CASE INSIGHTS

Australian Securities and Investments Commission v Macquarie Bank Limited [2024] FCA 416

1. Executive summary

In Australian Securities and Investments Commission v Macquarie Bank Limited [2024] FCA 416, Wigney J imposed a $10 million pecuniary penalty after Macquarie admitted that it failed to implement effective controls to prevent or detect unauthorised transactions through its bulk-transacting system.

Macquarie customers could authorise financial advisers, stockbrokers and other intermediaries to withdraw fees from their Cash Management Accounts. The authority was limited to fees. Macquarie’s bulk-transacting facility nevertheless enabled intermediaries to process multiple withdrawals across multiple client accounts without effective controls ensuring that the transactions were within the authority granted.

Macquarie had known for years that intermediaries could misuse the facility. It had implemented transaction alerts, but there was no written procedure requiring those alerts to be systematically reviewed. Internal papers, reviews and presentations identified the control weakness and customer risk from at least 2016, but effective preventive and detective controls were not implemented until January 2020.

The control failure allowed financial adviser Ross Hopkins to make 167 fraudulent transactions totalling $2,938,750 from 14 Cash Management Accounts belonging to 13 clients between October 2016 and October 2019. Ninety-seven transactions generated alerts that were not systematically reviewed.

Macquarie admitted that its failure to implement effective controls contravened the obligation in s 912A(1)(a) of the Corporations Act 2001 (Cth) to do all things necessary to ensure that financial services covered by its Australian financial services licence were provided efficiently, honestly and fairly.

The decision is significant because it confirms that:

  • the efficiently, honestly and fairly obligation is forward-looking and may require controls designed to prevent future failures;
  • a licensee may contravene s 912A(1)(a) without breaching another specific statutory duty;
  • known control weaknesses cannot remain unresolved merely because transaction volumes are high or implementation is difficult;
  • alerts that are not assigned, reviewed, escalated and closed are not effective controls;
  • failure to act on known customer-harm risks may amount to serious regulatory misconduct even where the failure is characterised as neglect or inaction rather than deliberate or reckless conduct; and
  • control design must reflect the legal scope of third-party authorities, not merely the technical capability of a transaction platform.

2. Citation and context

Case: Australian Securities and Investments Commission v Macquarie Bank Limited
Neutral citation: [2024] FCA 416
Court: Federal Court of Australia
Judge: Wigney J
Judgment date: 19 April 2024
Publication date: 29 April 2024
Hearing date: 19 April 2024
Proceeding: NSD 241 of 2022
Registry: New South Wales
Outcome: Two declarations of contravention, a $10 million penalty and costs.

ASIC commenced the proceeding alleging that Macquarie failed to do all things necessary to ensure that relevant financial services were provided efficiently, honestly and fairly. Although Macquarie initially defended the proceeding, it ultimately admitted the contravention, agreed to a statement of facts and consented to the declarations and penalty. The Court independently assessed whether the proposed orders were appropriate: at [1]–[3].


3. Statutory and procedural context

Section 912A(1)(a) required Macquarie, as an AFS licensee, to do all things necessary to ensure that the financial services covered by its licence were provided efficiently, honestly and fairly.

The provision became a civil penalty provision from 13 March 2019, following the commencement of s 912A(5A). ASIC therefore sought separate declarations for:

  • the period from 1 May 2016 to 12 March 2019; and
  • the civil penalty period from 13 March 2019 to 15 January 2020.

The $10 million penalty applied only to the second period because conduct before 13 March 2019 did not attract a pecuniary penalty under s 912A(5A): at [7]–[10].

The maximum available penalty for the post-13 March 2019 contravention was $525 million, calculated by reference to 2.5 million penalty units. The Court emphasised that the statutory maximum was only one factor and that a penalty approaching the maximum would be warranted only where the strongest possible deterrence was required: at [16]–[18], [86].


4. Material facts

Cash Management Accounts and third-party authorities

Macquarie offered Cash Management Accounts, which were deposit-taking financial products. Customers could authorise third-party intermediaries, including financial advisers, stockbrokers and accountants, to transact on their accounts.

The authorities varied in scope. A general authority could permit broad transactions, while a limited fee authority permitted only withdrawals for the intermediary’s fees: at [21]–[25].

Macquarie’s bulk-transacting system allowed registered third parties to upload data files and process multiple transactions across multiple client accounts. A fee-payment template was used where the customer had granted only a fee authority.

