You hold your own credit licence, and your brokers write under it. You are also with an aggregator, and the aggregator runs a compliance program. There is a risk-based audit program, some analytics that flag files worth a closer look, training through the year, and the technology that generates and stores the credit guide, the assessments and the proposals. Files get looked at. Reports come back. So when someone asks whether you need your own file audit, the honest first reaction is that the aggregator already does that.
That reaction quietly conflates two different things, and the gap between them is exactly where a licence holder gets caught. It matters more this year than last. In the middle of 2025 ASIC began its first targeted review of the best interests duty since the duty started in 2021. It has run in two phases, first gathering data on loan flows, commissions and clawback rates, then examining how aggregators supervise their brokers and handle complaints. ASIC has said it will report in the final quarter of 2026. Around the same time the Federal Court handed down a $20 million penalty against a licensed home-loan business that had left the supervising to the network operating under its licence. Brokers wrote a record 81% of new home loans in the March 2026 quarter, according to the MFAA, so the supervision stakes for the people who run broker businesses have never been higher.
What follows is a plain-English overview of where an aggregator's compliance program stops and your obligation as the licence holder starts. It is general information, not legal or compliance advice.
What your aggregator's compliance program is actually for
Start by giving the aggregator its due, because the program is real. Aggregators run risk-based audit programs, use data analytics to surface risk indicators, employ compliance specialists and put brokers through training. For a broker operating under the aggregator's own licence, they will often manage the day-to-day licensing obligations as well. None of that is window dressing.
The thing to understand is who it is built for. Most of that program is designed around the credit-representative relationship, where the aggregator holds the licence and is legally liable for the broker's conduct. Several aggregators say as much in their own material. To a broker who sits under their licence, the message is that compliance is taken care of. To a broker who holds their own licence, the same aggregators offer something narrower, usually described as consultative reviews. That is a different and smaller thing, and the difference is not marketing. It follows the licence.
There is a deeper point underneath it. An aggregator's file checks are built around the aggregator's own risk, not yours. In a submission to the ACCC, one of the larger aggregators described its lender reviews as testing compliance with its own regulatory obligations and the contractual obligations it owes its lenders under its head agreements. Read that again. That is the aggregator's risk lens, and it is a legitimate one. It is simply not designed to produce the supervision record you need for your representatives, under your licence.
The obligation you cannot hand over
When you hold your own Australian credit licence, the general conduct obligations in section 47 of the National Credit Act sit with you. They are worth stating plainly, because they are specific. You must take reasonable steps to ensure your representatives comply with the credit legislation. You must ensure they are adequately trained and competent. You must have adequate arrangements and systems to ensure compliance, and, in the words of section 47(1)(k), a written plan that documents those arrangements and systems. And you must have the resources to carry out your supervisory arrangements.
The standard is not fixed. Section 47(2) says adequacy is judged against the nature, scale and complexity of what you do. In practice that means a 40-broker group is held to a higher supervision standard than a six-broker one. As you grow, the bar moves with you, and it moves quietly.
None of this transfers to your aggregator. You can buy tools, reviews and training from them, and you should. But the documented monitoring-and-supervision system, and the written plan behind it, has to be yours, held in your name, and capable of being produced.
What happens when it is not was made very clear in 2025. The Federal Court ordered a $20 million penalty against a licensed home-loan business that admitted it had failed to supervise the people operating under its licence, including failing to create and enforce adequate policies and to investigate misconduct. ASIC's deputy chair called it a systemic governance failure by a licensee that did not adequately supervise its network. The lesson for anyone who holds an ACL is not subtle. When supervision fails, the regulator holds the licence holder to account. Not the aggregator. Not a third party. The licence holder.
What a file audit is supposed to evidence
If the supervision record is the thing you have to be able to produce, it helps to be precise about what a properly reviewed file actually shows. Two frameworks sit on every residential file, and they are separate tests.
The first is responsible lending, which remains fully in force. A file has to evidence reasonable inquiries into the client's situation, requirements and objectives, reasonable steps to verify that situation rather than taking it on face value, and a preliminary assessment that the credit is not unsuitable, made and documented before the credit was offered. The credit guide and the required disclosures have to be there, and the assessment has to be available to the client on request.
The second is the best interests duty, which has applied to credit assistance since 1 January 2021. It asks the broker to gather the client's information, make an individual assessment, and present the recommendation with the reasons for it. It goes further than responsible lending in one direction that catches files out: it asks specifically that cost be considered, and that any recommendation of a more expensive option be supported by a documented reason why that option is nonetheless in the client's interests. Complying with responsible lending does not, on its own, mean the best interests duty is met. They are different obligations, and a file has to answer both.
So a file that stands up evidences specific, individual inquiries, a verified financial position rather than bare reliance on a benchmark, a documented not-unsuitable assessment, a clear reason for the product chosen, the disclosures, and a document trail you can trace from end to end. A thin file leans on unverified benchmarks, skips the reason the product was recommended, or cannot show where the documents came from. The difference is not academic. It is the difference between a supervision record that holds and one that does not.
And it has to be true not for one good file, but across every broker writing under your licence, on an ongoing and documented basis. That is what supervision means when the regulator uses the word.
Why independence changes the evidence, not your liability
Here is the part that gets lost in the sales pitch, in both directions. Bringing in an independent file audit does not move your legal obligation. The duty under section 47 is non-delegable. Whoever checks the files, you remain the licence holder and you remain accountable. Anyone who tells you an external audit transfers your liability is selling you something that does not exist.
So what does independence actually change? The quality and the credibility of the evidence you are keeping to meet a duty you cannot hand off.
There is a structural point here worth naming plainly. An aggregator earns on the settled volume flowing through its panel. A compliance function that sits inside the party paid on that volume is, in structural terms, reviewing the very activity that generates its revenue. In the assurance professions this configuration has a name, the self-review and self-interest threat, and the standards that govern auditors treat it as something that needs a safeguard, usually independence. Those standards do not bind aggregators, and this is not a claim that any aggregator does its job poorly. Most take compliance seriously and act hard when they find a problem. It is a narrower point, and a structural one: a review carries more weight when the reviewer is not paid on the volume being reviewed.
That is where an independent audit earns its place. It documents its findings and gives you a record you can test and stand behind. And the accountability stays where it belongs. The audit identifies the issue, you and your broker remediate it, and you verify it is fixed. It does not take over your compliance function or your supervision responsibility, and it should not claim to. You stay in control. The record is what proves you were.
The question you cannot answer from the aggregator's report
So here is the question, and it is not whether your aggregator audits files, because it does. The question is whether you could put your hand, today, on your own documented supervision record. Your written plan. Your evidence that every broker under your licence is being monitored. Produced independently of the party that is paid on your settlements. If ASIC asked to see it, would you be showing them your record, or forwarding the aggregator's and hoping it counts as yours.
Most principals cannot answer that cleanly. That is not a failing of effort. It is what happens when the tools you have were built for someone else's obligation.