AI Can Draft the APRA Warning Comment. It Cannot Sign Off the Return., practitioner guidance from TheAICommand
← GRC
Regulatory analysis

AI Can Draft the APRA Warning Comment. It Cannot Sign Off the Return.

APRA Connect may accept an explanatory comment after a validation warning. That does not make the explanation true. Build every AI-drafted sentence from the return cell, source query, data owner, validation rule and named reviewer who accepts responsibility for submission.

·monthly

GRC content. Written for compliance, risk, and audit professionals in Australian financial services. General information. Not legal or compliance advice.

Quick answer

No. APRA Connect may accept an explanatory comment after a validation warning, but completion is not an assurance opinion. Build a cell-to-sentence evidence chain: every factual clause traces to the return cell, validation rule, source query and data-owner confirmation, and a named human reviewer accepts the wording before any authorised submission.

APRA Connect may accept an explanatory comment after a validation warning. That does not make the explanation true. Build every AI-drafted sentence from the return cell, source query, data owner, validation rule and named reviewer who accepts responsibility for submission.

An AI assistant can draft a warning comment from an evidence pack. It must not invent a variance cause, infer accuracy, clear a validation or decide the return is ready.

The control you need is a cell-to-sentence evidence chain. Every factual clause in the draft should point back to the exact return cell, the query that produced or checked it, the data owner who confirmed the source, the validation rule that triggered and the human reviewer who accepted the final wording.

That chain is a proposed internal control from TheAICommand. APRA does not prescribe a field set called a cell-to-sentence evidence chain. It does, however, publish requirements and guidance that make traceability, reliable data, validation and properly assigned human authority material to prudential reporting.

What is a warning comment actually doing?

APRA Connect separates technical workflow states from the truth of the information. APRA's support material, last updated 20 May 2026, says a return marked Complete has all required fields populated and is ready for submission, while Submitted is a separate status. Completion is not an assurance opinion.

APRA's APRA Connect Guide, version 9.0, May 2026 distinguishes errors from warnings. An error is mandatory and must be corrected and revalidated; a return with an error cannot be submitted. A warning flags a discrepancy or abnormal variation that may still be correct. All warnings require a response, and retained data needs an explanatory comment. Revised data must be validated again. A warning is a question to resolve, not a licence to explain away a number.

On its support material page, APRA also advises against making manual changes to uploaded files because that removes the traceability of changes for both the organisation and APRA. It encourages entities to resolve issues in their source systems or source files so that sign-off and verification processes can operate. This is the right design cue for AI: draft from controlled evidence, never patch the return or manufacture a narrative around an unexplained result.

The legal setting reinforces the distinction. The current Financial Sector (Collection of Data) Act 2001, compilation C2025C00113 from 21 February 2025, permits APRA reporting standards to address the form and content of reporting documents, their auditing, the people who sign them and when they must be provided. Section 13(9) requires an entity to comply with a requirement under a reporting standard to give a reporting document to APRA before a particular time or within a particular period. Section 17 also allows APRA to request an explanation or information where it considers a document incorrect, incomplete, misleading, non-compliant or inadequately informative.

If evidence confirms the value, the comment should explain why the rule triggered and why the value is retained. If evidence does not support it, correct the source or source file and revalidate instead. A polished sentence without proof is an unsupported assertion.

Where does human authority sit?

The applicable reporting standard and sector framework determine the required submission, signature and assurance arrangements. Do not convert sector-specific prudential standards into one generic sign-off rule.

For ADIs, APS 310 Audit and Related Matters, in force from 1 January 2023, sets responsibilities for appointed-auditor reporting on specified APRA data collections and controls. The assurance treatment depends on whether information is sourced from accounting records, non-accounting records or both. Its Attachment A is expressly not a complete list of ADI collections. It lists the forms subject to audit testing for APS 310 purposes.

For general insurers, GPS 310 Audit and Related Matters, in force from 1 October 2024, contains return-specific assurance levels in Attachment E. It separately requires an annual Financial Information Declaration signed by the chief executive officer and chief financial officer, subject to its stated alternative where those roles are held by the same person.

