Your AI Credit Score Is Not a Responsible Lending File., practitioner guidance from TheAICommand
← GRC
Regulatory analysis

Your AI Credit Score Is Not a Responsible Lending File.

A model can rank credit risk, reconcile application data and flag exceptions. It still cannot prove the inquiries, verification and customer-specific suitability assessment behind a lending decision. Build a customer-outcome file that preserves the evidence and the authorised human judgement.

·monthly

GRC content. Written for compliance, risk, and audit professionals in Australian financial services. General information. Not legal or compliance advice.

Quick answer

A score can rank credit risk, apply lending criteria or prioritise an application. It cannot show what the consumer needs, whether their financial information was reasonably verified, or why the contract is not unsuitable for them. Keep a customer-outcome file that separates applicability, inquiry, verification, conflict, automation, suitability, decision and consumer records.

A model can rank credit risk, reconcile application data and flag exceptions. It still cannot prove the inquiries, verification and customer-specific suitability assessment behind a lending decision. Build a customer-outcome file that preserves the evidence and the authorised human judgement.

A score answers a narrow question. It might estimate default risk, apply lending criteria or prioritise an application for review. It does not, by itself, show what the consumer needs, whether their financial information was reasonably verified or why the proposed contract is not unsuitable for them.

That distinction matters under the National Consumer Credit Protection Act 2009, current Compilation 52 dated 1 July 2026. For a credit provider within Part 3-2, the assessment, inquiries, verification and prohibition on unsuitable credit sit across separate provisions. Passing a model threshold is not a substitute for completing that statutory chain.

Use AI to organise evidence and expose gaps. Keep the application of lending policy, the judgement about reasonable inquiries and verification, the customer-specific unsuitability assessment, any exception and the final credit decision with authorised people.

What does a responsible lending file need to prove?

Start by separating credit risk from responsible lending. A lender may decide that an applicant falls outside its risk appetite even where the proposed contract is not unsuitable. Conversely, a favourable risk score does not establish compliance with the responsible lending obligations.

ASIC's responsible lending overview says credit licensees must comply with Chapter 3 of the National Credit Act and must not enter, suggest or assist with a credit contract that is unsuitable for the consumer. It also says the licensee must decide how it will meet those obligations. The law sets the duties. ASIC's regulatory guide explains its interpretation and gives practical guidance, but it is not a statutory form.

For a credit provider under the general rules, sections 128 to 130 of the current National Credit Act require an assessment of unsuitability before relevant regulated conduct, reasonable inquiries about the consumer's requirements and objectives and financial situation, and reasonable steps to verify the financial situation. Section 131 requires the contract to be assessed as unsuitable where it is likely that the consumer could not meet the financial obligations, could do so only with substantial hardship, or the contract would not meet the consumer's requirements or objectives, or circumstances prescribed by the regulations apply. Section 133 then prohibits entry into, or a credit-limit increase under, an unsuitable contract.

Scope still matters. RG 209, issued 9 December 2019 and amended in March 2025, explains that the obligations apply to regulated consumer credit and specified conduct, not every loan or every credit activity. Additional rules also apply to some product classes. Map the product, purpose, actor and conduct before applying a generic workflow.

The file must therefore prove more than an outcome. It must show the information sought, what was received, what was verified, what remained uncertain, how conflicts were resolved and why the contract was assessed as unsuitable or not unsuitable for this consumer.

The distinction becomes sharper with automated decision-making. RG 209.253 to RG 209.254 say that, where automated decision systems compile and assess consumer information under predetermined rules, ASIC considers that the systems should be tested prior to implementation and at reasonable regular intervals, identify situations that require further inquiries or verification steps and either complete those steps or refer the application for manual consideration, and maintain or produce a meaningful record of the assessment. That is guidance, not a new AI-specific legal test. It still makes a one-field score an obviously incomplete control artefact.

Where can AI assist without becoming the decision?

