Skip to content

PAN Lab example

Workforce Australia Targeted Compliance Framework

The lesson not learned: automated compliance sanctioning after a scandal

From 2022, Australia's automated Targeted Compliance Framework cancelled payments without weighing jobseekers' reasonable excuses for missed requirements. The Ombudsman found 1,009 jobseekers' payments unlawfully cancelled.

See more

The Targeted Compliance Framework is Australia's mostly automated system for enforcing mutual obligations, the requirements jobseekers must meet to keep their welfare payments. The Department of Employment and Workplace Relations (DEWR) owns the policy, and Services Australia makes the payment decisions. The Framework's fixed rules turn failures that private employment-services providers record into demerits, payment suspensions, and cancellations.

How it works

The Framework has run since 1 July 2018 under the Social Security (Administration) Act 1999, Divisions 3AA and 3A. It is a fixed set of rules, not a machine-learning risk score.

It moves each person through three zones: Green, Warning, and Penalty. Each failure a provider records adds a demerit. At three demerits, a capability interview is triggered. The sources read for this case do not describe that interview further.

Five demerits within six months move a person from the Warning Zone to the Penalty Zone. There, one failure automatically costs 50 percent of payment, and two failures cost 100 percent. Payment suspensions also apply automatically when a failure is recorded.

It works at very large scale. Advocacy analysis of departmental data describes roughly 2.5 million payment-suspension notices a year to about a million people. It also describes 200,000 to 240,000 people facing suspension threats each quarter. By one government account, nearly half of all employment-service users have faced a suspension threat.

What the law required

In April 2022, the SPROM Act changed the rules. Its full name is the Social Security Legislation Amendment (Streamlined Participation Requirements and other Measures) Act 2022.

It required a decision-maker to use discretion before cancelling a payment. That means considering the person's circumstances, or whether they had a reasonable excuse for missing a requirement.

It also required the Secretary to set up the Digital Protection Framework, a safeguard for automated decisions. It remained unfinalised roughly three years later.

The Framework's automated logic never included the discretionary step. Services Australia staff with the legal power to make these decisions, called delegates, sign off cancellations. They did not exercise the discretion independently. Analysis of the reviews counted some 986 cancellation decisions made without properly considering a reasonable excuse.

What the reviews found in the software

DEWR commissioned an independent assurance review from Deloitte in December 2024. It was delivered in June 2025 and cost A$439,142.

It found the Framework's IT system increasingly unstable, with five IT errors dating to 2018. It concluded that it could not assure the integrity, effectiveness, or appropriateness of decisions.

Analysis of the reviews counted about 55 IT defects in all. Three major bugs produced nearly 1,800 incorrect penalties. One bug went undetected for roughly five years and kept people in the Penalty Zone beyond the required time. Another lowered the point at which severe penalties applied, without legislative authority.

The review was later found to contain fabricated citations: a court quote and academic references that do not exist. DEWR released a corrected version, and Deloitte partially refunded its fee. The Ombudsman independently confirmed the review's core operational findings.

How it was caught

The defect ran from April 2022. External legal advisors detected it in September 2023, roughly eighteen months later.

The case file says that flag should have prompted a pause around March 2024. Cancellations were not paused until July 2024. DEWR and Services Australia ordered the pause.

The Commonwealth Ombudsman's first report, Automation in the Targeted Compliance Framework, was published on 6 August 2025. It called the roughly ten-month gap between the flag and the pause not acceptable.

It found that DEWR and Services Australia had acted contrary to the law. They had unlawfully cancelled the payments of 1,009 jobseekers, with a potentially catastrophic impact on vulnerable people. A further 45 were cancelled automatically after the pause was ordered.

Reports give the first figure as more than 900, 964, or 1,009. The case file calls 1,009 the most precise and most widely cited. Both agencies accepted all seven of the report's recommendations.

