Broker guide
Structuring a Mortgage Broker Compliance Manual in 2026
To assign compliance duties across your brokerage, build a mortgage broker compliance manual with a credit licence outsourcing policy and review owners.
- Published
- Updated
A mortgage broker compliance manual gives every procedure in your brokerage an owner, an approver, a review trigger and a version history. Staff then know what to do on a live file, who decides when something goes wrong and which record proves it happened.
Build the manual around the client-file lifecycle, then add the credit licence policies for complaints, hardship, debt collection, privacy, credit reporting, outsourcing and risk management. Owning a template doesn’t make a brokerage compliant. The manual counts when staff follow it and your records show they did.
Set Governance
Start the manual with a governance table that gives each procedure an owner, an approver, a review trigger and a version history. The owner keeps the procedure current, while the approver signs off each change before staff use it.
The Australian Securities and Investments Commission (ASIC) explains the expectation in Regulatory Guide 205 (RG 205), issued 1 April 2020. A holder of an Australian credit licence (ACL) needs a written plan that documents its compliance arrangements. RG 205 expects that plan to name who is responsible, the timeframes and the record keeping and reporting involved.
RG 205 also expects a review when your obligations, your business or its operating environment change. Write those changes into each procedure as review triggers, so a review happens on a named event as well as a date.
RG 205 suggests an external compliance review after major breaches or repeated compliance failures. The guide to mortgage broker compliance services explains how to choose outside help to tailor or review the manual.
If your brokerage works as a credit representative under an aggregator’s licence, the licensee’s policies govern your credit activity. Your manual then records how your team carries out those policies, who in your office owns each step and which licensee contact receives escalations.
| Governance field | What to record | Example entry (fictional) |
|---|---|---|
| Owner | The role that keeps the procedure accurate and answers staff questions | Credit manager |
| Approver | The role that signs off a change before staff use it | Principal |
| Review trigger | Events that force a review, plus a fixed review date | Licensee policy update, complaint about this step, failed file sample, 12 months since approval |
| Version history | Version number, date, change summary, approver and the date staff acknowledged it | Version 1.3, approved 10 September 2026, adds a written-clarification step |
| Linked records | Where staff save the proof that the procedure was followed | Client file notes in the customer relationship management (CRM) system |
Outsourcing and Risk Management Policies
A credit licence outsourcing policy names each function a provider performs for you and how you check the work. RG 205 lists commonly outsourced functions, including record-keeping systems, representative training, compliance reviews and debt collection.
The licensee stays responsible for an outsourced function. RG 205 expects due skill and care in choosing the provider, ongoing monitoring of its performance and a response when it breaches the service agreement or your obligations. Give each outsourced function an internal owner who reviews the provider’s reports and keeps the exit plan current.
Use the guide to outsourcing loan processing for the provider controls and exit steps. Your manual only needs the owner, the review trigger and a link to that procedure.
A credit licence risk management policy lists the risks to your clients and your licence, the control for each one and how you test the control. RG 205 expects a structured process that identifies risks, sets controls and monitors whether the controls work. Keep the risk register in the manual and link each risk to the procedure that controls it.
Worked Example: A File With Conflicting Income Evidence
A procedure is useful when it tells staff what to do with a real file. Kestrel Lane Finance is a fictional brokerage. Dana is the principal, Omar is a broker and Lily is the processor.
Omar’s client applies with a payslip showing a base salary of $92,000 a year. The employer’s letter states $73,600, because the client moved to a four-day week last month. The manual turns that conflict into five recorded steps.
| Manual element | What happens on Kestrel Lane’s file (fictional) |
|---|---|
| Staff action | Lily marks the file “income conflict” and stops lodgement. Omar asks the client which hours they work now and requests a current letter. |
| Policy source | The lender’s income verification policy, saved to the file with the date it was read, and Kestrel Lane’s verification procedure, version 1.3 |
| Escalation owner | Dana, the principal, decides which income figure the file uses if the documents still conflict |
| Decision record | A file note stating that the $73,600 figure applies because it reflects current hours, with Dana’s name and the date |
| Retained proof | Both documents, the client’s written explanation and any written clarification from the lender |
Without the manual, the file relies on Omar’s memory of a phone call. With it, a reviewer can see what was found, who decided and why the lower figure went into the serviceability assessment.
