You have 0 free articles left this month.
Lender

Lending emerges as leading source of Banking Code breaches

5 min read
Share this article on:

The latest compliance data has identified lending to individuals as the area accounting for the highest number of reported Banking Code breaches.

Lending to individuals has been identified as the leading source of reported Banking Code breaches in the latest data release from the Banking Code Compliance Committee (BCCC), covering the reporting period from July to December 2025.

The BCCC monitors and assesses banks’ compliance with the Banking Code of Practice, which sets standards of practice and service for the industry, investigates alleged breaches of the code, and can impose sanctions where serious non-compliance is identified.

Of the 9,326 total breaches reported during the period, lending to individuals was the most frequently breached code paragraph, accounting for 3,937 of the reported breaches.

 
 

Other commonly reported breaches related to providing extra care to customers experiencing vulnerability (1,528), complaints handling (1,479), deceased estates (1,305), and communicating with customers (436).

Commenting on the findings, the BCCC noted that many banks attributed the majority of reported breaches to staff error.

However, the committee said the data indicated these incidents point to broader weaknesses in underlying systems, processes, controls, training, supervision, or workflow design.

“Across these areas, the descriptions of breaches that we received from banks pointed to a common issue: compliance often depended heavily on individual staff judgement, memory or manual action at the point of customer interaction,” the BCCC said.

“In lending, examples included staff missing or bypassing required steps before progressing loan applications.”

Vulnerability issues

Another key theme to emerge from the BCCC report was that banks continue to miss opportunities to identify and support customers experiencing vulnerability.

Banks reported 1,528 breaches relating to commitments to customers experiencing vulnerability, affecting more than 10,000 customers and resulting in $5.52 million in customer financial impact.

“In vulnerability, staff did not consistently identify, record or act on vulnerability indicators. In complaints handling, staff did not always recognise signs of dissatisfaction or escalate matters as complaints, contributing to missed complaint-handling time frames,” the report said.

“Other parts of the data support this broader pattern. Gaps in staff skills or knowledge accounted for 10 per cent of staff-related breaches, with vulnerability obligations making up almost half of that group.

“A smaller but important group of breaches involved process deficiencies that contributed to staff errors, including manual processing, system set-up issues and inadequate quality assurance over customer communications.”

The BCCC said that, taken together, these patterns suggest staff error often reflects where breaches were identified, rather than necessarily the underlying reasons they occurred.

“Where breaches arise in processes that rely heavily on manual steps, individual judgement or consistent application of procedures, banks need to consider whether stronger system prompts, workflow controls, supervision, quality assurance or process design would reduce the risk of the same issues recurring,” it said.

Spotlight on lenders

The findings come as banks continue to face regulatory scrutiny over their handling of customers experiencing financial hardship, with several major lenders previously penalised for shortcomings in their support processes.

In May, Westpac was fined $26 million after ASIC found deficiencies in the way the bank handled hardship assistance requests from customers, including failures relating to its obligations to respond appropriately when borrowers were experiencing financial difficulty.

The action followed similar enforcement outcomes involving NAB and ANZ, which were also penalised over failures relating to hardship processes and customer support.

BCCC chair Sean Hughes said the report demonstrated why banks need to treat breach data as a source of practical insight, rather than simply a reporting obligation.

“Customer impact, financial impact, how breaches are identified and the corrective actions banks take all help show whether banks are detecting issues early, understanding their causes and responding in a way that reduces the risk of recurrence,” he said.

“We will continue to use breach data to monitor compliance with the Code, identify emerging risks and assess whether banks’ corrective actions are addressing the underlying drivers of customer detriment. We expect banks to use this data not only to report what went wrong, but to understand why it happened and what needs to change.”

[Related: Former ASIC commissioner to chair BCCC]

Want to see more stories from trusted news sources?
Make The Adviser a preferred news source on Google.
Click here to add The Adviser as a preferred news source.

sean hughes vanguard ta rslyri

Ben Squires

AUTHOR

Ben Squires is a commercial content writer at mortgage broking title, The Adviser.

He primarily works with clients to deliver promoted and sponsored content – both in print and online – and also writes news and features on the Australian broking industry.

As an experienced writer and journalist, Ben can write across different mediums but specialises in commercial content that meets client objectives.

Before joining The Adviser in 2024, Ben was a commercial content editor at News Corp, writing for several titles including The Australian, Escape, GQ and news.com.au.

He’s interested in writing about anything related to finance and technology.