For Australian mortgage brokers and brokerages
The loan settled two years ago. Who can still open the file?
Licences, payslips, bank statements, tax returns, debts and assets. Long after settlement most of it is still in a folder somewhere, and the list of people who can open it has only grown. APP 11 asks whether you still need to hold it at all.
Your IT provider secures the platform those files sit on. Cleverer proves the rest: who is responsible, what staff were trained on, what they acknowledged, and when access and retention were last reviewed.
Five minutes, no email required to see your result. For brokerages with staff, not for enterprise security teams.
Almost nothing about a client is missing from a completed application.
Not every brokerage collects every item on this list, and the mix changes with the lender. Read it as the shape of a typical file rather than a checklist.
- Identity documents Driver's licence, passport and Medicare details, often photographed and emailed rather than uploaded.
- Income evidence Payslips, employment letters, tax returns and notices of assessment.
- Full banking picture Statements covering several months of spending, which say more about a household than the applicant expects.
- Assets, debts and liabilities Other property, vehicles, credit cards, HECS, buy-now-pay-later and personal guarantees.
- Household and contact detail Addresses, dependants, relationship status, phone numbers and email addresses.
- Everything said along the way Notes, email threads and messages about health, separation, redundancy or family support.
Assembled in one folder, that is a more complete picture of a person than almost any other business holds. It is why brokerages are worth targeting, and why a client whose file leaks is unlikely to accept "we take security seriously" as an answer.
What happens to that information after the loan settles?
The application had a deadline and an owner. The file afterwards has neither. This is where most brokerages are genuinely exposed, and it has almost nothing to do with software.
- Access keeps growing and rarely shrinks Every person who helped on a deal usually still has the folder. Permissions are easy to grant during a busy month and easy to forget afterwards.
- Retention becomes a habit rather than a decision APP 11.2 asks entities to take reasonable steps to destroy or de-identify personal information once it is no longer needed, unless a legal retention requirement applies. Very few brokerages could say what their rule is, let alone show they follow it.
- Documents spread beyond the system of record A shared cloud drive is not the problem. The problem is when nobody can say who can reach it, what is in it, or why it is still there.
- Staff turn over faster than access reviews Loan processors, assistants and contract support move on. The offboarding checklist rarely covers every folder they touched.
- Nothing records what anyone was expected to do Handling expectations are usually spoken. Spoken expectations cannot be produced later.
To be clear about what is not being claimed: using Google Drive, Dropbox or SharePoint is not a compliance failure. Not being able to answer who can open a settled file, and why it is still open to them, is a different matter.
Your aggregator checks the advice. Your IT provider checks the systems. Neither checks this.
Already covered elsewhere
- Responsible lending files and compliance audits, through your aggregator or licensee
- Endpoint protection, patching and backup, through your IT provider
- Multi-factor authentication on email and CRM
- Lender portals and their own security controls
Cleverer does not replace any of it and does not supply technical security controls.
Sitting with nobody
- Which information handling obligations each role carries
- Dated proof each person completed the training
- Dated acknowledgement of the current handling policy
- A recurring access and retention review that leaves a record
- A log of concerns raised, and what was done about them
This is the half that gets tested after an incident or a complaint.
If a client, an insurer or a regulator asked today, what could you actually prove?
Answer as though you had to reply in writing this week, with documents attached.
- Can you list everyone who can currently open a settled client file? Including former staff, contract support and anyone whose access was granted for one deal.
- Can you state your retention rule, and show that the brokerage follows it? How long documents are kept, on what basis, and what happens when that period ends.
- Can you produce a dated training record for every person who handles client documents? Brokers, loan processors, administrators and anyone doing overflow support.
- Can you show who acknowledged your current information handling expectations, and when? Section 47 of the National Consumer Credit Protection Act already requires licensees to ensure representatives are adequately trained and competent for the credit activities authorised by the licence.
- Can you show that access was reviewed and removed when someone left? The CRM, the shared drive, the aggregator platform and the mailbox they had delegate rights to.
- Can you show a management review of information handling in the last 12 months? With a date, who was involved and what was decided.
- Can you show what happened after the last suspicious email or document request? Raised by whom, assessed how, closed when. Payment redirection attempts around settlement are not rare.
Ten questions, and an honest read on where the brokerage stands.
Short version of the full check. No email needed to see the result.
Privacy regulation in Australia has moved from guidance to monitoring.
The Privacy Commissioner said in March 2026 that the OAIC had deliberately moved toward enforcement over the previous year. The record she pointed to includes the first civil penalty ever imposed under the Privacy Act, $5.8 million against Australian Clinical Labs, proceedings on foot against Optus and Medibank, and a $50 million settlement with Meta. In January the regulator had run its first targeted compliance sweep, examining around 60 businesses' privacy policies against the Act instead of waiting for a complaint. Mortgage brokers were not among the six sectors it looked at.
The signal is not that brokers are next on a list. It is that the regulator has started looking at what businesses have actually implemented. APP 1.2 asks for practices, procedures and systems that are implemented, not for a policy that exists. The OAIC's own guidance on APP 11 treats reasonable steps as both technical and organisational measures, and puts governance, culture and training first among the areas to consider.
For an Australian credit licensee there is a second angle. Training and competence of representatives is a general conduct obligation under section 47 of the National Consumer Credit Protection Act, and ASIC sets out what it expects in RG 206. Training you cannot evidence is difficult to rely on in either conversation.
Cleverer makes the people side of this provable.
It runs alongside your CRM, your aggregator's requirements and your IT provider. It does not touch your systems or your files.
- Responsibility Every role in the brokerage carries a named set of information handling obligations. A loan processor's obligations are not a principal's. Both are written down and both are visible.
- Training Produce a dated training record without searching inboxes or spreadsheets. Assigned by role, completed by person, timestamped, and retained as evidence rather than as a certificate in a folder.
- Policies Know exactly who has acknowledged each current policy, and when. Update your handling or retention expectations and you can see immediately who has not accepted the new version.
- Oversight See overdue responsibilities and gaps before someone else finds them. Particularly useful for a principal running two or three offices who cannot watch every file.
- Review cycles Recurring reviews that happen on schedule and leave a record behind. An access and retention review becomes a dated event with an owner rather than a good intention.
- Issues Log a concern, show what was done about it, and close it out. The payment redirection attempt that got caught becomes part of your position instead of a story nobody wrote down.
What the brokerage can put in front of someone who asks.
Reasonable steps are judged on what was in place at the time. That is an argument won with records or lost without them.
- A dated register of who holds which obligation, and how it changed over time
- Training completion and certification per person, per role Exported as a report rather than reconstructed the week it is requested.
- Policy acknowledgement history against each version Who accepted what, on what date, against which version of the document.
- A management review trail covering access and retention Evidence that the brokerage reviews who can reach client files and why they are still held.
- An issues and escalation log Concerns raised, actions taken, dates closed.
Cleverer maintains organisational evidence. It does not provide technical security controls, it does not prevent breaches, and nothing here is legal advice.
Next step
Do not discover the gaps after an incident, a complaint or an insurance claim.
The Compliance Check scores the controls and the evidence separately. Most brokerages are comfortable with the first number and surprised by the second, and it is the second that decides how defensible you look.
Sources
- OAIC, APP guidelines, Chapter 11: security of personal information, covering APP 11.1 and APP 11.2.
- OAIC, APP guidelines, Chapter 1: APP 1.
- OAIC, Handling privacy complaints, a new approach for a new era (2 March 2026), and the January 2026 compliance sweep.
- ASIC, RG 206 Credit licensing: Competence and training, and RG 205 Credit licensing: General conduct obligations.