08 May 2018

National Security, Risk and Migration Vetting

'Extreme Vetting of Immigrants: Estimating Terrorism Vetting Failures', a Cato study by David J. Bier, comments
President Donald Trump has promised to implement “extreme vetting” of immigrants and foreign travelers, asserting that wide-spread vetting failures had allowed many ter- rorists to enter the United States. This policy analysis provides the first estimate of the number of ter- rorism vetting failures, both before and after the vetting enhancements implemented in response to the September 11, 2001, attacks. Vetting failures are rare and have become much rarer since 9/11.
A terrorism vetting failure occurs when a foreigner is granted entry to the United States who had terrorist associations or sympathies and who later committed a terrorism offense including support for terrorist groups abroad. This analysis defines vetting failure broadly to include individuals who had privately held extremist views before entry. Moreover, unless evidence exists to the contrary, it assumes that anyone who entered the United States legally either as an adult or older teenager, and who was charged with a terrorism offense within a decade of entry, entered as a result of a vetting failure, even without any evidence that he or she was radicalized prior to entry.
By this definition, only 13 people — 2 percent of the 531 individuals convicted of terrorism offenses or killed while committing an offense since 9/11 — entered due to a vetting failure in the post-9/11 security system. There were 52 vetting failures in the 15 years leading up to 9/11, four times as many as in the 15 years since the attacks. From 2002 to 2016, the vetting system failed and permitted the entry of 1 radicalized terrorist for every 29 million visa or status approvals. This rate was 84 percent lower than during the 15-year period leading up to the 9/11 attacks. Only 1 of the 13 post-9/11 vetting failures resulted in a deadly attack in the United States. Thus, the rate for deadly terrorists was 1 for every 379 million visa or status approvals from 2002 through 2016.
During this same period, the chance of an American being killed in an attack committed by a terrorist who entered as a result of a vetting failure was 1 in 328 million per year. The risk from vetting failures was 99.5 percent lower during this period than during the 15-year period from 1987 to 2001. The evidence indicates that the U.S. vetting system is already “extreme” enough to handle the challenge of foreign terrorist infiltration.

Homeopathy in Australian Pharmacies

The national Government has released its response to last year's Final Report of the Review of Pharmacy Remuneration and Regulation.

The response is of particular interest for disengagement regarding the sale and promotion of homeopathic products, which - as noted in a range of authoritative studies highlighted in this blog (eg here and here) - have no therapeutic efficacy apart from the placebo effect. It is disquieting that pharmacists continue to sell 'medications' in which it is impossible to detect a pharmacologically active agent. That practice, and the Commonwealth's response (an embodiment of regulatory capture), tells us something useful about health policy and about regulation, which we can contextualise through reference to the failures of ASIC, TGA, APRA and the OAIC evident in current reporting of for example the Hayne Royal Commission.

