Regulatory Frameworks
APRA / CPS 230
Operational Risk Management: AI system governance obligations
FAR
Financial Accountability Regime: accountability for AI-assisted decisions
ASIC
Consumer protection obligations and AI disclosure requirements
AML/CTF
Anti-money laundering and AI-assisted transaction monitoring
DDO
Design and Distribution Obligations: AI in product recommendations
CPS 234
Information Security: cybersecurity governance for AI systems
Analysis
GRC Intelligence

Your Resilience Documents Pass. Your Exercise Might Not.
APRA and ASIC have released the notes from their June superannuation CEO roundtables. The line worth acting on is that participants said crisis exercises often reveal governance, delegation and communication issues that documentation alone may not surface. Here is how to design one for an operation that now contains agents.
Read article
APRA's New Plan Asks Two AI Questions. Your Register Answers One.
APRA published its 2026-27 Corporate Plan on 20 August 2026. Under a single supervision priority it puts AI in two places, under two separate headings, meaning two different things. Most AI risk registers are built to answer only the first of them, and the second arrives with a dated cryptography deadline attached.
Read article
A Gate Your Customer Can Retry Is Not a Control
On 13 August 2026 ASIC published surveillance findings against nine named online brokers, including onboarding questionnaires that allowed repeated or unlimited attempts to pass. The same defect drew a $10 million penalty in March 2026. The design question generalises to every automated eligibility gate an organisation operates, and it gets sharper when the customer has an agent.
Read article
Your AI Drew the Control Map. Now Prove It Is Complete.
On 18 August 2026 APRA imposed licence conditions on Bendigo and Adelaide Bank after an independent root cause analysis found the bank did not have a clear, complete and reliable view of its regulatory obligations, material risks and key controls. Completeness is now inside an enforcement outcome, and it is the one property an AI-generated map cannot supply for itself.
Read article
The Weakness Was Found in 2020. Exploited in 2023.
On 11 August 2026 APRA announced that Bendigo and Adelaide Bank had admitted breaching its accountability obligations over a 2023 cyber incident, with an agreed $8 million penalty. The detail that generalises to AI controls is not the attack. It is that the weaknesses had been identified in penetration testing in 2020 and were still open when they were exploited.
Read article
Your Menu Outgrew Your Team. AI Buys Coverage, Not Capability.
On 19 August 2026 APRA said it will consult in September on reforms across eight areas of investment management, including ensuring a trustee's investment management capability is commensurate to the complexity of its investment menu. AI answers the coverage half of that sentence and leaves the capability half exactly where it was.
Read article
Data Residency Does Not Settle APP 8 for Your AI Prompts.
An Australian hosting region answers one field on a form. APP 8 turns on the overseas recipient, what it can access and for what purpose, and whether your organisation released the information's subsequent handling from its effective control. Map each access path before approving personal information in an AI workflow.
Read article
Your AI Credit Score Is Not a Responsible Lending File.
A model can rank credit risk, reconcile application data and flag exceptions. It still cannot prove the inquiries, verification and customer-specific suitability assessment behind a lending decision. Build a customer-outcome file that preserves the evidence and the authorised human judgement.
Read article
The Board Signed the Risk Declaration. Can It Trace the AI Evidence?
AI can reconcile hundreds of attestations, tests and actions before a prudential risk declaration. It cannot make the declaration true. Give every claim a traceable source, every exception a visible route and every required signatory the evidence needed for genuine enquiry.
Read article
ASIC Asked for the File. Your AI Summary Is Not the Production.
An AI summary can help organise an ASIC request. It cannot replace responsive source records, settle the notice's scope or make a privilege claim. Build a request-to-source ledger that lets legal reviewers trace every request item to native material, exclusions, gaps and the human production decision.
Read article
Your AI Fallback Is Not a Recovery Plan.
Your recovery playbook fails if the tool meant to execute it disappears with the crisis. Test every AI-assisted action after removing the model, data pipeline, credentials and provider support. A fallback is credible only when people can still start, run and evidence the action.
Read article
Your AI Vendor Count Is Hiding One Foundation Model.
