Australia’s banks reported 9,326 breaches of the Banking Code of Practice in just six months — and lending to individuals was the single biggest source, according to new data released by the Banking Code Compliance Committee (BCCC) covering July to December 2025. For brokers, who now originate the vast majority of new home loans, the message is blunt: the manual, judgement-dependent processes inside bank lending teams are failing often enough that your files, your clients and your settlement timelines are exposed.

Key Takeaways

  • The BCCC logged 9,326 Banking Code breaches in July–December 2025, with lending to individuals the most breached area at 3,937 breaches.
  • Vulnerability failures affected more than 10,000 customers and caused $5.52 million in customer financial impact.
  • Banks blamed “staff error” — the BCCC says the real culprits are weak systems, manual processes and poor workflow design, including staff missing or bypassing required steps before progressing loan applications.
  • The findings land amid heavy enforcement: Westpac’s $26m hardship penalty, NAB’s $15.5m fine and ANZ’s $240m misconduct bill.
  • With ASIC’s Best Interests Duty review report due by Q4, brokers who document client care properly are on the right side of a widening compliance gap.

What the BCCC Found: 9,326 Breaches in Six Months

The BCCC — the independent body that monitors banks’ compliance with the Banking Code of Practice, investigates alleged breaches and can impose sanctions for serious non-compliance — released its latest compliance data on 27 July, covering the July to December 2025 reporting period.

The headline numbers from the BCCC’s latest data release break down like this:

  • Lending to individuals: 3,937 breaches — the most frequently breached code paragraph
  • Extra care for customers experiencing vulnerability: 1,528 breaches
  • Complaints handling: 1,479 breaches
  • Deceased estates: 1,305 breaches
  • Communicating with customers: 436 breaches

That’s more than 42 per cent of all reported breaches sitting squarely in the lending function — the exact part of the bank your files pass through every day.

Why Lending Tops the Breach List

The BCCC’s description of what’s going wrong inside lending teams should sound uncomfortably familiar to any broker who has chased a lender for a lost document or an unexplained delay.

“Across these areas, the descriptions of breaches that we received from banks pointed to a common issue: compliance often depended heavily on individual staff judgement, memory or manual action at the point of customer interaction,” the BCCC said. “In lending, examples included staff missing or bypassing required steps before progressing loan applications.”

In other words, the checks that are supposed to happen before an application moves forward — verification steps, disclosure requirements, care obligations — are being skipped or forgotten at the coalface. Not systematically, not maliciously, but often enough to generate nearly 4,000 reported breaches in six months from lending alone.

What that looks like from the broker’s side of the file

Missed steps inside a lender rarely stay invisible. They surface as reworked assessments, last-minute document requests, settlement delays, incorrect loan setups and hardship requests that go nowhere. When a lender’s internal process fails, it’s usually the broker who wears the client conversation.

The Vulnerability Blind Spot: $5.52m in Customer Harm

The report’s second major theme is the one with the sharpest human edge: banks continue to miss opportunities to identify and support customers experiencing vulnerability.

The 1,528 vulnerability-related breaches affected more than 10,000 customers and resulted in $5.52 million in customer financial impact. Staff did not consistently identify, record or act on vulnerability indicators, and in complaints handling they didn’t always recognise dissatisfaction or escalate matters — contributing to missed complaint-handling timeframes.

Gaps in staff skills or knowledge accounted for 10 per cent of staff-related breaches, and vulnerability obligations made up almost half of that group. For a banking system that has spent three years promising better hardship support after high-profile enforcement, that is a poor scorecard.

‘Staff Error’ or System Failure? The BCCC Isn’t Buying It

Most banks attributed the majority of reported breaches to staff error. The BCCC pushed back, arguing the data points to broader weaknesses in underlying systems, processes, controls, training, supervision and workflow design.

“Where breaches arise in processes that rely heavily on manual steps, individual judgement or consistent application of procedures, banks need to consider whether stronger system prompts, workflow controls, supervision, quality assurance or process design would reduce the risk of the same issues recurring,” the committee said.

BCCC chair Sean Hughes was equally direct about what he expects next: “We expect banks to use this data not only to report what went wrong, but to understand why it happened and what needs to change.”

The distinction matters for brokers. “Staff error” implies isolated bad luck. “System weakness” means the same failure modes will keep recurring across lenders until process design changes — which makes lender selection, follow-up discipline and documentation a permanent part of protecting your clients, not a temporary annoyance.

The Enforcement Backdrop: Westpac, NAB and ANZ

This data doesn’t land in a vacuum. In May, Westpac was fined $26 million after ASIC found deficiencies in how it handled hardship assistance requests, including failures to respond appropriately when borrowers were in financial difficulty. That followed NAB’s $15.5 million penalty for failing vulnerable customers and ANZ’s $240 million bill for a string of misconduct issues.

The pattern is consistent: regulators and the code monitor keep finding the same weak points — hardship, vulnerability, manual lending processes — and the penalties keep getting bigger. ASIC has already chalked up $830 million in civil penalties for the financial year. Bank-side lending compliance is now one of the most scrutinised corners of Australian financial services.

What This Means for the Broker Channel

Brokers write roughly four in five new Australian home loans, which means the majority of the applications flowing through these breach-prone bank processes started life in a broker’s CRM. Three practical implications stand out.

1. Your follow-up discipline is now a compliance function

When bank staff “miss or bypass required steps,” a broker’s structured pipeline management — status checks, condition tracking, escalation when a file stalls — is often the only thing that catches the failure before it costs the client. That’s a service story worth telling, and a file-note habit worth keeping.

2. Lender conduct belongs in your best-interests thinking

Best Interests Duty analysis usually centres on rate, features and cost. But turnaround reliability, hardship track record and post-settlement service are legitimate factors in a recommendation — and now there’s public breach data to inform them. A lender that consistently mishandles vulnerable customers is a real risk factor for a client with fragile circumstances.

3. You are the client’s early-warning system

Banks miss vulnerability indicators at the point of interaction; brokers usually see them first — job loss, separation, health issues, irregular income. Recording what you saw and how you responded protects the client and demonstrates exactly the care obligation the banks are being penalised for missing.

Hardship and Vulnerability: Signals Brokers Catch First

The BCCC data is a reminder that a hardship referral handed to a bank is not a job done — it’s a handover into the most breach-prone part of the system. If a client is heading into difficulty:

  • Document the referral — date, contact, what the bank committed to, and diarise a follow-up.
  • Tell the client what good looks like — banks must respond to hardship notices within statutory timeframes; if the response is silence, that’s escalation territory.
  • Know the escalation ladder — internal dispute resolution first, then AFCA. Clients rarely know this pathway; brokers who walk them through it earn loyalty for life.
  • Watch deceased estates and separations — with 1,305 deceased-estate breaches reported, executors and surviving partners in your book need a proactive check-in, not a form letter.

The BID Contrast: Two Channels, Two Compliance Stories

There’s an industry-level angle here too. ASIC has confirmed its thematic review of broker compliance with the Best Interests Duty will be published by Q4 this year. That means within months, the market will be comparing two datasets: how brokers discharge a legislated duty to act in the client’s best interests, and how bank lending teams perform against their own industry code.

The BCCC report sets a low bar. If the broker channel’s BID report card comes back solid — and brokers’ record 80-plus per cent market share suggests customers have already voted — the contrast becomes one of the strongest advocacy tools the third-party channel has ever had. The flip side: any broker running thin file notes is handing ammunition to the other side of that comparison.

Broker Action Plan: Five Moves to Make This Week

  • Audit your in-flight pipeline for files stalled at lender processing — chase status on anything that’s been quiet for more than five business days.
  • Add a vulnerability flag to your fact-find and CRM if you don’t have one, with a simple note field for indicators and actions taken.
  • Build a hardship referral template — who you contacted at the lender, when, what was promised — so every referral is evidenced.
  • Review your top five lenders’ service conduct — hardship handling, error rates you’ve experienced, escalation responsiveness — and factor it into recommendations for at-risk clients.
  • Tighten your BID file notes now, before ASIC’s Q4 report resets the compliance conversation for the whole channel.

The Bottom Line

Nearly 4,000 lending breaches in six months tells brokers something they’ve long suspected: the manual machinery inside bank lending teams fails regularly, and the customers most likely to be hurt are the ones least equipped to notice. That failure is a service gap brokers already fill — but from here, it pays to fill it deliberately: documented follow-ups, recorded vulnerability indicators, evidenced hardship referrals and lender conduct factored into best-interests thinking. Watch for the BCCC’s next reporting cycle and ASIC’s BID review in Q4 — together they’ll frame the compliance debate, and the broker value story, heading into 2027.

Source: Banking Code Compliance Committee — Banking Code compliance data, July–December 2025 reporting period.

Disclaimer: This article is for general information and professional development purposes only. It does not constitute legal, compliance, or financial advice. Brokers should consult their aggregator’s compliance team and, where required, seek independent legal advice regarding their obligations under the National Consumer Credit Protection Act 2009 and ASIC’s responsible lending guidelines.