APRA’s decision to grant Revolut an authorised deposit-taking institution licence is a clear signal that the prudential perimeter remains live, and that new entrants can still be brought into the banking system under formal supervision.
The release was published by APRA on 21 July 2026. It confirms that Revolut has been granted an ADI licence. This is a massive achievement for Revolut and congratulations to everyone involved.
This also matters for boards, executives and risk teams because licensing is not a branding exercise — it is a gateway into a supervised environment where governance, risk management and control expectations become part of the operating model.
gateway into a supervised environment where governance, risk management and control expectations become part of the operating model.
The Board-Level Take
For established institutions, the immediate point is not whether Revolut changes your compliance register today. The point is that APRA is still willing to admit new players where the licence case is strong enough, which should sharpen attention on how the market is changing and how resilient your own control environment looks by comparison.
For newer or fast-scaling financial businesses, this is a reminder that prudential readiness is a whole-of-business issue. It is not enough to have a product proposition and growth strategy; the governance framework, risk ownership, incident handling, and operational discipline need to be credible as well.
What APRA Is Really Signalling
Licensing is still a live test of maturity
Granting an ADI licence is a substantive supervisory decision. It implies that APRA has been satisfied, at least to the level required for authorisation, that the applicant can operate within the prudential system. For boards, the practical lesson is straightforward: regulatory entry decisions still turn on evidence, not aspiration.
That should prompt a fresh look at how your organisation documents readiness, escalates issues, and demonstrates control effectiveness. If the evidence trail is thin, even a strong internal narrative may not be enough.
Market entry changes the risk conversation
A new ADI entrant can alter expectations around product design, customer experience, digital delivery and operating tempo. That does not automatically mean weaker controls — but it does mean incumbents need to stay alert to where prudential supervision, operational risk and consumer outcomes intersect.
Boards should be asking whether their current risk appetite, technology oversight and incident governance are robust enough to compete in a market where new entrants may move quickly but still need to satisfy prudential standards.
Questions Your Board Should Be Asking Now
- How are we tracking new ADI entrants and the implications for our own strategic and risk posture?
- If we were subject to a licensing-style readiness review today, what evidence would we produce on governance, risk and operational control maturity?
- Do our board and committee papers adequately capture competitive and prudential perimeter changes, or are we only seeing internal compliance issues?
- Where do we rely on assumptions about control effectiveness that are not backed by testing, assurance or incident data?
- Are our escalation pathways and accountabilities clear enough to support a regulator-facing review if our operating model changed quickly?
Why This Needs Attention Now
There is no long implementation runway here, but there is a strong strategic signal.
Licensing decisions like this are useful markers of where the sector is heading, and they deserve attention from boards and executive risk forums even when they do not impose a new deadline.
For organisations that want to stay ahead of regulatory movement rather than react late, this is the sort of development that should feed into board reporting, horizon scanning and maturity assessment work.
Turning Regulatory Change Into Readiness
The Innovation of Risk Reading Room tracks APRA, ASIC and other regulatory developments as they move from consultation to enforcement.
If your board or risk team wants a structured way to monitor obligations, test control maturity and identify evidence gaps early, that is the place to start.

