AI System Impact Assessment
A first-party assessment, self-made, reviewed 11 September 2026. It closes the National AI Centre's essential practice 2 — understand impacts and plan accordingly. General information about how the software works, not personal advice, and not a certification.
What the system is, and the decision it touches
ProofMemo is broker-controlled decision support and evidence certification for a regulated credit file. It reads a client's documents, reconciles the figures across them, runs the assessment the same way every time, and produces a dated record of what was checked, including what it could not establish. It does not make the credit recommendation and does not certify that a product is best for a person.
The decision it sits next to — whether to proceed with, or how to structure, a person's credit — can significantly affect that person's rights and interests. From 10 December 2026, Australian law requires disclosure where a computer program is substantially and directly related to such a decision. This assessment is written to that bar.
Who can be affected, and how
The credit client is most affected. A missed check, a mis-read figure, or a field wrongly treated as verified could flow into a decision about their borrowing — that is the adverse case. The beneficial case is a complete, checkable record of what was and was not established. The broker and licensee are affected too: the record evidences the reasonable steps actually taken, and a false assurance would expose them rather than protect them. Third parties whose information appears in a client's bank statements carry a privacy interest of their own.
The impacts we assessed, and the mitigation in place
A field could be wrongly treated as verified. The system reports what it could not establish, rather than presenting silence as completeness.
The machine could appear to make the decision. The decision path contains no model; every step is labelled by who acts there, and the build fails if any step decides on its own.
Sensitive data could reach a model or leave the machine. The most sensitive fields are removed before any model sees them, and documents stay on the broker's own machine, so there is no second copy.
An unfamiliar document could be silently mis-read. The system halts rather than guessing; an unreadable field is marked unobservable and located on the page for a person to check.
The system itself could be attacked or defeated. We keep a ranked, working register of the ways it could be defeated, and we work it down.
Residual risk, and what remains open
Privacy of third parties inside ingested documents is minimised by local processing but not yet governed by a settled retention schedule; that work is in progress. The assurance is first-party — not yet independently audited. And the system is decision support: it cannot discharge the broker's best-interests duty, that duty is not delegable to software, and the record declines to certify it.
Review
Reviewed when the assessment line changes, when a new document type is ingested, and at least at each major release.