Financial Stability Review – October 20264.1 Focus Topic: Operational Risk and Financial Stability

Operational risk, including the threat of cyber-attacks, is an increasingly important consideration for financial stability. Growing system-level vulnerabilities, including greater interconnectedness and concentrated reliance on common service providers, increase the risk that operational disruptions at one institution or infrastructure provider could quickly spread across the financial system and undermine confidence. This Focus Topic examines how operational risk differs from (but interacts with) traditional financial risks and considers the implications for how authorities assess, monitor and manage these risks. It also explores how operational disruptions can create and amplify financial stress. Strengthening operational resilience will require ongoing action across the financial system.

The threat that operational risks pose to financial stability is growing.

Operational risk encompasses a wide range of non-financial risks that can disrupt the critical operations of financial institutions, financial market infrastructures (FMIs) and the financial system more broadly. Under the Basel capital framework, operational risk is defined as the risk of loss resulting from inadequate or failed internal processes, people and systems or from external events. The crystallisation of these risks has the potential to generate severe shocks across the financial system and amplify episodes of financial stress. Major operational disruptions can also impair the provision of critical financial services that households, businesses and financial institutions depend on to access their funds, make payments and meet their financial obligations.

The rapidly evolving external threat environment has contributed to a greater focus on operational risks by financial regulators and central banks globally, including in Australia. Rapid advances in frontier AI capabilities, together with broader technological developments, are reducing the cost and technical expertise required to conduct sophisticated cyber-attacks against financial institutions and FMIs.1 At the same time, heightened geopolitical tensions have increased the likelihood of state-sponsored physical or digital attacks on the critical infrastructure that supports the financial system, including the electricity and telecommunications network.2 An Australian Prudential Regulation Authority (APRA) survey conducted in 2025 found that cyber, geopolitical and other operational risks were perceived to be the most significant threats facing APRA-regulated entities (Graph 4.1.1).3 This complex threat environment increases the risk that severe financial and operational shocks – including from cyber and geopolitical threats – occur at the same time. Longer-term shifts in climate patterns, and the increasing frequency and severity of extreme weather events, also pose physical risks to critical infrastructure.

Graph 4.1.1
A bar chart showing the results of APRA’s 2025 Stakeholder Survey on key risks facing regulated entities over the next two years. Cyber security was rated as a critical or high risk by 91 per cent of institutions, followed by geopolitical risks (70 per cent) and broader operational risks (48 per cent), making these the most significant threats identified by respondents.

Entity-level technology choices and governance arrangements can also affect operational risk, particularly during periods of significant change. Financial institutions and FMIs are simultaneously managing legacy technology while undertaking large-scale transformation programs to modernise critical infrastructure and adopt new technologies. Legacy systems can increase the risk of operational failures and cyber vulnerabilities, making transformation necessary to reduce risk. However, transformation programs can themselves strain internal capacity and increase the risk of implementation failures, operational errors and unanticipated disruptions. In such an environment, effective risk governance, clear accountabilities, and staged sequencing become increasingly important to an institution’s ability to deliver change safely, identify emerging vulnerabilities and respond effectively to operational disruptions.

The likelihood that operational incidents become systemic is increasing. Growing system-level vulnerabilities, including increasing interconnectedness and concentrated reliance on material service providers, heighten the potential for operational failures in one part of the financial system to quickly spread across multiple financial entities and undermine system-wide confidence.4 In turn, this can amplify the effects of operational disruptions and propagate widespread financial stress. Given the evolving geopolitical and cyber landscape, policymakers are also attuned to the risk that nefarious actors may seek to time the launch of cyber-attacks on critical financial institutions or infrastructure to coincide with heightened periods of financial market volatility. In such cases, should there be existing strains in market funding conditions or the disruption impairs resilience buffers, the shock is likely to be exacerbated in severity.

A key regulatory priority is to strengthen operational resilience across the Australian financial system.

Strengthening broad-based operational resilience across the financial industry has been a focus of regulators in Australia for a number of years. Operational resilience is an expansive concept, requiring financial institutions, FMIs and participants in the broader financial system to prevent, adapt, respond to and recover from operational disruptions.5 This multifaceted framing recognises that while some disruptions may occur even with strong preventative defences, critical operations must be managed in a way that allows for swift recoverability and for key services to continue to be available through periods of disruption.