For life companies, LPS 310 Audit and Related Matters, in force from 18 December 2023, requires the Auditor to report on annual returns identified in Attachment A. That attachment assigns reasonable, limited or no assurance by listed reporting standard. For RSE licensees, SPS 310 Audit and Related Matters, in force from 30 June 2024, assigns reasonable or limited assurance to specified reporting-standard information and requires limited assurance over relevant systems, procedures and internal controls.

Private health insurers sit under HPS 310 Audit and Related Matters, in force from 1 July 2023, which has its own annual-report and assurance requirements. Do not collapse that framework into the general or life insurance rules.

SectorStandardIn forceDistinctive assurance feature
ADIsAPS 3101 January 2023Assurance depends on accounting versus non-accounting record sources; Attachment A is not a complete list of collections
General insurersGPS 3101 October 2024Return-specific assurance in Attachment E plus a CEO and CFO Financial Information Declaration
Life companiesLPS 31018 December 2023Attachment A assigns reasonable, limited or no assurance by reporting standard
RSE licenseesSPS 31030 June 2024Reasonable or limited assurance plus limited assurance over systems, procedures and internal controls
Private health insurersHPS 3101 July 2023Its own annual-report and assurance structure

These differences matter. A model cannot provide appointed-auditor assurance, make a required declaration or become the person an applicable reporting standard requires to sign. It can assist the reporting team and authorised reviewers by organising evidence and drafting language. The relevant human remains responsible for enquiries, challenge and every internal authorisation, manual-submission, declaration or assurance role that applies.

For manual submission, APRA's May 2026 APRA Connect Guide gives Regulatory Reporting Administrator and Service Provider users Validate and Submit permission; a Regulatory Reporting Preparer can upload but not manually submit. Yet a clean uploaded return automatically submits by default regardless of uploader role. The Guide describes optional approval as an opt-in for individual entities; APRA's support material adds that it is available for selected collections and does not apply for corporate returns. Portal roles therefore do not supply a universal human gate. A pre-upload internal release gate is a proposed control where automatic submission can occur.

How do you build a cell-to-sentence evidence chain?

Start at the triggered rule, not at a blank chat window. Create one immutable evidence bundle for each warning or tightly related group of warnings, the same discipline that closes a sanctions alert with an evidence bundle rather than a model score. Give it a unique [EVIDENCE_BUNDLE_ID] and retain the return snapshot against which the validation ran.

The bundle should contain:

  • return identity, reporting period, reporting-standard version and submission version;
  • exact table, row, column, dimension member and cell value;
  • validation rule ID, rule text, severity, threshold and execution timestamp;
  • source query ID, approved code version, parameters, execution record and source-system snapshot;
  • reconciliation, control total or other validation result, including exceptions;
  • named data-owner role, confirmation, limitations and timestamp;
  • each draft claim linked to the evidence fields that support it;
  • human reviewer decision, edits, rationale and timestamp; and
  • final comment, return version and authorised submission record.
A luminous chain of five links from a return cell to a sentence of light
Five links from the cell to the sentence

This design adapts the principles in CPG 235 Managing Data Risk, which is prudential guidance rather than an enforceable standard. CPG 235 describes auditability as the ability to confirm data origin and make alterations transparent. It also discusses data lineage, documented validation, reconciliations, reasonableness review, clear accountabilities and audit trails. If your team cannot rebuild the inputs behind a model-assisted run, start with run lineage before automating commentary.

Use this prompt to produce a first draft from a locked evidence bundle. A reporting subject matter expert and the named data owner must verify every clause before the comment is approved or submitted.

Prompt
Draft an APRA Connect warning comment using only [EVIDENCE_BUNDLE_ID]. Do not infer a cause, confirm accuracy, clear the warning or recommend submission.

