Due diligence
Compliance and assurance
Our position, what the software helps a lender show, and what has been independently checked.
Our position
Creditcrest Technologies is not a credit provider, is not a credit assistance provider, and does not hold an Australian credit licence. The software produces evidence; the licensee makes every decision.
What the software helps a lender show
- Reasonable inquiries and verification before credit (National Credit Act s 130; RG 209), each answer sealed with the question asked.
- The small and medium loan cost limits and protected earnings, period by period.
- Hardship kept apart from default, with days past due frozen while a plan runs.
- Complaints on their RG 271 clocks, and the IDR data report for ASIC.
- Credit reporting from the ledger, with each condition checked before a default.
- AML/CTF customer due diligence and risk rating, and privacy requests on their clocks.
Independent checks, as they stand
| Check | Status |
|---|---|
| Penetration test by an independent firm | Not done yet. Done before any lender goes live; the summary is shared with lenders |
| SOC 2 or ISO 27001 | Not held. The controls on Security are what is in place today |
| Professional indemnity and cyber insurance | Not held yet |
| Legal review of the Lender Agreement and consumer wording | Before launch |
| Measured accuracy of statement reading | Published, per category, and refreshed with every release: How well it reads |
In use
Pre-launch. Every module is built and tested; none is yet in use with a lender, and nothing has run on a real borrower’s data. A lender can run the software in shadow beside its own process before switching anything on.