Policy Exceptions
Record a policy exception before you rely on it. A fictional example is a lender whose standard policy asks for two years in the same industry, while the client has 20 months.
- Define the exact variance, such as 20 months against the 24-month standard.
- Attach the supporting evidence, such as the employment contract and the previous role in a related field.
- List the compensating factors, such as a 70% loan-to-value ratio (LVR) and genuine savings held for 12 months.
- Send the request through the channel your licensee approves, such as the lender’s business development manager (BDM) or credit scenario team.
- Record who responded, their role and the date and time of the reply.
- Mark whether the reply is indicative support or a credit approval. Indicative support from a BDM is not a credit decision.
- Set an expiry or recheck date, such as 30 days or the date the lender’s policy next changes, whichever comes first.
Lender Scenario-Enquiry Template
A scenario enquiry asks a lender one precise question and gets a written answer you can keep. Send only the facts the lender needs, and leave out the client’s name, date of birth, address and account numbers.
| Field | What to write | Example entry (fictional) |
|---|---|---|
| Decision sought | The single question you need answered | Will you accept 20 months in the same industry for this applicant? |
| Borrower facts | Material facts only, using an applicant reference | Applicant A, pay as you go (PAYG) registered nurse, permanent full-time, 20 months in nursing after six years in aged care |
| Security facts | Property type, location type and value basis | Standard residential house, metropolitan, contract price $750,000 |
| Policy variance | The rule and how far the file sits outside it | Two-year industry requirement, four months short |
| Compensating evidence | Facts that reduce the lender’s risk | 70% LVR, 12 months of genuine savings, no other debts |
| Servicing position | How the file services, with the calculator and date | Services on your calculator as at 2 October 2026 |
| Available documents | Documents you hold now | Two payslips, employment contract, 12 months of savings statements |
| Response requested | The form, scope and validity of the answer | A written reply stating whether it applies to this scenario only and the date it should be rechecked |
Save the lender’s reply with the exception record. If the reply covers only part of the question, record what remains open before the file moves on.
Lender Panel Governance
Name who approves the lender panel your brokerage uses and who reviews it. ASIC’s Regulatory Guide 273 (RG 273), issued 24 June 2020, expects a broker to be accredited with a reasonably representative panel. The broker must also be satisfied that the products they can access let them act in each client’s best interests.
Review the panel against policy coverage, your clients’ needs, accreditation status, service performance and conflicts of interest. Keep broker feedback on turnaround and policy clarity, and record each decision to add or drop a lender with its reasons.
An aggregator’s commercial arrangement with a lender doesn’t prove the lender suits your clients. RG 273 says to tell a client when a lender they ask about is outside your panel.
If your panel can’t meet a client’s best interests, RG 273 says not to provide credit assistance, and a referral to another broker can help. Write that off-panel route into the manual, with the approver and the record it needs.
Define Client-File Controls
Connect intake, assessment, recommendation, disclosure and retention through one file lifecycle, so each procedure hands the file to the next with its records complete. RG 273 (issued 24 June 2020) lists the records ASIC generally expects. They include the credit guide, the information given to the lender, relevant client conversations and the reasons for the recommendation.
| Lifecycle stage | Procedure in the manual | Record that closes the stage |
|---|---|---|
| Intake | Identity, privacy statement, credit guide, initial needs and objectives | Signed privacy consent, credit guide issued, needs recorded |
| Assessment | Income, expenses, liabilities, deposit and security checks | Verified documents and the responsible lending assessment |
| Recommendation | Options compared, conflicts checked, best interests reasoning | Options presented, recommendation and reasons |
| Disclosure | Commission and fee disclosure, product information | Disclosure documents issued and acknowledged |
| Retention | Storage, access limits, retention period and disposal | File closed, location recorded, disposal date set |
The manual names the procedure for each stage. Use the mortgage broker compliance checklist for the file-level review points within each stage.