Put AI in the evidence-preparation lane. It can extract declared income and expenses, compare them with approved source records, identify inconsistent dates, group follow-up questions and draft a traceable chronology. It can also check whether required fields are blank or whether an override lacks a reason.

Do not let it fill silence with an inference. A model must not convert an unexplained transfer into salary, assume a household expense is reducible, invent a customer's objective or decide that an inconsistency is immaterial. Under this proposed control, the credit professional decides what further inquiry is reasonable, whether verification is adequate and what information can properly support the assessment.

This prompt is for a first-pass evidence reconciliation. A human credit assessor must verify every source, resolve every conflict and decide the next inquiry.

Prompt
Reconcile [APPLICATION_DATA] against [APPROVED_VERIFICATION_RECORDS] for application [APPLICATION_ID].

Create a table with: field, consumer statement, source record, source date, match status, discrepancy, missing evidence and suggested follow-up question.

Do not infer income, expenses, liabilities, household circumstances, requirements or objectives. Do not assess suitability or recommend approve, decline or refer. Mark every unsupported item OPEN. Cite the record identifier for every extracted fact.

Build a hard hand-off when the evidence stops being clerical. Route the case to a person when a requirement is unclear, data conflicts, the consumer reports foreseeable change, repayment capacity depends on reducing expenditure, the product has a complex feature, or the model encounters a case outside its tested conditions. The triggers should respond to the facts of the application, not merely to a low confidence score.

ASIC's guidance describes the inquiry and verification obligation as scalable. RG 209.81 to RG 209.84 say what is reasonable varies with the individual circumstances and requires judgement. RG 209.135 to RG 209.140 also distinguish statistical benchmarks from information about the individual consumer. Benchmarks can test plausibility in a broader process, but do not confirm that the consumer's information is true. A model-derived score should be treated with the same discipline: useful input, never proof of the customer facts it does not contain.

The human boundary also needs operating evidence. ASIC reviewed 624 consumer-impacting AI use cases reported by 23 AFS and credit licensees as at December 2023. Report 798, published 29 October 2024, observed that AI generally augmented rather than replaced human decision making, while finding that AI governance arrangements varied widely, with weaknesses that create the potential for gaps as AI use accelerates. That review does not prescribe a responsible lending workflow, and the question it raises for a board is how strong the evidence behind an AI update actually is. The question here is narrower and file-level: what a single customer's record has to prove. It supports a practical point: writing human review into a policy is weaker than recording the question the person considered, the evidence they changed or accepted, and the decision they authorised.

What belongs in the customer-outcome file?

The customer-outcome file is a proposed internal control from TheAICommand. It is not terminology used in the National Credit Act, an ASIC-mandated template or a safe harbour. It sits behind the formal assessment and does not replace the written copy that sections 120, 132, 143 or 155 may require for the relevant actor and product.

Use this checklist for each application in scope:

  • Applicability record: product, purpose, applicant type, responsible lending actor, regulated conduct and any verified exception or modification.
  • Inquiry record: the consumer's stated requirements, objectives and financial situation, with question, answer, date and channel.
  • Verification record: approved source, record identifier, period covered, value verified and any limit on the evidence.
  • Conflict record: inconsistencies, changed circumstances, missing information and the human-approved follow-up or stop state.
  • Automation record: score or rule outcome, model and version, material inputs, tested boundary, referral trigger and any override.
  • Suitability record: the relevant product terms, likely financial effect, requirements and objectives analysis, substantial-hardship analysis and information relied upon.
  • Decision record: named authorised role, assessment outcome, lending-policy outcome, reasons, exceptions, conditions and approval time.
  • Consumer record: the retrievable written assessment, request status and any correction raised by the consumer.

Keeping these layers separate prevents the score from swallowing the assessment. It also preserves a distinction that matters in review: a policy decline is not necessarily an assessment that a contract is unsuitable, and a not-unsuitable assessment is not a promise that the lender will approve credit.

