{"id":839,"date":"2026-10-07T12:44:26","date_gmt":"2026-10-07T01:44:26","guid":{"rendered":"https:\/\/nexiant.ai\/resources\/blogs\/?p=839"},"modified":"2026-10-07T12:44:29","modified_gmt":"2026-10-07T01:44:29","slug":"automated-decision-transparency-fraud-identity-models","status":"publish","type":"post","link":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/","title":{"rendered":"What Australia&#8217;s New Automated Decision Rules Mean for Fraud and Identity Models"},"content":{"rendered":"\n<style>\n  .nx-blog * { box-sizing: border-box; margin: 0; padding: 0; }\n  .nx-blog { font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, sans-serif; font-size: 16px; line-height: 1.75; color: #1a1a2e; max-width: 820px; margin: 0 auto; }\n  .nx-blog h2 { font-size: 1.55rem; font-weight: 700; color: #00184C; margin: 2.5rem 0 0.75rem; padding-bottom: 0.4rem; border-bottom: 3px solid #073EA1; }\n  .nx-blog h3 { font-size: 1.15rem; font-weight: 700; color: #073EA1; margin: 1.75rem 0 0.5rem; }\n  .nx-blog h4 { font-size: 0.98rem; font-weight: 700; color: #00184C; margin: 1.25rem 0 0.35rem; }\n  .nx-blog p { margin-bottom: 1rem; }\n  .nx-blog ul, .nx-blog ol { margin: 0.5rem 0 1rem 1.4rem; }\n  .nx-blog li { margin-bottom: 0.4rem; }\n  .nx-blog strong { color: #00184C; }\n\n  .nx-hero { background: linear-gradient(135deg, #00184C 0%, #073EA1 100%); color: #fff; border-radius: 12px; padding: 1.75rem 2rem; margin-bottom: 2rem; }\n  .nx-hero .nx-tag { display: inline-block; background: rgba(255,255,255,0.15); color: #AEC9FF; font-size: 0.75rem; font-weight: 600; text-transform: uppercase; letter-spacing: 0.08em; padding: 4px 12px; border-radius: 20px; margin-bottom: 0.6rem; }\n  .nx-hero .nx-meta { font-size: 0.95rem; color: #AEC9FF; margin: 0; }\n\n  .nx-callout { border-left: 4px solid #073EA1; background: #f0f4ff; border-radius: 0 8px 8px 0; padding: 1rem 1.25rem; margin: 1.5rem 0; }\n  .nx-callout.nx-callout--warning { border-left-color: #A30000; background: #fff5f5; }\n  .nx-callout .nx-callout-title { font-size: 0.8rem; font-weight: 700; text-transform: uppercase; letter-spacing: 0.07em; color: #073EA1; margin-bottom: 0.4rem; }\n  .nx-callout.nx-callout--warning .nx-callout-title { color: #A30000; }\n  .nx-callout p { margin: 0; font-size: 0.95rem; color: #1a1a2e; }\n\n  .nx-media { margin: 1.5rem 0 1.75rem; }\n  .nx-media img { width: 100%; height: auto; display: block; border-radius: 12px; border: 1px solid #d0daf5; background: #f5f8ff; }\n  .nx-media .nx-caption { font-size: 0.82rem; color: #666; text-align: center; margin-top: 0.6rem; line-height: 1.5; font-style: italic; }\n\n  .nx-flow { display: grid; grid-template-columns: repeat(4, 1fr); gap: 12px; margin: 1.5rem 0 1.75rem; position: relative; }\n  .nx-flow-step { background: #fff; border: 1px solid #d0daf5; border-radius: 12px; padding: 1rem; text-align: center; position: relative; }\n  .nx-flow-step::after { content: \"\u2192\"; position: absolute; right: -14px; top: 50%; transform: translateY(-50%); color: #073EA1; font-weight: 700; font-size: 1.2rem; }\n  .nx-flow-step:last-child::after { display: none; }\n  .nx-flow-number { width: 30px; height: 30px; border-radius: 50%; background: #073EA1; color: #fff; font-size: 0.8rem; font-weight: 700; display: flex; align-items: center; justify-content: center; margin: 0 auto 0.6rem; }\n  .nx-flow-step h4 { font-size: 0.9rem; color: #00184C; margin-bottom: 0.35rem; }\n  .nx-flow-step p { font-size: 0.8rem; color: #555; margin: 0; line-height: 1.5; }\n\n  .nx-grid { display: grid; grid-template-columns: repeat(auto-fit, minmax(185px, 1fr)); gap: 12px; margin: 1.25rem 0 1.75rem; }\n  .nx-card { background: #fff; border: 1px solid #d0daf5; border-radius: 10px; padding: 1rem; }\n  .nx-card-icon { width: 36px; height: 36px; border-radius: 8px; background: #073EA1; display: flex; align-items: center; justify-content: center; margin-bottom: 0.6rem; }\n  .nx-card-icon svg { width: 18px; height: 18px; fill: #fff; }\n  .nx-card h4 { font-size: 0.88rem; font-weight: 700; color: #00184C; margin-bottom: 0.2rem; }\n  .nx-card p { font-size: 0.8rem; color: #555; margin: 0; line-height: 1.5; }\n\n  .nx-table-wrap { overflow-x: auto; margin: 1.25rem 0 1.75rem; }\n  .nx-table { width: 100%; border-collapse: collapse; font-size: 0.9rem; }\n  .nx-table thead tr { background: #00184C; color: #fff; }\n  .nx-table th { text-align: left; padding: 10px 14px; font-weight: 600; }\n  .nx-table td { padding: 9px 14px; border-bottom: 1px solid #e0e7f5; color: #1a1a2e; vertical-align: top; }\n  .nx-table tbody tr:nth-child(even) { background: #f5f8ff; }\n  .nx-badge { display: inline-block; font-size: 0.73rem; font-weight: 600; padding: 2px 9px; border-radius: 20px; }\n  .nx-badge--red { background: #fde8e8; color: #A30000; }\n  .nx-badge--blue { background: #EEF2FF; color: #073EA1; }\n\n  .nx-signal-panel { background: #f5f8ff; border: 1px solid #d0daf5; border-radius: 12px; padding: 1.25rem; margin: 1.5rem 0 1.75rem; }\n  .nx-signal-panel h3 { margin-top: 0; color: #00184C; }\n  .nx-signal-grid { display: grid; grid-template-columns: repeat(auto-fit, minmax(180px, 1fr)); gap: 10px; margin-top: 1rem; }\n  .nx-signal { background: #fff; border-radius: 10px; padding: 0.9rem; border-left: 4px solid #073EA1; }\n  .nx-signal strong { display: block; font-size: 0.88rem; margin-bottom: 0.25rem; }\n  .nx-signal span { font-size: 0.8rem; color: #555; line-height: 1.5; }\n\n  .nx-scenario { background: linear-gradient(135deg, #00184C 0%, #073EA1 100%); color: #fff; border-radius: 12px; padding: 1.5rem; margin: 1.75rem 0; }\n  .nx-scenario h3 { color: #fff; margin-top: 0; margin-bottom: 0.6rem; }\n  .nx-scenario p { color: #E7EFFF; margin-bottom: 0.8rem; }\n  .nx-scenario ul { margin-bottom: 0; }\n  .nx-scenario li { color: #E7EFFF; }\n\n  .nx-stack { margin: 1.5rem 0 1.75rem; }\n  .nx-stack-layer { display: flex; align-items: flex-start; gap: 14px; background: #fff; border: 1px solid #d0daf5; border-radius: 12px; padding: 1rem; margin-bottom: 10px; }\n  .nx-stack-icon { width: 38px; height: 38px; border-radius: 10px; background: #073EA1; color: #fff; font-weight: 