of two conditions may be taken into account. The first is that it concerns the consumer’s financial situation, requirements or objectives. The second, in the Act’s own words, is that at the time of the preliminary assessment:
“(i) the licensee had reason to believe that the information was true; or (ii) the licensee would have had reason to believe that the information was true if the licensee had made the inquiries or verification under section 117.”
National Consumer Credit Protection Act 2009 (Cth), s 118(4)(b)
Read limb (ii) again. The benchmark is not what you noticed. It is what reasonable verification would have told you had you done it. Deliberately seeing less does not lower the standard you are measured against; it just means you are measured against a standard you did not meet. The detection tool does not raise the bar. It makes it harder to argue you could not have cleared it.
The practical reframe
Document-analysis software does not import a new obligation into your business. It changes the evidentiary position — specifically, how plausible it is to say that an anomaly was not reasonably apparent. That is a records question before it is a liability question.
What “doubt” triggers under RG 209
ASIC’s Regulatory Guide 209, Credit licensing: Responsible lending conduct, is unusually direct about why the verification limb exists at all. At RG 209.48 it acknowledges that information provided in an application may not always be reliable, and lists three reasons: overstatement or understatement by the consumer through mistake or misunderstanding; mistake or negligence by someone assisting the consumer; and deliberate fraud by the consumer or by a person assisting them. Note the ordering. Two of the three causes are not dishonesty.
RG 209.50 adds that it is “not sufficient merely to rely on other persons providing true information about their financial situation”, and that “if other circumstances or information raise doubt about the information provided, it is reasonable to take steps to verify the true situation”. The guide’s note on that paragraph quotes the Financial Services Royal Commission interim report: “Verification calls for more than taking the consumer at his or her word.”
From there the guidance gets specific. RG 209.115 states that a licensee “should not rely on information if you have reason to believe it is not true”, and may need to seek further information to determine the true position. RG 209.116 identifies circumstances raising doubts about reliability, including “obvious inconsistencies”. And RG 209.132 — the paragraph that should be printed and stuck above every processing desk — discusses payslips directly, citing the Federal Court’s decision in ASIC v ANZ. On ASIC’s summary of that case, the lender failed to take reasonable steps to verify income where it relied solely on a purported payslip, in circumstances where it knew payslips were a type of document that was easily falsified.
RG 209.133 then sets out what a reasonable response looks like once doubt exists. Where doubts are raised, ASIC says it would be reasonable to not have regard to that information until additional steps have been taken to confirm its accuracy, and to take additional steps to confirm it — for example by obtaining a separate source of information, such as a transaction statement containing income information, to confirm whether a payslip is true.
That is the operative test for a flagged document. Park the figure. Corroborate it independently. Do not proceed on it in the meantime. It is not complicated, and it does not require software — but it does require you to have noticed.
Where best interests duty bites
Section 158LA of the Credit Act is a single sentence: “The licensee must act in the best interests of the consumer in relation to the credit assistance.” Credit representatives are covered by the equivalent obligation in s 158LE(1), with the licensee required under s 158LE(2) to take reasonable steps to ensure they comply.
ASIC’s RG 273 translates that into conduct, and three paragraphs bear directly on doubtful documents. RG 273.40 says that if it is reasonably apparent that information about a consumer’s circumstances is incomplete or inaccurate, you should make further inquiries to obtain complete and accurate information. RG 273.41 goes further: if critical information is not obtained, you should refrain from making a recommendation.
RG 273.42 is the one to sit with:
“A mortgage broker who provides incomplete or inaccurate information as part of a home loan application will not be acting in the consumer’s best interests, even if the inaccurate information would increase the likelihood of approval or give the consumer access to better terms.”
ASIC Regulatory Guide 273, RG 273.42
The clause after the comma is doing real work. A broker who reasons that submitting a stronger income figure gets the client a better rate, and that a better rate is in the client’s interests, has the logic exactly backwards. Best interests duty does not net off against outcome. Passing on information you have reason to doubt is not a service to the client even when it produces an approval.
The AUSTRAC question, answered properly
A live source of confusion deserves clearing up, because it has been muddied by a year of AML/CTF reform coverage.
Mortgage brokers are not reporting entities under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, and the Tranche 2 reforms that commenced on 1 July 2026 did not change that. The relevant designated service in the Act’s table is “making a loan, where the loan is made in the course of carrying on a loans business”, with the borrower as the customer. The entity that makes the loan is the lender. Arranging one is not a designated service, and the expanded professional-services items introduced by the reforms cover real estate transactions, entity formation and related work — not consumer or home loan broking.
