Skip to main content

Broker guide

Mortgage Broker Information Security and Privacy

Protect mortgage broker client data with access, transfer, retention, breach response, continuity, AI-use and staff-training controls for daily work.

Published
Updated

Mortgage broker information security protects borrower records by controlling who can access them, how they move and what happens after an incident or outage. Give each control a named owner and keep evidence that it works. A secure document portal helps, but copies in email, downloads, archives and service-provider systems need controls too.

Your brokerage’s legal duties depend on its licence role, privacy status and contracts. The procedure below separates those duties from practical controls you can adopt across the team.

Map Client Information and Control Owners

Map each borrower record from collection to disposal, including the copies made during processing and lodgement. Record its purpose, storage locations, authorised recipients and the person who decides access or disposal.

Use a register like this to find copies outside the main application file.

Record classCommon locations and movementsDecision owner
Identity documents and verification resultsClient upload, verification provider, approved application file and lender submissionOperations lead controls collection and access, with the compliance lead approving retention
Income evidencePayslips, tax returns and financials in the upload portal, processor workspace and lender fileAssigned broker approves use, with operations controlling copies
Bank statementsCollection service, downloaded statements, assessment file and lender submissionAssigned broker controls required evidence and approved recipients
Credit reports and explanationsAuthorised retrieval service, restricted client file and lender submissionCompliance lead sets permitted handling and access
Application recordsFact find, assessments, policy evidence, client communications and lodgement recordsCompliance lead owns retention decisions, with the assigned broker maintaining the file
System recordsAccess logs, backups, exports and incident evidenceTechnology lead protects storage, with the incident owner directing preservation

One person can hold several roles in a small brokerage. Name a deputy for incident decisions so a missing principal does not stall containment.

Separate the Applicable Duties

An Australian credit licensee carries the general conduct obligations described in the Australian Securities and Investments Commission (ASIC) Regulatory Guide 205. Those obligations cover adequate resources and supervision, subject to the guide’s applicable exceptions. Outsourcing a function does not transfer the licensee’s responsibility for it.

A credit representative follows its authorising licensee’s controls and reporting arrangements. Record which decisions the representative can make and which need escalation. An aggregator agreement or lender accreditation can impose additional requirements, including approved systems and incident reporting.

An Australian Privacy Principles (APP) entity has obligations under the Privacy Act 1988. Establish that status for the brokerage itself. The Office of the Australian Information Commissioner (OAIC) small-business guidance explains coverage and exceptions to the small-business exemption.

Low turnover alone does not settle the question. Specific credit-reporting or tax-file-number duties can apply separately. Record the applicable branch and its basis, then incorporate service-provider contract duties without presenting them as laws applying to every broker.

Keep the procedure’s approval and review arrangements in your mortgage broker compliance manual. The information register supplies the day-to-day record of where client data goes.

Control Access, Devices and Transfers

Give each broker, processor and contractor a named account with only the access their work needs. Use multi-factor authentication, which requires another proof of identity beyond a password, wherever the system supports it. Keep administrator access separate from daily file work.

Use these controls when onboarding staff or changing their duties.

  • Give brokers access to their allocated clients and approved shared work.
  • Limit processors to assigned applications and the documents they need.
  • Give contractors time-limited access under an approved service agreement.
  • Restrict administrators’ client-file access to the support task being performed.
  • Log access approvals, permission changes and periodic reviews.

Encrypt managed devices and keep their software supported. Set automatic locking and give staff a process for reporting loss.

Keep client records out of personal cloud storage and shared household accounts. Assign a technology owner to updates and device access removal.

For transfers, use the approved portal or a restricted link addressed to the intended recipient. Limit downloading where the system permits it and set an expiry suited to the task. Confirm the recipient’s authority before releasing identity documents or a full bank-statement set.

Verify a Suspicious Request

If a supposed lender assessor requests documents through a new email address, pause the transfer. Call the lender through a number already recorded in an approved directory or existing verified contact. Confirm the request and approved delivery route independently of the message.

Send only the information needed for that purpose. Remove unnecessary identifiers from a working copy while preserving required evidence in the controlled original. Never place passwords or authentication codes in a client file or incident ticket.

When a person leaves, revoke accounts and active sessions at the agreed departure time. Remove shared links, delegated mailbox access and provider accounts, then retrieve managed devices. Record who removed each access path, when they did it and how removal was confirmed.

Set Retention, Archive and Disposal Rules

Set retention by record class and its applicable duty, with a defined starting event and disposal action. A completed settlement is not automatic permission to delete the assessment file. A general wish to keep everything is not a retention reason either.