Three contracted AI vendors can still fail as one service when they share a foundation model, cloud control plane or identity layer. Map every service to its common technical roots, then test whether your nominated substitute survives the same failure.
Read article
AI Can Draft the APRA Warning Comment. It Cannot Sign Off the Return.
APRA Connect may accept an explanatory comment after a validation warning. That does not make the explanation true. Build every AI-drafted sentence from the return cell, source query, data owner, validation rule and named reviewer who accepts responsibility for submission.
Read article
AI Can Sort the Breach Queue. It Cannot Stop the 30-Day Clock.
AI can assemble evidence, connect similar incidents and challenge a preliminary assessment. It cannot decide when your licensee knew enough, whether a breach is significant or whether a report is due. Build the breach workflow around the statutory clock, not the model.
Read article
Your TMD Needs Customers Who Do Not Exist.
Synthetic personas can expose a target market that is too broad, a distribution condition that fails at the edge and a review trigger that never fires. Use counterfactual pairs as adversarial tests, and never mistake generated cases for evidence of real customer outcomes.
Read article
A Sanctions Alert Is Not Cleared Because the Model Says So.
AI can assemble aliases, identifiers, ownership clues and transaction context. It cannot turn a similarity score into legal clearance. Preserve the list version, evidence, unresolved questions, non-match reasoning and a named human approval for every material alert.
Read article
Let AI Maintain the Obligations Register. Make a Human Own Every Change.
AI can compare approved source versions and propose candidate regulatory changes. It cannot decide what binds your organisation. Make it propose source-linked deltas, then require a named human to accept the legal state, effective date and register change, with two clocks keeping the history honest.
Read article
Your GenAI Approval Needs an Expiry Trigger.
A GenAI approval records what passed on one date. It does not prove the live system still deserves approval. Build a living validation passport with explicit failure modes, change triggers, expiry and a human-controlled stop-use rule, and keep the four regulatory layers behind it separate.
Read article
Defensible AI Lineage Starts Before the Prompt.
A citation beside an AI answer is not data lineage. You need the source snapshot, transformations, retrieved context, prompt, available model configuration, raw output and human edits. Without that packet, assurance starts after the evidence trail has already broken.
Read article
Do Not Put a Whistleblower Disclosure Into Your General AI Tool
A whistleblower disclosure is not ordinary case data. Section 1317AAE of the Corporations Act protects the discloser's identity and anything likely to identify them. Keep the raw account inside the protected whistleblower environment, and let AI assist only with a deliberately reduced control record that an authorised human has cleared for use.
Read article
Your AI Risk Register Maps the Regulator. It Misses the Plaintiff.
Australia's statutory tort for serious invasions of privacy gives individuals a direct cause of action that runs on different rules to the Australian Privacy Principles. Most AI risk registers do not carry it.
Read article
Your AI Vendor's Breach Starts Your Clock
On 6 July 2026 the OAIC reported the highest number of data breach notifications since the scheme began. Meanwhile organisations have quietly handed personal information to a new class of provider. Under the Privacy Act you hold what your AI provider possesses if you control it, which means the assessment clock and the notification are yours, not theirs.
Read article
Skill Files Are Controlled Documents. Treat Them Like It
The moment a skill file shapes work a regulator cares about, it stops being a personal productivity hack and becomes a controlled document. Version numbers and change logs inside the file, a named owner and approver, retained test evidence, reviews triggered by obligation changes, and a register of approved skills. Here is the discipline, anchored by a board-reporting skill your risk team can adapt today.
Read article
A Skill File for Regulatory Change: Impact Assessment On Demand
Every regulator release triggers the same scramble: read it, work out what it touches, brief the owners. The release changes every time. The method does not, and a stable method is exactly what a skill file is for. Here is a complete regulatory change impact assessment skill, the five prompts that build your team's own version, and how to install it in ChatGPT and Claude.
Read article
Your Website AI Assistant Is Someone Else's Code
On 24 June 2026 the Privacy Commissioner published two determinations finding that health providers interfered with privacy by letting third-party tracking pixels collect sensitive information from their websites. The reasoning is not about pixels. It is about who owns third-party code running on a page you control, and the fastest growing category of that code is an AI assistant your customers type into.