700; font-size: 0.85rem; display: flex; align-items: center; justify-content: center; flex-shrink: 0; }\n  .nx-stack-layer h4 { margin: 0 0 0.25rem; color: #00184C; font-size: 0.95rem; }\n  .nx-stack-layer p { margin: 0; font-size: 0.86rem; color: #444; line-height: 1.6; }\n\n  .nx-obligations { margin: 1.25rem 0 1.75rem; }\n  .nx-obl-item { background: #fff; border: 1px solid #d0daf5; border-left: 4px solid #073EA1; border-radius: 0 10px 10px 0; padding: 1rem 1.25rem; margin-bottom: 10px; }\n  .nx-obl-item h4 { font-size: 0.93rem; font-weight: 700; color: #00184C; margin-bottom: 0.3rem; }\n  .nx-obl-item p { font-size: 0.87rem; color: #444; margin: 0; line-height: 1.6; }\n\n  .nx-inline-link { color: #073EA1; text-decoration: underline; font-weight: 600; }\n  .nx-inline-link:hover { color: #00184C; }\n\n  .nx-faq { margin: 1.25rem 0 1.75rem; }\n  .nx-faq-item { border: 1px solid #d0daf5; border-radius: 8px; margin-bottom: 8px; overflow: hidden; }\n  .nx-faq-q { width: 100%; background: #fff; border: none; text-align: left; padding: 1rem 1.25rem; font-size: 0.95rem; font-weight: 600; color: #00184C; cursor: pointer; display: flex; justify-content: space-between; align-items: center; gap: 1rem; }\n  .nx-faq-q:hover { background: #f5f8ff; }\n  .nx-faq-q .nx-chevron { flex-shrink: 0; width: 20px; height: 20px; border-radius: 50%; background: #EEF2FF; display: flex; align-items: center; justify-content: center; transition: transform 0.25s; }\n  .nx-faq-q .nx-chevron svg { width: 10px; height: 10px; stroke: #073EA1; fill: none; }\n  .nx-faq-q[aria-expanded=\"true\"] .nx-chevron { transform: rotate(180deg); background: #073EA1; }\n  .nx-faq-q[aria-expanded=\"true\"] .nx-chevron svg { stroke: #fff; }\n  .nx-faq-a { display: none; padding: 0 1.25rem 1rem; font-size: 0.92rem; color: #333; line-height: 1.7; background: #fff; }\n  .nx-faq-a.open { display: block; }\n\n  .nx-cta { background: linear-gradient(135deg, #00184C 0%, #073EA1 100%); border-radius: 12px; padding: 2rem; text-align: center; margin-top: 2.5rem; }\n  .nx-cta h3 { color: #fff; font-size: 1.3rem; font-weight: 700; margin-bottom: 0.5rem; }\n  .nx-cta p { color: #AEC9FF; font-size: 0.95rem; margin-bottom: 1.25rem; }\n  .nx-cta a { display: inline-block; background: #E11A1A; color: #fff; font-weight: 700; font-size: 0.95rem; padding: 0.7rem 1.8rem; border-radius: 6px; text-decoration: none; transition: background 0.2s; }\n  .nx-cta a:hover { background: #A30000; }\n  .nx-divider { border: none; border-top: 1px solid #e0e7f5; margin: 2rem 0; }\n  .nx-disclaimer { font-size: 0.8rem; color: #888; font-style: italic; text-align: center; margin-top: 1.5rem; }\n\n  @media (max-width: 720px) {\n    .nx-flow { grid-template-columns: 1fr; }\n    .nx-flow-step::after { content: \"\u2193\"; right: 50%; top: auto; bottom: -18px; transform: translateX(50%); }\n    .nx-stack-layer { flex-direction: column; }\n  }\n<\/style>\n\n<div class=\"nx-blog\">\n\n  <div class=\"nx-hero\">\n    <span class=\"nx-tag\">Regulatory Strategy &nbsp;\u00b7&nbsp; October 2026 &nbsp;\u00b7&nbsp; Australia<\/span>\n    <p class=\"nx-meta\">From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC, screening and scam controls.<\/p>\n  <\/div>\n\n  <p><strong>Automated decision-making in fraud controls<\/strong> becomes a privacy disclosure question in Australia from 10 December 2026. From that date, an organisation that uses a computer program to make, or substantially help make, decisions that could significantly affect a person&#8217;s rights or interests must say so in its privacy policy.<\/p>\n  <p>The Office of the Australian Information Commissioner (OAIC) <a class=\"nx-inline-link\" href=\"https:\/\/www.oaic.gov.au\/news\/media-centre\/new-resources-on-transparency-for-use-of-ai-and-automated-decision-making\" target=\"_blank\" rel=\"noopener\">released its final guidance on 30 September 2026<\/a>, updating its APP 1 Guidelines and publishing a fact sheet and flowchart for the new Australian Privacy Principles (APPs) 1.7 to 1.9.<\/p>\n  <p>For fraud, financial crime and identity teams, writing the privacy policy paragraph is the easy part. The harder question is which of the many automated controls in the customer lifecycle fall within scope, who owns each one, and how the disclosure stays accurate as models and rules change. That question cuts across fraud scoring, customer due diligence (CDD), identity verification, payment authentication and scam interdiction, and it rarely sits with a single team.<\/p>\n  <p>This article sets out what the obligation requires and proposes a governance model risk leaders can use to answer it once, across domains. It is general information, not legal advice.<\/p>\n  <div class=\"nx-media\">\n    <img decoding=\"async\"\n      src=\"data:image\/svg+xml,%3Csvg%20xmlns='http:\/\/www.w3.org\/2000\/svg'%20width='820'%20height='460'%20viewBox='0%200%20820%20460'%3E%3Cdefs%3E%3ClinearGradient%20id='bg'%20x1='0'%20y1='0'%20x2='1'%20y2='1'%3E%3Cstop%20offset='0'%20stop-color='%2300184C'\/%3E%3Cstop%20offset='1'%20stop-color='%23073EA1'\/%3E%3C\/linearGradient%3E%3C\/defs%3E%3Crect%20width='820'%20height='460'%20rx='22'%20fill='url(%23bg)'\/%3E%3Ctext%20x='410'%20y='70'%20text-anchor='middle'%20font-family='Arial,%20sans-serif'%20font-size='30'%20font-weight='700'%20fill='%23ffffff'%3EAutomated%20decisions%3C\/text%3E%3Crect%20x='86'%20y='132'%20width='165'%20height='92'%20rx='18'%20fill='%23ffffff'%20opacity='0.92'\/%3E%3Crect%20x='328'%20y='132'%20width='165'%20height='92'%20rx='18'%20fill='%23ffffff'%20opacity='0.88'\/%3E%3Crect%20x='570'%20y='132'%20width='165'%20height='92'%20rx='18'%20fill='%23ffffff'%20opacity='0.84'\/%3E%3Crect%20x='207'%20y='272'%20width='165'%20height='92'%20rx='18'%20fill='%23ffffff'%20opacity='0.86'\/%3E%3Crect%20x='449'%20y='272'%20width='165'%20height='92'%20rx='18'%20fill='%23ffffff'%20opacity='0.90'\/%3E%3Ccircle%20cx='168'%20cy='162'%20r='16'%20fill='%23073EA1'\/%3E%3Ccircle%20cx='410'%20cy='162'%20r='16'%20fill='%23073EA1'\/%3E%3Ccircle%20cx='652'%20cy='162'%20r='16'%20fill='%23073EA1'\/%3E%3Ccircle%20cx='290'%20cy='302'%20r='16'