Canberra regtech startup LedgerClarity secured a 24-month ASIC enhanced regulatory sandbox exemption to test software that assembles open-banking dispute dossiers from Consumer Data Right feeds, pairing automated narrative drafts with mandatory human sign-off before complaints reach the Australian Financial Complaints Authority.
What the sandbox allows
Under INFO 248, eligible firms may trial financial services without a full Australian financial services licence for up to two years if they meet innovation, net-public-benefit, and exposure caps—$5 million aggregate and $10,000 per retail client on relevant products. LedgerClarity’s notification, accepted after the statutory waiting period, covers a “dispute preparation” service for accredited data recipients and small lenders, not legal representation itself.
The product pulls transaction and consent metadata that consumers already share under CDR rules, then maps discrepancies—duplicate debits, missing refunds, misaligned direct debits—to template paragraphs aligned with ASIC Regulatory Guide 271 internal dispute resolution steps. Users must acknowledge a plain-language scope screen stating the bot does not file with AFCA automatically.
Why open-banking disputes need tooling
OAIC assessment reports on CDR participants found many policies mention AFCA but omit OAIC review paths or skip RG 271’s acknowledgement-investigation-response sequence. Consumers confused about which regulator handles data versus payments complaints often stall at internal dispute resolution. LedgerClarity argues structured drafts reduce back-and-forth when banks already hold the underlying JSON payloads.
AFCA remains the recognised external scheme for banking-sector CDR disputes; the bots stop at generating PDF bundles with chronologies, consent IDs, and suggested remediation amounts. Compliance officers must click approve, matching sandbox conduct conditions. Professional indemnity insurance and AFCA membership are prerequisites LedgerClarity carried into the notification.
Human-in-the-loop design
Founders told InfoHandle every export includes a reviewer attestation field logged for ASIC Innovation Hub check-ins. Machine learning summarises merchant strings and flags potential hardship keywords, but final wording is editable. Sandbox rules prohibit misleading conduct; the UI colours uncertain claims amber until a human removes them.
Competing law firms worry unauthorised practice of law; LedgerClarity’s counsel classifies the tool as document assembly, similar to tax prep wizards. Still, the firm capped retail exposure under sandbox limits and invited ASIC observers to quarterly demos—a transparency move common among Innovation Hub alumni.
Risks regulators will watch
Privacy advocates asked whether aggregating CDR payloads for dispute narratives expands data use beyond consumer expectations. LedgerClarity’s consent flow requires a fresh CDR purpose string and stores artefacts encrypted at rest in Canberra Azure regions. OAIC could investigate mishandling separate from ASIC’s sandbox oversight if consumers complain about secondary use.
Accredited data recipients may hesitate to partner while liability for erroneous AFCA packs remains untested. LedgerClarity’s first pilot is with a mutual bank’s internal complaints team, not retail login—B2B2C rollout waits until sandbox metrics show decline rates on incomplete complaints.
Timeline and milestones
Sandbox clocks start from notification acceptance; LedgerClarity has until late 2028 to graduate to full licensing or wind down. Milestones include 200 reviewed dossiers, median preparation time under 45 minutes, and zero upheld misconduct findings. If successful, the firm will seek an AFS licence covering class advice limited to dispute formatting.
For Canberra’s small regtech scene, the approval signals ASIC still entertains CDR-adjacent experiments even as government reviews sandbox permanence. Open-banking dispute bots will not replace ombudsman staff—but they may stop consumers retyping transaction tables AFCA already expects banks to supply.
LedgerClarity plans a public metrics blog after the first 50 cases, redacting account numbers, to show whether dossiers shorten IDR turnaround—a transparency play designed to reassure mutual bank boards before wider API keys are issued.
Innovation Hub staff set quarterly check-ins to verify exposure caps stay under sandbox limits as pilot banks route more CDR consents through the tool. LedgerClarity built kill switches that revoke API tokens if aggregate retail exposure approaches the $5 million ceiling, a safeguard ASIC reviewers requested after seeing similar fintechs breach caps quietly.
Consumer advocates welcomed human sign-off but asked for plain-language disclosure when AI drafts include predicted AFCA outcomes; the startup removed probability language entirely, sticking to chronologies and amounts already visible in raw data. That design choice may slow marketing claims but keeps conduct risk inside sandbox guardrails.
If graduation to a full licence succeeds, LedgerClarity founders said Canberra’s talent pool—public servants who wrote CDR rules—gives them an edge over Sydney competitors chasing the same AFCA formatting niche. For now, the sandbox letter on the wall matters more than another pitch deck.