Build a schedule with these fields for every record class.

Schedule fieldWhat to record
Record classFor example, credit assessment evidence or temporary processing downloads
Starting eventThe exact event that starts the applicable period, such as the assessment or finalisation date
Reason and durationThe applicable law, licence obligation or permitted business purpose, with its actual period
Archive ownerThe person responsible for moving and protecting the retained copy
Authorised accessRoles permitted to retrieve the archive and the approval needed
Review dateWhen the owner checks whether the retention reason still applies
Disposal actionDestruction or effective de-identification, with approval and completion evidence
Other copiesProvider storage, backups, email attachments, exports and local downloads

Apply legal retention requirements to the records they govern. Keep the evidence needed to explain the credit assessment and the broker’s decisions. Use the file-level compliance checks to confirm that the retained record is complete.

For an APP entity, APP 11 requires reasonable security measures. It also requires reasonable destruction or de-identification when information is no longer needed for a permitted purpose, subject to its retention exceptions. Australian-law and court-order requirements can prevent disposal.

Apply that decision to all copies the entity holds, including archives, backups and provider-held records under its control. Obtain evidence of provider disposal. For backups that cannot yet be deleted separately, document restricted access and the route to final disposal under the OAIC’s guidance.

A disposal log can record the record class, covered dates, authority, method and completion evidence. Keep that log free of the identity documents it confirms were destroyed. De-identification must address whether a person remains reasonably identifiable from other details.

Contain and Assess a Data Breach

Stop further exposure immediately, assign an incident owner and preserve the evidence needed to understand what happened. The OAIC’s breach-response sequence is contain, assess, notify and review. These activities can overlap while urgent remedial action continues.

  1. Restrict the affected account, file or sharing link. For a compromised account, revoke sessions and involve the technology provider in securing access.
  2. Protect unaffected records and preserve access logs, message headers and the incident timeline. Avoid wiping a device before the incident owner has arranged evidence preservation.
  3. Alert the incident owner through the approved reporting channel. Record the time discovered and the containment actions already taken.
  4. Assign another authorised person to open applications and urgent settlement deadlines. Give them controlled access through a safe system.
  5. Assess the information exposed and the people affected. Establish who accessed it, whether it was copied and whether protection measures worked.

Record potential identity theft, financial loss or other serious harm relevant to the exposed records. Assess whether remedial action actually prevents likely serious harm. A successful email recall message alone does not establish that an attachment was never accessed.

The Notifiable Data Breaches (NDB) scheme applies to covered entities and information. An eligible breach involves unauthorised access, disclosure or loss likely to cause serious harm, where effective remedial action has not prevented that harm.

Under the OAIC’s assessment guidance, covered entities must assess suspected eligible breaches promptly. They must take all reasonable steps to complete assessment within 30 calendar days after becoming aware of grounds for suspicion. That period is not permission to delay containment or notification once eligibility is established.

Fictional Incident: A Misdirected Statement

A processor at Harbour Home Loans sends a client’s bank statement to an unrelated recipient. The incident owner disables the sharing link and preserves its access log. The log shows a download before the link closed.

The owner records what the statement contains and investigates further sharing. The owner also contacts the recipient through a safe channel to seek containment. Disabling the link does not resolve the downloaded copy, so the harm assessment remains open until the evidence supports a decision.

Keep the decision and its reasoning even when notification is not required. Record the entity’s coverage, affected information, likely harm and the evidence supporting remedial action.

Notify, Recover and Review

Route notifications according to the incident facts and the duty that applies to each recipient. Where the NDB scheme requires notification, notify the OAIC and people at risk of serious harm as soon as practicable, unless an exception applies. Use the OAIC’s notification guidance for the statement and individual notification options.

Assign a notification owner and keep a register like this.

RecipientTrigger to assessNotification owner
Affected people and OAICAn eligible breach under the applicable NDB requirementsIncident owner with privacy or legal support
Authorising licenseeRepresentative agreement, compliance escalation or possible regulatory reportingBrokerage principal
Aggregator or lenderAffected submissions, access credentials or contract reporting requirementsPrincipal or appointed relationship owner
InsurerPolicy notice terms and possible claimPrincipal or insurance contact
Technology providerCompromised accounts, logs, containment or restoration supportTechnology lead
Law enforcementSuspected criminal conduct requiring reporting or assistanceIncident owner with appropriate advice

Describe the affected information and practical protective action in plain language. Give clients a verified contact route. Coordinate shared incidents with the licensee or provider so responsibility for required notifications is explicit.

