This page is an educational summary for professionals working with AI. It is not the law and not legal advice. Always work from the current authoritative text linked below.
What does CPG 235 do?
CPG 235 sets out APRA's view of sound practice for managing data risk. It defines data as the representation of facts, figures and ideas, and data risk as the risk of loss from inadequate or failed internal processes, people and systems, or from external events, impacting on data. It asks entities to assess data quality across six dimensions, to classify data by business criticality and sensitivity taking the end-to-end use into account, and to adopt a systematic rather than ad hoc approach. Read the guide on the APRA website.
Who does it bind?
Nobody, on its own terms. APRA is explicit that practice guides do not create enforceable requirements. The duties live in the prudential standards, including CPS 220 and CPS 234; CPG 235 describes how APRA expects sound entities to meet them.
What do practitioners get wrong?
Both directions. Citing a CPG paragraph as though it were a standard obligation, or dismissing the guide because it is not enforceable. Neither survives supervision. APRA wrote the guide to target areas where it keeps finding weaknesses.
Where does AI use touch it?
Fitness for use is the dimension that bites. Data that is accurate and complete can still be inappropriate for the purpose a model is being pointed at, and the classification test looks at end-to-end use, which for a model pipeline includes the prompt, the retrieval store and the output. See rebuilding the inputs behind an AI run.
Bottom line
CPG 235 is old and still useful. It gives data risk a definition, quality a vocabulary, and classification a method, which is most of what an AI data pipeline needs before controls are argued about.
TheAICommand. Intelligence, At Your Command.