Consistent with its financial stability mandate, the RBA has an important role in responding to the evolving operational risk landscape, in partnership with agencies on the Council of Financial Regulators (CFR). Historically, operational risk was viewed primarily as an idiosyncratic risk affecting individual institutions and therefore largely the domain of microprudential supervisors such as APRA. However, the growth of system-wide vulnerabilities, together with the escalating threat environment, have elevated operational risk from a firm-level concern to a broader financial stability issue. This has been reflected in various programs of work with industry, including the Industry Resilience Initiative, which seeks to strengthen the resilience of the payments system as one element of the CFR’s geopolitical risk program (see below).6

Operational risk differs from traditional financial risk in ways that matter for how it is measured, monitored, and addressed.

Unlike financial risks, which are largely contained within the regulated financial sector, operational risks to financial stability can originate from a much broader range of entities. Incidents can arise at material service providers and propagate through complex supply chains and operational dependencies, requiring authorities to consider a broader set of entities beyond the regulated financial sector. This can be challenging because many critical service providers operate internationally or outside the typical regulatory perimeter, limiting visibility over vulnerabilities they may pose. Moreover, smaller entities can play an outsized role in operational risk. A prolonged disruption at a small third party that provides critical services to many financial institutions could have system-wide impacts. In contrast, smaller entities are less likely to represent critical nodes for the transmission of systemic financial risk, allowing financial risk monitoring effort to focus mainly on the largest institutions.7 These challenges are compounded by the gaps in operational risk maturity that can often exist between larger, regulated institutions and smaller or non-financial entities.

The complex and rapidly evolving nature of operational risk makes it harder for regulators to measure and monitor than traditional metrics of financial risk. The RBA closely monitors a range of financial indicators, such as liquidity and leverage ratios, at both the aggregate level and across households, businesses and financial institutions. These traditional risk metrics are well established and can reveal clear trends in financial vulnerabilities that require mitigating action to promote financial stability. In contrast, monitoring operational vulnerabilities is considerably more challenging because there are few standardised indicators that can reliably measure operational risk from a financial stability perspective and that apply equally to a diverse range of institutions. These assessment challenges reflect the breadth, complexity and diversity of operational risks facing individual entities and interdependencies that can be difficult to identify across the financial system. Where data do exist, there are often concerns about their quality and comparability, and their relevance for financial stability can be difficult to ascertain particularly given the limited historical experience of systemic operational events. Rapid advances in novel technologies – including frontier AI models – further add to this uncertainty. One response to these challenges has been to collect better quality data. For example, APRA has started collecting data on material service providers used by regulated entities, which can help to map out the key concentration risks and interconnections in the system. Another response is to adapt the monitoring approach to the unique nature of operational risk, including through greater emphasis on forward-looking scenario analysis and operational and cyber stress tests.

The features that distinguish operational risk from financial risks necessitate additional considerations for safeguarding financial stability. These include:

  • Building resilience: When seeking to build resilience to traditional financial shocks, policymakers typically focus on ensuring that financial institutions have sufficient capital and liquidity buffers to absorb severe-but-plausible shocks. While these buffers can also help to absorb the effects of operational shocks – where they create or amplify financial stress – interactions with liquidity and capital are not the only way that operational risk can manifest in systemic disruptions. The focus of operational resilience is therefore on ensuring that critical operations can be maintained through periods of disruption and be restored within acceptable tolerances if they are interrupted. This includes maintaining redundancy, contingency arrangements, and business continuity plans that are frequently stress tested and robust to a range of scenarios.
  • Crisis response and recovery: While every crisis is different, the response to an operational disruption can differ from a crisis response that is exclusively financial in nature. Indeed, some operational disruptions could impair the very systems used to implement traditional financial sector crisis responses such as additional liquidity provision by central banks. For example, a major operational disruption at a systemically important securities settlement facility could impair the flow of collateral and liquidity through the financial system in a period of stress. Restoring a base level of critical services in a timely fashion and recovering affected systems as swiftly as possible are key priorities for market participants and infrastructure providers.8 In extreme cases, authorities or operators of infrastructure may need to temporarily suspend critical financial services or market activity while underlying operational issues are resolved (e.g. via a bank holiday).9 Such decisions can be highly complex, requiring judgements about which systems should remain operational, which should be suspended, and how services can be safely resumed. Operational disruptions can occur quickly and with little warning (e.g. technology outages affecting payment systems), underscoring the importance of well-established coordination frameworks and crisis response arrangements.
  • Coordination: Operational disruptions can often originate from outside the financial system – for example, technology failures at material service providers, cyber-attacks, geopolitical events, or severe weather. This means that a broader range of authorities may need to be involved in the vulnerability assessment, crisis response and recovery compared with traditional financial shocks emanating from firms inside the regulatory perimeter. This could present coordination challenges, especially in crisis scenarios where multiple financial and operational risks are triggered at once. Certain operational risks, particularly cyber threats, are predominantly cross-border and can quickly spread across jurisdictions. Managing these risks requires close cooperation across industry, agencies and government in Australia and internationally (see below).10
  • Communication: One of the ways the RBA contributes to financial stability is by communicating its assessment of risks to the financial system through speeches and publications such as the Financial Stability Review. As part of its supervisory and regulatory responsibilities, the RBA also publishes assessments of systemically important financial market infrastructure.11 Public communications build awareness of issues that could affect the financial system and this supports more informed decision-making by financial institutions, households, businesses and policymakers to manage these risks. However, this approach can be more challenging for certain operational risks. In some cases, disclosing detailed information about operational vulnerabilities, critical infrastructure or key points of concentration could increase the risk of disruption if that information were exploited by malicious actors, including through cyber-attacks.12 In these cases, the RBA and other regulators work directly with relevant parties to address these risks – for example, through the work the CFR is leading with industry in response to geopolitical and cyber risks (see below).13

The RBA is increasingly viewing operational risk through a financial stability lens.

Alongside the RBA’s regulatory responsibility to ensure critical FMIs are managed in a way that promotes financial stability in Australia, the RBA also assesses the resilience of the Australian financial system as a whole, taking a system-level perspective. To examine the implications of operational risks for financial stability, the RBA employs the framework described in the April 2025 Financial Stability Review.14 Within the framework, rather than focus exclusively on risks (i.e. shocks that might occur, which tend to be difficult to control or predict), emphasis is on identifying operational vulnerabilities that could lead to shocks having system-wide effects, along with any offsetting features that improve system resilience. That is, we focus on what regulators, government and industry can control. In this way, the framework supports the identification of concrete actions that can be taken to address vulnerabilities and strengthen resilience in the financial system.

Institution-level operational resilience is foundational to system resilience. Assessments at the institution level are carried out by APRA for its regulated entities, by both the RBA and the Australian Securities and Investments Commission (ASIC) in their respective supervisory roles for certain key FMIs, and by ASIC across its regulated population, including financial market operators, market participants and other entities subject to ASIC’s operational resilience oversight.15 The RBA also manages operational risk in its role as a provider of critical settlement services through the Reserve Bank Information and Transfer System (RITS).

The operational resilience of the financial system also depends on non-financial institutions in sectors such as telecommunications and energy. In Australia, the Department of Home Affairs (DHA) is responsible for critical infrastructure policy. The DHA administers the Security of Critical Infrastructure Act 2018 (SOCI Act) framework, which establishes security and resilience obligations for entities that own or operate designated critical infrastructure assets, including in sectors that underpin the functioning of the financial system. The April 2025 power outages across the Iberian Peninsula in Spain provided a reminder of how the failure of critical infrastructure can affect an economy and the importance of resilient financial infrastructure. The outage caused economic activity to decline by almost half its daily level and the disruption would have been worse had the functioning of key financial infrastructure also been compromised.16

System-level vulnerabilities can amplify and propagate the effects of operational disruptions …