%20fill='%23073EA1'\/%3E%3Ccircle%20cx='531'%20cy='302'%20r='16'%20fill='%23073EA1'\/%3E%3Ctext%20x='168'%20y='198'%20text-anchor='middle'%20font-family='Arial,%20sans-serif'%20font-size='17'%20font-weight='700'%20fill='%2300184C'%3EIdentity%3C\/text%3E%3Ctext%20x='410'%20y='198'%20text-anchor='middle'%20font-family='Arial,%20sans-serif'%20font-size='17'%20font-weight='700'%20fill='%2300184C'%3EScreening%3C\/text%3E%3Ctext%20x='652'%20y='198'%20text-anchor='middle'%20font-family='Arial,%20sans-serif'%20font-size='17'%20font-weight='700'%20fill='%2300184C'%3EFraud%20score%3C\/text%3E%3Ctext%20x='290'%20y='338'%20text-anchor='middle'%20font-family='Arial,%20sans-serif'%20font-size='17'%20font-weight='700'%20fill='%2300184C'%3EAuthentication%3C\/text%3E%3Ctext%20x='531'%20y='338'%20text-anchor='middle'%20font-family='Arial,%20sans-serif'%20font-size='17'%20font-weight='700'%20fill='%2300184C'%3EScam%20pause%3C\/text%3E%3Ctext%20x='410'%20y='410'%20text-anchor='middle'%20font-family='Arial,%20sans-serif'%20font-size='20'%20font-weight='600'%20fill='%23AEC9FF'%3EOne%20register,%20four%20layers%3C\/text%3E%3C\/svg%3E\"\n      alt=\"Automated decision-making fraud controls visual mapping fraud and identity controls to the automated decisions they make, with a four-layer governance model for APP 1.7 disclosure\"\n      loading=\"lazy\"\n      width=\"820\"\n      height=\"460\"\n    >\n    <p class=\"nx-caption\">Fraud, identity, screening, payment authentication and scam controls can each make or shape decisions about a customer. A single register keeps their disclosure consistent.<\/p>\n  <\/div>\n  <div class=\"nx-flow\">\n    <div class=\"nx-flow-step\">\n      <div class=\"nx-flow-number\">1<\/div>\n      <h4>Program involved<\/h4>\n      <p>A computer program makes the decision, or does something substantially and directly related to making it.<\/p>\n    <\/div>\n    <div class=\"nx-flow-step\">\n      <div class=\"nx-flow-number\">2<\/div>\n      <h4>Significant effect<\/h4>\n      <p>The decision could reasonably be expected to significantly affect an individual&#8217;s rights or interests.<\/p>\n    <\/div>\n    <div class=\"nx-flow-step\">\n      <div class=\"nx-flow-number\">3<\/div>\n      <h4>Personal information<\/h4>\n      <p>Personal information about the individual is used in the program&#8217;s operation.<\/p>\n    <\/div>\n    <div class=\"nx-flow-step\">\n      <div class=\"nx-flow-number\">4<\/div>\n      <h4>Disclose<\/h4>\n      <p>Where all three are met, the privacy policy must describe the decisions and information used.<\/p>\n    <\/div>\n  <\/div>\n  <div class=\"nx-callout\">\n    <div class=\"nx-callout-title\">Quick answer<\/div>\n    <p>From 10 December 2026, Australian organisations must disclose in their privacy policy when a computer program makes, or substantially and directly helps make, decisions that could significantly affect individuals. Many fraud, identity, screening, payment authentication and scam controls can meet that test, even where an analyst makes the final call or a vendor supplies the model. A single cross-domain register of automated decisions, tied to change control, keeps the disclosure accurate.<\/p>\n  <\/div>\n\n  <h2 id=\"what-the-new-app-1-obligation-requires\"><span class=\"ez-toc-section\" id=\"What_the_new_APP_1_obligation_requires\"><\/span>What the new APP 1 obligation requires<span class=\"ez-toc-section-end\"><\/span><\/h2>\n  <p>APP 1.7 applies when three conditions are all met:<\/p>\n  <ul>\n    <li>the entity has arranged for a computer program to make a decision, or to do something substantially and directly related to making it<\/li>\n    <li>the decision could reasonably be expected to significantly affect an individual&#8217;s rights or interests<\/li>\n    <li>personal information about the individual is used in the program&#8217;s operation<\/li>\n  <\/ul>\n  <p>Where they are met, APP 1.8 requires the privacy policy to describe the kinds of personal information used, the kinds of decisions made solely by the program, and the kinds of decisions where the program does something substantially and directly related to the decision. APP 1.9 confirms that refusing or failing to make a decision counts, and that the obligation applies whether the outcome is beneficial or adverse.<\/p>\n  <p>Three features matter most for fraud and identity controls.<\/p>\n  <div class=\"nx-grid\">\n    <div class=\"nx-card\">\n      <div class=\"nx-card-icon\"><svg viewBox=\"0 0 20 20\"><path d=\"M10 1L3 5v6c0 4.25 3 8.22 7 9 4-.78 7-4.75 7-9V5l-7-4zm0 2.18l5 2.78V11c0 3.13-2.18 6.07-5 6.93C7.18 17.07 5 14.13 5 11V5.96l5-2.78z\"\/><\/svg><\/div>\n      <h4>Human review does not take a control out of scope<\/h4>\n      <p>The Explanatory Memorandum describes &#8220;substantially&#8221; as the program being a key factor in facilitating the human&#8217;s decision, and &#8220;directly&#8221; as having a direct connection with making it. A fraud score that analysts almost always follow is likely to meet that description even though a person makes the final call.<\/p>\n    <\/div>\n    <div class=\"nx-card\">\n      <div class=\"nx-card-icon\"><svg viewBox=\"0 0 20 20\"><path d=\"M3 3h14v2H3zm0 4h14v2H3zm0 4h10v2H3zm0 4h7v2H3z\"\/><\/svg><\/div>\n      <h4>The scope is wider than AI<\/h4>\n      <p>The OAIC&#8217;s final guidance confirms the requirements reach well beyond AI-driven decisions and may capture ordinary software, decision-support tools and embedded technologies. Rules engines and threshold logic are not exempt because they are simple.<\/p>\n    <\/div>\n    <div class=\"nx-card\">\n      <div class=\"nx-card-icon\"><svg viewBox=\"0 0 20 20\"><path d=\"M10 2a8 8 0 100 16A8 8 0 0010 2zm1 11H9V9h2v4zm0-6H9V5h2v2z\"\/><\/svg><\/div>\n      <h4>Third-party systems still count<\/h4>\n      <p>The obligation attaches to the entity that arranged for the program to be used. If a vendor&#8217;s model makes or shapes the decision, the organisation deploying it still needs to understand and disclose it, and contracts should state clearly who is making the decision.