The response states
The Government responds to the Report in accordance with meeting its obligations under the Sixth Community Pharmacy Agreement (6CPA). The independent Review upholds a commitment made between the Australian Government and the Pharmacy Guild of Australia (the Guild), during negotiations of the 6CPA in 2015, to conduct a comprehensive review of pharmacy remuneration and regulation.
The Terms of Reference for the Review provided that it would make recommendations on the future remuneration, regulation including pharmacy location rules and other arrangements that apply to pharmacy and wholesalers for the dispensing of medicines and other services, including preparation of infusions or injections for chemotherapy, provided under the Pharmaceutical Benefits Scheme (PBS), to ensure consumers have reliable and affordable access to medicines.
In November 2015, the then Minister for Health, the Hon Sussan Ley MP, appointed Professor Stephen King to chair a panel of three eminent independent reviewers to undertake the Review. Other members appointed to the Review Panel were Ms Jo Watson and Mr Bill Scott. The Government acknowledges the comprehensive consultation, analysis and strategic thinking undertaken by the Review Panel in delivering the Report.
The Government notes that the Report has been informed by an extensive public consultation process and gratefully acknowledges the input of all individuals and organisations who contributed their knowledge, expertise and vision to the Review.
The Report notes that Australia’s pharmacy sector is evolving and adapting to change – it is in the midst of transition from a product supply focus to one which is more patient-centred and adaptive to an outcomes-based approach to the optimal use of medicines – and that this trend is also occurring internationally.
The Government notes that a number of recommendations of the Review complement work that has already been undertaken, or is in progress by Government and/or other organisations, agencies or jurisdictions to progress issues that support community pharmacy with this transition. Other recommendations of the Review will require further investigation by Government. The Government recognises the pivotal role of the community pharmacy sector in delivering medicines to Australian patients. The Government is committed to working closely with community pharmacies and other stakeholders to address the significant pressures being placed on the health system, including a growing burden of chronic disease, an ageing population, and growing demand for high-cost, high-tech services and breakthrough medicines.
xxx The 6CPA between the Government and the Guild provides approximately $18.9 billion to more than 5,700 community pharmacies for dispensing PBS medicines, providing pharmacy programs and services and for the Community Service Obligation (CSO) arrangements with pharmaceutical wholesalers.
The 6CPA, which operates until 30 June 2020, supports Australia’s National Medicines Policy and the sustainability of the PBS, contributes to the Government’s investment in new medicine listings (since coming into Government in September 2013, the Coalition has added around $8.2 billion worth of medicines to the PBS) and provides greater certainty of Government revenue to community pharmacies, in an environment of ongoing medicine price reductions associated with price disclosure.
In May 2017, the Government entered into a compact with the Guild to strengthen the PBS. As part of the 2017-18 Budget measure Improving Access to Medicines – support for community pharmacies, the Government is providing $825 million over three years from 2017–18 to support and improve Australians’ access to medicines.
This funding includes an additional $210 million over three years to community pharmacies and $15 million to pharmaceutical wholesalers in response to lower than forecast prescription volumes and in recognition of the impact of the package of price reduction policies outlined in the Budget measure. As part of the 2017-18 Budget measure, the Government is also providing $600 million in funding to community pharmacy for new and expanded community pharmacy programs delivered under the 6CPA. This funding will enable pharmacies to offer new or expanded services to consumers, including home visits by pharmacists, helping patients with their medication, and supporting Health Care Homes (HCH) with medicine management. The Government undertakes to work collaboratively with the Guild and other key stakeholders to maintain the community pharmacy model and to secure a viable community pharmacy sector that continues to meet the needs of consumers into the future.
