Lead signal
BNZ's $2.6m undertaking and the FMA's 1 July takeover of consumer credit land the same message: the regulator now reads bank systems against bank paperwork, and a mismatch is misleading conduct, not an IT bug. CoFI incentive expectations and two named privacy decisions widen the same lens to sales and to customer data.
Show radar
Regulatory radar overview
Angle shows the regulatory category, distance from the centre shows when it bites, and size and colour show severity. Select a numbered signal to read its detail.
On a small screen, scroll the radar horizontally to see the full graphic.
Regulatory changes on the radar
$2.6m for a calculation mismatch
- Who it affects
- banks and deposit takers whose systems calculate interest, fees or product terms at scale
- What it can disrupt
- calculation engines that drifted from the terms customers actually signed
- Why it matters now
- enforceable undertaking accepted after $5.39m in underpaid interest. Find the drift before the regulator does.
A new regulator polices lending
- Who it affects
- banks with consumer lending books now supervised by the FMA rather than the Commerce Commission
- What it can disrupt
- affordability logic, remuneration controls and complaints workflows built for the old regulator's playbook
- Why it matters now
- the FMA took over consumer credit on 1 July. Its first supervisory themes are already published.
Disclosure documents changed in July
- Who it affects
- banks writing consumer credit and generating CCCFA disclosure documents
- What it can disrupt
- document generation systems still producing last year's disclosure statements on every new loan
- Why it matters now
- in force 1 July. A second template change lands 5 December 2026.
Credit definitions changed in July
- Who it affects
- banks whose product and registration systems classify consumer credit contracts
- What it can disrupt
- product classification logic, registration data and workflows built to the old definition
- Why it matters now
- amendment in force since 1 July. Live now, not pending
Health data breach findings landed
- Who it affects
- banks holding sensitive customer and health-adjacent data, including insurance and hardship records
- What it can disrupt
- security safeguards that would not survive a post-breach inquiry into whether they were reasonable
- Why it matters now
- Phase 1 found Privacy Act breaches in May. Compliance notices are coming and Phase 2 is next.
Outsourcing does not outsource accountability
- Who it affects
- banks whose customer data sits with outsourced processors, contact centres or cloud vendors
- What it can disrupt
- vendor contracts and oversight that leave privacy obligations implied rather than enforced and monitored
- Why it matters now
- decision published and the stores named. The principle applies well beyond retail.
Sales incentives under the microscope
- Who it affects
- banks running sales campaigns or paying incentives to staff, brokers and other intermediaries under CoFI
- What it can disrupt
- governance, record keeping and outcomes monitoring around incentives that cannot show fair treatment
- Why it matters now
- findings published under the CoFI regime. Expectations are now on record.
The new regulator named its targets
- Who it affects
- banks writing consumer credit, now supervised by the FMA under the published themes
- What it can disrupt
- remuneration conflicts, complaints handling and fraud detection that cannot stand a supervisory visit
- Why it matters now
- the 2026/27 supervisory year is underway. Themes are published, sweeps follow.
Compiled with care from public sources; errors and omissions excepted. Always check the linked source before acting. Regulatory Radar is general information, not legal or compliance advice.