Transcript of Speech and Question & Answer Session Panel Participation by Brad Jones, Assistant Governor (Financial System), at the Regulators 2023 (FINSIA) – Sydney
Brad Jones
I will begin by highlighting our priorities in the payments system, and briefly touch on some of the key focus areas for our financial stability work program.
Payments System Priorities
The Reserve Bank has a mandate to promote the safety, efficiency and competitiveness of Australias payments system. With our ASIC colleagues, the Bank also supervises clearing and settlement facilities, consistent with the mandate to promote the stability of the financial system.
As the Payments System Board, which sets the Banks payments policy agenda, recently updated its strategic priorities for the coming years, let me speak to some related priorities.[1]
First is to strengthen the resilience of Australias payments and market infrastructures. Some critical systems are relying on aging infrastructure. Its crucial that the associated risks and upgrades are managed carefully. Partly in response, industry are increasingly turning towards the services of third party providers, including cloud services. This can enhance resilience and security, but concentration risk among these providers is a concern. Cyber security is also a significant challenge, reflecting an increase in the scale and sophistication of attacks. And as businesses and consumers are more reliant on electronic payment systems than ever before, the Bank is developing a framework for supervising these systems, such as the NPP and the card schemes, to ensure they are managing risk appropriately.
A second set of priorities relates to key reforms for payments and market infrastructures. It is crucial that regulators have the powers to address risks in the payments system now and in the future, and the Bank strongly supports the governments reforms to modernise the regulatory frameworks for payments and market infrastructures. There are a few elements to highlight here. The draft legislation to modernise the Payment Systems (Regulation) Act 1998 (PSRA) is a key piece of reform. Definitions of payment system and participant need to be sufficiently broad so the Bank has the powers it needs to discharge its mandate. Separately, the Bank is supporting Treasury in its work to introduce a tiered licensing regime for payments service providers (PSPs). This should help to address regulatory uncertainties and barriers faced by many PSPs, and promote greater access to Australias payments system. The Bank also strongly supports reforms to the regulation of financial market infrastructures. This will introduce a crisis management regime for clearing and settlement facilities and strengthen the supervisory powers of the RBA and ASIC.
A third initiative is to promote competitive, cost effective and accessible electronic payments. A key focus over recent years has been reducing payment costs for small businesses. The Bank has been encouraging PSPs to help merchants lower the cost of accepting debit cards through least-cost routing. We are also monitoring the rapid adoption of digital wallets. Once the new PSRA is in place, the Bank will undertake a comprehensive public review of retail payments regulation to determine where to focus future regulatory action. Separately, the Bank has been encouraging the delivery of additional fast payment capabilities to consumers and businesses through the New Payments Platform (NPP). To prepare for the transition away from the legacy Direct Entry system, the Bank is encouraging industry to ensure all relevant accounts are connected to the NPP and to provide enhanced functionality for payments.
A fourth priority is to improve cross-border payments. The user experience for cross-border payments falls well short of that for domestic payments. An ongoing priority for the Bank is to contribute to the international effort to make cross-border payments cheaper, faster, more transparent and more inclusive under the G20 cross-border payments roadmap. The Bank is also encouraging the adoption of new functionality and messaging capabilities for cross-border payments, and conducting a study with Australian industry participants to explore the issues in linking the NPP with international fast payments systems.
A final priority is to shape the future of money in Australia. As part of this effort, we are exploring the case for new digital forms of money. Building on a pilot project that examined a wide range of use cases for a central bank digital currency (CBDC) earlier this year, we are now in the early stages of planning a project that will explore how different forms of digital money and infrastructure could support the development of tokenised asset markets in Australia. We will also publish a paper with Treasury around mid-2024 that will take stock of the research work to date and outline a forward workplan on CBDC. Alongside these efforts, the Bank is working with Treasury on options for maintaining adequate access to cash in Australia.
Financial Stability Priorities
The Bank has long promoted stability in the wider financial system. We manage system-wide liquidity, work closely with the Council of Financial Regulators, participate in a range of international fora on financial stability issues and produce a significant volume of related analysis. Our central position in the financial system means we also have a key role in financial crisis management, and we constantly examine ways to improve our arrangements.
