AI Decision Audit Trail · APRA-grade

Crystal-clear audit trails for every AI decision.

Compliant. Accountable. Board-ready.

Proofmarc captures every consequential AI decision your institution makes — inputs, model, confidence, human oversight, outcome — and seals it in a tamper-evident chain auditors can verify in seconds.

Built for
APRA CPS 230 APRA CPG 235 APRA CPS 234 ASIC RG 271 ASIC RG 274 BEAR / FAR
The Regulatory Imperative

What APRA is asking — right now.

Five questions every Australian board should be able to answer in 60 seconds. Most can't.
From the desk of · APRA Examiner ·
Re: Governance of artificial intelligence decisioning, CPG 235 / CPS 230 review.
Notice EXAM-2026-184
Response window 14 days
01
"Can you show every AI credit decision made last quarter?"
No audit trail
02
"Which decisions were made without human review?"
Unknown
03
"What were the model inputs for customer C-4421's declined application?"
3 weeks to reconstruct
04
"Has your credit model drifted since deployment?"
No baseline
05
"Are approval rates consistent across demographic groups?"
Manually checked
06
"Can each Accountable Person identify the AI decisions they were personally responsible for this quarter — and attest to the governance applied?"
No FAR register
AI Governance Readiness — Current State
Decisions with a full audit trail 0%
High-consequence decisions reviewed 31%
APRA queries answerable in <60s None
Time to reconstruct last audit 3 weeks
Board Exposure: Critical
The position most boards are in

Boards are exposed.

Most don't know it yet.

Every quarter, more institutions discover their AI is making decisions they can't account for. The questions on this notice aren't hypothetical. They're already on examiners' desks. The risk isn't whether you'll be asked; it's whether you'll have an answer that takes seconds, not weeks.

With Proofmarc
Every answer above is a structured report, generated in under 60 seconds from a queryable audit trail.
Boards are exposed. Most don't know it yet. Proofmarc turns each of these questions into a single-click query against an immutable evidence chain — every model, every decision, every reviewer, every regulatory clause it satisfies.
Proofmarc Verified < 60s audit response 100% decisions captured Tamper-evident chain
Board Attestation & FAR Accountability

When liability is personal,
accountability must be named and sealed.

Under the Financial Accountability Regime, AI governance obligations attach to the individual — not the institution. Proofmarc's Board Attestation module gives every Accountable Person a named, SHA-256 sealed record of their sign-off, tied directly to the audit trail they're attesting to.

  • Named director sign-off per reporting period — Chair, CRO, Head of AI Governance
  • Each attestation SHA-256 hashed and immutable — tampering is detectable, instantly
  • FAR-aligned — maps each Accountable Person to their specific AI obligations under s29
  • Board report generated in under 60 seconds from the live decision audit trail
Board Attestation Log
AI Governance Report  ·  Q2 2026  ·  PM-REPORT-2026-Q2
David Chen
Chair, Board Risk Committee  ·  FAR Accountable Person
pm-att-8f3e2a91c4b7d…  ·  25 Jun 2026
✓ Attested
Sarah Mitchell
Chief Risk Officer  ·  FAR Accountable Person
pm-att-c4a9f12e87d3a…  ·  25 Jun 2026
✓ Attested
James Thornton
Head of AI Governance  ·  FAR Accountable Person
Q2 2026 attestation  ·  Awaiting sign-off
Pending
ALL ATTESTATION RECORDS ARE SHA-256 HASHED AND IMMUTABLE
How it works

Three steps. No rip-outs. No rebuilds.

Sits between your model and its output. Captures every decision. Surfaces every gap.
01
Connect your AI models
A lightweight API webhook sits between your model and its output. One endpoint. No changes to model logic, no vendor lock-in.
One endpoint
02
Every decision, captured
Proofmarc records inputs, model version, raw output, confidence score, human review status, and the final outcome applied. Immutably and instantly.
Immutable chain
03
Board-ready governance
The governance dashboard monitors drift, distribution anomalies, and oversight gaps. Surfacing them before they become regulatory findings.
Audit in seconds
Managed cloud / On-premises option for DISP & government entities / Australian-hosted, sovereign data residency
The Decision Record

Every decision, fully reconstructable.

Inputs. Model. Confidence. Oversight. Outcome. Sealed.
Decision Record · DEC-089142
IMMUTABLE
Audit Log Decisions DEC-089142
Overview
Inputs
Model
Oversight
Outcome
Audit Trail12

The Decision Record

Every decision, fully reconstructable.
Verified by
Proofmarc
● Approved Reviewed
01 · Decision Inputs
Income$94,200
Loan amount$45,000
Credit score711
Employment38 months
02 · Model & Output
ModelCreditAI v2.3.1
Raw output0.9412
DecisionApprove
Threshold0.72
03 · Confidence
94.12%
High confidence
04 · Human Oversight
StatusReviewed
ReviewerEMP-2291
Reviewed at14:22:31
Action takenConfirmed
05 · Final Outcome
Model saidApprove
Final outcomeApproved
OverrideNone
CustomerC-44821
06 · Audit Metadata
Decision IDDEC-089142
Timestamp15 Jun 14:22 UTC
ProductHome loan
ClassificationMaterial
Override Intelligence

Every human override, categorised and explained.

When a reviewer disagrees with an AI decision, that disagreement is a governance signal. Proofmarc captures the reason at the moment it happens — categorised, trend-analysed, and surfaced before it becomes an APRA finding or a pattern a court will notice.

