Prudential accountability can ease harm

Scam losses need to be treated as a Board-level risk, with appropriate auditing and governance standards at financial firms to tackle fast-rising economic crime, writes Scam Victim Alliance in this submission about APRA’s new prudential standards

We welcome APRA's review of the prudential governance framework. We ask that the systemic risks of financial crime and scams be treated as material governance and operational risks that boards of ADIs must oversee. The Government already expects APRA to strengthen financial-system resilience, safeguard Australians' money and data against cyber threats, oversee emerging AI risks and hold regulated entities accountable for governance and risk-management failures capable of causing significant harm.

That harm is already occurring. Systemic weaknesses in identity takeover, scam detection, mule-account controls, payment interventions, complaint intelligence and remediation have exposed Australian consumers and small businesses to devastating financial and non-financial losses. We believe that when these weaknesses reveal material deficiencies in an institution's risk-management framework – which we contend happened to HSBC Australia between 2023 and 2024 – they should be considered prudential issues, not simply individual customer disputes.

As Australia's only self-funded, volunteer-led community dedicated to supporting people experiencing life-changing harm from financial crime and scams, we urge APRA to adopt stronger Board accountability, assurance and oversight of these risks to improve outcomes for all Australians.

Prudential Accountability Could Prevent Financial Harm for Thousands of Australians

APRA's purpose is to identify and respond to significant risks within financial institutions and the financial system, while holding Boards and management accountable for the prudent operation of their institutions. Scam Victim Alliance believes the Scam Prevention Framework legislation alone cannot deal with the threat of cyber-enabled financial crime and must be complemented by broader legislative, regulatory and prudential reform.

Our organisation believes existing ADI governance frameworks are failing to keep up with rapidly evolving systemic scams that expose Australians to sophisticated financial crime. We believe threat actors, crime networks and hacktivist groups are weaponising banking platforms and processes to steal and defraud customers, and that we need a whole-of-ecosystem approach – including reformed prudential standards – to protect Australian bank shareholders and customers from fast-escalating harm.

CPS 510 already imposes strong obligations for Board responsibility, information flows, conflicts management, fitness and propriety, and whistleblower protections – but these obligations do not explicitly address scam and financial crime risk or the intelligence generated through financial complaints.

Our organisation believes this could be a governance gap which means an ADI can technically comply with CPS 510 while its Board receives little meaningful information about financial crime losses and customer harm; fails to consider whether directors and senior executives have demonstrated effective oversight of these risks; and remains unaware of how rapidly evolving technology and control gaps are enabling new scam typologies. Most importantly, recurring scam typologies can remain classified as ‘individual customer matters’ that are blamed on ‘authorised’ transactions rather than recognised as evidence of systemic control failures or poor ADI governance.

This submission has three sections:

  1. Suggested changes to CPS 510

  2. HSBC case study: how 1,000 Australians were harmed and how it relates to Bendigo Bank

  3. Scam and financial crime governance audit ideas

Section 1: SVA Proposed Changes to CPS 510

SVA asks APRA to amend CPS 510 so that scams and complaints relating to financial crime risks are explicitly built into:

  1. The Board's non-delegable responsibilities (paragraph 13).

  2. The policy governing what information reaches the Board (paragraphs 20–22).

  3. The Risk Committee's monitoring role (paragraph 45).

  4. The Audit Committee's oversight role (paragraph 41).

  5. The definition of a reportable conflict (paragraph 74).

  6. The fit and proper test for directors and executives (paragraphs 84–86).

  7. The Board skills matrix (paragraph 47).

  8. The annual Board performance assessment (paragraph 51).

  9. Active enforcement of existing whistleblower protections (paragraphs 95–101).

The hallmark of good governance is not only how an institution responds after regulatory action, but whether a Board can spot warning signs early enough to prevent the need for regulatory action or law enforcement investigation in the first place. We think executive teams and Boards should be regularly scanning their business complaints data for any indication of new systemic typologies appearing.

The table below sets out suggested amendments, mapped to the exact paragraph of the draft standard.

