Bendigo Bank hit with new conditions over ‘longstanding’ management weaknesses

Australia’s top banking regulator has taken stiff enforcement action against one of the country’s major regional lenders, forcing it to commit an additional $70 million to fix widespread, long-standing failures in anti-money laundering (AML) and counter-terrorism financing (CTF) controls that slipped through years of internal remediation work.

The Australian Prudential Regulation Authority (APRA) announced the new binding licence conditions for Bendigo and Adelaide Bank on Tuesday, capping off a 12-month industry probe that was triggered after the bank itself commissioned global consulting firm Deloitte to investigate suspicious activity at a single branch in late 2025. What investigators initially expected to be an isolated issue quickly expanded into a company-wide audit that uncovered systemic gaps in how the bank manages financial crime risk, spanning every core layer of its AML/CTF framework.

Deloitte’s final root-cause analysis confirmed widespread failures across multiple critical functions: the bank’s approach to AML/CTF risk mapping, enhanced customer due diligence protocols, enterprise-wide risk oversight, automated transaction monitoring systems, and customer risk rating processes all fell short of regulatory requirements. The review also confirmed that the gaps left the bank vulnerable to potential compliance breaches between August 1, 2019 and August 1, 2025.

APRA’s formal order lays out four distinct categories of material weaknesses that prompted the new regulatory action. First, deficiencies in non-financial risk management are embedded across the entire organization, not limited to a single division or branch. Second, the bank lacks a clear, comprehensive and accurate understanding of its own regulatory obligations, material risk exposures, and key internal controls. Third, there are significant gaps in governance structures, accountability frameworks, compliance management systems, and overall risk management capacity across the bank. Finally, these core weaknesses have persisted for years, even as the bank carried out a multi-year enterprise-wide risk transformation initiative known as BEN+.

To address these failures, Bendigo and Adelaide Bank will invest $70 million over the next three years to overhaul its risk management systems, with the full cost already allocated to the bank’s 2026 financial year results. APRA is also retaining an existing $50 million financial penalty that it imposed on the bank in a previous enforcement action related to the same issues, bringing the total cost of the failures to $120 million for the lender.

Therese McCarthy Hockey, APRA’s Deputy Chair, emphasized in a statement that the new licence conditions reflect the severity of the unaddressed risk gaps uncovered by the probe. “The weaknesses identified by the root cause analysis are significant, longstanding and require decisive action,” she said. McCarthy Hockey added that the regulator acknowledges the cooperative approach the bank has taken so far, and that APRA is encouraged by the board’s public commitment to resolving all identified concerns fully, promptly and effectively. She also confirmed that despite the risk management failures, the bank remains financially sound with no threat to its current operations or customer deposits.

Richard Fennell, Bendigo and Adelaide Bank’s Chief Executive, acknowledged the severity of the gaps in an official response on Tuesday. “Our current non-financial risk management capabilities are clearly not where they need to be, and our risk rectification plan will be designed to drive a fundamental shift in our management of non-financial risk,” Fennell said. He added that the three-year remediation plan will deliver wholesale improvements to the bank’s risk governance and compliance infrastructure to bring the bank back into full alignment with Australian regulatory requirements.