<\/p>\n    <\/div>\n  <\/div>\n\n  <h2 id=\"why-automated-decision-making-fraud-controls-are-directly-exposed\"><span class=\"ez-toc-section\" id=\"Which_automated_decision-making_fraud_controls_are_exposed\"><\/span>Which automated decision-making fraud controls are exposed<span class=\"ez-toc-section-end\"><\/span><\/h2>\n  <p>Few organisations will struggle to identify a credit-decisioning model as in scope. Fraud and financial crime controls are less obvious because they are framed internally as protections rather than as decisions about a customer. From the customer&#8217;s side, many of them refuse, delay or restrict something.<\/p>\n  <p>The table maps common controls to the decision each one makes or shapes. Whether a particular control meets the &#8220;significantly affect&#8221; condition depends on its real effect, so the right-hand column is a question to test, not a conclusion.<\/p>\n  <div class=\"nx-table-wrap\">\n    <table class=\"nx-table\">\n      <thead>\n        <tr>\n          <th>Control<\/th>\n          <th>Decision it makes or shapes<\/th>\n          <th>Question to test<\/th>\n        <\/tr>\n      <\/thead>\n      <tbody>\n        <tr>\n          <td><strong>Identity verification at onboarding<\/strong><\/td>\n          <td>Accept, refer or decline an application<\/td>\n          <td>Does a failed check stop the person opening an account or receiving a service?<\/td>\n        <\/tr>\n        <tr>\n          <td><strong>PEP and sanctions screening<\/strong><\/td>\n          <td>Hold onboarding or a payment pending match review<\/td>\n          <td>How long can a hold last, and what does the customer lose while it does?<\/td>\n        <\/tr>\n        <tr>\n          <td><strong>Fraud scoring on payments<\/strong><\/td>\n          <td>Allow, step up, hold or decline a transaction<\/td>\n          <td>Is the outcome a short delay, or a refused payment the customer cannot easily retry?<\/td>\n        <\/tr>\n        <tr>\n          <td><strong>Risk-based payment authentication<\/strong><\/td>\n          <td>Approve without friction, or challenge and sometimes decline<\/td>\n          <td>Is a challenge an inconvenience, or does a failed challenge block the purchase?<\/td>\n        <\/tr>\n        <tr>\n          <td><strong>Scam interdiction<\/strong><\/td>\n          <td>Pause, delay or stop an outgoing transfer<\/td>\n          <td>Does the pause affect a time-critical payment such as a property settlement?<\/td>\n        <\/tr>\n        <tr>\n          <td><strong>Transaction monitoring and customer risk rating<\/strong><\/td>\n          <td>Raise alerts that may lead to restriction or exit<\/td>\n          <td>Does the output materially drive account restriction or closure?<\/td>\n        <\/tr>\n      <\/tbody>\n    <\/table>\n  <\/div>\n  <div class=\"nx-signal-panel\">\n    <h3>Two patterns that stand out<\/h3>\n    <p>Looking across the table, two patterns explain why disclosures written team by team tend to fail.<\/p>\n\n    <div class=\"nx-signal-grid\">\n      <div class=\"nx-signal\">\n        <strong>One customer, many controls<\/strong>\n        <span>The same customer can pass through five or six of these controls in one journey, each owned by a different team.<\/span>\n      <\/div>\n      <div class=\"nx-signal\">\n        <strong>Overlapping personal information<\/strong>\n        <span>Most controls draw on identity attributes, device and location data, transaction history and behavioural signals. Disclosures written separately by each team will either repeat each other or contradict each other.<\/span>\n      <\/div>\n    <\/div>\n  <\/div>\n\n  <h2 id=\"a-cross-domain-governance-model-for-automated-decisions\"><span class=\"ez-toc-section\" id=\"A_cross-domain_governance_model_for_automated_decisions\"><\/span>A cross-domain governance model for automated decisions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n  <p>A practical answer is a single register of automated decisions spanning fraud, financial crime, identity and payments, with privacy as reviewer rather than sole owner. A workable model has four layers.<\/p>\n  <div class=\"nx-stack\">\n    <div class=\"nx-stack-layer\">\n      <div class=\"nx-stack-icon\">01<\/div>\n      <div>\n        <h4>Inventory each decision, not each system<\/h4>\n        <p>Record the decision a control makes or shapes rather than the platform it runs on. One transaction monitoring system can support several decisions, such as alert generation, customer risk re-rating and account restriction, and each may need its own assessment. For every decision, capture the business owner, the systems and vendors involved, the personal information used and the possible outcomes, including refusal.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"nx-stack-layer\">\n      <div class=\"nx-stack-icon\">02<\/div>\n      <div>\n        <h4>Assess significance and human involvement consistently<\/h4>\n        <p>Apply one test across all domains for whether a decision could significantly affect rights or interests, and one test for whether the program&#8217;s contribution is substantial and direct. Record the reasoning. A fraud team and a KYC team should not reach opposite conclusions about controls that work in the same way.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"nx-stack-layer\">\n      <div class=\"nx-stack-icon\">03<\/div>\n      <div>\n        <h4>Map in-scope decisions to disclosure language<\/h4>\n        <p>Group in-scope decisions into the kinds of decisions and kinds of personal information the privacy policy will describe. A shared register prevents duplicated or conflicting wording. Disclosure operates at the level of kinds, and commercial-in-confidence information about the systems is excluded, which leaves room to be transparent without describing detection logic.<\/p>\n      <\/div>\n    <\/div>\n    <div class=\"nx-stack-layer\">\n      <div class=\"nx-stack-icon\">04<\/div>\n      <div>\n        <h4>Tie the register to change control<\/h4>\n        <p>The disclosure has to remain accurate after 10 December. Add an automated-decision check to the change process for models, rules, thresholds and vendors. A fraud model that starts declining payments it previously referred, or an identity vendor that introduces biometric matching, may change what the policy needs to say.