The recommendations in the report cover
 2-1: PBS Pricing Variations. 
2-2: The $1 Discount. 
2-3: PBS Safety Net 
2-4: Pharmacy Atlas 
2-5: Consumer Medicines Information. 
2-6: Electronic Prescriptions . 
2-7: Electronic Medications Record 
2-8: Electronic Prescriptions — Consumer Choice 
3-1: Access to Medicines Programs for Indigenous Australians 
3-2: Pharmacy Ownership and Operation by an Aboriginal Health Service 
3-3: Patient Labelling of Medicines under Bulk Supply Arrangements 
3-4: Machine Dispensing 
4-1: Community Pharmacy — Minimum Services 
4-2: Complementary Medicines in Community Pharmacy 
4-3: Placement of Scheduled Medicines within a Community Pharmacy 
4-4: Sale of Homeopathic Products in PBS Approved Pharmacies 
5-1: Community Pharmacy Accounting Information (King  and Watson) and Alternative Recommendation 5-1 (Scott) 
5-2: Remuneration to be based on the Cost of Dispensing Services Associated with a Best Practice Pharmacy Model (King and Watson)  and Alternative Recommendation (Scott) 
5-3: Remuneration for Dispensing – Methodology (King and Watson) and Alternative Recommendation  (Scott) 
5-4: Remuneration Limits 
5-5: Remuneration for Other Services 
6-1: Reforms to Pharmacy Location Rules 
6-2: Pharmacy Location Rules — Concentration of Ownership 
6-3: Transparency in Government Programs . 
6-4: Rural Pharmacy Maintenance Allowance 
6-5: Harmonising Pharmacy Legislation 
6-6: Evaluation Mechanisms 
7-1: Community Service Obligation 
7-2: A Comprehensive Supply Chain Analysis 
7-3: Supporting Access to High-Cost Medicines 
7-4: Supporting Access to Highly Specialised Medicines 
7-5: Tightening the Listing of Generic Medicine 
8-1: Scope of Community Pharmacy Agreements — Dispensing 
8-2: Scope of Community Pharmacy Agreements — Wholesaling 
8-3: Scope of Community Pharmacy Agreements — Programs and Services 
8-4: Community Pharmacy Agreement Participants. 
9-1: Community Pharmacy Programs — Key Principles . 
9-2: Dose Administration Aids — Standards . 
9-3: Home Medicines Review — Removal of Caps 
9-4: Pharmacy Support for Residential Aged Care Facilities 
9-5: Support for Expanded Pharmacy Services Identified by Pharmacy Trial Program 
10-1: Chemotherapy Compounding — Uniform Minimum Standards 
10-2: Chemotherapy Compounding — Payments. 
10-3: Chemotherapy Compounding — Practice Models 
11-1: Managing Patient Medicine Risks on Discharge from Hospitals
In relation to Recommendation 4-4: 'Sale of Homeopathic Products in PBS Approved Pharmacies' the report noted
 Homeopathy and homeopathic products should not be sold in PBS-approved pharmacies. This requirement should be referenced and enforced through relevant policies, standards and guidelines issued by professional pharmacy bodies. 
The Government response is
The Government notes this recommendation. 
The Government notes the importance of the provision of information to consumers for all medicines and health related products available through community pharmacy. 
Professional standards have been designed for use by individual pharmacists to assess their own professional practice. They are intended to serve as guidance for desired standards of practice. However, it is the sole responsibility of the individual pharmacist to determine, in all circumstances, whether a higher standard is required. It is equally their  responsibility to meet that standard and ensure that consumers are provided with the best available information about the current evidence for, or lack-of efficacy in, offered treatments and therapies. 
As in relation to Recommendation 4-2, the Government has accepted the recommendations of the independent RMMDR reforming the regulation of complementary medicines in Australia.
The report's recommendation regarding 4-2 was
Community pharmacists are encouraged to:
a. display complementary medicines for sale in a separate area where customers can easily access a pharmacist for appropriate advice on their selection and use; and 
b. provide appropriate information to consumers on the extent of, or limitations to, the evidence of efficacy of complementary medicines. This could be achieved through the provision of appropriate signage within the pharmacy (in the area in which these products are sold), directing consumers to ‘ask the pharmacist for advice’ if required.
The Government has endorsed a regime where pharmacies - increasingly owned by chains - are free to sell what would be acerbically characterised as snake oil on the basis that a pharmacist is on the premises and thus available to answer any question about whether the pills, potion or salve will work.