The MFAA has made the same point in its member guidance on the changes, noting that the expansion to real estate agents, lawyers and accountants does not bring brokers into the AML/CTF regime, and that lenders often require brokers to carry out identification checks on their behalf. That last clause is the nuance worth holding onto: brokers routinely perform AML steps as agents of the lender, under the lender’s program, without themselves being accountable to AUSTRAC.
Separately, the FBAA has been seeking clarification from AUSTRAC on whether commercial asset finance broking is caught by the reforms — a different question, about a different activity, still open at the time of writing.
Why this matters for your response protocol
Because there is no suspicious matter reporting obligation sitting on you personally, there is no statutory report to file when a document looks wrong. Your escalation path is your licensee’s, and it is defined by your credit representative agreement and your aggregator’s policy — not by AUSTRAC. Brokers who assume otherwise tend either to over-report into a void or to freeze. Check what your licensee actually requires, in writing, before you need it.
What ASIC has actually said this year
ASIC Commissioner Alan Kirkland addressed mortgage fraud at the MFAA conference in Melbourne on 22 July 2026. His remarks were brief and worth quoting accurately, because they are being paraphrased loosely:
“This newer and complex form of mortgage fraud involves coordinated conduct across multiple parties… ASIC is working closely with APRA and AUSTRAC, the lead agency on these matters, as well as with the police and major banks. We are looking to better understand what controls, frameworks and operational settings are in place — with a focus on the roles of licensees, brokers and referrers.”
Alan Kirkland, ASIC Commissioner, MFAA Conference, 22 July 2026
In the same speech, on evidencing compliance, Kirkland said file notes are “not enough just to document” — that reasons “have to be personalised and meaningful”, and that “if the reasons for a recommendation are boilerplate factors that could apply to anyone, then it will be hard to demonstrate that the recommendation was in that customer’s best interests.”
One correction is warranted here. ASIC published an open letter to licensees and directors on 8 May 2026 (release 26-092MR) containing the widely circulated lines that a risk “is here now, evolving quickly and requires the attention of boards and executives”, and that licensees should “act now, and act with discipline”. Those quotes are genuine. But the letter is about frontier AI and cyber resilience: it does not mention payslips, bank statements, mortgages or credit applications. Some trade coverage has connected it to AI-generated loan documents. That framing belongs to the publications, not to ASIC, and brokers building a compliance case on it should know the difference. Where trade reporting and the underlying release diverge, the release governs.
Your five-step response protocol
When a document does not reconcile
- Park the figure, not the file. Stop treating the doubtful number as usable. RG 209.133 describes setting it aside until additional steps confirm its accuracy. The application does not have to stop — the reliance does.
- Corroborate from an independent source. ASIC’s own worked example is using transaction data showing income credits to test a payslip. A second document from the same origin is not corroboration.
- Go back to the client, neutrally. Most anomalies are innocent: a document re-saved by an employer, a template reused across staff, a file edited to redact an unrelated detail. Ask what the document’s history is before you assume anything, and record the answer in the client’s words.
- Escalate on your licensee’s terms. If it does not resolve, the decision is your licensee’s to make, not yours to make alone. Know now what your aggregator requires: who you notify, in what form, and what you are permitted to tell the client.
- Write the note while it is happening. RG 273.169 cautions that drafting notes at the end of the process may not be as effective as a contemporaneous approach, and RG 273.168 warns that keeping records only briefly puts you at risk of being unable to demonstrate compliance.
What the file note needs to contain
RG 273.165 sets out what broker records should generally include. Applied to a doubtful document, the useful subset is: what you observed and when; what inquiry you made of the client and what they said; what independent source you obtained and what it showed; whether you relied on the original figure, a revised figure, or neither; and the reasoning for the recommendation you ultimately made. RG 273.167 confirms the acceptable forms — file notes, correspondence, working papers, fact-finds, comparison tool outputs, audio recordings.
One phrasing point. A file note should record what you observed and what you did about it. It should not record a conclusion you are not qualified to reach. “Payslip metadata showed a prior revision; obtained three months of transaction data; income credits consistent with stated salary; proceeded on verified figure” is a defensible note. “Client submitted a fraudulent payslip” is a finding, and unless it has been established, it is one you should not be making in writing.
What to review this week
None of this requires buying anything. Four things are worth an hour:
- Find your escalation path. Open your credit representative agreement or licensee compliance manual and locate the section on suspected document irregularities. If you cannot find it in ten minutes, email your compliance team and ask. Discovering the process mid-file is the worst time to learn it.
- Check whether you already have a second source. Most brokers using an open banking or transaction-data service already hold the corroborating information RG 209.133 describes. The question is whether anyone reconciles it against the payslip, or whether both simply travel to the lender.
- Audit your last ten file notes for the reasoning, not the facts. Kirkland’s boilerplate warning is the cheapest compliance improvement available. If your notes would read identically for any client, they are not doing the job RG 273 expects of them.