System-level operational vulnerabilities are characteristics of the financial system that can amplify the effects of operational incidents and cause stress to become more widespread. The two most important are (i) concentration and lack of substitutability and (ii) complex and opaque interconnections.17

Concentration and lack of substitutability

The reliance on a small number of providers of a given critical service across the financial system means that multiple entities can be affected at the same time by a disruption. This can include a shared reliance on critical service providers from outside the finance sector (e.g. cloud computing), national infrastructure (e.g. electricity and communications), or FMIs (such as payments, clearing and settlement systems) underpinning the operation of the financial system. Concentration risks are larger where entities are unable to, or have difficulty in being able to, switch to an alternative provider. For example, many key IT services such as cloud computing and storage are provided by a small number of providers, and while their scale and market-leading capabilities can help to bolster their IT security, it also contributes to a lack of substitutability and has the potential to connect financial institutions to a common vulnerability.18 Some of the largest regulated entities in Australia have around 150 service providers supporting critical operations, with many providers used by multiple entities, if not the whole industry. Many of these are located overseas and outside of the Australian regulatory perimeter.19 As noted above, APRA now requires entities to report their dependencies on service providers, which will enable a better understanding of where reliance on particular service providers is concentrated, to support better management of systemic risks. APRA’s operational risk management standard (CPS 230), which commenced on 1 July 2025, also requires entities to manage their own risks associated with the use of service providers.

A prolonged outage at a critical FMI could severely impact the broader financial system. While the safe and efficient operation of FMIs contributes to financial stability and economic growth, they also concentrate risk (including due to the limited substitutability of their services). This exposes the flow of payments to risks from single points of failure. A prolonged outage at an FMI could disrupt the movement of collateral and liquidity and undermine confidence in the ability of institutions to transact in financial markets (discussed below). Reflecting the systemic importance of these entities, the RBA and ASIC place a strong emphasis on ensuring that FMIs manage operational and financial risks effectively while continuing to provide services that are safe, efficient and transparent.20

Complex and opaque interconnections

Growing operational interconnectedness and complexity across the financial system is also increasing system-wide operational vulnerabilities. The links between financial institutions, FMIs and material service providers could rapidly transmit the impact of an operational incident from one institution to another. For example, this could occur if the inability of disrupted institutions to send payments creates settlement issues for their counterparties. During cyber-attacks, operational contagion can also spread through IT and network connections across entities. In such a scenario, institutions may choose to disconnect themselves from affected entities to protect their own systems from the cyber-attack, or pause operations to prevent problems from escalating, which in turn can create operational disruptions elsewhere in the system. These operational interconnections can arise from counterparty relationships, outsourcing and third-party relationships and can be difficult to monitor given the complexity of the financial system.

… and create financial stress.

Operational incidents can generate liquidity stress in the financial system by disrupting the flow of payments between financial institutions. Banks rely on incoming payments to fund outgoing obligations, meaning that a disruption at one institution can create liquidity stress for others. For example, consider a stylised example of a cyber-attack that causes an operational outage at a common material service provider, as shown in Figure 4.1.1. Multiple institutions use this provider for critical services (‘concentration’), with the outage preventing those institutions from making payments. In turn, this creates liquidity pressure at firms who were expecting to receive those payments to meet their own payment obligations.21 In severe cases, liquidity shortfalls could lead to fire sale dynamics in asset markets, thereby transmitting stress more broadly in the financial system.

Figure 4.1.1: Example of Operational Incident that Creates Financial Stress
Outage at material service provider to the banking system that prevents affected firms from sending payments

A broader loss of confidence could cause market participants to retreat from transacting in financial markets and reduce their counterparty exposures to entities perceived to have similar vulnerabilities to the most affected institutions, thus spreading the impact through the system. Precautionary behaviour of this sort could substantially tighten financial conditions. Certain types of operational incidents, such as cyber-attacks, could also erode confidence in the stability of key infrastructure or access to funds. Confidence is likely to erode more the longer a disruption lasts.

APRA’s inaugural System Risk Stress Test illustrated how operational incidents can temporarily impair financial resilience and amplify financial stress.