<\/p>\n      <\/div>\n    <\/div>\n  <\/div>\n  <div class=\"nx-callout nx-callout--warning\">\n    <div class=\"nx-callout-title\">Check disclosures against tipping-off obligations<\/div>\n    <p>Financial crime teams should check privacy policy wording with whoever advises on tipping-off obligations under the AML\/CTF Act, so a privacy disclosure never signals what prompts a suspicious matter report.<\/p>\n  <\/div>\n\n  <h2 id=\"where-accountability-should-sit\"><span class=\"ez-toc-section\" id=\"Where_accountability_should_sit\"><\/span>Where accountability should sit<span class=\"ez-toc-section-end\"><\/span><\/h2>\n  <p>Because these decisions cross domains, accountability usually works best at two levels, with privacy and legal providing review.<\/p>\n  <div class=\"nx-obligations\">\n    <div class=\"nx-obl-item\">\n      <h4>Decision owner<\/h4>\n      <p>Each decision has a business owner in the team that runs the control.<\/p>\n    <\/div>\n    <div class=\"nx-obl-item\">\n      <h4>Register owner<\/h4>\n      <p>A single executive, often the Chief Risk Officer or a delegate, owns the register and settles disagreements about scope.<\/p>\n    <\/div>\n    <div class=\"nx-obl-item\">\n      <h4>Privacy and legal review<\/h4>\n      <p>Privacy and legal review the assessments and own the final policy text.<\/p>\n    <\/div>\n  <\/div>\n  <p>The same structure answers a question boards are likely to ask after December: how many decisions about customers are now made or shaped by software, and who signs off when that changes?<\/p>\n\n  <h2 id=\"what-to-do-before-10-december\"><span class=\"ez-toc-section\" id=\"What_to_do_before_10_December\"><\/span>What to do before 10 December<span class=\"ez-toc-section-end\"><\/span><\/h2>\n  <ol>\n    <li>Inventory fraud, identity, screening, payment authentication and scam controls, starting with those that can refuse or stop something.<\/li>\n    <li>Apply the OAIC&#8217;s three-condition test consistently and record the reasoning for each decision.<\/li>\n    <li>Identify vendor-provided models and confirm contractually who makes each decision.<\/li>\n    <li>Draft grouped disclosure language with privacy, legal and financial crime input.<\/li>\n    <li>Add an automated-decision check to model, rule and vendor change processes.<\/li>\n    <li>Report the register and its ownership to the risk committee.<\/li>\n  <\/ol>\n\n  <h2 id=\"how-nexiant-supports-automated-decision-governance\"><span class=\"ez-toc-section\" id=\"How_Nexiant_supports_automated_decision_governance\"><\/span>How Nexiant supports automated decision governance<span class=\"ez-toc-section-end\"><\/span><\/h2>\n  <p>Nexiant brings together specialist capabilities across <a class=\"nx-inline-link\" href=\"\/solutions\/membercheck\/pep-sanctions-screening\/\">AML screening<\/a>, <a class=\"nx-inline-link\" href=\"\/solutions\/membercheck\/id-verification\/\">identity verification<\/a>, <a class=\"nx-inline-link\" href=\"\/solutions\/fraudshield\/transaction-monitoring\/\">transaction monitoring<\/a> and <a class=\"nx-inline-link\" href=\"\/solutions\/gpayments\/3ds-issuing\/\">payment authentication<\/a> through MemberCheck, NameScan, FraudShield and GPayments. Organisations running these controls can use the model above to decide which automated decisions need disclosure, and to keep that disclosure accurate as their controls change.<\/p>\n\n  <hr class=\"nx-divider\">\n\n  <h2 id=\"frequently-asked-questions\"><span class=\"ez-toc-section\" id=\"Frequently_Asked_Questions\"><\/span>Frequently Asked Questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n  <div class=\"nx-faq\">\n    <div class=\"nx-faq-item\">\n      <button class=\"nx-faq-q\" aria-expanded=\"false\">When does the automated decision transparency obligation start?<span class=\"nx-chevron\"><svg viewBox=\"0 0 10 6\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M1 1l4 4 4-4\"\/><\/svg><\/span><\/button>\n      <div class=\"nx-faq-a\">It commences on 10 December 2026. The OAIC released its final guidance on 30 September 2026, including updated APP 1 Guidelines, a fact sheet and a flowchart.<\/div>\n    <\/div>\n    <div class=\"nx-faq-item\">\n      <button class=\"nx-faq-q\" aria-expanded=\"false\">Which automated decision-making fraud controls are likely to be in scope?<span class=\"nx-chevron\"><svg viewBox=\"0 0 10 6\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M1 1l4 4 4-4\"\/><\/svg><\/span><\/button>\n      <div class=\"nx-faq-a\">Any control that makes, or does something substantially and directly related to making, a decision that could significantly affect a person, using their personal information. Identity verification at onboarding, screening holds, fraud scoring on payments, risk-based payment authentication, scam interdiction and transaction monitoring that leads to restriction or exit should all be tested against that condition.<\/div>\n    <\/div>\n    <div class=\"nx-faq-item\">\n      <button class=\"nx-faq-q\" aria-expanded=\"false\">Does a fraud alert reviewed by an analyst still need to be disclosed?<span class=\"nx-chevron\"><svg viewBox=\"0 0 10 6\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M1 1l4 4 4-4\"\/><\/svg><\/span><\/button>\n      <div class=\"nx-faq-a\">It may. The obligation covers programs that do something substantially and directly related to a decision, not only fully automated decisions. If the score is a key factor in the analyst&#8217;s decision, human review is unlikely to take it out of scope.<\/div>\n    <\/div>\n    <div class=\"nx-faq-item\">\n      <button class=\"nx-faq-q\" aria-expanded=\"false\">Do we have to explain how our fraud or screening models work?