Credit risk scoreResponsible lending assessmentLending decision
Question it answersHow likely is defaultIs this contract unsuitable for this consumerWill we lend on these terms
Evidence it rests onModel inputs and rulesInquiries, verification, requirements and objectivesAssessment plus lending policy and risk appetite
Who owns itModel ownerHuman credit assessorAuthorised decision-maker
A credit risk score sits beside a responsible lending suitability assessment
A score is not an assessment: two different questions, two different evidence bases.

Consider this fictional worked example. Applicant [CUSTOMER_ID] seeks [PRODUCT_TYPE] for [STATED_PURPOSE]. The model returns [SCORE_BAND] and no automated verification exception. A transaction-record reconciliation then finds a recurring debit absent from the declared commitments and a forthcoming employment change in a file note.

The score remains unchanged, but the customer-outcome file stays OPEN. Human assessor [ASSESSOR_ROLE] makes a follow-up inquiry, obtains approved verification and records how the changed information affects the assessment. Authorised decision-maker [DECISION_ROLE] separately records the not-unsuitable assessment and the lending-policy decision. The model did not decide that the debit was material or that the contract met the customer's objectives.

This prompt is for a pre-decision file completeness check. A human compliance or credit reviewer must determine whether the evidence and reasoning are adequate and whether the application may proceed.

Prompt
Review [CUSTOMER_OUTCOME_FILE] against [APPROVED_RESPONSIBLE_LENDING_CONTROL_STANDARD].

List only: missing inquiry records, verification gaps, contradictory facts, unsupported suitability statements, unresolved automation referrals, unexplained overrides, missing decision authority and missing links to the written assessment.

For each exception, cite the file field and source record. Do not supply missing facts, decide whether inquiries or verification are reasonable, assess substantial hardship, determine suitability or approve credit. Return unresolved items as OPEN for human decision.

RG 209.251 to RG 209.254 also recommend portfolio review using signals such as complaints, early default, arrears, hardship and switching events, and testing automated decision systems prior to implementation and at reasonable regular intervals. Use those outcomes to challenge the control and the model. Do not use portfolio performance to rewrite what the original customer file said.

Do this Monday

  1. Pick one credit pathway. Confirm the product, purpose, regulated conduct, actor and applicable responsible lending provisions with legal or compliance review.
  2. Separate the two decisions. Label the customer-specific unsuitability assessment and the lender's risk-appetite decision as different fields with different reasons.
  3. Trace ten recent applications. Link every material inquiry, verification source, exception, score, manual referral, assessment and final authorisation. Keep each gap OPEN.
  4. Test the referral boundary. Insert a conflicting liability, changed employment fact and unsupported objective into approved test data. Confirm the workflow stops for human consideration.
  5. Reconcile the consumer copy. Check that the retrievable written assessment reflects the evidence and grounds approved in the file, without exposing commercially sensitive lending criteria.
  6. Add an outcome loop. Review complaints, hardship, arrears and early-default signals as challenge data, with a human owner for investigation and control change.

Bottom line

A credit score may inform risk appetite or direct an application to the right queue. It does not prove customer-specific inquiries, verification or the statutory assessment of unsuitability. Build a customer-outcome file that links source evidence, automation exceptions and an authorised person's reasons without pretending the control is an ASIC template. Keep suitability, overrides and the final lending decision with accountable humans.

This article is general information and education only. It is not legal, compliance, financial or professional advice. Obligations vary by organisation and circumstance. Verify current requirements against the primary sources cited and seek advice specific to your situation.

