APRA v Bendigo and Adelaide Bank: first accountability regime civil penalty proceedings

8 minute read  02.09.2026 James Beaton, Caitlin Murray, Siobhan Doherty, Michael Hershan, Wesley Lalich

APRA has commenced the first accountability regime civil penalty proceeding against Bendigo Bank over a 2023 cyber attack, citing inadequate controls and accountability gaps. Bendigo Bank agreed to an $8m penalty.

On 10 August 2026, the Australian Prudential Regulation Authority (APRA) commenced Federal Court proceedings against Bendigo and Adelaide Bank Limited (Bendigo Bank), alleging contraventions of ss 37C(a) and 37D(1)(a)(i) of the Banking Act 1959 (Cth) (Banking Act) arising from a March 2023 cyber attack. Bendigo Bank has admitted the contraventions and agreed to an $8m penalty. The admitted contraventions relate to an accountable entity's (i) obligation to conduct its business with honesty and integrity, and with due skill, care and diligence and (ii) its key personnel obligations that the responsibilities of its accountable persons cover all parts or aspects of its operations. Both of these obligations now form part of the Financial Accountability Regime Act 2023 (Cth) (FAR Act).

This is the first civil penalty proceeding brought under the Banking Executive Accountability Regime (BEAR, or its successor, the Financial Accountability Regime (FAR)), and the first BEAR/FAR-related proceeding concerning the allocation of responsibilities between accountable persons. It is also a rare instance of APRA seeking civil penalties, reflecting APRA's propensity to exercise the full array of its enforcement powers and the relevance of this additional enforcement pathway for a broad variety of failures which can be the subject of enforcement action by either ASIC or APRA.

Bendigo Bank's admissions include that it failed to have adequate customer authentication controls and a systematic testing program for those controls within Alliance Bank, and that for a 12-month period no accountable person's accountability statement covered Alliance Bank's information technology operations at all — a gap the parties agree contributed to the attack going undetected and un-remediated. The proceeding underscores that accountability frameworks must have no gaps: exclusions carved out of one accountable person's statement must be affirmatively reallocated, and "business managed IT" does not dilute the licensee's or the accountable entity's responsibility for end-to-end coverage.

A week after commencing the civil penalty proceeding, APRA also imposed license conditions on Bendigo Bank and the continuation of a $50m operational risk capital add-on first imposed in December 2025, indicating APRA may pursue civil penalty proceedings alongside other supervisory measures. The license conditions include requiring Bendigo to undertake a risk management rectification program.

Background

Bendigo Bank is an authorised deposit-taking institution (ADI) that, during the relevant period (2 June 2020 to 1 July 2023), operated “Alliance Bank”, a network of five former credit unions that had become authorised representatives of Bendigo Bank under an alliance arrangement.

Alliance Bank ran on a separate licenced core banking system, Ultracs, which was hosted by a third party, TAS, distinct from Bendigo Bank’s main core banking system, RFS-B. Ultracs and the TAS services were managed under a “business managed IT” (BMIT) model, whereby the Alliance Bank business unit held primary responsibility for the platform, supported as needed by Bendigo Bank’s Technology & Transformation division.

By late 2021, Bendigo Bank had identified the operational risks inherent in the BMIT model and had commenced a multi-year process to migrate Alliance Bank customers onto RFS-B and ultimately wind down the Alliance Bank model, a process completed by June 2024.

The Cyber Attack

APRA’s claim arises from a brute-force cyber attack on the Ultracs platform used by Alliance Bank between 3 and 7 March 2023 (the Cyber Attack). At the outset of the attack, about 1600 customer accounts were still protected by the password “123456”, and many others used equally weak passwords. The attacker accessed approximately 257 customer accounts, changed passwords on at least 218 of them, and made 286 transactions involving 87 accounts — 66 unauthorised inter-account transfers totalling $217,190 and 154 outbound payments totalling $273,140 (of which $140,110 could not be reversed and were refunded by Bendigo Bank within four days).