<span class=\"nx-chevron\"><svg viewBox=\"0 0 10 6\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M1 1l4 4 4-4\"\/><\/svg><\/span><\/button>\n      <div class=\"nx-faq-a\">No. The privacy policy must describe the kinds of personal information used and the kinds of decisions involved, not the detection logic. Commercial-in-confidence information about the systems is excluded. Check the wording against AML\/CTF tipping-off obligations.<\/div>\n    <\/div>\n    <div class=\"nx-faq-item\">\n      <button class=\"nx-faq-q\" aria-expanded=\"false\">Do vendor-provided identity and screening tools count?<span class=\"nx-chevron\"><svg viewBox=\"0 0 10 6\" stroke-width=\"1.5\" stroke-linecap=\"round\" stroke-linejoin=\"round\"><path d=\"M1 1l4 4 4-4\"\/><\/svg><\/span><\/button>\n      <div class=\"nx-faq-a\">Yes. The obligation sits with the entity that arranged for the program to be used, so a vendor&#8217;s model that makes or shapes a decision still needs to be assessed and, where in scope, disclosed.<\/div>\n    <\/div>\n  <\/div>\n\n  <div class=\"nx-cta\">\n    <h3>Map the automated decisions across your controls<\/h3>\n    <p>Speak with a Nexiant expert about how your fraud, identity and financial crime controls fit together, and where automated decisions sit across them.<\/p>\n    <a href=\"https:\/\/nexiant.ai\/contact-us\/\">Speak to our fraud and identity team<\/a>\n  <\/div>\n\n  <p class=\"nx-disclaimer\">This article was accurate at the time of publication in October 2026 and is intended for general informational purposes only. It does not constitute legal, regulatory or compliance advice. Organisations should seek qualified professional guidance in relation to their specific obligations.<\/p>\n\n<\/div>\n\n<script>\n  document.querySelectorAll('.nx-faq-q').forEach(function(btn) {\n    btn.addEventListener('click', function() {\n      var expanded = this.getAttribute('aria-expanded') === 'true';\n      this.setAttribute('aria-expanded', !expanded);\n      this.nextElementSibling.classList.toggle('open', !expanded);\n    });\n  });\n<\/script>\n\n<script type=\"application\/ld+json\">\n{\n  \"@context\": \"https:\/\/schema.org\",\n  \"@type\": \"FAQPage\",\n  \"mainEntity\": [\n    {\n      \"@type\": \"Question\",\n      \"name\": \"When does the automated decision transparency obligation start?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"It commences on 10 December 2026. The OAIC released its final guidance on 30 September 2026, including updated APP 1 Guidelines, a fact sheet and a flowchart.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Which automated decision-making fraud controls are likely to be in scope?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Any control that makes, or does something substantially and directly related to making, a decision that could significantly affect a person, using their personal information. Identity verification at onboarding, screening holds, fraud scoring on payments, risk-based payment authentication, scam interdiction and transaction monitoring that leads to restriction or exit should all be tested against that condition.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Does a fraud alert reviewed by an analyst still need to be disclosed?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"It may. The obligation covers programs that do something substantially and directly related to a decision, not only fully automated decisions. If the score is a key factor in the analyst's decision, human review is unlikely to take it out of scope.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Do we have to explain how our fraud or screening models work?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"No. The privacy policy must describe the kinds of personal information used and the kinds of decisions involved, not the detection logic. Commercial-in-confidence information about the systems is excluded. Check the wording against AML\/CTF tipping-off obligations.\"\n      }\n    },\n    {\n      \"@type\": \"Question\",\n      \"name\": \"Do vendor-provided identity and screening tools count?\",\n      \"acceptedAnswer\": {\n        \"@type\": \"Answer\",\n        \"text\": \"Yes. The obligation sits with the entity that arranged for the program to be used, so a vendor's model that makes or shapes a decision still needs to be assessed and, where in scope, disclosed.\"\n      }\n    }\n  ]\n}\n<\/script>\n","protected":false},"excerpt":{"rendered":"<p>Regulatory Strategy &nbsp;\u00b7&nbsp; October 2026 &nbsp;\u00b7&nbsp; Australia From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC, screening and scam controls. Automated decision-making in fraud controls becomes a privacy disclosure question in Australia from 10 December 2026. From that date, an organisation that uses a computer program [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":841,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_aioseo_title":"APP 1.7 Automated Decisions in Fraud and KYC Controls","_aioseo_description":"From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC and scam controls.","om_disable_all_campaigns":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-839","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fraudprevention"],"blocksy_meta":[],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.0.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC and scam controls.\" \/>\n\t<meta name=\"robots\" content=\"max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n\t<meta name=\"author\" content=\"Zeeshan Rizvi\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.0.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"AI-Assisted Fraud Prevention and Risk Management - Nexiant\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"APP 1.7 Automated Decisions in Fraud and KYC Controls\" \/>\n\t\t<meta property=\"og:description\" content=\"From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC and scam controls.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/nexiant.ai\/resources\/blogs\/wp-content\/uploads\/2025\/11\/Nexiant-Dark-Logo-Apr.