Clients Who Need Extra Support
Adapt communication to the needs the client tells you about. Book longer appointments, send documents ahead and check understanding by asking the client to explain the loan in their own words.
Use a qualified interpreter when the client needs one. A family member or friend can attend as a support person, but the manual states that they can’t answer for the client or sign on their behalf without legal authority.
Watch for signs of coercion or unsafe participation, such as a companion who answers every question or a client who seems afraid to speak. Ask whether the client would like to speak privately, protect the client’s contact details and escalate to the owner named in the manual. Don’t assume a companion can consent for the borrower.
Suspected Application Fraud
A suspected fraud case tests whether the manual controls the file. Check identity, income, liabilities, deposit, occupancy and document consistency against each other, and look for edits, mismatched dates or details that don’t match other records.
- Stop lodgement and verify the doubtful item independently, such as calling the employer on a number you found yourself.
- Preserve the original documents, emails and metadata without editing them.
- Restrict file access to the incident owner and the people they name.
- Escalate to the lender and to the licensee through the channels the manual names.
- Let the incident owner control all communication with the client and any remediation.
Licensees assess whether the matter must be reported to ASIC. ASIC’s Regulatory Guide 78 (RG 78), issued 19 December 2023, gives licensees 30 calendar days to report a reportable situation, so record the escalation date.
Cover Complaints, Hardship and Debt Collection
Write each of these three policies as staff actions, escalation points and required records. A new staff member can then act on the day a client complains, reports hardship or owes the brokerage money.
| Policy | Staff action | Escalation | Required records |
|---|---|---|---|
| Dispute resolution | Acknowledge the complaint and log it the same day | Complaints owner, then the licensee’s internal dispute resolution (IDR) team when the licensee runs it | Complaint register entry, dates, response and outcome |
| Hardship | Explain that the lender decides and help the client contact the lender’s hardship team promptly | Broker, then principal if the client is in urgent need or vulnerable | Date of request, referral made, client consent and follow-up |
| Debt collection | Follow the policy before chasing any unpaid fee or passing a debt to a collector | Principal approves any referral to a collector | Debt amount, contact history and the collector’s agreement |
Dispute Resolution Policy
A credit licence dispute resolution policy sets out how you receive, record and answer complaints. ASIC’s Regulatory Guide 271 (RG 271), issued 2 September 2021, applies to credit licensees, including brokers. It expects acknowledgement within 24 hours or one business day, and a written IDR response no later than 30 calendar days after the complaint arrives.
Include the client’s right to take the complaint to the Australian Financial Complaints Authority (AFCA). RG 271 sets 21-day timeframes for complaints about default and hardship notices, but those apply to the credit provider, not the broker.
Hardship Policy Template
A credit licence hardship policy template tells staff how to help a client who can’t make repayments. Moneysmart, as at October 2026, says the lender must consider a hardship request and must give reasons if it refuses.
Your policy covers the broker’s part:
- Record the date the client raised hardship and what they said.
- Tell the client the lender’s hardship team assesses the request and give its contact details.
- With the client’s consent, send the lender the information the client asks you to pass on.
- Refer the client to the National Debt Helpline on 1800 007 007, which Moneysmart lists for talking to a financial counsellor.
- Follow up with the client on a set date and record the lender’s response.
Debt Collection Policy
A credit licence debt collection policy applies when your brokerage chases money a client owes it, such as an unpaid broker fee. ASIC’s debt collection guideline, Regulatory Guide 96 (RG 96), issued 13 April 2021, applies to creditors who collect their own debts and to collection agencies.
Set contact limits, require written records of every contact and name who approves a referral to a collector. Treat that referral as outsourcing, so the outsourcing policy’s checks apply.