For each proposed sentence, return:
1. the sentence
2. [RETURN_CELL_ID] and reported value
3. [VALIDATION_RULE_ID] and trigger condition
4. [SOURCE_QUERY_ID] and reconciliation evidence
5. [DATA_OWNER_ROLE] confirmation
6. uncertainty or missing evidence

Then provide a concise proposed comment. Mark unsupported claims HUMAN REVIEW REQUIRED. End with the questions the human reviewer must resolve.

The sentence map is the important output. A comment such as "The movement reflects seasonal claims activity" contains at least two claims: there was a movement, and seasonal claims activity caused it. The first might be demonstrated by current and prior return cells. The second needs a query and owner-confirmed evidence that actually tests the cause. Correlation, a prior-period comment or a plausible model explanation is not enough.

Fictional worked example: Return [RETURN_ID] triggers warning [VALIDATION_RULE_ID] because cell [RETURN_CELL_ID] is [PERCENTAGE] above the comparison period. Query [SOURCE_QUERY_ID] reconciles the cell to source ledger [SOURCE_LEDGER_ID]. Data owner [DATA_OWNER_ROLE] confirms that [VERIFIED_DRIVER] explains [AMOUNT] of the variance, while [UNRESOLVED_AMOUNT] remains under investigation. The AI drafts two sentences. Reviewer [REVIEWER_ROLE] deletes the unsupported sentence about seasonality, retains the quantified driver, discloses the unresolved amount and records decision [REVIEW_DECISION_ID]. The example is fictional and does not establish that any real return should be submitted.

Before approval, apply this claim checklist:

  • every number names its return cell and reporting period;
  • every stated cause has query evidence and owner confirmation;
  • facts, estimates and professional judgements are separated;
  • unresolved differences and material limitations are visible;
  • the draft matches the return version actually being reviewed; and
  • a named human has accepted, edited or rejected each sentence.

Use this second prompt as a challenge step. The human reviewer must resolve every gap and decide whether the return needs correction, escalation or approval under the organisation's authority model.

Prompt
Red-team [DRAFT_WARNING_COMMENT] against [EVIDENCE_BUNDLE_ID]. Test each factual clause for a direct link to the return cell, validation rule, source query, data-owner confirmation and current return version.

Identify unsupported causation, omitted uncertainty, inconsistent figures, stale evidence and language that implies assurance or approval. Return PASS, REVISE or ESCALATE for each sentence with the missing evidence. Do not rewrite the return, clear the warning or decide submission.

Do this Monday

  1. Select one recurrent warning. Choose a rule that produces material commentary effort and has stable source data. Record the applicable reporting standard, return version and current human authority path.
  2. Define the bundle schema. Add cell, rule, query, owner, reconciliation, claim, reviewer and submission fields. Keep model metadata, but do not confuse a model log with return evidence.
  3. Remove free-form generation. Permit the assistant to draft only when the required evidence bundle is present. Block unsupported claims and outside-source retrieval.
  4. Run a back-test. Apply the chain to three prior warnings. Ask an experienced reporting reviewer to identify any sentence whose claimed cause cannot be reconstructed.
  5. Separate drafting from approval. Ensure the AI account cannot approve comments, alter source values, submit returns or act under a signatory's credentials.
  6. Test the hand-off. Confirm the final reviewer can move from each sentence to the exact cell, query output, owner confirmation and validation result without asking the preparer to rebuild the story.

Bottom line

AI can reduce the writing burden around APRA validation warnings. It cannot convert a plausible explanation into verified reporting evidence or assume a human declaration, submission or assurance role. Build the comment from a cell-to-sentence chain and make a named person challenge every claim. If the chain breaks, fix the data or escalate the uncertainty before anyone signs off the return.

This article is general information and education only. It is not legal, compliance, financial or professional advice. Obligations vary by organisation and circumstance. Verify current requirements against the primary sources cited and seek advice specific to your situation.

