Domain Atlas / Public benefits & eligibility
Workforce Australia Targeted Compliance Framework: automated payment sanctioning after Robodebt
Work with this case in the PAN Lab ↗
The Commonwealth Ombudsman's first report, Automation in the Targeted Compliance Framework (published 6 August 2025), found that the Department of Employment and Workplace Relations and Services Australia acted contrary to the law and unlawfully cancelled the payments of 1,009 jobseekers under the predominantly automated Targeted Compliance Framework, with a further 45 auto-cancelled after a pause was ordered (the first-cohort figure is variously reported as 'more than 900', 964, or 1,009; 1,009 is the most precise and most widely cited). The unlawfulness was an omission: the April 2022 SPROM Act required a discretionary reasonable-excuse consideration before a cancellation and required a mandated automated-decision safeguard, the Digital Protection Framework, neither of which was implemented, so cancellations executed without the check the law required. The defect operated from April 2022, was detected in September 2023 by external legal advisors, and cancellations were not paused until July 2024 — a roughly ten-month gap the Ombudsman called not acceptable; both agencies accepted all seven recommendations. A commissioned Deloitte assurance review separately found the IT system increasingly unstable, with five IT errors dating to 2018, and could not assure the integrity, effectiveness, or appropriateness of decisions.[5]
What happened
The Targeted Compliance Framework (TCF) has, since 1 July 2018, enforced mutual-obligation requirements for Australian jobseekers through a predominantly automated demerit-point, three-zone system under the Social Security (Administration) Act 1999 (Cth), Divisions 3AA and 3A. Provider-recorded compliance failures accrue demerits; five demerits within six months move a person from the Warning Zone to the Penalty Zone, where one failure automatically costs 50% of payment and two failures cost 100%, and a capability interview is triggered at three demerits. It is a rules-based deterministic system, not a machine-learning risk score, operating at very large scale: advocacy analysis of departmental data describes roughly 2.5 million payment-suspension notices a year to about a million people, with 200,000 to 240,000 people facing suspension threats each quarter and, by one government account, nearly half of all employment-service users having faced a suspension threat.
In April 2022 the SPROM Act (Social Security Legislation Amendment (Streamlined Participation Requirements and other Measures) Act 2022) required a decision-maker to exercise discretion — to consider a person's circumstances or reasonable excuse — before cancelling a payment, and required the Secretary to establish an automated-decision safeguard, the Digital Protection Framework. The automated logic never incorporated the discretionary step, the human delegates did not exercise it independently, and the Digital Protection Framework remained unfinalised roughly three years later. The Commonwealth Ombudsman's first report, Automation in the Targeted Compliance Framework (published 6 August 2025), found the Department of Employment and Workplace Relations (DEWR) and Services Australia had acted contrary to the law and unlawfully cancelled the payments of 1,009 jobseekers (a further 45 were auto-cancelled after a pause was ordered), with a potentially catastrophic impact on vulnerable people. The defect operated from April 2022, was detected in September 2023 by external legal advisors, and should have prompted a pause around March 2024, but cancellations were not paused until July 2024 — a roughly ten-month gap the Ombudsman called not acceptable. Both agencies accepted all seven of the report's recommendations. (Reports variously give the first-cohort figure as "more than 900", 964, or 1,009; 1,009 is the most precise and most widely cited.)
An independent Deloitte assurance review (commissioned December 2024, delivered June 2025, at a cost of A$439,142) found the TCF IT system increasingly unstable, identified five IT errors dating to 2018, and concluded it could not assure the integrity, effectiveness, or appropriateness of decisions. Analysis of the reviews counted about 55 IT defects overall, including three major bugs that produced nearly 1,800 incorrect penalties, a roughly five-year undetected bug that kept people in the Penalty Zone beyond the required timeframe, and a bug that lowered severe-penalty thresholds without legislative authority; some 986 cancellation decisions were made without properly considering a reasonable excuse. The assurance review itself was later found to contain fabricated citations — a non-existent court quote and non-existent academic references — after which DEWR released a corrected version and Deloitte partially refunded its fee; the review's core operational findings were independently corroborated by the Ombudsman. The Ombudsman's second report, Fairness in the Targeted Compliance Framework (published 9 December 2025), found that automatic suspensions in the Penalty Zone undermine a jobseeker's ability to challenge penalties (Finding 6), that DEWR's assessment of provider performance lacks transparency (Finding 7), and that a high rate of provider decisions are overturned on review. The complaints infrastructure was overwhelmed: more than 140,000 calls to the complaints line went unanswered between November 2024 and September 2025, with over 8,000 documented complaints between July 2025 and March 2026. As at 1 December, DEWR had made 651 immediate-compensation recommendations totalling A$936,124.80, and with Services Australia had repaid 604 people a total of A$872,963.80.