Crypto

The US National Academies study Decrypting the Encryption Debate: A Framework for Decision Makers states
Encryption protects information stored on smartphones, laptops, and other devices—in some cases by default. Encrypted communications are provided by widely used computing devices and services — such as smart-phones, laptops, and messaging applications — that are used by hundreds of millions of users. Individuals, organizations, and governments rely on encryption to counter threats from a wide range of actors, including unsophisticated and sophisticated criminals, foreign intelligence agencies, and repressive governments. Encryption on its own does not solve the challenge of providing effective security for data and systems, but it is an important tool.
At the same time, encryption is relied on by criminals to avoid investigation and prosecution, including criminals who may unknowingly benefit from default settings as well as those who deliberately use encryption. Thus, encryption complicates law enforcement and intelligence investigations. When communications are encrypted “end to end,” intercepted messages cannot be understood. When a smartphone is locked and encrypted, the contents cannot be read if the phone is seized by investigators.
Yet even while the use of encryption is increasing, so is the amount of unencrypted stored data and communications and metadata. This is a result of the growth in the use of smartphones, social networks, text messaging, and other computing and electronic communications over the past decade. The result of the rise in both the amount of data and the use of encryption is that as the amount of data increases rapidly, there is both more data than ever of relevance to investigations and more data than ever that is inaccessible to investigators. With increasing use of encryption, often by default, law enforce- ment and some intelligence officials have increasingly called for a reliable and sufficiently rapid and scalable way to access plaintext—decrypted data and messages—so that they can protect the public and fulfill their public safety and national security missions. In particular, law enforce- ment officials point to
(1) the widespread and increasing use of encryp- tion by default in widely used products and services, 
(2) the myriad national security threats posed by terrorist groups and foreign rivals, (3) the increasing importance of digital evidence as human activity and crime have become increasingly digital, and 
(4) the limited effectiveness of alternative sources of digital evidence.
Critics have objected on a number of legal and practical grounds, arguing that regulations to ensure government access to plaintext likely would
(1) be ineffective, 
(2) pose unacceptable risks to cybersecurity, 
(3) pose unacceptable risks to privacy and civil liberties, 
(4) disadvantage U.S. providers of products and services, and 
(5) hamper innovation in encryption technologies.
In addition, critics argue that mandating means for ensuring government access to plaintext may be less necessary in light of the wider availability of data — and especially metadata —generally, and the alternative means currently available for government officials to obtain access to encrypted data.
There are a wide variety of legal and technical options available to governments that seek access to plaintext for law enforcement and intelligence investigations. These include the following:
• Take no legislative action to regulate the use of encryption, 
• Provide law enforcement with additional resources to access plaintext, 
• Enact legislation that requires that device vendors or service providers provide government access to plaintext without specifying the technical means of doing so, and 
• Enact legislation requiring a particular technical approach.
These are discussed in detail in Chapter 5.
Some computer scientists have reacted with concern to renewed proposals to regulate the use of encryption, citing the security risks. Several attempts have also been made in recent years to develop technical mecha- nisms to provide the government with exceptional access to encrypted data on locked devices and to encrypted communications that would minimize these risks. Three were presented to the Committee on Law Enforcement and Intelligence Access to Plaintext Information during its work (Box 5.1). The committee was not charged with reviewing specific proposals, but it did use these specific proposals to help develop and test its framework for evaluating suggested approaches.
The committee offers a framework (in the form of a set of questions) to ask about any path forward on encryption policy. The objective of this framework is not only to help policymakers determine whether a particular approach is optimal or desirable, but also to help ensure that any approach that policymakers might pursue is implemented in a way that maximizes its effectiveness while minimizing harmful side effects. The questions are as follows:
1. To what extent will the proposed approach be effective in permit- ting law enforcement and/or the intelligence community to access plain-text at or near the scale, timeliness, and reliability that proponents seek? 
2. To what extent will the proposed approach affect the security of the type of data or device to which access would be required, as well as cybersecurity more broadly? 
3. To what extent will the proposed approach affect the privacy, civil liberties, and human rights of targeted individuals and others? 
4. To what extent will the proposed approach affect commerce, economic competitiveness, and innovation? 
5. To what extent will financial costs be imposed by the proposed approach, and who will bear them? 
6. To what extent is the proposed approach consistent with existing law and other government priorities? 
7. To what extent will the international context affect the pro- posed approach, and what will be the impact of the proposed approach internationally? 
8. To what extent will the proposed approach be subject to effective ongoing evaluation and oversight?
In addressing these questions, policymakers will have to contend with incomplete data about the impact of encryption on investigations as well as incomplete data about the deliberate use of encryption by criminals. It is also difficult to quantify key factors such as the additional security risks of adding exceptional access to encryption systems. There are also a number of cases where one can only speculate about future behaviors that have bearing on the implications of government regulation of encryption. These include the fraction of criminals that would use noncompliant, unbreakable encryption if the government were to require vendors to provide exceptional access and the fraction of foreign customers that would eschew U.S. products if exceptional access were required.
Policymakers will also have to contend with the trade-offs associated with encryption and government access that underlie these questions. One of the fundamental trade-offs is that adding an exceptional access capability to encryption schemes necessarily weakens their security to some degree, while the absence of an exceptional access mechanism necessarily hampers government investigations to some degree. How much security is reduced and whether the resulting level of security remains acceptable depend on the specific technical and operational details of the exceptional access mechanism and on the requirements and perspectives of users. The impact on society when an investigation is hindered or thwarted will depend on the scope and scale of the associated crime or national security threat.
There are no easy answers to and many uncertainties in responding to these questions. However, developing and debating answers to these questions will help illuminate the underlying issues and trade-offs and help inform the debate over government access to plaintext.