Our research priorities comprise both conjunctural and longer-range issues. As set out in our recent Financial Stability Review, our conjunctural domestic focus is very much on the ability of borrowers to withstand ongoing pressures on their finances and the related implications for lenders. Internationally, we are closely tracking developments in the Chinese financial system and the risks around interest rates staying higher-for-longer, including for commercial real estate markets.[2] Over-and-above these conjunctural issues, we are also mindful of emerging threats to international and domestic financial stability that are likely to be with us over the longer-term. I addressed these issues in a recent speech and so wont go into detail here, other than to mention these challenges have a different complexion to those of recent decades and include rapid-fire bank deposit runs, contagion risk, higher interest rate volatility, geopolitics, operational risk and climate change.[3] This is a rather daunting list of challenges for both regulators and industry, which means that in the years ahead, we will need to constantly challenge ourselves on what resilience needs to look like.
Endnotes
See Reserve Bank of Australia (2023), Payments System Board Annual Report, October. [1]
Reserve Bank of Australia (2023), Financial Stability Review, October. [2]
B Jones (2023), Emerging Threats to Financial Stability - New Challenges for the Next Decade , Speech at the AFIA Conference, Sydney, October 31. [3]
Question & Answer Session
Christine Yates, Moderator
Lets turn to some questions and really have a conversation with our regulators. I might kick off with John and Mark. We hear about APRA and ASIC working very closely together with the banking sector at the moment, in regard to the implementation of FAR by March 24, so thats coming very quickly, and also, ultimately, then the superannuation industry and the insurance industry by March 2025. So how can professionals working in financial services, really, our audience here, best prepare for this transition and engage with regulators to prepare for this new regime? So, its just, really, about any pragmatic guidance.
John Lonsdale, APRA
Well, Im happy to go first. So, the financial accountability regime, a very important piece of legislation, was passed by the parliament. It extends the BEAR, if you like, in a couple of ways. So, it moves from prudential to prudential and conduct, and it also moves from banking to banking, insurance and super. So, theyre kind of the two kind of elements to it. We see it as a really important way to improve accountability, improve risk culture, improve governance, really, in our regulated entities and, if we can achieve that, we think well get better community outcomes, so we do think its really important. Weve put out, together with ASIC, some information very recently around probably a couple of aspects: the joint agency agreement between APRA and ASIC, how were going to work together. And that is a really unique function, a really unique thing about this piece of legislation, in the fact youve got a piece of law administered by two regulators. So weve put out a short document explaining: well, how is that actually going to work? And weve put out another document around: well, if youre a bank, how are you actually going to transition from a BEAR to a FAR? And that has to happen by March next year. So theyre the two things. Weve done some webinars. Hundreds of people came to the webinars. If you missed it, its all on our website, so Id encourage you to have a look. Well put out some more detailed material probably in a few weeks, really, particularly around the templates and what we expect. But broadly, if youre sitting in a regulated entity, start thinking about the accountability, start thinking about the mapping I think is what Id say to you. And the final thing Ill mention is that we are giving a lot of thought to regulatory burden. When we look at the FAR, we really want it to feel, if youre in a regulated entity, that youre not dealing with two regulators, youre dealing with one regulator. And theres a couple of things Id highlight. One is that, when youre putting in your information, youre going to put it in through the APRA Connect Portal, so youre not going to two agencies; youre going to one, and then well distribute that to ASIC. And, as were thinking about supervisory or enforcement actions, well do that collaboratively. So theres a lot happening in this space. Id encourage you: if you want more information, go to our websites; its there. And youll be hearing more from us on that.
Christine Yates, Moderator
Thank you, John. If theres anything more –
Mark Adams, ASIC
Ive got very little to add to what John says. Just engage with that content thats coming and know that were working closely. Theres more content to come. Theres the ministers rules too, I think. They all collectively set the scene, and I think thats the rub of it. Just engage with that and know that were open to being engaged with.
Christine Yates, Moderator
Thank you. Brad, Ill turn to you. We might talk a little bit more about payments, if we have a little bit of time. But I might pull you back to a different topic and we cant ignore the geopolitical tensions, which are extraordinary, across the globe: Ukraine last year, of course, whats happening in the Middle East, and on it goes. How does this increasing geopolitical tension impact how you think about the regulatory focus, the priorities?