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/nexiant.ai\/resources\/blogs\/wp-content\/uploads\/2025\/11\/Nexiant-Dark-Logo-Apr.png\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-10-07T01:44:26+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-10-07T01:44:29+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"APP 1.7 Automated Decisions in Fraud and KYC Controls\" \/>\n\t\t<meta name=\"twitter:description\" content=\"From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC and scam controls.\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/nexiant.ai\/resources\/blogs\/wp-content\/uploads\/2025\/11\/Nexiant-Dark-Logo-Apr.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#blogposting\",\"name\":\"APP 1.7 Automated Decisions in Fraud and KYC Controls\",\"headline\":\"What Australia&#8217;s New Automated Decision Rules Mean for Fraud and Identity Models\",\"author\":{\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/author\\\/zeeshan\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Automated-Decision-Rules-scaled.jpg\",\"width\":2560,\"height\":1280},\"datePublished\":\"2026-10-07T12:44:26+11:00\",\"dateModified\":\"2026-10-07T12:44:29+11:00\",\"inLanguage\":\"en-AU\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#webpage\"},\"articleSection\":\"Fraud Prevention\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/category\\\/fraudprevention\\\/#listItem\",\"name\":\"Fraud Prevention\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/category\\\/fraudprevention\\\/#listItem\",\"position\":2,\"name\":\"Fraud Prevention\",\"item\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/category\\\/fraudprevention\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#listItem\",\"name\":\"What Australia&#8217;s New Automated Decision Rules Mean for Fraud and Identity Models\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#listItem\",\"position\":3,\"name\":\"What Australia&#8217;s New Automated Decision Rules Mean for Fraud and Identity Models\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/category\\\/fraudprevention\\\/#listItem\",\"name\":\"Fraud Prevention\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/#organization\",\"name\":\"AI-Assisted Fraud Prevention and Risk Management\",\"description\":\"Nexiant\",\"url\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/wp-nexiant.nexiant.ai\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/Nexiant-Dark-Logo-Apr.png\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/company\\\/nexiantai\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/author\\\/zeeshan\\\/#author\",\"url\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/author\\\/zeeshan\\\/\",\"name\":\"Zeeshan Rizvi\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/5060e430addd1087c0299e5ea76cd12ea794a85047ffecd5cfbbf24f4c1fbb2f?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Zeeshan Rizvi\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#webpage\",\"url\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/\",\"name\":\"APP 1.7 Automated Decisions in Fraud and KYC Controls\",\"description\":\"From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC and scam controls.\",\"inLanguage\":\"en-AU\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/author\\\/zeeshan\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/author\\\/zeeshan\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/wp-content\\\/uploads\\\/2026\\\/10\\\/Automated-Decision-Rules-scaled.jpg\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#mainImage\",\"width\":2560,\"height\":1280},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/automated-decision-transparency-fraud-identity-models\\\/#mainImage\"},\"datePublished\":\"2026-10-07T12:44:26+11:00\",\"dateModified\":\"2026-10-07T12:44:29+11:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/#website\",\"url\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/\",\"name\":\"AI-Assisted Fraud Prevention and Risk Management\",\"description\":\"Nexiant\",\"inLanguage\":\"en-AU\",\"publisher\":{\"@id\":\"https:\\\/\\\/nexiant.ai\\\/resources\\\/blogs\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"APP 1.7 Automated Decisions in Fraud and KYC Controls","description":"From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC and scam controls.","canonical_url":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/","robots":"max-snippet:-1, max-image-preview:large, max-video-preview:-1","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#blogposting","name":"APP 1.7 Automated Decisions in Fraud and KYC Controls","headline":"What Australia&#8217;s New Automated Decision Rules Mean for Fraud and Identity Models","author":{"@id":"https:\/\/nexiant.ai\/resources\/blogs\/author\/zeeshan\/#author"},"publisher":{"@id":"https:\/\/nexiant.ai\/resources\/blogs\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/nexiant.ai\/resources\/blogs\/wp-content\/uploads\/2026\/10\/Automated-Decision-Rules-scaled.jpg","width":2560,"height":1280},"datePublished":"2026-10-07T12:44:26+11:00","dateModified":"2026-10-07T12:44:29+11:00","inLanguage":"en-AU","mainEntityOfPage":{"@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#webpage"},"isPartOf":{"@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#webpage"},"articleSection":"Fraud Prevention"},{"@type":"BreadcrumbList","@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/nexiant.ai\/resources\/blogs#listItem","position":1,"name":"Home","item":"https:\/\/nexiant.ai\/resources\/blogs","nextItem":{"@type":"ListItem","@id":"https:\/\/nexiant.ai\/resources\/blogs\/category\/fraudprevention\/#listItem","name":"Fraud Prevention"}},{"@type":"ListItem","@id":"https:\/\/nexiant.ai\/resources\/blogs\/category\/fraudprevention\/#listItem","position":2,"name":"Fraud Prevention","item":"https:\/\/nexiant.ai\/resources\/blogs\/category\/fraudprevention\/","nextItem":{"@type":"ListItem","@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#listItem","name":"What Australia&#8217;s New Automated Decision Rules Mean for Fraud and Identity Models"},"previousItem":{"@type":"ListItem","@id":"https:\/\/nexiant.ai\/resources\/blogs#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#listItem","position":3,"name":"What Australia&#8217;s New Automated Decision