Read article
A New AI Office Is Not a New AI Obligation
On 15 July 2026 the Commonwealth stood up an Office of AI inside the Department of the Prime Minister and Cabinet and announced a set of Australian Standards for AI. Commentary read it as Australia regulating AI. It is machinery, a standards process and a first target aimed at large data centres. Nothing announced binds how a regulated business uses AI today, and saying otherwise to a board is its own risk.
Read article
Canberra's AI Register Mandate Is a Preview
The Australian Government has made an AI use-case register mandatory for its own agencies. For private-sector GRC teams building registers under CPS 230, the government template is a working preview worth studying now.
Read article
FAR Eased Up. Your AI Map Still Holds
ASIC and APRA are trimming FAR reporting from 16 June 2026. The accountability behind your AI use-case register has not moved. The practical change is what you actively maintain versus what you only produce on request.
Read article
Agentic Trading and the Purpose Problem
In REP 835, ASIC published the gap in its own enforcement model: agentic trading systems are hard to assess through traditional notions of trader intent. Read as a hole in Australian law, that is imprecise. Our core prohibitions are drafted on effect, and the High Court has already said a sole or dominant purpose is not necessary. But purpose has not disappeared. It has moved to the people who deployed the system.
Read article
Super Trustees, AI and the Discretion You Cannot Delegate
APRA has put superannuation trustees inside its AI expectations and wants human involvement for high-risk decisions. The harder limit is statutory. A trustee's core discretions are owed personally to members under the SIS Act, and the money spent buying the AI has to clear the best financial interests duty. Here is how to tell a decision AI can support from one it must never make.
Read article
Freed Board Bandwidth Is for AI Oversight
APRA's draft CPS 510, released 16 June 2026, consolidates five governance standards and cuts duplicative fit-and-proper paperwork for around 6,000 people. Read with APRA's April AI letter, the freed board capacity has an obvious destination: AI oversight.
Read article
Governing AI Agents Before the Consumer Data Right Lets Them Act
The Consumer Data Right is gaining write access. Once actions are designated, an accredited provider, or an AI agent behind it, could initiate payments and switch products on a consumer's instruction. The controls for agent-initiated actions are far cheaper to build now, before any money can move.
Read article
Australia Will Not Pass an AI Act. You Are Still Regulated.
The National AI Plan settled the question every GRC team was waiting on. Australia will not pass a standalone AI Act. That is not a reprieve. It means AI is already regulated, spread across the laws and regulators you answer to now. Here is how to stop waiting for an AI law and map every AI use to the obligation it already touches.
Read article
AI Wrote the Ad. ASIC Still Holds You to It.
ASIC refreshed its advertising guide for the first time since 2012, and it now reaches AI-generated advertising and the capability claims firms make about their AI-enabled tools. The medium is no defence. Here is what AI-washing looks like, what RG 234 now expects, and the marketing controls to put in place before the next campaign ships.
Read article
The 2026 AI Governance Talent Market: Assurance Skills Move to the Core
Australia's AI governance market is shifting from principle-setting towards assurance: control design, model testing, data lineage, third-party oversight and evidence a board or auditor can challenge. APRA has named the skills gap, no salary guide prices the role cleanly, and the scarce profile is the practitioner who can move from principle to proof.
Read article
Your Pricing Agent Is Still Your Competition Risk
An AI pricing agent does not sit outside Australian competition law. Businesses must still set prices independently, prevent unlawful competitor coordination and control the data, objectives and vendors shaping every recommendation. Here is the cartel-law map, the five questions GRC must ask and the evidence pack to build before go-live.
Read article
AI in Complaints Handling: What RG 271 Reserves for a Person
Financial firms are putting AI into the exact process ASIC made enforceable in RG 271. AI can triage, summarise and draft a complaint response, but the 30 day clock, the reasons, the systemic issue call and the fairness of the outcome stay with a person. Here is the obligation map, a worked example and the prompts to build your own.