Licensee Duties and Delegated Tasks
Separate the obligations that attach to the credit licensee from the tasks it delegates to representatives or processors. RG 271 says the licensee’s IDR procedure must cover disputes about its credit representatives, so a representative doesn’t need its own ASIC-standard IDR process. ASIC’s credit representatives information sheet (INFO 126), as at October 2026, says most credit representatives must still hold their own AFCA membership.
| Obligation | Who holds it | Task delegated | Evidence a supervisor reviews when the control fails |
|---|---|---|---|
| IDR procedure | Licensee | Broker logs and acknowledges complaints | Register entry, acknowledgement time, response date and root cause |
| AFCA membership | Licensee and most credit representatives | Principal keeps membership current | Membership record and renewal date |
| Monitoring and supervising representatives | Licensee | Credit manager samples files | Sample results, defect log and coaching record |
| Hardship referral | Lender assesses, broker refers | Broker records and refers | Referral date, client consent and follow-up note |
When a complaint misses its acknowledgement time, the supervisor reviews the register entry, the staff member’s training record and the procedure version in use. The fix goes to the procedure owner, who decides whether the procedure or the training changes.
Govern Privacy and Information Risk
Give the privacy, information-security, retention, incident and continuity procedures each an owner, an approver, a review trigger and a version history. Keep the operating steps in the separate procedures, and keep the governance in the manual.
| Procedure | Owner (fictional) | Approver | Review trigger | Version history |
|---|---|---|---|---|
| Privacy | Principal | Principal | Privacy law change, complaint or new collection method | Version, date and change summary |
| Information security | Practice manager | Principal | Security incident, failed test or new system | Version and date, with test results referenced |
| Retention and disposal | Practice manager | Principal | Licensee or lender record rule change | Version, date and disposal log reference |
| Incident response | Principal | Licensee contact | Every incident and every response test | Version, date and incident reference |
| Continuity | Principal | Licensee contact | Staff change, test or real outage | Version, date and test date |
Privacy Policy and Privacy Statement
A credit licence privacy policy explains how your brokerage handles personal information. The Office of the Australian Information Commissioner (OAIC) published its guide to developing an APP privacy policy on 5 May 2014. It says Australian Privacy Principle (APP) 1.3 requires a clearly expressed and up-to-date policy covering the topics in APP 1.4.
A mortgage broker privacy policy is a public document. A privacy statement is the notice and consent a client receives when you collect their information. The OAIC guide says the privacy policy doesn’t replace that APP 5 notice, so a credit licence privacy statement template needs its own owner and review trigger.
The OAIC guide also says participants in the credit reporting system need a policy about credit-related personal information. Record in the manual whether your licensee’s policy covers that or your brokerage keeps its own.
Linking the Information-Security Procedure
Link the manual to the mortgage broker information security procedure for daily protection, breach response and continuity steps. The manual records what makes the governance change: an incident, a test result or a regulatory change.
Under the OAIC’s Notifiable Data Breaches scheme, as at October 2026, an organisation must notify affected people and the OAIC when a breach is likely to cause serious harm. After any incident, the procedure owner records the incident reference in the version history and decides whether the procedure changes.
Credit Reporting Procedure Template
A credit licence credit reporting template covers access requests, correction requests, the notices you must give and complaints. The OAIC’s credit reporting guidance, updated 23 September 2025, says a business that processes credit applications for a credit provider can have credit reporting obligations. Those rules sit in the Privacy Act, the Privacy (Credit Reporting) Code 2014 (Version 2.3) and the Privacy Regulation 2013.
| Request or matter | Staff action | Timeframe (OAIC guidance as at October 2026, or internal standard where marked) | Record |
|---|---|---|---|
| Access request | Log the request and route it to the credit provider or credit reporting body that holds the information | Route it on the day it arrives (internal standard) | Date received, holder contacted, outcome |
| Correction request | Log it and consult the other credit provider or credit reporting body if you can’t make the correction yourself | Correction within 30 days, or a longer period the client agrees to | Request, consultation, correction made or reasons for refusal |
| Notices | Send written notice of a correction, or written reasons for a refusal with the client’s complaint and external dispute resolution options | Correction notice within a reasonable period, and refusal reasons in writing | Copy of each notice |
| Complaint | Acknowledge, investigate and decide | Acknowledge within 7 days and decide within 30 days, asking for an extension before day 30 if needed | Complaint record, decision and any extension agreed |
The OAIC calls the correction rule a no wrong door approach. The complaint timeframes apply to credit providers and credit reporting bodies, so name the licensee or lender contact who handles a request that belongs to them.