Over a number of years, CFR agencies have worked to understand the implications of multiple forms of stress occurring at the same time. APRA’s inaugural System Risk Stress Test examined the financial resilience of the largest banks and superannuation funds to an extreme-but-plausible liquidity shock.22 The test also considered how resilience changed when a severe operational incident occurred at the same time. The operational incident was a short-lived outage of a material service provider that temporarily prevented settlement of debt securities transactions. This incident would have implications for liquidity conditions in financial markets because debt securities, specifically bonds issued by the Australian and state and territory governments, account for a large share of banks’ high-quality liquid assets (HQLA). Figure 4.1.2 shows a stylised example of key aspects of the scenario, while also incorporating other possible sources of contagion, such as fire sales and confidence loss, that may be present in some situations.

Figure 4.1.2: Example of Operational Incident that Amplifies Existing Financial Stress
Liquidity shock combined with outage at material service provider that prevents banks from monetising liquid assets

Traditional sources of financial resilience may be less effective, or unavailable, during an operational disruption. In the absence of the operational outage, participating banks in the stress test responded to the liquidity shock by drawing down their cash balances and converting other liquid assets into cash by selling them or by accessing liquidity offered by the RBA.23 That is, banks’ liquid assets acted as a buffer against the unanticipated liquidity shock. However, this response was impaired by the operational outage; banks could draw on their existing ES balance but could not monetise a large share of their other liquid assets during the outage. This included access to liquidity offered by the RBA through open market operations, reflecting that these facilities require the settlement of the securities that are used as eligible collateral. This meant banks relied more heavily on their existing cash balances to make payments, with ES balances run down faster than otherwise.

Financial stress can be most acute if operational shocks occur when the system is already under strain. APRA noted that the liquidity stress would likely have been more severe if the outage had occurred later in the stress test period after liquidity buffers had already been eroded. In this case, or with a more prolonged outage, banks may have been forced to liquidate other investments quickly, which can transmit stress more broadly in the financial system and further amplify liquidity stress. Such a scenario is relevant given the heightened risk of cyber-attacks that are timed opportunistically to create maximum disruption, as was seen during the financial market volatility in April 2025.

Initiatives to enhance operational resilience in Australia.

In recognition of the growing threat from operational risks, strengthening operational resilience has become a key focus for financial institutions, FMIs and CFR agencies in recent years.

Banks and other financial institutions have elevated operational risks – including cyber and geopolitical threats – as a strategic risk and devoted resources accordingly (Graph 4.1.1). This includes investment in defensive AI capabilities, the establishment of specialist geopolitical risk teams, and the development of contingency plans for geopolitical scenarios such as sustained electrical grid outages.24

Investments in resilience by individual institutions have also been supported by APRA and ASIC’s regulatory initiatives. Ensuring the resilience of individual APRA-regulated entities to operational risk and disruptions is the focus of APRA’s standard, CPS 230. Key aspects of this standard include increasing requirements to maintain and test internal controls, with a focus on good governance; improving business continuity planning; and enhancing institutions’ oversight of external service providers. Both APRA and ASIC recently issued public letters outlining their expectations of regulated entities regarding frontier AI preparedness and collaborated on a series of industry roundtables to better understand how entities are responding to these risks.25

Enhancing the operational resilience of the payments system has been a key focus for the RBA and other CFR agencies, reflecting the system’s critical role in supporting financial stability. This includes the following initiatives and activities:

  • The RBA and APRA oversee the Industry Resilience Initiative, which aims to ensure the continuity of payments services if a major institution experiences a prolonged outage.
  • The RBA, government agencies and members of the payments industry are collaborating to address recommendations relating to incident coordination identified from the 2024 tabletop cyber-attack simulation exercise. This includes developing a Payments Crisis Coordination Framework (PCC Framework), which outlines the roles and responsibilities of key industry and government stakeholders in coordinating a response to a cyber security crisis affecting the Australian payments sector. The PCC framework will be published on the CFR website later this month.
  • The RBA is undertaking work to strengthen the resilience of the critical payments systems it runs, including through investments in cyber resilience and the modernisation of core technology infrastructure.26
  • A strategic focus of the Payments System Board is strengthening payments system resilience. Consistent with this, the RBA has a program of work aimed at identifying system-wide vulnerabilities in the payments system and assessing ways to improve resilience, including to future threats such as those posed by quantum computing.27 APRA is also increasing its focus on quantum computing.28
  • The RBA is working with the DHA to promote the increased resilience, against all hazards, of assets that are used in connection with the operation of critical payment system assets, under the SOCI Act. An independent review of the Act was delivered in January 2026, with all six recommendations accepted in principle and reforms now being progressed through a two-tranche implementation program.29