- Decide your language in advance. Agree with yourself, before it happens, how you will raise an anomaly with a client without accusing them of anything. The conversation goes better when it is a question about a document rather than a question about a person.
The strategic point
Broker-side verification technology is going to keep arriving, from aggregators, from lenders and from third parties, and the marketing will keep framing it as protection. It is protection — but the more consequential effect is quieter. Every tool that makes an anomaly easier to see shrinks the space in which “it was not reasonably apparent” is a credible answer.
That is not a reason to avoid the tools. Section 118(4)(b)(ii) already measures you against verification you should have done, which means the defensive value of not looking was always an illusion. It is a reason to fix the thing the tools cannot fix: a documented, rehearsed, licensee-endorsed process for what happens in the twenty minutes after something does not reconcile. The brokers who have that will treat a flag as a workflow step. The ones who do not will treat it as a crisis — and will make the decision that matters under pressure, on a deadline, with a client waiting.
Frequently asked
Does running a document-analysis tool increase my legal exposure?
On the face of the legislation, no. Section 118(4)(b)(ii) of the Credit Act allows information to be taken into account where the licensee would have had reason to believe it was true had the s 117 verification been carried out. The standard is what reasonable verification would have revealed, not what you personally noticed. What a tool changes is how difficult it becomes to argue an anomaly was not reasonably apparent.
A tool flagged a document. Do I have to tell the lender?
That depends on your licensee’s policy and on what you ultimately rely on. What ASIC’s RG 209.133 describes is not having regard to the doubtful information until you have confirmed it, and taking additional steps to confirm it. What you submit must be information you have reason to believe is true. Your licensee or compliance adviser should tell you what notification their process requires — this is one to settle in advance rather than in the moment.
Do I have to lodge a suspicious matter report with AUSTRAC?
Mortgage brokers are not reporting entities under the AML/CTF Act for arranging a loan — the designated service is making the loan, and the reporting entity is the lender. The Tranche 2 reforms that commenced on 1 July 2026 did not bring mortgage broking into the regime. Brokers commonly perform identification steps as agents of a lender under that lender’s program, which is a different thing from holding the obligation yourself.
What if the client’s explanation is plausible but I cannot verify it?
RG 273.41 addresses this directly: where critical information is not obtained, ASIC says you should refrain from making a recommendation. That is uncomfortable commercially and it is the guidance. Record the inquiry you made, the response, and why the information remained unconfirmed.
Is Fraud Finder available if I am not with outsource Financial?
Based on the launch coverage, the tool has been rolled out to brokers within the outsource Financial network. Neither The Adviser nor Australian Broker reported availability beyond that network. Brokers elsewhere should ask their own aggregator what document-verification capability sits in their platform today.
Sources
- The Adviser, “outsource Financial launches new Fraud Finder for brokers”, 15 September 2026
- Australian Broker, “outsource Financial launches Fraud Finder to combat document fraud”, September 2026
- National Consumer Credit Protection Act 2009 (Cth), ss 117, 118, 158LA, 158LE — Compilation No. 52, compilation date 1 July 2026
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), s 5, s 6 Table 1 item 6, s 41 — Compilation No. 62, compilation date 1 July 2026
- ASIC Regulatory Guide 209, Credit licensing: Responsible lending conduct, 9 December 2019
- ASIC Regulatory Guide 273, Mortgage brokers: Best interests duty, June 2020
- Alan Kirkland, ASIC, “The best interests duty: A blueprint for building trust”, MFAA Conference, 22 July 2026
- ASIC 26-092MR and accompanying open letter to AFS licensees and market participants, 8 May 2026
- MFAA member guidance on AML/CTF changes; AUSTRAC, “Who and what we regulate”
Breaking news for modern brokers
Policy shifts, lender moves and compliance changes — read in the time between appointments.
Broker Tool
Something Doesn’t Reconcile. What Now?
Answer three questions about the document in front of you and get the sequence ASIC’s guidance describes — then work the file-note checklist while it is still fresh.
Contemporaneous file note
Work through these while the matter is live. RG 273.169 cautions that notes written at the end of a process may be less effective than a contemporaneous approach.
0 of 7 recorded
Nothing you tick is saved or transmitted — this checklist resets when the page reloads. Write the record in your CRM, not here.
Compliance moves that actually change your files — without the filler.
General information only. This tool summarises publicly available ASIC guidance and does not constitute legal or compliance advice. Your licensee’s process governs.
Disclaimer: This article is for general information and professional development purposes only. It does not constitute legal, compliance, or financial advice. Brokers should consult their aggregator’s compliance team and, where required, seek independent legal advice regarding their obligations under the National Consumer Credit Protection Act 2009 and ASIC’s responsible lending guidelines.
