HomeRisk Management

Risk Management

APRA’s section 66 exemption update is a governance check for banks, not just a legal footnote

APRA has finalised changes to Banking Act 1959 section 66 instruments — remaking one restricted-word determination and letting two others sunset — while a broader exemption for foreign bank holding companies stays under review into 2026. Paired with AFCA’s new naming rule for non-compliant firms and the UK PRA’s stricter waiver-by-application regime, it is a reminder that exemptions are governance assets, not legal footnotes.

Origin Energy Data Breach: A Live Case Study in Incident Response Governance

Origin Energy is investigating a potential data breach affecting up to 4.8 million customer accounts, after a hacker calling themselves “John Doe” claimed to hold records for two million Australians and issued a 14-day extortion deadline. Here's what the response so far reveals about incident response governance under Australia's Notifiable Data Breaches scheme.

We need more glass half-full risk managers

Way too many risk managers are glass half-empty people.  Of course the role of risk management is to focus on  the potential things that can go wrong, but that does not mean that the risk manager has to be negatively focused.  In actual fact, it is that negative focus that has made risk managers the type of person that businesses wish to avoid rather than engage.

Regulatory Growth Objective: A New Approach

Treasurer Jim Chalmers's new Statement of Expectations tells APRA and ASIC to back growth, not just guard against risk. The UK gave its regulators the same mandate in 2023 — and a 2025 Lords inquiry found it hadn't shifted the culture at all. Here's what Australian boards should watch for.

22 Days of Silence: The Governance Failure Inside a Data Breach

Partnered Health took 22 days to tell patients a hacker had accessed Medicare numbers, pathology results and DVA details across sixteen clinics, while the OAIC now examines whether the delay itself breached the law. New 2026 Allianz Risk Barometer data shows why every organisation should be watching: cyber, AI and political risk are converging faster than most operating models can absorb.

The Qantas privacy finding: a positive lesson in third-party oversight

A serious data breach does not automatically mean governance failed. The more important question is whether an organisation can demonstrate that it understood the risks,...