CFR agencies also have a large program of inter-agency work to enhance the operational resilience of the financial system more broadly, including by strengthening crisis preparedness and response capabilities. This includes the following initiatives:

  • The RBA is leading the CFR’s Cyber Operational Resilience Intelligence-led Exercises (CORIE) program.30 CORIE assists in raising cyber resilience testing capabilities and highlighting cyber resilience strengths and weaknesses across systemically important financial institutions and market infrastructures. The program has increased its resources to provide a more comprehensive view of the cyber threat landscape to participants and to test a larger number of entities each year.
  • The RBA and other CFR agencies are participating in a wide range of crisis response exercises, including government scenario exercises designed to strengthen cross-agency, government and industry coordination and enhance industry resilience to large-scale cyber-attacks and operational outages.
  • CFR agencies are conducting work to understand the landscape of material service providers to the financial system.

Operational resilience must remain a focus for financial institutions and FMIs.

In an environment of rapid technological change, heightened geopolitical risk and growing concentration and connectedness, strengthening operational resilience will require ongoing action across the financial system. Preparedness varies across sectors. Financial institutions, FMIs and other critical service providers must continue to strengthen prevention, contingency and recovery arrangements, and test their ability to maintain or rapidly restore critical services under severe scenarios.

Endnotes

1 Frontier AI models also offer opportunities to improve cyber defence capabilities. However, the need for entities to patch software vulnerabilities more quickly and more often can itself be a source of operational risk in the form of errors, outages and disruption across interconnected systems. See Chapter 3 in Bank of England (2026), Financial Stability Report, July. APRA and ASIC have noted that defensive AI is promising but still developing. See APRA and ASIC (2026), ‘Insights from the APRA-ASIC Industry Roundtables’, Information Paper, 27 August.

2 For an assessment of the threat posed by state-sponsored cyber actors, see Australian Signals Directorate (2025), ‘Annual Cyber Threat Report 2024–25’, October. Lwin and Holland describe the RBA’s framework for assessing how geopolitical risk could affect financial stability. See Lwin J and G Holland (2026), ‘Geopolitical Risk and Financial Stability’, RBA Bulletin, June. See also Jones B (2026), ‘Geopolitics and the Financial System: Some Echoes from History’, Australian Banking Association’s Conference – Banking 2026, Melbourne, 17 June.

3 This Focus Topic considers cyber risks as a key source of operational risk rather than as a distinct risk category. Geopolitical risk is also a key source of operational risk, though there are a wide range of potential geopolitical events and scenarios, with the importance of operational risk vis-à-vis other risks depending on the scenario. This may differ to how respondents considered these risks in APRA’s survey results shown in Graph 4.1.1. Beyond cyber, geopolitical and climate risks, operational risks can also stem from sources such as implementation errors during technology transformation, fraud, and human error. For more details, see APRA (2025), ‘APRA 2025 Stakeholder Survey Report’, June.

4 Material service providers are those on which an entity relies on to provide critical services – for example, third parties providing electricity or critical cloud computing services, or FMIs such as individual payments systems and securities settlement facilities. It is also important to consider the fourth and fifth parties that the material service provider relies on in providing their services.

5 This definition is from Adeney R, A Hitchins, C Lane, H Mehta and A Quashie (2024), ‘Operational Resilience in a Macroprudential Framework’, BoE Financial Stability Paper No 50.

6 See Lwin and Holland, n 2; and Jones, n 2.

7 The crystallisation of financial risks at smaller institutions can also pose challenges to financial stability. For example, a deposit run on a small bank may trigger runs at other banks perceived to have similar characteristics, leading to broader contagion and a loss of confidence across part of the banking system.