Brad Jones
Well, first of all, I agree with the proposition of your question, which is basically connecting, I think, to this idea that, more or less since the Second World War, economic policymakers and industry havent really had to think hard, deeply, about some of these issues because there was never any real, genuine prospect of economically integrated countries, and whether there are going to be potentially significant issues. That sort of a mindset clearly needs to shift. I dont think it would be helpful for me to be too prescriptive about what individual institutions do here because theyre each got their own obligations to manage risk, broadly speaking, in a prudent and comprehensive way. Maybe what I could say is, at least the way that I think about this is that theres kind of two dimensions here that we need to unpack, two layers. One is the risk of sort of slow-burn fragmentation in the global economy and the global financial system, and Id go so far as to submit its actually not a risk but its actually happening now. And I gave a speech about this earlier this week, where I sort of went through the different dimensions to this fragmentation. But the bottom line is its happening, its real and its playing out along various dimensions in the global financial system, in the global economy, and its making the system more susceptible to shocks. Thats the first point. The second point is that theres another dimension, which is the risk of fast-burn kinetic – some sort of fast-burn kinetic event, and that is a totally different sort of set of implications. But what both of those elements, I think, speak to, the slow-burn fragmentation risk and the fast-burn kinetic risk – they connect to this concept of resilience and preparedness, and we really need to be thinking very, very hard as a community about what that looks like.
Christine Yates, Moderator
Yes. Thank you, thank you. Peter, we started talking earlier, of course, about the importance of fighting financial crime and our industrys obligation to fight with you in that regard. What are you seeing taking place in the financial markets as our understanding matures; are you seeing this swell of improvement?
Peter Soros, AUSTRAC
Its a great question. I think its fair to say that we have really had an evolution. In the last five or six years, I think its fair to say that AUSTRAC has been more forward-leaning and more visible in the marketplace, and I think industry has really responded, so, —not all sectors; it has been a bit hit and miss. But I think, in general terms, industry is really responding and taking it a lot more seriously; we are absolutely seeing that. But even that response is coming in waves. I think, initially, industry quite rightly said, Okay, lets all have a look; are we doing this well? Okay, we need to invest more, and so we did see quite a significant spike in reporting that was coming into AUSTRAC, which is always welcome. What were now seeing I think is, after that initial period, an increase in the level of sophistication and maturity in the type of detection systems. So that is now helping us further improve again, industry again. So, were not just getting report of everything that might be something suspicious but a much more mature and developed understanding of the types of risk, and thats being done in partnership with AUSTRAC and based on the benefit of that additional guidance and material. So, I think we are on that journey. I think there are some sectors that have been faster than others, and so thats why our enforcement work is still really important. So, we need to make sure that there is a strong deterrence effect for those sectors that are slower to adapt, and so we remain committed to that. But we have seen that uptick, absolutely.
Christine Yates, Moderator
Yes. Thank you; thats good. So, Mark, on that theme of movement in the industry, if we think back to the design and distribution obligations, DDO, which is now two years in, what impacts are you seeing following the introduction of these obligations; are you seeing what you were needing to see across the industry?
Mark Adams, ASIC
Thank you. So, the DDO, from our perspective, is really an important addition to the mix of things in the framework which promote better consumer investor outcomes, so its at that supply side. So, its not just about disclosure; its about issuers and distributors thinking about the cohorts which this product is most apt to and its goal of promoting that ambition that people are getting the fit-for-purpose sort of product more likely than not. So, it is two years in and early days, so the short story is, I think, businesses have reflected on that and changed things. And theres been a bit of nudging on that. I mentioned earlier theres been 80 target market distribution stop orders that ASIC issued, so there is still thinking being done about getting that prism right. So thats at this stage. I probably just want to add one thing, and that is the obligation includes in it the monitoring function, the review and monitoring, as well as an obligation to change your distribution approach, if necessary. So, I think thats an area that ASIC will be turning its attention to, alongside the actual issuance side, so that the mix of the obligation does its role in promoting that outcome of the products being distributed more likely to the right cohorts.
Christine Yates, Moderator
Thank you, thank you. And, John, as we think about all this monitoring and how technology helps us do so many things these days. Ill turn to you, John; that sort of brings us to outsourcing, because so many organisations dont have the capability in-house and we have to outsource to third- and even fourth-party contractors rather than building inhouse systems. So what practical steps can boards or execs take to ensure that these business activities are being appropriately managed?