Regulatory / Fairness
The highest individual accountability risk. Each event requires full documentation under CPS 230 §44 and anti-discrimination obligations — and links directly to the FAR register.
Contextual Factor
Reviewers are routinely applying information the model doesn't have. A rising share flags a model retraining need — before the gap becomes a regulatory exposure.
Model Input Error
A concentration above 15% of overrides points to a data pipeline or feature engineering issue upstream of the model. Proofmarc surfaces the affected model so investigation can begin immediately.
Dispute / IDR
Automatically triggers an IDR record requirement under RG 271 and links the override to the Complaints Register — so the regulatory chain of custody is complete from decision to resolution.
Q2 2026  ·  Override Root Cause Analysis
Commonwealth Financial Group
4.2%
Override rate  ·  within 10% policy limit
100%
Overrides categorised at time of review
Contextual Factor
38%
Low Confidence
27%
Model Input Error
19%
Regulatory / Fairness
9%
Other
7%
⚠ PATTERN FLAG DETECTED
Contextual Factor is dominant at 38%. Concentration above 35% warrants formal root cause investigation and a remediation plan before next quarter close.
Now the board can see it too

Because "the AI decided"
is not a governance answer.

Proofmarc gives CROs, CDOs, boards, and external auditors a single, structured view of every consequential AI decision your organisation has made — and how it was governed.

Request a Demo →
scroll to continue
150,000+
AI decisions logged
for design partners
SOC 2 Type IIIn audit, Q3 2026
ISO 27001Aligned controls
Australian Data SovereigntyAWS Sydney, single-region
End-to-end encryptionAES-256 at rest, TLS 1.3 in transit

Sits beside the models you already use.

Proofmarc is model-agnostic. Drop our SDK alongside any LLM provider, foundation model, or in-house decisioning system — we log the decision, not the model weights.

OpenAI
Anthropic
Google Vertex AI
AWS Bedrock
Azure OpenAI
Databricks
Snowflake Cortex
In-house models

When the regulator asks,
the answer must already exist.

01
Credit & Lending Decisions
When a declined applicant escalates to AFCA or APRA questions your model's consistency, you need that specific decision instantly — inputs, confidence, reviewer action — not a weeks-long reconstruction.
APRA CPS 230 ASIC RG 271 Director liability
02
Insurance Claims Triage
When a claimant disputes a settlement or ASIC examines your claims handling, you need to show exactly which decisions were automated, which were escalated, and why — in a format auditors can verify on the spot.
ICA standards ASIC RG 274 Claims auditing
03
Fraud Detection & AML
When AUSTRAC asks why a transaction was flagged — or wasn't — the answer must be documented at the moment it happened. Proofmarc seals the model input, confidence threshold, and reviewer decision the instant it occurs.
AML / CTF Act AUSTRAC Audit-ready
04
Cohort Fairness & Anti-Discrimination
When the Racial Discrimination Act, Sex Discrimination Act, or a human rights challenge questions whether your AI treated demographic groups consistently, Proofmarc surfaces approval rates by cohort, model, and period — before the question reaches litigation or a Senate committee.
RDA · SDA · ADA ASIC RG 274 Cohort monitoring

Four roles. One
source of truth.

Chief Risk Officer
CRO
Real-time visibility over oversight gaps, drift breaches, and high-consequence decisions — without waiting for data science to reconstruct it.
Chief Data Officer
CDO
PSI-scored drift monitoring per model, weekly trend tracking, breach detection with structured remediation plans, and cohort fairness analysis — so your next APRA review has documentation, not gaps.
Board Directors
GOVERNANCE
Named attestation sign-off — tied to the live decision audit trail, SHA-256 sealed, and mapped to your FAR obligations under s29. When the question about personal accountability arrives, the answer is already on record.
External Auditors
AUDIT & ASSURANCE
A scoped read-only portal with structured records, integrity hashes, and compliance checklists — weeks of log reconstruction gone, audit costs down.

Start with what
you need today.

Every tier includes the full six-field Decision Record, immutable audit trail, and APRA reporting. Scale as your governance requirements grow.

Tier 01
Audit
Best for: Compliance leads
For teams beginning their AI governance journey: a complete, audit-ready decision trail without the overhead of a full governance program.
Full 6-field Decision Record
Immutable audit trail (SHA-256)
APRA/ASIC export formats
Up to 3 AI models
Drift monitoring
Board reports
Request Demo
MOST POPULAR
Tier 02
Governance
Best for: CROs & CDOs
For CROs and CDOs who need continuous visibility over AI model behaviour, drift, and oversight gaps. With board-ready reporting built in.
Everything in Audit
Drift monitoring (PSI weekly)
Outcome distribution analysis
Board report generator (<60s)
Director attestation module
Up to 10 AI models
Request Demo
Tier 03
Enterprise
Best for: CIOs & external auditors
For institutions with enterprise-scale AI operations, external audit obligations, and requirements for private cloud or on-premises deployment.
Everything in Governance
External auditor portal
Private cloud / on-premises
Unlimited AI models
Custom reporting periods
Slack/email alerting
Request Demo

All tiers priced by decision volume + registered model count. Contact us to discuss design partnership terms.

See Proofmarc
with your data.

We'll walk you through a live demo using a mock environment that mirrors your AI stack — so you can see exactly what your regulators and board would see.

45-minute working session with a real demo environment
APRA/ASIC posture assessment against your current setup
Board report generated from mock decision data in <60 seconds
No sales pitch — just the product, live, with your questions
Request Demo
We typically respond within one business day.