Govern Staff Competence
Give induction, mentoring, continuing professional development (CPD), policy training and competence evidence each an owner, a review trigger and an escalation path. INFO 126, as at October 2026, sets the training for credit representatives who provide home loan credit assistance. They need at least a Certificate IV in Financial Services (Finance/Mortgage Broking) and 20 hours of CPD each year.
The licensee stays responsible for competence even when training is outsourced. RG 205 (issued 1 April 2020) gives the example that a licensee who outsources training must still make sure its representatives are competent and adequately trained.
| Competence area | Owner (fictional) | Review trigger | Escalation path |
|---|---|---|---|
| Induction | Credit manager | New starter or changed role | Principal if induction isn’t complete before the first client file |
| Mentoring | Principal | Mentee’s first files and each quarterly check-in | Licensee if mentoring stops |
| CPD | Each broker, checked by the credit manager | Six months before the CPD year ends | Principal if hours fall behind |
| Policy training | Procedure owner | Each new procedure version | Credit manager if acknowledgement is missing after five business days |
| Competence evidence | Credit manager | File sample results and complaint outcomes | Principal, then licensee for a material concern |
Linking the CPD Procedure
Link the manual to the mortgage broker CPD requirements guide for role-specific planning, assessment and register fields. The manual records which events trigger more learning or supervision.
- Missed CPD evidence leads to a catch-up plan with a due date set by the credit manager.
- A failed assessment leads to retraining and a second assessment before the broker works on that file type unsupervised.
- A policy change leads to a short briefing and a signed acknowledgement from each affected staff member.
- A recurring file defect leads to supervised files until three in a row pass review.
Build Usable Procedure Pages
State the purpose, steps, required records, exceptions and escalation route on every procedure page. A page with all five tells a staff member what to do, what to save and who to call when the file doesn’t fit.
| Procedure page field | What to write |
|---|---|
| Purpose | One sentence on what the procedure protects, such as accurate income in the serviceability assessment |
| Steps | Numbered actions in order, with the role that performs each one |
| Required records | The document, note or system entry that proves each step happened |
| Exceptions | What counts as an exception and the exception record it needs |
| Escalation route | The role to contact, how to reach them and the response time |
| Governance | Owner, approver, review trigger and current version |
Give advertising its own procedure page too. The mortgage broker marketing guide covers review controls for active campaigns.
Revision Log
A revision log links each change in lender rules or regulatory guidance to the procedures it affects. It also records staff acknowledgement and the sample-file check that confirms staff apply the change.
| Column | Example entry (fictional) |
|---|---|
| Date logged | 3 September 2026 |
| Source and its effective date | A fictional lender’s income policy update, announced 1 September and effective 15 September 2026 |
| Procedures affected | Income verification, version 1.2 to 1.3 |
| Change made | Adds a written-clarification step for conflicting income documents |
| Approver | Principal, 10 September 2026 |
| Staff acknowledgement | All three credit staff by 12 September 2026 |
| Sample-file check | Two files with income conflicts sampled in October 2026 |
The log shows the procedure changed and staff applied it. It doesn’t establish compliance alone, because the files themselves still need review.
Credit-Team File Sampling
Sample credit-team files on a set schedule and after named events. Kestrel Lane samples each new broker’s first five files, two files after each procedure change, any file linked to a complaint and two random files a month.
- Check the scenario facts in the file notes against the documents.
- Check that each policy source is saved with the date it was read.
- Classify each defect as minor, moderate or material. A material defect could change the recommendation or the client’s outcome.
- Escalate a material error to the principal the same day, and to the licensee as its procedure requires.
- Feed each correction into coaching for the staff member involved.
- Report recurring causes to the procedure owner, who decides whether the procedure changes.