John Lonsdale, APRA
So, we know that outsourcing is a very important part of regulated-out business. I mean, it delivers technology, it gives innovation, and it gives services that maybe the business cant provide, so all of thats good. But what we say to regulated entities is: whether youre providing the service housing it inhouse or going out, you need to make sure that youve got the appropriate risk measures around it. So, I think thats the key issue. Weve put out CPS 230, its a big standard, and well put out some guidance early next year, I think, on that as well. Really, what that is about is saying, Know your third-party, fourth-party, fifth-party providers. So really understand who they are, because were not regulating them; youre involved with them. Know who they are, make sure there are robust controls in place and know what your critical operations are as well. And so, when I think about what we want people to do, our standard doesnt come into play for another 18 months, but we dont want to be in the world where it sort of comes into play and were not ready. So were asking regulated entities to really have a think now, and so its almost map the third-, fourth-, fifth-order parties, the material ones, and understand where they link into the critical functions as well: like, what makes them important. And the third thing Id say is that, really, for some entities, this is going to involve a bit of system change, youve got to go through that; but, for other organisations, it will involve a much deeper cultural change for the organisation, so be aware of that. And, if youre certainly in the latter camp, my message would be: Start talking about it; start talking about the importance of it and, really, what were trying to do, because, if we can nail this, I think it will really be an important sort of plank in the safety of the system and for entities.
Christine Yates, Moderator
Yes. Thank you; thats good. And then, Brad, well pick up on this theme of innovation. Theres so much happening in the payments system, so what are the key risks that you intend to mitigate or address – you cant mitigate all of them, but address – through regulation?
Brad Jones
Look, operational risk is becoming a huge issue, obviously, right across the financial sector and parts of the payments ecosystem are obviously right at the pointy end of that. So, what were really focused on is making sure that entities are leaning into some of the vulnerabilities that are really the flipside of the opportunity coin. Then payments: theres so much innovation going on in this space and, as a country, I think we really need to harvest all the benefits we can from whats happening on the innovation side but, at the same time, its obvious that there are some key points of vulnerability. The point that John made about third parties is one that looms very large for us. For the institutions that we regulate, its not enough to say, Well, these are third-party risks, and sort of assume that theyre not responsible. You are responsible for third-party risks, or the risks introduced through you turning to third-party vendors which can be an entirely sensible commercial decision, but it doesnt absolve you from your responsibilities to manage those risks appropriately. And cyber is sort of right at the pointy end of that issue because there is, I think, an ongoing concern – and we talk about this frequently as a sort of regulatory community – about where are the key points of vulnerability to cyberattacks and through third-party vendors. Its an issue that just keeps on cropping up in our conversations. Thats a particular area of focus.
Christine Yates, Moderator
Yes, a good pragmatic callout, so thank you, thank you. And, Peter, well look at just RegTech. So RegTech, again on this theme, can play a really critical role in how we really assist organisations meet their AML/CDF obligations. As you – well, for AUSTRAC, do you work with the RegTech sector, engage with them, provide that pragmatic guidance to help them get to the place that we need everyone to be?
Peter Soros, AUSTRAC
Look, theres no doubt that RegTech absolutely has a role to play in this space, and we are actively engaged with the RegTech community. We hosted an event with the RegTech community this week, where we encouraged the collaboration and the work to get it to operate. It is going to absolutely be a fundamental part of it. But just like John and Brad have talked about, you are ultimately responsible as the business. And so, over and above what John and Brad have talked about, I think we just emphasise this very similar message potentially in a slightly different way. When youre engaging with the regulatory technology or other outsourcing means, test, validate, assure yourselves that what youre using is good and robust; because it may be cost effective, it may have a skillset that you dont have but, if youre not regularly testing and validating and assuring that its doing what you want it to, and whether thats your internal assurance or getting someone in to come and have a look—we are strongly encouraging that as part of that innovation and testing mindset. Were all for it, very supportive of it, but just keep testing.
Christine Yates, Moderator
Yes. Thank you, thank you. I might just turn now to some general questions for everyone. Im just going to do a time check. Are we doing okay? Okay. So maybe Id like you all just to touch on, if you dont mind; well start at the end of the couch, how important is interagency cooperation within Australia and globally?