02 May 2018

Citation

'What do trial judges cite? evidence from the new south Wales district court' by Russell Smyth in (2018) 41(1) University of New South Wales Law Journal examines
the citation practice of the New South Wales District Court, using all decisions reported on AustLII/Caselaw NSW decided between 2005 and 2016. This study is the first to examine the citation practice of an 'inferior' trial court. The study suggests some important differences between the citation practice of the New South Wales District Court and what existing studies have found about the citation practice of superior courts in Australia. The proportion of citations to decisions of the High Court and New South Wales Court of Appeal is higher than in the superior courts. The proportion of citations to the Court's own previous decisions are lower than in the superior courts. The proportion of coordinate citations to courts in other states at the same level in the judicial hierarchy are extremely small. The Court cites fewer secondary sources than is the case in the appellate courts.

01 May 2018

new Australian Data Commissioner

The national Government has released its response to the Productivity Commission Inquiry into Data Availability and Use.

The report was noted here.

The response refers to $65 million over the forward estimates to 'reform the Australian data system and introduce a range of measures to implement the Productivity Commission’s recommendations'.

Three key features:
1. A new Consumer Data Right will give citizens greater transparency and control over their own data 
2. A National Data Commissioner will 'implement and oversee a simpler, more efficient data sharing and release framework. The National Data Commissioner will be the trusted overseer of the public data system' 
3. New legislative and governance arrangements will enable better use of data across the economy while ensuring appropriate safeguards are in place to protect sensitive information
The response refers to 'A new Data Sharing and Release Act'
The Government will introduce laws underpinning a new system for data sharing and release in Australia. This legislation will establish institutional and governance arrangements including Accredited Data Authorities and a trusted user framework to facilitate better sharing of data. The legislative package will set clear rules and expectations for data sharing and release, including making clear when data can be shared, and embedding strong safeguards for sensitive data and effective risk management practices. 
Balancing access and secrecy through a trusted user framework 
The Productivity Commission found, in some cases, secrecy provisions in existing laws could unreasonably hinder data sharing and release for matters of public interest. Australia's secrecy provisions relating to access to and use of identifiable data have been set after thorough consideration of our national interests, and will not be changed without careful consideration. The data sharing and release legislative package will provide a robust authorisation process, balancing the operation of secrecy provisions with data sharing and release for public interest purposes. Importantly, the new legislation will not affect existing protections applying to particularly sensitive data, such as national security and law enforcement data. A number of key data safeguards will apply.
Presumably development of the Act will involve consultation, with the response stating
The Government agrees to actively engage with the community on matters related to data availability and use. Engagement is key to the OpenGovernment National Action Plan 2016–2018 and the Data Integration Partnership for Australia, and will be acore function of reformed institutional and governance arrangements. The Open Government National Action Plan 2016-2018 commits to providing better access to government-held information and data, while improving privacy risk management capability across the public sector.
A position to be called the National Data Commissioner will be established alongside 'a new data sharing and release framework' (and alongside the OAIC?).
This will streamline the way public data is shared and released, which will in turn:
  • Promote greater use of data 
  • Drive economic benefits and innovation from greater use of data, and 
  • Build trust with the Australian community about the government’s use of data.
Realising benefits from data for all Australians needs a powerful champion with a mandate to unlock the productivity benefits of valuable datasets, identify opportunities for improved data use, and build national frameworks and guidelines. 