Inherent and known risk

The Court found that bulk fee transactions involved an inherent risk that intermediaries could make fraudulent or otherwise unauthorised withdrawals.

By early 2014, Macquarie had introduced alerts for transactions above a specified threshold. However, no written practice or procedure required the alerts to be reviewed or monitored. The alerts therefore had “little or no effect” in mitigating the risk: at [26]–[27].

Between about mid-2012 and mid-2016, Macquarie employees became aware that intermediaries had misused fee authorities. Some of those incidents involved Mr Hopkins. Steps were taken, but Wigney J described them as “obviously inadequate and ineffective”: at [28].

From mid-2016, internal reviews, papers and presentations identified:

  • the risk that bulk fee transactions could be used fraudulently;
  • weaknesses in the existing controls; and
  • the need for additional measures.

Despite that knowledge, Macquarie did not implement effective controls until January 2020: at [29].

Fraudulent transactions

Between October 2016 and October 2019, Mr Hopkins used the system to process:

  • 167 fraudulent transactions;
  • affecting 14 Cash Management Accounts;
  • held by 13 clients; and
  • totalling $2,938,750.

Ninety-seven of those transactions generated alerts, but the alerts were not systematically reviewed: at [30].

The Court’s findings concerned Macquarie’s control failures, not attribution of Mr Hopkins’s fraudulent conduct to Macquarie.

Scale of the platform

As at August 2017:

  • more than 500,000 customers held Macquarie Cash Management Accounts;
  • more than $26 billion was under management or on deposit; and
  • monthly transactions using the fee-payment template ranged from approximately $174 million to $477 million.

The scale of the platform increased the potential consequences of ineffective controls. It did not excuse Macquarie’s failure to implement them: at [32], [74].


5. Contraventions

PeriodActProvisionObligationContravening conductFinding
1 May 2016–12 March 2019Corporations Act 2001 (Cth)s 912A(1)(a)Do all things necessary to ensure licensed financial services are provided efficiently, honestly and fairlyFailure to implement effective controls preventing or detecting third-party bulk transactions outside limited fee authoritiesContravention declared
13 March 2019–15 January 2020Corporations Act 2001 (Cth)ss 912A(1)(a), 912A(5A)Same substantive obligation; contravention was also a civil penalty contraventionContinued failure to implement effective controls after the provision became a civil penalty provisionContravention declared; $10 million penalty

The Court treated the conduct across the full period as, in effect, one continuing contravention. Two declarations were made because the civil penalty amendments commenced part-way through the relevant period: at [68]–[69].


6. Key legal principles

“Efficiently, honestly and fairly” is not confined to criminal dishonesty

The honesty component is assessed by reference to commercial norms and morality. A licensee may fail to meet the statutory standard even where its conduct is not criminally dishonest: at [48].

This reinforces that s 912A(1)(a) is a broad conduct and systems obligation rather than merely a prohibition on fraud.

A separate statutory contravention is unnecessary

A licensee may contravene s 912A(1)(a) even where it has not breached another separate legal duty under the Corporations Act or otherwise: at [49].

For compliance teams, this means that identifying no breach of a prescriptive rule does not conclude the analysis. Material systems failures, customer-risk exposures and unreasonable inaction may independently engage s 912A(1)(a).

The standard does not require perfection

The Court confirmed that the statutory obligation does not require “absolute perfection”: at [50].

The relevant question is not whether every fraud could have been prevented. It is whether the licensee took all reasonable steps to ensure its financial services met the statutory standard.

“Ensure” gives the duty a forward-looking character

Wigney J stated that the word “ensure” indicates that compliance involves a degree of forward-looking conduct and may require steps to prevent future lapses or failures: at [51].

This is a central governance principle. Once a licensee identifies a credible control weakness, the obligation is not satisfied by recording the risk or discussing possible remediation. The licensee must implement effective preventive or detective measures within a reasonable timeframe.

Known risk plus ineffective response can establish contravention

Macquarie:

  • enabled third parties to transact;
  • knew those third parties could misuse limited authorities;
  • knew misuse had already occurred;
  • recognised deficiencies in existing controls; and
  • failed to implement effective controls despite there being no insurmountable barrier.

Those matters established the contravention: at [71]–[74].

Transaction volume is not an excuse

The Court rejected transaction volume as a sufficient explanation for failing to implement controls. High-volume platforms require controls proportionate to the risk and scale of activity; scale does not dilute the licensee’s statutory obligation: at [74].