APRA alleges the vulnerabilities exploited (being weak or non-existent password complexity rules, optional rather than mandatory multi-factor authentication, absent CAPTCHA/anti-automation controls, and ascertainable member numbers) had been identified as far back as a June 2020 penetration test, and were the same vulnerabilities exploited in an earlier, unsuccessful October 2022 brute-force attack. Bendigo Bank accepts that these findings were not escalated in accordance with its risk framework, were never provided to the Head of Alliance Bank (the relevant business system owner and risk owner) and remained unremediated until March 2023.

The contravening conduct

On the facts agreed between APRA and Bendigo Bank, Bendigo Bank admits two contraventions of the Banking Act (the same provisions are now part of the FAR Act):

  1. failing to take reasonable steps to conduct the business of Alliance Bank with due skill, care and diligence, in contravention of s 37C(a) of the Banking Act (now s 20(a) of the FAR Act), by not having adequate customer authentication controls to prevent and detect unauthorised access and payments; by not having, from 30 September 2020, a systematic testing program for those controls as required by Bendigo Bank’s own CPS 234 Controls Testing Framework; and by not having appropriate governance and risk management for the information security of the Ultracs platform and TAS-managed services; and
  2. failing to ensure that the responsibilities of Bendigo Bank’s accountable persons covered all parts or aspects of Bendigo Bank’s operations, in contravention of s 37D(1)(a)(i) of the Banking Act (now s 23(1)(a)(i) of the FAR Act), in that from 29 August 2022 to 30 August 2023 Alliance Bank’s information technology operations were not covered in the accountability statement of any accountable person.

The accountability gap

The s 37D(1)(a)(i) contravention emphasises the importance of accountable entities fully mapping and allocating accountabilities. Bendigo Bank’s Chief Transformation Officer (CTO) was an accountable person whose accountability statement, from 2019, covered management of Bendigo Bank-hosted IT operations and the requirement to ensure business-managed IT systems did not compromise the confidentiality, integrity or availability of the IT environment.

As part of a 2022 review of executive accountability statements, Bendigo Bank identified a series of proposed exclusions from the CTO’s accountability, including “Support and maintenance of Business Managed IT” and, specifically, “IT Operations for Alliance Bank”. Internal slide decks prepared in August 2022 proposed that these excluded responsibilities be reassigned to another accountable executive, described only as “Alliance Bank & CCO, Consumer (TBC)”. On 26 September 2022, the CTO signed an updated accountability statement, effective from 29 August 2022, which expressly excluded these responsibilities, but no other accountable person’s statement was updated to pick them up.

The result, agreed by the parties, was that from 29 August 2022 until 30 August 2023, including the period covering an unsuccessful October 2022 attack and the successful March 2023 Cyber Attack, no accountable person had accountability for Alliance Bank’s information technology operations. This was despite Bendigo Bank's Chief Customer Officer’s accountability statement covering distribution of products and services via Alliance Bank, and despite internal committee and Board-level discussions, dating back to at least 2020, flagging BMIT as a source of risk because Bendigo Bank did not have full visibility of all technology in use across the organisation. While the CTO and the Chief Information Security Officer took immediate operational responsibility for leading Bendigo Bank’s incident response once the Cyber Attack was discovered, questions arise as to whether the known risks would have been addressed sooner if the accountability had been allocated.

Key admissions and issues

Known risk, un-remediated for years, risks serious enforcement action

The Statement of Agreed Facts traces the relevant vulnerabilities back to a 2017 Deloitte review and a June 2020 penetration test (identifying weak password rules and ascertainable member numbers), through an unsuccessful October 2022 attack exploiting the same weaknesses, to the successful March 2023 Cyber Attack. Bendigo Bank accepts these findings were not escalated to the Head of Alliance Bank, to senior management or to the Board, and were not assessed against its own CPS 234, Operational Risk or Technology Risk frameworks. Where a regulated entity has identified a material risk and left it un-remediated over an extended period, that failure is likely to be viewed seriously by regulators and increases the likelihood of enforcement action.

Accountability coverage must be complete and cannot rely on implicit or de facto allocation

Accountable entities must ensure that the responsibilities of its accountable persons cover all parts or aspects of its operations.

