Home/GRC

GRC

AI in Governance, Risk & Compliance

Practical intelligence on AI developments across APRA, ASIC, FAR, AML/CTF, DDO, and CPS 230 for compliance and risk professionals in Australian financial services.

APRAASICFARAML/CTF

Intelligence, At Your Command.

Analysis

GRC Intelligence

Bordeaux Place De La Bourse Dusk
GRCRegulatory analysis·

Your Website AI Assistant Is Someone Else's Code

On 24 June 2026 the Privacy Commissioner published two determinations finding that health providers interfered with privacy by letting third-party tracking pixels collect sensitive information from their websites. The reasoning is not about pixels. It is about who owns third-party code running on a page you control, and the fastest growing category of that code is an AI assistant your customers type into.

Read article
Strasbourg Petite France Dusk
GRCRegulatory analysis·

A New AI Office Is Not a New AI Obligation

On 15 July 2026 the Commonwealth stood up an Office of AI inside the Department of the Prime Minister and Cabinet and announced a set of Australian Standards for AI. Commentary read it as Australia regulating AI. It is machinery, a standards process and a first target aimed at large data centres. Nothing announced binds how a regulated business uses AI today, and saying otherwise to a board is its own risk.

Read article
Riyadh Kafd Financial Dusk
GRCAI Governance·

Canberra's AI Register Mandate Is a Preview

The Australian Government has made an AI use-case register mandatory for its own agencies. For private-sector GRC teams building registers under CPS 230, the government template is a working preview worth studying now.

Read article
Valencia City Of Arts Dusk
GRCRegulatory analysis·

FAR Eased Up. Your AI Map Still Holds

ASIC and APRA are trimming FAR reporting from 16 June 2026. The accountability behind your AI use-case register has not moved. The practical change is what you actively maintain versus what you only produce on request.

Read article
Quebec City Old Port Blue Hour
GRCRegulatory analysis·

Agentic Trading and the Purpose Problem

In REP 835, ASIC published the gap in its own enforcement model: agentic trading systems are hard to assess through traditional notions of trader intent. Read as a hole in Australian law, that is imprecise. Our core prohibitions are drafted on effect, and the High Court has already said a sole or dominant purpose is not necessary. But purpose has not disappeared. It has moved to the people who deployed the system.

Read article
Bergen Bryggen Wharf Dusk
GRCRegulatory analysis·

Super Trustees, AI and the Discretion You Cannot Delegate

APRA has put superannuation trustees inside its AI expectations and wants human involvement for high-risk decisions. The harder limit is statutory. A trustee's core discretions are owed personally to members under the SIS Act, and the money spent buying the AI has to clear the best financial interests duty. Here is how to tell a decision AI can support from one it must never make.

Read article
Naples Lungomare Dusk
GRCAI Governance·

Freed Board Bandwidth Is for AI Oversight

APRA's draft CPS 510, released 16 June 2026, consolidates five governance standards and cuts duplicative fit-and-proper paperwork for around 6,000 people. Read with APRA's April AI letter, the freed board capacity has an obvious destination: AI oversight.

Read article
Rome Tiber St Peters Dusk
GRCRegulatory analysis·

Governing AI Agents Before the Consumer Data Right Lets Them Act

The Consumer Data Right is gaining write access. Once actions are designated, an accredited provider, or an AI agent behind it, could initiate payments and switch products on a consumer's instruction. The controls for agent-initiated actions are far cheaper to build now, before any money can move.

Read article
Kalgoorlie Hannan Street Dusk
GRCRegulatory analysis·

Australia Will Not Pass an AI Act. You Are Still Regulated.

The National AI Plan settled the question every GRC team was waiting on. Australia will not pass a standalone AI Act. That is not a reprieve. It means AI is already regulated, spread across the laws and regulators you answer to now. Here is how to stop waiting for an AI law and map every AI use to the obligation it already touches.

Read article
Marseille Vieux Port Blue Hour
GRCRegulatory analysis·

AI Wrote the Ad. ASIC Still Holds You to It.