ClauseWhat CPS 510 currently saysWhat SVA asks APRA to considerPara 13Lists the Board duties that can never be handed to someone else, e.g. setting risk appetite and overseeing “financial and operational resilience.”Add scam and fraud loss oversight to this non-delegable list, so a Board cannot treat scams as a customer-service matter that never reaches Board level.Paras 20–22Requires a policy on what management information reaches the Board, and requires senior managers to brief the Board “clearly, timely and transparently.”Require the policy to specifically cover scam and fraud complaint volumes, AFCA determinations and dispute outcomes, not only financial and prudential risk data.Para 45Sets out the Risk Committee's job: monitor risk position against risk appetite, advise on risk culture, and oversee how management implements the risk strategy.Add scam and fraud losses, mule-account activity and repeat scam typologies as matters the Risk Committee must specifically monitor and report on.Para 41Sets out the Audit Committee's job: oversee compliance and financial reporting, and ensure audit issues are “managed and rectified in an appropriate and timely manner.”Require the Audit Committee to review patterns in scam-related customer complaints and external dispute resolution outcomes as part of its oversight role.Para 74Requires entities to identify, assess and manage all conflicts affecting customers, and keep a conflicts register.Confirm that a bank knowingly or unwittingly facilitating scam infrastructure (e.g. hosting mule accounts, ignoring internal fraud flags) is a conflict that must be logged and escalated under this paragraph.Paras 84–86Sets the “fit and proper” test for directors and senior executives: skill, character, judgement, and any adverse findings against them.Require entities to consider a candidate's track record on customer harm – AFCA determinations, ASIC action, or repeated complaint failures – as part of the fit and proper assessment.Para 47Requires a documented “Board skills matrix” covering the skills and experience the Board needs, based on the entity's risk profile.Require fraud, scams and financial crime literacy to be a named category in the skills matrix, given the scale of scam losses now facing regulated entities.Para 51Requires an annual performance assessment of the Board, committees and directors against their objectives.Require the annual assessment to specifically evaluate how the Board handled scam and complaint risk that year, not only general risk-management performance.Paras 95–101Already protects staff, ex-staff, auditors and contractors who disclose problems to APRA, and bans confidentiality clauses that would silence them.Ask APRA to actively monitor and enforce these protections, given evidence that confidential settlement deeds in scam disputes may currently discourage disclosure.

Section 2: HSBC Case Study

The $34.6m Systemic Failure That Hurt More Than 1,000 Australians

Refer SA firefighter victim impact statement

On 13 December 2024, ASIC commenced civil penalty proceedings in the Federal Court; the matter concluded in June 2026 with a $35 million penalty against the bank. Despite the fine and the negative publicity order, HSBC Australia has been sold to Blackstone Capital for a profit, while Scam Victim Alliance continues to represent customers who remain under-compensated for their losses. Scam Victim Alliance is still representing under-compensated HSBC customers at no charge to them, asking the Australian Financial Complaints Authority (AFCA) to reimburse given that the bank has not.

Total HSBC customer losses (2020 – March 2024)$34.6m+

Losses via internal transfer rails with no fraud detection capability$25.8m

Reporting cohort affected1,024 customers

Rise in bank impersonation reports in a single year380%

ASIC Federal Court civil penalty (concluded June 2026)$35m

Customers Scam Victim Alliance is supporting (Aug 2026)7 for <$200,000

Customers still undercompensated at time of penalty 100+ in court docs, SVA representing 8 of these at AFCA

Between 2020 and March 2024, criminal networks exploited HSBC Australia's internal account transfer payment rails, which had no fraud detection capability. This was not a single error but a corporate control gap that was allowed to run for years while customer losses accumulated. While we do not profess that such a small fine or $34.6 million leak of money was ever a prudential risk to HSBC Australia – HSBC Australia was always comfortably capitalised and liquid – imagine if the Board of HSBC Australia had intelligence in 2022 and 2023 that warned it of a looming systemic weakness with its internal payment rails.

The Government's Statement of Expectations to APRA

On the same day the Federal Court handed down its findings in ASIC v HSBC, the Government's July 2026 Statement of Expectations (SoE) to APRA removed any remaining basis for APRA treating scam and fraud control failures as ASIC's or AFCA's problem alone.

The newly published SoE requires APRA to “require that regulated entities implement prudent practices in relation to risk management” (clause 2.4). Scam controls are risk management. There is no carve-out in that instruction for fraud losses simply because they appear as a “scam” rather than a balance-sheet risk.

The SoE further requires APRA's capability to be “matched to emerging threats” and aligned with the Government's cyber security framework (clause 2.10). Scam typologies – spoofing, mule networks, AI-enabled social engineering – are an emerging threat to the payments system that could quickly scale and escalate as frontier AI and quantum computing arrive.

Clause 4.3 asks APRA to take “decisive action where systemic prudential or member outcome risks and failures in governance or risk management, have the potential to cause significant harm” – and names a direct comparator (“platform investment governance”). HSBC's conduct is the banking-sector equivalent: governance failure, known internally for years, causing systemic consumer harm.