Many benefits of better data use within governments arise from improvements in economic productivity—by providing a stronger evidence base, more efficient systems, and competitive product and service offerings in the market economy. However, a balance must be struck between utilising data for the benefit of the Australian economy and society, and ensuring community trust in the way government uses data. 
The National Data Commissioner will provide a consistent and well-defined approach to data management, including proactively managing risks, dealing with complaints and monitoring the integrity of the data sharing and release framework. This will increase community trust and confidence in the way government manages and uses its data. 
The Australian Bureau of Statistics will provide technical guidance and support to the National Data Commissioner. 
A new National Data Advisory Council will advise the National Data Commissioner on ethical data use, technical best practice, and industry and international developments. 
A cultural change is required from agencies to ensure greater data sharing within government and support for whole-of-government initiatives and reforms. The new data sharing and release framework will support a drive for cultural change within government towards greater data sharing while mitigating the risks associated with sharing of personal data. Better legislative and governance arrangements will ensure government gets the maximum benefits from the data it already holds and collects while maintaining public trust in how data is being used. This will enable government to meet community expectations to be efficient and to use the data it already has more productively.
Let's trust that the enthusiasts within the Prime Minister's Department - where there is a disjunct between the suits and digital hipsters - heed the lessons of the UK Care.Data debacle.

Credit 'Fixing' and the ACL

The Federal Court has found that 'credit repair' business Malouf Group Enterprises Pty Ltd and its sole director, Jordan Francis Malouf, breached the Australian Consumer Law during the period January 2014 to December 2015 by making false and misleading representations and by engaging in unconscionable conduct. The Court described the conduct as "cynical and calculated"

 Action was taken by the Australian Securities and Investments Commission (ASIC) on a delegated basis from the ACCC under the ACL.

The penalty for that misleading and unconscionable conduct was $1.7 million, with $100,000 towards ASIC's costs. In determining the penalties, the Court took into account an enforceable undertaking in which the respondents will refund $1.1 million to consumers who did not have any negative listings on their credit files when they entered into contracts with Malouf Group during the 2014-2015 period. The penalties were towards the limit of the financial resources available to the respondents.

Malouf Group claimed to “clean up” a consumer's credit history by removing negative listings. It primarily operated through on-line and by telephone sales. The Court accepted ASIC's  allegation that the Malouf Group sales tactics misrepresented the services that Malouf Group actually provided because Malouf Group had not ascertained if the consumer had negative listings or if any negative listings were able to be removed.

The Court found that Malouf Group engaged in misleading or deceptive conduct in inducing consumers to enter into contracts, with  false representations on Malouf websites regarding its standing as a credit repair company; the display of false testimonials on the Malouf Group websites; the making of false representations as to Malouf Group's ability to clean up a consumer's credit history; and the making of false representations in Malouf' Group's sales scripts about the work  done for the consumer prior to the payment of the Malouf Group fee.

It characterised  examples of the tactics used to induce consumers to enter into contracts as "disturbing and unconscionable". It found that Mr Malouf was knowingly involved in the contraventions of the Australian Consumer Law, having devised and implemented the business model of Malouf Group; approved the content of the websites and advertising; approved the content of the sales scripts; and was involved in the training and supervision of sales staff to ensure that they followed the sales scripts.

APRA report on Commonwealth Bank

APRA has very belatedly responded to banking sector problems - evident in hearings of the current Hayne Royal Commission - with a report on the Commonwealth Bank.