ASIC refreshed its advertising guide for the first time since 2012, and it now reaches AI-generated advertising and the capability claims firms make about their AI-enabled tools. The medium is no defence. Here is what AI-washing looks like, what RG 234 now expects, and the marketing controls to put in place before the next campaign ships.

Read article
Atlanta Midtown Skyline Dusk
GRCMarket intelligence·

The 2026 AI Governance Talent Market: Assurance Skills Move to the Core

Australia's AI governance market is shifting from principle-setting towards assurance: control design, model testing, data lineage, third-party oversight and evidence a board or auditor can challenge. APRA has named the skills gap, no salary guide prices the role cleanly, and the scarce profile is the practitioner who can move from principle to proof.

Read article
Charlotte Uptown Financial Dusk
GRCRegulatory analysis·

Your Pricing Agent Is Still Your Competition Risk

An AI pricing agent does not sit outside Australian competition law. Businesses must still set prices independently, prevent unlawful competitor coordination and control the data, objectives and vendors shaping every recommendation. Here is the cartel-law map, the five questions GRC must ask and the evidence pack to build before go-live.

Read article
Ottawa Parliament Hill Dusk
GRCRegulatory analysis·

AI in Complaints Handling: What RG 271 Reserves for a Person

Financial firms are putting AI into the exact process ASIC made enforceable in RG 271. AI can triage, summarise and draft a complaint response, but the 30 day clock, the reasons, the systemic issue call and the fairness of the outcome stay with a person. Here is the obligation map, a worked example and the prompts to build your own.

Read article
Prague Old Town Vltava Dusk
GRCRegulatory analysis·

CPS 230's 1 July Deadline Just Caught Up With Your AI Vendors

From 1 July 2026, pre-existing contracts with material service providers must meet APRA's CPS 230, and a growing share of those arrangements are now AI. Here is the work to do before the deadline, plus a reusable contract-review prompt.

Read article
Brussels Financial Quarter Blue Hour
GRCRegulatory analysis·

The Scams Prevention Framework Meets AI: What 'Reasonable Steps' Now Demands

Treasury's exposure-draft codes for the Scams Prevention Framework set a technology-neutral reasonable-steps duty on banks, telcos and digital platforms. The scams it targets are now AI-generated, which raises the bar and creates a second duty: govern the detection AI you deploy to meet the first.

Read article
Warsaw Financial District Blue Hour
GRCRegulatory analysis·

AUSTRAC Just Put AI Risk Into Your AML Program Documents

On 19 June 2026 AUSTRAC updated the program starter kit documents that reporting entities build their AML/CTF programs from, adding artificial intelligence to the risk information. If you built your program before that date, your risk assessment is now out of step with the regulator's.

Read article
Doha West Bay Financial Dusk
GRCRegulatory analysis·

AML Tranche 2: What AI Can and Cannot Do for Your New Program

From 1 July 2026, tens of thousands of lawyers, accountants, real estate agents and dealers in precious metals become AML regulated for the first time. AI can help them stand up a program fast. It cannot own the risk-based judgement AUSTRAC will hold them to.

Read article
Luxembourg Kirchberg Financial Dusk
GRCRegulatory analysis·

Automated Decisions Now Belong in Your Privacy Policy

From 10 December 2026, APP entities that use personal information in automated decisions affecting people's rights must say so in their privacy policy. For Australian financial services, that is most of the AI already running in underwriting, fraud, collections and claims. Here is the readiness work, with a reusable AI project, prompt library and a worked insurer example.

Read article
Seoul Gangnam Financial Blue Hour
GRCOperational Risk·

Build an Offline GRC Controls Console Without Creating Shadow IT

A single-file controls console can sharpen evidence review without leaking data. Treat it as a governed end-user computing tool, not a free win.

Read article
Edinburgh Old Town Blue Hour
GRCRegulatory analysis·

AI in Internal Audit: What Still Counts as Evidence

Internal audit functions are adopting AI faster than they are writing the rules for their own use of it. The IIA's 2024 Standards never mention artificial intelligence, yet every evidence, documentation and objectivity requirement still applies to AI-assisted audit work.

Read article
Geneva Lake Jet Deau Dusk
GRCAI Governance·

Build an AI Use Case Register That Boards Can Actually Use

Practical guidance for GRC teams to create AI use case registers that deliver clear, decision-ready evidence for boards and risk committees.