Where responsibilities are removed from one accountable person, they should be contemporaneously, and explicitly, allocated to another accountable person. Maintaining accountability statements that accurately and comprehensively describe the allocation of responsibilities is key to demonstrating compliance, even for entities not required by FAR to lodge accountability statements with APRA and ASIC.

Nor is it sufficient that, operationally, certain executives are expected to and do step in during a crisis. The statutory obligation is concerned with accountable person responsibilities covering all parts or aspects of the entity’s operations, including business-managed or federated technology environments.

Third-party and “business managed” models do not reduce the licensee’s responsibility

Bendigo Bank’s BMIT model gave the Alliance Bank business unit primary day-to-day responsibility for a platform hosted and supported by external vendors, with the Head of Alliance Bank (who did not have an IT or information security background) holding relevant risk ownership. A Bendigo Bank internal review found this arrangement was a key root cause of the confusion over responsibility for IT security risk. The case reinforces that outsourcing or business-unit ownership of a technology platform does not relieve the accountable entity (or its accountable persons) of ultimate responsibility for information security governance under prudential standards such as CPS 234, nor of the obligation to maintain complete accountability coverage under BEAR/FAR.

Cooperation, remediation and lack of deliberateness are recognised, but prevention is better than cure

Bendigo Bank’s early notification, extensive voluntary cooperation, rapid customer remediation and substantial post-incident uplift are recorded as mitigating factors relevant to penalty. However, such actions did not prevent APRA from commencing civil penalty proceedings for what it characterises as systemic, multi-year control and accountability failures.

Key issues for APRA-regulated entities

  1. APRA enforcement under FAR – where to next: This is the first civil penalty proceeding under BEAR (or its successor, FAR). Significantly, it signals cyber security and information security failures, or other risk management failures, could be within the enforcement scope of Australia's accountability regime. Going forward, it is possible that accountable entities regulated under FAR might expect failures in information security, technology risk management and, in future, AI governance (and failures) may give rise to enforcement actions under FAR, particularly where those failures can be characterised as a want of due skill, care and diligence in the conduct of the entity's business.
    There is a question as to whether APRA would pursue enforcement under FAR for an information security or other conduct failure standing alone, in circumstances where there is no concurrent accountability mapping (or other clear FAR) deficiency, such as the accountability gap identified in this matter. The present case may be fact-specific in that both the substantive control failure and the structural accountability gap reinforced each other. The absence of an accountable person responsible for Alliance Bank IT meant the control weaknesses went un-escalated and un-remediated.
    A standalone "due skill, care and diligence" obligation under FAR, pursued separately from concurrent obligations of "honesty and integrity" and other accountability obligations gives APRA very broad regulatory scope. It remains to be seen whether APRA would bring a FAR proceeding based solely on a "due skill, care and diligence" case.
    Previously, ASIC enforcement action against financial services licensees for cyber security failures has been brought pursuant to the general license obligations under s 912A(1) of the Corporations Act 2001 (Cth) (Corporations Act), including to do all things necessary to ensure that financial services are provided efficiently, honestly and fairly. APRA's proceeding against Bendigo Bank represents a potentially different – and, for APRA-regulated entities, additional – enforcement pathway. Given APRA's existing prudential standards governing information security and operational resilience, including CPS 234 (Information Security) and CPS 230 (Operational Risk Management), it is possible that APRA may leverage the accountable entity's statutory obligation to "conduct its business with honesty and integrity, and with due skill, care and diligence" under ss 20(a) of the FAR Act as the jurisdictional foundation for enforcement actions for conduct failures. This would position FAR as a parallel, and potentially complementary, enforcement mechanism to ASIC's Corporations Act powers and to APRA's existing, and more frequently used, supervisory tools (such as capital overlays, additional licence conditions, and enforceable undertakings), raising the possibility that a broad variety of failures could be the subject of enforcement action by either ASIC or APRA.
  2. Duty to act with honesty and integrity, and with due skill, care and diligence – interpretation: The BEAR obligation - now replicated in s 20(a) of the FAR Act - requires an accountable entity to conduct its business "with honesty and integrity, and with due skill, care and diligence". In this proceeding the parties have proceeded on the basis that those words impose two distinct and severable obligations rather than a single composite standard.
    The contravention alleged against Bendigo Bank is framed as a failure to exercise due skill, care and diligence in the conduct of its business, without any reference to Bendigo Bank having acted without honesty or integrity. The implication is that the parties consider the statutory language creates independent limbs: an entity (or accountable person) can satisfy the honesty and integrity requirement while nevertheless breaching the obligation by failing to exercise the requisite standard of skill, care and diligence. This would be in contrast to the "compendious" interpretation that courts have often applied to the analogous obligation under s 912A(1)(a) of the Corporations Act, which requires a financial services licensee to "do all things necessary to ensure that the financial services covered by the licence are provided efficiently, honestly and fairly". Under that interpretive approach, articulated in cases such as ASIC v Westpac Securities Administration Ltd (2019) 272 FCR 170, the words "efficiently, honestly and fairly" are read together as expressing a single, unified normative standard rather than three discrete obligations. That is, the composite phrase describes a quality of conduct that is assessed holistically, rather than parsed into independent elements each capable of being breached in isolation.
    If a disjunctive reading of the relevant FAR obligation was intended and is correct, it would mean that a regulator need only demonstrate a failure of due skill, care or diligence to establish a contravention, without the additional burden of establishing that the conduct also failed to achieve the requisite standard of honesty or integrity when assessed as a whole.
    This interpretation of the obligation in s 37C(a) of BEAR, which is replicated in s 20(a) of FAR, has echoes of the obligation in section 180 of the Corporations Act for directors and officers to exercise their powers with care and diligence. While FAR only requires "reasonable steps" it does not offer the same express qualifications and defences that exist under the Corporations Act, such as the business judgment rule (section 180(2)), reasonable reliance on information and advice (section 189) or provisions providing relief from liability (section 1317S).
    Were the obligation in s 37C(a) of BEAR and s 20(a) of FAR to be interpreted as a compendious obligation, it would set a significantly higher bar for any contravention and limit the circumstances where the provision could be said to be contravened.
    It is likely the Federal Court, in determining APRA's case against Bendigo Bank, will be required to form a view on this issue.
  3. BEAR / FAR – not just about individual accountability: While BEAR / FAR is often conceived of as a regime focusing on individual accountability, it is notable, in this instance that no public allegations are made by APRA against individuals. This will no doubt be fact dependent. Individual accountability is a feature of the regime through a range of mechanisms such as remuneration consequences, potential disqualification or as an ancillary to an accountable entity's contravention. It may be that outside the most egregious contraventions (such as those which resulted in the banning of two directors in the Xinja Bank matter), individual accountability is generally achieved through remuneration or other consequences applied by the accountable entity.

