Customer Owned Banking Code of Practice review tightens hardship rules

Final report sets binding new financial hardship protections for Australia's mutual banks and credit unions

Customer Owned Banking Code of Practice review tightens hardship rules

News

By Jhoanna Hines

Australia’s mutual banks and credit unions are facing a sweeping overhaul of their consumer obligations.

Independent reviewer Eva Scheerlinck of Scheerlinck Consulting (pictured above) delivered the final report of the Customer Owned Banking Code of Practice review to the Customer Owned Banking Association (COBA) on 31 July 2026.

COBA announced the outcome on 6 August in Sydney.

Why this review matters to brokers

The Code governs how mutual banks and credit unions treat customers. It covers more than 5.4 million Australians and requires an independent review at least every five years.

For mortgage brokers, the changes are relevant. Mutual lenders are active in the broker channel. How they handle hardship, default, vulnerability, and automated decisions will affect how brokers manage client scenarios across these institutions.

Mutual lenders have more than tripled their combined mortgage book since 2019, reaching $150.9 billion in residential lending.

New binding obligations under the Customer Owned Banking Code of Practice

The report’s sharpest changes are in financial hardship. Scheerlinck found the existing code lacked the specificity to convert good intentions into reliable customer outcomes.

Under the new recommendations, code subscribers must proactively identify signs of financial distress. They must make contact without requiring a formal application first.

Any substantive response to a hardship request must follow within 21 business days. That timeframe aligns with the National Credit Code and the Banking Code of Practice applying to investor-owned banks.

This mirrors the direction already taken by the Australian Banking Association, which updated its own financial hardship industry guidance for customers in difficulty in July 2025.

For disaster-affected customers, the report recommends recognising disaster hardship as a distinct category. Adverse credit reporting must be suppressed for those customers.

The report also strengthens the existing debt waiver provision. Subscribers must genuinely consider waiving a debt where a customer faces severe, ongoing hardship with no reasonable prospect of repayment. Any decision – including a refusal – must be provided in writing.

‘This report was shaped by the generosity of everyone who took part, code subscribers, consumer advocates, financial counsellors and regulators alike,’ Scheerlinck said. ‘Their time and candour made sure the report is grounded in their experience.’

Michael Lawrence, chief executive officer of COBA, said the association would consult further before issuing a formal public response.

‘We are reviewing the recommendations with interest and will carefully consider them as we work through the findings with our Code subscribers,’ Lawrence said. ‘We look forward to continuing our engagement with stakeholders and will consult further as we develop our formal public response to the Report in due course.’

Automated decisions and vulnerability

The report introduces new obligations around automated decision-making.

Where an automated process materially informs a decision affecting a customer, the subscriber must disclose this. It must also provide a guaranteed pathway for the customer to have that decision reviewed by a human on request.

Routine internal uses, such as fraud screening that does not directly determine a customer outcome, are not captured.

The question of human oversight over automated lending decisions is already active across the industry. Lenders and technology firms have been debating where AI ends and human judgement must begin in complex loan scenarios.

On vulnerability, the report proposes replacing the code’s current static list of vulnerability indicators with a dynamic definition.

Under the new model, vulnerability includes circumstances arising from a customer’s interaction with banking products and services. Bank conduct itself can amplify a customer’s vulnerability.

The report also recommends dedicated provisions for domestic and family violence. These include:

  • a prohibition on subscribers using their products to perpetrate financial abuse
  • a ban on adverse credit reporting for debts arising from financial abuse
  • minimum training requirements for customer-facing staff

Customer Owned Banking Code of Practice: governance and compliance oversight

The report raises concerns about whether COBA has adequately resourced the Customer Owned Banking Code Compliance Committee (COBCCC), the independent body responsible for monitoring subscriber compliance.

Scheerlinck found the COBCCC’s assessed resourcing needs had exceeded approved funding on more than one occasion. This constrained its capacity to conduct own-motion investigations and issue public reports.

‘A compliance committee that cannot test subscriber compliance data, conduct own-motion investigations, or report publicly on inquiry findings is not able to provide the independent assurance the Code promises,’ the report states.

COBA and its code subscribers will now consider the recommendations before issuing a formal response. The Customer Owned Banking Code of Practice currently covers 46 of 48 customer-owned banks in Australia.

The supporting materials are published at customerownedbanking.asn.au/code-review.

Keep up with the latest news and events

Join our mailing list, it’s free!