APRA’s licence conditions on Bendigo and Adelaide Bank highlight again the regulators continual focus on when non-financial risk is not effectively part of what the organisation does and is not producing a dependable control environment for the people it serves.
For boards, the message is clear: risk management is part of everything all leaders and employees do, and just showing task or policy progress against a plan is not clear enough evidence that the underlying risk weaknesses has been fixed.
The 30-second take
APRA escalated from supervisory concern to formal licence conditions after Deloitte found longstanding and pervasive non-financial risk weaknesses.
Bendigo Bank must deliver a comprehensive rectification program, appoint an independent assurer and provide board attestation, while a $50 million operational-risk capital add-on remains.
Boards should govern risk management and risk remediation through a strong focus on continual risk maturity, strong culture, clarity of root causes, verified control outcomes and sustainable capability—not milestone statuses.
What the independent analysis found
On 18 August 2026, APRA said Deloitte’s root-cause analysis found weaknesses prevalent across Bendigo Bank. The bank did not have a clear, complete and reliable view of its regulatory obligations, material risks and key controls, and the review identified material deficiencies in governance, accountability, compliance management, risk oversight and capability.
The persistence matters most. APRA said key weaknesses remained despite several years of remediation under the bank’s BEN+ enterprise-wide risk transformation program. It was not satisfied that the underlying causes had been addressed or that sustainable risk uplift had been delivered.
The licence conditions require a comprehensive rectification plan, an independent assurer and board attestation. APRA will retain the existing $50 million operational-risk capital add-on until the bank has effectively addressed the prudential concerns. Financial strength did not prevent formal intervention in the non-financial risk framework.
The cost of delayed maturity is now visible
Bendigo Bank acknowledged that its non-financial risk capability was not where it needed to be. It announced a program expected to run for approximately three years at an initial estimated cost of $70 million, sponsored directly by the chief executive.
That cost is only one part of the impact. Management attention, independent review, board oversight, regulatory engagement and the continuing capital add-on sit alongside the program expense. A weakness that survives successive remediation cycles becomes more expensive and more difficult to close with confidence.
This was an escalation, not a surprise
APRA and AUSTRAC had already acted in December 2025 after an independent review identified significant deficiencies in the bank’s management of money-laundering and terrorism-financing risk. APRA required the broader root-cause analysis and imposed the $50 million capital add-on, while AUSTRAC began an enforcement investigation.
The sequence is instructive. A control failure in one area can reveal an enterprise governance problem when the organisation cannot connect obligations, risks, controls, ownership and assurance.
Executives and Boards need that enterprise view before a regulator asks whether the same weakness exists elsewhere.
Govern risk remediation as a business-wide control-outcome program
Risk management is about understanding explicit root causes, accountabilities, dependencies, evidence and effective testing. Measures should show whether obligations are understood, key controls are designed and operating effectively, recurring failures are falling and risk capability is improving in the business.
Attestations should be the end of an evidence chain, not a statement of confidence.
The organisation should be able to show what changed, how the change was tested, who challenged the result and how sustainability will be monitored.
Questions for your organisation
- Which material issues have remained open or repeatedly re-baselined across reporting periods?
- Can the board see the root causes behind each major remediation program rather than milestones alone?
- Is there a reliable link between regulatory obligations, material risks and key controls?
- Does independent assurance test whether remediation is operating effectively in the business?
- Are closure and attestation supported by evidence that would withstand regulatory scrutiny?
- Can management show that similar weaknesses have been assessed across the wider organisation?
The opportunity is to identify persistent weakness before it becomes a licence condition.
Explore more board-ready risk questions and take a readiness snapshot in the Innovation of Risk Reading Room.