Clause 4.6 requires regulated entities to maintain “robust cybersecurity arrangements to ensure the financial and operational resilience of those entities.” Fraud and scam controls sit inside operational resilience and are not a separate category APRA can ignore.

And clause 4.10 supplies the sharpest instrument: a “supervision-led and preventative approach… with a clear willingness to escalate to formal directions and enforcement action where necessary to prevent or remedy significant harm to depositors.” This is a government instruction to act before a $35 million Federal Court penalty is required – not after.

APRA already has precedent for treating governance failure as a capital and prudential issue, not merely a conduct one. Since 2018, APRA has imposed 5 capital overlays on insurers, 7 on banks, and 13 additional licence conditions on RSE licensees for governance concerns. Yet scam and fraud losses – despite the Federal Court's own finding that HSBC's failures were governance and operational-risk failures – have so far triggered only ASIC conduct action and AFCA dispute resolution, never APRA's capital-overlay or enforceable-undertaking machinery under APS 112 or CPS 510.

The new SoE removes APRA's ability to leave that gap open. If HSBC's own leadership knew about its control deficiencies for years and customers absorbed the loss, that is precisely the governance failure clause 4.3 instructs APRA to act “decisively” on – and clause 4.10 instructs APRA to escalate through formal directions before harm accrues, not respond only once a court has forced its hand.

Scam Victim Alliance calls on APRA to use its Statement of Intent, issued in response to this SoE, to commit to:

  • Treating sustained fraud control failures as a governance and operational-risk matter which could trigger capital overlays under existing CPS 220 / APS 112-style powers rather than a regulatory matter referred on to ASIC or AUSTRAC or a customer dispute at AFCA.

  • Publishing supervisory expectations on fraud-control adequacy, in the same way APRA already does for cyber and operational resilience.

  • Publicly reporting, per its Annual Performance Statement obligation under clause 7.5, on how many ADIs have been subject to heightened supervision or capital add-ons for fraud/scam control deficiencies – closing the transparency gap SVA has already identified around undisclosed AFCA settlement outcomes.

Structural Comparison: Bendigo Bank vs HSBC Australia

On 18 August 2026, APRA imposed formal licence conditions on Bendigo and Adelaide Bank under s9AA(1)(a) of the Banking Act 1959, following an independent root cause analysis (Deloitte, commissioned at APRA's direction). They found Bendigo's non-financial risk management weaknesses were extensive, that the bank lacked a complete and reliable view of its regulatory obligations, material risks and key controls, and that material deficiencies in governance, accountability, compliance management, risk oversight and risk management capability had persisted despite years of remediation activity. APRA is maintaining Bendigo's existing $50 million operational risk capital add-on until it is satisfied the underlying prudential concerns are fixed, and worked jointly with ASIC and AUSTRAC on the response.

Our HSBC victim-survivor Mr B has just had his SAPOL FOI file (SAP2400031153) released – of the $49,900 he lost through HSBC's compromised Digital Secure Key process on 25 November 2023, the funds were broken into first-hop payments including two separate Bendigo Bank accounts (also Macquarie and Suncorp) before being further co-mingled with other scam-typology funds and dispersed into additional mule accounts. Bendigo Bank is a documented receiving institution in the same mule-laundering chain that moved Mr B.'s HSBC funds beyond recovery. What's more, state-funded police agencies have not arrested anyone in connection with the financial crime, which police state in Mr B.'s FOI file was orchestrated by an overseas syndicate.

Bendigo BankHSBC AustraliaDeloitte RCA: longstanding, pervasive non-financial risk management weaknesses; control gaps for yearsFederal Court (ASIC v HSBC, 18 June 2026): known control gaps for years, ePayments Code breaches in 97% of cases examined, inadequate prevention/detection/investigation/remediationRoot cause established by an APRA-commissioned independent reviewNo root cause established via independent review, but detailed in a Federal Court judgment, orders and statement of agreed facts – a higher evidentiary bar than Bendigo's own RCAAPRA licence conditions imposed – Independent Reviewer, Rectification Plan, Board attestation, quarterly reporting, FAR accountability tie-inNo APRA licence conditions imposed to date$50m operational risk capital add-on maintained until fixedNo capital add-on imposed

If weaknesses identified by a bank-commissioned consultancy report can trigger licence conditions on Bendigo, SVA believes a Federal Court's judicial findings of sustained, known control failure at HSBC might also respectfully be considered as a trigger for prudential licence conditions.