Mark Adams, ASIC
Its essential. Im sure all my colleagues will say the same. Let me just give a few examples. Theres the informality. I dont want to underestimate the informality, and I think thats richer and deeper than its ever been. And thats everything about what were seeing, how were doing things, where were learning, where were growing. Its all those factors. Then theres the formality. And you and this audience need to know, when theres supervisory work going on, that were in dialogue to make that work as best and in a coherent and aligned fashion as much as possible with the sector. Then, if I just switch it to internationally, thats really crucial as well – and many of us are represented on international standard-setting bodies – because those international standard-setting bodies arent just academic; they produce good guidance and content and practices, which are influential in influencing the way that our businesses should operate and also informing policy frameworks within this jurisdiction. So theyre just three examples where I think the interconnection is just essential, yes.
Christine Yates, Moderator
Yes, thank you.
Peter Soros, AUSTRAC
Id add to that. Whether its operational engagement at the most junior levels of the organisation, were now picking up the phone or going to meetings together more than ever before or whether its at the end point, where were undertaking an enforcement outcome. Weve done really collaborative enforcement work with ASIC in the casino sector, weve done some great joint enforcement work with APRA in the banking sector, and youll see more of that. None of us have the resources on our own that wed all love, wed always love more, but the more that we can collaborate and share, the better it is.
Christine Yates, Moderator
Thank you. John?
John Lonsdale, APRA
So, like, we cant do our job without collaborating, and thats the frank answer. I mean, the financial system is global; right? So its all interconnected. We cant just be in our own bubble and do our own work; weve got to be cognisant of what others are doing and collaborate together. So, again, just to give you a feel, globally, we adhere to international standards. Weve got to, as a mid-size economy. Its important for the stability of the system. So we do that on banking, Basel; we do that on insurance; we do that on pensions. Were involved in all of those international committees. I talk regularly with heads of prudential regulators – I spoke this week with two heads of prudential regulators offshore to understand what their priorities are and what theyre doing – and that actually helps us inform what is happening here: does that ring true? Weve got supervisory colleges, so a number of our entities actually are operating globally as well, so we share information on that with the New Zealanders, so the Trans-Tasman Banking Council; Im off there next month. So theres a lot of global kind of work happening. And then, domestically, weve got MOUs with everybody here and very close working relationships. And the one that I would pluck out, I think, that is unique globally is the Council of Financial Regulators. It does not have powers itself, but it is a collaborative organisation of independent regulators and, when there are problems in the financial system – you saw it in March; youve seen it in the pandemic; you saw it in the GFC – I mean, that body and the way it works really comes to the fore for pinch point issues but also some of the longer term issues that weve got to address. So, its just critically important.
Christine Yates, Moderator
Fantastic; thank you. Another comment?
Brad Jones
Ill just add two quick points. The first is: Im sure youve all heard the expression about never waste a crisis. Weve had two big ones in the last 15 years and, if theres any good thats come out of those periods: the Global Financial Crisis and the pandemic, its that it forged a degree of cooperation and collaboration domestically and internationally that maybe wouldnt have happened in the absence of those events. And the second point Id make is commonality. The commonality of issues that we confront, the agencies represented on this stage, but also internationally, is just really striking. Were all dealing with, effectively, the same issues. They just play out slightly different in our patches. And so, yeah, its just become really existential that were speaking to one another on that basis.
Christine Yates, Moderator
Yes, very good. And, again, thank you for sharing because I think its a wonderful insight and should give everyone confidence on how Australia is being regulated. But thank you.
Question
Hi, Im from Rhizome Advisory. Ive got a question regarding AI and the expectation of regulation coming down the pipeline; what are your views on that?
John Lonsdale, APRA
AI is incredibly important as a productivity enhancer: better services to the community ultimately. But what we say to all our regulated entities, whether its AI or any other form of technology, is that you need to be prudent. You need to wrap risk management around it and you need to think through: what are the risks and what are the controls we need to have? And that needs to be carefully monitored, and boards need to be very aware, and senior management, of whats happening. So thats what Id say.
Question
Thats sort of gazumped my question. Im from Bendigo Bank, Adelaide. I had an AI question too and I was going to ask that one, but the second one is: how are the regulators thinking about AI about how it will help you do your job?