Read article
Chicago Riverwalk Financial Blue Hour
GRCOperational Risk·

AI Cyber Risk Is Now a Board Governance Issue

ASIC's May 2026 cyber uplift warning highlights that AI-driven cyber risk demands active board and risk committee oversight, not just IT fixes. This article outlines a practical governance operating model for GRC teams.

Read article
Brisbane Cbd Night
GRCAssurance·

From Voluntary AI Guardrails to Audit Evidence

Australia's voluntary AI guardrails only become useful when GRC teams translate them into control objectives, artefacts and assurance tests.

Read article
Melbourne Southbank Night
GRCOperational Risk·

AI Incident Response Needs an Evidence Pack, Not Just a Playbook

Prompt injection, data leakage and agentic failures require GRC teams to rethink incident response evidence, escalation and assurance.

Read article
Sydney Cbd Towers
GRCAI Governance·

Board AI Literacy Is Now a Control Expectation, Not a Training Nice-to-Have

APRA's April 2026 AI letter signals that board AI literacy is becoming a governance control expectation, not a generic awareness exercise.

Read article
Singapore
GRCRegulatory analysis·

ASIC's AI Supervisory Posture, Decoded

ASIC's posture on AI in financial services is now visible across REP 798, the 2026 Key Issues Outlook, and recent statements from the Chair. Five themes shape supervisory expectation, and three create immediate work for compliance teams.

Read article
Zurich Limmat Old Town
GRCRegulatory analysis·

CPS 234 and AI Vendors: A Due Diligence Framework

CPS 234 has been in force since 2019. AI vendors stretch the framework in specific ways: training data exposure, model update opacity, and inference infrastructure that crosses the standard's information asset boundaries. A practical due diligence framework.

Read article
Adelaide King William St
GRCRegulatory analysis·

FAR and AI: How Accountability Maps to Tooling Decisions

The Financial Accountability Regime makes specific senior executives answerable for the systems and decisions inside their portfolios. AI tooling decisions sit inside that accountability, whether they are formally documented in the responsibility map or not.

Read article
Frankfurt
GRCRegulatory analysis·

AML/CTF and Large Language Models: A Compliance View

Large language models are now embedded across AML/CTF programs, from suspicious matter triage to KYC document review. AUSTRAC's posture on these uses is shaping. Reporting entities need a clear governance position now, not later.

Read article
Rotterdam
GRCRegulatory analysis·

DDO and AI-Driven Personalisation: Where the Boundary Sits

AI personalisation is moving fast inside Australian financial services. The Design and Distribution Obligations were not written with adaptive recommendation engines in mind. The boundary between targeting and personal advice is the line GRC teams need to govern.

Read article
London
GRCRegulatory analysis·

APRA's Model Risk Thematic Review: What to Expect

APRA's model risk thematic review is expected to land in the second half of 2026. The signals from supervisory engagement to date suggest where it will press hardest, and what regulated entities should be doing now.

Read article
Oslo
GRCRegulatory analysis·

CPS 230 and AI: A Practical Operational Resilience Playbook

CPS 230 has been live since 1 July 2025. Nine months in, the practical question for boards and operational risk teams is no longer whether AI tools fall inside the standard. It is how to evidence it.

Read article

Regulatory Updates

Tracking the regulators

Active coverage. In-depth analysis of ASIC AI guidance, AML/CTF reform implications, DDO and AI-assisted product recommendations, and CPS 234 vendor due diligence is published above. Quarterly GRC talent market reports and a dedicated AML/CTF supervisory engagement piece are in development. New analysis posts here as it's published.

Browse all GRC analysis

Tools

Practical instruments

AI Readiness Assessment

Bespoke question banks for GRC analysts, governance managers, and compliance and audit professionals.

AI Tool Comparison

Side-by-side comparison of major AI tools with criteria weighted for GRC use cases.

Governance Scorecard

A dedicated AI governance maturity self-assessment against APRA CPS 230 and CPS 234 is in development. In the meantime, the AI Readiness Assessment includes GRC paths covering analyst, governance manager, and compliance and audit roles.