What the second report found

The Ombudsman's second report, Fairness in the Targeted Compliance Framework, was published on 9 December 2025. It found that automatic suspensions in the Penalty Zone undermine a jobseeker's ability to challenge penalties.

It found that DEWR's assessment of provider performance lacks transparency. It also found that review overturns a high rate of provider decisions.

The complaints line was overwhelmed. More than 140,000 calls to it went unanswered between November 2024 and September 2025. Over 8,000 complaints were documented between July 2025 and March 2026.

Who was harmed and what has been repaid

The cancelled payments were jobseekers' subsistence income. First Nations people are reported to have had disproportionately higher cancellation rates. That observation is recorded outside the Framework's own logic.

As at 1 December, DEWR had made 651 recommendations for immediate compensation, totalling A$936,124.80. With Services Australia, it had repaid 604 people a total of A$872,963.80. The case file does not give the year of that date.

The wider review of cancellations

A separate and far larger review covers automated cancellations under section 42AM. DEWR earlier published a figure of up to 9,510 unlawful cancellations or reductions.

Economic Justice Australia, an advocacy group, estimated potential exposure near 310,000. At a Senate estimates hearing in June 2026, a DEWR taskforce lead said the number was in the vicinity of that estimate.

The official then said that 55 to 70 percent may have legitimately lost eligibility. That implies roughly 93,000, or potentially more than 100,000, unlawful cancellations. It is about ten times DEWR's earlier figure.

These larger figures are estimates of potentially unlawful cases, pending case-by-case assessment. They are not confirmed cancellations.

Why it is called the lesson not learned

The scandal has been framed as a post-Robodebt failure: "first robodebt, now robodole". Robodebt was Australia's earlier automated scheme for raising welfare debts. Its end required courts and a Royal Commission.

The Framework was built after Robodebt and meant to have learned its lessons. This time the corrective loop existed: the Ombudsman, a commissioned assurance review, a parliamentary committee, and Senate estimates scrutiny.

But it acted late. The case file says a loop that catches a population-scale unlawfulness months to years after it starts does not prevent the harm. Such a loop records the harm afterwards.

The case file contrasts two other cases. Michigan's MiDAS was a system with a high error rate and no correction loop. The Medicaid unwinding was an accurate system carrying one wrong setting.

Reform and where it stands

In November 2023, the House Select Committee on Workforce Australia Employment Services reported in Rebuilding Employment Services. It recommended replacing the Framework with a Shared Accountability Framework. It concluded that the Framework's problems could not be fixed by minor tweaks.

The government's 2025 employment-services reform package, about A$312 million, kept mutual obligations. It also kept the points-based activation system that triggers automatic suspensions. Critics called it "punishment as usual".

The case file records that the Framework remains in operation and suspensions continue. Cancellations and reductions are paused pending remediation. The system is under several reviews at once.

What this case asks

The case file says the useful governance moves here are not accuracy fixes. No accuracy measure of the Framework would have found the gap, because nothing was misclassified. The harm lay in what was left out.

The first move is a live check of the person's reasonable excuse against every cancellation. The second is a check of each cancellation against the person's own circumstances before it cuts their income.

The third is a halt agreed in advance, so that a pause does not itself take ten months. The case file ties this to the Digital Protection Framework the law required.

The fourth is a faster review rhythm, so a uniform gap is caught while cancellations are still happening. In the case file's words, a safeguard named in a statute is not a safeguard in code.

What the available tools can and cannot address

A failure pathway is a link between two parts of the network where a mistake made by one part can be passed on to the other. A pathway counts as closed once it passes on only a few mistakes. It need not stop them all.

This case's budget is 12 units. Each tool costs units from it.

Explore (No Targets) sets no targets. Service means the benefit the deployment delivers.

Under Service Targets Only, the targets can be met. The cheapest way is one tool, Vet connections, costing 3 units.

