APRA grants Revolut an ADI licence — a reminder that prudential entry standards still matter

APRA’s decision to grant Revolut an authorised deposit-taking institution licence is a clear signal that the prudential perimeter remains live, and that new entrants can still be brought into the banking system under formal supervision.

The release was published by APRA on 21 July 2026. It confirms that Revolut has been granted an ADI licence. This is a massive achievement for Revolut and congratulations to everyone involved.

This also matters for boards, executives and risk teams because licensing is not a branding exercise — it is a gateway into a supervised environment where governance, risk management and control expectations become part of the operating model.

gateway into a supervised environment where governance, risk management and control expectations become part of the operating model.

The Board-Level Take

For established institutions, the immediate point is not whether Revolut changes your compliance register today. The point is that APRA is still willing to admit new players where the licence case is strong enough, which should sharpen attention on how the market is changing and how resilient your own control environment looks by comparison.

For newer or fast-scaling financial businesses, this is a reminder that prudential readiness is a whole-of-business issue. It is not enough to have a product proposition and growth strategy; the governance framework, risk ownership, incident handling, and operational discipline need to be credible as well.

What APRA Is Really Signalling

Licensing is still a live test of maturity

Granting an ADI licence is a substantive supervisory decision. It implies that APRA has been satisfied, at least to the level required for authorisation, that the applicant can operate within the prudential system. For boards, the practical lesson is straightforward: regulatory entry decisions still turn on evidence, not aspiration.

That should prompt a fresh look at how your organisation documents readiness, escalates issues, and demonstrates control effectiveness. If the evidence trail is thin, even a strong internal narrative may not be enough.

Market entry changes the risk conversation

A new ADI entrant can alter expectations around product design, customer experience, digital delivery and operating tempo. That does not automatically mean weaker controls — but it does mean incumbents need to stay alert to where prudential supervision, operational risk and consumer outcomes intersect.

Boards should be asking whether their current risk appetite, technology oversight and incident governance are robust enough to compete in a market where new entrants may move quickly but still need to satisfy prudential standards.

Questions Your Board Should Be Asking Now

  • How are we tracking new ADI entrants and the implications for our own strategic and risk posture?
  • If we were subject to a licensing-style readiness review today, what evidence would we produce on governance, risk and operational control maturity?
  • Do our board and committee papers adequately capture competitive and prudential perimeter changes, or are we only seeing internal compliance issues?
  • Where do we rely on assumptions about control effectiveness that are not backed by testing, assurance or incident data?
  • Are our escalation pathways and accountabilities clear enough to support a regulator-facing review if our operating model changed quickly?

Why This Needs Attention Now

There is no long implementation runway here, but there is a strong strategic signal.

Licensing decisions like this are useful markers of where the sector is heading, and they deserve attention from boards and executive risk forums even when they do not impose a new deadline.

For organisations that want to stay ahead of regulatory movement rather than react late, this is the sort of development that should feed into board reporting, horizon scanning and maturity assessment work.

Turning Regulatory Change Into Readiness

The Innovation of Risk Reading Room tracks APRA, ASIC and other regulatory developments as they move from consultation to enforcement.

If your board or risk team wants a structured way to monitor obligations, test control maturity and identify evidence gaps early, that is the place to start.

More from the Reading Room

When National Alerts Miss Local Needs: Queensland’s Opt-Out from AusAlert

Queensland opted out of AusAlert this bushfire season despite a 94% national test success rate. This isn't about whether that call was right — it's about the resilience discipline it illustrates: weighing your own specific variables today and making a definitive decision ahead of the event that will test it.

Regulator sharpens the warning on facial recognition

The OAIC has updated its facial recognition guidance for APP entities using biometric technology in high-volume, publicly accessible retail spaces. The update reflects the ART’s March 2026 Bunnings decision and reinforces that each deployment needs…

Risk Maturity in Action: Turning Customer Promises into Reliable Outcomes

Two recent ASIC matters provide a useful opportunity to think differently about risk management. They can be read as stories about compensation, penalties and compliance...

APRA’s Level 3 conglomerate standard reset is a governance issue

APRA has published its response to consultation on remaking the Level 3 conglomerate standards. This is a substantive prudential and governance update for groups with complex conglomerate structures, especially where superannuation, insurance and banking interests…