Skip to main content

Broker guide

Mortgage Broker Compliance Services Compared 2026

Need mortgage broker compliance services for a practice gap? Compare support for file audits, manuals, training or advice by method and accountability.

Published
Updated

Mortgage broker compliance services are file audits, compliance manual development, staff training and ongoing advice from an external provider. Choose the service that matches the gap you’ve found, then choose a provider that can show its method on a difficult file.

Outsourcing compliance moves the work to a provider, while the credit licensee stays responsible for the result. ASIC’s Regulatory Guide 205 (RG 205, April 2020) lists periodic compliance reviews and training among the functions licensees commonly outsource. It also says the licensee remains responsible for those functions.

If your brokers are credit representatives under an aggregator’s licence, the aggregator is the licensee. It must take reasonable steps to make sure its brokers meet the best interests duty. An external mortgage broker compliance company then adds the checks your brokerage wants on top of the aggregator’s.

Define the Compliance Gap

Start with the outcome you need, whether that is a review of past files, written procedures, trained staff or answers to new questions. Each outcome matches one service type, and the matrix below compares them on the same terms.

ServiceUse it whenWhat you receiveWhat stays with the brokerage
File auditYou need to know whether recent files meet your obligationsFindings on a sample of files, ranked by severity, with a correction for eachFixing the files, changing practice and deciding whether a finding must be reported to ASIC
Manual developmentYour procedures are missing, out of date or don’t match how staff workWritten procedures, templates and a review scheduleAdopting the manual, training staff on it and keeping it current
TrainingAudit findings repeat across brokers, or new staff are joiningSessions, materials and attendance recordsMeeting competence and CPD requirements, and checking staff apply what they learned
Ongoing adviceQuestions come up between audits, such as a complaint, a new product or a possible breachWritten answers within an agreed response timeActing on the advice and making the final decision

A file audit finds the gaps, and a manual or training closes them. Start with an audit when you don’t yet know where your gaps are. The compliance manual guide explains what the procedures themselves contain.

Training has a measurable floor. ASIC’s Regulatory Guide 206 (April 2020) expects representatives who give third-party home loan credit assistance to complete at least 20 hours of continuing professional development (CPD) each year. The CPD requirements guide covers what counts towards those hours.

How Each Service Reviews a Difficult File

A difficult file shows how differently the four services work. In this fictional file, Priya runs a business that has traded for 14 months, and her broker refinanced her loan to a lender that accepts one year of financials.

The broker’s note says “lender accepts 1 yr trading”, with no policy wording or date. The fact find records that Priya asked about an offset account, but the note doesn’t say why the recommended loan has none. The file also has no copy of the credit guide Priya received.

A file audit tests each part of the file against evidence:

  • Source-policy verification. The reviewer finds the lender’s policy that applied when the broker made the recommendation, then confirms Priya met it. A note with no policy wording or date is recorded as a gap, even when the policy did allow the loan.
  • Suitability reasoning. The reviewer checks that the notes show Priya’s requirements and the reasons for the loan recommended. ASIC’s Regulatory Guide 273 (June 2020) expects records of the options, the recommendation and why it was made.
  • Disclosure evidence. RG 273 also expects a copy of the credit guide given to the client, so the missing copy is a separate finding.
  • Severity. The reviewer rates each gap by its effect on the client and on your ability to show compliance. A missing reason for dropping the offset account ranks above a formatting gap, because the broker can’t show the recommendation was in Priya’s best interests.

The other services start from the same file but produce different work. Manual development asks why the gaps happened, then writes the missing step, such as a file note template with fields for policy wording and reasons. Training uses the file as a case study, and ongoing advice answers a specific question, such as whether a pattern of missing credit guides is a reportable situation.

Ask each provider how it rates a missing control compared with a one-off slip. A missing control, such as no procedure requiring brokers to record their reasons, affects every file and ranks higher. A broker who skipped an existing step on one file needs coaching, while the control itself works.

Quoted policy wording makes source verification faster for any reviewer. Bulma’s Policy Advisor quotes the lender’s policy wording in each answer, with the date Bulma last updated that policy, and brokers can copy both into their file notes.

Evaluate the Provider

Evaluate a mortgage broker compliance company on its Australian credit experience, its review method and samples of its work. Ask for all three before you compare fees.

