Compliance for Banks & ADIs
Authorised deposit-taking institutions regulated by APRA under the Banking Act 1959.
Published obligations that apply to banks & adis (23)
- criticalCWLTHNotifiable Data Breach (NDB) scheme
Under the NDB scheme, APP entities must notify the OAIC and affected individuals of an eligible data breach likely to cause serious harm — assessed within 30 days.
- criticalCWLTHMajor banks must provide CDR Banking + Action Initiation (2026)
CDR Action Initiation lets accredited recipients initiate payments + actions on consumer behalf.
- criticalCWLTHComply with Design and Distribution Obligations (DDO)
Issuers and distributors of retail financial products must have a Target Market Determination (TMD) and distribute consistently with it.
- criticalCWLTHComply with APRA CPS 234 (Information Security)
APRA-regulated entities must maintain information security capability commensurate with the size and extent of threats.
- criticalCWLTHMaintain a written AML/CTF program
Every reporting entity needs a documented AML/CTF program — an ML/TF risk assessment plus AML/CTF policies.
- criticalCWLTHComply with APRA CPS 220 (Risk Management)
APRA-regulated entities must have a comprehensive risk management framework.
- criticalCWLTHFAR deferred remuneration arrangements (40% deferral 4 years)
FAR accountable persons must have 40% of variable remuneration deferred 4 years.
- criticalCWLTHComply with APRA CPS 230 (Operational Risk Management)
APRA-regulated entities must manage operational risk including a comprehensive third-party / outsourcing register from 1 July 2025.
- criticalCWLTHReport cyber security incidents to ASD (SOCI)
Critical infrastructure asset operators must report critical incidents within 12 hours and other incidents within 72 hours.
- criticalCWLTHEnrol with AUSTRAC as a reporting entity
Tranche 2 entities must enrol with AUSTRAC within 28 days of first providing a designated service (29 July 2026 for services from 1 July 2026).
- criticalCWLTHComply with Financial Accountability Regime (FAR) accountability obligations
Banking entities from 15 March 2024; insurers and super trustees from 15 March 2025.
- highCWLTHBanking Code of Practice 2025
ABA member banks bound by the Banking Code — fair conduct + dispute resolution requirements.
- highCWLTHComply with credit reporting obligations (Part IIIA Privacy Act)
Credit providers and CRBs must adhere to the CR Code on collection, use, disclosure, hardship and dispute resolution.
- highCWLTHAvoid unfair contract terms in standard form consumer & small business contracts
From November 2023, unfair contract terms carry pecuniary penalties — up to $100M per term (from 28 March 2026).
- highCWLTHPublish a Privacy Policy that meets APP 1
Every APP entity needs a clearly-expressed Privacy Policy covering APP 1.4 requirements.
- highCWLTHConsumer Data Right (CDR) participant accreditation + compliance
Banking, energy and (soon) non-bank lending data sharing — accredited participants must comply with privacy safeguards.
- highCWLTHComply with CDR Banking (Open Banking) — major + non-major ADIs
Banking data holders must share consumer data with accredited recipients on consumer consent.
- highCWLTHRespond to hardship notices within statutory timeframe
Credit providers must consider hardship notices within 21 days under s 72 NCC.
- highCWLTHPre-2025 ban on unsolicited credit limit increase invitations
Credit card limit increase offers cannot be sent without prior written consent.
- mediumCWLTHComply with the ePayments Code
Voluntary but industry-standard code covering electronic transaction terms, mistaken internet payments, and unauthorised transactions.
- mediumCWLTHBanking Executive Accountability Regime (BEAR) — pre-FAR
BEAR superseded by FAR for banks 15 March 2024; historical exposure remains.
- mediumCWLTHMandatory AI guardrails for high-risk AI (in development)
Australian Mandatory Guardrails for High Risk AI Settings — Treasury consultation in 2024/2025.
- mediumCWLTHAdopt the Voluntary AI Safety Standard (DISR 2024)
10 voluntary guardrails for safe + responsible AI deployment; mandatory regime in development.
Applicability answers for banks & adis
- Do banks and ADIs need to enrol with AUSTRAC as a reporting entity?
- Do banks and ADIs need to maintain a written AML/CTF program?
- Does Customer due diligence (KYC) on every customer apply to banks and ADIs?
- Does Suspicious matter, threshold, and IFTI reporting to AUSTRAC apply to banks and ADIs?
- Do banks and ADIs need to designate an AML/CTF Compliance Officer?
- Do banks and ADIs need to detect + enhance due diligence on Domestic + Foreign PEPs?
- Does Independent review of AML/CTF program apply to banks and ADIs?
- Do banks and ADIs need to lodge the AUSTRAC annual compliance report (AML/CTF Act s 47)?