The Federal Court's findings in ASIC v HSBC were not just about financial losses but also that the bank – which has now sold to Blackstone Capital – also:

  • failed to have adequate systems to prevent and detect unauthorised transactions;

  • failed to comply with ePayments Code requirements in 97% of cases examined;

  • failed to properly advise customers how to regain access to their accounts after fraud-related restrictions were imposed; and

  • had deficiencies spanning prevention, detection, investigation, remediation and governance which were recognised by the Court as “serious… widespread and systemic.”

What SVA Urges APRA to Consider

Our organisation would urge APRA to consider:

  • Commissioning an independent root cause analysis of HSBC's scam and fraud control failures, mirroring the Deloitte RCA process, with findings reported directly to APRA, ASIC, AUSTRAC and State police agencies.

  • Imposing licence conditions under s9AA(1)(a) requiring HSBC to appoint an Independent Reviewer (subject to APRA veto), prepare a Rectification Plan with defined Target States, measurable Rectification Activities, and firm timelines, and provide quarterly reporting and Board Risk/Audit Committee minutes to APRA.

  • Considering whether an operational risk capital add-on is appropriate given that HSBC has sold out of Australia, on the Bendigo model, that cannot be removed until HSBC demonstrates – to APRA's satisfaction – that its scam and fraud detection controls meet the standard the Federal Court found absent.

  • Tying accountability to remuneration, requiring HSBC to reflect these obligations in the Accountability Statements of its FAR Accountable Persons and demonstrate that variable remuneration reflects whether rectification targets are being met so the executives who oversaw the control gaps face direct financial consequences, not just the shareholders and customers.

  • Requiring Board-level attestation from the HSBC Australia Chair and Risk/Audit Committee chairs once rectification is substantially complete.

  • Coordinating with ASIC and AUSTRAC, as APRA did with Bendigo, given the mule-account and money-laundering dimension of this case (Bendigo, Macquarie and Suncorp accounts all featured in the fund trail), recognising that HSBC's outbound control failure and Bendigo's inbound mule-account failure are two ends of the same laundering pipeline.

Australia is uniquely targeted by international syndicates, hacktivist groups and threat actors, with only Singapore losing more money per head to scams than Australia. We believe Australian scam risks that have caused significant customer and institutional harm should not remain invisible at Board level.

Section 3: Scam & Financial Crime Governance Audit Ideas

The Board could ensure that scam and financial crime risk is explicitly identified within the entity's risk management framework as a material non-financial risk, with a documented risk appetite statement, key risk indicators and escalation thresholds.

Definitions

  • Scam risk means the risk of financial loss, data compromise or customer harm arising from deception intended to induce a customer, employee or counterparty to transfer funds, disclose credentials, or redirect a payment.

  • Financial crime risk includes scam risk together with money laundering, mule account activity, identity theft and organised-crime-enabled fraud that uses the ADI's products, processes, staff interactions or payment rails to facilitate social engineering.

  • Complaint intelligence means the systematic analysis of Internal Dispute Resolution (IDR) complaint data and External Dispute Resolution (EDR) complaint data for the purpose of identifying emerging typologies, control weaknesses and systemic risk, as distinct from case-by-case issues.

  • Systemic control failure means a control weakness such as staff training, technical gaps, process gaps, audit controls or other internally examined processes that has affected, or is reasonably likely to affect, more than one customer, or that reflects a structural gap in fraud, cyber or financial crime controls.

Escalation Framework and Board Reporting

The Board's governance framework could set out how scam and financial crime risk is escalated from operational and complaints teams to senior management and the Board, and the maximum timeframes within which escalation must occur once a systemic control failure is identified.

The Board, or the Board Risk Committee acting on the Board's behalf, should report at least quarterly (and more frequently where risk indicators are elevated) covering, at a minimum:

  • scam losses and attempted scam losses, by emerging typologies, particularly examining how each customer became a lead, the deception at play, the transactional bleed and the money laundering/getaway vehicle that made the funds unrecoverable;

  • reimbursement and recovery rates and outcomes;

  • scam complaint volumes and trends, including IDR outcomes and EDR outcomes through AFCA;

  • emerging fraud typologies;

  • mule account activity detected and actioned;

  • identity takeover threats and patterns;

  • scam detection rate and value of scams prevented; and

  • systemic control failures identified since the last report and remediation status.