7. Control and governance failures

Control areaFailureBusiness consequence
Authority designLimited fee authority was not technically enforced within the bulk-transacting systemThird parties could use a fee facility for non-fee withdrawals
Alert governanceAlerts existed without a documented review procedureHigh-risk transactions were generated but not actioned
OwnershipKnown weaknesses persisted across multiple years and internal reviewsRemediation was delayed and accountability was ineffective
EscalationPrior misuse and internal warning material did not produce timely control upliftCustomer exposure continued after the risk was known
MonitoringNo effective systematic monitoring of bulk fee transactionsFraudulent withdrawals remained undetected
Change deliveryEffective controls were not implemented until January 2020Recognised risks remained operational for an extended period
Senior management oversightQuite senior employees knew of the deficiencies but failed to ensure they were addressedThe failure became a serious institution-level contravention
Platform governanceSystem functionality exceeded the legal authority granted by customersTechnical capability displaced the legal permission model

The Court found no evidence that Macquarie’s directors knew the facts giving rise to the contravention. However, the employees who knew of the deficiencies were quite senior and reported two or three levels below the Macquarie Group chief executive officer: at [40].


8. Remediation and cooperation

Macquarie effectively remedied the control weakness in January 2020 by implementing real-time alerts to account holders for transactions initiated by authorised third parties. In May 2020, it introduced a fraud-monitoring program for bulk transactions.

A review conducted in late 2020 or early 2021 did not identify additional fraudulent fee-related bulk transactions: at [31].

ASIC commenced its investigation in September 2020. Macquarie engaged openly with ASIC, attended voluntary meetings, provided information and later agreed to facts, admissions and joint submissions. The Court regarded that cooperation and Macquarie’s eventual admission as relevant mitigating considerations: at [43]–[44], [83].

The judgment records customer losses but does not set out a complete remediation or compensation framework. No conclusion should be drawn from the judgment alone about whether all affected customers were fully compensated.


9. Penalty and orders

Order or remedyLegal basisAmount or scopePinpoint
Declaration for pre-civil-penalty periods 912A(1)(a)1 May 2016–12 March 2019Formal declaration 1
Declaration for civil penalty periodss 912A(1)(a), 912A(5A)13 March 2019–15 January 2020Formal declaration 2
Pecuniary penaltys 1317G$10 millionOrder 1; [92]
CostsCourt orderAgreed or assessedOrder 2; [93]
Remaining proceedingCourt orderDismissedOrder 3

The Court accepted the agreed $10 million penalty as falling within the range of reasonably available penalties. Wigney J did not state that he would independently have selected that precise amount, but accepted it consistently with the principles governing agreed penalties: at [78].

Aggravating considerations

The Court regarded the contravention as serious because:

  • the control failure continued into the civil penalty period;
  • senior employees knew of the deficiencies;
  • customers were exposed to fraud;
  • actual losses totalled at least $2,938,750; and
  • $701,500 of that loss occurred after 13 March 2019.

Macquarie’s size and profitability also meant that a modest penalty would have limited deterrent effect: at [80], [84]–[85].

Moderating considerations

The Court found that:

  • the conduct was not deliberate or reckless;
  • it arose from neglect, laxity or inaction;
  • Macquarie received no direct financial benefit;
  • Macquarie had no prior relevant civil penalty findings;
  • it cooperated to an extent with ASIC; and
  • it ultimately admitted the contravention.

The Court observed that Macquarie may have avoided or deferred the cost of implementing adequate controls, although no amount was determined: at [81], [83].


10. Relevance for AFS licensees, banks and platform operators

The case has direct implications for licensees that permit advisers, brokers, administrators, custodians, accountants or other third parties to transact on customer accounts.

The licensee must understand:

  • the exact legal scope of each authority;
  • what the system technically permits;
  • whether transaction templates reflect the authority;
  • how unauthorised activity will be prevented or detected;
  • who owns each alert;
  • what escalation and suspension thresholds apply; and
  • how quickly known control weaknesses must be remediated.

An authority is not an adequate safeguard where the system permits transactions that exceed it and there is no effective monitoring.

The decision is also significant for cyber, fraud and operational-risk governance. A risk may originate in the misconduct of an external intermediary, but the licensee can still be liable where its own systems make the misconduct possible and its controls do not adequately prevent or detect it.


