The Australian Banking Association released an updated Industry Guideline on financial abuse this week, and the document is built around an idea that has been forming in banking for a decade: the product itself can be an instrument of abuse, and the industry that designs the product has to design against it.
The guideline, published September 17, consolidates what were previously separate ABA resources on elder abuse and family and domestic violence into a single framework. It supports the financial-abuse provisions of the Banking Code of Practice, and it sets expectations that go beyond staff training into how accounts, loans, and authorities are designed in the first place. For customers, it makes one specific promise: a person should only have to explain their situation once.
What financial abuse looks like through a banking lens
Financial abuse is control exercised through money. A joint account emptied at the wrong moment. A loan taken out in someone's name. A card cancelled, a bill left unpaid deliberately, a guarantor arrangement that traps a family member in someone else's debt. The banking system sees the transactions but often not the pattern, because each transaction, viewed alone, is ordinary.
The guideline asks banks to see the pattern. Its uplift provisions include expanded support for customers experiencing vulnerability, with specific guidance on how financial abuse presents in First Nations communities, where family and community obligations can complicate the standard screening questions. It also recognizes small business lending as a channel for abuse, with safeguards designed to test whether a borrower genuinely benefits from a loan rather than merely carrying it. That last provision matters because business lending has been the blind spot: abuse screening was built around personal accounts, while the small business loan, the director guarantee, and the family-linked structure did the same work with less scrutiny.
The design principles
The guideline's most distinctive move is its emphasis on safety-by-design, the principle that protection should be built into the product rather than bolted on as policy. That means designing staff training around recognizing control patterns, building safer ways for customers to disclose abuse, and updating expectations for third-party authorities, the arrangements under which someone manages another person's money. Third-party authority is the single most abused instrument in this space: a legitimate-looking authority document can be the mechanism by which one person takes over another's finances entirely. Stronger requirements there, including verification and review where abuse risk is present, target the point of maximum leverage.
The customer experience standard is blunt in a good way. The guideline states that a customer should only have to tell their story once, and should be able to agree on a safe way and time for the bank to stay in touch. People experiencing financial abuse are often in contact with their bank repeatedly, through multiple channels, while the abuse continues. Every repetition of the story is a cost to someone who has few left to pay. Making the single-disclosure standard explicit turns a customer-service aspiration into an obligation the code can be read against.
What the industry says it is doing
ABA chief executive Simon Birmingham framed the guideline in the strongest terms available to a trade body. Banks, he said, "will never accept their products being used to control or coerce someone," and he pointed to more than a decade of industry work on prevention, specialist teams, and confidential support. He described the framework as embedding world-leading financial safety-by-design steps.
Trade-association statements deserve the usual discount: the guideline is not enforceable on its own, and the Banking Code of Practice provisions it supports are the real instrument. But the direction of travel in Australian banking has been real. Banks maintain specialist financial-abuse teams, offer confidential support, and have progressively built screening into onboarding and transaction monitoring. A consolidated guideline does not create those practices, but it gives them a common standard, and common standards are what make industry practice legible to regulators, advocates, and the customers who need to know what they can expect.
The guideline arrives alongside a broader reform process. The ABA's July submission to the Department of Social Services flagged the consolidated framework as part of the sector's response to the National Plan to End Violence against Women and Children, and the ABA has worked with the finance industry associations on a companion safety-by-design resource for lending. The single guideline is one piece of a regulatory conversation that is still moving.
The enforcement backdrop in Australia
The guideline does not float free of legal force. The Banking Code of Practice carries enforceable financial-abuse provisions, and customers can take code breaches to the Australian Financial Complaints Authority, the external dispute-resolution body whose rulings bind member banks. A guideline that sharpens what the code's provisions mean in practice therefore changes what a complaint can point to: the written standard is now more specific, and specificity is what converts a code principle into a winnable dispute.
Australia's regulatory attention to financial abuse has been building for years, through parliamentary inquiries, the family-violence reform agenda, and the national plan the ABA's submission referenced. The banking sector's own instruments, this guideline chief among them, have been the industry's answer to a regulatory environment that was going to produce standards with or without industry input. There is a visible strategy in the consolidation: a single industry-wide framework is easier for banks to implement, easier for advocates to cite, and easier for regulators to accept as the baseline than the patchwork of separate elder-abuse and family-violence documents it replaces.
The timing also lines up with the broader safety-by-design movement that originated in technology regulation and has been migrating into financial services. The principle is the same in both domains: harms that are foreseeable consequences of product design are the designer's responsibility to mitigate, and waiting for harm reports to arrive before acting is the expensive way to learn. A joint account, a guarantor arrangement, and a third-party authority are products, in this framing, and the guideline treats them as products that can be abused by design.
Why this matters beyond Australia
Financial abuse is not an Australian problem with Australian solutions. The United Kingdom's financial sector built a Financial Abuse Code of Practice years ago, and UK banks maintain specialist teams with powers to freeze suspicious transactions under the country's banking rules. The United States has moved more slowly, but the same transaction patterns exist there, and elder financial exploitation alone moves billions of dollars a year through American accounts by the estimates of banking regulators and law enforcement alike.
What the Australian guideline adds to the international conversation is the design language. Treating the loan, the authority document, and the joint account as abuse vectors, and building the protections into the products themselves, is a step beyond training frontline staff to spot the abuse after it happens. The screening questions, the borrower-benefit tests, the authority reviews, these are upstream interventions that prevent the transaction rather than detect the pattern afterward. The upstream approach is cheaper, faster, and less visible, which is why banks like it and why regulators elsewhere will study it.
The guideline's real export is the "explain once" standard, which sounds like customer service but is actually an abuse-intervention design. A customer who must repeat their story to every department is a customer whose abuser has multiple chances to intercept, confuse, or coerce the process. One disclosure, recorded once, acted on everywhere, is a safety feature as much as a courtesy. When other jurisdictions copy the Australian framework, as they have copied elements of the UK's, that sentence is the one most likely to travel.
The small-business provisions are where the guideline's thinking is most developed. The pattern the safeguards target runs through family structures: a loan written to a family business where the beneficial owner of the borrowing is an abuser, a guarantee signed under pressure, a spouse's name added to a debt they never chose. The genuine-borrower-benefit test is designed to catch these at origination, when the loan can still be declined or restructured, rather than years later when the debt has become another instrument of control. It is a quiet change with real teeth, because it moves the bank's obligation from detecting abuse to testing for it, and testing happens before the money moves.
The test will be the outcomes
Guidelines are inputs. The outputs that matter are measured in people who keep control of their money, loans that are never written into abusive structures, and authorities that are revoked before they are misused. None of that is visible on publication day.
What the guideline does change immediately is the standard against which a bank's conduct can be judged. A customer who tells their story twice, a guarantor who is never asked whether they benefit, a third-party authority processed without review, can now be measured against an explicit, written, industry-wide expectation rather than an implicit one. That is how banking standards have always worked: the document comes first, the conduct follows unevenly, and the lag between them is where the actual protection, or its absence, is found. The lag, in this case, is the thing to watch.
Primary sources
- Australian Banking Association for the guideline release, its provisions, and the ABA's statements.
- Broker News for the guideline's scope, including the small-business lending and third-party authority provisions.