Completeness is now inside an enforcement outcome.
On 18 August 2026 the Australian Prudential Regulation Authority imposed licence conditions on Bendigo and Adelaide Bank Limited, following what APRA described as findings of longstanding and pervasive weaknesses in the bank's non-financial risk management framework. Inside the independent root cause analysis behind that action sits one sentence that should change how every compliance function treats an AI-generated map. The bank, APRA reports, "does not have a clear, complete and reliable view of its regulatory obligations, material risks and key controls".
Read the adjectives slowly. Clear is a drafting standard. Reliable is a quality standard. Complete is neither. It is a claim about what is missing, and the one property a language model cannot supply for the map it just produced.
What did APRA actually impose?
APRA required the root cause analysis in December 2025, alongside a $50 million operational risk capital add-on, after a separate independent Deloitte review found significant deficiencies in the bank's approach to money laundering and terrorism financing risk. Deloitte has now completed the root cause analysis, in a report dated 24 June 2026. Among its findings are the absence of the clear, complete and reliable view quoted above, and that "key weaknesses have persisted despite several years of remediation activity" as part of the bank's enterprise-wide risk transformation program.
APRA's conclusion is stated plainly: it is not satisfied the bank has addressed the underlying root causes or delivered sustainable risk uplift, despite having had significant opportunity to do so. The conditions require a comprehensive rectification program, an engaged independent assurer, and board attestation. The $50 million add-on stays until APRA is satisfied.
The chain is worth stating precisely, because the registered instrument never uses the word complete. Conditions on banking authority 2026 Bendigo and Adelaide Bank (C2026G00554) requires a rectification plan addressing the weaknesses and deficiencies in the non-financial risk management framework, "including with reference to the findings, observations and recommendations of the Deloitte RCA Report". It is the Deloitte report that found the missing clear, complete and reliable view. The instrument also defines an Independent Reviewer, the role APRA's release calls an independent assurer, with a scope of engagement, quarterly reporting direct to APRA and an obligation to escalate material deviations. Completeness is enforceable here by reference rather than by express words, which is harder to argue with rather than softer. The bank is bound to rectify against a report whose central finding is that its view was not complete.
Two things must be said fairly. APRA states the bank is financially sound, with strong capital and liquidity positions, and Deputy Chair Therese McCarthy Hockey framed the concern as gaps in the non-financial risk management framework rather than the bank's soundness. Separately, AUSTRAC has an enforcement investigation on foot, which is an investigation and not a finding of contravention.
One related question this article leaves alone. The accountability exposure created by findings that stay open for years is a real problem, but it is a different problem from whether the inventory those findings sit in is complete at all, and the second comes first. A well-managed backlog tells you nothing about the risks that never generated a finding because they were never on the list.
Where does AI come into this?
Not from APRA. Neither the 18 August release nor the 11 August one mentions artificial intelligence, no source says the bank used AI in its risk transformation program, and this is not an AI enforcement action. The connection drawn in the rest of this article is ours.
What makes it more than speculation is APRA's own letter to industry on artificial intelligence, issued to all APRA-regulated entities on 30 April 2026 after a targeted engagement with selected large banks, insurers and superannuation trustees. Two sentences do the work. The first: entities are using AI to improve threat hunting and vulnerability identification, "with the challenge being remediating at the speed with which vulnerabilities are identified". The second is broader and less quoted: "assurance practices are not keeping pace with the scale, speed and complexity of AI."
Put those beside a licence condition requiring an independent reviewer, and the practitioner question resolves itself. If your obligations register, risk taxonomy or control map was built or expanded with AI assistance, an assurer will not test whether it reads well. They will test whether it covers what it claims to cover.
Why can a model not assert completeness?
Because completeness is not visible on the face of a document. It is a relationship between a list and an authoritative source population, and only one half of that relationship sits in the model's context window.

A model given forty of your sixty source documents produces a map indistinguishable from one built on all sixty. It cannot report the twenty it never saw. Worse, the output reads as more confident, because fewer sources means fewer contradictions in the prose. Fluency and coverage are independent variables, and only fluency shows up in the deliverable.
A better prompt is not the fix. Asking a model to list the obligations it may have missed produces plausible gaps drawn from training data rather than from your source population, which is worse than silence because it looks like assurance. Ask it instead to confirm a control map is comprehensive and it answers the only question it can, which is whether the map is internally coherent.
The workable posture is narrow: let the model extract, never let it attest. Extraction from a defined document set is exactly the high-volume, well-specified work a model does faster than a person. Attestation about a boundary it cannot see is not.
What does reconciliation evidence contain?
Reconciliation converts an unprovable adjective into a dated artefact. Six steps, and the sequence matters because step one is where most programs fail.
- Define and freeze the source population. Name every authoritative source that defines completeness for this map: legislation, prudential standards, licence conditions, contracts, the policy set. Record each source's identifier, version and capture date. A map cannot be complete in the abstract, only complete against something.
- Extract, never assert. Have the model produce a candidate map in which every row carries its source locator: document, section, and the exact passage relied on. Rows without a locator are not entries. They are questions.
- Run the difference in both directions. One direction finds coverage gaps, the other unsupported entries. Most reviews run only the first.
- Adjudicate every difference by name and date. A person records the decision, the reason and the date. "Not applicable to this entity" is an acceptable outcome. An unexplained deletion is not.