Vet connections lets one system retrieve or copy another's records only where that is explicitly granted. On this network, mistakes stop passing along four pathways. They are Provider-recorded failures sent to the Framework, Prior demerits used in the next decision, Penalty applied to payment, and One rule set for every case.

Closing the first means mistakes stop passing along it, not that providers stop recording failures.

Under Service and Safety Targets, the targets include closing every failure pathway. Every combination that closes them all includes Gate record entries, Vet connections, and Understand the system. At this level those three cost 3, 3, and 4 units, 10 of the 12.

With Understand the system in a combination, Keep skills sharp, Upgrade model, Review on schedule, and Assign a challenger each cost less.

Still, no combination that closes every pathway meets the service target, whatever it costs. On this network, Gate record entries and Understand the system each lower it.

So at Service and Safety Targets, this case is not fully addressable with the available tools. Every combination was checked.

Under All Governance Targets, it is not fully addressable either, for the same reason. That level also asks for a larger, steadier gain in service and a target on the deployment's environmental footprint.

Stylized model of a documented deploymentPublic benefits & eligibility

Open this example in PAN Lab v0.1 to apply pressures and levers and watch what the system does.

What this models

This example runs on the Compliance-Framework-class automated mutual-obligation sanctioning engine network: 7 components and 13 pathways between them. Every context in the Lab is a stylized model, never a reconstruction of any actual deployment, and each assumption behind it carries a provenance label.

Evidence base: 8 assumed · 1 published baseline. In the Lab, the shaded evidence band behind each headline readout draws its width from the least-established class below.

Show all 9 assumptions
  • assumed

    This example follows the pattern the case file documents for the Targeted Compliance Framework, built after Robodebt: automation that failed by leaving out a step the law required. It is not a copy of the actual Framework or its code.

  • baseline

    The pathway named One rule set for every case stands for one fixed set of rules applied the same way to every case. So a single wrong setting, such as a long-lived IT bug, repeats across the caseload instead of averaging out. That is why three bugs produced nearly 1,800 incorrect penalties. A roughly five-year bug likewise kept people in the Penalty Zone too long. Neither showed up as scattered mistakes.

  • assumed

    This example draws the Framework as fixed rules that move people through demerits and zones, not as a model that predicts or scores risk. The documented unlawfulness came from omissions and wrong settings. The SPROM Act of April 2022 required a discretionary reasonable-excuse step and a safeguard for automated decisions, the Digital Protection Framework. Neither was put in place, and long-lived IT bugs ran undetected. So the error lay in what was left out and set wrongly, not in the Framework's accuracy. No accuracy measure would have found it.

  • assumed

    The step that was left out is drawn as an independent check of each cancellation, and the sources describe none. It stands for a decision on a person's reasonable excuse made before a cancellation takes effect. The SPROM Act of April 2022 required that step, and a safeguard for automated decisions, the Digital Protection Framework. Neither was put in place. So cancellations went ahead without the human and legal check the law demanded.

  • assumed

    The Ombudsman and the assurance review are drawn as oversight that worked in the end but came late. They found the unlawfulness and the defects. DEWR and Services Australia have since repaid compensation to hundreds of people. A check of each cancellation at the time it is made is drawn too, and the sources describe none. The pause came after roughly eighteen months undetected and about ten more months after the September 2023 legal flag. This sets the case apart from Robodebt and MiDAS, which had no internal corrective loop. It also sets it apart from the Medicaid unwinding, whose federal loop caught its defect within months.

  • assumed

    The delegate and appeal layer is drawn as a real correction route that was hampered and overwhelmed. The Framework's route to a delegate is drawn as a sign-off that is a formality, and corrections come slowly, one case at a time. The sources say decisions were mostly automated and the required discretion was not exercised. The Ombudsman found that automatic Penalty Zone suspensions undermine the ability to challenge. More than 140,000 complaints-line calls went unanswered. Yet review, where it happened, overturned a high rate of provider decisions.