References

  1. Federal Register of Legislation, Financial Sector (Collection of Data) Act 2001, compilation C2025C00113, 21 February 2025. https://www.legislation.gov.au/C2004A00871/latest
  2. Australian Prudential Regulation Authority, APRA Connect support material, last updated 20 May 2026. https://www.apra.gov.au/apra-portals/apra-connect/apra-connect-support-material
  3. Australian Prudential Regulation Authority, CPG 235 Managing Data Risk. https://www.apra.gov.au/practice-guides/cpg-235
  4. Australian Prudential Regulation Authority, APS 310 Audit and Related Matters, in force 1 January 2023. https://www.apra.gov.au/standards/aps-310
  5. Australian Prudential Regulation Authority, GPS 310 Audit and Related Matters, in force 1 October 2024. https://www.apra.gov.au/standards/gps-310
  6. Australian Prudential Regulation Authority, LPS 310 Audit and Related Matters, in force 18 December 2023. https://www.apra.gov.au/standards/lps-310
  7. Australian Prudential Regulation Authority, SPS 310 Audit and Related Matters, in force 30 June 2024. https://www.apra.gov.au/standards/sps-310
  8. Australian Prudential Regulation Authority, HPS 310 Audit and Related Matters, in force 1 July 2023. https://www.apra.gov.au/standards/hps-310
  9. Australian Prudential Regulation Authority, APRA Connect Guide, version 9.0, May 2026. https://www.apra.gov.au/system/files/2026-05/APRA%20Connect%20Guide%20-%20Portal%20-%20May%202026%20%28V2%29%20%281%29.pdf

TheAICommand. Intelligence, At Your Command.

Frequently asked questions

What is the difference between an error and a warning in APRA Connect?
An error is mandatory: it must be corrected and revalidated, and a return containing an error cannot be submitted. A warning flags a discrepancy or abnormal variation that may still be correct. All warnings require a response, retained data needs an explanatory comment, and revised data must be validated again.
Does a Complete status mean the return is assured?
No. APRA's support material says a return marked Complete has all required fields populated and is ready for submission, while Submitted is a separate status. Completion is a technical workflow state, not an assurance opinion about the truth of the information.
Who must sign or assure prudential returns?
It depends on the sector framework. APS 310, GPS 310, LPS 310, SPS 310 and HPS 310 each set their own appointed-auditor assurance and declaration arrangements, from GPS 310's CEO and CFO Financial Information Declaration to SPS 310's limited assurance over systems, procedures and internal controls. A model cannot hold any of those roles.
Can a clean upload submit itself?
Yes, by default. The APRA Connect Guide says that when a complete data file is uploaded without validation errors or warnings, default functionality automatically submits the return regardless of the uploader's role. Portal roles therefore do not supply a universal human gate, which is why a pre-upload internal release gate is a sensible proposed control.
What is a cell-to-sentence evidence chain?
A proposed internal control from TheAICommand, not an APRA field set. Every factual clause in a draft warning comment points back to the exact return cell, the query that produced or checked it, the data owner who confirmed the source, the validation rule that triggered and the human reviewer who accepted the final wording. It adapts the auditability and lineage principles in CPG 235.

Context

APRA refreshed its Connect portal documentation in May 2026: the Guide version 9.0 and the support material page, updated 20 May 2026, together describe validation mechanics that matter for AI drafting, including the default behaviour that a clean uploaded return automatically submits regardless of the uploader's role. Teams automating commentary should read the portal mechanics before wiring in a model.

AI angle

A language model is very good at producing a plausible variance narrative, which is exactly the risk: "the movement reflects seasonal claims activity" contains a causal claim no reconciliation has tested. The control is not a better prompt but a locked evidence bundle, a sentence-by-sentence map from claim to cell, and a named human who accepts, edits or rejects each sentence before anything is submitted.

Primary sources

APRA ReportingData AssuranceAI GovernancePrudential ReportingFinancial Services
← Back to GRC

Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. Regulatory obligations vary by entity type, licence, and circumstance. Always refer to primary source guidance from APRA, ASIC, or the relevant regulatory authority.