Read article
CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors
From 1 July 2026, pre-existing contracts with material service providers must meet APRA's CPS 230, and a growing share of those arrangements are now AI. Here is the work to do before the deadline, plus a reusable contract-review prompt.
Read article
The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands
Treasury's exposure-draft codes for the Scams Prevention Framework set a technology-neutral reasonable-steps duty on banks, telcos and digital platforms. The scams it targets are now AI-generated, which raises the bar and creates a second duty: govern the detection AI you deploy to meet the first.
Read article
AUSTRAC Just Put AI Risk Into Your AML Program Documents
On 19 June 2026 AUSTRAC updated the program starter kit documents that reporting entities build their AML/CTF programs from, adding artificial intelligence to the risk information. If you built your program before that date, your risk assessment is now out of step with the regulator's.
Read article
AML Tranche 2: What AI Can and Cannot Do for Your New Program
From 1 July 2026, tens of thousands of lawyers, accountants, real estate agents and dealers in precious metals become AML regulated for the first time. AI can help them stand up a program fast. It cannot own the risk-based judgement AUSTRAC will hold them to.
Read article
Automated Decisions Now Belong in Your Privacy Policy
From 10 December 2026, APP entities that use personal information in automated decisions affecting people's rights must say so in their privacy policy. For Australian financial services, that is most of the AI already running in underwriting, fraud, collections and claims. Here is the readiness work, with a reusable AI project, prompt library and a worked insurer example.
Read article
Build an Offline GRC Controls Console Without Creating Shadow IT
A single-file controls console can sharpen evidence review without leaking data. Treat it as a governed end-user computing tool, not a free win.
Read article
AI in Internal Audit: What Still Counts as Evidence
Internal audit functions are adopting AI faster than they are writing the rules for their own use of it. The IIA's 2024 Standards never mention artificial intelligence, yet every evidence, documentation and objectivity requirement still applies to AI-assisted audit work.
Read article
Build an AI Use Case Register That Boards Can Actually Use
Practical guidance for GRC teams to create AI use case registers that deliver clear, decision-ready evidence for boards and risk committees.
Read article
AI Cyber Risk Is Now a Board Governance Issue
ASIC's May 2026 cyber uplift warning highlights that AI-driven cyber risk demands active board and risk committee oversight, not just IT fixes. This article outlines a practical governance operating model for GRC teams.
Read article
From Voluntary AI Guardrails to Audit Evidence
Australia's voluntary AI guardrails only become useful when GRC teams translate them into control objectives, artefacts and assurance tests.
Read article
AI Incident Response Needs an Evidence Pack, Not Just a Playbook
Prompt injection, data leakage and agentic failures require GRC teams to rethink incident response evidence, escalation and assurance.
Read article
Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have
APRA's April 2026 AI letter signals that board AI literacy is becoming a governance control expectation, not a generic awareness exercise.
Read article
ASIC's AI Supervisory Posture, Decoded
ASIC's posture on AI in financial services is now visible across REP 798, the 2026 Key Issues Outlook, and recent statements from the Chair. Five themes shape supervisory expectation, and three create immediate work for compliance teams.
Read articleRegulatory Updates
Tracking the regulators
Active coverage. In-depth analysis of ASIC AI guidance, AML/CTF reform implications, DDO and AI-assisted product recommendations, and CPS 234 vendor due diligence is published above. Quarterly GRC talent market reports and a dedicated AML/CTF supervisory engagement piece are in development. New analysis posts here as it's published.
Browse all GRC analysisTools
Practical instruments
AI Readiness Assessment
Bespoke question banks for GRC analysts, governance managers, and compliance and audit professionals.
AI Tool Comparison
Side-by-side comparison of major AI tools with criteria weighted for GRC use cases.
Microsoft 365 Copilot Configuration
A ready-to-paste Copilot set-up for GRC practice: instruction text, files to attach, first prompts, and what never goes in, verified against Microsoft's documentation.
Governance Scorecard
A dedicated AI governance maturity self-assessment against APRA CPS 230 and CPS 234 is in development. In the meantime, the AI Readiness Assessment includes GRC paths covering analyst, governance manager, and compliance and audit roles.
Interactive tools



