Home/GRC

GRC

AI in Governance, Risk & Compliance

Practical intelligence on AI developments across APRA, ASIC, FAR, AML/CTF, DDO, and CPS 230 for compliance and risk professionals in Australian financial services.

APRAASICFARAML/CTF

Intelligence, At Your Command.

Analysis

GRC Intelligence

Trento Adige Castello Dusk
GRCRegulatory analysis·

Your Resilience Documents Pass. Your Exercise Might Not.

APRA and ASIC have released the notes from their June superannuation CEO roundtables. The line worth acting on is that participants said crisis exercises often reveal governance, delegation and communication issues that documentation alone may not surface. Here is how to design one for an operation that now contains agents.

Read article
Rostock Warnow Riverfront Dusk
GRCRegulatory analysis·

APRA's New Plan Asks Two AI Questions. Your Register Answers One.

APRA published its 2026-27 Corporate Plan on 20 August 2026. Under a single supervision priority it puts AI in two places, under two separate headings, meaning two different things. Most AI risk registers are built to answer only the first of them, and the second arrives with a dated cryptography deadline attached.

Read article
Plovdiv Old Town Roman Theatre Dusk
GRCRegulatory analysis·

A Gate Your Customer Can Retry Is Not a Control

On 13 August 2026 ASIC published surveillance findings against nine named online brokers, including onboarding questionnaires that allowed repeated or unlimited attempts to pass. The same defect drew a $10 million penalty in March 2026. The design question generalises to every automated eligibility gate an organisation operates, and it gets sharper when the customer has an agent.

Read article
Lviv Rynok Square Blue Hour
GRCRegulatory analysis·

Your AI Drew the Control Map. Now Prove It Is Complete.

On 18 August 2026 APRA imposed licence conditions on Bendigo and Adelaide Bank after an independent root cause analysis found the bank did not have a clear, complete and reliable view of its regulatory obligations, material risks and key controls. Completeness is now inside an enforcement outcome, and it is the one property an AI-generated map cannot supply for itself.

Read article
Liege Meuse Riverfront Dusk
GRCRegulatory analysis·

The Weakness Was Found in 2020. Exploited in 2023.

On 11 August 2026 APRA announced that Bendigo and Adelaide Bank had admitted breaching its accountability obligations over a 2023 cyber incident, with an agreed $8 million penalty. The detail that generalises to AI controls is not the attack. It is that the weaknesses had been identified in penetration testing in 2020 and were still open when they were exploited.

Read article
Malaga Muelle Uno Blue Hour
GRCRegulatory analysis·

Your Menu Outgrew Your Team. AI Buys Coverage, Not Capability.

On 19 August 2026 APRA said it will consult in September on reforms across eight areas of investment management, including ensuring a trustee's investment management capability is commensurate to the complexity of its investment menu. AI answers the coverage half of that sentence and leaves the capability half exactly where it was.

Read article
Thessaloniki White Tower Waterfront Dusk
GRCRegulatory analysis·

Data Residency Does Not Settle APP 8 for Your AI Prompts.

An Australian hosting region answers one field on a form. APP 8 turns on the overseas recipient, what it can access and for what purpose, and whether your organisation released the information's subsequent handling from its effective control. Map each access path before approving personal information in an AI workflow.

Read article
Linz Danube Hauptplatz Dusk
GRCRegulatory analysis·

Your AI Credit Score Is Not a Responsible Lending File.

A model can rank credit risk, reconcile application data and flag exceptions. It still cannot prove the inquiries, verification and customer-specific suitability assessment behind a lending decision. Build a customer-outcome file that preserves the evidence and the authorised human judgement.

Read article
Pisa Arno Lungarni Blue Hour
GRCRegulatory analysis·

The Board Signed the Risk Declaration. Can It Trace the AI Evidence?

AI can reconcile hundreds of attestations, tests and actions before a prudential risk declaration. It cannot make the declaration true. Give every claim a traceable source, every exception a visible route and every required signatory the evidence needed for genuine enquiry.

Read article
Heidelberg Old Bridge Neckar Dusk
GRCRegulatory analysis·

ASIC Asked for the File. Your AI Summary Is Not the Production.

An AI summary can help organise an ASIC request. It cannot replace responsive source records, settle the notice's scope or make a privilege claim. Build a request-to-source ledger that lets legal reviewers trace every request item to native material, exclusions, gaps and the human production decision.

Read article
Girona Onyar Riverfront Dusk
GRCRegulatory analysis·

Your AI Fallback Is Not a Recovery Plan.

Your recovery playbook fails if the tool meant to execute it disappears with the crisis. Test every AI-assisted action after removing the model, data pipeline, credentials and provider support. A fallback is credible only when people can still start, run and evidence the action.

Read article
Thun Aare Castle Dusk
GRCRegulatory analysis·

Your AI Vendor Count Is Hiding One Foundation Model.