  • Australian credit experience. Ask who will review your files and which Australian credit licensee files they have reviewed under the National Consumer Credit Protection Act 2009. Best interests duty reviews are specific to mortgage brokers, so ask for that experience directly.
  • Method. Ask how the provider chooses files to review. In an example in RG 273 (June 2020), ASIC describes a licensee selecting brokers by business volume, the range of lenders used, complaints and how their loans later performed.
  • Sample deliverables. Ask for a de-identified audit report, a manual extract or a training outline, depending on the service you need. A sample shows the format you’ll actually receive.

Then check how findings are prioritised and escalated. Each finding needs a severity, a named remediation owner, a due date and a rule for when it goes to your responsible manager or director. RG 205 (April 2020) expects licensees to give a director or senior manager responsibility for overseeing compliance.

Escalation timing affects your reporting deadline. ASIC’s Regulatory Guide 78 (December 2023) requires a credit licensee to report a reportable situation within 30 days of first knowing there are reasonable grounds to believe it has arisen. RG 78 also treats an investigation the licensee outsources as the licensee’s own investigation.

Test a Sample Audit Recommendation

Test a sample recommendation by checking that it names a concrete correction, a responsible person and the evidence that proves the work is done. Compare these two fictional findings.

Weak finding: “File compliance score 68%. Improve file note quality.”

Useful finding: “High severity. Notes on five of 12 refinance files give no reason for the lender chosen. Correction: add the reasons and the quoted lender policy to each note by 14 November 2026. Owner: Sam Lee, senior broker. Completion evidence: updated notes saved in the client file and rechecked by the compliance manager.”

The score doesn’t tell anyone what to fix or who must fix it. The useful finding gives a broker a task to complete and gives the responsible manager something to verify. If a provider’s sample findings read like the weak example, expect your own report to read the same way.

Agree the Engagement

Agree the engagement in a written contract that keeps compliance decisions with your brokerage and protects your clients’ files. RG 205 (April 2020) expects licensees to choose providers with due care, monitor their performance and act on breaches of service levels.

State in the contract that the provider reviews and advises, while your brokerage decides and acts. Your responsible manager signs off each remediation plan and every breach-reporting decision.

Client files contain personal information, so set confidentiality terms before the provider sees a file. The Office of the Australian Information Commissioner’s APP 11 guidelines say an entity that outsources storage but keeps access rights still holds that information. Your brokerage stays responsible for its security, so limit access to named reviewers and require the provider to tell you promptly about any data breach.

Compare Terms Side by Side

Ask every shortlisted provider to state the same five terms in the same way, so their quotes are comparable.

  1. Deliverables, such as the number of files per audit, the report format and the number of training sessions.
  2. Response times for advice requests, stated in business days, with a faster time for a possible reportable situation.
  3. Fees, on one basis for every provider, such as a fee per file reviewed, a fee per audit cycle or a monthly retainer.
  4. Contract length and notice period, including what happens to work in progress when either side ends the contract.
  5. Exit support, covering the handover of findings, working papers and outstanding remediation items.

End the Engagement Cleanly

Make the end-of-engagement duties explicit before you sign. On the final day, the provider removes its access to your systems and returns the findings register and working papers in an editable format.

The provider then securely deletes all your client information, backup copies included. It confirms the deletion in writing. The APP 11 guidelines say reasonable steps include verifying destruction when a third party holds the information.

Keep Responsibility With the Licensee

Outsourced review work never transfers the licensee’s duties. Under RG 273 (June 2020), credit licensees must take reasonable steps to make sure their brokers comply with the best interests duty. ASIC expects those steps to prevent breaches before they happen.

Keep the findings register and every client record in your brokerage’s own systems, so staff can find previous findings after the provider leaves. A client can ask for the written assessment that their loan is not unsuitable up to seven years after the credit assistance, according to ASIC’s Regulatory Guide 209 (December 2019). Never let a provider hold the only copy of a record you may need to produce.

Before you sign, match each gap you defined to a deliverable in the contract and name the person at your brokerage who acts on each finding. The compliance checklist lists the evidence a file review inspects, so you can check your own files before the first audit.

Check the policy behind your next scenario

Ask Bulma a lender policy question and inspect the source behind the answer.