Rules Mean for Fraud and Identity Models","previousItem":{"@type":"ListItem","@id":"https:\/\/nexiant.ai\/resources\/blogs\/category\/fraudprevention\/#listItem","name":"Fraud Prevention"}}]},{"@type":"Organization","@id":"https:\/\/nexiant.ai\/resources\/blogs\/#organization","name":"AI-Assisted Fraud Prevention and Risk Management","description":"Nexiant","url":"https:\/\/nexiant.ai\/resources\/blogs\/","logo":{"@type":"ImageObject","url":"https:\/\/wp-nexiant.nexiant.ai\/wp-content\/uploads\/2025\/11\/Nexiant-Dark-Logo-Apr.png","@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#organizationLogo"},"image":{"@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#organizationLogo"},"sameAs":["https:\/\/www.linkedin.com\/company\/nexiantai"]},{"@type":"Person","@id":"https:\/\/nexiant.ai\/resources\/blogs\/author\/zeeshan\/#author","url":"https:\/\/nexiant.ai\/resources\/blogs\/author\/zeeshan\/","name":"Zeeshan Rizvi","image":{"@type":"ImageObject","@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/5060e430addd1087c0299e5ea76cd12ea794a85047ffecd5cfbbf24f4c1fbb2f?s=96&d=mm&r=g","width":96,"height":96,"caption":"Zeeshan Rizvi"}},{"@type":"WebPage","@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#webpage","url":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/","name":"APP 1.7 Automated Decisions in Fraud and KYC Controls","description":"From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC and scam controls.","inLanguage":"en-AU","isPartOf":{"@id":"https:\/\/nexiant.ai\/resources\/blogs\/#website"},"breadcrumb":{"@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#breadcrumblist"},"author":{"@id":"https:\/\/nexiant.ai\/resources\/blogs\/author\/zeeshan\/#author"},"creator":{"@id":"https:\/\/nexiant.ai\/resources\/blogs\/author\/zeeshan\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/nexiant.ai\/resources\/blogs\/wp-content\/uploads\/2026\/10\/Automated-Decision-Rules-scaled.jpg","@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#mainImage","width":2560,"height":1280},"primaryImageOfPage":{"@id":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/#mainImage"},"datePublished":"2026-10-07T12:44:26+11:00","dateModified":"2026-10-07T12:44:29+11:00"},{"@type":"WebSite","@id":"https:\/\/nexiant.ai\/resources\/blogs\/#website","url":"https:\/\/nexiant.ai\/resources\/blogs\/","name":"AI-Assisted Fraud Prevention and Risk Management","description":"Nexiant","inLanguage":"en-AU","publisher":{"@id":"https:\/\/nexiant.ai\/resources\/blogs\/#organization"}}]},"og:locale":"en_US","og:site_name":"AI-Assisted Fraud Prevention and Risk Management - Nexiant","og:type":"article","og:title":"APP 1.7 Automated Decisions in Fraud and KYC Controls","og:description":"From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC and scam controls.","og:url":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/","og:image":"https:\/\/nexiant.ai\/resources\/blogs\/wp-content\/uploads\/2025\/11\/Nexiant-Dark-Logo-Apr.png","og:image:secure_url":"https:\/\/nexiant.ai\/resources\/blogs\/wp-content\/uploads\/2025\/11\/Nexiant-Dark-Logo-Apr.png","article:published_time":"2026-10-07T01:44:26+00:00","article:modified_time":"2026-10-07T01:44:29+00:00","twitter:card":"summary_large_image","twitter:title":"APP 1.7 Automated Decisions in Fraud and KYC Controls","twitter:description":"From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC and scam controls.","twitter:image":"https:\/\/nexiant.ai\/resources\/blogs\/wp-content\/uploads\/2025\/11\/Nexiant-Dark-Logo-Apr.png"},"aioseo_meta_data":{"post_id":"839","title":"APP 1.7 Automated Decisions in Fraud and KYC Controls","description":"From 10 December 2026, Australian privacy policies must disclose significant automated decisions. A governance model for fraud, KYC and scam controls.","keywords":null,"keyphrases":{"focus":{"keyphrase":"automated decision-making fraud controls","score":0,"analysis":[]},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-10-07 01:36:46","updated":"2026-10-07 01:44:29","focus_keyword":"automated decision-making fraud controls","additional_keywords":null,"truseo_locale":null,"seo_analyzer_scan_date":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/nexiant.ai\/resources\/blogs\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/nexiant.ai\/resources\/blogs\/category\/fraudprevention\/\" title=\"Fraud Prevention\">Fraud Prevention<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tWhat Australia\u2019s New Automated Decision Rules Mean for Fraud and Identity Models\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/nexiant.ai\/resources\/blogs"},{"label":"Fraud Prevention","link":"https:\/\/nexiant.ai\/resources\/blogs\/category\/fraudprevention\/"},{"label":"What Australia&#8217;s New Automated Decision Rules Mean for Fraud and Identity Models","link":"https:\/\/nexiant.ai\/resources\/blogs\/automated-decision-transparency-fraud-identity-models\/"}],"_links":{"self":[{"href":"https:\/\/nexiant.ai\/resources\/blogs\/wp-json\/wp\/v2\/posts\/839","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nexiant.ai\/resources\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/nexiant.ai\/resources\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/nexiant.ai\/resources\/blogs\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/nexiant.ai\/resources\/blogs\/wp-json\/wp\/v2\/comments?post=839"}],"version-history":[{"count":1,"href":"https:\/\/nexiant.ai\/resources\/blogs\/wp-json\/wp\/v2\/posts\/839\/revisions"}],"predecessor-version":[{"id":840,"href":"https:\/\/nexiant.ai\/resources\/blogs\/wp-json\/wp\/v2\/posts\/839\/revisions\/840"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nexiant.ai\/resources\/blogs\/wp-json\/wp\/v2\/media\/841"}],"wp:attachment":[{"href":"https:\/\/nexiant.ai\/resources\/blogs\/wp-json\/wp\/v2\/media?parent=839"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/nexiant.ai\/resources\/blogs\/wp-json\/wp\/v2\/categories?post=839"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/nexiant.ai\/resources\/blogs\/wp-json\/wp\/v2\/tags?post=839"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}