The Banking Code Compliance Committee (BCCC) has found that banks risk overlooking deeper weaknesses in systems, processes and controls by attributing most breaches of the Code of Practice to staff error.
In its latest Compliance Statement Report, the BCCC found that staff-related causes accounted for 84% of the 9,326 breaches reported by banks between July and December 2025. Staff training was reported as a corrective action for 83% of breaches, either alone or alongside other measures.
Chair of the BCCC Sean Hughes said staff error did not always explain why a breach occurred.
“Staff error may describe where a problem became visible, but it does not necessarily tell us what allowed it to happen,” Mr Hughes said.
“If compliance depends heavily on manual steps, individual judgement or staff memory, banks need to consider whether stronger systems and process controls could prevent problems recurring.
“Training is important, but it cannot be the default response to every breach involving a staff member.”
The report found that breaches attributed to policy or process deficiencies had a disproportionately large effect on customers. They accounted for only 7.9% of reported breaches but affected more than 1.26 million customers and caused $15.25 million in customer financial impact.
Mr Hughes said breach data should help banks identify underlying problems and choose corrective actions that address their root causes.
“Identifying a breach should be the beginning of the analysis, not the end,” he said.
“Banks need to understand why a breach occurred and whether changes to systems or processes would provide a more lasting solution.”
The report also found that banks continue to miss opportunities to recognise and support customers experiencing vulnerability.
Banks reported 1,528 breaches of vulnerability commitments, affecting 10,000 customers and resulting in $5.52 million in customer financial impact.
System and process issues accounted for 60% of customers affected by vulnerability-related breaches, but banks most frequently reported staff training as the corrective action.
“Banks need to ensure that their frameworks to support vulnerable customers work reliably when customers interact with the bank,” Mr Hughes said.
“Customers should not have to depend on a staff member recognising the right signal or remembering a manual step. Staff need reliable systems, clear escalation pathways and practical safeguards to support them so they can respond appropriately and consistently.
“The commitments banks make in the Code are intended to ensure customers receive fair outcomes, and banks need to deliver on their commitments.”
The report’s findings indicate that banks need to use breach data to strengthen the systems, processes and safeguards that shape customers’ experiences and reduce the risk of the same problems recurring.
Read the report: Compliance Statement – July to December 2025.
About us:
The purpose of the BCCC is to monitor and drive best practice Code compliance.
To do this, it:
- examines banks’ practices
- identifies current and emerging industry-wide problems
- recommends improvements to bank practices
- sanctions banks for serious compliance failures, and
- consults and keeps stakeholders and the public informed.
Contact details: