2026 Assessment of the Reserve Bank Information and Transfer System 1. Executive Summary

The Reserve Bank Information and Transfer System (RITS), Australia’s high-value payments system, is owned and operated by the Reserve Bank of Australia (RBA). This report presents a detailed assessment of RITS against the CPMI-IOSCO Principles for Financial Market Infrastructures (PFMI). The assessment has been prepared by the RBA’s Payments Policy Department and approved by the Payments System Board. It provides an update as at end March 2026, following the 2024 RITS Assessment and the 2023 Targeted RITS Assessment.

RITS is operated by a team of dedicated and capable professionals. Over the assessment period, the RBA has made meaningful progress in strengthening bank-wide governance, risk management and operational arrangements, including establishing the Governance Board, enhancing the enterprise Risk and Compliance Management Framework and investing significantly in technology and operating model initiatives. Notwithstanding this progress, the program of work affecting RITS has advanced more slowly than anticipated at the time of the 2024 Assessment. Most of the initiatives have not yet been fully embedded, and their effectiveness has not yet been demonstrated in practice.

This assessment has concluded that RITS observes all relevant PFMI, except for: Principle 2 (Governance), which has been downgraded to partly observed; Principle 3 (Framework for the comprehensive management of risks), which remains at partly observed; and Principle 17 (Operational risk), which also remains partly observed.

  • RITS governance: The commencement of the Governance Board and the new Audit and Risk Committee represent a material enhancement to the RBA’s governance structure. Notwithstanding this, the assessment has found that RITS-specific governance requires improvement to ensure that RITS is consistently recognised and managed across the entire RBA as a systemically important payments system (SIPS). The downgrade of Principle 2 (Governance) does not reflect a deterioration in the RBA’s governance of RITS relative to 2024; instead, it reflects greater urgency of implementing RITS-specific governance changes and reinforced recognition that effective governance is foundational to observance of the PFMI, especially in an increasingly complex risk environment. The assessment notes opportunities for the RBA’s governance arrangements to strengthen oversight and challenge for RITS, commensurate with its systemic importance.
  • Comprehensive risk management: Over the assessment period, substantive improvements to the RBA’s risk management foundations took effect. These include an uplifted enterprise Risk and Compliance Management Framework, clearer articulation of roles and responsibilities through the enhanced Three Lines of Accountability (3LoA) model and improvements to risk systems and capabilities. However, RITS does not yet have a standalone risk profile as befitting its systemic importance, and change-related risks are yet to be fully embedded into existing risk frameworks.
  • Operational risk: During the assessment period, significant expenditure and effort were made by the RBA to enhance RITS’s operational risk management. However, slower-than-expected progress in addressing prior recommendations, together with recently identified gaps (such as those revealed in the January 2026 incident), forestalled consideration of an upgrade. This reflects, in part, the increasing pressure from a complex change agenda alongside resource constraints, requiring difficult prioritisation trade‑offs. The more challenging external environment for operational risk means that focus on operational risk issues must continue to be prioritised.

To fully observe Principles 2, 3 and 17 of the PFMI, intended outcomes of the program of work established following the RBA’s 2022 technology outage and recommendations in this assessment should be delivered and embedded.