The scandal has been framed explicitly as a post-Robodebt failure — "first robodebt, now robodole" — an automated welfare-compliance system built after Robodebt's lessons that still produced systemic unlawful outcomes. It continued to widen: in June 2026 Senate estimates, a DEWR taskforce lead said potentially unlawful cancellations under section 42AM were in the vicinity of Economic Justice Australia's estimate of 310,000, then qualified that 55 to 70 percent may have legitimately lost eligibility, implying an estimated additional 93,000 or potentially 100,000-plus unlawful cancellations — about ten times DEWR's earlier published figure of up to 9,510. Those larger figures are estimates of potentially unlawful cases pending case-by-case assessment, not confirmed cancellations. The reform record is mixed: in November 2023 the House Select Committee on Workforce Australia Employment Services recommended in Rebuilding Employment Services replacing the punitive TCF with a Shared Accountability Framework, concluding its problems could not be fixed by minor tweaks; yet the government's 2025 employment-services reform package (about A$312m, including new Employment Goal Plans and a digital service) retained mutual obligations and the points-based activation system that triggers automatic suspensions, drawing "punishment as usual" criticism. First Nations people are reported to have experienced disproportionately higher cancellation rates, a differential-harm signal recorded outside the compliance engine's own logic. The TCF remains operational and suspensions continue; cancellations and reductions have been paused pending remediation, and the system is under multiple concurrent reviews.
The sociotechnical reading
Robodebt, already in this Atlas, ended the way its worst cases do: warning signals existed, no internal actor acted on them, and the scheme's end required the heaviest external actors in the map — courts and a Royal Commission. Its rehearsal question was, what would a pre-authorized circuit-breaker held by an internal actor have changed? The Targeted Compliance Framework is the unsettling sequel, because it is what a system looks like when the answer to that question was supposedly learned and still did not hold. This is a case built after the scandal, explicitly meant to embody its lessons, that automated unlawful subsistence-income cuts anyway. Its lesson is distinct in kind: importing a scandal's stated lessons is not the same as wiring them into a new system, and the two most load-bearing pieces of governance can both be present on paper and absent in operation.
The first is a check that was legally mandated and simply never built. Unlike MiDAS (a high-error engine with no correction loop) or the Medicaid unwinding (an accurate engine carrying one wrong specification parameter), the TCF's failure is automation by omission: the April 2022 SPROM Act required a discretionary reasonable-excuse determination before any cancellation, and required the Secretary to stand up an automated-decision safeguard, the Digital Protection Framework. The automated logic never surfaced the discretionary step, the delegates never exercised it, and the safeguard was never finished — so cancellations executed without the human and legal check the law demanded, in the same 986-case pattern the reviews documented. No accuracy metric, precision curve, or bias audit of the engine would have surfaced this, because there was no misclassification to measure; the harm lived in what was left out. Underneath it, because one deterministic ruleset ran the entire caseload, ordinary configuration bugs did not average out — three of them produced nearly 1,800 identical wrong penalties and one ran for roughly five years — the same correlated-error-at-scale signature the Atlas sees whenever a single logic is applied uniformly to a population.
The second piece is the one that most sharply separates this case from Robodebt and from the Medicaid unwinding, and it is the reason the lesson was "not learned." The corrective loop this time existed. There was a Commonwealth Ombudsman with statutory investigation powers, a commissioned assurance review, a parliamentary committee, and Senate estimates scrutiny — precisely the internal-and-external oversight apparatus Robodebt lacked. But the loop fired late: the unlawfulness was flagged by legal advisors in September 2023 and cancellations were not paused until July 2024, on top of roughly eighteen months of undetected operation and five-year-old bugs beneath. An oversight loop that catches a population-scale unlawfulness months to years after it starts does not prevent the harm; it documents it. So the productive governance moves here are not accuracy fixes and not even the mere existence of oversight. They are the ones that install a live discretionary reasonable-excuse determination against every cancellation; reconcile a cancellation against the person's own circumstances before it cuts their income; pre-commit the halt — the automated-decision safeguard the law actually mandated — so a pause does not itself take ten months; and tighten the loop's cadence so a silent, uniform, legally-required-check-shaped hole trips while it is still live. The Atlas's monitor-and-respond, circuit-breaker, and correction-latency patterns all sharpen here into a single warning: a safeguard named in a statute is not a safeguard in code, and an oversight loop that is present but slow is the difference between a scandal prevented and a scandal merely re-documented.
The concepts used in this reading are defined in the Field Guide; the governance responses live in the Practice Library. The model organization for this case can be stress-tested in the PAN Lab.