Reporting could be accompanied by management's assessment of root causes and trend direction, not just transaction-level or complaint detail alone. The Board Risk Committee's charter could explicitly include oversight of scam and financial crime risk within its mandate, consistent with the Board committee requirements of CPS 510 paragraphs 35 to 41. Where an entity combines its Audit and Risk Committees under CPS 510 paragraph 37, the combined committee must demonstrate dedicated agenda time for scam and financial crime risk at each meeting at which paragraph 3.3 reporting is presented.

Board Skills and Capability

The Board skills matrix required under CPS 510 could include demonstrated capability, across the Board collectively, in: cyber-enabled fraud; financial crime; artificial intelligence-enabled risk; digital identity; operational resilience; and organised crime threats.

Gaps identified against paragraph 3.8 could be addressed through the Board renewal plan or a documented director development plan, consistent with CPS 510 paragraph 49.

The annual performance assessment required under CPS 510 paragraph 50, and the independent performance assessment required under CPS 510 paragraph 53 for significant financial institutions, could evaluate how effectively the Board and its committees have overseen scam risk, emerging fraud trends, customer outcomes, remediation programs and the implementation of corrective actions.

Working with Complaint Intelligence

Entities could treat complaint data arising from suspected scams and financial crime as governance intelligence, with significant trends in complaint data – repeated typologies, recurring reimbursement disputes, or a common control weakness identified across multiple complaints – triggering a documented root-cause analysis, independent assurance review, and reporting to the Board Risk Committee. The entity could maintain a documented process for feeding root-cause findings back into fraud control design, customer remediation practice, process change and staff training. We believe reimbursement rates should be measured as part of this.

Escalation and Regulator Notification

Where the Board or senior management becomes aware of scam typologies scaling, the entity could escalate this to APRA, and to ASIC, AUSTRAC and the ACCC as relevant – not just the Fintel Alliance or the Australian Financial Crimes Exchange – according to the nature of the failure, within a timeframe set out in the entity's governance framework and, absent a documented justification, no later than 10 business days from identification.

An entity shouldn't rely on the resolution of individual AFCA or internal complaints as a substitute for escalation required under paragraph 5.1 where the underlying control failure is systemic and scaling on a week-to-week or month-to-month basis.

The Board must ensure management identifies and monitors scam and fraud risks that arise across the customer transaction ecosystem, and not only within the entity's own systems, including risks arising in novel and unusual ways through channels that suddenly scale or appear ‘unusual’.

Assurance and Audit

The entity's internal audit function, consistent with CPS 510 paragraphs 42 and 44, must include in its annual program an assessment of the Board's oversight of scam and financial crime risk, covering at a minimum:

  • verification that Board reporting under paragraph 3.3 occurred at the required frequency and content;

  • evidence of complaint-trend analysis and root-cause reviews;

  • existence and effectiveness of the senior executive accountability arrangement;

  • documented escalation to regulators for systemic control failures; and

  • evidence of ecosystem risk monitoring.

Conclusion

Our organisation believes scam and financial crime risk should sit alongside financial and operational resilience as a material governance responsibility requiring direct Board oversight. The Scams Prevention Framework – which is not rolling out until March 2027 – will require regulated entities to document governance policies and obtain annual senior-officer certification. However, the SPF's own Explanatory Memorandum acknowledges that code compliance does not equate to compliance with its governance principle, leaving “adequate governance” open to interpretation.

APRA's prudential toolkit is what can close that gap, as CPS 510 can turn a certified governance policy into a Board that is accountable, with capital and licence consequences, for whether that policy actually works. Directors and senior executives could be assessed on their actual track record in managing fraud risks and protecting customers from foreseeable harm by understanding rising systemic scam types.

Risk and Audit Committees could have an explicit mandate to examine scam losses, complaint intelligence, emerging typologies and systemic control failures – including settlement terms and any confidentiality provisions attached to scam-related IDR and AFCA outcomes. This would close the gap between information held deep within an institution and the risks ultimately visible to those responsible for its governance.

Existing whistleblower protections under CPS 510 should also operate effectively where employees seek to expose systemic scam or fraud-control failures. This is particularly important given SVA's concerns about confidentiality provisions, including those attached to AFCA-facilitated settlements, potentially discouraging disclosure of wider systemic problems that the SPF's disclosure and reporting obligations do not reach.

Our suggestions do not require APRA to be given an entirely new regulatory toolkit but instead tweak existing prudential governance mechanisms to prioritise recognising scam and financial crime risks – providing the structural accountability the SPF's governance principle was designed to encourage but, on its own, has no power to enforce.

ASIC Chair Sarah Court has promised timely reimbursement to HSBC victims after the historic case.

Next
Next

AFCA must Reopen HSBC Scam Cases Following Historic Federal Court Findings