Peter Soros, AUSTRAC
Look, we are actively thinking about a bunch of use cases ourselves and starting to play in that space, as I said, both on the intelligence front and as part of our regulatory role. Im very conscious, though, that were not alone. We operate in a big government ecosystem, and so were looking at leveraging some of our bigger partners who are engaging with that. But I think its fair to say that there are not only opportunities and benefits for you but also for us, and so we are engaging with that and thinking of use cases and seeing how it fits our remit. But were doing the exact same things that we ask you to do; that is really test, assure, understand your risks and think about the consequences of getting it wrong.
Christine Yates, Moderator
Thank you.
Mark Adams, ASIC
And I would just double down on that and say absolutely right. Theres just a couple of things Id probably just mention. There is a whole-of-government activity looking at best practices, led by the Digital Transformation Authority, and I think were all probably intertwined with that, so that will assist us in that. And that point that Peter made: we need to be exemplar in the application of these advanced analytics in our work.
Question
Im a digital banking and industry academic. I notice the capability for the takedown of scam websites, which I thought was a really interesting kind of innovation. Are we likely to see more of this come from government; and how can industry help with those kinds of initiatives?
Mark Adams, ASIC
Well, I can touch on that briefly. I mean, Im not front and centre on this activity, but I think we made an announcement yesterday with the Assistant Treasurer. So one of, I think, the significant efforts around responding to scams is what can be done to mitigate that through exercises to take down and engage in that. So it is an important plank of the activity, and I think there is funding support for that over the near term. So well have to keep seeing the strength of that contribution. There is the national scam centre, led by the ACCC, so there are bridges there for industry to engage with around the discussion around scams. So Id want to just emphasise that there are avenues for industry to engage with that dialogue because its touching everybody. And that takedown example is an example of something: I think that fusion shell I mentioned. So there is the first sort of investment scam taskforce thats been established with a short horizon, and thats an example of what potentially could be other examples to support dealing with investment-scam-like activities, and thats going to be really interesting to see what comes out on that.
Peter Soros, AUSTRAC
Yes. But theres not going to be any one initiative or silver bullet that will solve scams; its absolutely a multifaceted solution, right. So sometimes therell be a takedown facility, sometimes it will be a law enforcement response, sometimes it will be hardening industry as the first line to stop things getting into the gateway. Thats why the ACCCs Anti-Scam Centre, in the fusion cell, has all of those partners in there because were exploring all of those options and really making sure that as many bases or as many different treatments are covered as possible.
Question
Hello, Im a non-executive director on some financial services entities. One of the many learnings from the recent public data breaches is in relation to protection of data and retention of data, and financial services has more sort of regulatory requirements in that regard than other sectors. So Im just interested in your thoughts on data retention and data sharing, data protection.
John Lonsdale, APRA
Well, Im happy to lead off. I mean, its a very important issue. It goes, for us, with operational resilience, and what were saying to all entities is not just know what youre critical functions are and operations but know where your critical data is; right? Know what is critical, know where it is and know its safe, so wrap the risk management around it; so were saying that. We dont have particular rules, to my knowledge, on how long to keep it. I mean, these are issues for the entity itself, but you need to be managing the risk.
Peter Soros, AUSTRAC
Yes. We have some obligations under our anti-money-laundering regime to keep records for certain periods of time, but all the same things apply that John said. youve got to have the protections, the frameworks, in place to do that, and it is a challenge; youre always going to be susceptible. Thats why its not a one-off investment to protect your systems; its a continual battle. And for senior executives and independent directors, you have to be prepared to continue to fund it. Its not a: Oh, its orange this month; were going to whack some money at it and it will be green. Its a continual investment that youve got to be prepared to continue to engage with.
Christine Yates, Moderator
Thank you. We dont have time for any more questions. Id like to invite Yasser up to the podium and, as Yasser joins us, Id personally like to thank each of you and your agencies for the work that you do every day. Thank you.
Yasser El-Ansary
Thank you, Chris, and thank you to our regulatory panel; it was tremendously insightful, as we expected it to be. We really do appreciate the candour and the openness that you all bring to the discussion today. I think youll all agree that regulating the financial services sector is certainly a big challenge; we know that in a day-to-day context. We know that its vitally important, though, and the role that each of you play is absolutely critical to maintaining the stability of the great financial services sector that we do have in this market.