Three contracted AI vendors can still fail as one service when they share a foundation model, cloud control plane or identity layer. Map every service to its common technical roots, then test whether your nominated substitute survives the same failure.

Read article
Leiden Canals Blue Hour
GRCRegulatory analysis·

AI Can Draft the APRA Warning Comment. It Cannot Sign Off the Return.

APRA Connect may accept an explanatory comment after a validation warning. That does not make the explanation true. Build every AI-drafted sentence from the return cell, source query, data owner, validation rule and named reviewer who accepts responsibility for submission.

Read article
Trieste Molo Audace Dusk
GRCRegulatory analysis·

AI Can Sort the Breach Queue. It Cannot Stop the 30-Day Clock.

AI can assemble evidence, connect similar incidents and challenge a preliminary assessment. It cannot decide when your licensee knew enough, whether a breach is significant or whether a report is due. Build the breach workflow around the statutory clock, not the model.

Read article
Lugano Lake Lugano Blue Hour
GRCRegulatory analysis·

Your TMD Needs Customers Who Do Not Exist.

Synthetic personas can expose a target market that is too broad, a distribution condition that fails at the edge and a review trigger that never fires. Use counterfactual pairs as adversarial tests, and never mistake generated cases for evidence of real customer outcomes.

Read article
Lausanne Ouchy Lake Geneva Dusk
GRCRegulatory analysis·

A Sanctions Alert Is Not Cleared Because the Model Says So.

AI can assemble aliases, identifiers, ownership clues and transaction context. It cannot turn a similarity score into legal clearance. Preserve the list version, evidence, unresolved questions, non-match reasoning and a named human approval for every material alert.

Read article
Odense Harbour Blue Hour
GRCRegulatory analysis·

Let AI Maintain the Obligations Register. Make a Human Own Every Change.

AI can compare approved source versions and propose candidate regulatory changes. It cannot decide what binds your organisation. Make it propose source-linked deltas, then require a named human to accept the legal state, effective date and register change, with two clocks keeping the history honest.

Read article
Turku Aura River Blue Hour
GRCRegulatory analysis·

Your GenAI Approval Needs an Expiry Trigger.

A GenAI approval records what passed on one date. It does not prove the live system still deserves approval. Build a living validation passport with explicit failure modes, change triggers, expiry and a human-controlled stop-use rule, and keep the four regulatory layers behind it separate.

Read article
Maastricht Sint Servaasbrug Blue Hour
GRCRegulatory analysis·

Defensible AI Lineage Starts Before the Prompt.

A citation beside an AI answer is not data lineage. You need the source snapshot, transformations, retrieved context, prompt, available model configuration, raw output and human edits. Without that packet, assurance starts after the evidence trail has already broken.

Read article
Cork River Lee Blue Hour
GRCRegulatory analysis·

Do Not Put a Whistleblower Disclosure Into Your General AI Tool

A whistleblower disclosure is not ordinary case data. Section 1317AAE of the Corporations Act protects the discloser's identity and anything likely to identify them. Keep the raw account inside the protected whistleblower environment, and let AI assist only with a deliberately reduced control record that an authorised human has cleared for use.

Read article
Montevideo Rambla Dusk
GRCRegulatory analysis·

Your AI Risk Register Maps the Regulator. It Misses the Plaintiff.

Australia's statutory tort for serious invasions of privacy gives individuals a direct cause of action that runs on different rules to the Australian Privacy Principles. Most AI risk registers do not carry it.

Read article
Valletta Grand Harbour Dusk
GRCRegulatory analysis·

Your AI Vendor's Breach Starts Your Clock

On 6 July 2026 the OAIC reported the highest number of data breach notifications since the scheme began. Meanwhile organisations have quietly handed personal information to a new class of provider. Under the Privacy Act you hold what your AI provider possesses if you control it, which means the assessment clock and the notification are yours, not theirs.

Read article
Cologne Rhine Cathedral Blue Hour
GRCRegulatory analysis·

Skill Files Are Controlled Documents. Treat Them Like It

The moment a skill file shapes work a regulator cares about, it stops being a personal productivity hack and becomes a controlled document. Version numbers and change logs inside the file, a named owner and approver, retained test evidence, reviews triggered by obligation changes, and a register of approved skills. Here is the discipline, anchored by a board-reporting skill your risk team can adapt today.

Read article
Houston Buffalo Bayou Skyline Dusk
GRCRegulatory analysis·

A Skill File for Regulatory Change: Impact Assessment On Demand

Every regulator release triggers the same scramble: read it, work out what it touches, brief the owners. The release changes every time. The method does not, and a stable method is exactly what a skill file is for. Here is a complete regulatory change impact assessment skill, the five prompts that build your team's own version, and how to install it in ChatGPT and Claude.

