Owning the Risk: What Running a Brokerage Teaches You About Financial and Privacy Obligations
There is a meaningful difference between advising on risk and carrying it. As the accountable Principal of a mortgage brokerage, I owned NCCP, Best Interests Duty, Privacy Act, and AML obligations under real consequences.
Owning the Risk: What Running a Brokerage Teaches You About Financial and Privacy Obligations
There is a meaningful difference between advising on risk and carrying it. As Principal of a mortgage brokerage — something I have run for the better part of five years, mostly part-time around other contracts — I am the accountable person: the one whose name is against the licence obligations, whose process has to withstand a regulator's review, and who answers for a privacy breach or a poor consumer outcome. That accountability changes how you think about risk. It stops being a framework you assess and becomes an obligation you own.
Regulated by design, not by exception
Mortgage broking sits inside a dense and evolving regulatory perimeter. Building and running a compliant brokerage meant operating fluently across several regimes at once:
- -The National Consumer Credit Protection Act (NCCP) and responsible lending obligations — the requirement to assess that credit is not unsuitable, with the assessment evidenced, not assumed.
- -Best Interests Duty (BID) — the obligation, in force since 2021, to act in the customer's best interests and to demonstrably prioritise them over the broker's own. BID is a genuinely demanding standard because it is outcome- and evidence-based: it is not enough to have acted well; the file has to show the customer's interests drove the recommendation.
- -The Privacy Act and Australian Privacy Principles — every loan application is a concentration of exactly the personal and financial information that does the most damage when mishandled. Collection, consent, storage, and disclosure all had to be governed deliberately.
- -Anti-money-laundering and credit-fraud obligations — the customer-identification and monitoring controls that sit underneath every transaction.
Holding these together is not a compliance exercise you complete once. It's an operating posture: every process in the business had to be designed so that doing the work correctly and meeting the obligation were the same action.
Requirements that change underneath you
The defining feature of financial-services regulation is that the requirements move. Best Interests Duty reshaped the obligations mid-stream. Responsible-lending expectations shifted. Privacy reform is ongoing. Running a brokerage through that meant treating the control environment as something that has to be maintained against a moving baseline, not set once and forgotten.
That is the same discipline that matters in any second-line risk function: regulatory change is not an event you respond to, it's a condition you build for. The processes, the record-keeping, and the controls have to be designed to absorb change without the business grinding to a halt or, worse, quietly falling out of compliance while everyone is busy.
Senior-leader judgement under real consequences
What this experience built, that no framework teaches on its own, is the judgement that comes from carrying consequences. When you are the accountable person for financial and privacy risk in a regulated business, you learn to weigh commercial pressure against obligation in real time, to know which corners genuinely cannot be cut, and to make those calls defensibly and consistently.
That is the posture a senior risk role demands: not just knowledge of the rules, but the seasoned judgement to apply them under pressure, the integrity to hold the line when it's inconvenient, and the record-keeping discipline to show the call was sound. I learned those by owning them, not observing them.
Based on experience as Principal Broker and Director of an AFG-accredited mortgage brokerage — a practice I continue part-time — operating under NCCP, Best Interests Duty, the Privacy Act, and AML/credit-fraud obligations.