- State the residual explicitly. What remains unreconciled, why, who accepted it and when it will be revisited. A residual of zero on a first pass is a finding in itself.
- Package it as the assurer would ask for it. What gets handed over is the reconciliation record. The map is the conclusion; the reconciliation is the working.

TheAICommand works to the Verified Draft Method: de-identify the inputs, ground the model in your own source material, keep a person at the decision point, verify against the primary source, and log what happened. Reconciliation is that method applied to an inventory rather than a document, and the log is the part an assurer reads.
It also draws a clean line against ordinary register upkeep. Change control over an obligations register keeps an existing record accurate as sources move. Reconciliation asks whether the record covered its source population to begin with. An organisation can run immaculate change control over an inventory that was never complete, and the log will look excellent until someone tests the boundary.
What does this look like on one control map?
Take one map rather than the enterprise. [BUSINESS_AREA_BAND] holds a map of [CONTROL_COUNT_BAND] key controls, last rebuilt during [DATE_BAND] with AI assistance over the policy set and process documentation.
The source population is frozen first: [SOURCE_COUNT_BAND] documents, each versioned and date-stamped. The model extracts a candidate map with a source locator on every row. The difference run finds [GAP_COUNT_BAND] obligations in the source set with no control mapped to them, and a smaller number of controls carrying no locator at all, survivors of the previous template. Each difference goes to [OWNER_ROLE], who records a decision and a date. Several gaps close by pointing at a control already operating but never mapped. Two are genuine and become findings with owners. One unsupported control turns out to be a real internal control with no external source, retained with that basis stated. The residual is the honest part: [RESIDUAL_COUNT_BAND] items where applicability is contested, accepted by [ACCOUNTABLE_ROLE] on [DATE_BAND] with a review date attached.
None of that requires new technology. It requires the difference run to exist and its decisions written down as they are made, because reconstructing them later is what turns a two-week exercise into a multi-year program. The same discipline makes an AI use case register readable by a board rather than merely long.
What should the model never be allowed to assert?
Six things, each a claim about something outside the model's context.
That the map is complete. That the source population is exhaustive. That no difference means no gap, which holds only if the model read the source. That a control is material, which is a judgement about your business, not your documents. That a difference is immaterial and can close without adjudication. And that a finding is closed, which is a statement about the world rather than about text.
Anything the model does assert about coverage is a hypothesis requiring a source locator, just as AI-assisted audit output counts as evidence only once it is traceable. The model's job is to make the difference run cheap enough to do properly. The attestation stays with the person whose name goes on it.
Do this Monday
- Pick one map and ask a single question. For your obligations register, risk taxonomy or a control map, name the source population it was built from, with versions. If nobody answers inside ten minutes, that is the finding.
- Run the reverse difference. Check twenty rows for a source locator, then check twenty items from the source set appear in the map. The second direction is the one nobody runs.
- Date the last completeness test. Not the last review or update. The last time someone tested the boundary of the list against its sources.
- Separate extraction from attestation in writing. Record which parts were AI-extracted and which were human-adjudicated, so the distinction survives staff turnover.
- Write the residual down. Put whatever is contested or pending advice into a stated residual with a named acceptor and a review date, not an empty cell.
- Rehearse the assurer's request. Ask what you would hand over tomorrow if an assurer asked how you know the map is complete, then build the missing half now rather than under a condition.
Bottom line
APRA has made the absence of a clear, complete and reliable view of obligations, risks and controls a finding that a bank must now rectify under licence conditions, with an independent reviewer and board attestation attached. AI makes those maps far faster to build, and makes them look finished at the moment they are least provable. Completeness is not a quality you can write into a document. It is a reconciliation against a named source population, adjudicated by a person, on a date. Build the working, not just the answer.
Content disclaimer: This article is for general educational and informational purposes only. It does not constitute legal advice, regulatory guidance, or a substitute for professional compliance judgement. Statements about Bendigo and Adelaide Bank are drawn from APRA's published media releases and the registered instrument imposing the licence conditions, nothing described here has been decided by a court, and the AUSTRAC matter is an investigation rather than a finding of contravention. Obligations vary by entity type, licence and circumstance. Always refer to primary source guidance from APRA, ASIC, AUSTRAC or the relevant authority.
References
- APRA, APRA imposes licence conditions on Bendigo and Adelaide Bank over persistent risk management weaknesses, 18 August 2026. https://www.apra.gov.au/news-and-publications/apra-imposes-licence-conditions-bendigo-and-adelaide-bank
- APRA, Conditions on banking authority 2026 Bendigo and Adelaide Bank, C2026G00554, registered 18 August 2026. https://www.legislation.gov.au/C2026G00554/asmade
- APRA, APRA Letter to Industry on Artificial Intelligence (AI), 30 April 2026. https://www.apra.gov.au/news-and-publications/apra-letter-industry-artificial-intelligence-ai
- APRA, APRA and AUSTRAC take action in response to risk management deficiencies at Bendigo and Adelaide Bank, 18 December 2025. https://www.apra.gov.au/news-and-publications/apra-and-austrac-take-action-response-risk-management-deficiencies-bendigo
- APRA, Bendigo and Adelaide Bank admits to breaching its BEAR obligations in relation to cyber incident, 11 August 2026. https://www.apra.gov.au/news-and-publications/bendigo-and-adelaide-bank-admits-breaching-its-bear-obligations-relation
TheAICommand. Intelligence, At Your Command.