11. Recommended controls

AudienceControl typeLegal rationaleRisk indicatorPractical control
Board risk committeeGovernances 912A(1)(a) requires effective systemsLong-outstanding high-rated control weaknessRequire ageing and escalation of unresolved material risks
Platform ownerPreventativeTransactions must remain within authorityTechnical permissions exceed legal authorityEncode authority limits directly into transaction rules
Fraud teamDetectiveKnown fraud risk requires active monitoringRepeated or unusual fee transactionsReal-time behavioural analytics and transaction holds
OperationsDetectiveAlerts must operate effectivelyAlerts generated without assigned reviewDocument owner, service level, escalation and closure evidence
Third-party riskPreventativeIntermediaries may misuse accessAdviser or broker has bulk authorityRisk-rate intermediaries and periodically recertify access
ComplianceDetectives 912A is forward-lookingKnown weakness without implemented solutionTrack legal-risk acceptance and remediation deadlines
Customer protectionDetectiveCustomer loss may occur before internal detectionThird-party initiated withdrawalReal-time customer notification and confirmation
Executive managementGovernanceSenior knowledge heightens exposureRepeated internal reviews identifying same weaknessAssign a single accountable executive and funded remediation plan
Internal auditDetectiveIndependent assurance over control operationReliance on automated alertsTest alert completeness, review quality and false-negative risk
Incident managementCorrectiveFailures may trigger reporting and remediationUnauthorised transaction identifiedFreeze access, preserve evidence and assess breach reporting

12. Recommended next steps

AFS licensees and banking platforms should:

  1. map all third-party account authorities against system permissions;
  2. identify facilities where functionality exceeds the customer’s legal authority;
  3. test whether fraud and exception alerts are reviewed consistently;
  4. assign accountable owners and resolution deadlines to every material alert;
  5. examine unresolved internal audit, risk and compliance findings for repeated deferral;
  6. perform retrospective analytics where a known control gap has existed;
  7. review customer notification settings for third-party transactions;
  8. suspend or constrain bulk access where authority controls cannot be technically enforced;
  9. assess customer remediation and reportable situation obligations where unauthorised activity is identified; and
  10. provide the board or relevant committee with evidence that the control is operating, rather than relying only on design approval.

13. Broader impact

This case highlights that compliance with AFSL conditions requires ongoing vigilance and robust operational processes, not just box-ticking exercises. Considering Macquarie Bank’s size, the $10 million penalty [24-080MR] relative to the $2.9 million misappropriated sends a message that Licensees need to prioritise and invest in systems that protect consumers.

For advisers and Licensees, the case still emphasises the importance of understanding and adhering to all AFSL obligations. It also highlights the need for clear communication with clients about how their funds are handled and protected. The requirement for an independent expert review demonstrates a regulatory trend towards ongoing monitoring and improvement of compliance systems rather than punitive measures alone. AFS Licensees should consider implementing regular independent reviews of their compliance processes as a preventative measure to avoid similar pitfalls.


14. Referenced cases

Australian Building and Construction Commissioner v Pattinson [2022] HCA 13 — civil penalties are directed to deterrence rather than punishment — cited at [61]–[67].

Commonwealth v Director, Fair Work Building Industry Inspectorate [2015] HCA 46 — approach to agreed civil penalties — cited at [59]–[60].

Australian Securities and Investments Commission v Westpac Securities Administration Ltd [2019] FCAFC 187 — authority concerning s 912A(1)(a) — cited at [46].

Australian Securities and Investments Commission v Cassimatis (No 8) [2016] FCA 1023 — content of the efficiently, honestly and fairly obligation — cited at [46].

This analysis is suitable for internal legal and compliance review, but final positions should be confirmed against the complete source material, current legislation and any subsequent decisions.

Subscribe

Every fortnight “Three Hit Tuesday” delivers thought leadership, considered analysis and insights that will help you improve your advice, more effectively manage your regulatory risks and make you better informed than your peers.

AS-Subscribe Form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.

We respect your privacy. We know everyone says that, but we promise that we won’t sell your contact details to dodgy telemarketers, spam your email or otherwise exploit your trust.

Step 1 of 8 - Your Role

This field is for validation purposes and should be left unchanged.

Assess your ASIC exposure

Answer a few targeted questions to identify where your compliance may not stand up under ASIC review.

Takes less than 2 minutes. No preparation required.

What best describes your role?