Scholars of regulatory theory, whistleblowing and consumer protection might wonder what APRA has been doing up till now ... and whether it will in future engage more effectively with its regulatory responsibilities.

The Executive Summary in the report states
Community trust in banks has been badly eroded, globally and in Australia.
Globally, the financial crisis exposed a series of corporate scandals in banks. Governance weaknesses, serious professional misbehaviour, ethical lapses and compliance failures have resulted in substantial financial losses and record fines and penalties. ‘Conduct risk’ has entered the lexicon of bank Boards and regulators as a clear and present danger.
Banks in Australia were resilient through the crisis but their conduct is far from unblemished. Failings in the provision of financial advice, dubious lending practices, mis-selling of financial products, shortcomings in the setting of benchmark interest rates and compliance breaches have undermined community trust, drip by corrosive drip. Trust is the currency of banks, and improper conduct that undermines confidence or causes harm to customers devalues that currency.
The Commonwealth Bank of Australia (CBA) has acquired the status of a financial icon, built on its history, its continued financial success and its innovation in customer-facing technology. As Australia’s largest financial institution, CBA touches a wide range of Australians. Hence, the community holds high expectations for the institution, as does CBA itself. Nonetheless, it too has had a succession of conduct and compliance issues – AUSTRAC’s legal action a recent high-profile example – and these expectations have not been met. CBA has ‘fallen from grace’. How can this happen in a bank of CBA’s stature and sophistication? This, fundamentally, is the question that the Inquiry Panel has been asked to address.
There is no simple answer, no ‘silver bullet’ remedy. A complex interplay of organisational and cultural factors has been at work. However, a common refrain has emerged from the Panel’s intensive analysis and enquiries over the past six months: CBA’s continued financial success dulled the senses of the institution.
This dulling has been particularly apparent, at least until recently, in CBA’s management of its non-financial risks (that is, its operational, compliance and conduct risks). These risks were neither clearly understood nor owned, the frameworks for managing them were cumbersome and incomplete, and senior leadership was slow to recognise, and address, emerging threats to CBA’s reputation. The consequences of this slowness were not grasped.
The Panel has identified a number of tell-tale markers:
  • inadequate oversight and challenge by the Board and its gatekeeper committees of emerging non-financial risks; 
  • unclear accountabilities, starting with a lack of ownership of key risks at the Executive Committee level; 
  • weaknesses in how issues, incidents and risks were identified and escalated through the institution and a lack of urgency in their subsequent management and resolution; 
  • overly complex and bureaucratic decision- making processes that favoured collaboration over timely and effective outcomes and slowed the detection of risk failings; 
  • an operational risk management framework that worked better on paper than in practice, supported by an immature and under-resourced compliance function; and 
  • a remuneration framework that, at least until the AUSTRAC action, had little sting for senior managers and above when poor risk or customer outcomes materialised (and, until recently, provided incentives to staff that did not necessarily produce good customer outcomes).
In the environment of continued financial success, two critical voices became harder to hear, leaving CBA vulnerable to missteps. One was the ‘voice of risk’, particularly for non-financial risks. The fact that there had been no large loss-making events in this area (though reputational damage clearly), the heavy emphasis of the risk function on financial risks, and the ineffective operational risk and compliance frameworks, muted that voice.
The other was the ‘customer voice’. Notwithstanding the customer focus enshrined in CBA’s Vision and Values, and its industry-leading customer satisfaction scores, the customer voice (in particular, customer complaints) did not always ring loudly in decision-making forums and product design.
In the Panel’s view, cultural factors lie at the heart of these shortcomings. Four broad and interlinked cultural traits stand out. First, and obviously, a widespread sense of complacency has run through CBA, from the top down. CBA’s first ranking on many financial measures created a collective belief within the institution that CBA was well run and inherently conservative on risk, and this bred over-confidence, a lack of appreciation for non-financial risks, and a focus on process rather than outcomes. CBA was desensitised to failings with customers. Delays in (or premature closing of) risk and audit issues and the late delivery of projects were readily tolerated, with limited remuneration or other consequences.
