Commonwealth Bank began a tightly scoped pilot this week that lets a western New South Wales grain co-operative complete payroll batches when RSA hardware tokens fail mid-session, after September harvest payments froze behind dead token batteries and left casual silo crews waiting on weekend cash runs.

What broke

The co-operative, which InfoHandle is not naming while police review unrelated invoice fraud, runs CommBiz with dual approvers for outbound payments above $50,000. Payroll for harvest casuals typically clears on Thursday nights so Friday farm pickups can pay cash contractors. On 11 September three approvers held valid tokens, but two devices showed low-battery warnings during a $1.2 million fortnightly run; the third token refused to sync after a firmware push.

CommBank’s standard recovery path requires branch visits or mailed replacements—reasonable for metro firms, punishing when the nearest full-service branch is a three-hour drive and the next pay cycle includes penalty rates for bin workers. The co-operative’s treasurer approved partial transfers using a one-time bypass code issued after a video call with CommBiz fraud analysts, but only for whitelisted BSB accounts tied to known employees.

Who has the file

The Australian Financial Complaints Authority has not opened a public case, but rural banking advocates forwarded the incident to AFCA’s small-business team after similar complaints in 2025 about token logistics during flood evacuations. NSW Police’s cybercrime squad received a separate report about spoofed payroll change emails that hit the same co-operative in August; investigators said the token outage did not cause that fraud attempt but slowed verification calls.

CommBank told InfoHandle it logged the bypass under its privileged-access workflow, with session recordings and IP pinning to the co-operative’s fixed line. ASIC’s scam data collection does not break out hardware-token failures, leaving AFCA as the likely forum if a customer disputes liability after a bypass-assisted transfer.

How the pilot works

Under the pilot, nominated CommBiz administrators can request a time-boxed bypass when tokens fail integrity checks. Fraud desk staff verify director IDs, recent payment patterns, and callback numbers on file before issuing a single-use elevation that expires in 30 minutes. Payments remain capped at the co-operative’s historical payroll envelope; new payees still require branch-grade identification.

CBA security engineers said the bypass is not a return to SMS codes. It routes through the same transaction signing service used for token approvals, adding geofencing around the town’s NBN exchange and requiring a second director to acknowledge the elevation inside CommBiz chat. The bank declined to publish enrollment criteria beyond “multi-year agribusiness clients with clean fraud histories.”

Why rural payroll is different

Grain handlers face compressed pay windows: headers run 24 hours when weather breaks, and contractors expect cleared funds before fuel suppliers cut off weekend deliveries. Hardware tokens were introduced to kill business email compromise, yet battery swaps and USB drivers become failure points when IT support is a part-time bookkeeper.

Other majors pitch phone-based authenticators, but coverage gaps on farm properties push co-ops back to physical tokens. Rabobank and NAB have triaged similar requests with couriered tokens; CBA’s pilot tests whether controlled bypass beats leaving payroll idle while tokens ship from Sydney.

Liability questions

If a bypass session coincides with a spoofed email changing account details, the fight will be over whether CommBank’s elevation checks satisfied “reasonable steps” under the ePayments Code. Consumer lawyers said courts still treat hardware tokens as strong authentication; a bypass weakens that story unless logs show directors actively confirmed payees.

The co-operative’s board passed a resolution requiring two directors on every bypass call and banned payroll changes within 48 hours of elevation. CommBank said it will publish a rural business bulletin once the pilot ends in October, regardless of whether AFCA issues guidance.

What remains unknown

CommBank has not said how many agribusiness clients qualify, whether bypass elevates malware risk on shared office PCs, or if successful pilots become permanent. Token vendor supply chains also remain opaque: the co-operative waited five business days for replacements in 2024 after a warehouse backlog.

For now, harvest payroll moves with a bank-issued escape hatch—and a paper trail AFCA may scrutinize if the next bypass coincides with a scammer on the line.

NSW Farmers said it will survey members on authentication failures after header season, giving policymakers numbers beyond anecdotal branch-distance complaints.