References

  1. Federal Register of Legislation, National Consumer Credit Protection Act 2009, Compilation 52, compilation date 1 July 2026, current as accessed 31 July 2026. https://www.legislation.gov.au/C2009A00134/latest
  2. Australian Securities and Investments Commission, Regulatory Guide 209: Credit licensing: Responsible lending conduct, issued 9 December 2019, amended March 2025. https://download.asic.gov.au/media/hyeofbni/rg209-published-9-december-2019-20250306.pdf
  3. Australian Securities and Investments Commission, RG 209 Credit licensing: Responsible lending conduct, landing page. https://asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-209-credit-licensing-responsible-lending-conduct/
  4. Australian Securities and Investments Commission, Responsible lending. https://asic.gov.au/regulatory-resources/credit/responsible-lending/
  5. Australian Securities and Investments Commission, Report 798 Beware the gap: Governance arrangements in the face of AI innovation, published 29 October 2024. https://download.asic.gov.au/media/mtllqjo0/rep-798-published-29-october-2024.pdf

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

What is the difference between a credit score and a suitability assessment?
They answer different questions. A lender may decide an applicant falls outside its risk appetite even where the proposed contract is not unsuitable, and a favourable risk score does not establish compliance with the responsible lending obligations. A policy decline is not necessarily an assessment that a contract is unsuitable, and a not-unsuitable assessment is not a promise that the lender will approve credit.
What do sections 128 to 133 actually require?
For a credit provider under the Part 3-2 general rules: an assessment of unsuitability before relevant regulated conduct, reasonable inquiries about the consumer's requirements and objectives and their financial situation, and reasonable steps to verify that financial situation. Section 131 makes a contract unsuitable where it is likely the consumer could not meet the obligations, could do so only with substantial hardship, the contract would not meet their requirements or objectives, or prescribed circumstances apply. Section 133 then prohibits entry.
What does ASIC say about automated decision systems?
RG 209.253 to RG 209.254 say that where such systems compile and assess consumer information under predetermined rules, ASIC considers they should be tested prior to implementation and at reasonable regular intervals, should identify situations requiring further inquiries or verification and either complete those steps or refer the application for manual consideration, and should maintain or produce a meaningful record of the assessment. That is guidance, not a new AI-specific legal test.
Can benchmarks verify a consumer's financial situation?
No. RG 209.135 to RG 209.140 distinguish statistical benchmarks from information about the individual consumer. Benchmarks can test plausibility within a broader process, but they do not confirm that the consumer's information is true. A model-derived score deserves the same discipline: a useful input, never proof of the customer facts it does not contain.
Is the customer-outcome file an ASIC requirement?
No. It is a proposed internal control from TheAICommand. It is not terminology used in the National Credit Act, an ASIC-mandated template or a safe harbour. It sits behind the formal assessment and does not replace the written copy that sections 120, 132, 143 or 155 may require for the relevant actor and product.

Context

The responsible lending obligations sit in Chapter 3 of the National Consumer Credit Protection Act 2009, currently Compilation 52 dated 1 July 2026. For a credit provider under the Part 3-2 general rules, sections 128 to 130 require an assessment of unsuitability, reasonable inquiries about requirements, objectives and financial situation, and reasonable steps to verify that financial situation. Section 133 prohibits entering an unsuitable contract. ASIC's RG 209 was issued 9 December 2019 and amended in March 2025, an amendment that renumbered every paragraph above RG 209.67 by two. Paragraph references taken from a pre-2025 copy will be wrong.

AI angle

A model can reconcile declared figures against approved source records, flag inconsistent dates and group follow-up questions, which is exactly the clerical work that hides gaps. It must not fill silence with an inference. Converting an unexplained transfer into salary, assuming a household expense is reducible or deciding an inconsistency is immaterial are all customer-specific judgements. The credit professional decides what further inquiry is reasonable, whether verification is adequate and whether the contract is not unsuitable for this consumer.

Primary sources

Responsible LendingCredit GovernanceASICAI GovernanceConsumer Credit
← Back to GRC

Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. Regulatory obligations vary by entity type, licence, and circumstance. Always refer to primary source guidance from APRA, ASIC, or the relevant regulatory authority.