Loxodrome

Industries

Built for Australian financial services

For the risk, compliance and audit functions of APRA‑regulated institutions, by directors and operators who’ve lived it.

The regulatory position

The regulators stopped asking whether you understand the risk

“Where entities fail to adequately identify, manage or control AI risks in a manner proportionate to their size, scale and complexity, we will take stronger supervisory action and, where appropriate, pursue enforcement.”
APRALetter to Industry on Artificial Intelligence, April 2026

APRA’s April letter said it will take supervisory and enforcement action where AI risk isn’t managed. The August paper from APRA and ASIC went a step further: boards are now expected to show what they’ve done, including over agentic systems that act on their own. The Privacy Act’s automated decision-making disclosures start on 10 December 2026.

Insurers already have an enforcement precedent for algorithmic pricing. Super trustees owe a duty to members over AI they mostly don’t operate. Banks have the most AI in production and the most rules about explaining a decision to the customer. Loxodrome is built to test and prove the effectiveness of AI systems used by all of these regulated sectors.

01 / 04

Insurance

Pricing, underwriting, and a precedent on the record.

Insurance is where AI inconsistency has already been litigated. ASIC’s June 2023 pricing action against a major general insurer: $40 million penalty plus an estimated $447 million in remediation across its brands for an algorithmic pricing inconsistency. Industry-wide: around $815 million in remediation by general insurers for pricing failures. The EU AI Act classifies life and health insurance pricing as high-risk. Actuarial exemptions to anti-discrimination law are narrow, and proxy-variable bias in underwriting models (postcode, browsing history, claims history) is exactly what regulators are focused on.

The regulatory perimeter is widest here. APRA covers prudential, ASIC covers consumer duty, the Privacy Commissioner covers automated decision-making, and anti-discrimination law sits over the top of all three.

Where Loxodrome makes the difference

Independent evidence of pricing consistency

Same risk, same inputs, same price. Where outputs diverge, Loxodrome shows you why: model version, feature change, input anomaly.

A real answer to proxy bias questions

When ASIC or the Privacy Commissioner asks whether differential outcomes have actuarial justification, the answer needs to come from the decision record, not the model design document. Loxodrome captures both.

Claims AI under continuous testing

Triage, assessment and fraud detection are increasingly AI-driven. Loxodrome captures each claims decision chain with the human review step attached, and consistency checks that fail raise exceptions before complaints accumulate.

EU AI Act readiness, before the clock starts

For insurers with EU exposure, Article 12 requires automatic logging over the lifetime of high-risk systems, and Annex III captures risk assessment and pricing in life and health insurance. Under the Digital Omnibus, Annex III obligations are expected to apply from December 2027. Evidence accumulates from the moment systems are instrumented. A record that was never captured cannot be produced later.

Loxodrome Compare view with two decisions selected side by side and differences only shown
Illustrative data

For risk, compliance and audit teams in insurance →

02 / 04

Superannuation

Best financial interests, applied to systems that decide.

Trustees owe members a best financial interests duty under the SIS Act. Members are beneficiaries as well as customers, and the duty applies to every decision made on their behalf, including the ones a system makes. AI used in member-facing decisions, advice, administration, or investment processes operates inside that duty. Most funds are at productivity tools and triage agents today. That’s the point at which instrumenting is cheap and retrofitting isn’t.

The structural problem for super trustees is that much of the AI a trustee runs arrives through administrators and technology partners. CPS 230 makes the trustee responsible for governance over their material service providers, regardless of who operates the technology. The trustee carries the obligation, which is why it’s critical that the trustee also controls the evidence.

Where Loxodrome makes the difference

Evidence over AI you didn’t build

Much super AI is delivered through administrators and technology partners. Loxodrome is designed to capture decision chains across the supply chain, so the trustee holds its own record rather than depending on the provider’s.

A defensible answer to AFCA, ASIC, and members

When members or AFCA ask why a particular outcome was reached, the trustee needs an answer that doesn’t depend on the administrator’s logs. Loxodrome gives trustees decision-level evidence they hold themselves.

Validated once isn’t validated

A tool gets tested at go-live and then runs unexamined for years. Loxodrome keeps testing the decisions it produces against the controls you wrote for it, so the answer to “is it still doing what we approved” comes from records, not from the original sign-off.