Secondly, CBA has been reactive – rather than proactive and pre-emptive – in dealing with risks. Operational risk and compliance issues tended to receive attention only once they had emerged clearly or reputational consequences began to rear, but that attention did not always guarantee timely and effective resolution. A slow, legalistic and reactive, at times dismissive, culture also characterised many of CBA’s dealings with regulators. Taken together, complacency and reactivity led to a sense of ‘chronic ease’ in CBA, rather than the ‘chronic unease’ that has proven effective in driving safety cultures in other industries.
Thirdly, CBA became insular. It did not reflect on and learn from experiences and mistakes (its own and others’), including at Board and senior leadership levels. Lessons from previous incidents have not been readily captured or shared across CBA. A lack of intellectual curiosity and critical thinking about the ‘bigger picture’ and the full depth of risk issues inevitably limited CBA’s ability to learn, anticipate and adapt. CBA turned a tin ear to external voices and community expectations about fair treatment.
The fourth cultural trait is the collegial and collaborative working environment at CBA, which places high levels of trust in peers, teams and leaders. Reinforcing this is the significant value placed on the ‘good intent’ of staff. These are positive elements of a sound culture. However, they have had a downside. Pursuit of consensus has lessened constructive criticism and has led to slower decision-making, lengthier and more complex processes, and a slippage of focus on outcomes. It has also impeded accountability and the individual ownership of risk issues. Trust has not been continually validated through strong metrics, healthy challenge and oversight. Good intent has been too readily used to excuse poor risk outcomes.
The Panel has made a series of specific recommendations designed to strengthen governance, accountability and culture within CBA. They focus on some key levers of change:
  • more rigorous Board and Executive Committee governance of non-financial risks; 
  • exacting accountability standards reinforced by remuneration practices; 
  • a substantial upgrading of the authority and capability of the operational risk management and compliance functions; 
  • injection into CBA’s DNA of the ‘should we?’ question in relation to all dealings with and decisions on customers; and 
  • cultural change that moves the dial from reactive and complacent to empowered, challenging and striving for best practice in risk identification and remediation.
The Panel has also identified a number of ‘better practice’ benchmarks that CBA should aspire to meet.
CBA had acknowledged shortcomings ahead of the AUSTRAC action and this Inquiry. Remediation had begun, with a particular focus on upgrading risk management and compliance. These efforts will need to be substantially enhanced under CBA’s new leadership.
CBA’s new remediation program is ambitious and on a scale that exceeds previous risk management initiatives. In some areas, it has anticipated the Panel’s recommendations; in other areas, however, it remains a blank canvas. To succeed, it will be critical that the program breaks the mould – it cannot succumb to the weight of bureaucracy, unclear accountabilities and porous deadlines that have challenged earlier CBA projects. Milestones must be clear, realistic, and enforced. Senior leaders must take ownership and their remuneration should be linked to successful delivery. 
Regaining community trust will require time, hard work and an undistracted risk and customer focus. Many of CBA’s working practices and cultural traits are deeply ingrained and must be squarely addressed if the ‘reset’ of the institution recommended by the Panel is to succeed. The CBA Board must be up to this challenge, and the signs are positive. Significantly, the ‘light hand on the tiller’ of earlier years has been replaced by a firmer and more visible hand and oversight and challenge has intensified. In the end, however, it will be results that count.
The Report that follows may read as a long catalogue of shortcomings. That would be too narrow a read. The Panel acknowledges the undoubted financial strength and acumen of the CBA, its global standing, and the avowed commitment of staff to servicing customers. CBA needs to translate this financial strength and good intent into better meeting the community’s needs and the standards expected of a systemically important bank in Australia. The Report is a road map for this journey.