Recover through controlled access, with the technology lead confirming that the exposure has stopped. Review permissions before reopening accounts. Compare restored records with retained originals and logs to identify missing documents or unauthorised changes.

Record client remediation and unresolved consequences, including any missed application deadline. Assign each root-cause correction to a person and due date. If a contractor kept access after departure, fix the offboarding procedure and test revocation before closing that action.

Maintain Business Continuity and Recovery

Prioritise recovery by the deadlines and client consequences of a service failure. A brokerage with a settlement today needs an assigned communication route even while its document system is unavailable.

ASIC’s RG 205 addresses credit-licensee technological resources and business continuity. Its appendix asks about system security, confidential information and recovery arrangements. Representatives must align their recovery arrangements with their licensee’s requirements and their own contracts.

Use a recovery register that includes dependencies as well as systems.

Critical workAlternate routeRecovery priority and evidence
Today’s settlement or urgent applicationDeputy broker contacts the lender through a verified channelRestore the ability to coordinate before the specific deadline
Client contactApproved alternate phone service and authorised contact registerConfirm the team can reach affected clients
Required documents and file notesRestricted restoration from an authorised backupConfirm records are complete and permissions remain correct
Regulatory or licensee escalationDeputy uses the recorded incident contactsMeet the applicable reporting deadline
Routine processingApproved alternate workspace or reassigned processorResume after urgent work, with changes reconciled

Set recovery-time targets for each service and a maximum acceptable amount of lost work. Record the actual targets for your brokerage. Backups need an owner, protected access and a restoration procedure the deputy can use.

Test a fictional outage in which the document provider is unavailable and the principal is away. Restore a fictional application into an isolated approved workspace. Confirm that the deputy finds the correct file, sees only authorised records and can identify the next deadline.

Record elapsed recovery time and any missing work. Compare them with the targets and inspect whether restored permissions expose other clients. A completed backup job proves a copy was made, while a restoration exercise shows whether the team can recover usable records.

Control AI Use With Client Data

Approve each artificial intelligence (AI) use before staff enter client information, with a defined data boundary and a human decision owner. The OAIC’s commercial-AI privacy guidance addresses personal information in both inputs and generated outputs. It recommends keeping personal information out of publicly available generative AI tools as a matter of best practice.

Record each approved tool’s purpose and permitted information. Establish provider access, storage, training use, overseas handling and deletion terms before approving client-data use. For APP entities, entering personal information can be a use or disclosure under APP 6, depending on control over the information.

A practical brokerage policy can permit a generic lender-policy question without client identifiers. It can prohibit identity-document uploads to an unapproved tool and restrict client-data processing to an approved account and purpose. These are operating rules the brokerage sets after its privacy assessment.

Minimise prompt data and assess whether other details still identify the client. Removing a name does not de-identify a scenario if a rare occupation and property details make the person recognisable. Keep the identifying source file in the approved client system.

For each client-related output used in the file, record the following information.

  • The source documents and their versions.
  • What data was entered and which approved boundary applied.
  • The tool and account used, with the date of the output.
  • The checks against source evidence and applicable lender policy.
  • The broker responsible for the final advice or file decision.

Generated text needs verification before it becomes a file note or client communication. Correct invented facts and separate source evidence from the tool’s interpretation. Escalate unexpected provider behaviour or accidental disclosure to the incident owner using the same containment procedure as other data exposure.

Train Staff and Test the Procedure

Train each role on the decisions it makes, then observe staff completing those decisions in a practical exercise. Brokers need practice confirming lender requests and checking outputs against policy. Processors need practice choosing recipients and handling documents, while administrators need practice removing access and preserving logs.

Use fictional messages and records to test these situations.

  • A phishing message asks a broker to sign in through an unfamiliar link.
  • A supposed assessor requests identity documents at a new address.
  • A contractor leaves while an application remains open.
  • A staff member loses a managed device during travel.
  • An AI prompt contains identifiers outside the approved data boundary.
  • The incident owner is unavailable when an exposure is discovered.

Measure whether staff use the trusted contact route, stop the unsafe action and alert the correct deputy. Record the exercise date, participants, observed actions and outcome. Store the result without live borrower information or authentication codes.

Where a control fails, assign supervised follow-up and repeat the affected exercise. Give the principal a clear result: who can complete the procedure unaided, which access or recovery control failed and who owns the correction. Close the action only after the repeated exercise demonstrates the expected response.

Check the policy behind your next scenario

Ask Bulma a lender policy question and inspect the source behind the answer.