Board reporting that survives a trustee duty challenge

Trustees are increasingly asked to demonstrate active oversight of AI in member-facing decisions. Test results across the decision population give the board quantitative evidence of that oversight, with the underlying records available when an outcome is challenged.

For risk, compliance and audit teams in superannuation →

03 / 04

Banking

Credit, fraud and complaints, where every decision has to be explained.

Banks have moved AI into the parts of the business that produce regulatory exposure. Credit decisioning, fraud detection, AML screening, complaint triage, customer-facing chat. ASIC’s Report 798 (October 2024) examined 624 AI use cases across 23 financial services and credit licensees and singled out “unexplainable and inconsistent automated decisions” as a focus area. That applies whether you have models in production today or are still choosing your first use cases. The controls get written before the decisions start.

The pressure point is consistency. Under the NCCP Act a customer can ask for the assessment behind a credit decision and you have to produce it. Under CPS 230, you have to demonstrate control over the systems making those decisions.

Where Loxodrome makes the difference

Decision-level records for credit assessments

Side-by-side reconstruction of any two decisions. What model, what inputs, what changed, why outputs diverged. Defensible to ASIC, AFCA, and the customer.

Continuous control testing over credit, AML and fraud AI

Your control library run against decision records daily, across the population rather than a sample. Failed checks surface as exceptions, with the records that triggered them attached, before a complaint does.

Third-party and fourth-party AI in the same chain

Most credit and fraud stacks rely on third-party models, scoring APIs and bureau data. Loxodrome is designed to capture the decision chain across your systems and theirs, so controls over vendor AI can be tested from records you hold rather than logs the provider produces.

Evidence a complaints handler can read

RG 271 requires you to give a complainant the reasons for the outcome. When an AI system shaped that outcome, Loxodrome turns the decision chain into something a complaints handler can read, without involving data science.

For risk, compliance and audit teams in banking →

04 / 04

Vendors

If you sell AI to an APRA-regulated buyer, CPS 230 is in your contract.

Under CPS 230, an AI vendor that supports a critical operation, or exposes the buyer to material operational risk, is a material service provider. The buyer decides, and the classification triggers a specific list of obligations: prescribed contract terms, audit access, sub-processor disclosure, performance monitoring, exit plans, fourth-party risk. APRA finalised targeted amendments on 30 April 2026 (commencing 1 July 2026) introducing limited exemptions for certain non-traditional service providers, but the core obligations on AI vendors are unchanged. Vendors that cannot meet them stall in procurement.

Independence is the harder problem. APRA’s April 2026 letter observed an overreliance on vendor presentations and summaries without verification of operations, and found that second line and internal audit at regulated entities frequently lack the tooling to assess AI systems. Your buyers have been told to verify. Documentation you generated about your own system, signed by you, gives their assurance functions nothing to verify it against.

Where Loxodrome makes the difference

Independent evidence buyers can verify themselves

Your customers, their auditors, and their regulators can verify your AI’s decision history without your software in the loop. That answers the audit-access clause, the cooperation clause, and the regulatory-access clause in one record.

Shorter procurement, less customisation

A standardised independent evidence layer reduces the per-customer customisation that blows out enterprise sales cycles, and gives every regulated buyer’s assurance team the same verifiable record to test against.

Sub-processor transparency without exposing trade secrets

CPS 230 service-provider obligations require sub-processor notification and downstream liability flow-through. Loxodrome captures the chain at the decision level, what called what and when, without exposing model weights, prompts, or commercially sensitive infrastructure.

Verification the buyer’s auditor can do without you

APRA has told regulated entities to verify vendor claims rather than rely on presentations and summaries. Vendors that arrive with evidence a buyer’s auditor can verify independently have a structural advantage in that conversation.

Where to start

How many of your controls are ready to be tested?

Most AI control libraries were written to be attested, not tested. The AI Control Testing Readiness Assessment takes your library and one live AI-assisted process, and sorts the controls into three lists: what can be tested from records you already hold, what needs a document, and what will always need a person. For the rest, it says what would have to be captured, and where.

We do not access your systems and no decision data leaves your environment, so there is nothing for your security team to review. The memo is yours whether or not you go further.

We respond within two business days. We will not share, sell, or list your organisation publicly.