Contact

Tags

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJuYW1laWQiOiI0YjBlMjQzNi03NWIyLTRlYmItOWQxMy1iMTU2MWYwNTZjMGEiLCJyb2xlIjoiQXBpVXNlciIsIm5iZiI6MTc4ODM5NzY4NiwiZXhwIjoxNzg4Mzk4ODg2LCJpYXQiOjE3ODgzOTc2ODYsImlzcyI6Imh0dHBzOi8vd3d3Lm1pbnRlcmVsbGlzb24uY29tL2FydGljbGVzL2FwcmEtdi1iZW5kaWdvLWFuZC1hZGVsYWlkZS1iYW5rLWZpcnN0LWFjY291bnRhYmlsaXR5LXJlZ2ltZS1jaXZpbC1wZW5hbHR5LXByb2NlZWRpbmdzIiwiYXVkIjoiaHR0cHM6Ly93d3cubWludGVyZWxsaXNvbi5jb20vYXJ0aWNsZXMvYXByYS12LWJlbmRpZ28tYW5kLWFkZWxhaWRlLWJhbmstZmlyc3QtYWNjb3VudGFiaWxpdHktcmVnaW1lLWNpdmlsLXBlbmFsdHktcHJvY2VlZGluZ3MifQ.tz4TGrv-42zPWWffh5ZmDPYhpzL2_IUTpxQSpO2r7uM
https://www.minterellison.com/articles/apra-v-bendigo-and-adelaide-bank-first-accountability-regime-civil-penalty-proceedings