Back to the archive

The encyclopedia · Finance & Accounting · Operational decision · 2012–2017

Commonwealth Bank let 53,700 cash deposits go unreported — and paid A$700M

Australia's biggest bank wired its cash machines to credit deposits instantly and never reported 53,700 of them. AUSTRAC won a record A$700M penalty.

Commonwealth Bank of Australia · 2018-06

What happened

Commonwealth Bank of Australia (CBA) is the country's largest bank. Between 2012 and 2015 it rolled out Intelligent Deposit Machines — ATMs that let customers deposit cash and have it credited to an account almost immediately. The machines were configured to post funds before the transaction was logged for reporting, and the bank's systems never generated the reports the law requires.

Under Australia's anti-money-laundering and counter-terrorism-financing (AML/CTF) laws, a cash deposit of A$10,000 or more must be reported to the financial intelligence agency, AUSTRAC. CBA failed to report about 53,700 such transactions. It also failed to monitor or assess the risk on the accounts behind them, so patterns that should have triggered scrutiny went unseen for years.

In August 2017 AUSTRAC filed a statement of claim in the Federal Court — the largest civil penalty action it had ever brought. CBA admitted the breaches and agreed to the facts. In June 2018 the Federal Court imposed a A$700 million penalty, the largest civil penalty in Australian corporate history at the time.

The case is now a standard compliance lesson: a product built for speed was shipped without the reporting it legally required, and the control failure sat undetected for years. The bill was not the cost of the deposits — it was the cost of a bank that did not know what its own machines were doing.

Why it happened

  • The Intelligent Deposit Machines were configured to credit cash before the transaction was logged, so the reporting step the law requires never happened.
  • CBA failed to report roughly 53,700 cash transactions of A$10,000 or more, the threshold that triggers a mandatory report to AUSTRAC.
  • The bank did not monitor or risk-assess the accounts behind the deposits, so suspicious patterns went unexamined for years.
  • The control failure ran from 2012 to 2015 before it was caught, turning a configuration choice into the largest civil penalty in Australian corporate history.
What it costA$700M civil penalty — an Australian recordcostly

The lesson

A product built for speed still has to do the reporting the law requires. Ship the machine without the control and the regulator will price the gap years later, at record size.

Aftermath

The penalty was the largest civil penalty in Australian corporate history when the Federal Court imposed it in June 2018. The bank's chief executive stepped down earlier that year and CBA spent heavily rebuilding its financial-crime and compliance systems. The case is cited in AML teaching as the example of how a product-design choice — crediting cash before reporting it — becomes an enterprise-scale regulatory liability when the matching controls are absent.

Sources

spotted an error? The club wants to know.

Comments · 0

    Sign in to join the comments.

    More like this

    Somewhere, someone solved the problem this company failed at. 2nd Opinion →