Read article
Bordeaux Place De La Bourse Dusk
GRCRegulatory analysis·

Your Website AI Assistant Is Someone Else's Code

On 24 June 2026 the Privacy Commissioner published two determinations finding that health providers interfered with privacy by letting third-party tracking pixels collect sensitive information from their websites. The reasoning is not about pixels. It is about who owns third-party code running on a page you control, and the fastest growing category of that code is an AI assistant your customers type into.

Read article
Strasbourg Petite France Dusk
GRCRegulatory analysis·

A New AI Office Is Not a New AI Obligation

On 15 July 2026 the Commonwealth stood up an Office of AI inside the Department of the Prime Minister and Cabinet and announced a set of Australian Standards for AI. Commentary read it as Australia regulating AI. It is machinery, a standards process and a first target aimed at large data centres. Nothing announced binds how a regulated business uses AI today, and saying otherwise to a board is its own risk.

Read article
Riyadh Kafd Financial Dusk
GRCAI Governance·

Canberra's AI Register Mandate Is a Preview

The Australian Government has made an AI use-case register mandatory for its own agencies. For private-sector GRC teams building registers under CPS 230, the government template is a working preview worth studying now.

Read article
Valencia City Of Arts Dusk
GRCRegulatory analysis·

FAR Eased Up. Your AI Map Still Holds

ASIC and APRA are trimming FAR reporting from 16 June 2026. The accountability behind your AI use-case register has not moved. The practical change is what you actively maintain versus what you only produce on request.

Read article
Quebec City Old Port Blue Hour
GRCRegulatory analysis·

Agentic Trading and the Purpose Problem

In REP 835, ASIC published the gap in its own enforcement model: agentic trading systems are hard to assess through traditional notions of trader intent. Read as a hole in Australian law, that is imprecise. Our core prohibitions are drafted on effect, and the High Court has already said a sole or dominant purpose is not necessary. But purpose has not disappeared. It has moved to the people who deployed the system.

Read article
Bergen Bryggen Wharf Dusk
GRCRegulatory analysis·

Super Trustees, AI and the Discretion You Cannot Delegate

APRA has put superannuation trustees inside its AI expectations and wants human involvement for high-risk decisions. The harder limit is statutory. A trustee's core discretions are owed personally to members under the SIS Act, and the money spent buying the AI has to clear the best financial interests duty. Here is how to tell a decision AI can support from one it must never make.

Read article
Naples Lungomare Dusk
GRCAI Governance·

Freed Board Bandwidth Is for AI Oversight

APRA's draft CPS 510, released 16 June 2026, consolidates five governance standards and cuts duplicative fit-and-proper paperwork for around 6,000 people. Read with APRA's April AI letter, the freed board capacity has an obvious destination: AI oversight.

Read article
Rome Tiber St Peters Dusk
GRCRegulatory analysis·

Governing AI Agents Before the Consumer Data Right Lets Them Act

The Consumer Data Right is gaining write access. Once actions are designated, an accredited provider, or an AI agent behind it, could initiate payments and switch products on a consumer's instruction. The controls for agent-initiated actions are far cheaper to build now, before any money can move.

Read article
Kalgoorlie Hannan Street Dusk
GRCRegulatory analysis·

Australia Will Not Pass an AI Act. You Are Still Regulated.

The National AI Plan settled the question every GRC team was waiting on. Australia will not pass a standalone AI Act. That is not a reprieve. It means AI is already regulated, spread across the laws and regulators you answer to now. Here is how to stop waiting for an AI law and map every AI use to the obligation it already touches.

Read article
Marseille Vieux Port Blue Hour
GRCRegulatory analysis·

AI Wrote the Ad. ASIC Still Holds You to It.

ASIC refreshed its advertising guide for the first time since 2012, and it now reaches AI-generated advertising and the capability claims firms make about their AI-enabled tools. The medium is no defence. Here is what AI-washing looks like, what RG 234 now expects, and the marketing controls to put in place before the next campaign ships.

Read article
Atlanta Midtown Skyline Dusk
GRCMarket intelligence·

The 2026 AI Governance Talent Market: Assurance Skills Move to the Core

Australia's AI governance market is shifting from principle-setting towards assurance: control design, model testing, data lineage, third-party oversight and evidence a board or auditor can challenge. APRA has named the skills gap, no salary guide prices the role cleanly, and the scarce profile is the practitioner who can move from principle to proof.

Read article
Charlotte Uptown Financial Dusk
GRCRegulatory analysis·

Your Pricing Agent Is Still Your Competition Risk

An AI pricing agent does not sit outside Australian competition law. Businesses must still set prices independently, prevent unlawful competitor coordination and control the data, objectives and vendors shaping every recommendation. Here is the cartel-law map, the five questions GRC must ask and the evidence pack to build before go-live.

