Who we build for
For the people who have to prove it, whichever line they sit in.
Why Loxodrome
APRA’s April 2026 letter found that second-line and internal audit functions frequently lack the technical capability and tooling to assess AI systems.
Letter to industry on AI, 30 April 2026Every control in your framework mapped by test type, with the instrumentation gaps ranked by exposure.
When a control stops operating, a finding is raised against that control, with the accountable owner identified and the supporting decision records attached.
Inputs, model and version, tool calls, data accessed, the human review step, and the outcome written to the system of record.
Which AI systems are producing records and which aren’t, and what proportion of the relevant population each test examined. Where coverage is partial, the result says so.
Decision records sealed at capture and test results sealed when produced, exported as auditable workpapers.
Each failed test run is packaged for your GRC platform, with complete context from Loxodrome including the case reference, control ID and sealed test result. Loxodrome is not a second issue register.

Second line
CRO · CCO · Head of Operational Risk · Head of Model Risk · CISO
You don’t need another framework. You need your AI logs tested against the controls you already have, across the whole population, independent of the systems being tested.
APRA’s April 2026 letter found that second-line risk and internal audit functions frequently lack the technical capability and tooling to assess AI systems, including probabilistic models. Loxodrome is built to be that tooling.
Control tests run continuously and raise exceptions against the named control, with the accountable owner identified. You learn that a control has stopped operating effectively from your own independent testing, before a self-assessment cycle, a vendor briefing or an incident would surface it.
CPS 230, CPS 234, and ASIC s912A require you to demonstrate control, not describe it. A process narrative describes a control. A test result, with the population it covered and the records that failed it, demonstrates one.
APRA’s review found overreliance on vendor presentations and summaries without verification of operations. Loxodrome’s records sit outside first-line systems and are sealed at ingestion so they cannot be altered afterwards, including by us.
Move past traffic lights. Loxodrome gives your board numbers rather than assurances: which controls were tested, over what population, how many exceptions, and how long they took to close.
The same test covers your QA function. If reviewers agree with the model 99% of the time in three seconds, the review step isn’t working, and the test says so against the oversight control. QA moves from re-checking outputs to checking that the review step is real.
Override and concurrence by reviewer
| Reviewer | Concurrence | Override rate | Median review | |
|---|---|---|---|---|
| Benefit Request Agent1,847 oversight-required decisions · 1,838 reviewed | ||||
| Reviewer 1 | 99.4% | 0.6% | 3.2s | |
| Reviewer 2 | 93.7% | 6.3% | 49s | |
| Reviewer 3 | 91.4% | 8.6% | 58s | |
| Reviewer 4 | 88.8% | 11.2% | 74s | |
| Reviewer 5 | 85.1% | 14.9% | 96s | |
Third line
Chief Audit Executive · Internal Audit · External Auditors
Test what the first and second line say is happening. CPS 234 puts information security controls, including those held by third parties, in your audit scope, and your AI systems sit inside that. Loxodrome gives you an evidence base that doesn’t depend on the systems you’re auditing.
Every result is bound to the decision records it examined and the test version that produced it. Whether you rely on second line’s testing or your external auditor relies on yours, the check is a recomputation, not a redo.
Sampling doesn’t scale to systems that decide continuously. Test every recorded decision against the control’s assertion, not whether a process document exists. Sampling stays, as an independent residual check that the tests are checking the right thing.
Export the sealed set, recompute the chain, confirm nothing has changed, with no Loxodrome account and no request to the model owner. Completeness is reported separately and explicitly; a hash chain proves integrity, not coverage.

First line
Model owners · Operations managers · Business unit leads
Demonstrate your AI is doing what it’s supposed to. When it isn’t, you’re the first to know.
The same test that raises an exception to second line routes it to the named control owner first, with the decision record attached. You fix the control, not the finding.
A signed-off policy is documentation. Your CPS 230 attestation rests on evidence that the control operated, and a sealed test result over the whole population is that evidence, whoever asks for it.
Loxodrome reports which of your AI systems are producing decision records, which aren’t, and where the gap sits. A gap you know about is one you close before it becomes a finding.
If your observability platform uses a model to score decisions, that scorer is a first-line control. Loxodrome tests it like any other: did it run on every decision it was meant to, what did it flag, and did a person act on what it flagged.

Boards
Non-Executive Directors · Audit Committee · Risk Committee · Accountable Persons
Take FAR reasonable steps to ensure executives show you, rather than tell you, what’s happening with the company’s AI.
APRA’s April 2026 letter expects boards to “maintain sufficient understanding and literacy with respect to AI in order to set strategic direction and provide effective challenge and oversight”, and its review found overreliance on vendor presentations and summaries without verification of operations. Under FAR, accountable persons for operational risk, data and IT must take reasonable steps in those areas, and AI now sits inside all three.
Which controls were tested, over what population, how many exceptions were raised, how long they took to close, and which controls haven’t been tested at all. Every number opens back to the sealed result that produced it, so the answer to “how do we know?” doesn’t depend on the people who run the system or the vendor that built it.

Where to start
Most AI control libraries were written to be attested, not tested. The AI Control Testing Readiness Assessment takes your library and one live AI-assisted process, and sorts the controls into three lists: what can be tested from records you already hold, what needs a document, and what will always need a person. For the rest, it says what would have to be captured, and where.
We do not access your systems and no decision data leaves your environment, so there is nothing for your security team to review. The memo is yours whether or not you go further.
Thanks. We will be in touch within two business days.