A green dashboard is dangerous when nobody can prove the number behind it.
APRA’s 3 September 2026 action against ING Australia after years of liquidity miscalculations reminds us that any metric used for compliance or executive decisions must be governed as a controlled product with traceable data, independent checks and escalation for uncertainty.
The 30-second take
ING reported a liquidity coverage ratio of about 160 per cent, but APRA said the corrected position was materially lower and had at times fallen below the 100 per cent minimum.
APRA imposed licence conditions, independent reviews, remediation, higher liquidity requirements and a $50 million operational-risk capital add-on.
The business lesson is wider than banking: a reported result is not reliable evidence unless the calculation, inputs, ownership and challenge can be reproduced.
What happened
APRA announced its action against ING Australia on 3 September 2026. ING had notified the regulator in July after identifying that it had miscalculated its liquidity position over several years. According to APRA, the bank had been reporting a liquidity coverage ratio around 160 per cent, while the corrected ratio was substantially lower and at times below the prudential minimum of 100 per cent.
APRA described the matter as more than a reporting error. Its response included additional licence conditions, independent reviews of liquidity risk management and regulatory reporting, a remediation program, a higher liquidity requirement and a $50 million operational-risk capital add-on. Those measures remain until APRA is satisfied that the problems have been addressed.
The scale gives the issue practical weight. APRA noted that ING Australia has more than two million customers and more than $100 billion in assets. The weakness therefore affected a metric used to assess resilience in a material institution, not an obscure internal calculation.
APRA’s APS 210 Liquidity standard makes the board ultimately responsible for liquidity risk management. The standard requires a robust framework, reliable measurement and reporting, and processes for escalation. APRA’s supporting practice guide reinforces the need for sound systems, assumptions, controls and stress analysis.
Why this matters for your business
Every organisation has numbers that drive consequential decisions: cash headroom, customer harm, cyber exposure, inventory availability, service uptime, safety incidents, complaints, capital, project completion and regulatory compliance. These numbers often arrive as polished dashboards. The presentation can create confidence that the underlying calculation has not earned.
The ING case exposes a common failure pathway. Data is extracted from several systems, transformed through logic owned by a small team, adjusted manually and reported through a dashboard. When the result looks plausible and sits comfortably within tolerance, challenge weakens. The organisation begins managing to the reported number rather than to the underlying risk.
A buffer can make the problem harder to detect. A reported result that is well above a threshold may receive less scrutiny, even when errors in classifications, timing, assumptions or exclusions are material. The apparent margin becomes a substitute for control evidence.
This matters outside financial services. A retailer may overstate stock available for customer orders. A manufacturer may understate overdue maintenance because work orders are coded incorrectly. A health provider may report incident closure while actions remain incomplete. A technology business may show service availability that excludes customer-impacting failures.
In each example, management receives a green signal while exposure accumulates.
Where the risk can surface
The first weakness is fragmented ownership. Finance owns the report, technology owns the data, operations owns the process and risk owns the tolerance, but no one owns the end-to-end integrity of the metric.
The second is opaque transformation logic. Spreadsheets, code, manual overrides and mapping tables evolve without controlled change records. The reported figure cannot be reproduced independently from source data.
The third is weak exception handling. Reconciliations identify differences, but teams clear them as timing issues or known limitations without assessing whether the aggregate effect could change a decision or breach a threshold.
The fourth is assurance aimed at presentation rather than substance. Reviewers confirm that the dashboard was produced on time and approved, but do not test data lineage, calculation rules, assumptions, access, overrides and threshold logic.
What leaders should do now
The executive who relies on a critical metric should appoint one end-to-end metric owner. That person should maintain a plain-English definition, source inventory, calculation method, tolerance, known limitations and escalation rules. Ownership must include the integrity of the outcome, not simply timely production.
Data and control teams should make the number reproducible. Retain source snapshots, transformation rules, manual adjustments, approvals and version history. A competent reviewer should be able to rebuild a sample result and explain every material difference.
Risk owners should design challenge around decision sensitivity. Test what happens when classifications, assumptions or data timing change. If a modest adjustment can move the result across a limit or alter an executive decision, monitoring and escalation should reflect that sensitivity.
Internal audit or an independent reviewer should trace selected dashboard results back to source evidence and forward to the decisions they informed. The review should ask whether control failures were detected quickly and whether uncertainty was visible to the board, rather than merely confirming that a report existed.
Questions for your business
- Which reported metrics could conceal a material breach or poor decision if they were wrong?
- Who owns each critical metric from source data through calculation to executive use?
- Can an independent reviewer reproduce the result and every material adjustment?
- Do reconciliations escalate uncertainty before a number crosses a formal limit?
- Does assurance test the calculation and data lineage rather than the dashboard’s appearance?
Visit the Innovation of Risk for practical questions on metric integrity, escalation and decision evidence.