Read article
Ottawa Parliament Hill Dusk
GRCRegulatory analysis·

AI in Complaints Handling: What RG 271 Reserves for a Person

Financial firms are putting AI into the exact process ASIC made enforceable in RG 271. AI can triage, summarise and draft a complaint response, but the 30 day clock, the reasons, the systemic issue call and the fairness of the outcome stay with a person. Here is the obligation map, a worked example and the prompts to build your own.

Read article
Prague Old Town Vltava Dusk
GRCRegulatory analysis·

CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors

From 1 July 2026, pre-existing contracts with material service providers must meet APRA's CPS 230, and a growing share of those arrangements are now AI. Here is the work to do before the deadline, plus a reusable contract-review prompt.

Read article
Brussels Financial Quarter Blue Hour
GRCRegulatory analysis·

The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands

Treasury's exposure-draft codes for the Scams Prevention Framework set a technology-neutral reasonable-steps duty on banks, telcos and digital platforms. The scams it targets are now AI-generated, which raises the bar and creates a second duty: govern the detection AI you deploy to meet the first.

Read article
Warsaw Financial District Blue Hour
GRCRegulatory analysis·

AUSTRAC Just Put AI Risk Into Your AML Program Documents

On 19 June 2026 AUSTRAC updated the program starter kit documents that reporting entities build their AML/CTF programs from, adding artificial intelligence to the risk information. If you built your program before that date, your risk assessment is now out of step with the regulator's.

Read article
Doha West Bay Financial Dusk
GRCRegulatory analysis·

AML Tranche 2: What AI Can and Cannot Do for Your New Program

From 1 July 2026, tens of thousands of lawyers, accountants, real estate agents and dealers in precious metals become AML regulated for the first time. AI can help them stand up a program fast. It cannot own the risk-based judgement AUSTRAC will hold them to.

Read article
Luxembourg Kirchberg Financial Dusk
GRCRegulatory analysis·

Automated Decisions Now Belong in Your Privacy Policy

From 10 December 2026, APP entities that use personal information in automated decisions affecting people's rights must say so in their privacy policy. For Australian financial services, that is most of the AI already running in underwriting, fraud, collections and claims. Here is the readiness work, with a reusable AI project, prompt library and a worked insurer example.

Read article
Seoul Gangnam Financial Blue Hour
GRCOperational Risk·

Build an Offline GRC Controls Console Without Creating Shadow IT

A single-file controls console can sharpen evidence review without leaking data. Treat it as a governed end-user computing tool, not a free win.

Read article
Edinburgh Old Town Blue Hour
GRCRegulatory analysis·

AI in Internal Audit: What Still Counts as Evidence

Internal audit functions are adopting AI faster than they are writing the rules for their own use of it. The IIA's 2024 Standards never mention artificial intelligence, yet every evidence, documentation and objectivity requirement still applies to AI-assisted audit work.

Read article
Geneva Lake Jet Deau Dusk
GRCAI Governance·

Build an AI Use Case Register That Boards Can Actually Use

Practical guidance for GRC teams to create AI use case registers that deliver clear, decision-ready evidence for boards and risk committees.

Read article
Chicago Riverwalk Financial Blue Hour
GRCOperational Risk·

AI Cyber Risk Is Now a Board Governance Issue

ASIC's May 2026 cyber uplift warning highlights that AI-driven cyber risk demands active board and risk committee oversight, not just IT fixes. This article outlines a practical governance operating model for GRC teams.

Read article
Brisbane Cbd Night
GRCAssurance·

From Voluntary AI Guardrails to Audit Evidence

Australia's voluntary AI guardrails only become useful when GRC teams translate them into control objectives, artefacts and assurance tests.

Read article
Melbourne Southbank Night
GRCOperational Risk·

AI Incident Response Needs an Evidence Pack, Not Just a Playbook

Prompt injection, data leakage and agentic failures require GRC teams to rethink incident response evidence, escalation and assurance.

Read article
Sydney Cbd Towers
GRCAI Governance·

Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have

APRA's April 2026 AI letter signals that board AI literacy is becoming a governance control expectation, not a generic awareness exercise.

Read article
Singapore
GRCRegulatory analysis·

ASIC's AI Supervisory Posture, Decoded

ASIC's posture on AI in financial services is now visible across REP 798, the 2026 Key Issues Outlook, and recent statements from the Chair. Five themes shape supervisory expectation, and three create immediate work for compliance teams.

Read article

Regulatory Updates

Tracking the regulators

Active coverage. In-depth analysis of ASIC AI guidance, AML/CTF reform implications, DDO and AI-assisted product recommendations, and CPS 234 vendor due diligence is published above. Quarterly GRC talent market reports and a dedicated AML/CTF supervisory engagement piece are in development. New analysis posts here as it's published.

Browse all GRC analysis