Check AML Duties for the Actual Credit Activity
Identify which entity performs which service before you decide what anti-money laundering and counter-terrorism financing (AML/CTF) duties apply. The Australian Transaction Reports and Analysis Centre (AUSTRAC) lists loans or finance as a designated financial service, as at October 2026. That service is the lender’s.
When a broker arranges a home loan, the lender provides the loan. Your duties usually come through the lender’s and aggregator’s identification procedures, which set what you verify and record for them. A brokerage that also provides another listed service needs to check that service separately.
AUSTRAC says updated AML/CTF laws took effect on 31 March 2026 for existing reporting entities. Newly regulated businesses came under the new laws from 1 July 2026, with enrolment due by 29 July 2026. The newly regulated real estate service is brokering the sale, purchase or transfer of real estate, such as work by buyer’s and seller’s agents.
Record the steps that apply to your brokerage:
- Customer identification, following the lender’s or aggregator’s verification procedure for each application
- Escalation of unusual activity to the lender and the licensee, through the channel the manual names
- Recordkeeping, with identification records kept in the place and for the period the lender or aggregator requires
- Training, so staff who identify customers complete the lender’s or aggregator’s AML/CTF training
Base the AML procedure on the services your brokerage provides, and confirm whether those services make it a reporting entity. Make the procedure owner check AUSTRAC’s current scope and commencement guidance before the brokerage adopts a new control or quotes a deadline.
Act on Lender Policy Changes
When a lender policy update arrives, record the lender, the source document, the announcement date, the date the rule applies and the borrower or security class it affects. The announcement date and the effective date often differ, and open files depend on the effective date.
Then find every open file that relies on the earlier rule. Assign each one to its broker for review, and record whether the recommendation continues, changes or goes to the escalation owner, with the reason.
| Step | What Kestrel Lane records (fictional) |
|---|---|
| Capture | Fictional lender, policy update announced 18 September 2026, applies to applications lodged from 1 October 2026, affects applicants with variable income |
| Open files | Three files with that lender rely on the earlier income rule |
| Broker review | Omar reviews all three by 23 September 2026 |
| Decision record | Two continue because they lodge before 1 October, and one moves to another lender with the reason recorded |
| Reference update | Lender reference sheet version 2.1 replaces 2.0 for new files, and 2.0 is kept for the existing-file review |
| Staff briefing | Lily and Omar acknowledge the change on 24 September 2026 |
Update the team’s reference material and explain the changed requirement to affected staff. Keep the earlier version, because files lodged under it are still judged against it.
Bulma alerts brokers when a lender policy they’ve asked about changes. Each answer shows the date Bulma last updated that policy, which helps you match a file note to the version you relied on.
Keep Live Files Moving During Incapacity
Nominate an authorised continuity contact and keep a secure live-file register, so someone can find every deadline if the broker can’t work. Choose someone the licensee can authorise to act, or the licensee’s own nominated person.
| Register field | What to record |
|---|---|
| Applications | Lender, stage and the date of the next action |
| Conditions | Outstanding conditions and the date each is due |
| Settlement deadlines | Settlement date, finance clause date and contact for the other side |
| Client communications | Last contact, promised next contact and preferred channel |
| Complaints | Open complaints, response due dates and the IDR contact |
Store the register where the continuity contact can reach it under controlled access, without using the broker’s own login.
Handoff When a Sole Broker Can’t Work
Suppose a fictional sole broker, Sam, is hospitalised for six weeks with eight live applications. The continuity contact opens the register and contacts the licensee the same day.
- Confirm with the licensee who may act. INFO 126, as at October 2026, says a credit representative works within the licensee’s written authorisation, so only an authorised person can provide credit assistance on Sam’s files.
- Check the aggregator agreement, lender accreditations and any contract that limits who can act.
- Arrange controlled access to the records through the licensee’s or practice’s own accounts, with each access logged.
- Tell each client who now owns each deadline, starting with finance clause and settlement dates.
- Record every handover in the file notes.
Don’t let a colleague log in with Sam’s credentials or sign as Sam. If Sam dies, the estate’s questions go to a lawyer, while the licensee decides who services the clients. Name your continuity contact this week, then test the register with them before you need it.