8 For catastrophic incidents, the DHA provides guidance on what critical services should be prioritised for recovery.

9 During the 1893 banking crisis in the Australian colonies, the Victorian government implemented a five-day bank holiday.

10 This includes through participation in international groups and forums such as the Bank for International Settlements (BIS), the Financial Stability Board’s assessments of vulnerabilities and the Trans-Tasman Council on Banking Supervision’s work on strengthening crisis preparedness arrangements.

11 RBA (2026), ‘Payments and Market Infrastructure Assessments’, March.

12 In some cases, public disclosure of vulnerabilities of critical infrastructure may not be permitted based on national security grounds.

13 CFR (2025), ‘CFR Initiatives on Systemic Risks and Vulnerabilities’, December.

14 RBA (2025), ‘4.1 Focus Topic: A Conceptual Framework for Assessing Financial Stability’, April.

15 The RBA oversees RITS, including the Fast Settlement Service that settles payments in the New Payments Platform, and periodically assesses RITS against the Principles for Financial Market Infrastructures. The RBA contributes to the oversight of key international FMIs and messaging networks that are critical to the Australian financial system, including through cooperative oversight arrangements for entities such as Continuous Linked Settlement (CLS) and the Society for Worldwide Interbank Financial Telecommunication (SWIFT).

16 See Jones B (2025), ‘Anti-fragility and the Financial System’, Opening Remarks to FINSIA: The Regulators, Sydney, 12 September.

17 As discussed in Adeney et al, n 5, there are other system-level vulnerabilities relevant to operational risk. For example, if common AI models are used across financial institutions, the correlated model outputs could increase the likelihood of herding behaviour that amplifies the effects of operational and financial shocks.

18 See Douglas O, E Kandelas, and E Orum (2024), ‘Migration to Public Cloud: Risks and Regulatory Requirements for Clearing and Settlement Facilities’, April.

19 APRA (2025), ‘System Risk Outlook’, November.

20 In recognition of the important role that FMIs play, international standards have been developed for managing risks and ensuring efficiency and transparency at systemically important FMIs. See BIS Committee on Payments and Market Infrastructures and the International Organization of Securities Commissions (2012), ‘Principles for Financial Market Infrastructures’, April. ASIC and the RBA are responsible for implementing the standards in Australia.

21 It is assumed that other institutions do not rely on the provider or have sufficient operational resilience to maintain, or quickly recover, their critical services (e.g. by substituting to an alternative service provider).

22 See APRA (2026), ‘System Risk Stress Test’, Final Report, June.

23 This discussion focuses on banks rather than superannuation funds given these funds were only modestly affected by the outage at the common material service provider, largely reflecting its timing early in the scenario and their limited reliance on the segment as a primary source of liquidity.

24 See Jones, n 2.

25 APRA (2026), ‘APRA Letter to Industry on Artificial Intelligence (AI)’, 30 April; ASIC (2026), ‘ASIC Calls for Urgent Cyber Uplift as AI Accelerates Cyber Threats’, Media Release, 8 May; and APRA and ASIC, n 1.

26 This includes ongoing modernisation of RITS and implementing recommendations from the Deloitte report assessing the operating environment supporting it. See RBA (2023), ‘Strengthening the RBA’s Payments Infrastructure’, Media Release No 2023-23, 30 May; and RBA (2025), ‘Corporate Plan 2026/27’, August.

27 RBA (2026), ‘Payments System Board Annual Report’, September.

28 APRA (2026), ‘APRA Corporate Plan 2026-27 – Our Strategic Objectives’, August.

29 The overarching aim of the recommendations is to reduce complexity and confusion, simplify operation of the SOCI Act, and make the framework more agile and responsive to emerging threats. Tranche 1 of reforms addresses immediate risk and intervention settings. Tranche 2 improves the underlying architecture so the Act is clearer, more targeted, easier to operate and better able to support assurance of practical security and resilience outcomes.

30 See CFR (2022), ‘Cyber Operational Resilience Intelligence-led Exercises (CORIE) Framework’, July.