December 2028 can look a long way off. For New Zealand’s banks and non-bank deposit takers, however, treating the Deposit Takers Act 2023 (DTA) as a problem for 2028 risks missing what is already happening.
The Reserve Bank of New Zealand – Te Pūtea Matua (RBNZ) is steadily turning the DTA into a new prudential regime. Most standards are due by 31 May 2027, with relicensing opening the following day. Before then, RBNZ plans to publish “near final” tranche 1 standards in September 2026 and tranche 2 standards in December 2026 to support implementation planning. [1]
More importantly, RBNZ has already set out where it expects risk management to improve: forward-looking frameworks, stronger links between risk strategy and appetite, proactive risk identification, better oversight of controls, continuous monitoring and reporting, clear governance and an independent, adequately resourced risk function. [2]
The DTA is the regulatory catalyst, but the practical challenge is risk-management maturity. The task now is not premature compliance with unfinished standards. It is strengthening the underlying risk and governance models before regulatory deadlines make that work harder.
Download Protecht’s Risk in motion eBook to explore how continuous risk management can connect risk assessments, metrics, controls, incidents, assurance, actions and compliance in one operating model.
The DTA is changing New Zealand’s prudential architecture
The DTA creates a modern framework for licensing, regulating and prudentially supervising deposit takers, bringing banks and non-bank deposit takers under one regime. It gives RBNZ powers to establish prudential standards covering governance, capital, liquidity, risk management, disclosure, internal controls, assurance and recovery planning. [3]
These standards will be secondary legislation and are intended to replace more than 800 pages of existing banking requirements and regulations. The Act also embeds proportionality, so implementation will differ between institutions.
But the direction is common. The DTA provides for standards covering major financial and non-financial risks, including operational and cybersecurity risk, as well as business continuity and problem assets.
Treating this only as a compliance exercise will miss the mark. It is a prudential architecture concerned with how risk is governed, understood and managed across the organisation.
Protecht supports this broader approach by bringing risk, compliance, controls and assurance into a shared framework, rather than treating each prudential requirement as a separate compliance exercise.
RBNZ has already shown where risk management needs to mature
Risk leaders do not need to wait until 2027 to understand what RBNZ expects.
Its thematic review examined risk frameworks, governance and oversight, and the risk function across nine deposit takers. RBNZ found that many were already investing in improvement, but further work was needed. It also requires all deposit takers to assess themselves against the review’s expectations and be prepared to discuss shortfalls and remediation plans with supervisors.
That creates an immediate test. Does the organisation have a forward-looking view of material risk? Are strategy and appetite connected? Can management show which controls mitigate material exposures and whether they are effective? Is reporting timely, with clear responsibilities across the board, management, risk and assurance?
The February 2026 exposure draft of the Deposit Takers (Risk Management) Standard 2027 makes the direction clearer. It may still change, but RBNZ says the underlying policy has already been set by this stage of consultation. [4]
The draft would require a framework covering all material risks, encompassing the systems, structures, policies, processes and people used to manage risk. It links that framework to strategy, appetite, reviews, stress testing, information systems, internal controls, the risk function, compliance and internal audit.
It also expects risk appetite to create meaningful boundaries that can be translated into operational limits. Information systems would need risk-data aggregation and reporting capabilities that provide timely information across the business and maintain appropriate records for audit.
For organisations still managing important risk processes across separate systems and spreadsheets, that architecture will evolve into a data governance issue. If material risks cannot be readily connected to appetite, controls, incidents, issues and assurance today, the problem will not become easier as formal governance and evidence requirements increase.
Protecht can help make those connections visible by linking risks to appetite, controls, indicators, incidents and assurance, with reporting built from the same underlying risk information.
Waiting for final standards could make implementation harder
There is an understandable temptation to wait until every final requirement is known. For detailed clause mapping, that may be sensible. But the capabilities RBNZ is emphasising cannot be built quickly.
A consistent risk taxonomy, clear ownership, meaningful appetite, rationalised controls, stronger assurance and better reporting all take time.
The draft standard also places significant responsibility on boards and senior management. The board would approve risk strategy and appetite, promote a sound risk culture and ensure recommendations from framework reviews are implemented. Senior management would operate the framework and manage material risks within board-approved policies.
The DTA itself creates due-diligence duties for directors of licensed deposit takers and New Zealand chief executives of overseas licensed deposit takers, including taking reasonable steps to establish compliance procedures, identify deficiencies and remedy weaknesses promptly.
These are operating-model questions, not just documentation questions. Waiting until May 2027 would force organisations to tackle structural risk-management work alongside detailed regulatory mapping and relicensing. A better objective is to build the underlying capability now, then map the final requirements onto it.
A configurable platform such as Protecht allows organisations to strengthen their risk processes now while retaining the flexibility to adapt workflows, registers and reporting as the final DTA requirements become clearer.
Turn DTA readiness into a connected risk program
The breadth of the new regime also creates the potential for fragmentation. Governance, risk management, operational resilience, controls, obligations, assurance and reporting can easily become separate DTA workstreams even though the information underneath them is closely connected.
The emerging Risk Management and Operational Resilience standards show why. Together they span risk frameworks, information systems, operational-risk assessment, controls, incident reporting, business continuity, ICT and cyber risk and material service providers. [5]
In practice, those areas overlap. A disruption at a material service provider could affect a critical process, change operational-risk exposure, reveal a control weakness, trigger an incident, require remediation and push a key risk indicator outside appetite. Management need to understand that entire chain quickly.
A connected risk operating model makes that easier. Risks can link to appetite, indicators and controls. Assurance can show whether controls are effective, while weaknesses become owned and tracked actions. The same records can support obligations, attestations and reporting rather than forcing teams to reconstruct evidence for boards, auditors or supervisors.
Protecht is designed around these relationships, allowing organisations to connect controls, incidents, issues, obligations, assurance and actions back to the risks and business processes they affect.
Make 2026-27 the preparation period, not the waiting period
The full DTA regime is still being built. That is a reason for disciplined preparation, not inertia.
During 2026, deposit takers can use RBNZ’s thematic review and exposure drafts to assess maturity, identify known weaknesses and make improvements that will remain useful regardless of the final wording. During 2027, attention can shift towards mapping issued standards, confirming evidence, closing remaining gaps and preparing for relicensing. RBNZ’s current roadmap has relicensing opening on 1 June 2027, with deadlines varying by deposit-taker group through 2027 and 2028.
Using Protecht as their underlying system can help teams capture that work as it develops, giving them a clearer evidence trail when the focus shifts from improving risk maturity to demonstrating compliance.
By 1 December 2028, when most DTA standards come into force, the objective should not be to have completed a frantic compliance exercise. It should be to demonstrate that the underlying governance and risk processes have been operating effectively and sustainably.
The organisations best prepared for the transition will be those that use the implementation period to strengthen that operating model rather than waiting for every final clause.
Request a Protecht demo to see how a connected approach can help your organisation strengthen risk management today and adapt as the DTA standards become final:
References
[1] Reserve Bank of New Zealand – Te Pūtea Matua, DTA standards implementation roadmap
[2] Reserve Bank of New Zealand – Te Pūtea Matua, Thematic review on risk management
[3] New Zealand Legislation, Deposit Takers Act 2023
[4] Reserve Bank of New Zealand – Te Pūtea Matua, Deposit Takers (Risk Management) Standard 2027 – exposure draft
[5] Reserve Bank of New Zealand – Te Pūtea Matua, DTA Standards exposure drafts – tranche 3