  • assumed

    The part named Penalty Zone escalation marks the mechanism's signature. Five demerits within six months move a person to the Penalty Zone, where cuts of 50 or 100 percent of payment become automatic. No pathway connects it, so it does not change how mistakes move in this example.

  • assumed

    The pathway named Provider-recorded failures sent to the Framework is marked as private. Mutual-obligation reporting is continuous monitoring of the behaviour of about a million jobseekers. It is not matching of records across many government agencies. So the privacy question here is how intensive that monitoring is, not a data link.

  • assumed

    First Nations people are reported to have had disproportionately higher cancellation rates. That observation is recorded outside the Framework's own logic. This example does not model people or groups, and estimates no difference in harm among jobseekers. The case file documents that exposure, and it is measured outside any diagram like this one.

What this example does not show

Show all 4 limitations
  • Two groups of cancellations must be kept apart, and only the first is a confirmed count. The first comes from the Ombudsman's first report: at least 1,009 jobseekers whose payments were unlawfully cancelled, and 45 more after the pause was ordered. The second is a separate, far larger review of cancellations under section 42AM, which is still growing. For it, the Department of Employment and Workplace Relations (DEWR) earlier published up to 9,510 unlawful cancellations or reductions. An advocacy estimate put potential exposure near 310,000. At a June 2026 Senate estimates hearing, a DEWR official said the number was in the vicinity of that estimate. The official added that 55 to 70 percent may have legitimately lost eligibility, implying roughly 93,000 or potentially more than 100,000. Those larger figures are estimates of potentially unlawful cases pending case-by-case assessment. They are not confirmed cancellations.
  • First Nations people are reported to have had disproportionately higher cancellation rates. That observation is recorded outside the Framework's own logic. This example does not model people or groups, and estimates no difference in harm among jobseekers. The case file documents that concentration, and it is measured outside any diagram like this one.
  • Two of the scale figures come from advocacy analysis of departmental data. They are roughly 2.5 million suspension notices a year to about a million people, and 200,000 to 240,000 people facing suspension threats each quarter. Those two agree in direction across sources, but the exact base numbers and periods vary. A third comes from one government account: nearly half of all employment-service users have faced a suspension threat.
  • The assurance review that helped bring the IT instability to light was later found to contain fabricated citations. They were a court quote and academic references that do not exist. The department released a corrected version, and the reviewer, Deloitte, partially refunded its fee. The Ombudsman independently confirmed the review's core operational findings, but its citations should be treated with caution.

Sources and evidence

What this example rests on, claim by claim. Every entry resolves to the same ledger the Evidence Registry publishes.

  • A single automated rule set applied uniformly and without human review produced tens of thousands of correlated wrongful fraud determinations in the documented Michigan MiDAS case — one flaw repeating at caseload scale rather than averaging out.

    empirical
    • Government Michigan AG, settlement of civil-rights class action (Bauserman, 2022) https://www.michigan.gov/ag/news/press-releases/2022/10/20/som-settlement-of-civil-rights-class-action-alleging-false-accusations-of-unemployment-fraud
    • Investigative IEEE Spectrum, Michigan's MiDAS unemployment system: Algorithm alchemy that created lead, not gold https://spectrum.ieee.org/michigans-midas-unemployment-system-algorithm-alchemy-that-created-lead-not-gold

Where this connects

Institutional pressures in this domain

  • Austerity & recovery incentives — Cost-cutting and overpayment-recovery targets tilt the system toward denial and enforcement errors.
  • Vendor opacity — The deploying institution cannot inspect the model, data, or update pipeline it is accountable for.
  • Compliance over substance — Paper controls (sign-offs, checklists) satisfy audits while the behavior they describe erodes.
  • Reviewer bottleneck — One fixed-capacity checking stage sits between AI output and consequence; everything queues behind it.

All of them in context on the Public benefits & eligibility domain page.

Levers available here and the patterns behind them

Documented case histories